I have been writing our company policies for GDPR for the last 6 months, it has consumed my life. Actually it's just bureaucratic nonsense, much like ISO is. It will not stop spam, the marketing companies will move outside the EU where the rules don't apply. Legitimate companies will ask you to 'OPT-IN' to continue to receive junk mail, others just inform you that they have changed their privacy policy and you need to log-in to update your preferences. My main beef about it all is the fact that it's aimed mainly at large organisations, yet, it affects the small businesses as well, it's not a cheap exercise either.
Small business have been sent into a panic over the scare mongering spewd out by consultants on the web quoting ridiculous fines imposed if you don't comply. The cost to a small business to have a consultant do most of the work for you is in the region of £6k plus expenses.
An example I came across was a hairdressers local to me. They carry out a skin test on clients before they have a colouring or a perm, they then record those details along with the clients name etc; this means that because they are able to identify a living individual and store that sensitive information and their employees can access that data. So they must comply, investing in data security, access control the list goes on and on.
It's a bloody farce!