Privacy in dating services
What the apps collect, what leaks, and how to get your data back out.
This section covers what dating services know about you, who they pass it on to, and how to get your data back. The fact everything here rests on: under Article 9 of the GDPR, data on sexual life and orientation belongs to a special category whose processing is prohibited by default and permitted with explicit consent. The Norwegian supervisory authority treated even the bare fact that a person uses a dating service as data of that kind, and fined the service 65 million kroner.
- What dating apps collectLocation, photos, messages — and what happens when you delete the account.→
- Deleting your data from a dating appA ready-made request template and the deadlines. They must reply within a month.→
- Dating anonymouslyWhat you can hide, what you cannot — and what usually gives you away.→
Three questions this section answers
Privacy in dating breaks into three separate questions, and they are worth keeping apart: the answers and the remedies are different.
First, what is collected about you and where it goes next. The breakdown is here: what dating apps collect about you. That page also carries the Norwegian authority’s measurements of where the data from the large apps actually went, and the exact retention periods after an account is deleted.
Second, how to get your data back and what to do when the controller stays silent. Step by step, with a ready-made request template: how to delete your data.
Third, how far it is possible to stay unrecognised at all. That is no longer a question of law but of practice: what can be hidden and what cannot.
Separately, in the commercial section, the technical side is covered — whether profiles are visible to search engines and what reaches your bank statement: anonymous services. That page is monetised, and the notice appears at the top of it.
Why the law is stricter about this data than usual
This is not a legal technicality. It changes the extent of your rights and the controller’s obligations.
Article 9 of the GDPR places data on sexual life and sexual orientation in the special categories, whose processing is prohibited as a general rule. The prohibition lifts, among other grounds, with explicit consent — which is why dating services ask for it separately and in more detail than usual.
Two concrete obligations follow from that status. Large-scale processing of such data requires a data protection impact assessment. And where it forms the core activity, appointing a data protection officer is mandatory.
The Finnish Data Protection Ombudsman confirms the same list and the same principle of prohibition.
How serious this is became clear in the Norwegian case: the supervisory authority fined Grindr 65 million kroner, holding that the fact a person uses the service points strongly to membership of a sexual minority. The decision was upheld by the appeals board in 2023 and by the court of appeal in 2025. What fell under protection was not the text of the profile but the mere existence of the account.
Your rights and the deadlines worth remembering
Four figures that change the tone of correspondence with a controller.
One month — the deadline for answering a request for access or erasure. It runs from receipt of the request, so keep the date you sent it.
Two months — the maximum extension where a request is complex, but notice of the extension with reasons must be given within the first month.
One month — the period within which a refusal must state its reasons and explain the right to complain and to go to court.
Three months — the period within which the Finnish Ombudsman’s office has, since 2024, been required either to decide a case or to give you an estimate of when it will be decided. If neither happens, you can appeal to the administrative court. The target for actual handling, though, is one year, so do not count on a fast decision.
The order is strict: the controller itself comes first. The Finnish Ombudsman states plainly that cases where the controller has not been contacted are generally not taken up.
What has changed in recent years
The subject looks static, but three things have moved in a few years, and all three in the user’s favour.
The first is case practice on special categories. Before the Norwegian case, whether merely using a dating service counted as sensitive data was a theoretical question. Now there is a supervisory authority’s answer, upheld by the appeals board in 2023 and the court of appeal in 2025: it does.
The second is deadlines for the regulator itself. Since the beginning of 2024 the Finnish Ombudsman’s office must, within three months of a case being opened, either issue a decision or give the applicant an estimate of the timeline. Previously a case could sit without a single signal; now silence has its own appeal route to the administrative court.
The third is transparency about retention. Large operators have started writing concrete figures into their policies instead of phrases like “as long as necessary”. It makes for uncomfortable reading — it turns out transaction data is kept for ten years — but a verifiable figure beats polite vagueness.
What has not changed is the real speed. The target handling time for a complaint in Finland is one year. That is why the first step, a competent written request to the controller itself, remains the most effective one: in most cases it is also where the matter ends.
What you can do yourself in ten minutes
Steps that reduce how much is collected, not just the feeling of control.
Reset or limit the advertising identifier in your phone settings — that is what links you across apps, and it is the single most effective action.
Check the app’s permissions: location set to “always” is almost never necessary, “while using the app” is enough, and often you can manage without it.
Set up a separate email address used only for dating, and do not sign in through social networks — signing in that way creates a permanent exchange of data between the two services.
Open the service’s address with /robots.txt at the end and see whether the profile sections are closed to search engine crawlers. The spread between platforms is enormous.
And before deleting an account, download your data if the service allows it: once deleted, there is nothing left to request it from.
Deadlines that work in your favour
| What | Deadline | Basis |
|---|---|---|
| Answer to an access or erasure request | 1 month | GDPR, Art. 12(3) |
| Maximum extension where complex | +2 months, notice within the first | GDPR, Art. 12(3) |
| Stating the reasons for a refusal | 1 month | GDPR, Art. 12(4) |
| Ombudsman decision or estimate of timing | 3 months | Data Protection Act, from 1.1.2024 |
| Target handling time for a complaint | 1 year | tietosuoja.fi |
Contacting the controller itself is mandatory before complaining to the Ombudsman.
Frequently asked
Which user data is protected most strictly?
Data on sexual life and sexual orientation: Article 9 of the GDPR places it in the special categories, whose processing is prohibited as a general rule and permitted with, among other grounds, explicit consent. The Norwegian supervisory authority treated even the bare fact that a person uses a dating service as data of that kind.
How long does a response to an erasure request take?
One month from receipt of the request. It can be extended by at most two months where the request is complex or there are many of them, but notice of the extension with reasons must be given within the first month. A refusal must state its reasons and explain the right to complain within the same period.
Where do I complain in Finland if a controller will not delete my data?
To the Data Protection Ombudsman, but contact the controller itself first — cases without that step are generally not taken up. The form is submitted through the secure Turvalomake service, and it can be filed anonymously by leaving the contact fields empty.
Does deleting my account delete all my data?
No. Controllers have retention periods: Tinder, for example, deletes profile data three months after an account is closed, keeps customer support correspondence for six years, and transaction data for ten years under tax rules. Hiding a profile is not deletion at all.
What has changed in data protection in recent years?
Three things. Case practice appeared: the Norwegian supervisory authority treated the mere use of a dating service as a special category, and the decision was upheld in 2023 and 2025. Since 2024 the Finnish Ombudsman must decide a case or give an estimate of timing within three months. And operators have started publishing concrete retention periods instead of vague phrasing.
What can I do right now so that less is collected?
Reset the advertising identifier in your phone settings, set location to “while using the app” or turn it off, set up a separate email address for dating, and do not sign in through social networks. Then check the service’s robots.txt to see whether the profile sections are closed to search engine crawlers.
Sources
1464 words