So self-hostable or on-prem software has the advantage, not specifically FOSS. But in many cases this transfers the gdpr compliance burden to the business that's running the software
The burden is on the owner of the data in any case. When using an external data processor like Microsoft they have to make sure that the external company complies, and this must be explicitly covered by the contract.