If you're curious about the future of privacy, while flawed in some ways, the GDPR (General Data Protection Regulation) comes into effect in the EU next May. Here's their definition of personal data [1]:
"Personal data means data relating to a living individual who is or can be identified either from the data or from the data in conjunction with other information that is in, or is likely to come into, the possession of the data controller. This can be a very wide definition depending on the circumstances."
And then we have this:
"Right to change or remove your details
If you discover that a data controller has details about you that are not factually correct, you can ask them to change or, in some cases, remove these details.
Similarly, if you feel that the organisation or person does not have a valid reason for holding your personal details or that they have taken these details in an unfair way, you can ask them to change or remove these details.
In both cases, you can write to the organisation or person, explaining your concerns or outlining which details are incorrect. Within 40 days, the organisation must do as you ask or explain why they will not do so."
It's true that enforcement is difficult -- I imagine it'll be more reactive than proactive. That said, a breach is handled quite well, assuming the law
is enforced:
https://www.dataprotection.ie/docs/Data-Security-Breach-Code...
The GDPR is a solid step in the right direction, and a model for a better approach to privacy.
[1] https://www.dataprotection.ie/docs/A-guide-to-your-rights-Pl...