> It doesn't help that the GDPR is only really simple if you don't abuse personal data.
I'm not sure how helpful this criterion is; there exists a large gray area in what people consider to be "abuse". For instance, suppose that an EU-based business hotlinks an image from a U.S.-based website (or a website hosted on a U.S. CDN, or a website operated by a business owned by a U.S. corporation). Then that business is at risk of being fined, since it has no way of proving that the target website does not log IP addresses (e.g., for some DoS-protection suite), and if it does, the U.S. government could gain access to those IP addresses, which are defined as protected personal information.
In this scenario, the EU-based business isn't necessarily doing anything nefarious like selling data to advertisers, and it could even be refraining from storing any data at all. Likewise, a U.S.-based website that stores only connection logs isn't necessarily doing nefarious things with those. But the former business is still at risk of being fined, since IP addresses have been placed under the umbrella of protected personal information.
In the discussion a while back of the Google IP-address fine, I saw two talking points come up repeatedly: that there would have been no issue if Google weren't doing nefarious tracking of IP addresses, and that the EU operator must have known that IP addresses are radioactive to store or transmit but chose to do so anyway. AFAICT, the first is inaccurate, since any persistent storage of IP addresses by U.S. operators is problematic. And the second, I think, illustrates the real tension here: between privacy maximalists who prefer the least possible amount of data to be stored in all circumstances, regardless of the cost, and everyday server operators who fear that using the default settings on their software or using seemingly-trivial functionality could be introducing legal liability.
I'm still not sure myself about the relative merits of the two viewpoints, but much more could be done to assist the latter group in following best practices, instead of immediately demonizing them as nefarious loophole finders. (Not to say that nefarious operators don't exist, of course, but I suspect that their prevelance is very easily overstated.)