One of the problems stems for this dichotomy:
I did not see anything in GDPR which does not make sense to me, it looks like common sense applied to data management
versus
I get a feeling you haven't tried to actually properly implement the GDPR regs, talking to lawyers and everything
Which can be further shortened to:
common sense versus talking to lawyers
While interpretation of laws by necessity is at best difficult and at worst fraught with peril - reality in all its complexities is hard to catch in a few written pages - the legal profession has turned themselves into virtual toll collectors for anything related to law. Ask a lawyer about the legal implications of preparing a peanut butter sandwich and you'll be first presented with a legal disclaimer - pay me if you want advice - and then treated to a tale worthy of Lewis Carroll. GDPR is a $deity-send in this respect, good for many a year of steady income, especially given the stiff fines which threaten.
...which does not mean the person who used common sense to interpret the law is wrong. He is very much likely to be right and, having spent two weeks of technical work to prepare their infrastructure they're probably set to fulfil the obligations the law puts on them. It might need some fine-tuning here and there but that can mostly likely be handled as well without incurring the wrath of the courts.
In short, talking to a lawyer about being able to do something like this by yourself is more or less guaranteed to give the same reply as e.g. talking to someone who does data rescue whether you could replace the head stack on a hard drive by yourself. In both cases it is possible as long as you're careful and use the right tools, in both cases the answer will be 'you could do this at your own peril, disaster is waiting to strike, you take up enormous risks, let the professionals handle it'. Which is true to a certain level, there are risks just like there are risks in any venture.