Grindr given €6.5 million GDPR fine for selling special category user data without consent
The Norwegian DPA claims users' sexual orientations were exposed following the sale of data to third parties
Datatilsynet, the Norwegian Data Protection Authority (DPA), has fined location-based LGBTQ+ dating app Grindr €6.5 million (£5.4 million) for selling user data for advertising purposes without consent.
Considered the largest GDPR fine issued by the Nowegian authority to date, the penalty states Grindr unlawfully shared personal data of users with third parties for advertising and marketing purposes.
The fine was ultimately reduced from its initial sum of 100,000,000 NOK (£8.2 million) as a result of Grindr's co-operation with the Norwegian DPA and quick fixes to remediate its consent management platform.
Describing Grindr's infringements as "grave", the authority said that user GPS locations, IP addresses, advertising IDs, ages, and genders were included in the data shared with third parties. It also concluded that the fact users had been identified as Grindr account holders meant that sexual orienation data had been shared, which is considered a special category under GDPR and requires additional justification for processing.
"We consider that data revealing the fact that someone is a Grindr user strongly indicates that they belong to a sexual minority," said the Norwegian DPA. "Data concerning a person’s sexual orientation constitutes special category data that merit particular protection under the GDPR. As the consents Grindr collected were not valid, Grindr could not lawfully share such data.
"While it not defined as special categories of personal data in itself, location data is sensitive and personal. The fact that Grindr has also shared this data unlawfully adds to the severity of the case."
The fine is the largest ever issued by the Norwegian DPA, which said further orders may be issued to Grindr. The Norwegian Consumer Council, which originally filed the complaint against the company, has already claimed the dating app infringed additional provisions of GDPR and has asked the DPA to order Grindr to erase the illegally processed data.
Protecting every edge to make hackers’ jobs harder, not yours
How to support and secure hybrid architecturesFree download
Grindr has a three-week window in which it can launch an appeal to the fine, which may be extended depending on circumstances, the DPA said.
"Even though Datatilsynet has lowered the fine compared to their earlier letter, Datatilsynet relies on a series of flawed findings, introduces many untested legal perspectives, and the proposed fine is therefore still entirely out of proportion with those flawed findings.
"We’ve just received a copy of the letter from Datatilsynet and are analysing the document. The Company is considering its options including the right to appeal the findings to the Personvernnemnda (PVN - Appeal Board)," he added.
How virtual desktop infrastructure enables digital transformation
Challenges and benefits of VDIFree download
The Okta digital trust index
Exploring the human edge of trustFree download
Optimising workload placement in your hybrid cloud
Deliver increased IT agility with the cloudFree Download
Modernise endpoint protection and leave your legacy challenges behind
The risk of keeping your legacy endpoint security toolsDownload now