~
Trezor did this one wrong, there is no need to keep data after a successful delivery of their devices, once the delivery is successful they should just wipe the data, this is also a way of keep decentralisation functional.
A third-party shipping provider was actually responsible for the leak, not the manufacturer itself. So I would not put the blame entirely on the Trezor. And yes, they may have handled it better and may very well do so next time - but that is not a guarantee that a situation like this wont happen again.
I wouldn't expect much from a third party shipping provider in regard of data keeping, their system most of the time are sloppily created.
The 90 day data retention policy is from Trezor's own intiative as far as I know, if the retention period were shorter, maybe they could've negotiated for an even shorter data retention from their shipping partner as well.
The GDPR law itself only tell companies to keep data no longer than necessary, 90 days is pretty long time for a shipping log, they could've made it shorter especially since this breach covers EU customer which is very close to where the hardware shipped from.
They are currently working on anonymous delivery option but honestly, I would've expected them to create such thing from a long time ago.
Trezor manufactured hardware wallet, but their business is also very close to their customer's privacy which should make them self conscious to trim on all those logs and retention policy.