At this point, the nuclear option, like the GDPR, is the only way to align the interests of large data firms with the public.
If you think otherwise, consider how the market punished Equifax for their data breaches. Or Kaiser. Or Target. Or Facebook.
When given the choice between doing the right thing, and the expedient thing, this industry has a long, and shitty track record of always choosing the expedient thing.
My point is that governments have a “long and shitty track record” too.
Not saying that government is bad, but it’s clear that governments, when given the power, can be far more dangerous than any company. They can do a lot of good as well, but they have a pretty bad track record.