Well, I guess the truth is, personal data of EU and US citizens is sent in secret to european agencies all the time. Such institutions are all exempt from GDPR.
EU and member state institutions and agencies are not universally exempt.
There are some specific justifications that are scoped to government use only, in areas such as law enforcement or collection of statistics. But agencies still need to implement the law, document the specific requirements for any type of data they collect, observe time limits on retention, produce transparency reports, and so on.
We can't trust the intelligence agencies in the U.S., China, Russia, Australia, or Britain but of course the EU's agencies are trustworthy. After all, everyone knows there's nothing more effective than a European court and nobody more honest than European bureaucrats.
this is all an estimate. it's comprised of trading (to and from exchanges), sure, but also mining rewards, etc. there are some orgs analyzing the data, e.g. www.chainalysis.com