Another policy point would be data de-risking. It has been shown time and time again that companies cannot protect their own data, not to mention user data. I think we should make it very costly to be breached and lose PII. It would raise the bar a lot for who could do what, but I do not think companies have really demonstrated that they can handle this data responsibly. These data losses have even become a national security risk. [1]
1. https://foreignpolicy.com/2020/12/21/china-stolen-us-data-ex...