Perhaps this can eventually combine with companies having to agree to a T&C or EULA type of contract to have access to your data. Such a contract can prohibit copying, at the user’s discretion, or stipulate that revoking access must result in deletion of all copies of that data, automatically.
Some other mechanism can then be put in place to detect and deal with bad actors. Perhaps there could even be some sort of verification of compliance, whereby services/companies must undergo a process that requires proving these systems/processes are in place and operational.
This does nothing for the results of what a third party does with your data—such as models trained with your data—but there are options for removal of data. Of course, it’s ultimately up to users to be cautious about sharing their data.