Neither @nutomic@lemmy.ml or I are too familiar with the GDPR, so we don't know everything that it requires. Lemmy doesn't do any logging of IPs or other sensitive info, but of course instance runners could be doing their own logging / metrics via their webservers.
We have a Legal section under admin settings, that's an optional markdown field, that can probably be used for it. We'd need someone with GDPR expertise though to help put things together. Lemmy is international software, not european-specific, so we have to keep that in mind when supporting GDPR.