GDPR says you must delete information about the customer; but there are cases where you still might need to have that data available.
If your customer can interact with another one inside your app/platform, he/she can commit a crime, and you might be required by court (and by law) to disclose some information (even conversations! inside the platform).
Setting something to "deleted" might not be the best way to do the actual soft delete.
Sometimes you can "delete" that user moving it to a separate part of an LDAP branch (where nobody except someone with authority can access).
In other cases, you can add the "deleted" flag on the table. If so, MAKE SURE your app access the data from a view of the table where the 'deleted' users are not present. Even better: partition the underlying table based on the "deleted" field to physically separate active and deleted users.
But whatever you do, ask your Data Protection Officer first.