Earlier quoted context omitted.
GDPR like all EU regulation is needlessly complicated and aimed at a compliance model that seems designed for SAP.
The compliance model is very simple. Do not collect data. Problem solved. If you need to collect data (e.g. because you are a webshop), only collect the minimum necessary. The problem is not the GDPR, the problem is the surveillance industry that wants to grab as much data as possible and try to do as much malicious compliance as possible.
In a perfect world, yes. In the real world, there is an entire industry of lawyers who will smother your competitors with bogus requests because GDPR requires you spend time and resources to investigate and respond to each and every complaint regardless of merit.