Maandag 14 september 2026 — Editie #14
GlobalRainbowNews

The global platform for LGBTQ+ news, analysis and stories. Independent and inclusive.

NederlandsGlobalDeutschFrançaisEspañol
redactie

Grindr Fined €26M for HIV Data Leak: What Users Should Know

Spain's data authority fined Grindr €26 million for sharing sensitive user data, including HIV status. What does this mean for your privacy?

RainbowNews RedactieSeptember 16, 2026 — International3 min read
···

Photo: RainbowNews Editorial

Spain's data protection authority has fined dating app Grindr €26 million. The reason: the app shared sensitive user data, including HIV status, with third parties without proper consent. The ruling, announced this month, is one of the largest privacy fines against a dating app in Europe. It raises new questions about how safe personal health data really is on gay dating platforms.

What happened at Grindr

The Spanish agency AEPD found that Grindr shared user data with advertising partners. This included location, sexual orientation and HIV status. Users were not properly informed. They also could not give real consent, according to the ruling.

This is not the first time Grindr has faced this issue. In 2018, the app admitted it shared HIV status with two analytics companies. In 2021, Norway fined the app €6.5 million for similar reasons. The new Spanish fine shows the problem has not been fully solved.

Grindr says it will appeal. The company states it changed its data policies years ago. But regulators say the changes were not enough.

Why HIV data is extra sensitive

Under European privacy law (GDPR), health data gets extra protection. HIV status falls into this category. Sharing it without clear consent is a serious violation.

The risk is not only theoretical. People living with HIV can face discrimination at work, in insurance and in personal relationships. In some countries, HIV status can even lead to legal problems. That is why groups like the Aidsfonds and UNAIDS have long warned about digital privacy risks.

Dr. Kenneth Mayer of Fenway Health has said in earlier interviews that trust is a key part of HIV care. When people fear their status will leak, they may delay testing or treatment. That has direct public health consequences.

What this means for dating app users

The fine is a warning to the whole industry. But users cannot wait for regulators to solve every problem. There are practical steps you can take today to protect your health data.

First, think carefully about what you put in your profile. HIV status, PrEP use and other health details are personal. You do not have to share them publicly. Many users prefer to discuss these topics one-on-one in a private chat.

Second, check the app's privacy settings. Most dating apps let you limit what data is shared with advertisers. These settings are often hidden deep in the menu. It is worth spending ten minutes to review them.

Third, be aware that no app is 100 percent secure. Data breaches happen. If you would not want a piece of information on a billboard, think twice before putting it in an app profile.

The bigger picture: dating apps and health

Dating apps have become an important part of gay men's social and sexual lives. Research from the RIVM and other institutes shows that apps like Grindr, Scruff and Romeo are also used to share health information. Some users list their PrEP status, last test date or viral load.

This openness has benefits. It can reduce stigma and help people make informed choices. Studies have shown that apps can even support HIV prevention, for example by linking users to testing services or PrEP information. For more on modern HIV prevention, see our guide on PrEP in 2026 and long-acting injections.

But the openness also creates risks. When apps collect this data, they become attractive targets for hackers and advertisers. The Grindr case shows what can go wrong when companies put profit before privacy.

What regulators are doing

European regulators are becoming stricter. Since GDPR came into force in 2018, fines have grown larger. The €26 million Grindr fine is part of a trend. In 2023, TikTok was fined €345 million for how it handled children's data. Meta has faced fines in the billions.

In the United States, the picture is different. There is no federal privacy law like GDPR. But some states, like California, have their own rules. The Federal Trade Commission has also taken action against Grindr in the past.

Consumer organisations argue that stronger enforcement is needed. Privacy International, a UK-based group, has repeatedly called for tougher rules on dating apps. They say self-regulation has failed.

Practical tips for safer app use

  • Review the privacy settings in your dating apps every few months.
  • Do not put sensitive health data in your public profile.
  • Use a separate email address for dating apps, not your main one.
  • Turn off location sharing when you are not actively using the app.
  • Read privacy updates when the app asks you to accept new terms.
  • Delete accounts you no longer use, and ask for your data to be removed.

If you are worried about how your health data might be used, talk to your doctor or a sexual health clinic. They can advise on how to share information safely. Organisations like Aidsfonds in the Netherlands and Terrence Higgins Trust in the UK also offer confidential support.

The bottom line

The Grindr fine is a reminder that health data is valuable and vulnerable. Dating apps have made gay life easier in many ways. But they also collect huge amounts of personal information. Users have a right to know what happens with that data.

Regulators are stepping up, but slowly. In the meantime, taking a few simple steps can reduce your risk. Privacy is not just a legal issue. It is part of your overall health and wellbeing. For related reading, see our article on mental health care after a hate incident, which also touches on the emotional impact of privacy violations.

RR

RainbowNews Redactie

Editor

Part of the RainbowNews editorial team.

Meer van deze auteur →

More in Redactie