Alrighty, brainstorming time people. If you could write some practical laws, what protections do we need to stop these from happening.
I'm thinking 3 categories: Reporting, oversight, and accountability.
Reporting: all entities holding personally identifiable information (PII) must reach out once every 12 months. This hopefully unveils seedy brokers relying on obscurity. Maybe a policy to postpone notification up to 5 years (something like that) may be available as opt-in.
Oversight: targets of PII have oversight of what is collected/used. Sensitive information may be purged permanently upon request.
Accountability: set minimum fines for types of data stored. This monetary risk can then be calculated and factored into business operations. Unnecessary data would be a liability and worth purging.