.jpg)
.jpg)
Grindr has agreed to pay £26 million to settle a High Court claim brought by roughly 12,000 UK users who alleged the dating app shared their HIV status, testing history and other intimate details with advertising firms without proper consent. The settlement, disclosed in a filing to the US Securities and Exchange Commission, closes a two-year legal dispute without any admission of liability from the company, which continues to dispute the substance of the allegations.
The claim centred on data practices that predate 2020, when Grindr operated under the ownership of the Chinese gaming group Beijing Kunlun Tech. Users alleged that information including HIV status, dates of recent testing and use of PrEP, the HIV prevention regimen, was passed to third-party advertising and analytics companies such as Apptimize and Localytics, allowing those firms to target or customise advertising based on some of the most sensitive personal circumstances a user could disclose. Some material may have reached further still, with claimants alleging onward sharing with additional parties beyond the original recipients.
Under UK data protection law, health information and data revealing sexual orientation fall within a category of "special category" personal data that carries the strictest legal protections available. Processing such data for commercial purposes generally requires explicit, informed consent, a standard that is difficult to satisfy through a buried clause in a terms of service agreement. The claimants, represented by the London firm Austen Hays, argued that no such consent was properly obtained, and that users had reasonably assumed information volunteered on the app would stay within it rather than feeding an advertising pipeline.
Grindr's position, set out in its regulatory filing, is that the settlement resolves the matter without conceding wrongdoing. The company said it disputes the allegations but "recognises and acknowledges the distress and loss of trust expressed by some of its UK users" regarding the pre-2020 period, and pointed to a subsequent overhaul of its privacy practices. The £26 million will be paid in two instalments of £13 million, the first due by the end of this year and the second by the end of March 2027. Divided evenly among the roughly 12,000 claimants, that works out to an average of about £2,167 per person, though individual payouts will depend on the final distribution mechanism.
The case is notable less for its size, which Grindr, now listed on the Nasdaq with a market valuation in the billions, can absorb without much difficulty, than for its timing. The conduct at issue ended more than six years ago, yet it has only now converted into a firm financial liability. That gap illustrates something UK regulators have been signalling for some time: legacy data practices do not become safer simply because the underlying technology has moved on or the company has changed hands. Ad-tech integrations built years ago can resurface as balance-sheet items long after the product decisions behind them have been forgotten by everyone except the users affected and the lawyers willing to pursue a claim.
For companies operating in health-adjacent or identity-sensitive markets, the settlement sharpens an already clear message. Special category data is not a compliance footnote to be managed through generic consent banners; it requires a level of specificity and restraint that many advertising-funded business models were not built around, particularly in the years before UK and EU regulators began enforcing the rules with any real consistency. Group litigation of this kind, still relatively novel in England and Wales, gives that message teeth. It offers claimants a route to redress that does not depend on an individual proving personal loss, and it gives law firms a viable commercial incentive to bring cases on behalf of large, diffuse groups of users who would otherwise have little practical means of holding a platform to account.
The wider effect is likely to be felt in how technology companies handling sensitive personal data assess their own historical exposure, rather than in any immediate change to Grindr's operations. Boards and general counsel across the sector now have a concrete figure to weigh against the cost of auditing old data-sharing arrangements they might otherwise have preferred to leave unexamined.