The thing that really gets me about this one is that surely you can easily just delete the data after you've verified someone? But instead they decided to keep 153,347,439 of them.
I believe we need to criminalize possession of the data, with statutory damages per violation.
This means the police don't get involved. The only thing you need is a tort lawyer willing to take a share of the damages. Also, a data breach is proof that you possessed the data.
A business wouldn't be able to reduce their liability exposure to zero, but to an acceptably low level, for instance by actively erasing the data before a breach can occur.