Why do so many people think that these companies sell your data?
The most common behavior people observe that makes them think companies are selling their data is when they visit some site P that sells widget p and then on completely unrelated site Q they start seeing ads for p. The obvious conclusion to draw is that Q now knows they visited P. In reality, ad broker X knows the user visited P, and is satisfying queries from Q (really, from the user agent visiting Q) by vending ads for p to the user agent that is displaying site Q's content alongside that ad. But the ad and Q's content are generally sandboxed from each other the same way that your bank account login state is sandboxed from Q also (1). In reality, Q has no idea the user has visited P, but the content on the page strongly suggests that Q does.
(1) note: It is possible there are holes in the security model that an unscrupulous Q could use to gather information on a user about their history on P; that's generally considered a violation of the ad vendor's policy and will get Q kicked off the ad network.
throw these companies have lots of money to pay fines, suits, and campaign donations with, and the outcome is decided
When you purchase data, it can be remixed and resold, can be used outside the original terms of service agreed to between FB/Google and their users. This is difficult to enforce agreed upon protections, and is a troubling issue (e.g. Cambridge Analytica had user data they used in a "clearly wrong" manner -- a problem that AFAIK was from 3 years ago and has since been shut down).
Buying access to the users means an advertiser is purchasing the ability to put a message in front of the user. This data is covered by user agreements, and is much harder for third parties to use in a "clearly wrong" manner. This data must be deleted at the request of the user, and can be (relatively) easily deleted by going to the original source (a key distinction -- it's very hard to delete data that has been sold and resold).
It is important to use the correct description of what is happening. On FB, you're not "buying an audience" so much as "defining an audience to reach". You don't get to hold the user data in a csv; you get to put messages in front of groups of people. You don't possess the data -- you have access to use it through a user interface provided by FB/Google.
I respect that you may feel FB/Google holding these user data is unethical. Other people feel the exchange is perfectly fine. Regardless, using precise language is important to not muddy the waters, especially in such a tendentious debate.
Saying or assuming that no tech companies sell user data is disingenuous. Case in point, doesn't Edmunds have an exclusive data contract to share data with Oracle Data Cloud?
Re-reading my comment, I don't think I said anything about companies in general.
The fact that they collect it in the first place is the real problem. And when they inevitably get hacked and lose the data (happened), or leak the data (happened), or their employees inappropriately access the data (happened), or they hand it over to whatever government after putting up a token fight (happened)... it doesn't matter one bit.