Grindr settles U.K. privacy claims over historic HIV status data

Grindr agrees £26 million settlement in U.K. data case
Online dating platform Grindr has agreed to pay £26 million ($35.1 million) to settle U.K. claims alleging that it shared users’ personal information, including HIV status, with third parties. The claims, brought on behalf of more than 10,000 clients, concern historical data practices before 2020, when the company was managed by Kunlun.
In a filing with the U.S. Securities and Exchange Commission dated September 2, 2026, the California-based company said the settlement contains no findings or admission of liability. Grindr said it disputes the allegations but recognises the distress and loss of trust expressed by some U.K. users over the pre-2020 period.
The settlement will be paid in two instalments: £13 million by December 31, 2026, and another £13 million by March 31, 2027. Kunlun, a Chinese gaming company, sold the platform to investor group San Vicente Acquisition LLC in May 2020.
Claims centre on sensitive information and service providers
The dispute follows research published by Norwegian non-profit group SINTEF in April 2018. SINTEF found that Grindr was sharing users’ HIV status and last-tested date with Apptimize and Localytics, two companies engaged to optimise the app. Grindr said soon afterwards that it would stop the practice.
At the time, Grindr said it had never sold, and would never sell, personal user information, particularly HIV status or last-test dates, to third parties or advertisers. It maintained that advertisers had not received that information unless it appeared in a user’s public profile, and said Apptimize and Localytics used the data only to provide services to Grindr.
Grindr said in its 2026 filing that it has revamped its privacy programme since 2020. The company also stressed commitments to transparency, user control and responsible data practices, describing the platform as a safe space for users.
Regulatory context remains significant
The U.K. settlement sits alongside prior action in Norway. In January 2021, Norway’s data protection authority fined Grindr £8.6 million, later reduced to £5.5 million, for violating the General Data Protection Regulation by sharing personal data including location, sexual orientation and mental-health details with advertisers.
Grindr challenged that decision, but Norway’s court of appeal upheld the fine last October. The case illustrates that data connected to health, sexual orientation and location requires careful controls not only for advertising activity but also when organisations engage external providers to operate or optimise their products.
Business implication
Businesses handling sensitive user information should identify every third party that receives it, confirm the purpose of each transfer, and ensure that privacy governance and user controls remain effective as products and ownership structures change.

