Earlier quoted context omitted.
Complicated? Remove this “feature” to start: >all of which upload your personal data from the phones to their own servers without your knowledge or consent. Our default legal position shouldn’t be one of accommodating a corporation’s existing market-acquisition practices over people’s privacy.
Are you seriously proposing to ban uploading pictures that contain other people to third parties computers without consent? That would go way beyond Facebook. Would I need to track down everyone in a picture before annexing it to a Yahoo e-mail? I'd think the most pro-privacy reasonable approach would be to stop companies from identifying them beyond "someone who did not consent to being tracked".
For instance, it could still be legal for Facebook to slurp your friend's address book (and your profile, indirectly), but the regulation could require them to discard and purge that information if they can't immediately match it to an account.