A security researcher used a modern bug bounty platform to disclose an accidental dump of personal data of ~50,000 FAANG company's users from that company's servers. The data passes through several 3rd party systems not related to the company and lands on the researcher's laptop. What were the legal obligations of the company running the program to protect the data affected? What were the legal obligations, if any, put on the researcher around protecting the data? Who should be responsible for the cleanup?You may be surprised to learn this FAANG company never disclosed the dump, and both the researcher and the 3rd parties continued to have access to the data.