As a consumer, if I request deletion of my data, I expect it to be actually deleted - not just have a "deleted" flag set.
With soft-deletion, the data is still right there, ready to be abused after a breach.