Earlier quoted context omitted.
> probably wise for even site administrators who aren't doing advertising-related data collection to pop the banner. I disagree. As far as I can see, GDPR enforcement is not heavy-handed. You get a warning before any attempt at enforcement; then you get a modest "warning" fine. Also, I'm not aware that the silly cookie banners provide any protection against GDPR enforcement; it's how you handle the data that matters,…
Handling data correctly may not be feasible, especially for smaller users on shared-hosting solutions. https://news.ycombinator.com/item?id=30402052 ... and again, the problem is "correctly" is in the eye of a judge after an alleged violation has occurred.
Regarding Apache logs, a default install of logrotate will probably bring you into compliance (not sure, haven't looked into it lately). Scrubbing IP addresses from Apache logs defeats the purpose of the logs; you need to know what IP addresses are attacking your server.
To reach the stage of a modest fine, you will have to ignore that warning and advice, effectively saying "So fine me, regulator!" And if your violation isn't egregious, you'll be a long way down the list of forthcoming legal actions.
Basically, making a reasonable effort to understand GDPR and come into compliance is probably both a protection against action, and a defence against conviction.
It's not hard to comply with the GDPR, unless you are running a business that depends on violating GDPR.
IANAL.