Breach report
Social MediaGrindr
Grindr Admits It Shared HIV Status Of Users
Gay dating app Grindr was found sharing users' HIV status and test dates with two analytics vendors alongside location and email data. The revelation led to regulatory action and a record Norwegian GDPR fine over data sharing.
Reported by NPR
Records exposed
Undisclosed
Undisclosed (Grindr had about 3.6 million daily active users)
- When
- 2018
- How they got in
- Sharing of sensitive data with third-party analytics vendors
- Sector
- Social Media
In April 2018, BuzzFeed News, drawing on research by Norwegian nonprofit research organization SINTEF, reported that Grindr, the world's largest dating app for gay, bisexual and transgender men, had been sending users' HIV status to two outside companies. The recipients, Apptimize and Localytics, provided software for testing and optimizing mobile apps. At the time, Grindr said it had about 3.6 million daily active users.
The data being shared included not only HIV status and the date of a user's last test, fields that users could choose to add to their profiles, but also other identifiers transmitted alongside it, such as GPS location, phone ID and email address. Researchers warned that this combination could make it possible to link sensitive health information to specific individuals. SINTEF also found that some personal data was sent to other partners without encryption.
Grindr initially defended the practice, saying the vendors were bound by contracts, that it did not sell personally identifiable information, and that users chose whether to disclose their HIV status. Within hours, facing a fierce backlash from HIV advocates and users, the company's security chief said it would stop sharing HIV data with the analytics firms. Grindr told NPR it was removing the information from both vendors' systems.
The revelation prompted a letter from US Senators Ed Markey and Richard Blumenthal demanding answers from Grindr and the vendors, and a complaint in Europe. In a related case brought by Norway's Consumer Council, the Norwegian Data Protection Authority in December 2021 fined Grindr 65 million kroner, about $7 million, for sharing user data with advertisers without valid consent, finding that simply being a Grindr user revealed information about sexual orientation. The fine was upheld on appeal in 2023. In 2024, a group action was filed in London alleging that Grindr had shared users' HIV status and other sensitive data with third parties.
The Grindr case is not a hack, but it is frequently discussed alongside breaches because it involved the unexpected disclosure of highly sensitive data. It demonstrates that third-party software development kits and analytics tools can become data leakage channels, and that companies handling health or sexuality information must scrutinize every outbound data flow. It also helped shape how European regulators interpret consent for special categories of personal data.