55 episodes
- In this episode of the Privacy Partnership Podcast, Robert Bateman unpacks Grindr's recent agreement to pay £26 million to settle a major UK data privacy lawsuit. The UK is currently viewed as a highly conservative, even hostile, environment for mass privacy claims. So how did a payout of this magnitude happen?
Robert breaks down the historical data sharing allegations, the regulatory backdrop, and the critical procedural differences that set this actively managed group litigation apart from recent representative action failures.
Key Topics Discussed
The £26 Million Settlement: An overview of Grindr’s agreement to settle UK High Court proceedings brought by approximately 12,000 users. The claims concerned pre-2020 data practices (under former owner Kunlun) and included allegations of the unauthorised sharing of highly sensitive information, such as HIV status and testing dates.
Grindr's Position: Grindr disputes the allegations, and the settlement includes no findings or admission of liability. The company says it has overhauled its privacy programme since 2020 and agreed to pay the £26 million in two installments by March 2027.
The Regulatory Backdrop: A look back at how regulators have previously handled Grindr’s adtech practices, including a 2022 reprimand from the UK’s ICO and a 65 million NOK fine from Norway’s Datatilsynet (upheld on appeal in October 2025).
The UK Litigation Landscape: Why the UK is currently a tough jurisdiction for mass privacy claims. Robert explores how the landmark Lloyd v Google Supreme Court decision blocked uniform damages for "loss of control" under the Data Protection Act 1998 without proving individual damage or distress.
Why This Case is Different: Why didn't this claim fail like the representative action involving sensitive medical records in Prismall v Google? We discuss how claimant firm Austen Hays gathered 12,000 signed-up individuals to bring specific allegations of distress, and why the immense cost and complexity of defending a bifurcated trial likely drove a pragmatic settlement.
Cases & Regulatory Actions Mentioned
Grindr High Court Settlement (Sept 2026): £26 million settlement for UK users represented by Austen Hays.
Lloyd v Google (2021): Supreme Court ruling effectively blocking opt-out representative actions for uniform data protection damages under the DPA 1998.
Farley v Paymaster (Aug 2025): Court of Appeal ruling establishing that claims for compensation based on a fear of third-party misuse must be "well-founded" and assessed case-by-case. (The Supreme Court appeal is listed for 7-8 October 2026).
Prismall v Google: High Court case demonstrating that representative actions involving even highly sensitive data (medical records) will fail if they attempt to bypass individual assessments.
Datatilsynet vs. Grindr (2021/2025): 65 million NOK fine for unlawful behavioural advertising disclosures, upheld by the Borgarting Court of Appeal.
ICO Reprimand (July 2022): UK regulator's finding against Grindr regarding transparent privacy information.
Get in Touch
If your organisation needs support navigating adtech compliance, data protection litigation, or evaluating its financial exposure, reach out to us at Privacy Partnership. - n this late-summer roundup episode of the Privacy Partnership Podcast, host Robert Bateman unpacks a massive €825 million GDPR fine, the immediate impact of the EU AI Act taking effect, and a wave of enforcement actions across the UK, Europe, and the United States.
In this episode, we cover:
Mind the Gap (UK ICO Enforcement): Why the disconnect between an organisation's written privacy policies and its actual practices is a major regulatory red flag. Robert discusses recent reprimands for the Metropolitan Police Service and ACRO Criminal Records Office, highlighting the dangers of ignored mandatory training, unpatched software, and inadequate logging.
Automated Decision-Making Under Fire: A deep dive into the Dutch DPA's record-breaking €825 million fine against Uber for automatically deactivating drivers' accounts without human review. Plus, we look at similar Article 22 enforcement actions by the Italian Garante against energy suppliers, and noyb's data retention challenge against SCHUFA.
The EU AI Act Meets the GDPR: The AI Act reached its general application date in August. We break down the immediate impact of Article 50's transparency rules for generative AI and deepfakes. Furthermore, a recent Italian Garante ruling on satirical deepfakes of a journalist serves as a stark reminder that complying with the AI Act does not mean you can ignore the GDPR.
US Privacy Updates: A quick-fire roundup of major transatlantic developments, including California's regulatory action against unregistered data brokers, New Jersey's new Kids Code Act, the FTC's consultation on the privacy implications of personalised pricing, and TikTok’s massive $400 million children's privacy settlement with the DOJ.
Resources & Links
Links to all the regulatory decisions, enforcement notices, and legislation discussed in this episode are available in the September Privacy Partnership newsletter, delivered directly to our clients. France fails to ban kids from social media: Age assurance remains privacy's "hard problem"
19/08/2026 | 7 mins.France’s Constitutional Council has struck down the central provision of a new law that would have banned under-15s from accessing social media.
In this episode, Robert Bateman looks at why the Council found the measure disproportionate, focusing on two fundamental rights: freedom of expression and the right to private life.
The decision also highlights a longstanding problem with age assurance: to identify children online, platforms may need to establish the age of everyone else too.
Topics covered include:
France’s proposed under-15 social media ban
The Constitutional Council’s decision of 14 August 2026
Freedom of expression and access to online services
The privacy implications of universal age assurance
Why this was a constitutional ruling, rather than a GDPR judgment
The difficulty of balancing children’s safety against privacy
Whether privacy and child protection sometimes involve a genuine trade-offIs TikTok a patron of the arts? How an appeal under the "special purposes" exemption failed
06/08/2026 | 4 mins.In this episode of the Privacy Partnership Podcast, Robert Bateman dives into a fascinating and highly creative legal defense recently mounted by TikTok. Facing a £12.7 million fine from the UK Information Commissioner's Office (ICO) for processing the data of underage children, TikTok attempted to use a jurisdictional trump card: the "special purposes" exemption under Section 156 of the Data Protection Act 2018.
Did TikTok’s recommender algorithm process user data for "artistic purposes"? Should the platform be shielded by freedom of expression laws? And how did a philosophy professor from Oxford end up testifying at a data protection tribunal? Robert breaks down the Upper Tribunal's July 2026 ruling, explaining why tech platforms can't retrofit a fundamental rights defense onto an engagement-driven algorithm.
Key Topics Covered:
The £12.7m Penalty: The background of the ICO's enforcement action against TikTok for age-gating failures and processing the data of under-13s without parental consent.
The "Special Purposes" Exemption: A look at Section 156 of the DPA 2018, which provides procedural safeguards (including court approval) before a regulator can penalize processing done for journalistic, academic, literary, or artistic purposes.
The "What is Art?" Debate: TikTok's argument that its platform facilitates artistic expression, and why the Upper Tribunal decided to sidestep the philosophical debate entirely.
Algorithm vs. Intent: Why the Upper Tribunal ruled that an engagement-driven recommender system—which is completely indifferent to whether a video is actually "art"—cannot be said to be processing data for an artistic purpose.
The Underage Contradiction: The fatal flaw in TikTok claiming to facilitate the artistic expression of under-13s while simultaneously banning them in their own Terms of Service.
Articles 12 & 13 as Procedural Obligations: Why the Tribunal rejected TikTok’s attempt to classify transparency and privacy notice failings as "processing" breaches.- Can you scrape the internet for AI training data without completely running afoul of the GDPR? The European Data Protection Board (EDPB) has finally offered an answer: Yes, but get ready to implement a massive amount of filtering.
In this episode of the Privacy Partnership Podcast, Robert Bateman breaks down the EDPB’s newly adopted Draft Guidelines 03/2026 on web scraping for generative AI. Robert begins by exploring the political context behind this unexpectedly pragmatic guidance, discussing how the EDPB is effectively front-running the European Commission’s upcoming "Digital Omnibus" proposal to cement its authority over how privacy law applies to AI development.
Then, Robert walks listeners through a practical, 10-point checklist for developers and privacy teams trying to navigate this regulatory minefield, from mapping out complex controllership arrangements to leveraging a fascinating loophole for the "incidental and residual" scraping of sensitive, special category data.
Key Topics Discussed:
The Digital Omnibus Context: Why the EDPB’s new guidance is "deceptively permissive" and how it serves as a strategic maneuver to preempt upcoming EU legislation.
Controllership in the AI Supply Chain: How to define your role—whether you are dictating instructions to a scraper, co-determining collection criteria, or buying a pre-scraped dataset.
Establishing a Lawful Basis: Why consent is a non-starter at this scale, how to lean on Legitimate Interests, and why a missing "robots.txt" file does not equal a green light.
Designing the Collection: The end of indiscriminate web hoovering, the importance of data minimisation, and respecting technical barriers (like CAPTCHAs and ai.txt).
Transparency at Scale: How to utilize the Article 14 "disproportionate effort" exception while maintaining a highly detailed, searchable public scraping notice.
Cleaning and Accuracy: Applying syntax-based filters to weed out format-identifiable data on the fly, and utilizing synthetic data where feasible.
The Article 9 Workaround: How the EDPB is applying the 2019 GC & Others CJEU search engine ruling to allow the incidental scraping of special category data—and the rigorous output filters required to justify it.
Accountability: The massive documentation burden required to prove your technical measures and filters remain effective against the evolving state of the art.
More Technology podcasts
Trending Technology podcasts
About The Privacy Partnership Podcast with Robert Bateman
Robert Bateman provides the latest on data protection and privacy, with regular solo news updates and short-form interviews. Brought to you by Privacy Partnership: www.privacypartnership.com
Podcast websiteListen to The Privacy Partnership Podcast with Robert Bateman, Waveform: The MKBHD Podcast and many other podcasts from around the world with the radio.net app

Get the free radio.net app
- Stations and podcasts to bookmark
- Stream via Wi-Fi or Bluetooth
- Supports Carplay & Android Auto
- Many other app features
Get the free radio.net app
- Stations and podcasts to bookmark
- Stream via Wi-Fi or Bluetooth
- Supports Carplay & Android Auto
- Many other app features


The Privacy Partnership Podcast with Robert Bateman
Scan code,
download the app,
start listening.
download the app,
start listening.



























