Really interesting legal question - "Seems like the ball is with Google at the moment, the exposed data is on their GCP servers. So, they can figure out next steps." is a comment above. How will the chain of insecure infrastructure + the data scrapers + the people responsible for configuration react?