"Im from the government and Im here to help"
Im from Ireland, On a day to day basis the GDPR rules are more or less red tape for businesses more so than anything else. This does however affect the average Joe citizen at times. The main element applies to business and governmental organisations who are meant to keep your data safe, ie not sell or otherwise let carpetbaggers access to your personal details, name, age, social security, email address, bank details etc.
How do business get around this: Well take the internet, prior to these rules coming in if I i was to surf the net I assumed that every site I visited used my data for their own means, sell it on or for some other marketing strategy, now every site that I visit asks me to accept the security rules and if you dont you cannot access the website. If you click accept then the site can sell your data out the back of a van because you have given your consent; so actually all thats changed is that you are reminded your data is being pimped. Flip side I can theoretically at least demand that a company wipe their mainframe or desk drawer of all information the have on me for example facebook would have to wipe me off their system, within the EU.
Generally when I encounter an incompetent company who did something stupid like take money from my bank by mistake a fast solution to getting a refund is to mention GDPR and data breech down the phone and they are forced to jump high and fast as you can make a complaint officially to the government.
As far a photos go citizens have the right to demand that any images or video clips that might identify them can be removed from the public sphere, ie the internet but the enforcement of this would be in the hands of the government and the big firms Google etc

. However if you were to offer them a euro to take their portrait that might be construed as them giving you consent to use that image.