This question is becoming critical right now, as nonrecoverable deletes are required within 30 days for both GDPR and CCPA.
Most products do the asynchronous rewrite, especially if they're based on immutable storage. That's fine, but it should be tested to verify that it's not triggering on every delete, for example, and that it's resource-efficient.