Grindr to pay £26m to settle claims over sharing users' HIV status

Grindr has agreed to pay £26 million to resolve a long-running legal claim that it breached UK privacy laws by sharing users' HIV status with third parties. The settlement addresses allegations that sensitive health information was disclosed outside the dating app.

Grindr, the dating app used primarily by gay and bisexual men, will pay £26 million to settle a longstanding claim that it breached UK data protection laws by sharing users' HIV status with third parties.

The claim, brought on behalf of users, accused the company of disclosing sensitive health information to outside firms. The settlement ends the litigation without a trial, resolving allegations that the app's handling of HIV-status data violated privacy protections under UK law.

Allegations and scope

According to the legal claim, the contested practice involved the transmission of information about users' HIV status to third-party entities. The case argued that such disclosures constituted a misuse of particularly sensitive personal data and a breach of statutory privacy obligations. The settlement is intended to resolve those complaints, though specific terms regarding compensation and the mechanism for payment to claimants have not been detailed in the summary announcing the agreement.

Broader privacy implications

The resolution highlights wider concerns about how apps collect, use and share sensitive health information, particularly within social and dating platforms. Privacy advocates and legal experts have increasingly scrutinised how third-party data sharing can expose users to risks, and this settlement may prompt other companies to review their data‑handling practices to avoid similar disputes.

Next steps

While the settlement closes this particular lawsuit, it could influence future litigation and regulatory attention on data practices in the tech sector. Users, advocacy groups and industry observers will be watching for any changes Grindr or comparable services make to privacy policies, notification practices and third-party data arrangements in response to the case.