GDPR's special category data rule: why it reaches an adult classifieds site with no office in Europe

The fine that was not about a hack
In December 2021, Norway's data protection authority fined Grindr LLC 65 million kroner. Nobody had broken into Grindr's servers. No database had leaked. The company had done what most sites with a login and an ad budget do without a second thought: it shared identifiers with advertising partners so it could run targeted ads and measure whether they worked. That is the exact same plumbing behind a Meta Pixel or a Google Ads conversion tag on thousands of ordinary websites.
Grindr's defense was that none of this actually disclosed anyone's sexual orientation. A user could pick a nickname, skip the photo, and share nothing explicit about who they were. The regulator did not accept that. It held that being a known user of an app built around a specific sexual minority "strongly indicates, and appears in most cases to accurately reflect," that the person belongs to that minority, whether or not they typed a word about it. The fine stood on appeal, upheld again by a Norwegian court in 2025.
The reasoning matters more than the number. A classifieds operator reading about this case usually files it under "that's a dating app problem, we sell listings." But the legal test the regulator applied was not about what Grindr's app was called. It was about what a reasonable person could work out from the data, and that test does not stop at the door of a dating app. A directory built around adult personal ads produces exactly the same kind of data: an account on this kind of platform, browsing a specific category, contacting a specific type of listing. None of that requires a single explicit word to tell a third party something intimate about the person behind it.
This is the piece that gets missed by an operator focused on chargebacks, age verification, and content moderation, all real and immediate risks. Data protection law is a different track entirely, with its own regulator, its own fines, and a legal test built for exactly this kind of platform even though it was written with no adult site in mind.
Why it counts even when nobody says it out loud
European law has a name for data that lets someone work out a sensitive fact without it being stated directly: inference. In August 2022, the Court of Justice of the European Union ruled on a case that had nothing to do with adult content. A Lithuanian public official had been required to declare, among other things, the name of his partner, and that declaration was published online. The court held that naming a same-sex partner, without a single word about orientation, still counted as processing data about sexual orientation, because a reader could get there through what the court called an intellectual operation of comparison or deduction.
That test travels well beyond one Lithuanian civil servant. The question is never "did the platform say this person is gay, straight, or anything else." It is whether a piece of data, combined with ordinary reasoning, lets a reader arrive at that conclusion. A listing category, a "seeking" field, a service description, or simply an account active on a platform organized around a specific kind of personal ad can clear that bar on its own, with no explicit label attached.
Under the GDPR, once data clears that bar, it stops being ordinary personal data and becomes what the regulation calls a special category, Article 9's term for the same bucket that holds health records, religious belief, and trade union membership. This is not a minor label. Article 9 opens by prohibiting the processing of this kind of data outright, and only lifts that prohibition for a short, closed list of specific situations. Ordinary personal data, by contrast, only needs one of several everyday legal grounds, and that gap is exactly where most classifieds sites are currently standing without realizing it.
The practical effect is that a field built purely for search and filtering, letting a visitor narrow listings by category or preference, is quietly doing double duty. It helps a visitor find what they want, and it is also the exact kind of data point a regulator would point to as evidence the platform processes special category data about both visitor and listing. Removing the label a user might type is not enough to opt out; the CJEU test runs on what can be deduced, not on what was declared.
Why "we don't have an office in Europe" does not help
The most common reaction to all of this, from an operator based in a country nowhere near Brussels, is that European regulators have no reach here. That reaction is wrong, and the GDPR is explicit about why. Article 3(2) applies the regulation to any business, wherever it is based, the moment it offers goods or services to people located in the EU, regardless of whether any of them pay for anything, or the moment it monitors the behavior of people located in the EU. Neither branch requires a European entity, a European bank account, or a European employee.
The guidance regulators use to apply that article does say that a website simply loading for a visitor in Germany is not, by itself, enough to trigger it. What tips the balance is evidence the business is actually targeting people in the EU: pricing shown in euros, marketing aimed at a European audience, or, very concretely, offering the site in European languages. A classifieds platform that already serves French, German, Italian, Spanish, and Portuguese pages to attract exactly those visitors is close to the textbook example regulators use to explain when the rule applies.
This is not a reason to strip out every European language or geo-block EU visitors, which would trade a compliance problem for a much larger business one. It is a reason to stop treating "we're not registered in Europe" as an answer. The obligation attaches to the processing of data about people in the EU, not to where the company happens to be incorporated. A business that already translates its site to reach European visitors has already done the thing regulators look for as proof it meant to reach them.
The ad-tech stack that quietly breaks
Most sites run their entire privacy compliance through one mechanism: a cookie banner offering to accept or reject non-essential tracking, sometimes with a toggle for "legitimate interest." That banner was built for ordinary personal data, where a business really can rely on a general legal basis like legitimate interest to run analytics or serve ads. Special category data does not work that way. Article 9(2) has its own separate, closed list of conditions that can lift the general ban, and legitimate interest is not on it. A platform needs a normal Article 6 basis and, on top of it, a separate Article 9(2) condition, and skipping the second one is precisely the gap the Norwegian regulator found in Grindr's setup.
The condition that fits a commercial platform is explicit consent, and explicit consent is a materially higher bar than the ordinary consent a cookie banner usually collects. It has to be a clear, specific, affirmative statement about the particular kind of data being shared, and it cannot be satisfied by folding a line about "sharing data with advertising partners" into a general privacy policy accepted by continuing to browse. Regulators have been direct about this: consent for this kind of processing has to stand on its own, separated from the rest of the terms a user agrees to, naming what is collected and who receives it.
This lands squarely on the two tools most classifieds operators reach for first: a Meta Pixel and a Google Ads conversion tag, both designed to tell an advertising platform which visitor did what, on which page, so ads can be targeted and measured. On a general merchandise site, that is unremarkable tracking. On a site organized around a specific category of personal ad, the same signal tells the receiving platform that a given visitor is browsing that category, functionally the same disclosure that got Grindr fined, just running through a different vendor's pipe. This is a second, independent reason, alongside the difficulty of even opening an ad account with Google or Meta for this category in the first place, to build traffic through channels that never receive this kind of signal.
None of this means an operator has to run the site with no analytics at all. It means the consent flow for a platform in this category cannot be the same one-click banner built for a bookstore. The unbundled, specific, opt-in step has to happen, and has to happen before any script capable of sending category-level signals to a third party fires, not after.
The trap of "but it's already public"
A specific argument comes up often once an operator understands the rest of this: the listings on the site are public anyway, visible to anyone who loads the page, so how can there be a special protection problem. GDPR does have an exception that sounds like it fits: Article 9(2)(e) lifts the general ban for data that has been manifestly made public by the data subject. It reads like a natural fit for a directory of public listings.
It is also the exact argument Grindr made and lost. The company pointed out that a profile only became visible to other users of the app, framing that visibility as the user's own choice to make the information public. The regulator rejected it, holding that the exception requires a deliberate, specific act by the person themselves to make that particular data public, not the platform's own decision to display account data to whoever views a page. Even a fully public listing, with no login wall, does not automatically clear that bar, because the question is about the poster's own intent to make that specific fact public, not about who happens to see the page afterward.
A checkbox agreed to at signup, buried in a registration flow, saying that a profile "will be visible on the platform," is not the same thing as a deliberate, informed act to make a specific sensitive fact public. Regulators have been consistent in construing this exception narrowly, and an operator who builds a compliance argument on top of it is relying on the one condition that has already been tested against nearly this exact fact pattern and did not hold up.
What to actually do this quarter
The starting point is not a new tool, it is a document: a Data Protection Impact Assessment. Article 35(3)(b) makes one mandatory before large scale processing of special category data, not optional best practice, and a platform with any meaningful volume of listings organized around personal ads is squarely inside that requirement once it has real EU traffic. Commissioning this assessment, even a modest one done properly, produces the paper trail that shows a regulator the business took the question seriously before being asked, the single biggest factor in how a first complaint gets handled.
Next comes an inventory, not a redesign: every script that fires before a visitor makes any choice, every pixel, every analytics tag, every heatmap or session recording tool. The goal is to know, specifically, which of them receives a signal that reveals what category of content a visitor is looking at, because that is the exact same shape of data this entire piece has been about. The documents already collected for identity verification carry a parallel version of this same exposure, and the same instinct, know exactly what is being held and who can reach it, applies to both.
Consent needs its own step, separate from the terms and conditions checkbox, naming plainly what categories of data are shared and with which named companies, collected through an affirmative action rather than assumed from continued browsing. This is more friction at signup, and it is also the only version of consent that survives the standard a regulator will actually apply if a complaint arrives.
The last piece is the simplest to state and the hardest to give up: minimize what leaves the platform. A tag that never receives category-level signals about a visitor cannot become evidence in a case like Grindr's, no matter how the rest of the compliance program is built. The safest integration with any advertising or analytics vendor is the one that was never given the sensitive signal in the first place.
Treat this the same way a payments account or a hosting contract has already taught most operators to treat high risk exposure: work out the answer before a regulator asks the question, not after. The businesses that come out of a first data protection complaint intact are the ones that can already point to a DPIA on file, a consent flow built for this specific category of data, and a documented answer to exactly what leaves the platform and where it goes.


