I do not want any of your data, above that which I must hold for the service to be useful. It’s just a liability.
See also: Marco Arment, maker of the Overcast podcast player, pushing people to take their accounts anonymous [0]. It’s just good business sense at this point.
I also plan on having zero trackers. I’ll just get over the fact that I’ll have no visibility of users on my site other than what I can glean from public forums or, you know, actual paid sign-ups. It’s all too fraught with leak risk and I can’t be bothered.
We go to great extent to not have any kind of Personally Identifiable Information, because the liability is way too big.
It really sucks when a client accidentally send us a list of their customers email and we have to clean up everybody's inbox.
I wonder how many companies who have 'leaked' data recently are doing these things. Granted, it will never catch all bugs, but avoiding these things is negligence, which should be punishable.
Criminalization is wrong, though. Put the company to death, that's enough. Even the high penalties of GDPR already cause changes of management behavior (at least where I work).