Regulatory Watch  /  Norway (EEA)  /  Fine
Moderate impactFineIn effect

Norwegian DPA fines Grindr €6.3 M for illegal sharing of sensitive data

The Norwegian Data Protection Authority imposed a fine of 65 Mio NOK on Grindr for sharing sensitive personal data without valid consent. The authority found the consent mechanism invalid and highlighted the lack of a genuine opt‑out. The fine was adjusted from an initial draft of 100 Mio NOK based on Grindr's revenue and remedial actions.

Why it matters: The enforcement underscores that personal data, especially sensitive categories, cannot be used as a payment mechanism without proper consent under GDPR.

Summary generated from the sources below. Check the primary source before relying on it; this is not legal advice.

Sources
NCC & noyb GDPR complaint: "Grindr" fined € 6.3 Mio over illegal data sharing
noyb · primary source · Dec 15, 2021
NCC & noyb GDPR complaint: "Grindr" fined € 6.3 Mio over illegal data sharing
noyb · Dec 15, 2021
Details
JurisdictionNorway (EEA)
RegulatorNorwegian Data Protection Authority
LawGeneral Data Protection Regulation
StatusIn effect
PublishedDecember 15, 2021
EffectiveDecember 15, 2021
DecisionDecember 15, 2021
Penaltyfine of 65 Mio NOK (€ 6.34 Mio or $ 7.17 Mio)
OrganisationsGrindr
Topicsconsent, sharing, targeted advertising, profiling, data brokers
Datapersonal, sensitive, location