I'd like to point out that you're responding to me as if you assume I have no to little experience with this law and its consequences for organizations. That's not a reasonable assumption - my post is speaking from organizational experience. You're not talking to some outsider of all of this.
If you have specific problems with GDPR or that it goes too far, I'd like to know what those specific aspects are. In my view, there's some basic rules on how to deal with personal data that the GDPR codifies, and it does that surprisingly (for the EU) reasonably. It starts from simple principles of citizen rights and ethical behaviour and writes a complete rulebook on how to apply them - that's my definition of a good job.
It might be difficult for business to adapt to actually now considering processing personal data a risk. But that by itself does not make GDPR "overregulation" - that just makes it a difficult regulation change to process. I won't shed a tear about business having a difficult time going through that process - I'm incredibly happy that they are forced to consider processing personal data a risk, because it is.
Also note I specifically said "Websites that don't want to comply with GDPR" - not "Companies that are not sure they can comply with GDPR yet". There's a reasonable difference, I agree. But, yes, if you find that your business intrinsically cannot comply with GDPR or you don't want to - it's time to take a good hard look in the mirror.