Grindr Settles UK Class Action for £26 Million Over Data Privacy Violations
In a significant legal development, dating app Grindr has agreed to a settlement of £26 million to resolve a class action lawsuit in the United Kingdom. This lawsuit accused the company of improperly disclosing sensitive user data to third parties, violating UK data protection laws. The settlement will be executed in two separate payments of £13 million, scheduled for December 2026 and March 2027.
The class action was initiated in April 2024 in England’s High Court by the law firm Austen Hays. It drew upon research conducted by SINTEF in 2018, which ensured attention to Grindr’s data sharing practices. The lawsuit alleged that Grindr shared sensitive information such as users’ HIV status, last test dates, sexual orientation, and GPS locations with analytics companies Localytics and Apptimize. These actions raised concerns about privacy and user safety, particularly regarding how third parties could leverage this data for targeted advertising or other purposes.
The allegations indicated that these violations of privacy occurred in two distinct periods: prior to April 3, 2018, and between May 25, 2018, and April 7, 2020. According to SINTEF’s research, the implications of such data-sharing were substantial, enabling numerous parties to customize their advertising towards Grindr users based on deeply personal and sensitive information.
While Grindr disputes the allegations, it has acknowledged the distress and erosion of trust experienced by its UK user base regarding the issues highlighted for the pre-2020 period. The company noted in its SEC Form 8-K filing that many of the challenged practices took place when it was owned by the Chinese firm Kunlun. Significant regulatory pressures led to a sale mandated by the Committee on Foreign Investment in the United States. Since the change in ownership, Grindr has asserted that it has revamped its privacy protocols to better align with the specific needs of its community.
This settlement is notably larger than a prior fine imposed by Norwegian regulators, who had issued a 65 million kroner penalty (approximately £5 million) in December 2021. The fine was aimed at penalizing Grindr for GDPR violations concerning the unauthorized sharing of user data with advertising partners. Norwegian regulations classified identifying someone as a Grindr user as special category data related to sexual orientation, intensifying the implications of such data misuse. Grindr faced numerous unsuccessful appeals in this case, including judgments from Norway’s Privacy Appeals Board in 2023 and the Oslo District Court in 2024, concluding with a ruling from the Borgarting Court of Appeal in October 2025.
As part of the recent settlement, it is important to note that Grindr has not admitted to any wrongdoing or liability. The company expressed its continued commitment to transparency, user agency, and responsible data handling practices. It positions itself as a safe environment for its LGBTQ+ community, striving to rebuild trust among its users and address concerns surrounding data privacy.
The case underscores the increasing scrutiny that dating applications face in how they manage sensitive personal data. It highlights a broader trend of vigilance over privacy issues, particularly data that might expose users’ sexual orientation or health-related information. As awareness grows and technology evolves, there is a growing expectation from users that their personal data will be protected in a manner consistent with their privacy rights.
In conclusion, while Grindr maintains its stance of innocence in the ongoing situation, the financial settlement serves as a stark reminder to all dating services about the critical importance of robust data privacy practices. As legal frameworks continue to strengthen in favor of user rights and data protection standards, the implications of this case will likely resonate beyond the app itself, influencing the operations and policies of similar platforms in the industry.
