Earlier quoted context omitted.
How is GDPR a problem at all? Is it so hard to avoid personalized tracking of unregistered users, ask users for their consent at sign-up time and implement a button for them to export and delete their data?
The problem with GDPR is that the actual scope of it applies to is rather unclear, and the regulatory guidance hasn't been reassuring as to what the actual extent will be in practice. For example, do email addresses on the comments on a blog site fall under that protection? If so, there are some agencies in charge of enforcing GDPR that are violating GDPR on their sites...
THat doesn't mean you can't use email addresses without asking; ie if the comment system uses emails to notify people of replies or moderative actions, then it's totally legit to collect it for exactly this purpose.
You only need consent if the personal data collected isn't strictly necessary for the operation of your site, ie if you use tracking cookies and sell emails to advertisers.