I really don't have time for section references at the moment but suffice to say the act is not only about the sale of info. But here are some clear points of failure:
1- did the obtain permission from the data subject to use the info in the way it was used - No
2- did they make efforts to de-sensitize personal info before it was used like this - No
3- did they take reasonable measures to protect the data - No (you can argue this but considering this info was accessible via google puts it in the public domain)
Lastly, considering that you had a breach, did you disclose this individually to those affected, the details of the situation, what data exactly was lost, any steps being taken to remedy, etc - Hell No - haven't heard of anyone receiving any personal emails on this.