Funny that Facebook had no issue with Cambridge Analytica until Cambridge Analytica became an issue. Let's also ignore the fact that Cambridge Analytica was a private foreign company illicitly compiling data to influence US elections. But yes by all means, it's no different than a research group and volunteers studying an algorithm. You definitely nailed it.
AlgorithmWatch is a non-profit, works with international highly regarded news organizations and has open souced the tools [1].
If you want to compare them, then the analogy is more like:
"This is the German version of Mozilla doing research on Facebook's Ad library" (which Mozilla found to be severely flawed some years ago).
Then, let's push for a regulation where the researchers will go to jail if there is a data leak from there.
Surely the regulation should be non-controversial since the researchers are 100% trustworthy like you mentioned.
Unless there is such protection, FB is still liable.
For FB, if the researchers turn out to be good, FB will benefit nothing. If the researchers turn out to be bad, FB will be fucked. I wouldn't want to play this game either.
What if the data leak was out of their control, aka should researchers be liable to field advanced, expensive security teams to protect against the liability of this suggested regulation.
I 100% agree with your sentiment, but I think the answer is incredibly complex.