If you're hosting or planning to host a web service in the UK: Don't.
Put it somewhere else. Stick it behind Cloudflare or AWS CloudFront. Don't pay UK businesses. Punish them (us) for our stupidity.
Don't register as a company in the UK if you can avoid it.
Geoblock UK users entirely if you must.
https://www.gov.uk/government/publications/online-safety-act-explainer/online-safety-act-explainer
I suspect that a lot of the security risks associated with data collection and storage (including data breaches) would be eliminated if these companies simply didn't collect the information in the first place. "Ounce of prevention, pound of cure" and whatnot.
Most of the time, it seems like the information collected is in excess of what the company/website actually needs to provide its services. Am I just getting more cynical as I get older, or are most companies just stockpiling this data to sell to third parties for an added revenue stream?