While GP stated soft-deletes aren't allowed, I figured I'd contribute to this thought exercise.
What about symmetric encrypting the field(s) and then giving the customer the key, and tell them to print it or store it safely, or else they won't be able to recover? And then don't store the key or write it to disk (remove it from memory)