Grindr to Pay £26 Million to Settle U.K. Claims Over HIV Status Data Sharing

Grindr, a popular dating app for LGBTQ+ individuals, has agreed to pay £26 million (approximately $32.5 million) to settle claims made by the UK’s Information Commissioner’s Office (ICO) over the sharing of HIV status data without users’ consent. This settlement marks one of the largest fines issued under the UK’s Data Protection Act 2018.

The incident, which dates back to 2021, involved Grindr collecting and processing sensitive health information from its users, including their HIV status, without explicit permission. The app allegedly shared this data with third-party advertisers, sparking concerns about how such information was being used and stored. While Grindr maintained that it did not disclose the specific nature of the data to these parties, the ICO’s investigation found that the company had indeed transmitted sensitive health data, including HIV status.

Grindr operates as a cross-platform service, allowing users to connect with one another via various devices and applications. The app’s architecture enables it to collect user data from multiple sources, including social media profiles, location-based services, and other online platforms. This integration of external data points allows Grindr to build more comprehensive user profiles, but also raises concerns about data handling and consent.

The ICO’s investigation into Grindr’s practices revealed that the company had collected and processed sensitive health information without adequate safeguards in place. The regulator found that users were not adequately informed about how their HIV status would be used or shared, failing to meet the UK’s General Data Protection Regulation (GDPR) requirements for explicit consent.

The £26 million settlement is a significant blow to Grindr, highlighting the importance of robust data protection practices and user consent in the age of digital dating. This incident serves as a stark reminder that even the most well-intentioned companies can inadvertently compromise sensitive information, and it underscores the need for ongoing vigilance and accountability within the tech industry.

As the world becomes increasingly interconnected, users must remain mindful of how their data is being collected, processed, and shared by online services. Grindr’s settlement serves as a cautionary tale about the importance of explicit consent in handling sensitive health information. To protect yourself from similar incidents, always carefully review an app’s terms of service and privacy policies before sharing any personal data, and be wary of services that collect or process sensitive information without your explicit consent.


Source: The Hacker News — 2026-09-08