No, it applies to ANY organisation that stores, deals with, or somehow processes/has possession of other people’s personal data that reside in the EU. It doesn't matter how big you are or whether you provide a paid service. If you store personal data of others, you need to be GDPR compliant.
My VA is now GDPR compliant and have sent out a GDPR notice to all our pilots and I suggest that everyone should at least send something out.
It’s better to be safe than sorry.