GDPR is reasonable, maybe too weak regulation of big businesses with lots of data.
The problem is that it applies to small organisations, even non-profits, that do not trade that information which is proportionately a much bigger burden. Real examples of organisations I have come across who have to comply with GDPR include a local community theatre, a parish church etc. They are keep fairly simple information, and not exchanging it with anyone, but they still have to put effort into ensuring compliance. They are pretty good and ethical anyway - the theatre recently impressed me when I found out that if you give them medical information in case of emergency they put it in a sealed envelope and no one opens it unless there is an actually emergency that requires it (i.e. you keel over there!).
> Real examples of organisations I have come across who have to comply with GDPR include a local community theatre, a parish church etc. They are keep fairly simple information, and not exchanging it with anyone, but they still have to put effort into ensuring compliance.
Yeah, and that is precisely where you want something like the GDPR to be as well!
Large corporations are one thing, they have compliance departments, but so, so many local organizations have gotten hacked or data exfiltrated because "why do software and hardware updates when everything is working" or due to incompetence ("cc all"). GDPR finally gave the younger crowd some leverage to get the old guard to do things at least somewhat decently.
> The problem is that it applies to small organisations, even non-profits, that do not trade that information which is proportionately a much bigger burden.
Eh?
Collect only the personal data you need (with permission) and keep it secure. Such a basic responsibility to your members privacy and safety is hardly a burden.