I suspect that the 'nightmare GDPR letter' pushes the boundaries on what the GDPR would probably intent as a reasonable request, and I wonder if it would hold up in court if challenged by one of the companies.
I think most of the provisions make a lot of sense if you look at them in a simple way. It's not unreasonable to ask a company:
* what information on me do you keep?
* what are you using it for?
* can you provide me with a copy of my data? (with interesting situations where the data itself might be privacy or competitively sensitive, e.g. can I expect a company to share derived insurance scores with me? what if the data also includes other people's data?)
* can you erase my data?
As for impact on small SaaS businesses, I think it is relatively limited. .e.g For my SaaS side business I could probably answer the nightmare request within a day, if I would get 1+ request per week we could probably automate the response, with the exception of manual ID validation. Information deletion is something that the app wouldn't handle well at the moment and would be a bit more work.
Thinking of it in this way, this is probably only a problem for a) large user bases (in which case I hope companies have the capacity to automate these requests efficiently), and b) data hoarding / ad companies (for which I don't really feel sorry)