News: 1696545098

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

EPIC urges watchdog to probe Grindr's data privacy – or alleged lack thereof

(2023/10/06)


Grindr isn't doing a very good job protecting its users' private information, including their NSFW photos, according to the Electronic Privacy Information Center (EPIC), which wants the FTC to investigate potentially unlawful practices by the LGBTQ+ dating app.

On Wednesday, EPIC filed a complaint with the US government watchdog over Grindr's "apparent failure to safeguard users' sensitive personal data." This includes both present and past users who have since deleted their accounts, according to the complaint. Despite promising in its [1]privacy policy to delete personal info if customers remove their account, Grindr allegedly retained and disclosed some of this data to third parties.

Considering that people trust the dating app with a ton of very sensitive information — this includes their sexual preferences, self-reported HIV status, chat history, photos including nudes, and location information — "learning that Grindr breaks the promises it makes to users would likely affect a consumer's decision regarding whether to use Grindr," the complaint states

[2]PDF

.

[3]

Grindr, for its part, says privacy is of the uppermost importance to it, and that these "unfounded" claims stem from allegations made by a disgruntled ex-worker. So that's all right then.

[4]

[5]

"Privacy is a top priority for Grindr and the LGBTQ+ community we serve, and we have adopted industry-leading privacy practices and tools to protect and empower our users," a spokesperson told The Register .

"We are sorry that the former employee behind the unfounded allegations in today's request is dissatisfied with his departure from the company; we wish him the best."

[6]

The former employee in question is Grindr's ex-chief privacy officer Ron De Jesus. In June, De Jesus filed a wrongful termination lawsuit

[7]PDF

against his former bosses that also accused the dating app of violating privacy laws.

According to the lawsuit, De Jesus was "leading the charge to keep Grindr compliant with state, national, and international laws" after Norway's data protection agency [8]fined the dating app biz about $12 million in December 2021 and a Wall Street Journal [9]article in May 2022 accused the application developer of selling users' location data.

[10]LGBTQ+ folks warned of dating app extortion scams

[11]Catholic clergy surveillance org 'outs gay priests'

[12]Amazon had secret algorithm to hike prices, claims FTC

[13]Game on: FTC tries again to block Microsoft Activision merger

But despite De Jesus' attempts, "Grindr placed profit over privacy and got rid of Mr De Jesus for his efforts and reports," the lawsuit alleges.

EPIC's complaint, which highlights De Jesus' allegations, asks the FTC to look into potential violations of privacy law, including detection data retention and disclosure practices.

It also accuses Grindr of violating the Health Breach Notification Rule (HNBR). The dating app is subject to the HNBR because it asks users to self-report health data including HIV status, last-tested date, and vaccination status. By sharing these records with third parties and retaining health data after users deleted their accounts, Grindr allegedly breached the HNBR, EPIC says.

[14]

The privacy advocates at EPIC want the FTC to make Grindr comply with the laws and stop any "unlawful or impermissible" data retention practices. Additionally, the complaint calls on the federal agency to force Grindr to notify any users' whose data was misused, and impose fines against the dating app for any violations of the HBNR. ®

Get our [15]Tech Resources



[1] https://www.grindr.com/privacy-policy

[2] https://epic.org/wp-content/uploads/2023/10/EPIC-FTC-Grindr-Complaint.pdf

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/bootnotes&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZR@GZRKgKzxzI0iR0aks2QAAAEY&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/bootnotes&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZR@GZRKgKzxzI0iR0aks2QAAAEY&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/bootnotes&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZR@GZRKgKzxzI0iR0aks2QAAAEY&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/bootnotes&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZR@GZRKgKzxzI0iR0aks2QAAAEY&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[7] https://www.bloomberglaw.com/public/desktop/document/ManuallyCollectedComplaint/188?doc_id=X4FD3TJNKQH897QGRKS05OICKS9

[8] https://edpb.europa.eu/news/national-news/2021/norwegian-dpa-imposes-fine-against-grindr-llc_en

[9] https://www.wsj.com/articles/grindr-user-data-has-been-for-sale-for-years-11651492800

[10] https://www.theregister.com/2022/06/27/ftc-lgbtq-extortion/

[11] https://www.theregister.com/2023/03/10/catholic_clergy_surveillance/

[12] https://www.theregister.com/2023/10/04/amazon_project_nessie_algorithm/

[13] https://www.theregister.com/2023/09/27/ftc_microsoft_activision/

[14] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/bootnotes&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZR@GZRKgKzxzI0iR0aks2QAAAEY&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[15] https://whitepapers.theregister.com/



Privacy as the dev's last priority

Anonymous Coward

Unfortunately data deletion is not cost-efficient and typically not pre-programmed in databases. Cloud providers charge for data deletion. Ideally all data should be deleted automatically on regular basis unless a user id still exists. But this is wishful thinking.

Here is my experience with another (non-dating) platform. I requested account deletion. First it took months with deletion not happening. After nagging them again, they finally deleted my login. But I could still see my pictures online by searching them in Google. And the content was still accessible by URLs for a year or two. At this point I gave up, as the pictures were not too sensitive.

Similar story with other services. I am frustrated for the huge number of even larger companies mishandling the data. Smaller companies are a pure disaster: every time they ask for personal details, I know they will soon end up in some data souk.

My less paranoid/sophisticated friends are much happier. They simply do not care.

Young men, hear an old man to whom old men hearkened when he was young.
-- Augustus Caesar