Grindr has agreed to pay £26 million ($35.1 million) to settle a UK lawsuit accusing it of sharing users’ personal data, including their HIV status, with third parties for commercial purposes. The Grindr HIV status lawsuit was filed in April 2024 and alleged that the dating app, the largest LGBTQ+ platform in the world, passed on sensitive information to advertisers and other partners without proper consent, in breach of UK privacy law.
The Grindr HIV status lawsuit
UK data protection rules treat health information as a special category: it can only be processed or shared with a user’s explicit, informed consent, not the general terms-of-service agreement most people click through without reading. Grindr’s app has long included a profile field where users can disclose their HIV status. The claim alleged that this data, or attributes derived from it, reached advertising and analytics partners as part of Grindr’s wider commercial data-sharing arrangements, exposing users to risks that go well beyond unwanted adverts, up to and including outing someone to people they never chose to tell.
In practice, sharing with third parties in a case like this usually means the app’s own code, or a software development kit embedded in it, hands profile attributes to ad networks and analytics vendors so they can target or measure adverts. Once a data point like HIV status is packaged into that pipeline alongside a device identifier, it behaves like any other targeting attribute to the systems receiving it, regardless of how sensitive UK law considers it to be. That mismatch between how the data is legally classified and how it is technically handled is the crux of most special-category data claims, not just this one.
The £26 million figure, and its dollar equivalent of $35.1 million, was first reported by The Hacker News. Settling avoids a trial and a public airing of exactly how the data moved between Grindr and its commercial partners, which is usually the part of these cases most useful to anyone trying to understand how the sharing actually happened.
A wider pattern of UK privacy claims
This is not an isolated case. teqpost has been tracking a run of UK claims against platforms accused of passing on user data without properly informed consent, including the third UK App Tracking Transparency lawsuit filed against Apple, which likewise argues that a platform’s stated privacy controls did not stop data reaching third parties. The through-line across both cases is that UK courts are increasingly willing to let large compensation claims over data sharing run their course rather than have the matter absorbed by a regulatory fine alone, which historically has been the more common outcome.
The two cases differ in one important respect. The Apple claim concerns tracking consent generally, while the Grindr case concerns a special category of health data that UK law already singles out for stricter handling, which is likely why the settlement figure here is large enough to be reported on its own terms rather than as a line item in a wider regulatory action.
For Grindr users, the settlement provides financial redress but does not reverse whatever disclosure the lawsuit alleged already took place. Once a field like HIV status has passed into an advertising or analytics pipeline, it cannot be recalled from every system it touched, which is precisely why regulators classify this category of data differently from ordinary browsing or location history and require a higher bar of consent before it can be shared at all.








