LinkedIn & Data Privacy: How secure is user data?

Last updated:
07.09.2022
Online networks like LinkedIn make it easier to build and maintain professional connections. However, the information users are required to provide is usually personal data and should be protected accordingly.
LinkedIn & Data Privacy: How secure is user data?
Key Takeaways
  • LinkedIn requires users to provide a significant amount of personal data.
  • LinkedIn uses AI and third-party service providers to analyze user data.
  • Companies must comply with GDPR requirements and update their privacy policies when using LinkedIn.
  • Users can control the visibility of their activities and data sharing in their settings.
  • LinkedIn shares data with external partners; complete protection is only possible by leaving the platform.

There have never been more ways to find a new job than there are today. Digital platforms like LinkedIn are making it easier than ever for companies and job seekers to connect. However, creating a profile requires providing a significant amount of personal data. We explain the extent to which LinkedIn complies with the GDPR and what you need to look out for yourself.

LinkedIn: Is GDPR-compliant data usage guaranteed?

To create a LinkedIn profile, users are asked to provide personal data. In addition to your name and contact details, you can add further information to your user profile:

  • Education and degrees
  • Work experience, including specific company names
  • Connections to people you have worked with previously
  • Skills and expertise

Filling out these sections is voluntary, though LinkedIn strongly encourages it. This makes sense, as those looking for a new job generally want to present themselves in the best possible light. Furthermore, listing your educational background and work history is a standard part of any job application process. However, unlike a paper application, users of digital career networks are exposing their data to a much larger audience.

As required by law, LinkedIn provides information on its website regarding how all collected data is used. Since the acquisition by Microsoft in 2017, LinkedIn’s privacy policy has included a notable update regarding access rights. External service providers and affiliated companies, such as Microsoft with services like Outlook, can access user profiles. Tools like the LinkedIn Sales Navigator can also pose risks to member privacy. Additionally, LinkedIn uses artificial intelligence to analyze user activity in order to provide more relevant recommendations.

LinkedIn Privacy: What should companies keep in mind when using LinkedIn?

In principle, the network itself—specifically LinkedIn Ireland Unlimited Company—is responsible for processing personal user data. LinkedIn informs its members about how this collected data is processed within its privacy policy.

Companies that use the platform solely to post job openings do not initially need to provide separate privacy notices. However, if they actively collect user data and process it further through external services, the operators of the respective LinkedIn company page must include their own privacy policy. This constitutes joint controllership under Article 26 of the GDPR, meaning all parties involved must enter into a Joint Controller Agreement. This agreement must specify which party is responsible for implementing which GDPR regulations. LinkedIn provides a Page Insights Joint Controller Addendum for this purpose, which business owners can find under the "Admin tools" menu on their company page. If operators use the analysis tools provided by LinkedIn to gain insights—for example, via the LinkedIn Insight Tag—they must also state the legal basis for doing so. In most cases, the only applicable basis is legitimate interest under Article 6(1)(f) of the GDPR. While the use of the LinkedIn Insight Tag is mentioned in the platform's own privacy policy, every company that uses this analysis tool via its profile is required to obtain consent from its users. Furthermore, they must inform users in their own privacy policy about, among other things:

  • That LinkedIn places a cookie in the browser.
  • What data the cookie collects and for what purpose.
  • How long the data is stored.
  • That users can object to the storage and processing of their data at any time.

Data protection must also be handled in this way when using the company's own training platform, LinkedIn Learning.

What users can do themselves to protect their data on LinkedIn

When you fill out your LinkedIn profile, all information about you is initially visible to the public. This means other members or customers of the platform can see what you like, who you follow, what comments you make, and whether you belong to certain groups.

However, in the privacy settings, users have the option to restrict the visibility of their activities to their own contacts only. They can also decide whether their contacts may be shared with one another or whether personalized advertising may be displayed to them based on an analysis of their activities. Unfortunately, you cannot prevent LinkedIn from sharing data with external service providers and partners to provide and improve its services. Regrettably, this applies to most social networks. In this case, the only option for users is to terminate their membership.

The career network LinkedIn therefore offers job seekers good opportunities to network and increase their visibility. For entrepreneurs and all members, however, it is just as important to keep an eye on the protection of their own data and that of users of company profiles on LinkedIn.

Do you have further questions on this topic? Our experts will be happy to advise you free of charge.

If you're looking for a partner to support you on your journey to data protection and information security, feel free to contact our team of experienced experts.
60+ Expertinnen und Experten
Book a consultation
Topics
Editorial
Alexander Ingelheim
Co-Founder & CEO
Alexander Ingelheim is Co-founder and CEO of Proliance. His driving force from day one has been to support companies with the hurdles and challenges of data protection and GDPR. He brings extensive experience from his work in international consulting, including positions at Bregal Unternehmerkapital GmbH and McKinsey & Company. He is also a certified Data Protection Officer (TÜV & DEKRA).
Zum Autorenprofil
Zum Expertenprofil
About Proliance
Proliance stands for Professional Compliance for businesses. We are a digitally driven Legal Tech company based in Munich, established in 2017 and now with over 90 privacy enthusiasts. Our more than 2,500 clients include start-ups, medium-sized businesses, and corporate groups from almost all industries.
About us
Latest Articles

Topics you might be interested in