When companies lose control of personal data, who is accountable for the harm that comes years later?

A point-of-view article by Chirag Dani.
A deeper exploration of customer accountability, autonomous systems and the next generation of cyber regulation.
When a large organisation is attacked and customer information is stolen, we usually discuss three things:
How did the attacker get in? ; How much data was stolen? ; How much will the organisation be fined?
I think we are asking the wrong final question.
The question I increasingly want boards, regulators, technology leaders and legislators to answer is: Who carries the risk after the organisation has lost control of my identity?