If these kinds of breaches were actually costly, then people would indeed treat PII as toxic. But they aren't. The media brouhaha blows over within a week or so, and things are fine again.
Leaking PII should be very, very expensive, and then this idiocy would stop.
Everything is paid for by the customer. If you spend an absolute fortune protecting someone's named and address combination, that will be paid for by the customer.
So then the customer will just pay more, because the "prevent you from getting fined into oblivion" insurance businesses you just created with the flick of a pen will need to get paid their overhead and won't do it without a profit.
Then over confident, short sighted or shady characters will accept those directorships and/or sign off on the design because they think nothing will happen or don't care for jail.
What you didn't have was a computerised database which could spam everyone on that list in milliseconds, or profile everyone's character, purchase history, medical history, and more.
We used to do a lot of worse stuff too, like eat radium hoping for brighter skin.
The Payment Card Industry takes breaches deadly seriously. It is my opinion that any organization that collects PII should be held to the same standard (and penalties) that any organization that collects/processes credit card information.
Leaking PII should be very, very expensive, and then this idiocy would stop.