Definitely something to consider, but as envisioned this company would actually greatly reduce the attack surface for this information, by eliminating it from a huge amount of third party companies with unknown security practices.
As to your direct question. there are obviously the “best practices” around security and risk tolerance. There are some times a users personal information might be necessary, but likely there’s a lot where it wouldn’t.
One could for example anonymize is the primary data graph away from the user. The key piece of information is directed data flow not the information.
Another question is whether or not that is an acceptable risk given the alternatives. For a single consumer to realistically opt-out and keep track of all the companies benefitting from their data, it’s an impossible task.
That consumer would be safer since the target vector is only themselves, but if you want to make a dent against this industry you’d have to do it at scale.