(More than just Cassandra tho, many databases don't actually "delete", at least not immediately. They "mark for deletion", and may or may not _actually ever delete_ anything.)
The database not actually deleting is still the application properly deleting it. If the DB eventually carries that out or not is a lesser concern to me, tbh.
The concern here is that facebook doesn't actually tombstone their entries or doesn't even have their DB mark it deleted.
I am sure they aren't purging backups of the data.
What if hacker deletes your Facebook account? Under GDPR Facebook has actually obligation to keep your data safe from this scenario. Which means they have to keep logs to investigate what happened and also be able to restore your data.
You should delete backups after certain amount of time and state your policy to users.
You can't keep indefinite backups and comply with GDPR.
So if your 5 year old backup, which has no purpose at all, gets stolen, expect a whopping fine for being an idiot. Or your web logs get stolen and it turns out you keep them 2 years, don't expect favourable treatment as that's totally unnecessary data retention.
I'd happily put down $50 for whoever spilled the beans on what is really going on at Facebook and other companies in that vein.