Ireland’s Data Protection Commission (DPC) fined LinkedIn Ireland Unlimited Company €310 million after finding that specified processing of members’ data for behavioural analysis, targeted advertising and analytics did not comply with the GDPR. The decision, dated 22 October 2024 and announced on 24 October 2024, concerns processing involving users in the European Economic Area and the United Kingdom. LinkedIn appealed, and the DPC’s fines register still lists the penalty as pending appeal as of 18 August 2026.
The short answer
- Regulator: Ireland’s Data Protection Commission.
- Company: LinkedIn Ireland Unlimited Company.
- Conduct examined: Behavioural analysis, targeted advertising and related analytics using first-party and third-party data.
- Penalty: Three administrative fines totalling €310 million, plus a reprimand and compliance orders.
- Current status: LinkedIn is appealing; the fine is not an uncontested, finally settled payment.
The DPC’s announcement is available at its official press release.
What LinkedIn’s processing involved
Behavioural analysis and targeted advertising
The DPC uses “behavioural analysis” to describe using information supplied, inferred or observed about a person to inform advertisements shown to that person, or aggregating information for targeted advertising. Targeted advertising means directing particular adverts at an individual based on information held about them.
This was not primarily a case about hackers stealing passwords. It concerned whether LinkedIn had a lawful basis, gave sufficiently specific information and processed data fairly for advertising and analytics.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Scan for outdated or missing drivers - takes under a minute3Repair Windows errors before they cause bigger problems#1 Best Overall
First-party and third-party data
First-party data included information members supplied or generated through their use of LinkedIn. Third-party data came from enterprise customers and other sources, including Bing, according to the DPC’s decision summary. The regulator assessed these categories separately because the available legal bases and transparency obligations differed.
The GDPR legal bases the DPC rejected
Consent for certain third-party data
For third-party data used in behavioural analysis and targeted advertising, the DPC found that LinkedIn could not validly rely on Article 6(1)(a) consent. The consent mechanism and surrounding information did not satisfy the requirements that consent be freely given, informed, specific and unambiguous.
That is more precise than saying LinkedIn had “no consent”: the finding concerned whether the consent obtained was legally valid for the processing under examination.
Contractual necessity for advertising
The DPC found that Article 6(1)(b), contractual necessity, could not justify using members’ first-party data for behavioural analysis and targeted advertising. A processing activity may be commercially useful or take place inside a platform relationship without being objectively necessary to perform the user contract.
Legitimate interests
The DPC also rejected Article 6(1)(f), legitimate interests, for first-party data used in behavioural analysis and targeted advertising and for third-party data used for analytics. It concluded that LinkedIn’s interests were overridden by users’ interests and fundamental rights in the circumstances examined.
This does not mean legitimate interests can never support advertising. The result turned on LinkedIn’s particular purposes, impact, user expectations and balancing assessment.
Why transparency and fairness mattered
Articles 13 and 14
The DPC found infringements of Article 13(1)(c), which applies when data is collected from the individual, and Article 14(1)(c), which applies when data is obtained from another source. LinkedIn’s notices referred generally to consent, contractual necessity and legitimate interests but did not clearly connect each data category and purpose with the applicable legal basis.
A long privacy policy is not automatically transparent. Users need to be able to understand what data is used, why it is used and which legal basis is being claimed for each relevant operation. The DPC’s detailed findings are in its decision summary.
Recommended Free Tools
Article 5(1)(a) fairness
The DPC separately found that the processing was unfair. Fairness is broader than providing a notice: processing can still be unfair if its design, effects or mismatch with user expectations is detrimental, discriminatory, unexpected or misleading. The DPC did not impose an additional standalone fairness fine because it said the relevant conduct was already reflected in the other penalties.
How the €310 million was divided
| Fine | What it covered |
|---|---|
| €105 million | Invalid reliance on consent, with related lawfulness and fairness infringements, for third-party data used in behavioural analysis and targeted advertising. |
| €110 million | Invalid reliance on contractual necessity and legitimate interests, with related infringements, covering first-party data for behavioural analysis and targeted advertising and third-party data for analytics. |
| €95 million | Transparency infringements under Articles 13(1)(c) and 14(1)(c). |
| €310 million total | Three fines rather than one undifferentiated penalty. |
Other orders imposed on LinkedIn
The decision was not limited to money. The DPC issued a reprimand and ordered LinkedIn to bring the relevant processing into GDPR compliance. It also required changes to privacy-policy disclosures concerning Articles 13(1)(c) and 14(1)(c), where LinkedIn continued relying on the relevant legal bases, and corrective steps for the identified behavioural-analysis and targeted-advertising processing under Article 6.
Has LinkedIn paid the fine?
There is no basis to report that LinkedIn has paid a final €310 million penalty. The DPC’s fines register lists the LinkedIn fine as pending appeal as of its April 2026 update.
What the 2026 court ruling decided
LinkedIn appealed on 18 November 2024 under sections 142 and 150 of Ireland’s Data Protection Act 2018. On 20 April 2026, the High Court decided preliminary procedural questions; it did not finally determine whether the GDPR findings or the €310 million penalty should stand.
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Clear out junk files and repair common Windows errorsFree Scan →Best Value
- No more exposed information in unprotected notary journals. This product shields clients' confidential information from prying eyes. It allows the Notary Public to keep the journal open during the transaction, as NO prior client information is viewable.
- Shields clients' AND Notary Publics' confidential information
- GLBA and HIPAA require non-disclosure policies and procedures. Notary Privacy Guard is a compliance tool for the professional Notary Public.
- Decreases Notary Public's liability from exposing client information
- Journal column headers are printed on the Notary Privacy Guard, no having to peek underneath to complete the journal entry. Becomes part of the journal and also acts as a place marker.
- A section 142 appeal is limited to the decision to impose a fine.
- Infringement findings and other corrective measures proceed through the relevant section 150 route.
- The court retains discretion over new evidence or arguments.
The DPC’s judgments page records the court development. A plain-language case report is available from Irish Legal News.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What this means for LinkedIn users
Geographic scope
The inquiry concerned processing of users in the EEA and UK. It does not automatically decide the legality of LinkedIn’s practices for users in the United States or every other jurisdiction.
No automatic compensation
A regulatory fine is not distributed automatically to affected users. Any compensation claim would be a separate matter requiring its own legal route and, generally, proof of legally recognised damage.
Not a finding that LinkedIn sold data
The DPC’s stated findings concern lawfulness, fairness and transparency in processing for behavioural analysis, targeted advertising and analytics. “LinkedIn sold users’ data” is not an accurate summary of the decision.
Free tools Windows power users keep installed
One-click scans. No signup required.
Not a security-breach ruling
The case did not find that an unauthorised intruder accessed LinkedIn systems. It addressed the legal justification and fairness of authorised data processing.
Why advertisers and other platforms should care
- Map each purpose separately: advertising, analytics and behavioural profiling should not be bundled into one vague purpose.
- Match the legal basis to the operation: consent, contractual necessity and legitimate interests are not interchangeable labels.
- Test contractual necessity objectively: revenue generation or improved engagement does not by itself make processing necessary to perform a contract.
- Make consent genuinely optional and specific: the choice must cover the processing actually carried out.
- Document legitimate-interest assessments: identify the interest, assess necessity, weigh user rights and account for reasonable expectations.
- Make notices operationally clear: identify data categories, purposes and legal bases, including where data comes from third parties.
- Review partner data: third-party sources and customer-provided data require their own provenance, purpose and disclosure checks.
- Treat fairness as substantive: a technically complete notice will not cure a processing design that is unexpected or disproportionate.
Timeline
- 20 August 2018: La Quadrature Du Net’s complaint-based inquiry began after referral from France’s CNIL; the complaint represented 8,540 users, according to the High Court case summary.
- July 2024: The DPC submitted its draft decision through the GDPR cooperation mechanism; no concerned supervisory authority objected.
- 22 October 2024: The DPC decision was dated.
- 24 October 2024: The DPC announced the €310 million decision.
- 18 November 2024: LinkedIn appealed.
- 25 June 2025: The High Court directed that preliminary issues be determined first.
- 2 December 2025: The preliminary-issue hearing began.
- 20 April 2026: The High Court delivered its preliminary procedural judgment.
- 18 August 2026: The DPC register still showed the fine as pending appeal.
The Bottom Line
€310 million is the amount Ireland’s DPC imposed on LinkedIn Ireland for GDPR findings involving targeted advertising, behavioural analysis, analytics and transparency. The decision is not yet finally settled: LinkedIn’s appeal remains pending, and the 2026 High Court judgment addressed procedure rather than the merits.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




