This is a great video from The Department for Education, which is aimed at schools, but gives a very clear and simple guide to what you need to consider when thinking about GDPR compliance.  It translates well for the rest of us, too.