While I love the EU's new data privacy regulation from a user's perspective, it's a nightmare for businesses to achieve compliance, because of the (sometimes intentionally) vague language of the law. And even if you pay an experienced lawyer to draft the policies and procedures required by GDPR, there's a very real residual risk of predatory law firms collecting penalties from mass-mailed cease-and-desist letters based on technicalities. Even if your business isn't located within the EU, you are required to comply with GDPR because the location of the
user matters.
I've built a tool that blocks users who are trying to access your website from within the EU as a short-cut to compliance, which makes sense if your business isn't reliant on EU users and you don't want to spend thousands in legal fees to achieve GDPR compliance.
You can check it out here: https://www.gdpr-shield.io