If I hand you my data, as many here handed their data to FaceBook, for safe keeping and you hand it to someone else without my permission well then yes I hold you responsible.
That doesn't answer the question. You give me your data. I give it to someone else without your permission. Let's say that person is Fred. It's found out that Fred had your data stored in the cloud unprotected.
For the sake of argument, and because I agree with you, I think I should be investigated for mishandling your data. It probably turns out you agreed to that without realizing it when you gave me your data, but let's put that aside for now.
Fred stored your data in the cloud completely unprotected. Didn't even try to protect it. The question is, should Fred be held accountable for his actions?