Foreplay: I know that you don't like what you read but this is a diction of GDPR, so before you start down-voting, please - Rec.74; Art.24 and read [1]) as the "entity" that obtained the data.
Let me shed some light. Facebook/Google have nothing to do with it except they are breaking the law because of you that have planted data from you friends without their consent.
Following the GDPR, the one who gave personally identifiable information (PII) to the Google/Facebook/whatever, makes HIM/YOU/HER responsible for whatever they do with it.
(Or in other words - if you are gathering the personal data on your website for a 3rd party, you better be sure that the 3rd party has a strong legal bond with you regarding the information you have "traded" to it or you might have troubles.)
Even if "your friend" has given his/hers PII to you, you dont have any consent to share it with whatever 3rd party application you are using and is stealing your data based on "I Agree button". This is making you, as a controller of PII responsible for his PII. If the 3rd party application ("Facebook/Google/...) took it from you for whatever "reason", those information were not yours to share and you have zero comfort in not being given consent. You have decided, for your friend, that you will share his/hers information with 3rd party application. Due to negligence (you didn't read the "I Agree" text, you didn't care (negligence),... whatever. It really doesn't matter.)
You have two troubles here.
- The application was violating GDPR. Clearly. Without any doubt. They slurped in the PII data from your friends which gave no consent. They might argue that you have misleaded them. In this case all guilt is on you. Unless they are well known for their acts. Which against paints a big red text "negligence" over your forehead.
- YOU were violating GDPR by not taking care for PII of your friend and giving it to 3rd party without consent, approval, anything ("Hey I just took his phone number").
Not only can 3rd party application be held guilty of stockpiling PII without consent, in same manner can YOU be guilty of giving them PII data (oh yeah, "I Agree" button) and your "friend" has all the law support in EU to sue you for this - EU wont, they have larger fish to fry but your friend can and might.
[1] - GDPR defines a controller as: >>> the natural <<< or legal person, public authority, agency or other body which, alone or jointly with others, >>> determines the purposes and means of the processing <<< of personal data