This plugin follows GDPR guidelines because it stores IP addresses to help identify and block harmful traffic, which is considered a legitimate interest under GDPR. There is no link between the stored IP addresses and personal details of visitors.
To align with GDPR, update your Privacy Policy to explain that you collect IP addresses for security, how long you keep them, and that visitors should be informed. You are not required to get visitor consent for this legitimate-interest security logging. See Article 6.f: https://gdpr-info.eu/art-6-gdpr/
There is nothing that connects the IP data to other identifiable information about your visitors.
Visitor Log retention (Pro): Under Firewall → Settings → Visitor Logging, the default is 7 days. You can choose 1, 3, 7, or 14 days. Old entries are pruned automatically.
To be fully GDPR compliant update your Privacy Policy with something like:
“We use firewall software to protect our website from malicious software and attacks. As part of this, visitor IP addresses may be logged for a limited period (by default up to 7 days on our firewall visitor log, configurable up to 14 days) to identify repeat suspicious behavior. This is in accordance with GDPR Article 6.f.”
Joining Forces Against Cyber Threats with Security Ninja Pro
By choosing Security Ninja Pro, your website can participate in a shared bad-IP network. When participating sites report blocked hack attempts, that intelligence helps other sites block those IPs earlier.
Privacy and Data Sharing in the Global Network
When an IP is reported to the network, the data is limited to the blocked IP, the reporting site, and the block reason. No personal profiles of visitors are built.
Sites can opt out of reporting blocked IPs to the central database if they prefer not to share that information.
More detail: Block IP network and non-sensitive diagnostic data.