A few years ago I was tasked with working on a voter management platform (used by campagins to track people, how they are voting, and calls made to them. A CRM for voters if you will). The part I was in charge of the Facebook data. The company we were working for would have parties where they got people to sign in with FB and give ALL their friends info up which we would then fetch and import into our backend. The idea here was to grab their political affiliation, interests, jobs, education (pretty much everything FB offered up) and then use that to match them to their voter records (you can get these records from the state I guess). They could then target people based on interests and the like.
Overall it was a neat project and my first foray into auto-scaling on AWS, event queues, and creating AMI's (ready to go images that when launched would start consuming the queue). However after working on this for a few weeks I took a look at FB's ToS and realized that by storing that data, planning on keeping it forever, and not giving users a way to delete the data (let alone any sort of private policy outlining what we were doing with the data) we were in violation. I brought this all to my bosses attention who more or less told me to "don't worry about it" and then shortly after I was moved off the project. That project (and the company that paid us to write it) no longer exists AFAIK (which is for the better) but this would have been the nail in the coffin for them.
I'm really glad FB is taking this step b/c that project opened my eyes to something this article touches on which I don't think a large number of users have considered: when you "Friend" someone on FB you also give them a blank check for all of the data you share with them that they can sign over to any/everyone. It's good that FB is reigning this back in and not letting people give up access to their friends data.