wow! in Europe, this request 1. From address 2. To address 3. bcc addresses 4. cc addresses 5. Time 6. Date correlates person-related information (who was in contact with whom at which date and time). storing it, let alone processing it is only admissible on a need to know basis. even if you jump through the hoop of an officer acting on behalf of Seattle is not a person any more, which is a stretch already, even then…
So, email addresses kind of suffer from the same problem as Social Security numbers - they were never designed to be private information! But they have been forced to fit that role. And, you know, cities have no problem giving out personal information all of the time. Your personal address, or whoever owns property in a city, is a matter of public record. And so the city has no problem handing out your name and addre…
[EDIT: to be clear, the following refers to the GP comment referring to in Europe, where as the parent comment is clearly US-centric]
Even if you replaced every distinct e-mail address with an ID or hash or whatever, they would still fall foul of GDPR because that ID or hash would become PII. You might say that's impossible, but for instance, if you knew that you happened to send specific e-mails to people in that dataset, you could correlate the times to discover your own hash, then filter by your hash and use the times to correlate with who you sent them to. Now you know the hashes of everyone you corresponded with, and can do PII-based analysis on that, e.g. how many people e-mailed them and when, whether they responded, who else they e-mailed after receiving those e-mails (so you might be able to start identifying colleagues etc), etc.
PII, even in what looks to be anonymous data, is very valuable to people who are determined to mine it, which is why typically data such as this should only be disclosed in aggregate, and usually after verifying that each aggregated set of data actually covers a large enough group of individuals that also can't be correlated another way.