I helped build a GDPR compliant system for container shipping crew personnel details that included passport photos and other sensitive details. GDPR was actually helpful in that it asks you to treat personal data as if it’s as important as credit card data. We did this and consequently if you had a a database dump or backup you’d be really hard pushed to extract any crew information from it and getting at passport copies was even more difficult. I think it’s a very well thought through spec and eventually those companies ignoring it will get burned one way or another.
Edit: removed needlessly aggressive "That is a lie" opening gambit.
Edit: removed needlessly aggressive "That is a lie" opening gambit.