Your shopping cart is empty!
Grindr pays £26m over HIV data leak

£26 million split across 12,000 UK users is roughly £2,167 per person. That is what the story of sharing HIV status with advertising partners cost Grindr — and the first time a medical data leak got a clear price tag per claimant.
How it was calculated and what was agreed
The claim was filed back in April 2024, with claimants represented by London firm Austen Hays. The settlement was signed on 2 September 2026: £13 million due by 31 December 2026 and another £13 million by 31 March 2027. Grindr admitted no liability and formally continues to deny the claims, agreeing only that users experienced distress.
What exactly went to advertising partners
The period runs from 20 July 2018 to 7 April 2020; PPC Land breaks down what was shared:
- the user's HIV status together with advertising identifiers;
- IP address, device characteristics and GPS coordinates;
- age, gender and App ID.
There were between seven and ten recipients — the Norwegian case named MoPub, AppNexus and AppsFlyer. The data did not go to a single partner but down a chain, and once shared it cannot be recalled.
A regulator's fine and a class action are different line items
| Norway, regulator's decision | United Kingdom, settlement | |
|---|---|---|
| Amount | 65m kroner (~£4.8m) | £26m |
| Who it covers | all users in the country | 12,000 claimants |
| Who initiates | the supervisory authority | the users themselves |
| Admission of liability | a finding of infringement | none |
The British settlement came out 5.4 times more expensive while covering only 12,000 people. A regulator's fine and a class action are two separate line items, and the second one hurt more. The budget lesson is simple: audience segments built on sensitive data now carry a legible price of risk.
Why this concerns an ordinary advertiser
The Norwegian decision held that the app identifier alone is enough for data to count as a special category under Article 9 of the GDPR, regardless of what travels alongside it. "We shared no diagnosis, only an ID" stopped being a defence: sensitivity is defined by the context of the app or site section, not by the name of the field.
For a Ukrainian business this matters in two cases: when the audience includes EU users, and when the site works in a sensitive area — medicine, psychology, legal aid, financial distress. A single event marking a visit to a page about a medication or a diagnosis, sent into an ad platform, already describes a person more precisely than it looks. Which events and parameters actually leave your site is visible in analytics settings — the basics are in the guide on Google Analytics 4 setup.
What to check on your side
- list every place data leaves for ad platforms: pixel, app SDK, server-side conversions, audience uploads;
- review event payloads — check whether you pass a product, section or page name that itself reveals something sensitive;
- count how many data recipients you really have: chains often include intermediaries the marketer never hears about;
- verify that consent covers advertising use, not only analytics;
- if you send data through an SDK or server-side conversions, write the field list down — it is the cheapest way to avoid reconstructing it a year later.
Doing this now is cheaper than counting £2,167 per user later.


