LinkedIn has been issued a fine of €310 million (£258.36m) by the Irish Data Protection Commission for violating GDPR in its advertising practices.
Based on an initial complaint filed in 2018 to the French data protection authority, an inquiry looked into the lawfulness and transparency of LinkedIn’s processing of personal data from its behavioural analysis and targeted advertisements.
The investigation fell under the remit of the Irish DPC since LinkedIn’s European headquarters are based in Ireland.
The personal data involved in the complaint included data provided directly to LinkedIn by its users as well as the data its third-party partners were able to obtain.
The investigation found that LinkedIn was in breach of several articles of GDPR, which includes: gaining formal consent, ensuring legitimate interest, and ensuring a principle of fairness is followed when processing third-party and first-party data.
Recommended reading
- Demystifying GDPR & AI: Safeguarding Personal Data in the Age of LLMs
- Has GDPR Been a Boost or a Bust for Businesses?
- Meta Delays AI Training in Europe Following Regulatory Concern
The ruling includes three administrative fines, a formal reprimand and demands that LinkedIn gets its practices under compliance.
“Today the Irish DPC reached a final decision on claims from 2018 about some of our digital advertising efforts in the EU. While we believe we have been in compliance with the GDPR, we are working to ensure our ad practices meet this decision by the DPC’s deadline,” LinkedIn said in a statement.
The company did not share if it would challenge the fine.





