This. Most EU regulations are common sense and/or don't apply to small companies.
Have a privacy policy, don't collect unnecessary user data, encrypt data properly, don't use cookies to track people outside what is needed for your website to function, and allow your users to access and delete their data. You should have already done that before GDPR, and if you did not, you're the reason we need the law.