That's largely correct but keep in mind that you're only looking to delete PII not the content created by the member unless it contains PII. In my view you need to treat it as a non-reversible action because that's the only way you can satisfy the regulations.So basically there's no legal way round avoiding complete account deletion in the Uk.
If I receive a request I verify that it is legitimate, give the member a grace period, ask them to identify the information they wish to be removed and ensure they understand that once I've removed their PII it is not reversible.
As I said earlier in the thread, if you carry out the request there should be no way back because there is no way for the member to verify their identity because you no longer hold that information.
One thing I will say is that in my experience almost everyone abandons their request once they realize it's non-reversible. I think it's also worth pointing out that while there maybe legitimate reasons for retaining PII, few of those reasons (as far as I am aware) have been put to the test and I don't want to be the person that sets the precedent because the penalties are harsh.