I think they will try to muddy the waters around "externally disclose" rather than "personal data". Specifically, if the advertiser says "send this ad to this list of people if you know of them", then Twitter didn't disclose the user's phone number externally, so that's alright then.

Of course, even if they can pull that one off, they are still stuck with admitting that they processed the personal information not just for the purposes that they said they were going to process it for - and that is a big GDPR no-no.

