As said, it's really not that hard.
It’s not about protecting all data. It’s about protecting personal data.
“which is any piece of information that relates to an identifiable person.”
And then if they do e2e encryption where the EU can’t get to it, that runs afoul of another proposed EU regulation.
https://www.politico.eu/article/eu-commission-violation-priv...
A very important aspect of GDPR is a consideration for the purpose of the processing of data. If your company is providing an international messaging service in order to harvest sensitive personal data from private messages, then yes that is very much illegal. But if the purpose is simply to provide a messaging service and you are taking the appropriate steps to secure the data of your users, then it is not illegal.
It’s the perfect user experience!