So i been looking at the sony hack and who was the lead authority in the uk, the ICO (information commissioner office) fined them £250,000 ($396,100) for there mess up, there seems to be very clear rules in place if anything like this happens to a organization and what should happen.
Quote from ICO website:
A personal data breach is:
a breach of security leading to the accidental or unlawful destruction, loss, alteration,
unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed in connection with the provision of a public electronic communications service.
When and how do we notify the ICO?
You must notify the ICO within 24 hours of becoming aware of the essential facts of the breach. This notification must include at least:
your name and contact details;
the date and time of the breach (or an estimate);
the date and time you detected it;
basic information about the type of breach; and
basic information about the personal data concerned.
When and how do we notify our customers?
If the breach is likely to adversely affect the personal data or privacy of your subscribers or users, you need to notify them of the breach without unnecessary delay. You need to tell them:
your name and contact details;
the estimated date of the breach;
a summary of the incident;
the nature and content of the personal data;
the likely effect on the individual;
any measures you have taken to address the breach; and
how they can mitigate any possible adverse impact.
You do not need to tell your subscribers about a breach if you can demonstrate that the data was encrypted (or made unintelligible by a similar security measure).
If you do not tell your customers, the ICO can require you to do so if we consider the breach is likely to adversely affect them.
more at source
https://ico.org.uk/
So we have unauthorised disclosure of personnal information, people effected not notified (yes we have a statement from gaming website but not everyone looks at them) but on steam itself? nope, emails sent out? nope. i hope the ICO go after steam for this and fine them because there responce has been slow and unacceptable.