Rights International Spain (RIS) – No Violation (Spain, 2022)

No Violation
Agencia Española de Protección de Datos17 January 2022Spain
final
No Violation

A Spanish data protection authority found no violation against Grindr, a social networking app, despite concerns raised about its data practices. The authority decided that the claims did not meet the necessary criteria for a violation. This case illustrates the challenges in holding companies accountable for data practices.

What happened

Rights International Spain filed a complaint against Grindr for allegedly mishandling user data, but the authority found no violation.

Who was affected

Users of the Grindr app, particularly those concerned about their data privacy, were affected by this case.

What the authority found

The authority concluded that there was insufficient evidence to support the claims of data mishandling against Grindr.

Why this matters

This ruling indicates that proving data violations can be complex, and it may be difficult for users to hold companies accountable. It serves as a reminder for users to be vigilant about their data privacy.

GDPR Articles Cited

AI-verified

Art. 7(GDPR)
Art. 12(GDPR)
Art. 13(GDPR)
Art. 22(GDPR)
Art. 5(1)(a) GDPR
Art. 6(1)(a) GDPR
Art. 61(GDPR)
Art. 9(2) GDPR
View original scraped data
Art. 5(1)(a) GDPR
Art. 6(1)(a) GDPR
Art. 7(GDPR)
Art. 9(1) GDPR
Art. 12(GDPR)
Art. 13(GDPR)
Art. 22(GDPR)
Art. 61(GDPR)

Original data from scraper before AI verification against source document.

Entities Involved

Rights International Spain (RIS)
GRINDR LLC
Source verified 9 April 2026
articles corrected
Full Legal Summary
Detailed

Rights International Spain (RIS), a Spanish human rights NGO, filed a claim against LGBTQ Social Network App GRINDR (Grindr LLC) with the Spanish DPA (AEPD) on 9 March 2020. The claim was based on the [https://www.forbrukerradet.no/out-of-control/ “Out of Control” report] on targeted advertising practices published by the Norwegian Consumer Council (NCC), and the claimant selected Grindr as an example of potentially problematic data mining practices without data subject’s knowledge and consent. = The AEPD inquired if any other DPAs were carrying out procedures on this topic through the mutual assistance provision in Article 61 GDPR. The AEDP received affirmative replies from the Norwegian, Slovenian and French DPA. The Norwegian DPA informed the AEPD that its current investigation was in response to a claim received in January 2020. Hence, it was basing its investigation on Grindr’s active Consent Management Platform (CMP) at that time, and not on the updated CMP introduced in April 2020. The Norwegian DPA expressed that, according to their investigation, the consent obtained by Grindr for processing personal data used for marketing purposes seemed to be in breach of GDPR (see the summary of the Norwegian DPA's Grindr decision here). The Norwegian DPA also considered that Grindr was specifically oriented towards the LGBTQ community, and therefore, a legal basis under Article 9(2) GDPR for the processing of special categories of data was also required in this case. The Slovenian DPA informed the AEPD that it had also received a claim based on the same report, and was still awaiting a reply from Grindr’s representatives. The French DPA stated that it had received two complaints regarding this issue, but had not yet initiated any procedures at that moment. = In its response to the AEPD, Grindr highlighted that it had updated its CMP, which gives the data subject granular information regarding every non-essential processing element, allowing the user to activel

Outcome

No Violation

The DPA investigated and found no violation.

Violations (1)

Third-Party Cookies Without Consent
critical

Third-party tracking cookies or scripts are loaded without obtaining prior user consent.

Art. 13, 14 GDPR

Related Enforcement Actions (0)

No other enforcement actions found for Rights International Spain (RIS) in ES

This is the only recorded action for this entity in this jurisdiction.

Details

Decision Date

17 January 2022

Authority

Agencia Española de Protección de Datos

GDPRhub ID

gdprhub-4539

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Rights International Spain (RIS) - Spain (2022). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: