Earlier quoted context omitted.
> Is the requirement to push that deletion to all other SSB instances? Well if you follow the GDPR: yes. Article 17.2 > Where the controller has made the personal data public and is obliged pursuant to paragraph 1 to erase the personal data, the controller, taking account of available technology and the cost of implementation, shall take reasonable steps, including technical measures, to inform controllers which are…
If the personal data is encrypted and you destroy the only key that can be used to decrypt it, is it still personal data? Or is it now simply some random bytes?
It comes down to the individual to interpret and enforce a solution that may or may not be in compliance.
It's like doing taxes in the US. You may or may not doing it correctly and you'll only find out if they start knocking.