@Yuvalne
yet another reminder that you can't give away data you don't have in the first place.
Law enforcement is not the only (and may not be the most important) adversary where this matters. If your system is compromised, it can leak data that you collect. You may be liable for that leak but you'll suffer reputation damage even if not.
If the thing that's leaked is 'User with UUID {...} logged in at UNIX timestamp {...}' (with no way of linking a UUID to a human) and contains no PII, then you are probably not even legally required to disclose the breach to your customers.