@dwr
PII with an expectation of privacy should be locked down within companies. Like private keys or passwords.
Any leak should come with a per instance leak penalty of $10,000 automatic disclosure / pay out to the individual affected. Companies have 3 years to migrate.
Put a clear penalty in place, companies would update their systems.