I'm honestly baffled about the response, especially from the pro-privacy crowd on HN. This is simply the reality of GDPR. If you host and operate a website that serves EU visitors you must comply with GDPR. Of course this is a burden on small operators and it may come off alarming the first time you receive a GDPR request, however, this is GDPR working as intended. It is intended to force operators to explicitly decide which user data they are going to collect (incl. on how to inform users, correct, delete, export, etc. this data).
I do agree that there might be ethical concerns on how this study was conducted, however, the email messages do not suggest pending legal action. They're pretty standard GDPR requests.