What if a data breach happens due to an 0 day exploit with a 3rd party library? Do people from the company where the data breach happened still go to jail then?
in other words, all they have to do is fulfill their obligation disclose that they were hit by this 0-day, in order to at least be protected from jail time.