Yes. You should have a system for tracking every single dataset containing personal data: that data does not belong to you. You are just its steward.
You should have had such a system even before GDPR came into existence, but after it did? Your organization's lack of organization is not the legislator's problem.