Wil's point about companies using information about you that you did not provide, and in fact have no relationship with, business or otherwise, is a more interesting one. For some people, contact information is a very sensitive matter, and celebrities are the uninteresting case, compared to those being stalked, witness protection, etc. How are we going to deal with this?
Especially in light of the fact that the data is essentially unprotectable. It is not often observed that "DRM in general is impossible" doesn't just apply to media conglomerates, but to people as well; there's no way to DRM your phone number or address, either. So that's pretty much out. What's next?
EU law deals with it. It's illegal (and has been for decades) to store personal information about someone unless you have a legitimate, proportionate reasons etc. etc.
Maybe not DRM as DRM, but sure you can protect such things. Just not necessarily with systems in place currently. Conceptually simple solution: unique tokens for your phone / address that a routing system directs to you. Your info is never even in the hands of e.g. someone you buy from, and you can simply revoke the token to prevent any and all spam from now until forever, regardless of what they do with it.
The problem here is not that "DRM in general is impossible" and I fail to see how DRM could solve the issue with Instagram, even if DRM wasn't totally broken. Facebook can access your phone contacts and Instagram can access your photos only with your consent. You're willingly giving them that data.
The far bigger issue here is that services like Instagram can take and use your data without your consent indirectly. If I give your photo or your phone number or your location to some service and that action brings you harm, who's to blame and whom can you sue?
I'm not a lawyer, but I bet it's not going to be Instagram or Facebook or the other offenders out there ;-) And DRM here is meaningless.
You don't own somebody's phone number because you have it in your contact DB. You are willingly giving them the phone numbers of everyone in your phone book... your contacts are not giving their consent to having their data sent wherever.
DRM would, hypothetically, solve the problem of giving your phone number to somebody but not allowing them to share it further without your consent. Except, of course, it doesn't.
By the way, because after years on the net I can see this coming from miles away, let me draw a distinction in advance between "I personally don't care about my number being shared without my knowledge out of other people's contact book to arbitrary third parties", and "I don't think anybody else should ever care about having their number shared out of somebody else's contact list with arbitrary other third parties." They aren't the same thing, and if you want to argue the latter point, that can be done without trying to argue that there isn't any consent issue at all, which is simply false. Whether you consider it right or wrong, some things are happening that some people don't want to occur.
I wasn't trying to defend these services. Instead I believe that such EULAs should be against the law, as the fine print is too subtle to be understood by a majority.
Especially in light of the fact that the data is essentially unprotectable. It is not often observed that "DRM in general is impossible" doesn't just apply to media conglomerates, but to people as well; there's no way to DRM your phone number or address, either. So that's pretty much out. What's next?