Grindr to Pay £26M Over U.K. HIV Status Data Sharing Claims

Dating app Grindr has reached a £26 million (approximately $35.1 million) settlement of U.K. legal claims alleging it improperly shared users’ personal HIV status and related data with third parties. The case, filed in April 2024, represents over 10,000 U.K. users who accused Grindr of breaching privacy laws for commercial gain. The company has denied the claims but agreed to resolve the matter without admitting liability.

Legal Origins & Key Allegations

The lawsuit stems from operations before 2020, during a period when Grindr was owned by Beijing-based Kunlun. Claimants argued the company shared sensitive HIV status and last-tested date information with analytics firms like Apptimize and Localytics to optimize performance and target ads. These practices were reportedly uncovered in April 2018 by SINTEF, a Norwegian research non-profit.

Grindr has stated that such data sharing was ceased shortly after discovery. The company also emphasized that advertisers did not access users’ HIV or test date data unless it appeared in public profiles. Grindr further noted it has since overhauled its privacy program following its acquisition by an investor group, San Vicente Acquisition LLC, in May 2020.

Settlement Details & Penalties

The resolution requires Grindr to pay £13 million by December 31, 2026, and another £13 million by March 31, 2027. The legal action focused exclusively on historical practices before 2020. In a U.S. Securities and Exchange Commission filing, Grindr clarified its agreement does not amount to an admission of wrongdoing, but acknowledged the harm to user trust caused by the pre-2020 behavior.

Earlier enforcement in Norway spotlighted similar privacy concerns. In January 2021, Grindr was fined £8.6 million (later reduced to £5.5 million on appeal) under GDPR rules for transmitting personal data—including sexual orientation, location, and mental health statuses—to advertisers. That decision was upheld in 2025.

The U.K. case was brought by Austenhays Solicitors. The company represents a large group of claimants alleging violations of statutory privacy protections relating to sensitive data, a category given special status under data protection laws. The case underlines regulatory focus on how apps collect, use, and share health‐related information.

Grindr says its platform now emphasizes transparency, user control, and responsible data handling. The app stresses its commitment to safeguarding users’ sensitive information moving forward.

***Analytical Angle***
Grindr’s settlement illustrates how privacy misuse—especially involving health and sexual orientation—remains among regulators’ highest priorities. Even in the absence of admitted liability, the financial, reputational, and legal stakes are significant. Businesses relying on data collection must ensure policies match operations, especially where past practices fall under renewed scrutiny. For users, this case reinforces the need to understand what personal info is shared—and how apps are held to evolving standards in data protection.