Actually GDPR is exactly what they're asking to. Possession of personal data that is not required for a service's functionality is illegal under GDPR.
But it has to be freely given. "Give permission or you can't use this service" is not ok for data that isn't required to provide the service.
If the purpose wasn't "we keep to resell it later" it's likely illegal.
Well, "illegal" given that this type of criminality is pretty much ignored (I've been fobbed off by the regulator after pointing a systematic law-breaking by a $company many many many times. Still better than not having this).