From a GDPR perspective, it also covers logs, internal training data etc. If a user requires to be deleted, you have to delete everything, there can be no trace of their existence.
False. Transaction data must be kept for legal reasons and deletion requests do not apply to it.
But logs don't count as the transactional data that needs to be kept for legal reasons.
Addresses are sensitive information and whatever was happening sounds like multi-purpose-consent-necessary data processing and it was years old.