I think it should be illegal, full stop.
Then we're certainly not in agreement. And that's fine.
I think sale of data should be 100% allowed, provided the customer consents (and gets fair compensation). The customer, however, needs to be aware of what data is being sold, to whom, and what they're getting in return. Burying that 20 pages deep in a TOS doesn't count, it needs to be in a format that an average person could reasonably be expected to fully understand. The service provider and the company receiving the data should have strict legal requirements to keep that data safe, so if there's a breach of any variety, the consequences would be a lot steeper than a few dollars per person affected.
So essentially what I'm after here is transparency to the customer, and actual consequences for companies that fail to protect customer data.