GDPR should help but if the apps were hosted on a developer account registered to a business entity, the majority of data will relate to the business rather than the individual, in which case GDPR may not throw up a huge amount. I don't believe the automated decision making parts of GDPR apply to businesses either.
In the UK at least, if it wasn't a registered business (limited company) then there is no legal distinction between you and the trading name and hence all the rights under GDPR would be available to you.
Several of my bank apps will send me push notifications when a payment requires 2fa so I can authorise in app, a much better process than the SMS based 2fa most do.
Whilst that's the maximum permissible sentence in Norway it's worth highlighting that it can be extended indefinitely if he is considered still a risk to society - the requirement to review the need to continue detaining him (on a semi frequent basis) being considered a human right.
Based on his activity since being convicted I doubt he'll be released for significantly longer than his minimum sentence.
In the UK at least, if it wasn't a registered business (limited company) then there is no legal distinction between you and the trading name and hence all the rights under GDPR would be available to you.