

Pretty sure that the gdpr specifically precludes forever retention. Data should be retained as long as is necessary and whether 1, 3, 5, 10 or however many years, sooner or later deletion is appropriate, and the timeline depends on what is reasonable.
3 years is a long time to not log in and if a court decided that it exceeded a ‘reasonable’ period for legitimate interest the fines can go to 10% of global revenue. The law encourages risk averse behaviour.
They could make a better system where the user sets the timeline but it would be impossible to predict the return.
On this one i think its probably driven by risk management not nefarious intent.

Not something i need imagination for. Im not saying 3 years is optimal, but there does have to be a threshold somewhere. Personally i’d build it into user settings to allow users to self select a time period they accept.