> [...] it seems to me that an unintended consequence is that non-technical people hosting forums/blogs etc. will be at risk of GDPR requests that they cannot comply with due to lack of technical skills [...]
If it's only due to technical skills then this problem can be solved technically.
The forum software needs to enable people to be GDPR compliant.
> On a semi-related note: if you are a small SASS operator wanting to comply with such requests, what are you meant to do about your DB backups that contain data that is meant to be forgotten?
This hasn't been tested in court, yet. But there are several possible approaches. Like delete on restoration or backing up in slices, so that the personal data becomes anonymous unless you have all the parts.
Don't forget that the "right to be forgotten" is not an absolute right. It doesn't trump everything else. Nobody would expect somebody to sue ESA for their "right to be forgotten" for a public message that they could send to ESA to put on a CD on a probe they sent into space and win.
First of all, it forces everybody involved with personal data to think about how they handle personal data and inform the users about that.
If you state "due to technical limitations, your personal data in backups can't be erased at the time of the request but will be deleted on restoration" up front during the signup of the user, this is already an improvement over the past where nobody knew what happened with their data.