Norway fines Grindr for $7.3 million over privacy breach
Full article618 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
Grindr disputes the agency's findings.
Norway’s data protection agency is fining LGBTQ+ social app Grindr nearly $7.1 million for unlawfully disclosing personal data to third parties for marketing.
The ruling follows a 2020 complaint by the Norwegian Consumer Council alleging that Grindr shared user device data with third parties that, due to the nature of the app, effectively allowed advertisers to connect those users with information about their sexual orientation.
The Norwegian DPA, known as Datatilsynet, concluded that Grindr did not have proper consent mechanisms in place allowing users to specifically opt-in to the sharing of their data for advertisements by third parties.
“We consider that data revealing the fact that someone is a Grindr user strongly indicates that they belong to a sexual minority,” the DPA wrote. “Data concerning a person’s sexual orientation constitutes special category data that merit particular protection under the GDPR. As the consents Grindr collected were not valid, Grindr could not lawfully share such data.”
The fine is slightly less than the $12 million the Norwegian regulator announced it intended to issue earlier this year. The authority cited additional financial information about Grindr and changes made by the company to address the privacy concerns in its final determination.
Grindr is disputing the findings and is weighing its right to appeal under Europe’s General Data Protection Regulation (GDPR), company chief privacy officer Shane Wiley said in a statement.
“We strongly disagree with Datatilsynet’s reasoning, which concerns historical consent practices from years ago, not our current consent practices or Privacy Policy,” Wiley said in a statement. “Even though Datatilsynet has lowered the fine compared to their earlier letter, Datatilsynet relies on a series of flawed findings, introduces many untested legal perspectives, and the proposed fine is therefore still entirely out of proportion with those flawed findings.”
The investigation covers the app’s policies in Norway between July 2018 and April 2020, when the company changed how it asked for consent in response to the complaint. The DPA’s investigations into the five advertising partners that received data from Grindr are still ongoing.
Latest Podcasts
Government
Technology
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/grindr-norway-gdpr-violation-fine/