Comment Breach Disclosure Laws (Score 1) 183
First, everyone who says that it's not his decision is right.
Second, if he feels that his client should inform the individuals, he could look at the state laws that apply. Figure out which states your customer's customers are from, and then look here. See which states have laws that were in effect at the time of the breach.
Depending on what information may have been lost and what states we're talking about, the answer varies.
I've handled a couple of these so far, and I'm glad to say that the company involved did the right thing in all cases.