There's probably nothing outright incriminating in those documents, rather that the political party or parties were using their subsidy money to pay for services rendered from companies owned by the party leadership – which is 100% legal, but not very pretty in the public eye.
I don't find it very surprising that they could and did use the GDPR "loophole" to close the public sector from public insight. Before GDPR there were very clear laws of transparency making sure that they could not deny giving out public documents. And if they did, they'd be taken to court and always loose. They would still try denying some public documents and threatening court would work against that.
With a data protection authority on their side, they finally got the law on their side, using tactics such as saying that there is a risk that these documents end up on an American server. While at the same time using Microsoft services and American servers themselves. Which is the subject of the OP article.
Appointing a crooked head of a data protection authority or any authority is easy and it is legal. Circumventing laws is not that easy. But it is easier when you have more laws that are more open for interpretation.
The right thing to do would have been to make transparency laws more powerful than GDPR laws, because it was obvious that they would be abused. Now the EU has GDPR laws enforced on a union-wide basis, but not wholesome transparency laws enforced on a union-wide basis.