GDPR is not about security but about privacy and data access protection. In fact security is mostly on paper: requires that you document the data and procedures, but doesn't require you to upgrade your security. So the effort for the one has little to do with effort for the other.