Summary of the core of #GDPR: your users' and clients' personal data is not yours, and you have to get their permission to collect it and for each way you use it, and let them control the data you have of them.
Lots of details, of course. It is legislation, after all.