The UI doesn't say "delete", it says "remove". Remove could mean "hide from view" or it could mean "delete the underlying database entry". It's a bit of grey area where it could be argued that users have consented to by using Facebook.
Granted GDPR is supposed to catch businesses that pull those kind of stunts, you have to remember that Facebook do already break GDPR in number of public ways too. So it's pretty clear they have a relatively open interpretation of the regulations (and an army of lawyers who are confident they can proceed in such a way). Or it might just be the case that even the worst fine issued by the GDPR is worth the risk given the financial benefits awarded to Facebook for retaining data.