As a reminder, the GDPR also introduces the concept that you are responsible of the safety of your database. Which means that you must ensure that no third parts can access your database and especially the personal information it can contain. Third parts, but also employees/co workers. For example, if all of the employee of a company, can access the database, it might not be GDPR-compliant. (all depends of what the employees are doing of course).
But, this also concerns your web host. Because, you can protect the access to your admin section with password, private key, etc... but, can your web host access the HD/SSD where your data are hosted? And does your web host guarantee that no one can access it?
In theory, your web host should give you these guarantees, that they are doing everything to keep your data confidential.
So with major hosts, they are delivering this guarantee, but with smaller hosts, it's unsure. So it's something to keep in mind.