Any company that accesses/uses Personally Identifiable Information (PII) must register a “PII Czar” with the proper authorities. That person (or persons, depending on the size/scope of the PII data) can be held criminally liable in the event of a data breach.
If a jury finds that the PII Czar enacted the correct policies/procedures & took the right precautions, a jury could find them innocent. But if there was willful or negligent handling at the company, the PII Czar goes to jail.
In the US, one of the big lies told at the corporate level is that no one ever sees jail time because the regulators are too underfunded in comparison with large companies. What’s necessary is clear personal ownership of PII and criminal liability in the event of a data breach.