Also it's not really my experience having worked for a few EU tech companies. The small guys have 0 issues following the regulations, even without a single lawyer working there, since they're usually not so blinded by the prospect of infinite money and usually just stick to collecting what is necessary and nothing more. My company has 1 or 2 lawyers, but they're more there for things wholly unrelated to GDPR or anything like it, and we've never been on the sharp end of the legislation and likely never will be, assuming the suits don't drop 100IQ points and decide to go for "infinite" growth.
Even a cash-only business with no electronics anywhere would still need nontrivial GDPR compliance efforts because it has employees. Just because you need the data to run your business doesn’t automatically make you exempt without further paperwork. Your lawyers definitely do occasional GDPR compliance work.
https://www.dickinson-wright.com/news-alerts/the-gdpr-covers...
It’s a bit like accounting. You can structure your business operations is ways that make the accounting easier or harder, but unless you shut the business down you will always have done enough somewhere to need to think about (and probably file paperwork for) accounting/GDPR. And much like accounting, I’m not saying the GDPR is bad, but it’s also not a business activity that you can just ignore because you’re not running an adtech data vacuum or whatever.
Tell that to GitHub for instance: https://github.blog/2020-12-17-no-cookie-for-you/
Edit: In addition with AI act and its very broad definition of what an AI is and a classification like "Education" you might end up in level "highest risk" just for calculating statistics on your quiz app (no one knows until a court rules). With Cyber Resilience Act and its application of the (physical) supply chain direction, your open source repo from 5 years ago might end up being a footgun with you being personally accountable for other companies using it in their product. And so on...
And for a startup it's trivial to comply with GDPR because:
- you start from scratch, so you know not to collect more data than you need
- you don't need that much data to begin with