SendTech Times
News
MARKET SIGNAL:

Grindr Agrees £26m Settlement Over UK HIV-Data Privacy Claims

Newsroom brief

Grindr will pay £26m to settle claims over historical sharing of users’ sensitive data, including HIV status, while denying liability and pointing to privacy changes since 2020.

Verified against source materialEdited by SendTech Times Capital & Policy DeskSource: BBC
Grindr Agrees £26m Settlement Over UK HIV-Data Privacy Claims
Image source: BBC

Grindr will pay £26 million to settle UK legal claims over allegations that users’ personal details, including HIV status, reached outside analytics companies, the BBC reported after a new US filing made the agreement public.

The settlement gives the dating app a defined financial exposure while leaving the legal allegations formally disputed.

Grindr said the agreement carries no admission of liability and concerns “historical data practices” before 2020, when Chinese firm Kunlun owned the company.

The payment schedule is split in two.

SEC paperwork filed by Grindr sets out one £13 million transfer to counterparties by 31 December and a second £13 million transfer by 31 March 2027.

The agreement was reached on 2 September.

The lawsuit began in the UK High Court in 2024 over claims that Grindr misused personal information.

The class action later moved into the United States, and Austen Hayes, the law firm behind the case, had registered more than 11,000 claimants.

The disputed data went beyond ordinary account details.

The claim alleged commercial sharing of sensitive categories such as ethnicity, sexual orientation and HIV status in breach of UK privacy law.

Grindr users can choose to display HIV status and a last-test date, a feature the company presents as a way to reduce stigma, encourage conversations and help people make informed health choices.

Apptimize and Localytics were named as the analytics providers that could see sensitive information.

The claim also alleged that advertising customisation may have involved a wider, potentially unlimited group of outside parties.

That history matters because the new settlement follows public revelations from 2018 that Grindr had shared personal data, including HIV status, with the two analytics companies.

Grindr defended the practice then as consistent with industry standards, but later said it had stopped sending HIV data to those providers.

Regulators had already acted before the latest settlement.

Norway’s data protection watchdog fined the company £5.5 million, and the UK Information Commissioner’s Office issued a reprimand in 2022 over data practices.

Grindr’s ownership and public-market status frame the company’s present defence.

The app became publicly listed in 2022, two years after new owners took over from Kunlun.

In the new filing, Grindr said it recognises distress and loss of trust expressed by some UK users over the pre-2020 period, while still disputing the allegations.

The company now says privacy practices have been overhauled since 2020 to meet the “unique needs of its community.” The confirmed result is a narrower legal endpoint than the broader privacy debate: a £26 million settlement, paid in two tranches, with no admission of liability.

Share this article
inXf

Related articles

More
Open-Weight AI Safety Gap Widens As GLM-5.2 Nears Frontier Models
Capital & Policy

Open-Weight AI Safety Gap Widens As GLM-5.2 Nears Frontier Models

SaferAI found Z.ai GLM-5.2 close to frontier cyber and biology capabilities while lacking published safety commitments, making release controls part of the AI risk debate.

Singapore Gives Platforms January Deadline For Anti-Scam Controls
Capital & Policy

Singapore Gives Platforms January Deadline For Anti-Scam Controls

Singapore is requiring messaging services to restrict unknown contacts and social platforms to verify advertisers under anti-scam rules that carry a January 31, 2027 compliance deadline.

CIRCIA Rule Faces September Deadline As Industry Seeks Narrower Filings
Capital & Policy

CIRCIA Rule Faces September Deadline As Industry Seeks Narrower Filings

CISA is working toward a September target for the delayed CIRCIA rule as industry groups seek fewer covered entities, narrower incident triggers and leaner reporting requirements. The law sets 72-hour incident and 24-hour ransomware-payment reporting deadlines, while the proposed rule could cover more than 300,000 entities.

Khalifa Fund Cybersecurity Program Starts Without Funding Or Cohort Details
Capital & Policy

Khalifa Fund Cybersecurity Program Starts Without Funding Or Cohort Details

Khalifa Fund and the UAE Cyber Security Council have launched a national program for cybersecurity startups with CyberE71 support. The announcement names mentorship, investor access and partnership support, but gives no funding amount, cohort size or application timetable.

Singapore Online Safety Office Gets 500 Reports in First Test
Capital & Policy

Singapore Online Safety Office Gets 500 Reports in First Test

Singapore’s new Online Safety Commission received more than 500 reports in its first two months, with doxxing and harassment dominating eligible online-harm complaints.

Yokogawa Opens Singapore Hub For Industrial Cyber Resilience
Capital & Policy

Yokogawa Opens Singapore Hub For Industrial Cyber Resilience

Yokogawa Engineering Asia has launched a Singapore center focused on OT cyber resilience, training, response planning and recovery coordination for Southeast Asia, Oceania and Taiwan.

Anthropic Report Details AI Agent Use In Cyber Operations
Fintech & Digital Payments

Anthropic Report Details AI Agent Use In Cyber Operations

Anthropic’s latest misuse report describes attackers using AI agents to coordinate cyber operations, adapt malware and expand activity across espionage, fraud and surveillance cases.

Discovery Bank Claims 500% AI ROI as Most Enterprises Face Longer Payback
Fintech & Digital Payments

Discovery Bank Claims 500% AI ROI as Most Enterprises Face Longer Payback

PYMNTS reports that Discovery Bank says its behavioral AI system produced more than 500% ROI while fraud, credit and service workflows run on the same operating layer.

Keep Reading

More Stories

Latest
ClickFix Attack Uses Browser Cache To Hide Malware PayloadCybersecurityOct 6, 2026ClickFix Attack Uses Browser Cache To Hide Malware PayloadMicrosoft Threat Intelligence traced a ClickFix cache-smuggling method that preloads malware into browser caches, then uses file size checks and a pasted Run command to launch later credential-theft stages.VOA Tests Six-Month Startup Buildout Before Funding DecisionsFintech & Digital PaymentsOct 6, 2026VOA Tests Six-Month Startup Buildout Before Funding DecisionsTechCabal’s interview with VOA Venture Partners founder Victoria Olayide Adesanya describes a six-month build programme that lets the firm work inside African financial-infrastructure startups before deciding whether to invest.Bitcoin Holds $86,000 As Dollar Index Hits 18-Month HighCrypto/Web3Oct 6, 2026Bitcoin Holds $86,000 As Dollar Index Hits 18-Month HighCoinDesk reported that bitcoin stayed near $86,000 while the U.S. Dollar Index reached about 102.5, with U.S. rate expectations and European political risks strengthening the dollar backdrop.Google Freezes OSS Bug Bounty Reports After AI Submission FloodCybersecurityOct 6, 2026Google Freezes OSS Bug Bounty Reports After AI Submission FloodGoogle has stopped accepting new product vulnerability reports in its OSS VRP after invalid automated submissions swamped reviewers, while older reports and some Cloud VRP routes remain open.Fleuret AI Raises €4M For Continuous AI Pentesting PlatformCybersecurityOct 6, 2026Fleuret AI Raises €4M For Continuous AI Pentesting PlatformTech.eu reported that French startup Fleuret AI raised €4 million in pre-seed funding to develop an agentic-AI platform that turns penetration testing into a continuous security process.GFT Analysis Says AI Documentation Can Cut Maintenance Work 30%Fintech & Digital PaymentsOct 6, 2026GFT Analysis Says AI Documentation Can Cut Maintenance Work 30%A GFT Technologies analysis says AI-linked software documentation can cut maintenance effort and speed developer onboarding when knowledge assets stay synchronized with code changes.Schneider Electric Lines Up $22.6 Billion PTC DealAIOct 5, 2026Schneider Electric Lines Up $22.6 Billion PTC DealSchneider Electric plans to buy PTC in a cash transaction valuing the US engineering software provider’s equity at about $22.6 billion, adding product-lifecycle software to its industrial AI push.Aggarwal Pledges Ola Electric Stake To Fund ₹1,000 Cr Rights IssueCapital & PolicyOct 5, 2026Aggarwal Pledges Ola Electric Stake To Fund ₹1,000 Cr Rights IssueOla Electric founder Bhavish Aggarwal pledged 20 Cr shares to finance his participation in a rights issue that forms part of a larger ₹1,500 Cr fundraising plan.Natrona Schools AI Review Puts Student Privacy Ahead Of Classroom Tool UseAIOct 5, 2026Natrona Schools AI Review Puts Student Privacy Ahead Of Classroom Tool UseNatrona County trustees questioned whether teacher AI tools expose student data, even as existing district rules already ban unauthorized generative AI use by students.AMD Prices 256-Core EPYC 9996 At $14,904 For Server BuyersChips & SemiconductorsOct 5, 2026AMD Prices 256-Core EPYC 9996 At $14,904 For Server BuyersTechRadar reports that AMD’s 6th Gen EPYC 9006 “Venice” lineup includes a 256-core EPYC 9996 with 512 threads, 1GB of L3 cache, a 600W default power rating and a $14,904 list price for 1,000-unit orders.New Relic Reports US$18 Million GreenOps Savings After AI CertificationCloud & Data CentersOct 5, 2026New Relic Reports US$18 Million GreenOps Savings After AI CertificationA New Relic company news item carried by iTWire says the observability vendor has earned ISO/IEC 42001 certification, joined the EU AI Pact and reported US$18 million in GreenOps savings from more than 80 engineering initiatives.VDURA V12 Targets GPU Clouds With One Storage PlaneCloud & Data CentersOct 5, 2026VDURA V12 Targets GPU Clouds With One Storage PlaneVDURA has made its V12 software generally available, adding tenant isolation, API-driven provisioning, tiering and RDMA data paths for GPU cloud and AI-factory storage fleets.