Disclaimer: I don't speak for Google and don't have any real context into why this occurred. Speaking as myself, a private citizen. I work in Spam & Abuse and it's possible that this is the result of some clustering algorithm that was trying to take down sharders / phone buying rings. It's very possible that the SWEs responsible didn't consider this possibility (that legitimate customers would be used to shard purcha…
It might be a very very good idea to lobby to get company policy instated that says "if the system thinks a user has gone rogue/bad, their account gets locked and all, but the data gets kept around until the user says to kill it, or for 6 months."
Because if Google thinks the account has gone bad, that's not the user saying "delete me," so the privacy policy (and associated laws) don't apply! There's nothing stopping you even stashing the data away indefinitely until the user explicitly asks for it to be killed (but that's scary).
At the end of the day though, algorithms fail, and IMO this is a practical edge-case policy glitch in the business architecture that should have been countered for.
Or does "user account gone rogue" have to be interpreted as "delete me" for crazy obscure Reasons™?