After you informed them did they respond positively to change or dismissively? I'm suspecting the latter...
Based upon other companies and agencies where I have pointed out this sort of thing the answer is:
But WE take your privacy seriously (BS #1) and OUR data is secure (BS#2). Got to wonder if they believe their own BS?