Most are being tempted of the perks or bonuses but they are not seeing the long-term effect of their decisions. They should at least consider the possibilities of exposing their data to these sites and what may happen to them in case of breach of data especially if hackers got a hold of their information.
In the end, the users are making a trade which they do not realize that they are making -- they are exchanging information and their data for perks and bonuses. When something goes bad as a result of this trade, they blame everyone else except themselves. There are many reasons why this happens, but ultimately most people are very fragile and behave like children. When they do something wrong, they think that with enough whining and covering that their blame will disappear. The same happens with many KYC stories or stories where the user did not read the TOS -- it is the casinos fault of course!

Who knows, one of their partners is already plotting how to exit the game and disappear to a Caribbean island?
Life is not a Netflix movie, this almost never happens. Speculating on very rare scenarios is misguided and not worth the time here..
Since I stopped using local gambling sites, I have never received a call like that, even though I have given my KYC information to the online casino several times, now no one calls me anymore, local sites are much more dangerous because their network is wide, sometimes they sell to other local gambling sites.
You can't make such general statements for everyone because it depends a lot on where the user lives. Therefore for many places your statement will be wrong. Local casinos in the EU have to adhere to strict data protection laws, much stricter than online casinos and this is not going to be true for many other countries.
If you know you value your privacy so much, and you don’t want anyone to tamper with your informations, then make sure you make use of gambling sites that doesn’t require kyc, but as long as you have submitted your kyc, then your informations are no longer private.
If a person has completed KYC even once anywhere in this industry, it may already be too late for them overall. Still, they can work on harm reduction by not submitting data anywhere else and preferably asking for the deletion of old accounts where data was submitted.