Provide option to delete email addresses after unsubscribing from notifications
When unsubscribing from the notification service, the email addresses are still stored in the database. When you're going to re-subscribe, the email tells you that you already verififed the email address.
To comply with data minimization, an option should be given for record should be completely deleted when unsubscribing.

-
M commented
I just tested it again and it does not seem to be the case. I am talking about the notification service, not the opt-out service. Even if you completely removed your email address using the opt-out service and unsubscribed from the notification service, your email address is still stored as you get an email saying "Welcome (again) to Have I Been Pwned" when you re-subscribe to the notification service. That means that the email address is still stored anywhere.