1. Ask permission for collecting data
2. Keep sensitive data safe
3. Restrict access to said data
4. Keep a log of what happens with the data
5. Delete it upon request
6. Have all of the above documented and adhere to the protocol.
It's such a none issue unless you're relying on the very thing GDPR is designed to combat. If you not collecting and selling peoples data, and you don't do the above already, see this as a good opportunity to do what you should have been doing all along. There is such an awareness now, that it's the easiest it has ever been to know how to handle sensitive data properly.
This entity can allow a 3rd party service to access these logs so that 3rd party can do whatever needs to be done if it is within the reasons the entity gave for having the data.
What neither can do is go use that data for anything other than the said purposes.
And if the given reasons are gratuitous and somehow the regulators notice, expect to get a nastygram and have to comply or face fines.
Basically what you can't do is collect data for longer than you have a legitimate need for, or cash-in and sell data you've collected. Basically, all said and done, just don't be sleezy and you'll be ok.
Why do you think permission is required?
And even (1) isn't always needed. There are several justifications for processing personal data, and permission is only one of them. (Although for compliance it is the easiest)
https://gdpr-info.eu/art-6-gdpr/
And (5) has a bunch of caveats. You don't always need to delete data.
Right to Erasure: https://gdpr-info.eu/art-17-gdpr/
German courts already considered a EULA or "check box to consent and get thing" a non-binding consent (to some extend).
Largely, if you are running afoul the GDPR in germany there is basically two options A) you rely on adsense a lot and B) you ran afoul the previous laws already.
So, overall, I would say that yeah, most of the stuff forbidden by the GDPR was already forbidden. The GDPR grants you new rights and requires corporations to ensure compliance however, that's new.
Plus the teeth in form of pretty hefty fine limits. Which is good IMO.