That seems like a GDPR violation waiting to happen. It shouldn't be possible for them to store an email address like that forever and be in compliance.
This can be implemented without storing it. They could store a hash. No idea what they actually do.
GDPR says you are not allowed to store my data just because. If you have a good enough reason, everything is allowed.
If user [email protected] violates our ToS and I suspend them, I can keep that email address forever to keep them from signing up again. They can’t just say “GDPR! You have to forget me, tee-hee!”