The GDPR argument actually cuts the other way. GDPR protects your personal data from third parties — it is not a basis for withholding your own data from you, the data subject. Quite the opposite:
Art. 15 gives you a right of access to your personal data,
Art. 20 gives you the right to receive it "in a structured, commonly used and machine-readable format".
If they classify the consumption data as personal enough to hide it, they've conceded it's your personal data — and those two articles attach to it automatically.
And your car example is the sharpest point in this thread: the key is fixed for the meter's lifetime, so refusing it to the current resident protects nobody — the previous key holder keeps access forever anyway. That's exactly why Kamstrup's "Change ownership of encryption keys" process exists: the correct answer to the move-out scenario is a key-ownership handover, not a blanket refusal to everyone.
Practical next step: send a written request citing GDPR Art. 15 + Art. 20, asking for (a) your consumption data in a machine-readable format, and (b) the specific legal basis for refusing the data subject access to his own data — "GDPR" as a one-word answer doesn't meet their obligation to justify a refusal. If they stonewall, that's what your national data protection authority is for.