Make companies "super-liable" for any data beyond the data they (actually) need for the functioning of the service that is stolen in a data breach from their servers.
This would hopefully not just encourage more companies to believe that data is "toxic" [1] and treat it as a liability, not as an asset, but it would also encourage them to adopt end-to-end encryption in as many types of services as possible (and eventually stuff like homomorphic encryption or any form of encryption that doesn't give the company itself and hackers direct access to the data).
[1] - https://www.schneier.com/blog/archives/2016/03/data_is_a_tox...