We've been doing a lot of thinking about how to support GDPR at Snowplow (Kafka and Kinesis but plenty of other logs and stores) - for our first phase we're just going to support irreversible pseudonymization of tagged PII:
https://github.com/snowplow/snowplow/issues/3472
For later phases, yes user-specific encryption of PII or hashing-with-lookup table are the way to go...