Grindr Inc. resolved a group action in the High Court of England and Wales on September 2, 2026, agreeing to pay £26 million to about 12,000 British users who alleged the dating application passed sensitive personal information, in some cases including HIV status, to advertising companies during a period ending in early 2020.

In Short

Grindr agreed to pay £26 million to end a UK lawsuit brought by 12,000 users who said the app shared sensitive details, including HIV status, with advertising firms before 2020. The money arrives in two equal instalments, one due at the end of December 2026 and one at the end of March 2027, and the company admitted no wrongdoing as part of the deal. For anyone buying or selling audience data, the case puts a number on information that European law treats as prohibited by default.

What the filing states

The disclosure reached investors through a Form 8-K filed with the United States Securities and Exchange Commission on September 4, 2026, signed by chief financial officer John North and carrying an earliest-event date of September 2. Grindr Inc. and Grindr LLC, its indirect wholly owned operating subsidiary, were named together in the filing.

According to the filing, the settlement covers historical data practices before 2020, a period when the business was owned and controlled by Kunlun. The document sets out a payment schedule rather than a lump sum: £13.0 million to the counterparties by December 31, 2026, and a further £13.0 million by March 31, 2027. Each instalment converts to roughly $17.6 million at the exchange rate the company applied as of September 3, 2026, putting the dollar cost at about $35.2 million.

The language on liability is unambiguous. According to Grindr, the settlement includes no findings or admission of liability, and the company continues to dispute the allegations while acknowledging what it described as distress and loss of trust among some of its UK users regarding that pre-2020 period. On its own conduct since, the filing states that the company has overhauled its privacy programme, and that Grindr "is and remains a safe space for users, committed to transparency, user control, and responsible data practices."

The Guardian reported the £26 million total and the claimant count on September 7, 2026, three days after the filing. The 8-K itself does not name a global figure or the number of claimants; it discloses only the two instalments. Neither document identifies the advertising companies at the centre of the allegations.

Two years from issue to resolution

The procedural history is longer than the settlement date suggests. The claim was issued in April 2024 by the London firm Austen Hays, but Grindr was not served with the proceedings until April 2025, a gap of a full year between filing and service. Twelve months after service, the matter closed without a trial.

Twelve thousand people signed up to the action, according to The Guardian. Divided equally, £26 million produces an average of £2,167 per claimant, though the filing contains nothing about how the fund will be allocated among individuals, and equal distribution is an assumption rather than a disclosed term. Austen Hays' parent firm, Gateley, said: "We thank our clients for trusting us with this sensitive case."

Grindr was founded in 2009 and now claims close to 15 million users worldwide. The proportion of the UK user base represented by 12,000 claimants is not disclosed in either document.

The ownership change underneath the claim

Both the filing and the newspaper account place the conduct at issue in a corporate era that ended six years ago. Grindr was sold to the investment group San Vicente Acquisition in a deal worth $608 million, with new management installed, after a United States national security panel raised concerns that the personal data of American users could be reached by China's government. The Guardian identifies the previous owner as the Chinese gaming company Beijing Kunlun Tech; the 8-K refers to it more broadly as the Chinese conglomerate Kunlun. The two descriptions point to the same corporate parent.

Two years after the sale, in 2022, the company reached the New York Stock Exchange through a merger with a special purpose acquisition company, in a transaction that valued the app at $2.1 billion, or £1.55 billion at the time. Current market value stands at $2.65 billion, equivalent to £1.96 billion. Against that figure, the settlement represents roughly 1.3 percent of the company's market capitalisation.

That sequence matters for how the liability travelled. The conduct alleged predates both the change of control and the listing, yet the payment obligation sits with the listed entity and its shareholders. A privacy exposure created under one owner became a disclosed balance sheet item for another, six years and one stock market debut later.

Norway ran the same period to judgment

The UK action is not the first regulatory or legal test of the same window. Norway's data protection authority opened the sequence after the Norwegian Consumer Council and the European privacy group noyb filed complaints in January 2020. PPC Land reported in July 2021 that the authority had notified a penalty of 100,000,000 Norwegian kroner, close to €10 million at the time, over disclosures of personal data to third-party advertisers without a legal basis and disclosures of special category data without a valid exemption. The final figure came in lower: 65 million kroner, described by The Guardian as £4.8 million and equal to 10 percent of the company's global revenues.

Grindr contested it. The Oslo District Court upheld the fine on July 1, 2024. The Borgarting Court of Appeal then dismissed the appeal on October 21, 2025, ruling that sharing sensitive personal data with advertising partners without valid consent breached the General Data Protection Regulation.

The appeal court's factual findings are the most detailed public account of the mechanics. Disclosures ran from July 20, 2018 to April 7, 2020. The data leaving the app included advertising identifiers, IP addresses, device technical specifications, self-reported age and gender, GPS location, and the App ID identifying the origin of the data. The court held that the App ID alone constituted information about sexual relations and sexual orientation, because it revealed that a person was using the application at all. Grindr operated with between seven and ten advertising partners during the period. One of them, MoPub, had 160 partners of its own, including AppNexus, which reserved the right to share information with 4,000 further partners.

On consent, the court found that users faced a choice between declining to use the app and accepting the privacy policy in full, which did not amount to voluntary agreement. On the company's public statements, the court of appeal concluded that its claim not to sell personal user information to third parties for advertising purposes was clearly misleading, given that data was in fact shared for advertising.

Norway sits inside the EEA rather than the European Union, and the GDPR was extended to the EFTA members in July 2018, which is why a Norwegian regulator was applying the same instrument as a British court would have done before the United Kingdom left.

What the settlement does not establish

A settlement without admission of liability produces no precedent. There will be no High Court judgment on whether the alleged sharing breached UK data protection law, no ruling on quantum for non-material damage in a group action of this shape, and no published finding on which advertising companies received what.

That is the second time in twelve months that a case touching the same conduct has ended without a British court reaching the merits. It also means the £26 million figure carries no analytical weight as a benchmark: it reflects the settlement value both sides accepted, not a calculated measure of harm.

What the case does establish is arithmetic. Grindr paid roughly 5.4 times the Norwegian regulatory fine to close a private claim brought by 12,000 people, in a jurisdiction where a supervisory authority had reached no comparable enforcement outcome. Private litigation, in this instance, priced the exposure higher than regulation did.

Why the filing matters to advertisers

Grindr's advertising business has grown consistently through the period in which these legal questions have been resolving. Full-year 2024 advertising revenue reached $53.7 million, up 56 percent, and the platform reported 37 percent advertising growth alongside a stated 2026 priority of increased focus on direct advertising and brand partnerships. Second-quarter 2026 advertising revenue gained 44 percent to $25 million, even as direct deals proved harder to close than the strategy implied. The company has also built product on top of the audience, including a generative AI architecture processing more than 130 billion chats a year, and a live-streamed Madonna concert in Times Squarebroadcast inside the app on June 4, 2026.

The commercial logic that produced the exposure has not gone away. An LGBTQ+ audience of 15 million monthly users across 190 countries is valuable precisely because the platform knows things about those users that no general-interest publisher can observe. Article 9 of the GDPR treats data concerning health and data concerning sex life or sexual orientation as special category data, prohibited by default and permitted only where a specific exemption applies on top of an Article 6 lawful basis. The Norwegian ruling extended that classification to something less obvious than a self-reported HIV status field: the mere fact of app usage, transmitted as an identifier.

For buyers, that is the operative finding. A segment does not need a health label attached to it to fall inside Article 9. Context supplies the inference, and the inference is what the law regulates. The same reasoning has surfaced elsewhere in the market: a California data broker was fined $45,000 for selling lists organised by medical condition, and Healthline settled a California consumer privacy case for $1.55 million after investigators observed article titles referencing HIV and multiple sclerosis diagnoses being transmitted to advertising networks.

The transmission layer is the part media buyers rarely see. Data leaves a mobile application through an embedded tracking SDK, which batches events locally and despatches them with device model, operating system version, locale, network type, IP address and, where permitted, an advertising identifier. Nothing in that payload flags its sensitivity. A complaint documented in December 2025 traced Grindr usage data reaching TikTok through AppsFlyer without the complainant's explicit consent, five years after the period covered by the UK claim.

The exposure that outlives the practice

Two features of this case travel beyond dating applications. The first is duration. The conduct ended in early 2020; the last payment falls due on March 31, 2027, seven years later. Legacy data practices generate liabilities that survive product changes, ownership changes and public listings, and they surface on the balance sheet of whoever holds the entity when the claim lands.

The second is the growth of collective redress as a route. UK courts and tribunals have become materially more hospitable to grouped claims against advertising-funded businesses, a shift visible in the £5 billion collective claim certified against Google on behalf of UK search advertisers in August 2026, and in continental compensation awards such as the €5,000 granted to a Facebook user by the Leipzig District Court. American juries have moved in the same direction, with one finding that Meta violated privacy law in collecting health data. Regulatory fines remain capped by statute and by regulator capacity; private claims are not.

Consumer sentiment provides the third data point. Research published in February 2026 found dating app users increasingly unwilling to share identifying information, with UK women increasing refusal responses by 3.19 percentage points and US women by 5.72 percentage points. The pool of consented sensitive data is contracting at the same time as the legal cost of processing it without valid consent is rising.

Grindr's next scheduled obligation is the first £13.0 million instalment, due within roughly sixteen weeks of the filing. The company's risk disclosures on this matter sit in its Form 10-K for the fiscal year ended December 31, 2025 and in subsequent quarterly reports.

Timeline

Summary

Who. Grindr Inc. and its operating subsidiary Grindr LLC, defending a group action brought by the London law firm Austen Hays on behalf of approximately 12,000 UK users. Austen Hays' parent firm is Gateley. The company is listed on the New York Stock Exchange under the ticker GRND and is headquartered in West Hollywood, California.

What. A settlement of £26 million, payable in two instalments of £13.0 million each and equivalent to roughly $17.6 million per instalment, resolving allegations that sensitive personal information including HIV status was shared with advertising companies. The settlement includes no findings or admission of liability, and Grindr continues to dispute the allegations.

When. The group action was issued in April 2024 and served in April 2025. Grindr resolved it on September 2, 2026, disclosed the resolution in a Form 8-K on September 4, 2026, and the total figure was reported publicly on September 7, 2026. Payments fall due on December 31, 2026 and March 31, 2027.

Where. The High Court of England and Wales, covering UK users, with parallel enforcement history in Norway before the Norwegian Data Protection Authority, the Oslo District Court and the Borgarting Court of Appeal.

Why. The claim concerned data practices before early 2020, when Grindr was owned and controlled by Kunlun, and covered categories that European data protection law treats as prohibited by default absent explicit consent. A Norwegian appeal court had already found on the same period that sharing App IDs with advertising partners breached the GDPR, and the settlement closes the private UK route without producing an equivalent British judgment.