Closely followed by the BETTERID act in response to sites using substandard identity providers, a set of stringent compliance requirements to ensure the compliant collection and storage of verification documentation requiring annual certification by an approved auditing agency who must provide evidence of controls in place to ensure [...]
What would you have preferred? Of course you'd prefer if the law never existed in the first place, but I don't see having a third party auditor verify compliance is any worse than say, letting the government audit it. We don't think it's "regulatory capture" to let private firms audit companies' books, for instance.