They shouldn't be able to collect it in the first place. The big companies have 10 page agreements that say they "value" your privacy and that they don't sell your data to third parties. They do value it, highly. And they don't sell it--they just hoard it, mine it, and sell increasingly accurate targeting. Why would they give it up? I mean, besides coughing it up with little objection to national security letters.

The problem is that this includes literally everything on a cloud service. My emails and documents on Gmail/Google Drive is my personal data. My email on Fastmail is my personal data, even if they’re privacy friendly. So that service would be illegal.

Even having an account at all, and being able to see that I have a subscription, or that I previously watched that video, is personal data they collected.

So the Privacy Policy is what you “agree” to let the company do with that data. How do you even begin to differentiate the superfluous stuff they track just for ads, on a technical level without workarounds?

And then think about banning “transferring personal data to a 3rd party.” Does that mean I can’t host account data on AWS, or use a hosted database, be causing I’m transferring data to a different company which can presumably also access it? That’s what the privacy policy has to allow, and why sites have so many “partner services”