Earlier quoted context omitted.
First, intentionally leaking this type of data is extremely illegal under Europe's strict privacy laws. So we are limited to unintentional breaches of privacy which can be guarded against with auditing requirements. Second, you have to look at the potential damage such a leak would have on the affected porn watchers. Is it really that damaging to your reputation if someone could prove that you visited Pornhub in the…
> First, intentionally leaking this type of data is extremely illegal under Europe's strict privacy laws. So we are limited to unintentional breaches of privacy which can be guarded against with auditing requirements You already know this, I’m certain, but laws and “audits” do little more than nothing to meaningfully protect data.
Personally I worked for a FAANG company that took data protection quite seriously. I would love to say that it was because they cared so much about their customer's privacy (which was of course the official position) but I think the reality was at least partially that the people in charge knew that if data was leaked and it could be pinned on lax internal policies, the company would be liable for millions if not billions in damages.
From that I conclude that the legal framework does provide a certain degree of protection to customer data. Nothing is perfect, of course, but that's true for every law: a red traffic light doesn't force drivers to stop, and in fact people run red lights every day. But the threat of getting fined for running a red light is pretty effective at forcing most people to stop for a red light most of the time, which is not nothing.
Also consider the logical conclusion of your cynical argument. If the laws and regulations that require companies to guard their customers privacy are almost entirely ineffective, as you claim, then shouldn't we abolish them? After all, they impose a burden on companies, which makes goods and services more expensive for consumers, without providing any non-material benefits in return.