Grindr Will Pay £26 Million to End a UK Group Claim That Its Pre-2020 Ad Stack Carried HIV Status

Table of Contents

Grindr Inc. agreed on September 2 to pay £26 million to resolve a group action in the High Court of England and Wales. Austen Hays issued the claim in April 2024 for UK users who said the dating app passed sensitive personal data, in some cases including HIV status, to advertising companies. The company was served in April 2025. A Form 8-K signed after the deal described the period as “historical data practices before 2020,” when Beijing Kunlun Tech owned and controlled the business.

The settlement includes no findings and no admission of liability. Grindr “disputes the allegations” and “recognizes and acknowledges the distress and loss of trust expressed by some of its UK users regarding that pre-2020 period.” It will pay £13 million by 31 December 2026 and another £13 million by 31 March 2027, about $17.6 million per instalment at the September 3 exchange rate the company used, or roughly $35 million in all.

The Guardian reported about 12,000 claimants. Split evenly, that is about £2,167 each before costs. Austen Hays had told users who joined earlier that names would stay off the public record. In 2024 the High Court granted blanket anonymity so the people suing over leaked health and sex-life data would not have to put those facts on an open claim form.

What the claim said left the app

The lawsuit alleged unlawful processing and misuse of private information under UK data protection law. Austen Hays pointed to research published by the Norwegian institute SINTEF in 2018. That work said Grindr’s free app sent data to analytics firms including Localytics and Apptimize. The categories named in later coverage of the claim included HIV status, last test date, sexual orientation, ethnicity, GPS location, device and advertising identifiers.

The Register reported that Austen Hays framed the sharing as opening a path for “a potentially unlimited number of third parties” to target or customise ads. Periods in the claim included activity before 3 April 2018 and between 25 May 2018 (when GDPR applied in the UK) and 7 April 2020. One later summary of the group case put a core window at 20 July 2018 to 7 April 2020 and said seven to ten advertising partners sat in the chain over that stretch.

HIV status and a last-tested date are health data. Under UK GDPR they are special-category personal data. Processing them for advertising needs a lawful basis plus an Article 9 condition. Consent for that use has to be explicit, specific, and separate from the consent to use the app to meet people. A privacy policy that mentioned “analytics partners” is not that consent. That is the legal theory the group action put on the High Court file.

Grindr’s then chief privacy officer, Kelly Peterson Miranda, told Recorded Future News in May 2024 that the suit’s assertion the company sold HIV last-tested dates for advertising was “categorically” untrue. The September 2026 settlement does not resolve that factual dispute. It ends the case.

Regulators had already written this story once

In 2021 the Norwegian Data Protection Authority notified a 100 million kroner penalty over Grindr’s third-party sharing. The fine was later set at 65 million kroner. Norwegian courts upheld it; the appeals court rejected Grindr’s challenge in October 2025. The authority’s core finding was that GDPR consent was not valid for the advertising and analytics disclosures.

In July 2022 the UK Information Commissioner’s Office issued a reprimand after finding UK GDPR infringements. A reprimand is not a fine. It is a public finding that the same fact pattern existed in the ICO’s file.

An Israeli class proceeding over third-party sharing without explicit consent settled in 2025. The UK group claim was the large English follow-on: same special-category theory, a High Court docket, and a claimant list big enough to force a nine-figure pound number into an 8-K.

Grindr said in 2018 that it would stop sharing HIV status with third parties. The UK claim treated later years as still in scope. Whether the 2018 announcement closed the pipe or only the public description of the pipe is what the settlement leaves untried.

Ownership changed. The data history did not vanish.

Kunlun, a Chinese gaming company, owned Grindr through the period the claim covers. In 2020 the Committee on Foreign Investment in the United States pressed a sale over concern that US users’ personal data could be reached by the Chinese state. San Vicente Acquisition bought the company for $608 million and installed new management. Grindr listed in 2022 through a SPAC at a $2.1 billion valuation. Recent coverage put the market value near $2.65 billion. £26 million is a small slice of that cap table. It is not a small number for a privacy group action in England.

Current management’s line is that the conduct is pre-sale and that the privacy programme has been rebuilt “with a keen focus on the unique needs of its community.” The 8-K adds that Grindr “is and remains a safe space for users, committed to transparency, user control and responsible data practices.”

A buyer of an app that stores HIV status, location, and sexual orientation does not buy a clean slate under UK GDPR. The controller of record in 2018 and 2019 is still the controller of that processing. A later owner who settles is paying to close a docket that attached to the product, not only to Kunlun’s letterhead.

Why this case was always about special-category data in the ad request

Most UK app claims about “sharing with advertisers” die on the ordinary-personal-data branch: identifiers, coarse location, device type. This one did not, because the allegation was that a health attribute and a sex-life attribute rode with those identifiers. Once that is pleaded, the case is no longer about whether a privacy notice mentioned SDKs. It is about whether Article 9 ever authorised the disclosure.

Location on a gay dating app is also not ordinary location. Combined with a profile and a health field it can identify a person at a clinic, a bar, or a home. GPS in an ad call is how that inference leaves the app. The High Court’s anonymity order recognised the same risk in reverse: people should not have to publish their names to sue over the publication of their status.

For other consumer apps the lesson is narrow and expensive. If your product collects health, sex life, or sexual orientation, keep those fields out of every advertising and analytics SDK. Contractual “we do not sell health data” language is not a substitute for a network trace. Norway already priced the consent failure. The UK group action priced the private-law follow-through at £26 million and two years of High Court process.

Claimants who joined Austen Hays will now wait on the instalment calendar and on whatever the court requires to approve distribution. Grindr’s public-company filing treats the matter as closed enough to schedule cash. It does not treat the underlying allegation as tried. That is what a settlement without admissions is for.

Written by: 

Online Privacy Compliance Made Easy

Captain Compliance makes it easy to develop, oversee, and expand your privacy program. Book a demo or start a trial now.