Earlier quoted context omitted.
The correct way is to follow what all other engineering and trade (medicine/law) already follow. Some software engineers are licensed. A company must hire these software engineers, and any changes to what data is saved or how is saved must be signed by these engineers. If a breach occurs, an investigation occurs and if these licensed software engineers are found to be negligent, they lose their license. If they are f…
I actually agree with you but this is a dangerous opinion to express on this forum, where move fast and break things is seen as the one true path.
It's not surprising. But what should not be surprising is that sooner or later, software engineering will be regulated [1]. The question is simply whether software engineers will let politicians do it to them in an unreasonable way, or whether they do it themselves in a more reasonable way.
[1] Well, it has already begun. EU has the notion of the GDPR Data Protection Officer [1] https://www.gdpreu.org/the-regulation/key-concepts/data-prot...