I've not seen anyone address this, but reading between the lines, many people seem to hold a view that the existence of these finely-grained personal data profiles at this massive scale is fine so long as they exist only on the servers of fb and goog, but why? What makes that acceptable or reasonable, besides the persuasiveness of large amounts of money?
I think the clearest path forward is that no one should be creating these kinds of data profiles.
I don't think a bot learning my route to work, or a doctor's appt(along with a swath of more "monetizable" personal info) so it can alert me to potential traffic delays is a reasonable trade-off for the massive societal problems the behaviour of creating these data profiles poses.
If this data is such a monumental danger when it escapes the permeable confines of the fbs and the googs, then it shouldn't exist within these companies either, not just because as we've seen the confines are quite permeable, but also because the potential for negative use of the data doesn't change depending on who has access to it.
It can be persuasively argued that simply creating and collecting these data profiles is itself a negative use of the data.