That's not what happens though. You get a request, you have 30 days to respond to it (and for the vast majority the privacy policy is ok as a response) and if the requester isn't happy they report it to the regulator who writes for more information. In that situation you again send off your privacy policy, maybe with a bit more detail.
The regulator either tells you that you're wrong, and explains why, and gives you advice to come back into compliance, or agrees with you and tells the requestor that they've misunderstood the law.
And all of this has provisions for proportionality. The regulators will recognise that small forums run for small projects will not have resources to respond to many requests.