Isn't it up to regulator to make a business pay (or not) ?
I imagine in the case of the data privacy laws that it is. But the point about this is that the lawyers are claiming that businesses breached the 'unfair competition' laws (by not following the legal requirements) and thus are liable for the damages caused to their client for this breach.