To a large extent, privacy is security and collecting less data means not ending up being humiliated in the same way Adobe once was. It also means not upsetting the more local FTC, if someone is large enough for them to care about a breach.
"GDPR compliance" (minus the cookie parts) is kind of just an extension of what someone should be doing anyway.