Typically most users don't get delete rights on the groups in order to avoid that they delete a group and with that all objects that are contained in it.
However, when any user creates a new group, this user gets full access rights on this group. Meaning that customer's administrators have to regularly go through the groups to adjust the access rights or have to invest in development of a report to adjust the access rights.