Earlier quoted context omitted.
I have a similar reaction from folks when I don't trust services/devices. Most telling moment was when I refused to upload my license to LinkedIn because I lost 2FA (token on phone, phone destroyed). Microsoft assured me they would "delete the license as soon as it was verified". I've written too many software systems for too many companies, and I do not believe them . Of course, they'd outsourced to AU10TIX, which d…
When are the victims going to start getting significantly compensated for these breaches? They will keep happening as long as the consequences are just the cost of doing business.
There is obviously a fine that could bankrupt the company: this would be a clear signal "do not do this".
There are also many cases where people have been doing everything they should have been, and still got hacked (zero days, for instance).
Now, I do not think people should only be slapped on the wrist in that case: it still needs to be significant so companies carefully decide to store only the data they really do need!