is the use of ssh keys GDPR compliant in every EU country?

Hi all,
by law in Italy almost every kind of system access must be protected by a physical device or username/password or similar credential.
As far as I know, even securing private key with “passphrase”, that secret can’t be enforced nor automatically expired as specifically required by italian law
because it’s just written in key.

Am I wrong on something? how is in your country?
