It's not rocket science - encrypt with a one time symmetric key, encrypt the key with a public key, store blob and key marked as deleted. Store the corresponding private asymmetric key on a hardware token to be used when you decide you need the deleted data. That way no db hack exposes any usable data.