What a GDPR nightmare.
The only real problem is verifying the legitimacy of requests. How do you know for sure that an email containing a GDPR request came from the same person that also sent the comments? I guess you could come up with some rules. For example, if the request was signed with the same GPG key as the original comments or if a request passes DMARC...
I'm curious to hear what the author thinks of that!
Addendum: If you track your website's sources in a public VCS and include comments in there you probably have to run a "filter-branch" (or whatever your VCS has for that) over it to purge PII from the version history.
It does and can happen. Albeit, not often.