Short answer
HubSpot's API docs: gdpr-delete permanently deletes a contact and associated content to follow GDPR. Set idProperty to email to identify the contact by email. Permanent and GDPR deletions are not held in the restore tool.
1. Privacy settings
Data privacy settings in my demo portal.

2. The request
POST https://api.hubapi.com/crm/v3/objects/contacts/gdpr-delete
{ "objectId": "user@example.com", "idProperty": "email" }
3. Related
GDPR settings and bulk delete.