Actually, to comply with GDPR, they have to (for people affected by GDPR).
What if hacker deletes your Facebook account? Under GDPR Facebook has actually obligation to keep your data safe from this scenario. Which means they have to keep logs to investigate what happened and also be able to restore your data.
You should delete backups after certain amount of time and state your policy to users.
You can't keep indefinite backups and comply with GDPR.
So if your 5 year old backup, which has no purpose at all, gets stolen, expect a whopping fine for being an idiot. Or your web logs get stolen and it turns out you keep them 2 years, don't expect favourable treatment as that's totally unnecessary data retention.