My favorite approach is encrypting all of a user’s data (everywhere) and just deleting the key from a central store instead of actually erasing.
This is actually the reason some companies do not delete users/accounts [0].
Broken encryption, 20 years better machines in future and quantum are solved with same trick. We have event sourcing.
Implement best current encryption, delete everything except event store, decrypt events with old encryption publish events and everything in now encrypted with best current encryption events in new store. Delete deprecated old event store. Skip aggregates with deleted old key.