

Some do, some don’t, but more importantly: most just don’t care.
I had a tester wander into a set of edge cases which weren’t 100% properly handled and their first reaction was “gee, maybe I didn’t see that, it sounds like I’m going to have a lot more work because I did.”
There’s a corp solution called “CyberArk” that’s intended for storing passwords and other secrets and providing an audit trail for every access, as well as access controls, etc. It’s nothing like a solution for personal data storage, but those core concepts would be great.
The trick is getting Meta, Alphabet, X, banks, retailers, libraries and the rest to agree to use this API for storage of your data. The next (impossible) trick is enforcing their secure deletion of copies of your data in a timely fashion after they have accessed it.