@kravietz My problem with GDPR is the opposite - namely how it harms big corporations least.
For example, me running a SSH server on my personal vserver became technically illegal as the SSH protocol does not support the necessary disclosures, and happily logs every login attempt to the system log (where it tends to age out after 7 days as no one ever looks there anyway unless something is wrong).
I am aware that this kind of log would be permitted under the GDPR if it were properly disclosed. I would also be required to disclose my home address to the entire world just because I run SSH.
IMHO the very least GDPR should have done would be an exclusion so entities that do not use data in a way that requires explicit permission do not need to comply with the disclosure, legal entity etc. requirements. Maybe further conditioned by not making any profit.