It sounds like in this case, Comcast provided data to a 3rd party so they could try to collect on past due accounts. I’m surprised it isn’t more common to keep your data in house and provide programmatic access to data on as needed basis combined with auditing and access controls.
You can make 3rd parties sign all kinds of agreements, but even if they are held responsible, it diminishes your brand too. An entity as large as Comcast could afford to make an API instead of providing direct access to raw data.
In my experience, it's not that organizations are unable to fix the collections sides of their orgs, it's that they don't care to on an organizational level. It's a lot easier to share a spreadsheet over email regardless of the consequences than to go outside your lane and advocate for spending resources to do something better. You aren't going to win any credit, debt collectors are going to complain, and the only people who might benefit are easily disregarded as leeches because the system thinks their account is delinquent.
I'm more curious at what point Comcast is responsible for handing your PII to that shitty little debt collector organization that let your information leak onto the internet because they really have no concept of IT security.
Not like you as a delinquent customer willingly shared your information with that shitty debt collector organization that leaked it, so who's really responsible?
You can make 3rd parties sign all kinds of agreements, but even if they are held responsible, it diminishes your brand too. An entity as large as Comcast could afford to make an API instead of providing direct access to raw data.