As a public body, you are required to appoint a data protection officer. That officer may be an existing staff member, provided that they have suitable training. They may fulfil other tasks and duties, as long as these duties do not result in a conflict of interests. The same person can act as the data protection officer for more than one organisation, so you could share a DPO with other schools or the local authority. (GDPR Art. 37-39) If no-one in your organisation is competent to act as a DPO, then you were almost certainly breaching the Data Protection Act.
https://gdpr-info.eu/art-37-gdpr/
>Things like publicly visible visitors books are outlawed (depending on how you read guidance), the alternative are electronic systems - more cost.
They were already illegal under the Data Protection Act. You can use visitor forms or cards instead of a visitor book - the receptionist still has a record of visitors, but their personal information isn't on display.
>Displaying certain sensitive information, prescriptions for pupils, are now outlawed, this could compromise safety.
This was already illegal under the Data Protection Act. If parents want staff to be aware of sensitive medical information relating to their child, you should have taken a written declaration consenting for that information to be shared. That information should not be displayed in a place where pupils, visitors or any other unauthorised person might see it.