There's little public benefit in responsible disclosure here; all it would lead to is the whole thing being swept under the rug with some trivial "fix". There's lots of public benefit in immediate, wide disclosure - the scramble to fix this under pressure from vendors before potential abuse, and any real or imagined attempt at abuse, and subsequent lawsuits, would go far towards educating people and the industry about privacy, security, and bad business practice. It's a nice low real damage, high publicity case.
It's not like this stuff is new. But without serious pressure, the businesses will never learn and never stop making or enrolling into such systems.
Anyway, if it happened over here in the EU, I'd do the responsible disclosure thing and give a full, detailed advance expose to the local Data Protection Authority.
(And if I sound adversarial, then consider that neither the vendor developing such systems, nor the venues using them, are doing it in the interest of the customers.)
I think most people would acknowledge there's a big difference.
Which would still be wrong but you're implying that the business is the victim here when it's the complete opposite.
Nothing wrong about that. Of course still doesn't justify publishing/providing access to client data who did nothing wrong.
Of course in other places, there aren't really any good options. So I guess the most "moral" approach would be to what you think would cause most financial damage to the business and discourage people from going there.