> By the time the company get sentenced, the people involved have already left with a nice bonus, and found a nice new job, there is no incentive for avoiding it.
> You need proper fines and jail time for the people involved, even decades later.
That's not sufficient though. The people who did the bad acts need to be punished, but the owners who profited from the bad acts need to be punished too. If you don't do that, you just create situations like Amazon: set a sounds-good internal policy but have internal incentives for employees to violate it (e.g. exploit 3rd party seller data to unfairly compete with them) and lax enforcement, then fire the employees as scapegoats when caught to deflect blame when the violations become a PR or legal problem. So some harsh action needs to be taken against the owners and the shareholders.
A "corporate death penalty" doesn't really work, because shareholders can always sell. You don't want the guy responsible to profit, while some innocent schmuck gets punished because he happened to be holding the bag when the music stopped. You need action against the shareholders who were owners at the time of the bad acts.
Instead, since we have computers with big disks now, there needs to be a registry that tracks the historical beneficial owners of a company's stock. Then when something worthy of a "corporate death penalty" happens, those people are tracked down, fined, and any profits they enjoyed get clawed back. If they go bankrupt, tough: as owners, they should have proposed or voted for shareholder proposals to keep the management under control.
Of course there would be some finer details to work out (e.g. breaking the veil on shell corporations, policies to deal with straw ownership, letting other shareholders off the hook if some small group (e.g. founders) have complete voting control of the company), but I think the idea is workable if you don't consciously let clever-assholes exploit loopholes