Dating Profile Photos and Location Shared With a Third Party: What the FTC Alleged in Its 2026 OkCupid and Match Case

A dating profile is a bundle of photos, a location and personal answers, and users hand it over on the strength of a privacy policy. In March 2026 the United States Federal Trade Commission (FTC) announced action against the dating app OkCupid and its affiliate Match Group Americas over what it alleged was the sharing of that kind of data with an outside company, contrary to the app’s own promises. This guide summarises the FTC’s press release and the case page. It reports allegations and the terms of a proposed settlement, not findings of guilt, and it concerns United States enforcement. It is general information, not legal advice.

What the FTC alleged

According to the FTC’s press release of 30 March 2026, the agency alleged that OkCupid, which is operated by Humor Rainbow, Inc. of Dallas, deceived users by sharing personal information, including photos and location information, with an unrelated third party, contrary to its privacy promises. The complaint alleges that OkCupid gave an unauthorised third party access to the personal data of millions of users in violation of its privacy policies.

The FTC says OkCupid’s policy told consumers that it does not share personal information with others except as indicated in the policy, or when users are informed and given a chance to opt out. The policy at the time said personal information might be shared with service providers, business partners, other entities in its family of businesses, or when the company informed consumers and offered an opt-out. The FTC alleged that the recipient was none of those, and that consumers were not told or offered a choice.

Photos, location and no restrictions

The press release says the third party asked OkCupid to share large datasets of user photos and related data, and that OkCupid had no business relationship with it, but the app’s founders were financial investors in it. The FTC alleges OkCupid gave the third party access to nearly three million user photos, plus location and other information, “without placing any formal or contractual restrictions” on how the information could be used.

The point for users is that the FTC’s case rests on the gap between what a privacy policy promised and what was alleged to have happened, not on a data breach in the sense of a hack.

Alleged concealment

The FTC also alleged that, since September 2014, Match and OkCupid took extensive steps to conceal and deny the sharing, including trying to obstruct the FTC’s investigation. As an example, it says that when a news story revealed that the third party had obtained large OkCupid datasets, OkCupid told the media and its users that it was not involved with the third party. The release adds that the FTC’s action followed its successful enforcement in federal court of a Civil Investigative Demand, which required OkCupid to hand over information it had requested.

The proposed settlement

Under the proposed settlement, OkCupid and Match are permanently prohibited from misrepresenting, or assisting others in misrepresenting:

  • the extent to which they collect, maintain, use, disclose, delete or protect personal information such as photos and demographic and geolocation data;
  • the purpose for which they collect, maintain, use or disclose that data; and
  • the function of the privacy controls they provide, including consumer choices under applicable state privacy laws and other mechanisms to limit or manage the processing of personal data.

The Commission’s vote to authorise staff to file the complaint and the stipulated final order was 2-0. They were filed in the United States District Court for the Northern District of Texas, Dallas Division. The FTC notes that it files a complaint when it has “reason to believe” a law is being violated, and that stipulated final orders have the force of law when approved and signed by the court. The case page lists the complaint, the stipulated order and a joint motion to enter the order, all dated 30 March 2026.

What a dating app user can control

The case is about company conduct, so it gives users no tool to stop sharing after the fact. What users can do is limit what an app holds in the first place. The FTC’s consumer advice on online privacy suggests looking at the privacy settings on a smartphone to see what information an app can reach, such as location, contacts and photos, and considering turning off unnecessary permissions or deleting apps that request many permissions they do not need to function. This site’s guides on dating app permissions and on what dating photos reveal apply that advice to profiles.

For people in the United Kingdom, the FTC’s order does not create rights there. The site’s guides on requesting a copy or deletion of dating app data and on what the ICO advises after a breach cover the UK routes. The FTC’s earlier action over billing and cancellation is covered in the guide to dating app guarantees and chargebacks.

Frequently asked questions

Is this a finding that the companies broke the law?

No. The FTC describes its complaint as based on “reason to believe”, and the release states allegations alongside a proposed settlement.

The bottom line

The FTC alleged in March 2026 that OkCupid shared nearly three million user photos, with location and other information, with an outside company despite its privacy promises, and that Match and OkCupid concealed it. The proposed settlement bars them permanently from misrepresenting how they handle personal data and privacy controls. The case is a reminder that a dating profile is data as well as a personal introduction, and that limiting permissions and photos is the part users control.

Sources