I have always advocated that if a company has your PII, it should notify you annually:
- What personal data they possess
- To whom they have shared/sold/provide that data to
- If they have lost or exposed that data (ex. breach)
- When they will remove/delete the data
- Provide a 1-click option to delete the data
In this way, consumers can track what data is out there and who has it!
RE: Cybersecurity Regulations Will Force Companies to be Trustworthy