That happens. Still, many companies do not. Some companies are unaware of the legislation.
I was informing one worker of a company of one such law.
Many companies do not break the law even though there are no controls just because that is the right thing to do.
Oh, I see. Indeed anonymised data should be fine under GDPR. However it is often very difficult to anonymise data. Some things are easy to anonymise, other are very complex.
For a small company who does not mainly work with data, the easiest solution to comply with GDPR is indeed just deleting the data altogether.