As a last resort, I am considering contacting the police and the GDPR authorities to request Microsoft to delete all my information and permanently delete the account to prevent any misuse of my data.
Won't matter. The attacker can make a copy of all the information in your Microsoft account (and certainly has by now).
Please consider this: The attacker knows everything about you that is in your Microsoft account. If your name and address is there, the attacker knows it. If your payment card information is there, the attacker has it. They have contact information for all the contacts stored in your Microsoft account.
Did you store passwords in Microsoft Edge? (I hope you didn't.) The attacker now knows those passwords. Was there any sensitive or confidential information in files you were storing in OneDrive? The attacker now knows it all. How about your Microsoft Authenticator app - the attacker can use it. You're getting the idea, right?
The attacker can do anything that you can do with the information in your Microsoft account. Nobody on the internet knows whether it's really you. If someone presents your name and your address to an online merchant, and pays with your credit card information, then as far as the merchant is concerned, you bought it.
When your contacts receive phishing email from your email account, which they have trusted for years, how can they know that it wasn't you who actually sent it?
Are you sure you want to regain control of that Microsoft account, now that it can be used against you - if it hasn't already? I think you should want to put as much distance between your hacked account and yourself as you can. Change those passwords. Cancel those card accounts. Get new email addresses and warn your contacts not to open any mail from your former address. Take action ASAP, so the information in your attacker's hands is worthless to them.