Even if you sanitize/delete the account holder record, you can’t delete the transactions themselves (as it would screw up your accounting) nor the merchant association.
Now let’s say you have a very particular customer that always goes to a very specific restaurant at pretty much the same time every day consistently.
That pattern alone is enough to single out that particular person (and deanonymize them by correlating with other records such as cell phone location data, etc).
Wherever possible a business should delete relational data upon request. However, relational data is special because it cannot be effectively deleted by overriding user data with random values as Confluence seems to do.
Even if banks were allowed to delete customer data, they would face the same problem as social or booking services in that their relational data must be truly 'removed' rather than just overridden.
If you understand the GDPR exclusively based on legal precedent, you'd probably conclude the GDPR doesn't exist.