Honestly, it's not even that extreme in most cases. I think it's usually not malice, it's incompetence.
That's why I don't trust big companies with my data. Nothing to do with some CEO's evil plans, but more to do with the hundreds/thousands of mid-level "not my job" or "doing my best" workers who are actually in charge of handling my data.
Sufficiently advanced incompetence is indistinguishable from malice, and should be treated accordingly.
I disagree with this as stated. Maybe in the right context you could make a case for it, but in general? Heck no. Intent matters a great deal, and there is no justice in treating someone incompetent (or negligent) the same as someone who is actually malicious. Both things are bad, but the latter is worse than the former even if they lead to the same outcome.
But is there someone accountable for it being so? Are they malicious? Who is ultimately to blame?
The road to hell is paved with good intentions.
The CEO is responsible for what their company does. If a major breach can occur through the oversight or "incompetence" of one worker, the CEO has already failed, whether through negligence or malice.
At some level, and certainly at the level where you get paychecks of 10 million a year for the "huge responsibility you are bearing", then incompetence IS malice!
I am saying that it's less likely to be some evil machination that led to the misuse of my data and more likely to be negligence or incompetence.
Both are inexcusable, but one is more common/likely than the other.
You can certainly link them together and yes leaders should be held responsible no matter what, but from my perspective as the user who had his data leaked, it doesn't really matter how/why it happened, does it?
Not being held accountable for negligence or incompetence is the evil machination.
People who make poor choices love to pretend that they had no choice at all.
2. It doesn't really matter if you opt out, because _other people around you don't_: they take pictures in which you show, they tag you, they talk about you, they send you links, etc. Which means they (Meta) build a shadow profile of you anyway.
The "personal responsibility angle" is pure fiction.
I live a somewhat normal adult life and manage without having anything to do with Meta ¯\_(ツ)_/¯ I probably miss out on some things, but I don’t notice.
All my friends just contact me through other sources.
If you have kids, it’s more difficult - I can acknowledge that.
So yeah if a business requires me to have an account I’ll find a different business to patronize. Frankly if you’re expecting someone other than you to take responsibility for the media you consume, that’s a problem.
They will keep happening as long as the consequences are just the cost of doing business.
There is obviously a fine that could bankrupt the company: this would be a clear signal "do not do this".
There are also many cases where people have been doing everything they should have been, and still got hacked (zero days, for instance).
Now, I do not think people should only be slapped on the wrist in that case: it still needs to be significant so companies carefully decide to store only the data they really do need!
Or, if that does not happen, when enough people rise up in revolution and take the compensation for themselves.
Or, never.
If enough people vote enough or revolt enough, they cannot be stopped. But the incentives for too few people rising up are too costly. They work hard to keep the equilibrium in that balance.