One I have actually dealt with was VATMOSS. Especially when first introduced it had very low ceilings for registration and actually deterred small businesses from trading across borders.
I also think GDPR is too strict for small businesses and non-profits and not strict enough to deal with big businesses that trade data.
> too strict for small businesses and non-profits
Maybe just calibrated poorly. Small enough and IMO the only important rule is no sharing with others. That should always be strictly enforced. But why worry about how some small timer handles my personal data or if I can make various requests of him? The stakes are too small to matter.
Having health with VATMOSS too my experience is that it was trivial to implement. Maybe your country fucked up the rollout? Here in Sweden I had zero issues.