Maybe the solution is a data tax. You pay a set amount every year for every piece of personal data you have. If you buy personal data from another company, you still have to pay the tax for the data you acquired.
If you have a breach of data, your tax goes up for a period of 10 years.
In addition, every piece of personal data needs to have provenance which must be tracked. There must be a way to track from when a consumer input the data all the way through. Fraud in regards to this provenance is punishable by jail time. If you have data that does not have provenance, the company will be severely fined and people will go to jail. In the event of any data breach, not only will the company that had the breach be taxed extra, all companies that provided the data to the company (which is in the provenance information for the data) that had the breach will also be punished with increased data taxes.
EDIT:
In addition, maybe require annual personal data reports. The reports should contain
Amount of personal data.
Amount of personal data last year.
Data breaches.
Amount of personal data acquired directly from consumers.
Amount of personal data purchased and from whom at what prices.
Amount of personal data sold and to whom for what price.
This will be a filing to a government agency every year on penalty of perjury and be signed by all the board members and the c-suite. This will be publicly made available by the government. That way people can see what is happening with their data, and who is profiting off their data.