The issue is in part that even if you had settings on for privacy or were careful who you added to your friends lists, the way they got the data appears to have meant all it took was for a friend of a friend to have had lax settings and downloaded the app.
With that sort of loophole there is no way to protect your information on the system short of not using it, or entering so little that it defeats the purported purpose of Facebook as an easy to use social network (not forgetting that Facebook tend to make privacy settings very obscure and unclear in what does what, with at times quite frequent changes in both the settings that are visible and what they do behind the scenes).
Facebook has been a privacy nightmare pretty much since day 1, with it only being a matter of time until a big enough misuse of it's data came to light to result in questions about the DPA and regulation (as opposed to just the odd murmur or tech press being interested), it's been used for years on smaller/more manpower intensive scale for scams and fraudsters, CA look like they've made use (misuse) of Facebooks toolset to gather far more in an automated fashion that let them make use of it for their ends.
I remember the old 3 dead trolls in a baggie "Privacy song" (I can't link as it's got naughty words), and it's so very true.