No, you are responsible ultimately for what information you reveal or don't.
It's all good having some big behemoth like the EU laying the smackdown with GDPR for companies and sites but that shouldn't mean you let your guard down and expect all sites to follow the rules.
I don't need to care about trackers because I am blocking them pro-actively.
I have NoScript installed and temporarily allowed domains because I wanted to see if a website about stopping mining mines its users.
However, I agree with you, people need to stop downloading random (potentially malicious) javascript and executing it. Getting your info stolen is someone elses fault, but your responsibility.
I think you mean ultimately here, penultimately means last except for one (so that there is someone that is even more responsible than you for the data you reveal or not)
Additionally, you can go a step further into the Privacy mania and install NoScript (JavaScript blocker). In my experience you only need to unblock 1-2 script domains on every website to make it functional.
Except that “uBlock origin” is maintained by the OG developer and “uBlock” (of ublock.org) is a now filthy ripoff owned by some greedy dickhead who OG developer trusted with control over the original repository.
So yeah you only need one of them but I’d stick with the OG “origin” one.
I meant if you have uBlock (origin or the other thing) you don't need noscript-addon, because uBlock (both origin and the other thing) can block javascript.
Sorry for confusion.
A site that claims to be "...the central source for consumers to learn what kinds of information data brokers have about them and how to exercise their opt-out choices" arguably shouldn't itself do data mining. Or should at least be clear about what it is doing with the data that it collects about you.