If the message is really private (i.e. end-to-end encrypted) then Facebook can't see it , and if it can't see it, or process it in any way then the GDPR does not apply. And if Facebook does access the message and stores it on their servers in plaintext form then that's their (bad) choice, and they should be held responsible for it.