GDPR is enforced in the UK exclusively by the Office of the Information Commisioner, which is hopelessly underfunded. There are no "expensive audits and invedtigations". Instead, the ICO sends you several letters containing friendly advice on how to come into compliance, before even thinking about actual enforcement.