You chose to use the Facebook service, you chose to provide this information to them, and you chose to agree to their terms of service.
Facebook isn't a government agency, it's a private organization that has persuaded people to give it armloads of data about themselves, and uses that for whatever completely legal purposes it so desires. It's not like they are taking out credit card applications or anything on behalf of these users.
What is it about this completely voluntary relationship that is so inherently evil? I really don't get the harsh kickbacks and complaints against things like "Facebook keeps records of pokes even if the user 'removes' them". So what? How is that something that is litigation or 'outcry' worthy?
How much of this data is just persistent in the system because they operate at a scale where data deletion or removal just cannot feasibly be accomplished[1]? Much like google - 'we dont delete anything'. Why should they legally or otherwise be required to verify something is actually deleted, instead of simply ensuring it's inaccessible in their system? Why is nobody complaining about NTFS or ext3/4 not actually zeroing out the file space when you delete something, and instead just 'marking it deleted' or 'removing the pointer in the inode'? How is that fundamentally any different at all?
Please, educate me, because I really don't get it.