Why are we trying to mash everything down to a one-dimensional ranking? Over simplification can be as deceptive as over-complication.
A breach of one's personal data is clearly less severe than a violent attack upon one's person. But the former could enable the latter (eg if information were purchased by a stalker). And it certainly increases the base level of risk from fraud and adversarial commercial contact (secretly exploiting knowledge of a target to manipulate them into a purchase/sale decision).
Now scale the individual loss up by huge numbers of people, and consider what incentives led to the information security failure. While it's sometimes practical to remediate individual losses of privacy, at scale future injuries are virtually assured. It seems to me that this warrants an application of strict liability principles.
As for restitution, in ym view not only should injured parties be compensated in cash (and much more of it), but they should also be granted, individually or by proxy, partial ownership of the offending firm; that is, existing investors should have the value of their asset significantly diluted. The loss of personal security should be reflected in a loss of financial security to the asset holders.