Looking at this from an IT managers perspective, this discussion can go one forever because we do not sight of the following:
Company IT policy if there is one (we have been told that personal data may be stored on company laptops, but is it in writing?)
Contract between the company and the IT support organisation
Instructions, verbal or written between the company and IT support organisation.
Service level agreement between the company and the IT support organsiation.
My inital thought is if data personal or otherwise is on a laptop that is the property of the company provided for business purposes by the company then any data on any company device is the property of the company and they can do with is as they wish.
While you say it has been 'stolen' what proof is there of that fact, or are you relying on the fact that it is simply not there anymore and it must be the IT company because they are evil perverts?
Was anything else discovered on the laptop to evidence that it was used to visit sites considered by the company as questionable?
What evidence do you have that the data has been stolen for
nefarious means, seen on the Internet, published for personal gain, blackmail, round robin email or have they just been serviced and had all the non company data taken off?
So many questions, how about some facts instead of stirring up a storm in a tea cup?