End users might not understand the technical details, but one should assume that if you're giving company X access to your data, company X could potentially share that data with companies Y and Z. Company X's privacy policy should cover their use (and sharing) of the data in either case, and if they didn't anticipate companies Y and Z intercepting data when this is clearly documented as a possibility in Facebook's docs, then I agree - company X should be held accountable.