In terms of what a company has to do, not that much changed since GDPR's predecessor. The difference between the previous law from the 90s and GDPR is mainly publicity (privacy wasn't as big a topic in the 90s) and higher fines, so what I notice as an EU resident is that more companies implement it. (Also companies abroad, but I can't say that e.g. Google's update impacted me beyond annoying banners: they still say "…
But it did change for everyone else that didn't have those laws. Also, the impact of a brach is much bigger now.
OP was asking for EU residents to comment on how it impacted them. This is how it impacted me. If someone else is very happy with GDPR because their country didn't implement the previous law (DPD), they should comment separately.
Edit: actually, all EU member states implemented the DPD: https://en.wikipedia.org/wiki/Data_Protection_Directive#Impl...
So this is actually representative for everyone else.
> Also, the impact of a [breach] is much bigger now
Indeed, as I mentioned, the fines are higher, and that's the only change in that regard.
Note that the requirement to report data breaches to the authorities is not a GDPR thing. The Netherlands introduced a separate law for that prior to GDPR.
And the reason you can be fined for a breach is not because you had a breach. It's not a crime to become the victim of criminal activity, so that's also not new with GDPR. The reason for it resulting in a fine is that it often highlights inadequate security of personal data, which was also illegal under the previous law.