LinkedIn violates data protection rules, uses 18 million email addresses without user consent

The report covered the first few months in 2018, just before GDPR was introduced

LinkedIn on a mobile device

LinkedIn, the white-collar social network with over 500 million users has responded to an investigation which revealed the company violated data protection rules by using the email addresses of 18 million people to buy targeted ads on Facebook.

Following a complaint from a non-LinkedIn user, the Data Protection Commissioner (DPC) of Ireland conducted an audit into LinkedIn's processing of personal data.

The DPC's report, which doesn't say how it acquired the 18 million email addresses covered the first five months of 2018 (Jan-May) and concluded that LinkedIn Ireland, the data controller, used a hashed form of the email addresses to target Facebook users with ads trying to target the user to sign up to its service "with the absence of instruction from the data controller as is required" to stay GDPR compliant.

"The complaint was ultimately amicably resolved," said the DPC, "with LinkedIn implementing a number of immediate actions to cease the processing of user data for the purposes that gave rise to the complaint."

Advertisement
Advertisement - Article continues below
Advertisement - Article continues below

LinkedIn has also been instructed to delete all personal data processed during the time of unlawful processing "with the absence of instruction from the data controller". 

LinkedIn, along with other countries have now moved its data processing from Ireland to the USA in an effort to loosen the stranglehold GDPR places around it. It avoids processing user data under law that should not apply to them. LinkedIn will have international users who aren't EU citizens but prior to the move, would have their data processed in a European country.

The report also details particulars about the ongoing investigation it has into Facebook and how it handles facial recognition data, a type of data which has special requirements under GDPR because it records biometric data. Details of Yahoo's data breach and the interaction between Facebook and WhatsApp are included too.

IT Pro has approached LinkedIn for comment.

Featured Resources

Digitally perfecting the supply chain

How new technologies are being leveraged to transform the manufacturing supply chain

Download now

Three keys to maximise application migration and modernisation success

Harness the benefits that modernised applications can offer

Download now

Your enterprise cloud solutions guide

Infrastructure designed to meet your company's IT needs for next-generation cloud applications

Download now

The 3 approaches of Breach and Attack Simulation technologies

A guide to the nuances of BAS, helping you stay one step ahead of cyber criminals

Download now
Advertisement

Most Popular

Visit/operating-systems/25802/17-windows-10-problems-and-how-to-fix-them
operating systems

17 Windows 10 problems - and how to fix them

13 Jan 2020
Visit/hardware/354584/windows-10-and-the-tools-for-agile-working
Sponsored

Windows 10 and the tools for agile working

20 Jan 2020
Visit/microsoft-windows/32066/what-to-do-if-youre-still-running-windows-7
Microsoft Windows

What to do if you're still running Windows 7

14 Jan 2020
Visit/business-strategy/public-sector/354608/uk-gov-launches-ps300000-sen-edtech-initiative
public sector

UK gov launches £300,000 SEN EdTech initiative

22 Jan 2020