Ireland’s Data Protection Commission (DPC) fined LinkedIn Ireland EUR 310 million and issued a reprimand for breaches of the GDPR in how it processed members’ personal data for behavioural analysis and targeted advertising.
What happened
- The inquiry followed a complaint made in August 2018 by the French non-profit La Quadrature du Net to the French data protection authority, which was passed to the DPC as lead supervisory authority.
- The DPC found that LinkedIn had not validly relied on consent, legitimate interests, or contractual necessity for the processing.
- It also found breaches of the transparency and fairness principles, and ordered LinkedIn to bring its processing into compliance.
- LinkedIn said it believed it had complied with the GDPR but was working to ensure its advertising practices met the decision by the DPC’s deadline.
Why it mattered
It was one of the largest GDPR fines to date and reinforced regulators’ view that profiling for advertising needs a clear and valid legal basis. It also added to pressure on large platforms to rethink consent and advertising models across Europe.
Lessons for organisations
Document the lawful basis for each processing purpose, especially profiling and advertising, and make sure privacy notices explain it plainly. Regular data protection impact assessments help catch these issues before a regulator does.
Sources: Data Protection Commission, Infosecurity Magazine
Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.