When a Dating App Suffers a Data Breach: What the ICO Advises Users to Do Next

Dating profiles hold unusually personal information: photos, location, messages, and often details about relationships, sexuality, religion or health. When a service holding that information is breached, the consequences can go beyond a leaked password. This guide sets out what the UK’s Information Commissioner’s Office (ICO) advises people to do after a personal data breach, and why dating data can be particularly sensitive. It applies to UK data protection law and is general information, not legal advice.

Why dating data is more sensitive than most

The ICO’s guidance on special category data explains that the UK GDPR singles out certain types of personal data as likely to be more sensitive and gives them extra protection. The list includes personal data revealing racial or ethnic origin, political opinions or religious or philosophical beliefs, as well as data concerning health, a person’s sex life and a person’s sexual orientation. Dating profiles and conversations can reveal several of these. The ICO says the reason for the extra protection is that use of this data could create significant risks to a person’s fundamental rights and freedoms. The ICO also notes that this guidance is under review because of changes made by the Data (Use and Access) Act.

The ICO’s public advice on breaches recognises that a breach can put wellbeing at risk. It says harm can include experiences such as discrimination, abuse or serious distress, and that anyone concerned for their safety should contact the police for information and support.

Step 1: find out what happened by asking the app

The ICO says a person affected by a breach can complain to the organisation and ask it to explain what has happened, what information has been affected, and what steps it plans to take to protect that information. Organisations need a process for data protection complaints, and the ICO says many concerns can be resolved quickly this way.

The organisation has 30 days to acknowledge a complaint. It also has to investigate, keep the person informed about progress and provide an outcome without unjustified delay. The ICO says the organisation should be able to confirm whether the person’s information was involved, acknowledge how it affected them, and advise on further steps. The ICO suggests keeping a record of all contact, noting who was spoken to and when on any call, following up in writing where possible, and chasing politely if there is no response within 30 days.

Step 2: reduce the risk of scams that use leaked details

The ICO says hackers sometimes share personal information online after a breach and criminals can use it to scam people. It suggests these simple protective steps:

  • Report lost or stolen documents. If documents such as passports, driving licences, credit cards or cheque books were affected, report them to the organisation that issued them.
  • Check finances. Check bank statements, get a copy of your credit report and look for transactions, accounts or activity you do not recognise, contacting your bank, building society or card company if anything looks unusual.
  • Be alert to phishing. Watch for suspicious emails, text messages and websites, because criminals can use breach information to create fake messages that can be very difficult to spot.
  • Secure accounts. Use strong passwords and multifactor authentication where available.
  • Consider Cifas protective registration. The ICO says this places a warning flag against a name and other personal details on the National Fraud Database, so organisations using Cifas information pay special attention when the details are used to apply for products or services. It says there is a fee for the service.

For dating users, the phishing warning has a particular edge. A leaked profile can be used to craft messages that appear to come from the app or from a match. The guide to fake dating apps and clone listings explains how fraudulent apps mimic real ones, and the guide to protecting financial information covers what not to share.

Step 3: consider what else the breach may expose

If private photos or messages may have been exposed, the sextortion guide explains how blackmail attempts follow and what to do. Where a breach exposes someone’s sexuality or relationship status to people they have not told, the ICO’s list of specialist support organisations is a useful starting point, and the LGBTQ+ dating safety guide covers support routes. The ICO says that if someone does not feel able to contact the police or would prefer another kind of help, it has put together a list of organisations offering confidential advice and practical help, including specialist charities and helplines.

Step 4: complain to the ICO if the app does not put things right

The ICO says a person can complain to it if an organisation has not kept their information safe, but recommends giving the organisation an opportunity to investigate and respond first, because that may resolve the concern and help the ICO handle any later complaint faster. Its data protection complaints page explains what information to provide, and a complaint can be made online.

Step 5: reduce what a future breach could reveal

The bottom line

After a dating app breach, the ICO’s advice runs in order: ask the app what happened, check accounts and finances, watch for phishing, use strong passwords and multifactor authentication, consider Cifas protective registration, and complain to the ICO if the app does not respond properly. Because dating data can reveal a person’s sex life or sexual orientation, which the UK GDPR treats as special category data, anyone worried about their safety should contact the police, and specialist support is available if that feels difficult.

Sources