The point you're missing is most affected users didn't download anything, and were simply friends of someone who did. (OFA or Krogers app)
The distinction you make of OFA being on the up and up and CA not is valid, but doesn't mean suddenly OFA is on a completely different level. There still was a massive amount of data sucked up without consent.