Further, if you collect my data, YOU are liable for it. Breaches should not be the user's problem. Meaning, if someone walks off with the contents of your database containing my PII using anything less than a crazy number of zero days, you are liable for a set financial penalty per user's info lost (in the way HIPAA does it) and / or you are liable in perpetuity for protecting against identity theft with an insurance policy. I don't need to prove attribution. If I ever have a problem that could plausibly be linked back to the data exposure, you are liable for damages.
Finally, it should not be the user's problem to clean up identity theft, ever. If a bank opens an account in my name without properly authenticating me, that is the bank's problem, not mine. It should be up to them to conclusively prove it was me that did it, not up to me to prove that I didn't. Does this mean it will be more complicated to open up various accounts and credit? Yes. Does it mean that there will be lost business for these institutions? Yup. Tough luck; that is the price we have to pay.
The entire point of this should be to heavily disincentivize collection of PII unless absolutely necessary for core business function.