And with application layer DDoS attacks and intrusions: surrender? Do not ban bad actors? Or outsource to Cloudflare that keeps an army of EU lawyers and is compliant?
Nah, that's a legitimate interest (the example given in Recital 47 is preventing fraud, which is similar). You can process it as long as you only use it for that purpose and delete it as soon as possible.