Earlier quoted context omitted.
> Seriously though, GDPR compliance isn’t that hard Unless compiling data on your users and selling it is your entire business plan. One of the issue I see it that many companies have been lured into this impression that they need to track everything, in great detail, but it doesn't actually provide that much value. I blame the snake oil sales people in the advertising/remarketing/up-selling/cross-selling business.
This is correct. So many websites don’t actually need to collect any user data. It’s just a distraction, slows down and bloats their site and worsens UX. I recommend to simply get rid of any tracking. If you want user feedback, ask them or do tests. It’s cheaper and more effective.
Any commercial organisation is going to have customers and therefore customer details and payments data.
Any commercial site needs to record enough logs to investigate events like outages or security threats.
Any site that isn't purely informational and read-only probably works with user-provided data in some way.
People keep writing about GDPR and similar laws as if they only apply to data-harvesting analytics plugins on ad-ridden content farms but the same laws apply to everyone else as well. For many it will be reasonable and indeed necessary to process personal data in order to do whatever the site or app does.