The short version
- Grindr has agreed to a £26 million settlement to resolve a class-action lawsuit regarding the unauthorized sharing of user data.
- The claims focus on historical practices prior to 2020 when the company was owned by Kunlun, involving third-party analytics providers.
- The agreement includes no admission of liability but acknowledges distress caused to users whose private health and identity information was exposed.
Grindr, the prominent LGBTQ+ dating application, has reached a financial settlement to resolve legal challenges concerning the handling of sensitive user data. The company agreed to pay £26 million to address allegations that it shared personal information with external entities without adequate consent. This resolution concludes a protracted legal dispute that began in 2024 when a class-action suit was filed in the High Court, later expanding to include claims served in the United States.
The lawsuit, led by the law firm Austen Hayes, alleged that Grindr violated UK privacy regulations by distributing private details for commercial purposes. The data in question included highly sensitive information such as users' HIV status, ethnicity, and sexual orientation. According to regulatory filings submitted to the US Securities and Exchange Commission, the settlement was finalized on September 2, with payments structured in two installments of £13 million each.
The first payment is due by the end of December, while the second will be made by March 31, 2027. Grindr explicitly stated that this financial agreement does not constitute an admission of liability. However, the company acknowledged the significant distress and erosion of trust experienced by some users in the United Kingdom regarding data practices employed during a specific historical period.
The controversy centers on data sharing practices that occurred before 2020, when Grindr was owned by the Chinese firm Kunlun. During this time, the app shared user data with two data analytics services: Apptimize and Localytics. Revelations in 2018 indicated that these third parties had access to sensitive health information, including HIV status, which users could optionally share on their profiles to facilitate informed health choices and reduce stigma.
At the time of the initial disclosures, Grindr defended its actions as consistent with industry standards for data analytics. The company subsequently ceased sharing HIV-related data with these specific providers. Nevertheless, the allegations suggest that a potentially unlimited number of third parties may have utilized this information to customize advertisements targeted at Grindr's user base, raising serious concerns about commercial exploitation of private health metrics.
Legal representatives for the claimants emphasized the severity of the breach. Chaya Hanoomanjee, the lawyer leading the case, noted that individuals experienced significant distress due to the non-consensual sharing of their private information. She argued that the company has a responsibility to compensate those within the LGBTQ+ community whose data security was compromised, framing the settlement as a necessary step toward accountability.
Regulatory bodies had previously scrutinized Grindr's data practices. In 2022, the UK Information Commissioner's Office reprimanded the company for its handling of user data. Additionally, Norway's data protection watchdog imposed a fine of £5.5 million related to similar privacy violations. These regulatory actions preceded the current settlement but underscored ongoing concerns about how the platform managed sensitive personal information.
Grindr has since undergone significant changes in ownership and operational structure. The company became publicly listed in 2022, two years after being acquired by new owners who replaced Kunlun. In its recent filing, Grindr stated that it had overhauled its privacy protocols since 2020 to better meet the unique needs of its community. The firm maintains that it remains committed to transparency, user control, and responsible data management.
The settlement marks a significant financial and reputational milestone for the app, which serves millions of users globally. While Grindr disputes the core allegations, the agreement reflects a recognition of the harm caused by past practices. The resolution provides compensation to over 11,000 claimants who joined the suit, offering some measure of redress for those affected by the historical data breaches.
Moving forward, the focus shifts to ensuring that current privacy safeguards remain robust and effective. Grindr's commitment to maintaining a safe space for its users will be tested by continued scrutiny from regulators and the public. The case highlights the broader challenges faced by digital platforms in balancing commercial interests with the protection of sensitive personal data, particularly within marginalized communities.
Sources behind this briefing
Go to the original reporting
- BBC World↗Grindr to pay £26m to settle claims it allegedly shared users' HIV status