You still have to backup those keys somewhere... and if you don't do it the same way as for the data then your backups are effectively worthless.
You've also added (possibly substantial) latency to every single operation that operates on user data.
Yes you would need to carefully design the system that allows deletion of keys while minimizing chances of data loss, but it can be done, and it's going to be cheaper and less complex to do so on a tiny subset of the data.
Latency considerations are also down to design, it's not a given that there will be significant overhead imposed.