So it's a bunch of EU Germans receiving payment for downloading your entire social graph and click-jacking your facebook session (this looks to be a chrome extension that would have access to everything, not something that uses even the marginally-permissioned oauth API).
1. Where is the GDPR privacy notice?
2. In light of all the cambridge analytica fallout, where is ANY privacy notice?