Earlier quoted context omitted.
Careless programmers can also mishandle health/credit card/minor information. We have laws protecting all of that data in particular. I'm not sure the expansion of data privacy laws to include all PII is so farfetched.
It's a slippery slope. Analysis of writing style, patterns of use, etc can deanonymize data to the point where basically everything becomes PII.
Where personal data and privacy is concerned, I'd rather err on the side of caution, than the world we live in now.