Light bulb Limited Spots Available: Secure Your Lifetime Subscription on Gumroad!

Sep 10, 2026 · 7 min read

Grindr Pays $35M Over Shared HIV Status Data

Grindr has said for eight years that it never sold health data to advertisers. That was never quite the accusation, and it was never the legal question either.

In February 2018, researchers at the Norwegian institute SINTEF pointed a traffic analyzer at Grindr. Buried in the outbound payloads sat a field carrying users' HIV status, travelling alongside a phone identifier, an email address and GPS coordinates to two vendors nobody had heard of. Grindr's chief technology officer called it "standard practices in the mobile app ecosystem." Eight years later, the company will pay £26 million to close a UK claim about it.

Key Takeaways

  • Grindr disclosed a £26 million settlement, about $35.2 million, in an SEC filing dated September 4, 2026, payable in two £13 million installments due December 2026 and March 2027, per The Record.
  • Austen Hays filed the claim in the High Court of England and Wales in April 2024 for roughly 12,000 users, alleging HIV status and last tested dates reached third parties before early 2020, under Beijing Kunlun Tech's ownership.
  • The deal records no admission of liability and works out at about £2,167 per claimant, nearly three times the £750 per head Richard Lloyd sought from Google in the action the Supreme Court rejected in 2021.
  • Norway's Datatilsynet fined Grindr NOK 65 million, roughly $7 million, in December 2021 — meaning this private settlement costs five times the company's largest regulatory penalty.

What Does the Settlement Actually Cover?

One UK group claim, brought by about 12,000 named individuals over historical sharing of HIV status data. Nothing else.

Austen Hays, now part of Gateley, issued proceedings in April 2024. The parties settled on September 2, 2026, and the deal surfaced two days later in an SEC filing. Grindr disputes the allegations but acknowledges "the distress and loss of trust expressed by some of its UK users."

No regulator decided anything here, so there are no published findings and none of the compliance orders bolted onto CNIL's €500,000 fine against a French hospital last week. It is a payment that makes a case go away.

Why "We Never Sold It to Advertisers" Is Not a Defense

Because the GDPR prohibits disclosing health data to anyone at all, including a paid vendor following your instructions, unless a specific condition applies. "We did not monetize it" is not a condition.

Grindr's former chief privacy officer, Kelly Peterson Miranda, said in 2024 that "we have never used users' health-related information for any type of advertising purposes." Take that at face value; the test does not turn on purpose of use. Article 9(1) of the General Data Protection Regulation bans processing of health data outright, and processing expressly includes disclosure by transmission. Lawful disclosure needs an Article 6 lawful basis plus two things that routinely get skipped.

  • An Article 9(2) condition lifting the prohibition. For a consumer app that means 9(2)(a), explicit consent, a higher bar than ordinary consent.
  • An Article 28 processor contract governing instructions and onward subprocessing.

Encryption sits somewhere else. It is an Article 32 security measure, and Article 32 asks whether data was protected in transit, not whether sending it was allowed at all. The ICO's guidance on special category data is blunt: the condition comes first.

What Is a "Third Party Service Provider" Here?

In the 2018 reporting that started all of this, it meant two mobile analytics and A/B testing platforms: Apptimize and Localytics.

Neither was an ad network. BuzzFeed News first reported the SINTEF findings, and Grindr said the data supported a feature letting users display HIV status on their profile. Plausible, and the entire problem. An experimentation SDK does not choose what it receives; if the profile object under test carries a health field, the health field ships too. Grindr later told NPR it had pulled the data from Apptimize.

Most coverage skips the lesson. Sensitive attributes rarely leak because someone signed a data sale. They leak through vendor plumbing, dragging a whole object across a boundary nobody drew — the same shape as the Meta pixel deployments that put patient data onto ad platforms, firing on pages nobody thought of as clinical.

A grey steel filing cabinet in a dim records room with one drawer pulled slightly open revealing unlabeled folders, a brass lock on the drawer face and a key resting on top

Why £26 Million for 12,000 People Is the Number to Watch

It works out at roughly £2,167 per claimant before legal costs and the funder's cut, and that per head rate is what decides whether the next claim gets funded.

Set it against the case that supposedly killed mass privacy litigation in England. Richard Lloyd sued Google for 4.4 million iPhone users over the Safari Workaround, seeking a uniform £750 each, and in November 2021 the Supreme Court held the claim doomed to fail: a representative action under Civil Procedure Rule 19 demands the same interest across the class, and damage must be proved, not assumed from loss of control.

What survived is exactly what Austen Hays built: an opt in book of individually signed up claimants, each with pleaded distress, in the one category of data where distress is easy to evidence. Twelve thousand people rather than 4.4 million, at nearly three times the per person value. Lloyd did not close the door on collective privacy claims; it changed the door's shape, and made special category data the most attractive thing to walk through it.

How This Fits Grindr's Enforcement Record

It is the most expensive privacy outcome in Grindr's history, and no regulator produced it.

Norway's Datatilsynet proposed NOK 100 million in January 2021 and finalized NOK 65 million that December, over sharing user data with advertising partners without valid consent. The Privacy Appeals Board upheld it, and so did the Borgarting Court of Appeal in October 2024. Roughly $7 million, contested through the courts until October 2024. The UK settlement is five times larger and closed in two years.

The ad side has not gone quiet. In June 2026 the EFF measured Grindr contacting 20 tracking domains within 15 minutes of ordinary use, a real time bidding question separate from this settlement's pre 2020 one. That is history the company says it closed; this is current architecture.

What Should Compliance Teams Do With This?

Run it as a vendor boundary audit rather than a health data story. The failure happened at the SDK boundary.

  • Inventory special category fields by storage location, not product name. Find the column, the JSON key, the profile attribute, then trace everywhere that object is sent.
  • List every SDK in your build and what each captures by default. Broad capture plus one sensitive field is the whole incident.
  • Write down the Article 9(2) condition for each disclosure, per recipient. If nobody can name it, you do not have one.
  • Run the Article 35 DPIA before the processing. It is where "should this vendor see this field" gets asked aloud.
  • Price historical data handling at acquisition. Grindr's owners are paying for practices under prior ownership, as legacy transfers drove the €825 million Dutch DPA fine against Uber.

What Can Affected Users Do Now?

If you were not in Austen Hays's book of roughly 12,000 claimants, this settlement pays you nothing.

Such is the arithmetic of an opt in group claim. No fund waits for late arrivals, no notice window lets other UK users register, and the agreement records no findings to cite in a claim of your own. The ordinary routes remain: a subject access request, a complaint to the ICO, an Article 82 claim where damage can be shown.

For everyone else holding health adjacent data the signal is louder. The FTC ran the same theory when it sued Hims & Hers over health data sent to advertising platforms, and UK claimant firms now have a £26 million comparable to quote in the next letter before action. A settlement with no admission of liability changes no law. It does something more immediate: it tells the next litigation funder what a book of 12,000 people with a health field is worth.

Stop Email Tracking in Gmail

Spy pixels track when you open emails, where you are, and what device you use. Gblock blocks them automatically.

Try Gblock Free for 30 Days

No credit card required. Works with Chrome, Edge, Brave, and Arc.