Or you could just stop fucking sending my data to third parties when it's for your own sole benefit rather than mine.
I realize my comment is crass, but it's getting ridiculous how pervasive the sharing of PII has become between tech companies, and the risk-laundering that's given rise to. Everyone's adopting a myriad of SaaS platforms that are deceptively easy to plug in, and it's too tempting to shed accountability. Attitudes of "it's not our fault, it was our vendor" beckon better due diligence.
I don't mean to single out Framework here - the problem is not in any way limited to them, and to be honest their response may be one of the more responsible disclosures I've seen (it's helpful it lists the specific fields and some technical data, and I'm glad they're clamping down even if it comes too late). I'm a fan of their mission, and wish them resounding success in their business.
But a forceful call to action is needed!
Tech leaders and CTO's: Let's get our act together as an industry. Treat PII like the toxic asset it is. Remember each row in that database is a real human being, and appreciate the gravity of responsibility they entrusted you with when they forked over their information. Be more rigorous vetting your vendors (think about the gauntlet Apple puts their hardware suppliers through). And for god's sake, stop indiscriminately shipping it off to every trendy service du jour.
Consumers: Avoid falling into indifference. Refuse to accept these data thefts are inevitable. And get rightly fired up and angry when the companies you trusted with custody of your data let you down.