is the use of ssh keys GDPR compliant in every EU country?

Hi all,
by law in Italy almost every kind of system access must be protected by a physical device or username/password or similar credential.
As far as I know, even securing private key with “passphrase”, that secret can’t be enforced nor automatically expired as specifically required by italian law
(https://www.garanteprivacy.it/web/guest/home/docweb/-/docweb-display/docweb/4129029)
because it’s just written in key.

Am I wrong on something? how is in your country?

Grazie
Fabrizio