... except when they sell their domain registration business.
And yes, I realize that there's a (technical) difference between selling data and selling a business including its data assets.
But then again, maybe a really big chunk of the value of that business is its customer data.
For some business acquisitions special terminology like "aqui-hiring"[0] has evolved so it's understood that not every sale of a business is of the same nature.
And since the value of data has arguably become much higher than ever before, the distinction of selling data by itself and selling the entire business is becoming smaller as time goes on.
Who knows what they'd sell if their business declined for a while and there was a hostile takeover or they otherwise got desperate for new revenue streams.
And then if you were paying attention you could make a new one of these requests... but maybe you'd miss it for a bit, and then it would be too late.
The law should be based on what you collect instead of what you sell to better protect against this sort of thing.
Companies selling your data are your bank(credit card purchases), mobile carriers(location), your DMV(photos, driving record, misc PII including address, dob etc), state/county government(public records like marriage licenses). Its weird everyone bashes on google and FB for something they don't even do.
I want the means to tell companies "Do not collect information on me." And I want that to be enforceable by law.