Best guide I know is the UK's ICO guide - should give you the best starting point. Read the guide to data protection on the ICO site too - GDPR is only a minor update to the old data protection regs.
If you want to read the actual law it's in pretty plain language. Between the two that should be all you need.
https://ico.org.uk/for-organisations/guide-to-data-protectio...