Skip to main content
When Past Owners Left Privacy LandminesSupervisory Authorities & Enforcement
6 min readFor Data Protection Officers (DPOs)

When Past Owners Left Privacy Landmines

These questions come from a DPO roundtable I attended last month, right after Grindr's £26m settlement hit the news. The room went quiet when someone asked: "Could our pre-acquisition data practices trigger a claim like this?" That silence told me everything. Most teams don't have a clear answer.

The Grindr case isn't just about one app's mistakes. It's about what happens when historical data practices collide with current accountability. The settlement covered data sharing between 2016 and 2020, under previous ownership by Kunlun, yet the current company paid the price. No admission of liability, but £26m speaks louder than any legal disclaimer.

Here's what practitioners are actually asking when they see cases like this.

Can We Be Held Liable for Previous Owners' Actions?

Yes, and the Grindr settlement demonstrates exactly that risk.

When ownership changes, the legal entity controlling the data may change, but the data itself doesn't get a clean slate. If you're the current controller, you inherit the compliance position. Article 82 GDPR makes controllers liable for damage caused by processing that infringes the regulation, and claimants don't need to prove which specific owner was at fault if the processing was continuous.

Your practical exposure depends on three factors: whether the previous owner's practices violated GDPR (or its predecessor, the Data Protection Directive), whether affected individuals can demonstrate material or non-material damage, and whether your acquisition agreement addressed indemnification for historical claims.

The Grindr case involved sharing HIV status, PrEP usage, ethnicity, and sexual orientation data with analytics providers Apptimize and Localytics. That's Article 9 special category data, which requires explicit consent or another Article 9(2) condition. The claim alleged inadequate consent, and while Grindr disputes the allegations, the settlement amount suggests the risk was real enough.

What you should do now: pull your acquisition documentation and check whether it includes representations about historical data practices and indemnification for privacy claims. If you acquired a company in the past five years and don't have clear answers about their pre-acquisition consent mechanisms, data sharing arrangements, or processor contracts, you've got a gap.

How Far Back Should We Audit Historical Practices?

Start with the GDPR limitation period in your primary jurisdiction, but don't stop there.

In the UK, claims under the Data Protection Act 2018 generally face a six-year limitation period from when the cause of action accrued. The Grindr claim covered 2016-2020, filed in April 2024. That's within scope, even for practices that predate GDPR's May 2018 application date, because the Data Protection Directive established similar protections for special category data.

Your audit window should cover at minimum:

  • Six years back from today for UK exposure
  • The period since GDPR application (May 25, 2018) for all EU/EEA jurisdictions
  • Any period where you processed special category data without documented lawful basis, regardless of date

Focus your audit on special category data first. The Grindr case centered on health data (HIV status, PrEP usage) and data concerning sex life or sexual orientation. These categories carry the highest risk because they require explicit consent or a specific Article 9(2) condition, and because supervisory authorities treat violations more seriously. Norway's supervisory authority fined Grindr €6.5m in 2021 for sharing user data for behavioral advertising without proper lawful basis, a penalty upheld in Oslo District Court in 2024.

Don't limit your review to what you think was "sensitive." The UK Information Commissioner's Office reprimanded Grindr in July 2022 for failing to provide effective transparency information to UK users. Basic transparency obligations apply to all personal data, and violations can support civil claims even without special category data involved.

What If We Can't Find Documentation from That Period?

Missing documentation is evidence of a control failure, not a defense.

Article 5(2) requires you to demonstrate compliance, not just claim it. If you can't produce consent records, processor agreements, or legitimate interests assessments from the relevant period, you can't demonstrate that processing was lawful. In litigation, that gap works against you.

Practical steps when documentation is missing:

  • Interview staff who were present during that period and document what they remember about data practices, consent flows, and third-party sharing
  • Pull server logs, email archives, and contract repositories to reconstruct what actually happened
  • Review any supervisory authority correspondence or audit findings from that timeframe
  • Check whether your processors from that period retained their own copies of data processing agreements

If you discover that historical practices likely violated GDPR and you can't prove otherwise, you need to assess your exposure. Calculate the potential claimant pool (how many individuals were affected), the severity of the violation (was it special category data? was it shared with third parties?), and whether those individuals have demonstrable harm.

Grindr's settlement covered approximately 12,000 claimants represented by Austen Hays. The £26m figure works out to roughly £2,167 per person if distributed equally, though the actual distribution method hasn't been confirmed. That gives you a rough benchmark for UK special category data claims, though your exposure will vary based on the specific facts.

Should We Proactively Contact Affected Users About Historical Issues?

Only if you're prepared to manage the response, and only after legal counsel reviews the approach.

Proactive notification can demonstrate good faith and potentially reduce damages in civil litigation, but it also creates evidence that you knew about the problem and triggers transparency obligations under Article 34 (if it's a personal data breach) or Article 13/14 (if it's a transparency gap).

The Grindr filing acknowledged "distress and loss of trust expressed by some UK users over the pre-2020 period." That language suggests they were already hearing from affected individuals before the formal claim was filed. If you're in that position, proactive outreach may be moot.

Consider notification when:

  • You've discovered a clear violation that affected a defined group
  • You can offer a concrete remedy (account deletion, compensation, enhanced controls)
  • Legal counsel confirms that notification won't waive privilege or create additional liability
  • You have the operational capacity to handle the volume of responses

Don't notify if you're still investigating and don't have facts yet. Premature notification creates confusion and locks you into a narrative before you understand the full scope.

How Do We Prevent This from Happening Again?

Build ownership transition reviews into your M&A playbook and your annual compliance calendar.

For acquisitions: before you close, require the target to produce documentation of their current data inventory, lawful basis for each processing activity, processor agreements, and any open supervisory authority matters. Include specific reps and warranties about GDPR compliance in the purchase agreement, with indemnification for pre-closing violations. Within 90 days post-close, conduct a full Article 30 records review and remediate gaps.

For divestitures: document your current state before the sale, so you can defend against claims that the buyer inherited. Negotiate carefully about who retains liability for which time periods.

For ongoing governance: review your Article 30 records annually, not just when regulators ask. Grindr said it overhauled its privacy program after the 2020 ownership change and described itself as committed to transparency and user control. That's the right direction, but it didn't erase the exposure from 2016-2020.

If you process special category data, document your Article 9(2) condition for every processing activity, maintain consent records with timestamps and the specific consent language used, and audit your processor contracts to confirm they're not using your data for their own purposes.

Where to Go for More

Review your supervisory authority's guidance on special category data processing. The ICO's guidance on lawful basis and the EDPB's guidelines on consent (05/2020) provide the framework you need. If you're facing a potential claim, engage litigation counsel who understand GDPR civil liability, not just regulatory enforcement. The two require different strategies.

And if you're about to acquire a company that processes health data, dating preferences, or other Article 9 categories, add six months to your due diligence timeline. The cost of getting it right is a fraction of a £26m settlement.

You Might Also Like