The GDPR replaces the right to be forgotten with the right to erasure.
But article 17 also gives the following grounds for refusal:
Paragraphs 1 and 2 shall not apply to the extent that processing is necessary:
1) for exercising the right of freedom of expression and information;
2) for compliance with a legal obligation which requires processing by Union or Member State law to which the controller is subject or for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;
3) for reasons of public interest in the area of public health in accordance with points (h) and (i) of Article 9(2) as well as Article 9(3);
4) for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in accordance with Article 89(1) in so far as the right referred to in paragraph 1 is likely to render impossible or seriously impair the achievement of the objectives of that processing; or
5) for the establishment, exercise or defence of legal claims.
The first example is effectively a carte blanche to argue nearly any request for refusal in court.
The second one allows member states to pretty much tell companies not to delete information, whilst this was set up with compliance in mind, the wording has likely been formatted to also fit other needs such as security and state monitoring.
The third one pretty much allows you to keep medical records and insurance information.
The forth one is similar to the first with celebrities, public figures and major events in mind (the Gawker clause).
The fifth one has been singled out by dating sites and other services such as ride sharing apps as the reason for them to keep data.
I am not a lawyer this isn't a legal advice, speak to a legal firm or an auditor for proper advice.
I have been working on a few GDPR compliance projects internally for the past year and I've had to speak with quite a few lawyers and they all pretty much said it's actually far better for most companies than the existing framework as long as they can automate data discovery and know where they data comes from and where does it go.
You can fight the right to erase the data of a user pretty easily, what you cannot cockup (Art. 15, 20 and 21 of the GDPR primarily) is the ability to disclose what data you have on them and what is it used for which is like I've previously stated the tricky part for most cases.
And as far as I can see Tinder pretty aced the tricky part.