This argument was used last time [1]. It didn't work then and it's a silly excuse now.
Users gave Facebook their "name, email address, age range, gender, locale, and profile photo" [2]. Some of them marked those data private (i.e. only for friends). Those data were shared, without the users' informed consent, with third parties through the log-in function.
Documenting a breach doesn't unmake it a breach. And a breach can be a breach without involving any technical exploits. This was a breach.
> Seeing this and being surprised is like watching a teen movie where the gossiper...
People didn't realize Facebook was selling their secrets. That may strike you as naïve. But it's this asymmetry, between specialists (e.g. Facebook employees and technologists at large) and non-specialists (i.e. most of Facebook's users), that drives the need for regulation.
An analogy can be found in lemon laws [3]. We protect consumers from specialists (e.g. car salespersons) taking advantage of the customers' reasonable ignorance of cars. Facebook is selling the world lemons and mocking them for buying.
[1] https://www.cbsnews.com/news/facebook-cambridge-analytica-wa...
[2] https://techcrunch.com/2018/04/18/login-with-facebook-data-h...