Why is the GDPR an requirements nightmare? It's one ruleset for the whole EU instead one ruleset for each EU state. And the GDPR seem to be not more complicate than the individuel laws where before.
In other words, it's not a replacement: it is an additional set of rules to keep (although most of it would be a superset of various national laws).
I quote from the title of 2017/0003/COD COM (2017) 10:
Proposal for a REGULATION OF THE EUROPEAN PARLIAMENT
AND OF THE COUNCIL concerning the respect for private
life and the protection of personal data in electronic
communications and repealing Directive 2002/58/EC
(Regulation on Privacy and Electronic Communications)
Note the word "repealing".My point still stands - you still need to conform to both GDPR and the state-specific legislation.
But assuming that I am right, then a replacement directive would simply cause the states to update their laws and nothing would really change in terms of complexity compared to the situation before.
So yea, a 20M EUR fine could destroy a startup.