Cambridge Analytica is accused of improperly using the data on behalf of political clients.
In a statement, Mr Zuckerberg said a “breach of trust” had occurred.
In a later interview with CNN he said he was “really sorry”, and pledged to take action against “rogue apps”.
He added that he was “happy” to testify before Congress “if it’s the right thing to do”.
In his statement posted on Facebook, he promised to make it far harder for apps to “harvest” user information.
“We have a responsibility to protect your data, and if we can’t then we don’t deserve to serve you,” Mr Zuckerberg said.
Mr Zuckerberg added: “While this specific issue involving Cambridge Analytica should no longer happen with new apps today, that doesn’t change what happened in the past.
“We will learn from this experience to secure our platform further and make our community safer for everyone going forward.”
In 2014, Facebook invited users to find out their personality type via a quiz developed by Cambridge University researcher Dr Aleksandr Kogan called This is Your Digital Life.
About 270,000 users’ data was collected, but the app also collected some public data from users’ friends.
Facebook has since changed the amount of data developers can gather in this way, but a whistleblower, Christopher Wylie, says the data of about 50 million people was harvested for Cambridge Analytica before the rules on user consent were tightened up.
Mr Wylie claims the data was sold to Cambridge Analytica – which has no connection with Cambridge University – which then used it to psychologically profile people and deliver pro-Trump material to them.
The firm’s chief executive, Alexander Nix – who was suspended on Tuesday – was secretly recorded in a Channel 4 investigation saying the London-based company ran Donald Trump’s digital campaign during the 2016 US election.
“We did all the research, all the data, all the analytics, all the targeting, we ran all the digital campaign, the television campaign and our data informed all the strategy,” he added.
Dr Kogan has said he was told by Cambridge Analytica everything they had done was legal, and that he was being made a “scapegoat” by the firm and Facebook. (Courtesy BBC)