It becomes tricky fast.
There is obviously a fine that could bankrupt the company: this would be a clear signal "do not do this".
There are also many cases where people have been doing everything they should have been, and still got hacked (zero days, for instance).
Now, I do not think people should only be slapped on the wrist in that case: it still needs to be significant so companies carefully decide to store only the data they really do need!