Actually it's not. If Dick did a "woopsies" and "accidentally" leaked his whole DB it would be an absolute nothing burger from a legal perspective. You could try to sue him, and lose. User data security is an externality.
Even if Dick was knowingly violating PCI compliance, it would be civil matter, not a criminal one. Plus as far as we know he's not required to have PCI compliance considering Jim said Dick uses a third party for the nitty gritty financials. The idea of someone going to jail over data security is extremely rare, and almost always some low/mid-level government worker taking him classified data.
See:
https://www.schneier.com/essays/archives/2007/01/information_security_1.html