Irish Regulator Fines LinkedIn 310 Million Euros for GDPR Violations
Time 2 Minute Read

On October 24, 2024, the Irish Data Protection Commission (the “DPC”) announced that it had issued a fine of €310 million (approx. $335 million) against LinkedIn Ireland Unlimited Company (“LinkedIn”) for breaches of the EU General Data Protection Regulation (“GDPR”) related to transparency, fairness and lawfulness in the context of the company’s processing of its users’ personal data for behavioral analysis and targeted advertising. In addition to the fine, the DPC also issued a reprimand and an order to bring processing into compliance.  

Specifically, the DPC considered that LinkedIn’s practices:

  • breached the rules on legal bases under Article 6 of the GDPR and the sub-principle of lawfulness under Article 5(1)(a) of the GDPR as LinkedIn: (1) relied on invalid consent to process third party data of its members for behavioral analysis and targeted advertising; and (2) relied unlawfully on legitimate interests and contractual necessity for its processing of first party personal data of its members for behavioral analysis and targeted advertising;
  • breached the sub-principle of fairness under Article 5(1)(a) of the GDPR; and
  • breached the rules on provision of information under Articles 13 and 14 of the GDPR.

Before being finalized by the DPC, this decision was submitted to the remaining concerned supervisory authorities in the EU under Article 60 of the GDPR. The remaining supervisory authorities did not raise any objections to the DPC’s decision. 

Read the Press Release.  

You May Also Be Interested In

Time 3 Minute Read

The Connecticut Attorney General recently issued a legal memorandum regarding the application of existing Connecticut laws, such as the Connecticut Data Privacy Act, to the use of artificial intelligence.

Time 3 Minute Read

On March 20, 2026, Oklahoma Governor Kevin Stitt signed SB 546 into law, enacting the Oklahoma Consumer Data Privacy Act, which will take effect on January 1, 2027.

Time 2 Minute Read

On March 23, 2026, the UK Information Commissioner's Office released new guidance clarifying the use of the new recognized legitimate interest lawful basis for processing personal information under UK data protection law.

Time 2 Minute Read

On March 3, 2026, the Virginia Attorney General appealed a federal court’s grant of a preliminary injunction barring the enforcement of a new Virginia law requiring age verification and a time limit on social media use by minors under the age of 16 pending a final determination on the merits.    

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Archives

Jump to Page