Earlier quoted context omitted.
Why should users have rights in this situation, other than the right to stop using the service? I understand why it would be nice if they did, but why should they? Why is it am imperative?
It depends where you are but there are certain legal rights that no terms of use can waive. They're set up as a minimum standard of acceptable behaviour that someone should be able to expect by default and that there is no reason why a company shouldn't / can't adhere to. Generally they're around physical protection from harm, though they do extend to other things (including Data Protection in Europe). Why should the…
So basically, you're saying people should trade trust in one third party (the service provider) for trust in another third party (whoever sets and enforces the basic standard). I can understand why people may choose to do this (though in many cases I don't think the second third party is any more reliable than the first), but I don't see it as an improvement. I don't think FB cares about whatever legal standards are in place; to them that's just a cost of doing business. But they do care about losing users.
can you imagine what the likes of Facebook or Exxon or whoever might do without them.
Sure, and I can also imagine people not using FB or Exxon (many people boycotted Exxon for years after the Valdez spill, IIRC). Also, I can turn the question around: can you imagine what those who are trusted to enforce standards of behavior might do once they know the public trusts them and won't question what they do? How good a job did regulators do at enforcing standards of behavior on investment banks?
And before you ask, I do not use FB, precisely because I don't trust them to take care of my data. And it's not just FB; I don't trust Google to take care of my data, which is why I don't use gmail, for example, or any other Google services except search and maps. I don't expect anyone to take care of my data unless I'm paying them, as a customer, to do that--and even then I watch them.