It's sometimes easier to encrypt everything sensitive with a user-specific key and destroy the key.
That's how I've done it as well. The files are backed up for as long as we want, they are just useless once the user's secret is trashed. You can do the userid blocklist's on database restores etc. but for long term backup file storage it becomes silly.
I don't think the GDPR imposes a requirement to actively filter backups.
It's not a backup, it's the authoritative dataset.