They're claiming to be GDPR compliant while in fact not even the European Commission believes that. The attempts to tape over this legally are a cheap way of hiding the fact, and it only "works" because everybody in power wants this to magically be compliant when actually it simply isn't.
https://eliatra.com/blog/the-sovereignty-illusion-why-awss-european-cloud-cannot-escape-us/
Since US companies are bound by US law, even *if* it were to "also" be "GDPR compliant" does not mean that they don't have full access, and are harvesting the data for their (US) national purposes. I personally remember a large university project that was involved in improving bulk image scanning across AWS, in the early 2000s. See also Snowden leaks etc. They're not relying on data security, but on looking away and pretending.