Yes, and? What about all of the data that is kept not owing to legal/regulatory requirements? That's the key issue here, not some trite truism about regulatory record-keeping requirements.
All data they process are required by law, but they have to collate a dozen systems manually and the legal department has to go thru everything and block out data the customer is not allowed to see (also by law)...
No all companies are evil and the GDPR has really made a significant change all the places I know of.
Perhaps the corporations could also consider whether they want to be an information hog in the first place and slurp up people's data.
You know what the easiest way to fulfill a data request is? To not have any data to give.