A few things might have been missed because they are not super common:
1. Data export
2. DPO or DPO-ish person (which simply might be you, the developer)
3. Actually writing down somewhere what data you store, how, where and why (which is a lot easier to do than you'd think -- again unless you are trying to hide that on purpose)
The GDPR has massive costs, and the 90% of companies that aren't villains are going to bear about 90% of them.
EDIT: D'oh, just noticed the "Fork me on GitHub" banner. Okay, then!
Sure, the companies might be "hysteric", but I don't think this list is aimed to spread that hysteria.
Edit: removed remark about reaction
(E.g. the linked article for ragnarok mentions that just eu access is being closed)
On the other hand, I can attest to the pain its caused to smaller companies having to implement support for it, and while some of the companies that have shut down were apparently using user data in detestable ways, I'm sure it's got a lot of companies scrambling.
Interested to see what happens after the 25th.
You have a few hundred customers and maybe 10 of those are in Europe.
Would that company need to worry about complying? How much should they worry?
That's one site that I wouldn't regard as either "good riddance" or "grandstanding".
I wonder what went into their calculation that caused them to decide to shut down.
1) Paid some actual lawyers to look at compliance
2) Looked at the revenue they are currently getting in the EU
3) Looked at the engineering effort and cost they would have to expend to come into compliance
4) Compared 2 & 3 and decided to pull the plug
It's interesting to me because this is the first solid evidence that GDPR does have a real cost to a business isn't a bad actor in spite of what many people otherwise claim.
The costs may be large and many companies may leave, but China has shuttered out these same companies and they've done well to solve their needs from within the country.
Of course China's goals were much different than citizen's rights.
We really need something like the GDPR, and it can't be opt out. There is far too cavalier an attitude by almost all businesses toward your information and they never really suffer any penalty for their recklessness. And there are quite a few genuine bad actors who really need to get reined in.
I also hope that once the GDPR is in effect, there will be some adjustments to it when everybody starts figuring out what works, what doesn't, and what's expensive.
However, the GDPR probably should have had some sort of "grandfather" clause that would have applied to something like Ragnarok Online. Bringing a code base of that age into compliance would probably require a massive engineering effort that completely swamps the revenue they are currently getting.