The compliance risk is what's dangerous and challenging, not the actual "fixing" of systems. Many people in these comments seem to have no experience with business risk management. They think it's as simple as "just make data deletable." But, the technical side is the easy part. It's the getting sued part that's potentially catastrophic. Even if you "win" you still have spent thousands or tens of thousands defending. And even if you do win, you could be sued again the very next day.
GDPR is more than just deleting data, it's a massive business risk to even companies doing it "right."
You can be sued at essentially anytime for any reason, long before the GDPR. If you're worried about a GDPR lawsuit ruining your company then you're either violating the GDPR or you should have shut down already because the risk was already there.
X is guilty of violating Y because they're worried about being sued for Y. Interesting legal principle.
> or you should have shut down already because the risk was already there
X should shut down because of the risk of being sued for Y? What?
No luck at home with Virgin Media's "ehhh we'll look at IPv6 eventually"