Make a neutral third party liable for the cost and then that third party which is mostly disinterested gets to calculate risk and compliance procedures.
The only way we're really going to get data handling under control is to give the victims of data abuse financial beneficiaries of liability through the courts and insurance companies.
This all ends in corporate feudalism, doesn't it?