I'd like to see a complete and concise list of exactly what needs to be done to comply with GDPR. Everything I've seen so far has been vague legalese open to subjective interpretation. Pretty scary when the punishment for an incorrect interpretation is a 20M EUR fine.
And what are the "many ways" you can "accidentally run afoul of this law while still protecting user data" ?
It's hard for me to grasp.