Earlier quoted context omitted.
How? Your bank stores personal data covered by gdpr but enabling crappy secure systems is not the domain of gdpr. Most likely this is caused by SCA another European directive that ruined our lives with extra security hoops (for payment providers) for little extra security - or even worse in case of voice password or security questions
A person's voice is, I believe, personal data. > Processing personal data is generally prohibited, unless it is expressly allowed by law, or the data subject has consented to the processing - https://gdpr-info.eu/issues/consent/
Given the same voice get processed and recorded during a normal phone call to the bank so you would need to give consent just to talk on the phone (and they do have a disclaimer when you are calling in Europe).
Most likely this is buried deep in some massive EULA you accept when you open an account.