The only customer info I store is Name, address and trelephone number. I do not store e mail addresses. Any marketing done to these customers is by direct mail, so no worries there.
However as far as GDPR is concerned, I am legally bound to protect that info that I store. on my pc I do this by protecting access via a password. Copies on dvd or cd have to also similarly protected.
I also have to produce a document stating what info I store and how it is protected.
That's it!