GDPR requires restructuring of applications to keep data on a temporary basis with the consent of the users, to remove data after the fact, to selectively restore, and to allow users access to their own data. These are proactive steps required, and while applications written in the next six months will be built with those requirements in mind, it's still a fairly large burden for business-as-usual applications.