The sheer number of affected customers and the types of data involved make this breach significant.
The TT-CSIRT does not have the legal authority to force any private entity to comply with its guidance. Any entity has a duty to its employees and the people they serve.

