That's my take on it as well - GDPR is for the individual instances to deal with, as they're the ones who hold the data on their users and anything coming to them.
The software, of course, can have some design which purges data automatically or whatever, but ultimately the control is whoever is hosting Lemmy so no matter what Lemmy does, people can override it (though some sane defaults are always good, of course).