Yeah in the case of a data privacy breach at a minimum they should be contacting those impacted to say we might have lost your data, offer them some contact addresses/phone numbers/guidance for support. Some companies even hire specialist support agencies to do this. They might also announce it publicly. Often they will try and figure out if someone has downloaded the data first to get a more accurate picture. But a week is the longest they should take, 2 weeks as a bit arse... longer than that and they're getting into class action territory.
Bookmarks