Every time any new regulation comes out, doesn't matter what law it is, Small Business™ trots out the same sob story: "Woe is us, we are too small to follow this new burdensome law!" I get it--it's going to be costly. This cost is one of many that founders will need to consider when they decide between go and no-go. If founders can't afford to follow (and prove they follow) the law, I think they should re-think their start-up idea. The ADA has done enormous good, in part, because of that industry of lawyers keeping a close watch for opportunities to sue. Same is probably true for HIPPA. Same will, hopefully, be true for GDPR.
The cost of compliance will fall drastically. My company (Aptible) started in HIPAA and is doing a lot with GDPR. They are very similar in a lot of ways, including the emergence of new systems of record for privacy and security management data.