I am surprised the EU haven't investigated Android and found it breaches GDPR requirements, simply due to the fact it's too easy to collect information that can later be used for analytical purposes without the users consent.
I imagine you can find instances of GDPR breaches in all modern OS' if you looked hard enough - something as simple as a HTTP POST request may be illegal depending on the payload.
Sadly, progress is often slow, but Apple's progress in this area will hopefully inspire Googlers like the one in this article to make statements and drive progress forward.