This does nothing to protect against a bad cron job script. The web frontend, and even backend, are not linked to background maintenance tasks.
And a field in a DB doesn't prevent a manual DB delete, or api call to a backing store.
The real problem here, was a lack of backup testing / restore testing.
If you have backups, you MUST manually verify they can be restored, in a desired state.
And this means restores MUST be tested every time code changes happen, which effect backups.
Now for those who decided that a blockchain is the perfect solution for storing personal data however...
But you might have a hard time chasing down every copy, it's a distributed system by design.
The example I’m aware of is where personal information is held due to ‘legitimate interest’ and the request to delete isn’t deemed (however that is defined) to override that.
I won’t try to go further as it’s not 100% clear cut and IANAL.
Have a look at the legislation or the various explainers that have been posted online if you’re interested.
Edit: In this case I would guess that Canon would have trouble claiming a legitimate interest in keeping hold of your photos!