>Under CCPA/CPRA in California, you can request that personal information is removed. There are half a dozen other laws around the US that allow for similar requests in different forms.
CCPA/CPRA is a minor start, IMHO.
Telecoms need to collect and store usage information (including call detail) to perform billing functions.
As with most such laws, there are loopholes big enough to drive a column of tanks through.
And many other corporations collect and store data both for billing and because they can [mine|analyse|sell] such data.
Just being able to request removal of "data" isn't nearly enough.
Unless there are unambiguous opt-in data collection/retention policies, with clear, concise language about how such data could be used.
What's more, such policies should apply to any and all third parties providing services to corporations with such data.
Further, as another comment[0] in this discussion pointed out, the Third-Party Doctrine should be gutted and a requirement that all government agencies collect data for law enforcement purposes through the issuance of warrants by judges that specify the "probable cause, supported by oath or affirmation, and particularly describing the place to be searched, and the persons or things to be seized."[1]
This is (unfortunately) a wide-ranging issue, with a growing number of industries (autos, electronics, "cloud" services, etc., etc., etc.) collecting, storing, using and selling all sorts of PII.
From a privacy perspective, this is a nightmare, the CCPA notwithstanding -- even in California.
[0] https://news.ycombinator.com/item?id=35073264
[1] https://www.law.cornell.edu/constitution/fourth_amendment