There is a diference between e2ee and just encryption. Article32 seems to only be requiring encryption at rest (and maybe transit) but not e2ee.
https://gdprhub.eu/index.php?title=IMY_(Sweden)_-_DI-2021-43...
> Sending an e-mail containing sensitive data with enforced TLS-encryption instead of end-to-end encryption was deemed insufficient secured under Article 32(1) GDPR.