Grindr Settles $35 M Lawsuit Over Unauthorized Sharing of HIV Status and Sensitive Data
What Happened – Grindr agreed to pay roughly $35 million to settle a UK privacy lawsuit alleging that, between 2018‑2020, the app disclosed users’ HIV status, test dates, PrEP usage, ethnicity and other identifiers to advertising partners without valid consent. The claim was brought on behalf of about 12,000 UK users and follows a similar enforcement action in Norway.
Why It Matters for Trust & Control Assurance
- Demonstrates the risk of privacy‑control gaps when third‑party advertising SDKs receive granular user data without a lawful basis.
- Highlights the need for continuous consent‑management monitoring and auditable evidence that data‑sharing practices align with GDPR‑style obligations.
- Shows how a single control failure (lack of consent verification) can trigger large financial penalties and erode user trust.
Who Is Affected – Consumer‑tech and dating‑app providers, advertising networks, and any organization that processes health‑related or other highly sensitive personal data.
Recommended Actions
- Conduct a privacy‑impact assessment focused on third‑party data flows and consent capture.
- Map your consent‑management process to the GDPR “lawful basis for processing” control and collect evidence (policy docs, logs, UI screenshots).
- Implement continuous monitoring of SDK integrations and enforce a vendor‑risk program that validates privacy safeguards before data is shared.
Technical Notes – The alleged sharing leveraged advertising SDKs that collected device identifiers, location, IP address and event data, then combined them with self‑reported health information. No software vulnerability was cited. Source: Malwarebytes Labs