The fact is political bodies have been empowered with increased enforcement discretion. They are motivated, as political bodies, by politics.
I watched the same thing happen, around 2012, in Frankfurt and Berlin with respect to Germany's regional banks. Weak and undercapitalized, in violation of EU rules, they were summarily ignored due to political necessity. The same tendencies will apply with GDPR. The lack of a requirement for politically-independent enforcement was a mistake.
The "political bodies" in this case are the National Data Protection Authorities. They are indendent, and their only politics is ensuring compliance with the data protection regulation, as required by the GDPR, Article 52 [0].
Furthermore, due to lack of evidence, your example is not conclusive as to show that regulatory bodies act for political reasons they were not supposed to pursue. Also, if one regulatory body broke the rules, that does not mean that others will do so, too.
However, I'd love to know the details of what bank was breaking what regulation and what authority was not acting according to their mission, if that is what you want to exemplify.