Currently product managers and some dev leads are currently working with our legal teams to build requirement epics around GDPR to be worked on very early next year by development teams.
About a year ago we had a big push to be fully HIPAA compliant, so we're following a similar process. Luckily, we are hosted on Amazon and already "do the right thing" in terms of encrypting PII and storing it in the closest AWS region, so hopefully it's not too much of a huge lift.