I can see the purpose of "right to be forgotten", but I think in some circumstances it is going to be abused. Any service that "bans" users for fraudulent/abusive activity and stores data about the banned user to prevent them from creating new accounts is going to have a problem. Banned user can just request to be forgotten and then create a new account. Unless there is some exception within GDPR that will support this use case.
https://gdpr-info.eu/art-17-gdpr/
You're allowed to ignore deletion rules for the purposes of:
3 Paragraphs 1 and 2 [the rights to be forgotten] shall not apply to the extent that processing is necessary:
(e) for the establishment, exercise or defence of legal claims.
What about symmetric encrypting the field(s) and then giving the customer the key, and tell them to print it or store it safely, or else they won't be able to recover? And then don't store the key or write it to disk (remove it from memory)
- have a legally trained person review your eventual solution and your reasoning behind it
- document the exceptions, which laws and which datums it covers
- keep track of the law as it changes, especially with new bodies of law such as the GDPR you can expect updates to reflect the situation on the ground and in a way the GDPR itself is such a change.
- be prepared to review the situation/code if the law changes in the future
- be aware that 'data retention' laws are very different from one industry to another (for instance telecommunications is a totally different beast than e-commerce)
Compliance with tax & financial regulations counts as a "legal ground". But that doesn't mean companies can retain all of the email history.
This can get quite complicated, moreso if a company deals with both consumers and companies as customers.