This sounds like the kind of thing the EU has laws for, where a company is legally mandated to fix vulnerabilities that may reveal personally identifiable information if made aware of these. Worth asking someone who's more of a lawyer than I am about that (since I am definitely not a lawyer).