As others pointed out, the article mixes a lot of things together. EU (GDPR) has very specific and very hard to meet anonymization bar (tldr; it requires anonymization to be at the level where it’s mathematically improbable to de-anonymize the user). None of the “anonymization” examples in the article would pass this EU bar.
Actually the GDPR "just" requires to protect the data against "reasonably likely" attacks.
«
To determine whether a natural person is identifiable, account should be taken of all the means reasonably likely to be used, such as singling out, either by the controller or by another person to identify the natural person directly or indirectly.
To ascertain whether means are reasonably likely to be used to identify the natural person, account should be taken of all objective factors, such as the costs of and the amount of time required for identification, taking into consideration the available technology at the time of the processing and technological developments.
»
I can’t speak for everyone, but the company I work for takes this very seriously and does its best to comply with the law. Said that, all of it is very complicated. Most (if not all) privacy problems I observed so far are caused not by malice but by incompetence. And those get fixed as soon as found.