Back to Feed
Privacy FinesSep 8, 2026

Grindr to Pay £26 Million to Settle U.K. Claims Over HIV Status Data Sharing

Grindr to pay £26 million to settle UK lawsuit over sharing HIV status data.

Summary

Dating app Grindr will pay £26 million to settle a UK lawsuit alleging it shared users' sensitive personal information, including HIV status, with third parties for commercial purposes. The lawsuit, filed in April 2024, covers historical data practices before 2020. Grindr disputes the allegations but acknowledges user distress and has since revamped its privacy program.

Full text

Grindr to Pay £26 Million to Settle U.K. Claims Over HIV Status Data Sharing Ravie LakshmananSep 08, 2026Data Privacy / Regulation Online dating app Grindr has opted to pay £26 million ($35.1 million) to settle a lawsuit in the U.K. over allegations that it shared users' personal information, including their HIV status, with third-parties. Grindr, which is the largest LGBTQ+ dating app, was sued in April 2024, accusing it of violating U.K. privacy laws by sharing sensitive data for commercial purposes such as advertising. The claims were brought on behalf of more than 10,000 clients. According to a filing with the U.S. Securities and Exchange Commission on September 2, 2026, the California-based company said it settled the suit related to historical data practices before 2020, when it was managed by Kunlun. The Chinese gaming company sold the online platform to an investor group called San Vicente Acquisition LLC in May 2020. "The settlement includes no findings or admission of liability," read the filing. "While Grindr disputes the allegations, it recognizes and acknowledges the distress and loss of trust expressed by some of its U.K. users regarding that pre-2020 period." The company also said it has since revamped its privacy program as of 2020 and emphasized that the platform "remains a safe space for users," while committing to transparency, user control, and responsible data practices. As part of the settlement, Grindr has agreed to pay £13 million to the counterparties by December 31, 2026, and a further £13 million by March 31, 2027. It all goes back to April 2018, when a Norwegian non-profit research group SINTEF uncovered that Grindr was sharing users' HIV status and last tested date with two companies, Apptimize and Localytics, enlisted to optimize its apps. Soon after, the company said it would halt the data sharing practice. "Grindr has never sold, nor will we ever sell, personal user information – especially information regarding HIV status or last test date – to third parties or advertisers," Grindr insisted at the time. "No advertisers have ever had access to HIV status or last test date, unless they viewed it in your public profile. The HIV status and last test date information was used by Apptimize and Localytics only to provide services to Grindr." In January 2021, Norway's data protection authority fined Grindr £8.6 million (later reduced to £5.5 million) for violating the General Data Protection Regulation (GDPR) by sharing personal data, such as location, sexual orientation, and mental health details, with advertisers. Grindr challenged the decision but Norway's court of appeal upheld the fine last October. Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE     Tweet Share Share Share SHARE  data privacy, mobile security, Regulation ⚡ Top Stories This Week Attackers Exploit Critical Langflow and Rails Flaws in Credential-Probing and C2 Activity Iranian Hackers Pose as Recruiters to Deliver Cross-Platform RATs Through Coding Tests ⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flaw Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code Thousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordination Channel Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters PostgreSQL Fixes 12-Year-Old Logical Decoding Flaw Enabling Replication-Role Code Execution New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic Google Releases Chrome Update to Patch Actively Exploited V8 Zero-Day ThreatsDay: CEO Phishing Kits, 5K Dropbox Account Hacks, OAuth Traps + 17 More Stories Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root Thomson Reuters Court Software Breach May Have Exposed SSNs and Sealed Data Pegasus Zero-Click Spyware Exploit Infects Serbian Student Movement Member's iPhone Researcher Releases FalconFlank PoC Showing Privilege Escalation in CrowdStrike Falcon Fake Software Installers Disable Windows Update and Weaken Microsoft Defender Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code Meta Ads Push StreamRat Android Trojan That Can Gain Near-Complete Device Control Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain GeoNetwork Fixes Unauthenticated RCE Chain Affecting Government Geoportal Backends Researchers Use Claude to Port Pre-Auth RCE Exploit From One PLC Model to Another ⭐ Featured Resources See How Keeper Secrets Manager Removes Hard-Coded Credentials Download the CISO's Guide to Smarter AI Security Investment Phishing Is Costing Security Teams More Than Ever — Read the New Report Build AI Agents and Automations Without Losing Security Control

Entities

Grindr (product)