Grindr Pays £26 Million to Settle U.K. Case Over HIV Status Data Sharing
The world's largest LGBTQ+ dating app has agreed to a landmark U.K. privacy settlement after being accused of passing sensitive health data to advertisers.

Key points
- Grindr has agreed to pay £26 million (about $35.1 million) to settle a U.K. lawsuit over sharing users' personal data.
- The claim, filed in April 2024, alleged the app passed on sensitive information including users' HIV status.
- The data was said to have been shared with outside companies for commercial purposes, mainly advertising.
- Grindr is the largest dating app aimed at LGBTQ+ users, which made the sensitivity of the data central to the case.
- The settlement is one of the biggest U.K. payouts to date over the handling of health-related information by a consumer app.
Grindr will pay £26 million, roughly $35.1 million, to settle a U.K. lawsuit that accused the dating app of sharing users' personal details, including their HIV status, with outside companies.
The case, first reported in outline by The Hacker News, was filed in April 2024. It argued that Grindr broke U.K. privacy law by handing sensitive information to third parties for commercial reasons, chiefly advertising.
Grindr is the largest dating app aimed at gay, bi, trans and queer users. That makes the data on its servers unusually sensitive: for many users, the app itself signals things about their identity they may not have shared elsewhere.
What data did Grindr share?
The lawsuit centred on health information, specifically users' HIV status, alongside other personal details tied to their profiles. Claimants argued this data was passed to advertising partners without the clear, informed consent that U.K. law requires for health data.
Under the U.K. General Data Protection Regulation, or UK GDPR, health information sits in a special category. It cannot be shared for marketing without a very high standard of consent. A tick-box buried in a privacy policy does not clear that bar.
Why does this matter to ordinary users?
Because the data at stake was not a password or a credit card. It was information about people's bodies and sexuality that, in the wrong hands, could out them, embarrass them, or be used to discriminate against them.
Advertising networks are not a single company. Data shared with one ad partner can be copied, resold and combined with other profiles across the web. Once it leaves the app, control over it is largely gone.
That is why regulators treat health data differently from, say, a shoe size preference.
What should Grindr users do now?
If you used Grindr in the U.K. during the period covered by the claim, you may be eligible to receive part of the settlement. The law firm that ran the case is expected to publish details of how to register.
Beyond this specific payout, a few practical steps help on any dating or health app:
- Review the app's privacy settings and turn off ad personalisation where offered.
- Think twice before filling in optional health fields, even inside apps that feel private.
How the settlement compares
| Detail | Figure |
|---|---|
| Settlement amount | £26 million (about $35.1 million) |
| Lawsuit filed | April 2024 |
| Jurisdiction | United Kingdom |
| Data at issue | Personal profile data, including HIV status |
| Alleged recipients | Third-party advertising partners |
Is this an authentication story?
Honestly, no, and it is worth saying so. This is not a breach where hackers broke in, and multi-factor authentication, the extra login step that asks for a code or a fingerprint, would not have changed anything here.
The issue is authorisation and consent at the business layer: what the app itself chose to do with data users had legitimately handed over. No login control can fix a policy decision to share data with advertisers.
That distinction matters. A lot of privacy incidents get lumped in with hacks, but the fix here is legal, contractual and about product design, not about stronger passwords or passkeys.
Common questions
Was Grindr hacked?
No. This case is about data the company chose to share with advertising partners, not data stolen by outside attackers.
Will affected users automatically get money?
Not automatically. U.K. group claims usually require eligible users to register with the law firm handling the case before a deadline.
Does this apply outside the U.K.?
The settlement covers the U.K. claim only, but regulators in the EU and U.S. have taken their own actions against Grindr over similar concerns in the past.



