> I can almost guarantee that what happened was something unintentional
It's unintentional on paper because nobody is stupid enough to put in writing that they intentionally make the ban mechanism very trigger-happy in order to collect more personal information.
On the other hand, it works in their favor, so there will not be any attempts at fixing this trigger-happiness either.
> The number of privacy reviews to add a data collection around bans
The number of privacy reviews to add a data collection around bans would be astronomical
Just like the privacy reviews that ultimately get them to continuously do things that are in breach of the GDPR and that even a layman with no specific legal/tech knowledge would consider creepy/unethical/illegal?
> I would feel bad for that engineer
That's the thing, there is no single engineer working on this. There is no ticket "increase the amount of personal information given by people" - as per my first point it would be a huge liability to put something like this in writing.
However, one engineer working on the ban system might have its KPIs tied to the amount of "bad" people blocked, where "bad" can be deemed as someone who got challenged and didn't subsequently complete or pass the additional verification (the thinking is that a legit user would have nothing to hide and complete the verification, and indeed many do). This effectively encourages ban trigger-happyness and indirectly increases data collection while being completely deniable.
Remember that these companies are not stupid/incompetent - there's lots of money at stake to get this "right" (in their own way - aka beneficial to their business model). They just have to pretend to be stupid/incompetent in order to get plausible deniability and deflect eventual litigation/regulation.