Responsibilities of organizations or businesses to consumers

What responsibilities do organizations or businesses have to consumers when there is a data breach? Are there cases where professionally a business/organization is not required to act, but ethically they should? Present a current example.