Grindr will pay £26 million to settle a UK privacy lawsuit involving about 12,000 users who alleged the dating app shared highly sensitive information, including HIV status and testing data, with third-party companies without adequate consent.
The settlement ends a two-year group action in the High Court of England and Wales over Grindr’s data practices through early 2020. Grindr disclosed the agreement in a U.S. regulatory filing and said it will pay £13 million by December 31 and another £13 million by March 31, 2027.
The agreement contains no finding or admission of liability.
London law firm Austen Hays filed the first claim in April 2024. The firm alleged that Grindr shared users’ personal and sensitive information with third-party companies, including software vendors Localytics and Apptimize.
The information allegedly included users’ HIV status, the date they were last tested for HIV, whether they used pre-exposure prophylaxis, commonly known as PrEP, their ethnicity and information concerning their sex lives or sexual orientation.
Under the UK General Data Protection Regulation, health information, racial or ethnic origin, sex life and sexual orientation are treated as special category data and receive additional protection. Organizations processing that information need a lawful basis as well as a separate legal condition permitting them to handle the sensitive data.
The Grindr users alleged the company lacked adequate consent for the way their information was processed and shared.
Grindr disputes the allegations. In its filing, the company described the case as involving “historical data practices before 2020,” when Grindr was owned and controlled by Chinese gaming company Beijing Kunlun Tech.
The company said it recognizes the distress and loss of trust expressed by some UK users and has overhauled its privacy program since changing ownership and management in 2020.
Questions over Grindr’s handling of HIV information drew widespread attention in 2018, when research by Norwegian nonprofit SINTEF found that the app was sending information including users’ HIV status and last HIV test dates to software companies Apptimize and Localytics.
Grindr said the vendors operated under contractual confidentiality and security requirements and later announced that it would stop sharing HIV-status information with the companies.
The platform later faced scrutiny from Britain’s privacy regulator.
The UK Information Commissioner’s Office reprimanded Grindr in July 2022 after finding that it had failed to provide effective and transparent privacy information to UK users about the processing of their personal data.
The ICO investigation, which examined processing from June 2020 onward, identified problems with Grindr’s explanations of its legal bases for processing data and the information shared with third-party advertising partners. The regulator recommended clearer disclosures about profile information, advertising partners, IP addresses and advertising identifiers.
Austen Hays has said the claims involved approximately 12,000 Grindr users. The firm alleged that the disputed data practices violated UK privacy and data protection laws and caused users distress over the handling of highly personal information.
The £26 million settlement resolves those claims without a court judgment on whether Grindr violated UK privacy law. Grindr will make the first half of the payment by the end of 2026, with the remaining £13 million due by March 31, 2027.