Hard disagree. Many security "breaches" are really the discovery of customer data in an S3 bucket "that no one is using in an out of the way data store that otherwise wouldn't need to be touched."
Forcing companies to track and manage the data in their stewardship is necessary because clearly the economic incentive is not high enough - by your own admission. It's easier (and cheaper) to just leave around. But - when, not if - it's hacked, /I/ bear the cost of their negligence, not them.
This is exactly why consumer protection laws are needed.