Hello,
Yes you are right, but actually it’s most on the Mautic side than on the WordPress extension.
An article was published recently about the future of Mautic and the GDPR compliance. I’m not aware of any roadmap (but I’m very busy now so I don’t follow all the discussions on the slack channels…).
For the moment, if someone asks you to forget its data, you must drop all it’s details from your Mautic instance. Also if someone requests its own data, you must extract them manually.
Behind all of these, having a Mautic instance is actually a first step to a better compliance because data are centralized and you are controlling everything around it. For sure you must be very paranoiac about backups to avoid leaks…
Also this extension isn’t storing or reading user data, it only simplify the mautic integration.
But this discussion is very important, if you have idea about the GDPR implementation or something that can be done on the WordPress side, I’ll be glad to hear it !
Thanks
Stéphane