Love the apologetics by haveibeenpwned "to be fair they're also dealing with .." some other related criminal investigation, etc.
If you can't appropriately manage your risk, and your response, that doesn't mean the regulations and disclosure requirements should shift, it means, just like your shit security practices that allowed the breach in the first place, your IT team is inappropriately and illegally under-resourced to responsibly and compliantly follow law. They should pay significant penalties for failing to promptly disclose, and if due to insufficient staffing should be required to fix as condition of settlement.
I think it's due to historic risk management - even 50 years ago Germany was far from settled and secured compared to the US economically or politically. Many other countries were similar and didn't take seriously the seismic risk changes of the past few decades. Now they are.