Earlier quoted context omitted.
One option would be to collect less data on users, which should make it easier to manage.
Easy peasy unless your system was built before it became illegal to "haphazardly" process PII. Even organization that take GDPR very seriously and invest a lot on compliance do not generally really know all the places where their legacy systems are storing PII. The law is draconian.
I think this is an extremely poor excuse. You're basically saying they don't understand their systems well enough. It is like a chemical company blaming environmental legislation when they've left barrels of polluting chemicals all over the place and not kept track of them.