www.malwarebytes.com 8 Sept 2026, 12:51 UTC

Grindr Agrees to £26m UK Settlement Over Sensitive Data Sharing

Grindr Agrees to £26m UK Settlement Over Sensitive Data Sharing
CyberSIXT Evidence Panel Source marked as original reporting

GRINDR has agreed to pay £26 million (about $35 million) to settle a UK privacy lawsuit alleging that it shared highly sensitive user data with advertisers, including details such as ethnicity, HIV status, the date of a user’s last HIV test, and whether they used PrEP. The claim, brought on behalf of around 12,000 UK Grindr users by Austen Hays, asserts that these data-sharing practices occurred up to early 2020, when Grindr was controlled by Beijing Kunlun Tech before being sold to US owners in 2020.

The settlement is framed by Grindr as not constituting an admission of liability, with the company acknowledging distress and loss of trust among some UK users regarding that pre-2020 period.

Under the terms disclosed in a US regulatory filing, Grindr will make two payments of £13 million: the first by 31 December 2026 and the second by 31 March 2027. The UK settlement follows a separate enforcement action in Norway, where the Data Protection Authority found that Grindr shared personal data with advertising partners for behavioural advertising without a valid legal basis.

The case highlights how advertising identifiers, IP addresses, locations and other app-related data can combine to reveal intimate information about users, even when such data are not explicitly labelled as medical or sexual-orientation data. Grindr says it has overhauled its privacy programme since 2020 and emphasises user control and responsible data practices going forward.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline