LinkedIn Advertising Privacy Lawsuit: Allegations, Eligibility Questions and Case Status

LinkedIn faces billions in fines and active U.S. lawsuits over advertising privacy violations and hidden browser scanning.

LinkedIn faces multiple privacy lawsuits and enforcement actions globally that stem from allegations of improperly using member data for targeted advertising, harvesting personal information without consent, and running hidden code to scan users’ devices. The most significant enforcement action came in October 2024, when Ireland’s Data Protection Commission fined LinkedIn €310 million ($335 million USD) for violating GDPR rules by using members’ personal data for behavioral targeting without obtaining freely given, specific, and unambiguous consent. Beyond the Irish fine, LinkedIn is defending against active class-action litigation in U.S.

federal courts, including a 2026 lawsuit alleging the company ran hidden JavaScript code to scan users’ browsers for installed extensions and device information—a practice known as “BrowserGate.” While some LinkedIn privacy litigation has settled, such as an advertising metrics case that resulted in a settlement of approximately $4.5 million for U.S. advertisers, many lawsuits remain active or recently filed. The scope of these cases spans three continents, involves multiple regulatory bodies and private plaintiffs, and raises questions about how technology companies collect, process, and monetize user data that individuals never knowingly provided. For users and advertisers dealing with LinkedIn, understanding what each case alleges, who it affects, and what remedies are available requires parsing several parallel legal tracks that are still unfolding.

Table of Contents

What Are the Main Allegations Against LinkedIn?

linkedin‘s privacy problems did not emerge from a single incident or allegation. Instead, multiple regulators, consumers, and groups have filed complaints or litigation that paint a picture of systematic issues. The Irish DPC investigation, which began in 2018 based on member complaints, found that LinkedIn processed personal data of its members for targeted advertising purposes without obtaining consent that was “freely given, sufficiently informed or specific, or unambiguous” in violation of GDPR Article 6. The company failed to provide members with sufficient information about how their data would be used, violating Articles 13 and 14 of the GDPR. In essence, LinkedIn’s consent model was found to be fundamentally broken—users may have clicked “agree” to broad terms, but they did not receive granular notice or choose freely to enable behavioral targeting.

Beyond regulatory findings, private plaintiffs in the United States have brought lawsuits alleging that LinkedIn used hidden code to fingerprint devices and enumerate installed browser extensions without users’ knowledge or consent. According to court filings, LinkedIn injected JavaScript that scanned for dozens of browser extensions to collect detailed device and behavior data. This “BrowserGate” litigation, filed in 2026 in U.S. District Court in Northern California, includes claims from two named plaintiffs (Jeff Ganan and Nicholas Farrell) and proposes to represent a class of millions of LinkedIn members. The hidden code was not disclosed to users in privacy policies or settings, and it operated silently in the background each time a member visited LinkedIn’s website or used LinkedIn features embedded on third-party sites.

The €310 Million GDPR Fine and Its Global Impact

The October 2024 fine by Ireland’s Data Protection Commission represents the most significant financial penalty LinkedIn has faced for privacy violations and signals that European regulators are willing to impose massive costs on the company for noncompliance. The €310 million figure was calculated based on LinkedIn’s turnover and the gravity of the violations, and the DPC determined that fines under the maximum 4% of global revenue would adequately deter similar conduct. However, LinkedIn filed an appeal in November 2024, and the next hearing is scheduled for December 2025, meaning this case is far from finalized. The company maintains that its advertising practices comply with GDPR, and the appeal process could result in a reduction, reversal, or upheaval of the fine.

The practical effect of the Irish DPC’s decision was immediate and limited to Europe. LinkedIn ceased allowing advertisers to target European Economic Area (EEA) users based on LinkedIn group membership, which can reveal sensitive information such as sexual orientation, political opinions, or race. This change was precipitated partly by a separate complaint filed by civil rights organizations (including European Digital Rights, Global Witness, and others) under the Digital Services Act in February 2024. While the loss of detailed behavioral targeting reduces LinkedIn’s ability to serve highly customized ads to EEA users, it does not translate to a direct payment or compensation for European users who were affected. European individuals harmed by the unlawful processing may pursue individual claims under GDPR Article 82, but as of July 2026, no large-scale class action settlement has been announced in Europe.

Privacy Claim CategoriesEmail Scraping34%Data Monetization27%Non-Deletion22%Identity Exposure12%Tracking5%Source: Class Action Settlement

BrowserGate: Hidden Code and Active Litigation

The most active and potentially far-reaching U.S. lawsuit is the “BrowserGate” litigation, which centers on LinkedIn’s practice of injecting hidden JavaScript code into web browsers to scan for installed browser extensions. According to the complaint, every time a LinkedIn member visited the platform or encountered a LinkedIn widget on another website, the hidden code enumerated the user’s installed extensions without explicit permission. This data collection serves multiple purposes: it allows LinkedIn to identify which tools competitors or ad-tech platforms use, gather behavioral insights, and even fingerprint devices for tracking purposes. The code did not appear in LinkedIn’s privacy policy, was not listed in user settings, and could not be disabled by individual users.

Two class-action lawsuits were filed in U.S. District Court, Northern District of California, in March 2026 on behalf of plaintiffs Jeff Ganan and Nicholas Farrell. As of July 2026, a judge has advanced the data privacy class action, allowing it to proceed past initial pleading challenges. The case brings claims under California’s Invasion of Privacy Act and the federal Electronic Communications Privacy Act, as well as claims for breach of contract and unjust enrichment. The scope of a potential class could encompass millions of LinkedIn members who used the platform during the period when the hidden code was active. However, plaintiffs must still overcome LinkedIn’s defenses, prove that the extension scanning caused injury, and negotiate or litigate the damages phase—all of which may take years.

Eligibility Questions for Each LinkedIn Privacy Case

Understanding which lawsuit might affect you requires clarity on the different cases and their scope. If you are a U.S. advertiser who purchased ads through LinkedIn Marketing Solutions between January 1, 2015, and May 31, 2023, you may be eligible for a share of the settled advertising metrics litigation, which resulted in a payout of approximately $4.5 million after legal fees and administrative costs. To claim in this case, you would need to verify that your organization purchased paid ads through LinkedIn’s platform during the specified period and submit proof of expenditure and authorization. The settlement administrator maintains a claims process on a dedicated website, and the deadline for claims submissions is typically 60-90 days after the settlement becomes final.

For the BrowserGate litigation and other active cases, eligibility is much broader but still evolving. If you were a LinkedIn member at any time the hidden code was active (which researchers and plaintiffs suggest spans several years), you are a potential class member. However, class actions do not require opt-in; you are automatically included unless you affirmatively request exclusion. If the BrowserGate case settles or results in a judgment for plaintiffs, a claims process will be established, and class members will be notified by mail, email, or postings on settlement websites. For the GDPR fine, European individuals have the right to pursue individual claims under Article 82, but no opt-in class action process exists in the same manner as U.S. litigation.

Health Data Sharing and Unauthorized Tracking

In May 2025, a proposed class-action lawsuit was filed alleging that LinkedIn and Google improperly received personal health data from tracking code embedded on California’s Covered California health insurance exchange website. The complaint alleges that meta pixel and Google Analytics trackers on the Covered California website sent users’ health information—including plan choices, family member data, and citizenship status—to LinkedIn and Google without users’ knowledge or consent. This claim is particularly significant because health data is among the most sensitive personal information available, and its unauthorized disclosure violates California consumer privacy laws (CCPA) and federal privacy law (the Electronic Communications Privacy Act).

The Covered California case highlights a broader problem: even when a state agency or health organization believes it is complying with privacy law by posting a privacy policy, third-party tracking code embedded on its website can transmit personal data to advertising platforms without specific user notice or choice. Covered California users who applied for insurance or browsed plan options had no way to know that their data was being sent to LinkedIn and Google’s ad targeting systems. As of July 2026, this case is in early stages, and no settlement has been reached. However, the allegations underscore how tech platforms can harvest personal data through mechanisms that operate beyond users’ control or understanding, even on government websites.

Where Cases Stand and What to Expect

The settlement of the LinkedIn advertising metrics case in U.S. federal court demonstrates that the company is willing to resolve some claims to avoid lengthy litigation, even when it does not admit fault. However, the far larger cases—the Irish DPC fine, the BrowserGate litigation, and the health data case—remain unresolved or under appeal. The Irish DPC fine could be reduced, upheld, or overturned by December 2025, and LinkedIn’s appeal has the potential to significantly alter the regulatory landscape for how tech companies collect consent in Europe. The BrowserGate case is still in the discovery phase, meaning attorneys are gathering evidence, and summary judgment rulings have not yet been decided; a final outcome could take 2-3 more years or may result in a settlement if the parties believe the risk is too high.

New litigation and enforcement actions are likely to continue as regulators and private plaintiffs scrutinize LinkedIn’s data practices. In March 2026, the BrowserGate lawsuit was allowed to proceed, signaling judicial confidence in the claims. Additionally, LinkedIn’s data scraping battles (in which the company has successfully defended against scraping services like Proxycurl in 2026) show that courts are willing to enforce LinkedIn’s terms of service. However, these victories do not insulate the company from claims that its own harvesting of user data violates privacy and consumer protection law. The distinction is critical: LinkedIn can prevent third parties from scraping its site, but that does not validate LinkedIn’s own data collection practices.

Data Scraping Litigation and the Limits of LinkedIn’s Enforcement

While much of the litigation against LinkedIn focuses on the company’s own data practices, LinkedIn has been aggressive in suing third-party data scraping services that harvest member profiles and information without permission. In 2026, a federal court sided with LinkedIn in a lawsuit against Proxycurl, a data scraping and enrichment service, ruling that LinkedIn’s User Agreement unambiguously prohibits unauthorized scraping and the misuse of scraped data. The court’s decision affirmed that LinkedIn has the right to protect its data and that users who violate the terms by enabling or using scrapers face legal consequences. However, this enforcement win does not contradict or diminish the allegations that LinkedIn itself has misused member data—it simply establishes that the company has the right to control how its platform is used by outsiders.

The scraping litigation also reveals the asymmetry in how data privacy law treats large platforms versus smaller actors. LinkedIn can prevent third parties from collecting data but faces regulatory scrutiny and lawsuits when it collects data from its own members. This dual role—as both a data collector and a data protector—underscores the broader concern that LinkedIn and other social platforms have built business models dependent on harvesting personal information while claiming to defend user privacy against third-party threats. For users and regulators, the challenge is ensuring that the rules apply equally to all data collectors, not just those operating outside a platform’s ecosystem.

Frequently Asked Questions

If I’m a LinkedIn user, will I receive money from any of these lawsuits?

It depends on which lawsuit and your circumstances. If you’re a U.S. advertiser who bought ads before June 2023, you may claim a share of the ~$4.5M settlement. If you’re a LinkedIn member and were harmed by the BrowserGate browser scanning, you’re a potential class member, but no settlement or judgment exists yet. European users have GDPR Article 82 rights but no large-scale class action settlement. For the health data lawsuit, eligibility is limited to people who applied for insurance through Covered California.

What is BrowserGate and why is it a big deal?

BrowserGate refers to hidden JavaScript code that LinkedIn allegedly ran on its website to scan users’ installed browser extensions without permission. This revealed sensitive data about what software users had installed and enabled device fingerprinting. It’s significant because users had no knowledge of the scanning and could not disable it.

Has LinkedIn been found guilty in any of these cases?

The Irish DPC found LinkedIn violated GDPR and fined it €310 million, but LinkedIn appealed and the decision is not final. No U.S. court has issued a final judgment on the active cases; they are still in litigation. The advertising metrics case was settled without admission of fault.

What happened as a result of the Irish DPC fine?

LinkedIn ceased allowing advertisers to target EEA users based on LinkedIn group membership, which can reveal sensitive information like political views or sexual orientation. The company also appealed the fine, with the next hearing scheduled for December 2025.

How do I know if I was affected by the hidden browser scanning?

If you were a LinkedIn member and visited LinkedIn’s website or encountered LinkedIn widgets on other sites during the period the hidden code was active, you were potentially affected. The lawsuit seeks to identify all affected members through their account activity records.

When will these cases be resolved?

Timelines vary significantly. The advertising settlement is already final. The BrowserGate case is still in discovery and could take 2-3 years. The Irish DPC appeal hearing is scheduled for December 2025. The health data case is in early stages with no timeline set.


You Might Also Like