According to the GDPR the burden of proving compliance is on the controller by keeping paper trails and documentation. So technically they would already need to be able to prove were all data has come from, or else they can't have it. So either they start untangling or they delete it. :)