Grindr Reaches £26 Million Settlement in UK Data Privacy Lawsuit
Grindr has agreed to pay £26 million (approximately €30.5 million) to settle a group-action lawsuit in the United Kingdom. The case was brought forward by 12,000 users who alleged the dating app unlawfully shared their sensitive personal data, including in some cases their HIV status, with advertising companies.
The settlement marks the end of a two-year legal challenge led by the law firm Austen Hays. The claim, filed in April 2024, focused on Grindr's data handling practices up to early 2020, arguing that the company had violated UK data protection laws. If the settlement is distributed evenly, the claimants would receive an average of around £2,167 each.
Grindr Points to "Historical Practices"
In a statement, Grindr confirmed it had resolved the legal action but noted that the settlement includes "no findings or admission of liability." The company attributed the issues to "historical data practices before 2020," a period when Grindr was owned by the Chinese gaming firm Beijing Kunlun Tech. Following concerns from a US national security panel about potential data access by the Chinese government, Grindr was sold to a US-based investment group in 2020 and has since appointed new management.
The company stated it has since overhauled its privacy program with a "keen focus on the unique needs of its community," and that it remains "a safe space for users, committed to transparency, user control and responsible data practices."
A Pattern of Privacy Concerns
This is not the first time Grindr has faced scrutiny over its handling of user data in Europe. In 2021, Norway’s data protection authority fined the company 65 million Norwegian krone (around €6 million at the time) for similar data protection violations. That fine was later upheld by a Norwegian court of appeal, which described Grindr's claim that it did not sell user information for advertising as "clearly misleading."
While this lawsuit was filed in the UK, the case is a significant reminder of data protection rights across Europe, including in the Netherlands, under the General Data Protection Regulation (GDPR). The handling of sensitive health information requires explicit user consent, and this settlement serves as a precedent for how such breaches may be handled for apps widely used within the LGBTQ+ community.