So the below is loosely organized thoughts answering what you said:
I can't say I have the answers, but I haven't thought long enough or hard enough about this. But one option is continue the analogy via a thought exercise.
What would it mean to have company have a credit check and credit history? Something the owner of the data could view and evaluate before choosing to lend it?
What is data valued at? Is there a bidding process for the loan? Can a consumer check the interest rate / payment they'd get from company X or Y for use of their data for a period of time?
Data right now is a non-physical asset that has value, doesn't adhere to the laws of scarcity, and has no equivalent of copyright protection. The behavior that produces is inevitable. If someone says hey here is this thing that has value, you can hoard for later, and it costs you virtually nothing to obtain it then you'll get entities doing nothing but recklessly fighting to hoard it.
----
> I envision modern privacy as an extension of property rights, a fundamental human right.
Ultimately, I think this is the only way the system balances out - how you get there from here is a whole different question.
Jumping around again, there has to be a regular cost of holding the liability (eqv of a monthly payment). Maybe that's a true transfer of money to the provider via an interest payment, maybe it's a more risk/maintenance cost. But without a regular cost, the incentive is to simply be a "startup mindset", hoard as much as possible, never make a payment, go for it all or go bankrupt when your company fails. You get the same behavior. You must have marginal cost associated with data (in both continuing to hold it for a longer period of time, and of obtaining more).
HIPPA while not perfect, is an example of their being somewhat of a cost associated with holding data. And consequences for improperly handling it. And the healthcare industry is still very profitable. So it's not too far out of the imagination.
But of course there are gotchas. What happens if I tell you my name, can I "force" you to forget it? Do these rules only apply to companies and not individuals? How is security handled? Suspected hacker asks to be forgotten, including the logs and ip traces?
How do you treat derivative data? I use your info to build a ML model, and then forget your data but get to keep the model for free? What if it's not an anonymous model, but is specific to you? With money if I make profits off what you lent me you are owed none of it, I keep it all.
But it's always easy to find problems with a new idea before someone has even presented a proposal. Anyone could list a billion more, but that doesn't mean it doesn't work. Someone could also list a million things wrong with electricity pre-invention (how are you gonna stored it? won't it start fires? look how much capital investment it'd take to build a grid..), doesn't mean it doesn't work.
----
The above is all just rambling on the topic.
So a few focused thoughts:
1. "Right to be forgotten" is important. It changes/fixes the ownership of the asset.
2. Penalties for misuse or lack of protection is next. Penalties must be there to eliminate poor handling of data
3. If there is ownership by people, and it provides value to companies, give people a way to earn off of it - assign it monetary value.
Right now we're in a "why buy the cow when you can get the milk for free" situation. Companies will resist change because they're getting it all right now - so it seems like either they get incentivized and/or someone needs to enforce it.
But again, just because I haven't thought of it, doesn't mean it isn't there. Maybe it's simply "right to be forgotten" and someone makes a market place for lending / selling your data. The same way people are paid for filling out surveys they are offered different amounts for use of their data.
-----
Imagine a non-profit like Mozilla Foundataion, gives you a plugin to monitor all of your web habits and captures your personality/data in a box that you own and control. Maybe you also give it some of your accounts to scrape or something.
Amazon competitor feels Amazon has a moat they can't surpass because Amazon has 7+ years of your buying and browsing history. Now you can go to this competitor and say hey, my data-box has all of my Amazon browsing and purchase history, I'll sell/lend it to you for a rate of $x / month. Competitor knows they can monetize that
and profit more than $x by getting you to make more purchases through showing you the specific better deals in your interests they have over amazon, and ignoring the things you've already bought. Or auto filling out your regularly scheduled monthly grocery products and with one click you're now receiving them from Amazon competitor.
The competitor is better off because they can now compete with Amazon, you're better off because you control your data and earn from lending it, the web is better off because Amazon now competes via a better selling better product and not resting on their laurels of simply having a "data" moat.
The above is just a spur of the moment idea, but maybe there is a smart person who would want run with this, or much more likely come up with a very different and much better way to fix data ownership. Whoever figures the data issue out that will change the web and the world. The alternative (forever on the path we're on) leads us to, in my opinion, a bad state of affairs.