In the US I highly doubt any of that would be illegal save in maybe California. But if I for instance had my email associated with my fediverse account and my friend had my contact name plus my email then meta could ostensibly build a profile out on me without my knowledge or consent. That would only be limited by my friend who might have way, way more interaction with me on the rest of the phone (sms, etc etc) to build an even fuller profile. That’s basically what I’m suggesting. My fediverse account might not say much about me by itself but by linking that and other data courtesy of my friend, I’m now a decently built profile to meta.
There is a python script floating around that will sync your communities, etc. I’d link but don’t have it handy.