On the other hand this legislation will completely change the internet as we know it.
All you need is a privacy policy and the ability to delete / return customer data when requested. But that doesn't have to be in real time/automated, you can just set up an email address and respond manually. It's rare you'll even get a request if you're a company with such a small IT budget.
All the other things (double opt-in email, not contacting your customers in an unsolicited way) are process changes that can be implemented without IT cost.
Oh, and by the way, as long as you show something to EU visitors (even an error page telling them to GTFO), you need a privacy policy.
As a small business you can comply with the GDPR fairly easily unless you have no regard for anyone's privacy to begin with. And even if you're not 100% compliant you won't be insta-sued to bankruptcy, you'll only be reported and the relevant data protection agency will check on you. The GDPR encourages data protection agencies to help businesses fix their problems and only use fines as a last resort for gross violations and wilful negligence.
Unless you're storing/processing information that has special protections (e.g. religion, sexual orientation, medical data) the bureaucracy is also fairly tame, especially for small businesses, especially for businesses that aren't at their core based on processing personal information (e.g. not online dating startups).
Compare this with the "upload filter" as it has been interpreted in the media so far: allegedly every website that allows users to upload content would have to implement their own Content ID database and sign deals with publishing companies or license filtering services.
They’re both controversial EU-wide regulations, for one.