>
with Reddit really not understanding their legal requirements before shooting that response backI think you and the author misunderstand gdpr and ccpa.
Severing the link between username and post is not at all obviously noncompliant with GDPR and CCPA. So simply making the username equal to "[deleted]" is likely compliant.
1 - anonymity is a valid method here -- once you cannot link a post with a person, it's colorably no longer "personal data", which is defined as data related to an *identifiable* person.
2 - in GDPR art 17, there are multiple reasons Reddit could avoid deleting. Note that the right of deletion only covers personal data, and has multiple exceptions, including (art 6) legitimate interests of others, which could cover the other people in threads reading and responding to messages.
Even if you believe that none of the above suffice, enforcement lies in going through a country-specific DPA in Europe. Either the one Reddit has established as their primary DPA, or a user's country-specific DPA. From then, the (heavily overloaded) DPA would have to prioritize this for enforcement action (which I strongly suspect they wouldn't) and agree with the complainant's position (which I also am not sure they would.) Even if all that happened, Reddit could appeal.
But I strongly suspect that the DPA would not take action and find anonymization good enough, particularly since Reddit is intended to be public. The DPAs are generally expending their resources on the most egregious violators and/or their naughty list of Google / Facebook.
As for CPRA, it also has multiple exceptions for deletion [1], including anonymization (by rending a post no longer personal information); as well as (d)(4) right of free speech, etc.
A similar enforcement overload analysis will likely apply to the CA Privacy Protection Agency as DPAs.
[1] https://www.caprivacy.org/cpra-text/#section5