This highlights a major problem with tort law: It's monetary damages or GTFO. In other words, it's nearly impossible to make a case for damages when there is no obvious monetary aspect of the harm done. I can't sue Home Depot for giving up my credit card info to hackers unless I can prove that it led to someone running up my credit card bill. Either this needs to change, or it should be a crime for companies to release customers' personal information to unauthorized third parties.
Part of the problem is how these data breaches are framed in the media. It's always "Company X was HACKED!" and "Company Y SUFFERED a major data breach!". They're portraying the negligent company as the victim! It should be "Company A carelessly released their customers' data." or "Company B failed to protect 10 million credit card numbers." Once we stop pretending these companies are victims, we can start making and enforcing tougher privacy laws.