As technology improves, it's hard to imagine regulations keeping pace with preventing this sort of thing ...I don't really see why. The main risks with modern big data storage and mining technologies mostly come from the "big" part. A single random person passing you in the street and seeing you out and about for a few seconds probably isn't much of a threat to you. A casual photo in someone's family holiday album where you were in the background probably isn't much of a threat to you either. Nor is a snapshot from a CCTV camera in a store where you shopped.
On the other hand, a few thousand such records in electronic form, all uploaded to the same site that is systematically scanning them, extracting all the metadata that went with each of them, and then correlating all of that with other data that can identify you from your face... That is a threat to you in all kinds of ways. However, the only organisations capable of posing such a threat are those that have access to sufficiently large amounts of data. There aren't actually very many of those.
Governments and essential services that you use often are one category. In a way, this is the trickiest area ethically, because there is obvious scope for abuse of large data sets and there are obvious security risks to keeping such data at all, but sometimes these organisations also have legitimate reasons for processing such data. The parts of governments that operate in the public eye, which is most of them, probably aren't going to break whatever rules we decide are ethically appropriate and codify through laws or official regulations, though.
Another major category is services you deal with regularly. If you shop at a store and they use surveillance technology for legitimate security purposes, that's one thing. If you shop at a store that is part of a larger organisation and the members of that organisation pool their footage and analyse it for other purposes such as customer tracking and marketing as well, that's a bit different. But again, there are relatively few organisations with the ability to collect, store and process large enough volumes of data to pose a significant general threat to privacy. It seems unlikely that these organisations would try too hard to push the boundaries on what is permitted, if the rules are reasonably clear and the penalties for breaking them significant.
The really shady category, IMHO, is the organisations that collect large amounts of data about you by getting other people to provide it. The moment your friend installs a social network's app on their phone and gives it (intentionally or otherwise) permission to upload and scan the data from their phone, the social network also has your phone number and so on. Of course, in places like the EU where there are stronger data protection and privacy laws, the legality of doing so has been challenged several times. But the greatest con the likes of Facebook ever pulled in building their massive databases was solving the scalability and jurisdictional problems by getting almost everyone to spy on each other for them. Even if you choose not to participate yourself, at their scale there will be dozens if not hundreds of people helpfully providing a very detailed set of data about you to Facebook anyway, with Facebook actively encouraging them to do so. Moreover, unlike the case with your own government or services you physically visit or use in person, social networks and the like operate internationally and aren't necessarily subject to the same data protection controls, as long as they can rig it so that they aren't actually the ones transferring personal data out of a controlled area, which of course they also solve by getting your friends to do it for them.
What all of these cases have in common is that they are big organisations dealing with lots of people. The data mining and mass surveillance aspects typically only work as a significant threat to privacy at large scales. And if they're big enough to do that, and not secretive enough to literally hide behind special laws in the way that government security services do, they're also big enough to be actively monitored for compliance and if necessary penalised for non-compliance by regulatory authorities.