Security News

Grindr Agrees to £26m Settlement Over Historical Data Sharing Allegations

Infosecurity Magazine · 8 Sept 2026
Key Takeaway Australian small businesses handling sensitive customer data, especially health or personal identity information, should audit third-party data sharing arrangements now, since past practices can lead to costly legal exposure years later.

Dating app Grindr has agreed to pay £26m ($35.2m) to settle a UK group action claiming it unlawfully processed and shared users' personal data before 2020, when the company was owned by Chinese conglomerate Kunlun. The settlement was reached on September 2 and disclosed to investors days later. Grindr will pay the sum in two instalments by March 2027 and has not admitted liability, continuing to dispute the allegations.

The claim, filed by law firm Austen Hays in April 2024 on behalf of roughly 12,000 people, alleged Grindr shared highly sensitive information, including HIV status, testing dates, PrEP use, ethnicity and sexual orientation, with third parties without adequate consent. This echoes Grindr's 2018 disclosure that it had shared HIV data with two analytics providers, a practice it stopped after researchers exposed the arrangement. Under UK data protection law, health and sexual orientation data receive special protection, meaning unlawful sharing of such information carries significant legal and regulatory risk.

Grindr said it was sold to new owners in 2020 and has since overhauled its privacy practices. The case highlights the long-term liability businesses can face for how they historically handled sensitive customer data, even years after the practices in question have ended.

data privacy GDPR third-party risk sensitive data regulatory compliance
Carrying this risk through a supplier? Assessing third-party and supply chain security ->

Summarised by CISO AI from Infosecurity Magazine. We link back to every original so you can read it yourself.