The Irish Data Protection Commission (DPC) fined LinkedIn €310 million ($335 million) on Thursday for breaching user privacy laws by conducting behavioral analysis on personal data to enable targeted advertising.
"The inquiry examined LinkedIn's processing of personal data for the purposes of behavioral analysis and targeted advertising of users who have created LinkedIn profiles (members)," stated the DPC. "The decision [...] concerns the lawfulness, fairness, and transparency of this processing."
This fine was issued under the European Union's General Data Protection Regulation (GDPR), an information privacy law that sets out clear rules on data collection, processing, storage, and transfer within the EU and European Economic Area (EEA). GDPR has been in force since May 25, 2018.
Following a complaint to the French Data Protection Authority in 2018, the DPC’s investigation found LinkedIn in violation of three GDPR principles regarding transparency and fairness, including Article 6 GDPR and Article 5(1)(a), Articles 13(1)(c) and 14(1)(c), and Article 5(1)(a).
The violations included LinkedIn’s lack of explicit consent from users and insufficient communication regarding third-party data use. LinkedIn also relied on "legitimate interests" as a legal basis for processing first-party data, used for ad targeting. Beyond the fine, LinkedIn has been granted a three-month window to bring its operations into GDPR compliance.
The DPC emphasized that user consent, as per GDPR standards, must be freely given, specific, informed, and reflect a clear indication of user intent. The Commission noted that data processing should be conducted transparently and fairly.
DPC Deputy Commissioner Graham Doyle remarked, "The lawfulness of processing is a fundamental aspect of data protection law, and processing personal data without an appropriate legal basis represents a severe breach of an individual’s fundamental data protection rights."
Responding to the ruling, LinkedIn, owned by Microsoft, said, "While we believe we have been in compliance with the General Data Protection Regulation (GDPR), we are working to ensure our ad practices meet this decision by the IDPC's deadline."
In parallel developments, Austrian privacy organization noyb (None Of Your Business) has filed a complaint with France’s data protection authority against Pinterest. The group claims Pinterest inappropriately uses "legitimate interests" to default-track user activity for ad targeting without explicit consent.
Noyb stated, "Instead of seeking opt-in consent under Article 6(1)(a) GDPR, [Pinterest] falsely claims to have a 'legitimate interest' in processing people's personal data under Article 6(1)(f) GDPR." Pinterest counters, stating that its personalized advertising approach is "GDPR compliant."