Ip used for technical reasons such as logging access are not concerned by the gdpr per se. The same goes to KYC informations.
The gdpr is actually a well written piece of legislation which should worry you only if you do shady stuff.
The only edge case that I know are not well addressed concerns the status of encrypted data (would be deleting private keys considered to be deleting them? This question is important on blockchain data storage)