This is a clear violation of GDPR. The GDPR emphasizes the right to erasure (Article 17) and data minimization (Article 5). These principles require that personal data be:
* Kept for no longer than necessary * Deleted upon request or when no longer needed
Both of these conditions are met when someone "deletes" a picture from their device.
This bug basically proved that Apple is non compliant with this and there's no way that EU is going to ignore this big of a violation. If found guilty then they can fine Apple 20 million euros or 4% of global turnover(revenue) which is > $4 billion.