I've noticed one particular app on my phone is using information that I didn't give it, or give consent for storage. I queried this with the privacy team of the app provider, and they came back saying that they don't store the information, it is held locally on the phone, and they have no access to it because of encryption.
But their app is visibly using this information.
Does GDPR apply to this scenario, where the info is stored locally on the phone, encrypted?
I guess a similar scenario would be WhatsApp messages held on a phone, which WhatsApp don't actually have access to.