Many regulatory bodies seem to constantly fall short of what they are supposed to do and then demand more money and powers to continue to fail at what they are supposed to do.
At what point would you accept that they maybe not fit for purpose and other solutions should be considered?
It maybe better to put resources into educating people on how to protect themselves from privacy breaches or minimise the impact.
The only thing I've ever seen from the ICO is a letter saying that if I have customer data I have to pay them a fee or pay a fine. Then I have to go through the inconvenience of telling them I don't have any, so I don't have to pay this fee.