In fairness, I mean, if the people collecting the data sell it on the open market, then you can't realistically expect it to be private.

The only solution in that case is to make it illegal to sell the data. And that's never gonna happen in the US.