Therefore, the most natural way of expressing access control/privacy requirements is to pose constraints on the users social graph.
So, the releasing of a resource is conditioned to the fact that the resource requestor has a relationship (either direct or indirect) of a specific type with other OSN member(s).
However, relationships convey sensitive information in that a user may not want to reveal to other users that he/she holds a relationship of a given type with another user.