Grindr has agreed to pay £26m ($35.2m) to settle a UK group action over allegations it unlawfully processed users' personal data and misused private information before 2020, the company disclosed in an SEC filing.
£26m settlement and payment schedule
The settlement was reached on September 2 and disclosed two days later in a filing with the US Securities and Exchange Commission. Under the agreement, Grindr will pay £13m ($17.6m) by December 31, 2026 and a further £13m by March 31, 2027. The company said the agreement contains no finding or admission of liability and that it continues to dispute the allegations.
Austen Hays' allegations: HIV status, PrEP, ethnicity and more
The claim was issued by law firm Austen Hays at the High Court of England and Wales on April 22, 2024. Austen Hays alleges Grindr shared sensitive personal data with third parties without adequate consent. Specifically, the firm said the claim covered HIV status, last tested date and whether users took PrEP, and that ethnicity and data relating to sex life or sexual orientation were also potentially shared. The action, Austen Hays said, related to users of the free version of the app between 2016 and 2020. Grindr said it was served with the proceedings in April 2025.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleGrindr's ownership period under Kunlun and the company's response
Grindr told investors the claim related to historical data practices from a period when the company was owned and controlled by Chinese conglomerate Kunlun. The company has said it was sold to new owners in 2020 and has since overhauled its privacy program. Grindr's filing acknowledged the distress and loss of trust expressed by some UK users over the pre-2020 period while continuing to dispute the claims themselves.
Regulatory history: Norway fine and UK Information Commissioner's Office reprimand
The settlement closes long-standing, historical privacy claims amid prior regulatory action. Grindr disclosed in 2018 that it shared HIV data with two analytics providers, Apptimize and Localytics, and said it stopped after researchers in Norway revealed the arrangement. Norway's data protection authority fined Grindr €6.5m in 2021 over sharing user data for behavioral advertising without a legal basis; that penalty was upheld when Grindr lost a challenge in the Oslo District Court in 2024. Separately, the UK Information Commissioner's Office reprimanded the company in July 2022 for failing to give UK users effective and transparent privacy information.
What this means for claimants, UK users, and Grindr
- Claimants: Austen Hays has said it represents about 12,000 people. That figure would yield an average of roughly £2,167 ($2,928) per claimant if the settlement were divided equally; the firm and Grindr have not confirmed the distribution method.
- UK users: The claim focuses on sensitive categories that UK data protection law treats as specially protected—health, sex life and sexual orientation—which the company acknowledged could explain user distress and loss of trust around the pre-2020 practices.
- Grindr: The company emphasizes the settlement addresses historical practices and notes a change of ownership in 2020 followed by a privacy program overhaul. Grindr also maintains it disputes the allegations and the settlement contains no admission of liability.
The settlement resolves a high-profile group action that hinges on what the law treats as among the most sensitive categories of personal data. It also leaves open practical questions the public record has not yet answered: how exactly the roughly £26m will be allocated among claimants and whether the settlement will alter any subsequent regulatory or civil actions. Grindr's staggered payment schedule fixes deadlines for the company—December 31, 2026 and March 31, 2027—while preserving the company's denial of liability even as it moves to close historical claims.
Original story: https://www.infosecurity-magazine.com/news/grindr-settles-uk-data-privacy/




