Mom and pop businesses with limited IT skills are not collecting emails and private information. At worst they’d be using some external service (e.g. Mailchimp) which does it for them, and those have an obligation to be familiar with the law.
The GDPR really isn't that hard to follow, for a "mom & pop" business, it really comes down to:
* Limit data retention — Don't keep personal data longer than necessary
* Honor data subject rights — Allow individuals to access, correct, delete, or port their personal data
Simply, don't collect personal information if you don't need it. If you do need it, add a delete button.