One important way is ambiguity. For example, it relies on "legitimate interests" as a lawful basis for a lot of different types of processing, but there is no specific, actionable definition of that term. This is compounded by the right of the data subject to object to some processing, but again with only an ambiguous specification of when those rights take precedence over the legitimate interests of the data controller (other than a few specific cases, such as direct marketing).
As another example, there is a new subject right to erasure of their data, though again this isn't absolute. Several potential complications were discussed about this right. One is how to handle copies of that data in back-ups, archives or retired equipment. Another is how to deal with data held in deliberately tamper-proof formats, some of which will already have existed before this right to erasure was introduced by the GDPR.
Another important way is the compliance costs, and in particular the disproportionate costs to small businesses. For example, it cost mine many hours and thousands of pounds to understand the new requirements, take advice, and update our documentation to be compliant, yet the actual data processing we did was always very light and so wasn't affected much by the new rules either. In other words, it cost us a significant amount of time and money without really benefitting anyone.
Related to that is the enforcement mechanism and penalty regime. Regulators are all-powerful, and again, while they can impose some heavy fines on big businesses, those are meaningfully capped. In contrast, the rules allow them to impose penalties high enough to literally destroy any SME. The practical safeguards are the limited resources of regulators and the idea that those regulators are supposed to work collaboratively with data controllers and impose proportionate penalties for any compliance violations that can't be resolved, but this is awfully close to relying on personal judgement and good will, not what is actually written in law.
Then there is the reality that the GDPR doesn't actually do that much to protect against some of the biggest threats to personal privacy. For example, I would argue that two of the biggest risks in our modern "big data" world are excessive collection and processing of personal data supplied by third parties and excessive collection and processing of data by governments. The GDPR has done very little to curb either of those things. Every time I go out, I'm still potentially being listened to or photographed by countless other people's devices, which may then be uploading that data to big tech firms along with time and place information. Countless people have probably handed over my phone number or email address to big tech firms by allowing apps to scan their address book. We still see ever more intrusive monitoring of normal people's daily lives by governments, with tech like facial recognition cameras or mass surveillance of communications routinely infringing on personal privacy, and the authorities pushing for these things are entirely unrepentant and rely on the usual vague justifications about security and what a dangerous world we live in.
In short, the GDPR imposes significant burdens on data controllers without being clear about what their obligations or how to interpret key details in practice, introduces a penalty regime that hangs like a sword of Damocles over data controllers and represents an existential threat to smaller controllers, and yet at the same time hasn't actually been very effective at reducing the big risks to data subjects or increasing their control over how data about them is used and by whom.
None of these concerns is new. All were discussed extensively around the time the GDPR was introduced. But, perhaps because it was a law meant to improve individual privacy and that's a cause many of us support in principle, sometimes people get very defensive of it instead of looking at it critically and asking whether it actually achieves what it set out to do and whether any costs it introduces are proportionate to any benefits it offers.