You could argue that it's not the comments themselves that are personally identifiable, but the association between comment and username (and IP etc). Following that argument, you could retain the comments as long as you delete the username and other identifying info.
Not sure if that would hold up, as some comments can be pretty identifying. But it's a compromise that a company could try.