News Uk

Grindr is paying £26m over UK data claims. Here is what that means for your phone

Grindr has settled a UK group action over pre-2020 data sharing that allegedly included users' HIV status. No liability was admitted. The useful question is what the case says about the data dating apps still hold.

By TrueQueer
A smartphone lying face up with its screen lit

Grindr has agreed to pay £26 million — around $35 million — to settle a group action in the High Court of England and Wales brought on behalf of UK users over data practices from the period up to early 2020. The claim alleged that the app shared sensitive personal information, including users’ HIV status, with third parties. The settlement includes no finding or admission of liability.

The company disclosed the resolution in an 8-K filing with the SEC dated 2 September, confirming two instalments of £13.0 million each — the first due by 31 December 2026, the second by 31 March 2027. PinkNews reported the settlement on 7 September and the Washington Blade followed on 9 September.

What the claim actually alleged

The proceedings were issued in April 2024 and served on Grindr in April 2025. They concern conduct from before 2020, when the app was owned and controlled by the Chinese conglomerate Kunlun — a point Grindr’s filing makes twice.

The underlying allegations draw on research published by the Norwegian research institute SINTEF in 2018, which examined data flowing from Grindr to third-party analytics firms. The categories at issue included HIV status and last test date, sexual orientation and GPS location. Grindr has consistently disputed the allegations. In its filing the company said that while it disputes them, it “recognizes and acknowledges the distress and loss of trust expressed by some of its UK users” about that period, and pointed to an overhaul of its privacy programme since 2020 under new ownership and management.

That is about as close to an apology as a no-liability settlement gets, and it is worth noting the distinction: Grindr is paying for a period it no longer controls, under a corporate structure that no longer exists, without conceding the claim.

Why HIV status is not just another data field

For anyone who has never had to think about it, it is easy to file this under general privacy annoyance. It is not.

HIV status is special category data under UK and EU law precisely because disclosure can cost people jobs, housing, custody arrangements, immigration outcomes and physical safety. A person’s HIV status can be inferred from far less than an explicit field — a last-test date, a set of app behaviours, a location trail that includes a sexual health clinic. In a country where being gay is criminalised, the same trail is evidence. This is why the queer data privacy conversation is never really about targeted ads.

The claim covers roughly 10,000 to 12,000 UK claimants, depending on which count you take. The number of people whose data moved through those pipelines in that period was very much larger.

What this changes in practice

Honestly? For your phone today, not much directly. Settlements of historical claims do not alter anything currently running on your device. But the case is a useful prompt for a few things that are worth doing regardless of which apps you use.

Check what the app knows that it doesn’t need to. Health and status fields on dating profiles are optional on every major app. If you have filled one in, it exists in a database, and databases are breached, subpoenaed and sold. Decide deliberately whether the convenience is worth it, rather than by default because a signup flow asked.

Turn off ad personalisation and third-party sharing where the setting exists. Most apps now offer it under privacy or data settings, largely because of UK GDPR and equivalent rules. It is a two-minute job that measurably reduces how many companies hold a profile of you.

Treat location as the sensitive field it is. Distance display is the core mechanic of proximity-based apps, but most offer an option to hide precise distance. If you are travelling — and especially in the 60-plus jurisdictions that still criminalise same-sex conduct — use it. Several apps also have discreet-icon and PIN-lock options built specifically for border crossings.

Assume nothing on a dating app is ephemeral. Photos, messages and “deleted” profiles frequently persist on servers. Ask for your data under a subject access request if you want to know what is actually held; UK and EU users have that right and companies have to answer within a month.

The broader pattern

The reason this settlement is significant is not the money. £26 million is real but it is not existential for a New York Stock Exchange-listed company, and it is spread across two payment dates fifteen months apart.

It is significant because group actions are becoming a functional enforcement route for data misuse in the UK at a moment when the queer risk profile is rising rather than falling. Governments in several countries have shown active interest in identifying LGBTQ+ people through data — through medical records, through platform records, through purchase histories. The infrastructure that once served adtech serves surveillance just as well. An app’s 2018 decision to pipe HIV status into an analytics tool was, at the time, treated internally as a routine integration. It took six years, a High Court claim and £26 million to establish that it was not.

The practical lesson for users is not to abandon the apps. They remain, for a lot of people in a lot of places, the only reliable way to meet other queer people at all. It is to use them the way you would use any service that holds something that could be used against you: deliberately, with the optional fields left blank, and with the settings checked once a year rather than never.

grindrprivacyhivukdata protection

Related Articles

More in News →