Data leaks in those companies are not about the security of the data itself but about who can cover themselves in case of a leak.
If you can demonstrate all the compliance, that's an insurance when something happens, regardless of the actual security value it provides which is rarely evaluated anyways.
Companies working this way really aren't tech companies and they don't behave as such.