Skip to main content
ComplianceData Protection

Grindr Settles UK Data Suit for $35 Million Over HIV Status Sharing

Serene UK courthouse scene with blurred smartphone on bench.

"The settlement includes no findings or admission of liability," read the filing.

What Grindr agreed to pay and when

Grindr has opted to pay £26 million ($35.1 million) to resolve a U.K. lawsuit alleging the company shared users' personal information, including HIV status, with third parties. Under the settlement disclosed in a filing with the U.S. Securities and Exchange Commission on September 2, 2026, the company will pay £13 million to the counterparties by December 31, 2026, and a further £13 million by March 31, 2027.

The claims: a class action over pre‑2020 data practices

The suit, filed in April 2024 on behalf of more than 10,000 clients, accused the dating platform of violating U.K. privacy laws by sharing sensitive data for commercial purposes such as advertising. Grindr said the settlement relates to historical data practices that took place before 2020, when the app was managed by the Chinese gaming company Kunlun.

How the alleged sharing was first exposed

The controversy traces back to April 2018, when the Norwegian non‑profit research group SINTEF discovered that Grindr was sharing users' HIV status and last tested date with two analytics firms, Apptimize and Localytics, which Grindr had enlisted to optimize its apps. Grindr responded at the time by saying it would halt the data‑sharing practice and insisted that "Grindr has never sold, nor will we ever sell, personal user information – especially information regarding HIV status or last test date – to third parties or advertisers." The company added that "No advertisers have ever had access to HIV status or last test date, unless they viewed it in your public profile," and that the HIV status and last test date information was used by Apptimize and Localytics only to provide services to Grindr.

Corporate handoff and Grindr's position

The SEC filing notes the disputed practices relate to the period before a change in ownership: Kunlun sold the online platform to an investor group named San Vicente Acquisition LLC in May 2020. In the filing, Grindr said it disputes the allegations but "recognizes and acknowledges the distress and loss of trust expressed by some of its U.K. users regarding that pre‑2020 period." The company also said it has revamped its privacy program as of 2020 and emphasized that the platform "remains a safe space for users," committing to transparency, user control, and responsible data practices.

Regulatory actions in Norway and appellate outcome

Separate from the U.K. litigation, Norway's data protection authority originally fined Grindr £8.6 million in January 2021 for violating the General Data Protection Regulation by sharing personal data — including location, sexual orientation, and mental health details — with advertisers. That fine was later reduced to £5.5 million. Grindr challenged the decision, but Norway's court of appeal upheld the fine last October.

What this means for U.K. users, dating‑app operators, and regulators

  • U.K. users: More than 10,000 clients were represented in the claim; the settlement acknowledges user distress over pre‑2020 practices and provides a timetable for compensation payments, though it includes no admission of liability.
  • Dating‑app operators: The case — and the earlier SINTEF finding — underscores scrutiny on how sensitive profile fields (HIV status, last test date) are handled with analytics vendors; Grindr says it revamped its privacy program after 2020.
  • Regulators: The Norway fine, its reduction, and the subsequent appeal decision that upheld the penalty demonstrate active enforcement of data‑protection rules in cross‑border privacy cases involving dating apps.

Grindr remains described in the material as the largest LGBTQ+ dating app, and the company stresses it never sold personal user information. The settlement closes one chapter of litigation over historical practices while leaving open the reputational and regulatory aftershocks: payments are scheduled by the end of 2026 and early 2027, and the mix of civil litigation and regulatory penalties — including the upheld Norway fine — will likely remain a reference point for how sensitive profile data is treated going forward.

Original story