Something sure is that when they (OP app) starts sending mail or SMS to user contact to shame him/her, it will definitely be unsolicited mail/sms.
Imagine you have a friend in debt and start receiving such notices ? They’re collecting private information on you (your name, your phone number or your email) without your consent.
IANAL but I’m pretty confident it falls under GDPR.
(Sans parler du fait que les mecs qui font ça sont quand même une belle bande d’enfoirés)