Grindr disclosed in a September 4 filing with the US Securities and Exchange Commission that it has agreed to pay £26 million, roughly $35.2 million, to settle a UK High Court group action brought by around 12,000 users. The claim alleged the app shared sensitive personal data, including users’ HIV status, last-tested date, sexual orientation, and location, with third-party analytics vendors Apptimize and Localytics before 2020. Grindr will pay £13 million by the end of this year and the remaining £13 million by March 31, 2027. The filing states the settlement “includes no findings or admission of liability,” and the company says it continues to dispute the allegations while acknowledging the “distress and loss of trust” some UK users experienced over that period.

The practice at issue dates to 2018, when Norwegian research group SINTEF first documented Grindr sharing HIV status and testing data with app-optimization vendors, a pattern common across mobile analytics before GDPR enforcement matured. Grindr notes the conduct predates its 2020 change of ownership away from Chinese parent Kunlun and its 2022 NYSE listing, framing the settlement as closing out a legacy liability.

What makes this case worth tracking is the enforcement route, not just the amount. The UK’s Information Commissioner’s Office has fined companies directly over health-adjacent data sharing before, with penalties that go to the Treasury. This settlement instead came through a private group litigation claim, a mechanism that pays claimants directly, an estimated £2,167 each if split evenly, without requiring a regulator to act at all. The signal for a privacy leader: historical third-party data-sharing decisions, especially anything touching health status, remain financially live for years, and UK civil litigation is proving at least as consequential a liability route as regulatory enforcement.

The case sits alongside this publication’s coverage of the gap between containing an incident and properly disclosing it, and a recent case of a vendor retaining customer data longer than a company believed it had.

Source: U.S. Securities and Exchange Commission