At least my reading of the GDRP is that it tries very hard not be a big burden. If you are a small company or organisation and you collect a minimal amount of information (for example to contact them) there is not a lot you have to do.
The main thing is, you are not allowed to be sloppy. If you collect personal data, you have to think about whether you should collect it at all, where to store it, process it, and when to delete it. And you have to tell people that before you ask them for personal data.
Nothing like, we just collect a bunch of data, give copies to everybody, and have no idea what we collected. That attitude no longer works.
If you set up food regulations, are you going to exempt restaurants with only one cook? Or have aviation regulations that do not apply to airlines with only one pilot?
Given that the entire GDRP is less then a hundred pages, you can easily read it in one evening and get an idea of what you can do, have to do, and what the corner cases are that you may need to discuss with a lawyer.
But restaurants with only one cook can't afford a $300/h lawyer to tell them how to keep their shit hygienic!
If it turns out that you are in breach, they will write to you with information about what you're doign wrong and how to fix it.
In the EU we don't rely on lawyers for a fraction of the stuff you do in the US.