As much as I like the idea of "right to be forgotten", it seems to me that an unintended consequence is that non-technical people hosting forums/blogs etc. will be at risk of GDPR requests that they cannot comply with due to lack of technical skills. This will have a silencing effect for people wanting to operate non-profit sites as they won't be able to afford to comply with such requests. They will be forced to eit…
I understand that there's forums/websites run by people who have no idea what they're doing. And regulations like GDPR make sure that services they are using have baseline encryption and guarantees. Like, it should encrypt passwords and private data, don't store it if not necessary and have functionality to delete users.
It is not about people running the websites/forums, it is about software they are choosing to use. Baseline should not be "it works", but it should be "it works and provide reasonable level of security". I know it is some work on part of people who have no idea what they're doing, but ultimately it is up to developers to set up CMS and forum engines to comply.