What frustrates me the most about the GDPR is that a single person building a mailing list for a $19 ebook launch is just as affected and burdened as any other company. A side-business that might make you $30,000/yr is now no longer worth pursuing because of the costs of working with a lawyer to make sure you are GDPR compliant and have all of the right policies in place.
It raises the barrier to entry for small one person businesses even more, forcing out anyone who can't justify the costs of compliance.
If you're building a mailing list for your ebook, won't you just need:
1) Allow people to login and view their personal information: name, email.
2) Allow people to delete the profile.
And don't retain any data other than (1) or (2). If you want to track users to see if they clicked links and what countries they are browsing from then: (A) anonymize it or (B) make it visible in the profile information (1).
If all you record is name and email, you won't need a lot of infrastructure. Your policy might say you transfer email addresses to AWS when sending emails.
It raises the barrier to entry for small one person businesses even more, forcing out anyone who can't justify the costs of compliance.