So manfriday have a GDPR policy and it's all good that it was hosted on FB so it's all their responsibility and manfriday aren't liable at all?
Correct. As FB was the platform and everyone in the group had already signed up to FBs t & cs Man Friday do not need a GDPR policy as long as that data is not taken elsewhere to start a group away from FB.
Why and how was that person able to get that membership list?
ManFriday are a campaigning group they should have had GDPR policies in place to manage a situation like this.
The members list is available to anyone in the group. Its under the "people in this group" tab.
When this person took that info on to twitter they breeched the t &cs of facebook its nothing to do with MF.
MF do not need a GDPR policy if the only place they have a group in on FB. It is covered by FB GDPR.
If MF set up a web page and requested all who joined to give their personel data then yes they would need a GDPR policy but using FB as their platform means they dont.
And the you can give out your own number thing - yes of course you can, but a campaigning organisation, a business, a charity - anyone who isn't using that information for purely personal purposes - is supposed to have a record of your clear and explicit expression of consent to that data being used. I hope manfriday have that.
Unless that info is stored in anyway other way than for personnel use then yes but having peoples number in your phone that they gave you is totally ok. They do not need a GDPR policy to swap numbers for personal use.
There has been no breach of people numbers and emails so I dont see why you are stating they need a policy for this when you have no idea how they store such info or why.