Because it's not worth it. I'm protecting the family member, not the company.
The image of people standing up for the noble whistleblower is far from the truth. Disclosing the company here won't achieve anything apart from garnering a few karma points and generating some short lived outrage at the company.
I'd consider disclosing it to the ICO, and made tentative steps in that direction at the time, but it's not clear that they are interested and whose interests they would protect.
Here's a question that might make this discussion useful: What is people's experience of reporting data breaches to the UK's ICO? In your case, was meaningful action taken by the ICO and was the person doing the reporting protected? .
And one thought about this situation and the common view that companies/corporation are a being on their own: I'm pretty sure that the IT guy that gave the OK to the CRM and then asked to sack your family member is directly responsible and could have took another decision if they were a person with a higher moral ground, like accept responsibility and accepting the risk of being fired. And the same apply to every level of the chain of command.
But it's easier to say that people are removed by design from the consequences of their acts so it's not easy to take the right decision for anyone. It's just not convenient, instead.
The image of people standing up for the noble whistleblower is far from the truth. Disclosing the company here won't achieve anything apart from garnering a few karma points and generating some short lived outrage at the company.
I'd consider disclosing it to the ICO, and made tentative steps in that direction at the time, but it's not clear that they are interested and whose interests they would protect.
Here's a question that might make this discussion useful: What is people's experience of reporting data breaches to the UK's ICO? In your case, was meaningful action taken by the ICO and was the person doing the reporting protected? .