One requirement, imho, is quite ridiculous, however. That is the need for entities which need to abide by the GDPR but do not have a presence in the EU to assign a representative in the EU.
This part definitely needs some relaxation. Just complying with the regulation ought to be enough as the first step, especially for start-ups.