Seriously, why can't we just have a law that makes entirely illegal the retention of any personally identifiable information in any way that is legible to the retainer.
You can store my data for me, but only encrypted, and it can be decrypted only in a sandbox. And the output of the sandbox can be sent only back to me, the user. Decrypting the personal data for any other use is illegal. If an audit shows a failure here, the company loses 1% of revenue the first time, then 2%, then 4, etc.
And companies must offer to let you store all of your own data on your own cloud machine. You just have to open a port to them with some minimum guarantees of uptime, etc. They can read/write a subset of data. The schema must be open to the user.
Any systems that have been developed from personal user data (i.e. recommendation engines, trained models) must be destroyed. Same applies: if you're caught using a system that was trained in the past on aggregated data across multiple users, you face the same percentage fines.
The only folks who maybe get a pass are public healthcare companies for medical studies.
Fixed.
(But yeah it'll never happen because most of the techies are eager to screw over everyone else for their own gain. And they'll of course tell you it's to make the services better for you.)