GDPR, the European privacy rules, go into effect in May. What should associations and non-profits do first?