My business is not absurdly simple. It's actually pretty complex. We've been respectful of privacy since day 1, although we weren't perfect so we did have to make some updates for GDPR (and I'm glad they were forced on us).
It didn't take long. Couple weeks of work. I did them myself.
Compliance documentation is what's needed: https://twitter.com/Adys/status/1014612906359615490
Edit: Depressing to see people are downvoting real world experience in favour of FUD.