If you have paid for digital goods with an account, the data is clearly required! Deleting an inactive account after say a year is a choice made by the company, not directly imposed by GDPR.
It's trying to establish principles of good personal data governance, rather than being prescriptive about all uses of data.
This does make it hard for legal teams to determine compliance I guess. But don't expect the EU to be more definite any time soon!
Here is one of the provisions of interest:
https://gdpr-info.eu/art-5-gdpr/
Ubisoft also cites GDPR provisions for deletion of inactive accounts:
https://www.gamepressure.com/newsroom/ubisoft-removes-player...
They could equally well have said that an account which was inactive for 2 years, or 3 years would be deleted and still be legally compliant.
If you have regulators breathing down your neck being conservative on time isn’t a terrible idea.
Malicious compliance. They deliberately misinterpret and continue to get pulled up on it. For example, just recently: https://www.bbc.co.uk/news/technology-63784393
This completely contradicts any argument that their interpretation of privacy regulation is remotely compliant. They cross the line in their favour relentlessly.