All this "my final determination" and "your other surprise account" nonsense could be rectified pretty quickly with a GDPR banhammer. I am increasingly of the opinion that personal info of any kind should be legally radioactive, and very high-risk for companies to hold onto or collect.
I agree. I am the author of a [very mild] social media app, that Serves an extremely tinfoil demographic.
The #1 posture is that if we don't actually need the information for the application to run, we don't take it.
I won't go into detail about how we do what we do, but we don't keep any data, other than the email the user chooses to send us (which can be a DEA or proxied one). We also never export that email outside the server. No marketing aggregations, no trend analysis, etc. The email stays inside the deployed server.
This stance has not made me popular with my coworkers, but it has made our app quite popular with end-users.