> ## Content Index
> Fetch the complete content index at: https://bytevyte.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# Grindr UK Privacy Settlement Puts a £26M Price on Leaked HIV Data
- URL: https://bytevyte.com/grindr-uk-privacy-settlement-puts-a-26m-price-on-leaked-hiv-data/
- Published: 2026-09-15T15:17:27.000Z
- Updated: 2026-09-15T15:17:27.000Z
- Description: Grindr UK privacy settlement: £26m for 12,000 users over HIV-status data sent to ad partners, paid in two £13m instalments by March 2027.
- Author: Bytevyte Editorial
- Tags: quick-beats

**Grindr** has agreed to pay £26 million to settle a UK group action over allegations that it passed sensitive user data, including HIV status, to advertising partners. The Grindr UK privacy settlement was reached in the High Court of England and Wales on September 2, 2026, and covers roughly 12,000 British users. Grindr disclosed the terms in a US regulatory filing and accepted no finding of liability.

Under the agreement, the California-based company will pay two instalments of £13 million each, worth about $17.6 million per tranche at the September 3 exchange rate. The first falls due by December 31, 2026, and the second by March 31, 2027\. Divided evenly across the claimant group, the total works out to about £2,167 per person. At early-September rates, £26 million is worth roughly $35 million, or about $48.6 million in Canadian dollars.

The claim was filed in April 2024 by the London law firm Austen Hays on behalf of UK users who said Grindr breached domestic data protection rules by sharing personal information for commercial purposes. The categories at issue may have included HIV status, the date of a user's most recent HIV test, use of pre-exposure prophylaxis, ethnicity, sex life and sexual orientation. HIV status, PrEP use and sexual orientation sit in the most heavily protected tier of UK data protection law.

The alleged conduct falls in two windows, one before April 2018 and another between May 2018 and April 2020, ending when Grindr changed its consent guidelines. Grindr disputes the allegations, and the settlement carries no admission of liability. The company acknowledged the distress and loss of trust expressed by some of its UK users over earlier data practices. At the time, Grindr was owned by the Chinese gaming group Beijing Kunlun Tech.

Timing is part of the story. More than six years separate the end of the conduct period from the settlement, and the claim took about two and a half years to resolve from filing to signature. Group actions over data practices move on a different clock than the software that created them.

## What the Grindr UK Privacy Settlement Costs

The figure is the most informative part of the deal. It attaches the first public price to sensitive health signals reaching programmatic advertising, the automated auction system that routes app data through layers of intermediaries before an ad renders. Grindr priced its exposure by settling rather than litigating, and that number now gives every app that pushes user signals into real-time bidding a reference point for what a comparable leak could cost.

Two structural details matter for anyone tracking similar cases. The payments are split across two financial years, spreading the cash impact instead of concentrating it in a single quarter. The £2,167 average also invites comparison with the parallel Israeli action, where the remedy is a free month of the paid Grindr Xtra tier rather than cash. Two jurisdictions, two different valuations of the same kind of harm.

| Matter                              | Decision-maker                      | Outcome                      | Date         |
| ----------------------------------- | ----------------------------------- | ---------------------------- | ------------ |
| UK group action, about 12,000 users | High Court of England and Wales     | £26m in two £13m instalments | Sept 2, 2026 |
| Israel representative action        | Tel Aviv District Court             | Free month of Grindr Xtra    | Sept 2026    |
| Norway enforcement                  | Norwegian Data Protection Authority | €6.5m fine                   | 2021         |
| BBVA marketing opt-out              | Italy's Garante                     | €5.5m fine                   | Sept 2026    |

Eligibility differed sharply between the two consumer settlements. The Israeli remedy reaches users who logged into the app at least once in the past year, a rolling condition that ties the benefit to current engagement. The UK group is fixed at roughly 12,000 people who signed up to the claim after Austen Hays filed it in 2024, so the cash goes only to those who opted into the litigation.

Because the Grindr UK privacy settlement includes no admission, it does not establish that Grindr broke the law, which limits how much weight claimants elsewhere can place on it as precedent. What it does establish is a benchmark. Other firms weighing a defence against a similar claim now have a settled number to argue against.

## A Wider Enforcement Pattern

The Grindr UK privacy settlement did not arrive in isolation. In 2021, the Norwegian Data Protection Authority fined Grindr €6.5 million for failing to let users opt out of their data being sold to third parties, a decision that shaped the UK claim. Days after the English agreement, the Tel Aviv District Court approved a separate Israeli deal over comparable allegations. Italy's Garante fined BBVA €5.5 million in the same enforcement round over a marketing opt-out failure, evidence that European regulators treat consent mechanics as a standing target rather than a one-off case.

Grindr is the largest LGBTQ+ dating app, and the settlement lands in a stretch when regulators are pursuing consent failures across sectors, not only dating. The BBVA penalty applies the same principle to banking marketing. The common thread is the opt-out: whether a user could meaningfully refuse, and whether that refusal actually stopped the data flow.

For app developers, the control point sits in the ad stack rather than the courtroom. Sensitive attributes can enter bid requests through analytics and attribution software long before anyone classifies them as health data. Grindr's pre-2020 arrangements show how an integration built under older consent rules can resurface years later as a group action with a defined price attached. Firms that audit SDK data flows now, rather than after a claim lands, avoid the situation Grindr faced: conduct that ended in 2020, litigation from 2024, and payouts running into 2027.

## Why This Matters

Consent now carries a price in the UK market. Grindr's choice to settle rather than fight means the cost of routing sensitive signals into advertising auctions is no longer theoretical for apps serving British users. For users, the consequence is that data categories they never treated as public, from test dates to medication use, can travel through commercial pipelines, and the remedy arrives years later as a modest per-person payment. With instalments running through March 2027, the case stays on the books well beyond the headlines.

## Sources

[Grindr settles HIV status data-sharing lawsuit for $35 million](https://www.malwarebytes.com/blog/privacy/2026/09/grindr-settles-hiv-status-data-sharing-lawsuit-for-35-million?ref=bytevyte.com)

*AI-generated image.*

## Related Articles

- [23andMe Data Breach Settlement: States Win $18 Million Over 6.9 Million Genetic Records Exposed](https://bytevyte.com/23andme-data-breach-settlement-states-win-18-million-over-6-9-million-genetic-records-exposed/)
- [Uber GDPR fine: €825M ruling on automated account bans](https://bytevyte.com/uber-gdpr-fine-eu825m-ruling-on-automated-account-bans/)

✔Human Verified

---

*Researched and cross-referenced against primary sources by the Bytevyte editorial team. This article was generated with the assistance of artificial intelligence and reviewed by the Bytevyte editorial team.*