Earlier quoted context omitted.
So peoples PII should be just sitting there unregulated because companies can't afford to clean up their privacy messes?
You are asking a question as if this was some sort of moral issue, and that's pretty much guaranteed to lead to terrible decisions -- ultimately immoral decisions -- so my advice is to not approach technical problems through a moralistic lense, but through a technical lense. The situation we have now is that massive amounts of code and business processes that were created without the assumption that things like email…
Especially taking into account that there might not be a linear relationship between the damage accrued by society versus the costs of the company to ameliorate such damage.