In the quiet moment of tapping 'accept' on a permissions screen, a transaction begins that most users never fully witness. The £26 million Grindr settlement — involving 12,000 British users whose most intimate data, including HIV status, was allegedly shared with advertisers without consent — has drawn back the curtain on an industry-wide practice of assembling detailed human profiles from both disclosed and inferred personal information. Europe has built laws to resist this, yet the fines levied against Google, Meta, and Apple, though measured in the billions, dissolve into days of corporate
Digital Data Leeches: How Tech Giants Profit From Your Secrets
They just include it in their budget.
So Grindr settled for 26 million pounds. That sounds like a real consequence. Why does it matter that they didn't admit liability?
Because without an admission, there's no legal precedent. The settlement is money, but it's not a judgment. It doesn't establish that what happened was illegal—just that Grindr decided paying was cheaper than fighting.
And we should note: we don't have a court ruling on whether the data sharing actually happened. The lawsuit alleged it. Grindr denies it. The settlement doesn't resolve that factually.
But 12,000 people sued. They had evidence, presumably.
They did. But the legal system and the market system operate differently. A company can settle to make a problem go away without ever admitting the problem existed.
Right. And 26 million pounds, while real money to most people, is a rounding error for a major tech company. That's the actual story.
So the fines the EU is imposing—890 million for Google, 500 million for Apple—those are also just rounding errors?
Exactly. Alphabet made 117 billion euros in profit in 2025. The 890 million fine is less than one percent of that. It's a cost of doing business.
Though we should be careful: those fines are for specific violations—GDPR breaches, market dominance abuse. They're not fines for the data collection itself, which is technically legal if disclosed in the terms of service.
Which almost nobody reads.
Right. And even if you do read them, the terms are written to be incomprehensible. That's deliberate, according to the experts quoted here.
The source says tech companies want to "make it as difficult as possible" for users and regulators to understand what's happening. That's a strong claim. It's attributed to one expert, not proven empirically.
But it rings true from experience.
It does. And the mechanism is real: when you install WhatsApp, it uploads everyone's phone numbers without their knowledge or consent. That's documented.
Yes. And that's the part that should scare people more than the abstract idea of "profiling." Your contacts are being uploaded without their permission.
Le Pouls
- Twelve thousand Grindr users discovered that their most private details — sexual preferences, location patterns, HIV status — had allegedly been sold to advertisers without their knowledge or agreement.
- The Grindr case is not an anomaly but a window into a vast, largely invisible industry that infers income, sexuality, and home addresses from location pings and browsing habits, then packages human beings into targeting products.
- The EU's GDPR, Digital Markets Act, and Digital Services Act represent the world's most ambitious attempt to rein in this data economy, yet regulators find themselves outpaced by the complexity and global reach of the companies they are trying to govern.
- Fines totaling hundreds of millions of euros against Apple, Meta, and Google sound consequential until measured against Alphabet's 117 billion euro annual profit — at which point they become a line item, not a deterrent.
- Digital rights advocates warn that without genuine political will, adequate funding for enforcement authorities, and a reckoning with Europe's deep dependency on US tech infrastructure, the rules will remain real but the consequences will not.
In the quiet moment of tapping 'accept' on a permissions screen, a transaction begins that most users never fully witness. The £26 million Grindr settlement — involving 12,000 British users whose most intimate data, including HIV status, was allegedly shared with advertisers without consent — has drawn back the curtain on an industry-wide practice of assembling detailed human profiles from both disclosed and inferred personal information. Europe has built laws to resist this, yet the fines levied against Google, Meta, and Apple, though measured in the billions, dissolve into days of corporate profit — leaving the machinery largely intact.
When a user taps 'accept' on an app's permission request, they are thinking about convenience. What they are rarely thinking about is the elaborate transaction that follows — one that happens largely out of sight.
The Grindr case brought that transaction into sharp relief. Around 12,000 users in Britain alleged that the LGBTQ+ dating app had shared their most sensitive personal information — including sexual preferences, location patterns, and in some cases HIV status — with advertisers, without their consent. Grindr agreed this week to pay £26 million to settle the claims, though the company has not admitted wrongdoing. For those affected, the settlement is at least a partial acknowledgment that something went wrong.
But Grindr is one node in a much larger system. When users grant apps access to their contacts, location, or browsing behavior, that data flows into profiles of extraordinary detail. Tech companies infer income from neighborhood data, sexual orientation from location history, and domestic arrangements from overnight GPS patterns. These inferences are bundled with voluntarily provided information and sold as targeting access to advertisers — who never need to know a user's name, only that the user fits the profile.
The European Union has tried to push back. The GDPR, the Digital Markets Act, and the Digital Services Act together form one of the world's most ambitious data protection frameworks. Fines have followed: Apple paid 500 million euros in 2025, Meta 200 million, Google 890 million. The figures are large in isolation. Against Alphabet's annual net profit of roughly 117 billion euros, they represent days of earnings — something companies can simply absorb into their operating budgets.
Digital rights advocates point to a structural problem: European regulators are navigating business models of extraordinary complexity, while the continent remains deeply dependent on US companies for cloud infrastructure, operating systems, and AI services. That dependency erodes leverage. Without stronger political will and properly funded enforcement authorities, the rules exist — but the penalties are too small to change behavior. The machinery keeps running.
When you install an app and tap yes to its permission request, you're usually thinking about convenience. You want the app to work. You don't think much beyond that moment. But what happens next—where your data goes, who sees it, what gets built from it—is the real transaction taking place, and it happens largely out of view.
The Grindr case makes this visible in the starkest possible way. Around 12,000 users in Britain sued the dating app, which caters to the LGBTQ+ community, alleging that it had shared their most intimate information with advertisers without permission. The data in question wasn't vague or generic. It included sexual preferences, location patterns, and in some instances, HIV status. Earlier this week, Grindr agreed to pay the claimants 26 million pounds—roughly 30 million euros or 35 million dollars. The company has not admitted wrongdoing and continues to dispute the allegations, but the settlement stands. For the users involved, it represents at least some acknowledgment that something went wrong.
Grindr is one case, but it illuminates a much larger machinery. When you give WhatsApp access to your phone's contacts, the app uploads all those phone numbers to its servers—including numbers belonging to people who don't use WhatsApp and never consented to having their information shared. That data flows into what digital policy experts call an "enormous profile." Google and other major tech companies then package these profiles into targeting products. A car manufacturer or clothing brand can tell Google: reach these people, show them my ads across Google Search, Gmail, and hundreds of millions of third-party websites that run Google's advertising network. The advertiser doesn't need to know your name. They just need to know you fit the target.
These profiles are built from two streams of data. Some comes from what you voluntarily enter—your stated preferences, photos you upload, information you type into your profile. But much of it is inferred. If a company has your location data and knows where you spend your nights, it can assume that's your home address. If that address is in an expensive neighborhood, the company can estimate your income. If your phone's location history shows you regularly visiting a gay club, the inference becomes obvious. All of this gets added to the profile, sorted, and sold.
The European Union has built some of the world's strictest data protection laws to push back against this. The General Data Protection Regulation, or GDPR, aims to protect personal data and privacy. The Digital Markets Act and Digital Services Act are meant to prevent tech companies from abusing their power. US companies operating in Europe must comply. The EU Commission has imposed substantial fines: Apple paid 500 million euros in 2025, Meta paid 200 million euros, Google paid 890 million euros. These are large numbers. But they need context. Alphabet, Google's parent company, had a net profit of around 117 billion euros in 2025. The fines amount to days of profit. "They just include it in their budget," says Jan Penfrat, a digital policy expert at European Digital Rights, an NGO network defending fundamental rights in the digital realm.
This is where the enforcement gap becomes clear. Tech giants have global infrastructure, enormous financial resources, and business models so complex that European regulators struggle to navigate them. Europe also depends heavily on US companies for cloud services, operating systems, platforms, and increasingly AI infrastructure. That dependency limits Europe's leverage. Penfrat argues that Brussels lacks the political will to take firmer action and to properly fund the data protection authorities that would need to enforce it. The result is a system where the rules exist but the penalties are too small to change behavior. The machinery keeps running.
Citations marquantes
All of this flows into an enormous profile.— Jan Penfrat, digital policy expert at European Digital Rights
These are sums that a company like Google or Amazon will make in just a few days.— Jan Penfrat, on EU fines relative to tech company profits