Earlier quoted context omitted.
If your businessmodel does not allow for the proper dealing with the information it collects you shouldn't be in business in the first place.
issue isn't the business model, is the size. For a large company, handling GDPR is trivial. For a startup or small company, the cost is prohibitively high. I'm not arguing for or against it, just pointing that the resulting unintended consequence is protecting large companies. Exactly the opposite of the original intent.
A small business or a startup should have a relatively limited amount of data capture, and that data should be stored in a relatively limited number of places. In most cases, it should be straightforward to make sure that this is documented and appropriate controls are in place.
On the other hand, large companies have vast quantities of uncontrolled data gathering that nobody is responsible for.