Grindr settles UK data lawsuit for £26 million, but privacy questions linger
Grindr has agreed to pay £26 million to settle a class‑action lawsuit over alleged sharing of users' HIV status and other personal data. The payout, split into two £13 million instalments, comes after years of regulatory scrutiny and a string of complaints from the LGBTQ+ community.
According to BBC News, the settlement covers more than 11,000 claimants who say the app let third parties access sensitive information before 2020, when the service was owned by Chinese firm Kunlun.
The settlement details
- Total payment: £26 million, in two £13 million tranches.
- First instalment due by 31 December 2024; second by 31 March 2027.
- No admission of liability from Grindr.
- The lawsuit was originally filed in the High Court in 2024 and later served in the United States.
- Law firm Austen Hayes led the claim, describing the alleged data sharing as a breach of UK privacy law.
How Grindr’s data sharing worked
Grindr allowed users to voluntarily disclose their HIV status and the date of their last test. The company said this feature was meant to reduce stigma and help users make health‑related decisions. Internally, the app collected the same data for analytics and advertising purposes. Two external firms—Apptimize and Localytics—were given access to that dataset. The claimants allege that the analytics providers used the information to tailor ads, effectively turning health data into a marketing asset.
In 2018, the practice first came to public attention when journalists reported that Grindr had been sending HIV status, ethnicity, and sexual orientation to the two analytics firms. Grindr defended the approach as industry‑standard at the time but later said it stopped sharing HIV data with those companies.
What the settlement does (and doesn’t) change
The payment resolves the legal claims but does not alter Grindr’s underlying technology. The company’s filing to the U.S. Securities and Exchange Commission notes that it has "overhauled" its privacy practices since 2020, emphasizing user control and transparency. However, the settlement does not require Grindr to provide a detailed audit of current data flows or to submit to ongoing external monitoring.
| Aspect | Pre‑2020 (as alleged) | Post‑2020 (company statement) |
|---|---|---|
| Data shared with third parties | HIV status, ethnicity, sexual orientation sent to Apptimize and Localytics | No HIV data shared; tighter API controls; user‑controlled privacy settings |
| Legal outcomes | £5.5 million fine by Norway’s data protection watchdog; UK ICO reprimand | £26 million settlement (no admission of fault) |
| Ownership | Kunlun (Chinese) | Publicly listed company (since 2022) |
The trade‑off for Grindr is clear: paying a large sum to close the case while keeping its core data‑collection model largely intact. Users gain a public acknowledgment of past mistakes and a promise of improved privacy, but they do not receive any guaranteed protection beyond what Grindr claims to have implemented.
The broader implications for LGBTQ+ tech platforms
Grindr is not the only service that gathers health‑related data from a marginalized community. Apps that facilitate dating, social networking, or health tracking often rely on third‑party analytics to fund free or low‑cost services. The settlement signals that regulators and courts are willing to hold these platforms accountable when sensitive health information is involved.
For competitors, the case underscores the need to separate core community features from commercial data pipelines. Transparent consent mechanisms, clear data‑retention policies, and independent audits can reduce legal risk and preserve user trust.
What to watch next
- Regulatory follow‑up: The UK Information Commissioner’s Office may issue further guidance on health data handling for dating apps. Any new rulings could force Grindr and peers to adopt stricter technical safeguards.
- User‑controlled privacy tools: Look for updates to Grindr’s privacy dashboard, such as granular opt‑outs for analytics or the ability to delete historic health information.
- Litigation trends: Other LGBTQ+ platforms could face similar class actions, especially if they allow users to self‑report health status.
- Market reaction: Investors may monitor whether the settlement affects Grindr’s stock price or prompts a shift in its revenue model away from data‑driven advertising.
Practical steps for users today
- Review your Grindr privacy settings and disable any optional sharing of health data.
- Delete historic health entries if the app permits it; a clean profile reduces the risk of unwanted exposure.
- Consider using a password manager that generates unique passwords for each service, limiting the impact of a single breach.
- Stay informed about updates from Grindr’s privacy dashboard and any new regulatory announcements.
- If you feel your data has been mishandled, keep records of communications and consider joining any future collective actions.



