Grindr to Pay £26 Million to Settle U.K. Claims Over HIV Status Data Sharing
- ID
- 22289
- Status
- summarized
- Published
- 08 Sep 2026, 3:00 PM
- Fetched
- 08 Sep 2026, 5:56 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/grindr-to-pay-26-million-to-settle-uk.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 4.5
- Created
- 08 Sep 2026, 6:01 PM
- Tags
- Audience
- developerssaas_founders
What happened
Grindr will pay £26 million ($35.1 million) to settle a UK lawsuit alleging it shared users' HIV status and last tested date with third-party optimization vendors Apptimize and Localytics before 2020, when it was owned by Kunlun. The settlement covers 10,000+ claimants, with no admission of liability, and payments split across December 2026 and March 2027. Norway's DPA had already fined Grindr £5.5 million (reduced from £8.6 million) in 2021 for the same data-sharing practices.
Why it matters
If your app passes sensitive personal data (health, financial, identity) to third-party analytics or optimization SDKs, you carry liability even if those vendors only use the data internally — Grindr's defense that Apptimize and Localytics never exposed the data to advertisers did not prevent the fine or settlement. Malaysian builders operating under PDPA should audit what user fields flow into third-party SDKs, not just what they sell to advertisers.
Discussion angle
What user data are you inadvertently leaking to analytics/optimization SDKs that you wouldn't explicitly share with advertisers — and does your privacy policy actually cover that distinction?