Government: "You know that data you were required to delete when $(USER) requested to be forgotten? We require you to provide it in connection with our ongoing investigation of $(USER)."
Is this a real issue though? If I comply to regulations to remove data as required by law, I'd be surprised if a government body could require me to provide data I am supposed to have deleted.
And on the subject of backups, those are typically exempt but there are some obvious problems there when you restore a backup at a later time.
To me the big ticket items in the GDPR are the notification duty and the data processing agreement 'chain' that gives some level of certainty that the companies you deal with are going to take this serious.
The implementation details and all the moving bits and pieces are most likely not going to be the parts where the real tests will be in the first year or two.