It's really not that hard to comply with GDPR. The easiest way is not storing PII, and if you do, only do so with consent and have a way of deleting that data. That's already 80% of compliance.
True, and that's my default approach. But what about building a ML dataset and model?
Also, aren't we supposed to gather consent for every use, separately? And not prevent users from using the service should they refuse to share their data?
Or am I just confused, and should just spend more time looking into it, or pay some (supposedly expert) (expensive) lawyer ?