Technically perhaps correct, but for the victims it seems rather irrelevant to me.
In a data breach, someone would have used a technical vulnerability or some other (e.g. social engineering) vulnerability of Facebook to get illegitimate access to the data.
In this case Facebook simply gave them access to the data and took their word that they won't misuse it.
Now maybe the latter situation might not be a data breach in the classical sense, but I don't see how it makes it any better for the victims. If anything it seems worse -- Facebook didn't even try to protect their data.