The GDPR does not state that it needs to be automated. I assume SME's will also not automate this unless they get a lot of request. Basically all features that are required by the GDPR are already in most common SME software.
In that case, the GDPR actually sounds quite positive - I believe users should be able to request that their data is deleted, and be told in advance if it's going to be used for anything non-obvious (e.g. training an ML model).