Given it seems to be hosted by Automattic/Wordpress.com I would imagine he has auto domain renewal on (terms state on by default unless you turn it off).
However the domain registration terms also state (found at
https://wordpress.com/automattic-domain-name-registration-agreement/)18. Right to Suspend or Disable. We shall have the right, at our sole discretion and without liability to you, to suspend or cancel your domain name, or to restrict or suspend your account and/or ability to register domain names, in but not limited to, the following circumstances:
...
If you use a domain name for unlawful purposes or in furtherance of illegal activities.
...
When required by law, government rules, court orders, or legal process.
The hosting terms also have similar clauses as below (found at
https://wordpress.com/tos/)6. General Representation and Warranty
You represent and warrant that your use of our Services:
...
Will comply with all applicable laws and regulations (including, without limitation, all applicable laws regarding online conduct and acceptable content, privacy, data protection,.....
...
Will not use the Services for any unlawful purposes, to publish illegal content, or in furtherance of illegal activities;
....
Will not disclose sensitive personal information of others;
There is also the user guidelines which state (found at
https://wordpress.com/support/user-guidelines/)To be transparent about what is and isn’t allowed on your site, we’ve put together this set of guidelines. The following activity/material isn’t allowed on WordPress.com.
Illegal content and conduct.
Self-explanatory.
...
Posting private information.
Don’t share someone’s personal information without their consent. This includes collecting sensitive information in Contact Forms such as account passwords and credit card numbers, to name a couple.
In all of the above the underlying theme is that the site does not comply with GDPR laws (irrespective of where it is hosted - GDPR applies worldwide if you cater to European citizens (although I’m waiting to see how they regulators enforce based on this) and it also applies if a site is hosted elsewhere but controlled from a European country). Throughout all the terms and guidelines of Automattic/Wordpress.com It is clear you must comply with the law.
Perhaps if someone wanted to contact Automattic and report the site pointing this out it may get suspended. Automattics reporting page is found at
https://wordpress.com/support/report-blogs/