Near as I can tell, this is about data in Facebook's databases finding its way to other organizations without the users' knowledge or consent. But the way this happens is pretty benign:
1. User installs Facebook app, and that app phones home with info about user's friends (who did not consent to this). This is what happened in the Cambridge Analytica scandal. People started asking why apps are allowed to see info about the user's friends (who did not install the app). But to a programmer, the answer is obvious: it's the "app inherits owner's permissions" model that's been part of the Unix tradition for decades. Anyway, Facebook has since changed this behavior.
2. User adds some bots as friends (maybe because their profile photo is of a cute girl), and the bots phone home with public info about user's friends. This is an entirely predictable consequence of the "friends of friends" permission model. Facebook users can set "friends only" permissions to prevent this, but most don't bother.
Is it one of these two vectors that's getting people upset, or something else that I'm missing? Keep in mind that advertisers never get to see people's private info. They just make an ad and say something like "show this to people aged 18-25 who are into video games."