I've not expressed any particular admiration towards PCI-DSS (and if you perceived any, I didn't mean to give that impression). Furthermore, the point of my post was certainly not to treat PII/Pseudo-PII like credit card numbers.
Payment card data is secret information, that's a given of the industry. If you disagree with that, I welcome you to share your credit cards in a reply here. Is it a design flaw? Yeah, you could say that; there's much better models and PSD2 will fix many things (not all) at the core of your complaints.
In the mean time, having to treat credit card numbers as highly sensitive is a fact of life, and when you're trying to protect users, you have to be pragmatic, you can't live in an ideal world with theoretical technology; you have to regulate what's there.
The GDPR's definition of PII is broad and contains many things which aren't secrets. I can tell you my full name, it's easy to figure it out from my profile, that's not a secret but it's still PII and GDPR asks that you treat it as such. Same for usernames, which are most often publicly visible on websites.
GDPR, more than dictating what you should encrypt, gives the users a set of rights over a class of data they share with companies in order to give (european) users more trust and comfort when choosing whether to share data with those companies. Things like "I should be able to know what a company has on me, and I should be able to download it and delete it".
I can't tell you the number of websites I've seen that don't let you delete accounts properly. That don't let you edit your real name (even if you get married or you legally change it!). That don't allow you any insight into where your email address ends up after you sign up with it. This is the problem that GDPR is trying to solve.