A clone and remove/update per GDPR request seems like undue delay, certainly one that could be avoided by alternative architecture choices (keep the personally identifiable information (PII) in a mutable store)
> Under Article 12.3 of the GDPR, you have 30 days to provide information on the action your organization will decide to take on a legitimate erasure request. This timeframe can be extended up to 60 days depending on the complexity of the request.
even if they ask for more time, first communication has to come within 30 days
It looks pretty straightforward English to me.
GDPR is published in 24 languages, including English, I don't know why people still don't get it and what's so hard to understand.
It's not a single law, it's a collection of articles, the 17th says that data should be erased without undue delay.
We don't have common law in Europe, EU is mostly civil law (emphasis on civil) or Romano-Germanic law. The only exception is Scandinavian law, which is very similar to (and a subgroup of) civil law anyway.