Earlier quoted context omitted.
> If there's a risk that someone could sue you over something, Which bit of GDPR introduces that risk?
Maybe sue isn't the correct term, but you are talking about potentially a 20 million dollar fine. I'm being told that the EU would never pursue that with a small business and they'd just tell you what you need to fix. That also sounds weird to me as an American. I'm not saying it isn't true, just that it's not the way I'm used to thinking about laws.
For past experience with German privacy regulators (as an example, since our old law was fairly strict too), I'll quote a recent comment of mine:
From what I know, the German DPAs (they are organized on state level) hand out like 2 fines per month each, generally way below the maxima (under old German law, the max was 300000 €), and concluding the majority of cases without a fine. E.g. from the Bavarian DPA (german doc: https://www.lda.bayern.de/media/baylda_report_07.pdf, page 151):
in the years 2015-2016 they had 173 proceedings that involved potential fines. 52 of those resulted in fines. 34 of those fines were