
Around 12,000 app users in Britain sued Grindr over allegations of sharing sensitive personal data with advertisers.
Grindr has agreed to pay £26 million to settle a lawsuit brought by 12,000 UK users alleging the dating app shared sensitive personal information, including HIV status, with advertisers without liability admission.
AI-generated summary
Around 12,000 app users in Britain sued Grindr over allegations of sharing sensitive personal data with advertisers.
Everyone has secrets. Things they wouldn't tell just anyone – except, perhaps, their dating app. What sort of partner they're looking for. Where they go to look for them. Their sexual preferences, maybe, or details about their health.
This information is meant to help the app find suitable matches. Selling the details on to other companies is not in the users' interest.
But this is what allegedly happened with Grindr, a dating app explicitly aimed at the LGBTQ+ community. Around 12,000 app users in Britain sued the company, which they said had shared highly sensitive personal information with advertisers — even, in some cases, a user's HIV status.
The lawsuit, filed in 2024, was settled earlier this week. Grindr has agreed to pay the claimants a total of 26 million pounds (€30 million; $35 million) – but stresses that this is not an admission of liability. Grindr continues to dispute the allegations, there has been no legal judgement.
What happens to the data you entrust to apps?
This latest case is just one of many that raise the bigger question of what actually happens to the information we entrust to our apps on a daily basis.
For users, an app is primarily just a helpful product. But they are often supported by cloud services, analysis tools, advertising networks and other service providers. They save and transfer data, link and analyse it — often contrary to our interest.
Jan Penfrat, a digital policy expert, says that many of the big tech companies want to "make it as difficult as possible for users and regulatory authorities to understand what data is gathered on our devices by which players, and for what purpose."
Penfrat works for European Digital Rights (EDRi), a European network of NGOs and experts that campaigns to defend fundamental rights and freedoms in the digital realm.
We all know what it's like: An app, a messenger service, for example, is quickly installed, and when it asks if it has permission to use personal data, users will often just click "yes."
Phone numbers are stored on servers — without approval
But the devil is in the detail. When you install WhatsApp, for example, you give it access to all the contacts in your smartphone. The phone numbers are transferred to the server — including those of people who don't use WhatsApp themselves, and who have not given permission for their contact details to be passed on.
"All of this flows into an enormous profile," says Penfrat.
Companies like Google then offer so-called "targeting" products based on this data.
"This means a car or clothes manufacturer can say: I'd like to address these target groups, and I want my advertising to appear in their Google search, Google Mail, or any of the hundreds of millions of third-party websites with integrated Google advertising," Penfrat explains.
Selling data profiles
Google is just one of many companies that offer data profiles. Two types of data feed into these profiles. One is the data that every user voluntarily discloses when they state something in their profile, or upload private photos.
But in addition, many big tech companies have for years now made assumptions based on the data they receive.
"If they have access to my location data and know where I usually am at night, they can assume that this is my home address," Penfrat says.
"If, for example, it's in a very expensive part of town, they can immediately make assumptions about my income. If they see: Oh, he has geolocation switched on and he regularly goes to a gay club, then he's probably a member of the LGBTQ community. And all this goes straight into the profile."
Strict regulation in Europe
The EU already has one of the strictest data protection regulations in the world. The General Data Protection Regulation (GDPR) aims to protect people's personal data and privacy.
Other EU digital laws such as the Digital Markets Act or the Digital Services Act are intended to prevent big tech companies misusing their power over businesses and users. US businesses also have to abide by these laws if they offer their services to people in Europe, or observe their behavior.
The EU Commission has imposed numerous fines as punishment for violations of these regulations. In 2025, it fined Apple €500 million euros ($580 million). Meta, the company that operates Facebook, was fined another €200 million ($232 million).
Google had to pay €890 million ($1.03 billion) in fines this year. That sounds like a lot — but a look at the net profit of the Google corporation Alphabet puts it into perspective. In 2025, Alphabet's net profit was around €117 billion ($136 billion).
"So these are sums that a company like Google or Amazon will make in just a few days," says Penfrat. "They just include it in their budget."
Dependency on US digital services
As a result, it is not that easy for the EU to implement truly effective controls. The tech giants have global infrastructures, huge financial resources, and complex business models. European agencies first have to get past these.
Added to this is Europe's dependency on cloud services, operating systems, platforms and increasingly also AI infrastructure that, at least to date, have been provided in large part by US companies.
Penfrat criticizes Brussels for lacking the political will needed to take firmer action against these companies, and to better equip European data protection authorities.

Anthropic reported disrupting multiple attempts to use its Claude AI models for biological weapons research, missile projects, and espionage, as safety concerns grow over advanced artificial intelligence capabilities.

California Governor Gavin Newsom signed 13 new laws to protect minors online, restricting addictive social media features like infinite scrolling and algorithmic recommendations for users under 16, banning AI-generated sexual content involving minors, requiring parental controls for AI chatbots, and prohibiting AI-powered toys, citing California's approach as more effective than Australia's under-16 social media ban.

Anthropic reported blocking several malicious uses of its Claude AI models, including attempts to develop missile guidance in Yemen, Russian and Chinese cyber-espionage campaigns, Iranian influence operations, and a recruitment scheme targeting Uyghurs in Syria, while also addressing internal safety concerns and legal disputes with the Pentagon.

OpenAI has asked members of Congress for guidance on whether coordinating an industry-wide slowdown in frontier AI development would violate antitrust laws, as legal scholars warn such efforts could breach the Sherman Act, while a bipartisan bill aims to create legal channels for AI labs to collaborate on safety without antitrust risk.
OpenAI held meetings with utility executives in July to discuss deploying its AI products to counter cybersecurity threats, as reports emerged of AI-driven attacks on water systems and warnings from Anthropic researchers about uncontrolled superhuman AI posing existential risks to humanity.

LG has denied allegations that its smart televisions record ambient conversations or listen while on standby, stating that voice data is only recorded when users press and hold the voice button or activate the 'Hi LG' wake word after enabling Far-Field voice recognition. The company says audio is immediately deleted if the wake word is not recognized. The denial follows an investigative report by Gamers Nexus, Level1Techs, and independent researchers claiming LG TVs track users, harvest network data, and archive background noise up to 12 meters away, even when the microphone switch is off. Researchers allege unmatched wake-word interactions may be stored locally as plain text and uploaded later, and that TVs scan home networks for device information. LG maintains that features like ACR, voice recognition, and interest-based advertising require explicit user opt-in and can be disabled in settings.