You seem to be making the same mistake a lot of people (especially those from countries with no regard for consumer protection or privacy) do with regard to the GDPR:
It's not about e-mail addresses. It's about personal information. It's not about what data you can have. It's about how you can use data.
You don't own my personal information, I do. If I give my information to you, you can only use it in whichever ways I consented to when I gave it to you. If you want to use it for something else, you need to ask me again. And you can't just give me a blanket CYA contract to sign just so you can decide later.
This is precisely how it would work in normal everyday social interactions. If I go to a Mom & Pop shop and give them my number so they can call me when my favorite brand of soup is back in stock that doesn't mean they can call me to tell me about random new stuff they carry or give my number away to someone else.
Personal information is owned by the person it is about. It gets murky with aggregates (but the GDPR helps you figure out which ones are still considered personally identifiable) but it's blindingly obvious for things like "enter your e-mail address".
Do you have an e-mail input in a contact form? I'm going to assume that'll be used so you can respond to me although it'd nice of you if you say that explicitly right there on the form. If it's a comment form, why do you need my address? Who will it be shown to? What are you going to do with it? Where will it be stored and how can I tell you to delete it later? That's why you now need to think up a Privacy Policy: these are questions you always had to answer for yourself but now you're legally required to make conscious decisions about this.
Is this too much of a hassle? That likely means you didn't have any good reason to collect that information in the first place. Great! Personal information is a liability and it's better to collect less of it than more. Although that may disappoint future Zuckerbergs, collecting people's private information (even if they give it away voluntarily) imbues a lot of responsibility on you if you don't want to be completely careless. And the GDPR is an example for a policy that gives that responsibility teeth and punishes companies who are careless.
You don't want to store passwords in plaintext. You don't want to hoard credit card details or medical data. Personally identifiable information is no different. The GDPR just provides ways for you to store and use that information legally, in addition to reiterating that privacy and control of your personal information is a human right.