Skip to content
Enforcement · Data Protection Authority of Ireland EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.

LinkedIn: Insufficient legal basis for data processing

The Irish DPA (DPC) has fined LinkedIn EUR 310 million.

€310,000,000 Fine

Full text 2 findings

Paragraphs carrying a topic or an applied provision show those connections inline
§

The Irish DPA (DPC) has fined LinkedIn EUR 310 million. This decision is related to an investigation following a complaint in 2018 from the French NGO 'La Quadrature Du Net'. In July 2024, the DPC issued a draft decision under the GDPR cooperation mechanism under Art. 60 GDPR, to which no objections were raised. During its investigation, the DPC found that LinkedIn had no valid legal basis for processing user data for the purposes of behavioral analysis and targeted advertising. The DPC found that LinkedIn could not rely on Art. 6 (1) a) GDPR, as the consent of the users did not appear to be freely given, informed and unambiguous. Furthermore, according to the DPC, LinkedIn could not rely on Art. 6 (1) f) GDPR, as the interests, fundamental rights and freedoms of the users outweighed the interests of LinkedIn. The DPC also ruled that LinkedIn could not rely on Article 6 (1) b) GDPR as a legal basis.

§

Finally, the DPC also found that LinkedIn had not provided users with sufficient information about the data processing in accordance with Art. 13 (1) c) GDPR and Art. 14 (1) c) GDPR. GDPR Articles: Art. 5 (1) a) GDPR, Art. 6 (1) a), e), f) GDPR, Art. 13 (1) c) GDPR, Art. 14 (1) c) GDPR Industry: Media, Telecoms and Broadcasting

How it connects

2 of 2 paragraphs apply legislation or carry a topic — see them in the full text ↓
C-654/23 Inteligo Media SA v Autoritatea Naţională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP) Het Hof van Justitie van de EU (Eerste Kamer) beantwoordt een prejudiciële vraag over de uitleg van artikel 13 van Richtlijn 2002/58/EC (ePrivacy) en de verhouding tot de GDPR,… CJEU Mar 27, 2025 Telecommunications Personal Data Marketing
C-154/21 RW v Österreichische Post AG The Court of Justice of the European Union (First Chamber), in response to a preliminary reference from the Oberster Gerichtshof (Austrian Supreme Court), interpreted Article… CJEU ·First Chamber Jan 12, 2023 Right of Access Personal Data Recipient
C-654/23 Inteligo Media SA v Autoritatea Naţională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP) The Court of Justice of the European Union ruled on a preliminary reference from the Romanian Curtea de Apel Bucureşti in proceedings between Inteligo Media SA and the Romanian… CJEU ·First Chamber Nov 13, 2025 Telecommunications Personal Data Legitimate Interest
2022 EDPB Annual Report 2021 Enhancing the depth and breadth of data protection 2 EDPB Annual Report 2021 2 ENHANCING THE DEPTH AND BREADTH OF DATA PROTECTION An Executive Summary of this report, which… May 12, 2022 Privacy Shield Processing Agreement International Transfer
3 O 762/19 LG Rostock: Pre-ticked cookie consent boxes invalid under Art 6(1)(a) GDPR The German consumer organisation Bundesverband der Verbraucherzentralen und Verbraucherverbände - Verbraucherzentrale Bundesverband e.V. (vzbv, the claimant) filed a lawsuit… Sep 15, 2020 Consent Legitimate Interest Controllers
C-507/17 Google LLC v CNIL C-507/17 (Google Territorial Scope) CJEU Sep 24, 2019 Territorial scope (GDPR) Right to be Forgotten Direct Marketing