Earlier quoted context omitted.
If the 1-3 person startup's application is geared around personal information and it needs a complex privacy policy to describe what it does with data, then yes, it will have to work very hard to comply with GDPR, but that will also result in meaningful improvements in privacy and data control for its customers. Do you have examples of startups where data is not a core business concern, who still find it very onerous…
Here's an example: I have a profitable, bootstrapped SaaS business based in US . It's not based on ads or selling data. I don't even have a freemium plan. Only a limited free trial after which you have to start paying. It's a trivial application that stores mostly already public data. Only email is required to login so that I can send password reset and other such communication. I've been talking to a very well known…
My first job twelve years ago was at a company similar to yours in Switzerland. A small bootstrapped SaaS targeted at enterprise and government. Switzerland is quite serious about privacy with strict laws regarding them, but since they have been around for a long time, nobody freaked out about it. It is just part of the daily business for everyone.
I can't remember compliance with such constraints being a serious competitive disadvantage for the company. In fact after Snowden the label "Made in Switzerland" and images of datacenters in mountain bunkers became an advantage internationally.