Everyone has information they would not share with just anyone. Yet people often entrust intimate details to dating apps: the kind of partner they seek, where they look for one, their sexual preferences, or information about their health.
This data is intended to help apps find suitable matches. Users do not expect it to be sold to other companies.
That is what roughly 12,000 users in Britain allegedly experienced with Grindr, a dating app aimed at the LGBTQ+ community. The users claimed the company shared highly sensitive personal information with advertisers, including HIV status in some cases.
A lawsuit filed in 2024 was settled earlier this week. Grindr has agreed to pay the claimants a combined £26 million (€30 million; $35 million), while stressing that the payment is not an admission of liability. The company continues to dispute the allegations, and no legal judgment has been made.
What happens to the information users give apps?
The Grindr case is only one of many that raise a broader question: What happens to the information people entrust to apps every day?
To users, an app may appear to be a simple product. In reality, it often relies on cloud services, analytics tools, advertising networks, and other providers that collect, transfer, combine, and analyze data—sometimes in ways that conflict with users’ interests.
Jan Penfrat, a digital policy expert, says many major technology companies want “to make it as difficult as possible for users and regulators to understand what data is collected on our devices, by whom, and for what purpose.”
Penfrat works for European Digital Rights (EDRi), a European network of NGOs and specialists campaigning to defend fundamental rights and freedoms online.
This issue is easy to overlook. After quickly installing an app or messaging service, users are often asked to approve access to personal data—and may simply select “yes” without reading the terms.
Phone numbers can be uploaded without consent
The details matter. When someone installs WhatsApp, for example, the app can access the contacts stored on their phone. Those phone numbers are then sent to its servers, including the numbers of people who do not use WhatsApp and have not agreed to have their contact information shared.
“All of this flows into an enormous profile,” Penfrat says.
Designed to fail: What dating apps really want from you
To view this video please enable JavaScript, and consider upgrading to a web browser that supports HTML5 video
Companies such as Google then use this information to offer targeted advertising products.
“A car manufacturer or clothing company can choose specific audience groups and place its ads in Google searches, Gmail, or hundreds of millions of third-party websites that use Google advertising,” Penfrat explains.
How data profiles are created
Google is one of many companies that build and offer data profiles. These profiles draw on two main sources. One is information that users voluntarily provide, such as details entered into an account or private photos uploaded to a platform.
The other comes from inferences made by major technology companies based on the data they collect.
“If a company can access my location data and determine where I usually spend the night, it can infer my home address,” Penfrat says.
Who is in control of your data?
To view this video please enable JavaScript, and consider upgrading to a web browser that supports HTML5 video
“If someone regularly appears in an expensive part of a city, a company can draw conclusions about their income. If location services show that they frequently visit a gay club, the company may infer that they are part of the LGBTQ+ community. That information is then added to their profile,” Penfrat says.
Europe’s strict data rules face enforcement challenges
Europe already has one of the world’s strictest data protection frameworks. The General Data Protection Regulation (GDPR) is designed to safeguard personal data and privacy.
Other European digital laws, including the Digital Markets Act and Digital Services Act, seek to stop major technology companies from abusing their power over businesses and users. U.S. companies must also comply with these rules when providing services to, or monitoring the behavior of, people in Europe.
The European Commission has issued numerous fines for violations. In 2025, it fined Apple €500 million ($580 million), while Meta, the company behind Facebook, was fined another €200 million ($232 million).
Google also had to pay an €890 million ($1.03 billion) fine this year. Although substantial, that figure is modest compared with Alphabet’s net profit. In 2025, Alphabet earned approximately €117 billion ($136 billion).
“These are amounts that companies such as Google or Amazon can earn in just a few days,” Penfrat says. “They simply include them in their budgets.”
Europe’s dependence on U.S. digital services
Effective oversight remains difficult because technology giants operate global infrastructures, possess immense financial resources, and use complex business models. European regulators must first overcome those barriers.
Europe’s quest for digital independence
To view this video please enable JavaScript, and consider upgrading to a web browser that supports HTML5 video
Europe is also dependent on cloud services, operating systems, digital platforms, and increasingly AI infrastructure that have so far been provided largely by U.S. companies.
Penfrat criticizes Brussels for lacking the political will to take stronger action against these companies and to give European data protection authorities greater resources.
Also Read
- Man Utd cruise past Sabah on Champions League return with 4-0 win
- BRICS Summit Marks Dual Milestones Amid Deepening Energy Ties and Cohesion Challenges
- Trump promises to send $500 to nearly 1 million Americans for Obamacare ‘overcharges’
- Oil Prices Rise Dramatically as Regional Conflict Fuels Global Supply Pressures

