I imagine that's exactly what the business sector doesn't want to do.
I remember when Google and Microsoft changed their privacy policies 2-3 years ago to become much more generic and "unified" - as in they could now use your data however they found fit from across all of their services and products. Great piece of PR that "unified" trick, though, so props to the PR team, I suppose.
The tech media mostly treated it with a shrug even when there was something that sounded quite suspicious in there, and had a tone of "yeah, but that's probably just used for X, and it's unlikely Google/Microsoft will use it for other nefarious purposes. It's just for legal reasons, you see."
No, those provisions weren't put in there "just for legal reasons" and they were put in there on purpose because they were meant to be used. Also, if they put it in there "for legal reasons" it's also because they intend to use it and need the legal cover. It's weird how the media took out exactly the wrong message from it back then.
It also bares repeating, because the media didn't cover it much back then, and it was quite a sneaky thing for Google to do - Google changed its privacy policy to no longer keep your data "anonymized." Many people even on HN like to defend the companies' data collection "because they anonymize it", which in itself has always been a joke, as studies have proven, but they no longer even do that:
https://www.extremetech.com/internet/238093-google-quietly-c...