However, the rules are vague enough to be interpreted in other ways as well. If some authority decides to make an example of pesky local startups for whatever reason there is little that prevents them from doing so. Remember, both the actual implementation and the enforcement of the regulation lies with the EU member countries, which even might decide to further devolve that responsibility to a local level.
Moreover, in the past similar regulations such as the legal notice requirement for websites in some EU member countries were abused by shady lawyers who specifically target small business that supposedly don't comply with these rules.
However, who will decide what the state of the art actually is at any given time? Politicians, lawyers, competitors, actual IT experts? The latter don’t commonly work for either EU or local authorities.
Because the laws are implemented by each EU member state that state of the art might even differ depending on whether you’re located in, say, France or Germany.
As soon as your side project processes and / or stores user data GDPR applies to you.
Good luck with providing the requisite documentation and data processing agreements if authorities ask for them and you didn’t prepare those in time.
Any hobby that gets to a point of making money in EU gets a nexus. Everything else is a FUD. Facebook, Google, Apple, etc all have nexus which is why it is applicable to them. JoeSchmoeLLC from Delaware does not.
A small company absolutely can get by with shoebox accounting, too, it's just not particularly advisable to do so.
The same applies to completely ignoring GDPR, whether it's enforceable or not.
It is as laughable as it gets. Let me guess:
1. You never cross a street not on a crosswalk 2. You never drive above speed limit 3. You never signup for the same website twice if their TOS say "you shall have only one account"? ...
And so many other silly statements.
Laws are only useful if they cab be enforced. This law cannot be enforced against any entity not in jurisdiction.
If you don't want to do business with someone from another country you certainly don't have to comply with other countries' laws. If on the other hand you do sell a product or service to businesses or people abroad you have to comply with the relevant laws of their respective home countries.
That's not a new or GDPR-specific situation but rather has been the case since pretty much the beginning of international trade.
"I got a letter from your government the other day. I opened and read it. It said they were suckers..." On a serious note though, regulation is already onerous to small (and very small) business. The last thing a rational entrepreneur would do is tie themselves up with more of it voluntarily. Unless you can present a reason to do so that is not sanctimonious.
Get the basics down, the documentation can follow. Get the basics wrong and it becomes painful.
However, the documentation still is required. You can create some of that later or just in case you're requested to do so but as soon as third parties (i.e. data processors) are involved that might not be possible anymore.
At the very least you'll be very busy for a few days because such requests by relevant authorities will come attached with a somewhat tight deadline ("Please supply these documents within 2 weeks or else ...").