News

πŸ‡³πŸ‡΄ Sharing data without a legal basis!

Data Transfers, Legal basis | 27/03/2025

πŸ‡³πŸ‡΄ Norway: Dating App Fined for Illegal Disclosure of User Data πŸ‡³πŸ‡΄

The dating app Grindr, dedicated to gay, bi, trans, and queer individuals, with 13.7 million users, has been fined €6.5 million in Norway for illegally sharing user data for advertising purposes.

Facts:

Grindr was collecting and sharing personal data, including:

  • πŸ“ GPS Location
  • πŸ“± IP Address and Phone Information
  • πŸ“Š Age
  • 🏳️‍🌈 Sexual Orientation

Violation of Article 9 of the GDPR: Sensitive Data

Data concerning a person’s sexual orientation constitutes sensitive data.
Article 9 of the GDPR prohibits its processing unless one of the following conditions is met:

  • Explicit consent from the individual concerned.

Grindr did not properly inform its users that it was collecting and sharing their data without a legal basis, violating Article 6 of the GDPR.

Lack of Transparency:

  • Information about the sharing of personal data was not communicated clearly to users.
  • The Norwegian Authority concluded:
    • The collected consent was invalid.
    • Being identified as a Grindr user strongly indicated an individual’s sexual orientation, requiring special protection under the GDPR.

Consequences:

  • πŸ’° Administrative Fine: €6.5 million.
  • πŸ“’ Public Decision: Significant reputational impact for Grindr.

πŸ”§ Best Practices for GDPR Compliance

To avoid such penalties, companies must:

  • πŸ”’ Protect Sensitive Data: Obtain explicit consent before processing data related to sexual orientation.
  • πŸ“„ Ensure Transparency: Clearly inform users about how their data is processed and shared.
  • βœ… Verify Consent Validity: Consent must be free, specific, informed, and unambiguous to comply with the GDPR.
  • 🚫 Limit Data Sharing: Avoid sharing sensitive data with third parties without a solid legal basis.
Back to news list

Explore all our areas of expertise:

]]>