It's been interesting to read about the impact of GDPR on sites of all sizes and purposes. Let's say I have a site where people can write and share math problems. I have a simple policy stating that any problem that directly or indirectly harasses anyone or any group will be flagged and deleted, and that repeated behavior like this will lead to banning.
Say a user gets banned. They then ask me to remove all information about them from my site. Am I allowed to keep any information that would help me keep this person from starting this cycle all over again?
What impacts will GDPR, and other data retention policies like it, have on the issue of moderation?
You then clearly have a "business need" (banning troublesome members), that clearly allows handling and storage of data. Hence "right to be deleted" does not apply any more (or more correctly, it is overruled by a more specific right)...
I work with a bank. They have a general 3 or 6 month rule for "non customers" and "ex customers" (i.e. 3-6 months after you are not a customer anymore you will be deleted by normal retention).
If you are fraudulent, the retention interval is now 10 years! They have a full-time DPO who has spoken both to external legal council (he is a legal-trained person himself) and our local DPA.