What happened

Grindr has agreed to pay £26 million, about $35.2 million, to settle a UK group action over allegations that it unlawfully processed users' personal data and misused private information before 2020. The settlement was reached on September 2 and disclosed to investors two days later in a filing with the US Securities and Exchange Commission.

Law firm Austen Hays issued the claim at the High Court of England and Wales on April 22, 2024, and Grindr was served with the proceedings in April 2025. The claim covers HIV status, last tested date and whether users took PrEP, with ethnicity and data relating to sex life or sexual orientation also potentially shared. Austen Hays has said it represents about 12,000 people, all users of the free version of the app between 2016 and 2020.

The allegations reach back to a period when Chinese conglomerate Kunlun owned the company. Grindr disclosed in 2018 that it shared HIV data with two analytics providers, Apptimize and Localytics, and said it stopped after researchers in Norway revealed the arrangement. There is no finding or admission of liability, and Grindr continues to dispute the claims. It will pay £13 million by December 31, 2026 and a further £13 million by March 31, 2027.

Why this is a GRC story

Health, sex life and sexual orientation are special category data under UK law. They carry the highest regulatory and civil exposure, which is why this case is a warning for any company that touches sensitive personal data: practices that look routine at the time, like sharing user data with analytics vendors, can become a group action years later.

The enforcement picture here is cumulative, not one-off. Norway's data protection authority fined Grindr €6.5 million in 2021 over sharing user data for behavioral advertising without a legal basis, a penalty upheld when Grindr lost a challenge in the Oslo District Court in 2024. The UK Information Commissioner's Office separately reprimanded Grindr in July 2022 for failing to give UK users effective and transparent privacy information. Add the £26 million settlement, and one company's historical data practices have produced a fine, a reprimand and civil damages across two jurisdictions.

The ownership angle carries a governance lesson. The practices happened under one owner, and the clean-up happened under the next. Grindr says it has overhauled its privacy program since being sold to new owners in 2020. That is the realistic pattern for many acquired companies: a change of control is a moment when privacy risk gets reassessed, or should be, because legacy data flows rarely die with the old ownership.

What to watch

Watch how the £26 million is distributed among roughly 12,000 claimants, and whether the settlement encourages similar group actions against other apps that shared sensitive data with analytics or advertising vendors. For compliance teams, the practical checklist is short: inventory every third party that receives personal data, confirm a lawful basis for each flow, and treat special category data as a higher-risk process with senior sign-off. The conduct in this claim ended in 2020, but the claim itself was only issued in 2024. Old data practices have a long tail.

Attribution: Analysis based on Infosecurity Magazine's reporting and related public reporting. This article is original commentary, not a repost of the source material.

More daily case studies
← Back to GRC News