The Poland proposal [1] to limit GDPR compliance to only large businesses was trying to address that. But it's flawed, because a small company (Cambridge Analytics) could still make a lot of damage to users' privacy... but the intent of Poland was good.
I feel there should be an opt-out based on the numbers of users and the age of the company/service: If you can easily prove that you're not handling more than X users and your company is less than 2 years old, then GDPR does not apply yet, as long as you warn clearly on your website that you're not-yet-falling-under-GDPR. If you're still in the GDPR-waiver zone but believe to be GDPR compliant, then you can remove the warning and are subject to GDPR like every other company.
That way entrepreneurs won't be scared to try some MVP here and there. I'm especially thinking of those trying to start a startup in countries that are part of the E.U.. The rest of the world entrepreneurs can just focus on their local userbase.
[1] https://iapp.org/news/a/polands-proposed-gdpr-exemptions-spa...