Make companies "super-liable" for any data beyond the data they (actually) need for the functioning of the service that is stolen in a data breach from their servers.
This would hopefully not just encourage more companies to believe that data is "toxic" [1] and treat it as a liability, not as an asset, but it would also encourage them to adopt end-to-end encryption in as many types of services as possible (and eventually stuff like homomorphic encryption or any form of encryption that doesn't give the company itself and hackers direct access to the data).
[1] - https://www.schneier.com/blog/archives/2016/03/data_is_a_tox...
I think we need to teach people that their data is valuable, likely dangerous in the hands of others, and not to spew it all over the web. Kinda like we did before FB convinced everybody to use their real names.
Other than them, who cares? If you want to put people in harm's way, you should accept the consequences when harm occurs.
>I think we need to teach people that their data is valuable, likely dangerous in the hands of others, and not to spew it all over the web. Kinda like we did before FB convinced everybody to use their real names.
No, it's much easier to hold the companies accountable, and they should be held accountable. No company that suffers a "data breach" should have the resources to exist after the breach. Society should punish them out of existence, because they are known cancers.
We don't consider this a leak when the marketing firm loses its data. It's only a leak when we find out that the marketing firm has lost control of its data.