Doesn’t that only apply to Europe? Doesn’t seem to protect Americans at all.
It is sufficient to delete or anonymize identifying information. For instance, in the case of discord, it is possible to delete only the account information without deleting the chat themselves to comply with GDPR. You can still see the chat messages for the account id 123456789, but you shouldn't be able to associate this account id with an email or other personal information.
Even if they "Anonymize" the data? I don't really know all the specifics of GDPR. Do they currently offer people in EU a way to download/review/delete (for real) all their data?
It's really hard to figure if a text message contains PII or not, so they would have to anonymize everything, meaning transform the text message into random garbage. At that point the only thing that remains is the metadata about timestamps.
I haven't checked whether they're complying or not, but as an European citizen it is my legal right to download all my personal data hosted by them, and to have them migrate it for me to one of their competitors.
I don't think you could anonymize chat messages with any level of confidence. Not an expert in this but my team generally has to treat free-text fields at the highest level of data classification because they could contain anything. The best you could do is try to mask obvious PII like phone number patterns but that's definitely not sufficient.