The definitions of personal data are highly ambigious. Perfectly normal processes that people would not normally consider collecting personal information (like maintaining a normal HTTP access log) do count because of things like claiming an IP Address is personal information.
hell everything about the law is highly ambigious. Let's say somebody runs a web forum where people can post messages. We are using one right now. Lets say no personally identifiable data is deliberately collected. No use of email addresses as usernames, or even to offer a forget password flow. The user names are arbitrary. There is no IP address logging of any form even to combat abuse. All posts are publicly available, so users don't need to sign up unless they want to post, and obviously posting is entirely voluntary, so obviously consent is no issue.
Even under this scheme, which is seeking to minimize all compliance burdens of the GDPR while still offering a forum, the site still needs to offer data dumps from users on demand, since their screenname is quite plausibly linkable to their real life identity.
And how do you implement the right to be forgotten. You can implement it as a mass delete of that user's posts, but that is probably not good enough. The problem is that many forums either support or have a user convention of quoting parts of previous messages (including screen name) so people know exactly what you are trying to reply to.
If commonly used, then that defeats mass deletion as a proper implementation of the right to be forgotten, since large chunks of the user's posts (associated with the user's screenname) will be left in replies. Filtering that out may range from easy to difficult, or even to being a completely manual process (which wouldn't work well for certain super prolific posters).
And this is before considering the fact that the law does not let you off the hook if you fail to find some personally identifiable data for that data dump because it was something somebody else posted as unstructured text in the body of a post. It could just be a phone number and address pairing, with no reference to the screen name or anything. No way are you going to reliably find that, but you are still technically liable if a user discovers you had that data and missed it when they requested the data dump. The regulators may decide not to really enforce such edge cases, but they could. They even might enforce that against you if the regulator decides they want to send a message, and crack down hard on violations.
Consider instead a video provider, and there is personally identifiable information about a different user mentioned in some uploaded video. Are regulators going to expect you yo be able to find that video in response to a subject access request? Surely not. But what if you are YouTube? The answer then could very well be quite different, since google could easily search their autogenerated closed captions to potentially find this video. They certainly could be doing that already to augment their profile of you. (I doubt they are, but it is definitely not impossible).
Very very few business never collect any personally identifiable information. Even if they try, they will likely collect some accidentally, like if a consumer calls with a question which cannot be answered right away. A note of some form will be taken that will probably have a name or phone number, so that once an answer is found, it can be provided back to the caller. A B2B business cannot avoid this either, since they still deal with individuals in the other businesses. While I'm sure the majority of businesses just ignore this, since the GDPR is really only targeting mass data collection, not little incidental bits here and there, but the terms don't actually make any such distinction.
The GDPR depends a lot of regulators exercising discretion in terms of not going after such tiny violations. Which is not really a problem per se, but does mean greater legal uncertainty in cases that involve some slightly gray areas. At least in contrast to the often far more black and white hyper-specific legislation often found in civil law countries, or even the eventual binding precedent over ambiguous laws set in common law countries. The main avenue for getting such certainly with the GDPR is the enforcement harmonization system in the GDPR which will likely take several more decades before many common gray areas have been definitively settled.