GDPR is poorly designed. It deliberately uses super vauge and imprecise wording. That is bad enough when operating in a common-law legal system where that is the norm. It is inexcusable in the Civil Law system that much of Europe operates in.
Consider you offer the ability to users to voluntarily submit reviews of restaurants. One reviewer complained that person seated at table next to them was excessively noisy, and that upon asking the waitstaff to do something about it, they did nothing.
It is actually entirely plausible for a company like Facebook to have enough information to be able to determine exactly who that other person is, given that review. For example if say both posted images of their receipts to Instagram. Why would they do that? Beats me, but plenty of people do things like that. Under a wide but not at all implausible reading of the personal information definition in the GDPR, that review qualifies as personal data of the person at the other table. The definition of personal data is "any information relating to an identified or identifiable natural person". And that review does include information about a natural person, and we have shown that the person is theoretically identifiable by Facebook.
This means if that other person asks for all their personal info from the site, technically that review should be included. But most likely even Facebook does not yet have the ability to automatically identify this other individual. However, the regulation does not specify any applicable exception, so if you fail to turn over that data (despite having no way of knowing that review pertains to this specific individual), the supervisory authority could still legally fine you.
Would you ever be fined for that? No of course not. Strictly speaking nothing in the wording of the regulation would prevent them from doing so. But obviously they have so many bigger concerns, and are unlikely to bother interpreting things so widely.
After all, there is not a single large company that operates in Europe that is fully compliant with the GDPR if interpreted widely. There quite simply cannot be, since the costs of actually identifying everything that could count as personal data under a wide interpretation and ensuring the company can always look up 100% of it without ever missing any would bankrupt every such large company.
And that is only touching on one little aspect of the GDPR, and one that is unlikely to actually be a major deal. Much worse is how vague the "legitimate interests" reason for processing is. That is the reason that many companies are relying on for much of their processing, and nobody can say with any certainly what cases are included in that, and what are not.
So obviously the best the companies can due is attempt to follow the spirit of the regulation rather than the letter. But of course, if you do that, you cannot be entirely sure the regulators will agree with you.