Fortunately I don't do any analytics or advertising. I've already set up the server logs to be deleted after a month. Commenters can't create accounts, but it wouldn't be too hard for me to delete their comments. I should probably make a privacy policy.
WordPress does have some plugins for complying with GDPR, so I'm going to try one of those to see what else needs to change, in those developers' opinion. If only there were such a thing as certification so I could trust anyone was doing more than guessing!
Anyway, thanks for your feedback. I appreciated your article.