We've already got users who fall under GDPR protection. Not as many as we will by the end of this year, but some.
And really, I've done all I can do. I've talked it up, given powerpoint presentations, and emailed a comprehensive report about penalties for failing to comply as well as a project outline for becoming compliant.