Yes. Whether or not you are affected by the GDPR does not depend on the size of your company, but solely on whether you process, store or otherwise use personal data (e.g. names of your customers, telephone numbers or email addresses) in any form.
EPUs must also comply with the GDPR.
The risk for small businesses comes primarily from potential claims for damages and penalties resulting from incorrect handling of data subject requests and the documentation requirements of the GDPR.