LinkedIn Fined €310M for Behavioral Ad Targeting

Oct 2024 · €310M fine

By Karim El Labban · ZERO|TOLERANCE

LinkedIn Fined EUR 310M for Behavioral Ad Targeting

The Irish Data Protection Commission (DPC) fined LinkedIn Ireland Unlimited Company EUR 310 million in October 2024 for processing member personal data for behavioral advertising and analytics without a valid legal basis.

The decision found that LinkedIn relied on consent that did not meet GDPR standards and improperly invoked legitimate interest as a fallback legal basis for intrusive ad targeting.

01

KEY FACTS

  • .What: LinkedIn processed member data for behavioral ads without valid consent.
  • .Who: Hundreds of millions of EEA LinkedIn members.
  • .Data Exposed: Professional profiles, on/off-platform behavior, and inferred demographics.
  • .Outcome: Irish DPC fined LinkedIn EUR 310M and ordered compliance.
02

WHAT WAS EXPOSED

  • .Member professional profile data including job titles, employers, skills, and connections used for ad segmentation
  • .On-platform behavioral data including content engagement, article reading, job search activity
  • .Off-platform tracking data collected through LinkedIn Insight Tags on third-party websites
  • .Inferred demographic and psychographic data derived from member activity
  • .Third-party data enrichment information matched against LinkedIn profiles
03

REGULATORY ANALYSIS

The DPC examined LinkedIn's reliance on three legal bases: consent (Article 6(1)(a)), legitimate interest (Article 6(1)(f)), and contractual necessity (Article 6(1)(b)). All three were found inadequate.

Consent was not "freely given" because advertising consent was bundled with other purposes.

Legitimate interest failed the balancing test because extensive behavioral profiling--including off-platform tracking--constituted processing members could not reasonably expect from a professional networking platform.

04

SOURCES

Irish DPC Decision IN-22-5-1, CJEU Planet49 Case C-673/17, EDPB Guidelines 2/2019 and 05/2020

RELATED ANALYSIS

USPTO GovDelivery Scam: How Fraudsters Weaponize Real .gov Emails to Steal From Trademark Filers
Apr 1, 2026 · 77K+ victims · 60+ domains · First-person investigation
Free Mobile Fined EUR 42M After 24.6 Million Customer Records Stolen
Jan 16, 2026 · EUR 42M fine
Illuminate Education: FTC Action Over 10.1 Million Student Records Breach
Dec 1, 2025 · $5.1M settlement
Capita Fined £14M After Black Basta Ransomware Exposes 6.6M Records
Oct 1, 2025 · £14M fine
SHEIN Fined €150M for Cookie Consent Violations
Jan 23, 2025 · €150M fine
MORE REGULATORY ENFORCEMENT →