Fraud and AML say keep it for years, privacy says delete it. How do you build a system that satisfies both?
Treat the two obligations as different purposes over different columns rather than a fight over one table. Keep the narrow set you are compelled to retain in a restricted, purpose-locked store the product cannot read, delete everything else on schedule, and make your compliance function name the retained fields.