Court documents says that they blocked access as soon as they were aware of it. They also "built out its systems to detect and filter out “potentially health-related terms.”". Are you expecting more, like some sort of KYC/audit regime before you could get any API key? Isn't that the exact sort of stuff people were railing against, because indie/OSS developers were being hassled by the play store to undergo expensive audits to get access to sensitive permissions?
"chose" is doing a lot of the heavy lifting here. Suppose you ran a Mastodon server and it turned out some people were using it to share revenge porn unbeknownst to you. Suppose further that they did it in a way that didn't make it easily detectable by you (eg. they did it in DMs/group chats). Sure, you can dump out the database and pore over everything just to be sure, but it's not like you're going to notice it day to day. If a few months later the revenge porn ring got busted should you be charged with "intentionally eavesdropping" on revenge porn or whatever? After all, to some extent, you "chose" to run the Mastodon server.
Not knowing those details (they are probably available but I'm not interested enough to read the court documents) I'm going to defer to the courts on this. Understand that depending on ongoing appeals I may have to change my stance a few times. If this keeps coming up I may eventually have to get interested and learn more details so I can pressure my representative to change the laws, but for now this just isn't important enough - to me - to dig farther than the generalizations I made above.
Really the only blame here should be on Flo.
At one point I was getting a strangers fertility app updates - didn't know her name, but I could tell you where she was in her cycle.
I've also had NHS records sent to me, again entirely unsolicited, although that had enough I could find who it was meant for and inform them of the data breach.
I'm no fan of facebook, but I'm not sure you can criminalise receiving data, you can't control what others send you.
Of course not. You can, however, control what you then do with said data.
If a courier accidentally dropped a folder full of nuclear secrets in your mailbox, I promise you that if you do anything with it other than call the FBI (in the US), you will be in trouble.
This happens accidentally every single day and we don't punish the victim