However they sold access to the data to a bug pharma company (GSK). This was widely publicized. Not sure if that counts: GSK had some ability to look at the data but didn’t have an on premise copy of it.
Also, I worked on the GDPR deletion project. I can attest that they do best effort to delete your data when your request that. At least when I was there, this was the case. One caveat is for coding errors, oversights and bugs.