I find it difficult to trust companies that sell the information and don't inform their compromised victims to inform that same cohort if someone else takes the information to sell. It may result in slightly improved security, but the bar should be that when information of the user leaves the care of the fiduciary, there should be reporting. I suspect companies are cavalier about security of customer data because they sell it anyway, so hackers getting it is hardly any more harmful.
Thanks!
RE: Cybersecurity Regulations Will Force Companies to be Trustworthy