Shall I fetch the tin foil?
Yes, GOG should have disclosed this information to us when we place an order. EU legislation requires that any information regarding our order or person sent to third parties, and in that respect GOG has broken the law.
In practical terms, however, no real harm has been done. As some have correctly stated, there is a fundamental flaw with this statement...
AstralWanderer: Order ID is individual and so can be linked to personal details by GOG or anyone else with access to GOG's database.
...namely, that the only ones with access to GOG's database are GOG themselves. If anyone gets access to GOG's database, then they will also have access to the order data including the order IDs anyway. Nothing can come from simply disclosing an order ID code that a hacker hacking into GOG's server wouldn't be able to discover without that information.
If GOG started transmitting information like names, credit card information, IPs or the like, THEN I'd start worrying.