The compliance model is very simple. Do not collect data. Problem solved. If you need to collect data (e.g. because you are a webshop), only collect the minimum necessary.
The problem is not the GDPR, the problem is the surveillance industry that wants to grab as much data as possible and try to do as much malicious compliance as possible.
Designing around GDPR compliance shows up all over the place in industrial data collection. It doesn't only affect surveillance webslop.
The costs are often worse on industrial side because the data is so much larger and faster than web or mobile data.
> compliance model is very simple. Do not collect data. Problem solved
In a perfect world, yes. In the real world, there is an entire industry of lawyers who will smother your competitors with bogus requests because GDPR requires you spend time and resources to investigate and respond to each and every complaint regardless of merit.