LinkedIn faced probe for Facebook ads targeting 18 mn non-members

Image
IANS San Francisco
Last Updated : Nov 26 2018 | 11:30 AM IST

An investigation by Ireland's Data Protection Commission (DPC) found that LinkedIn had processed hashed email addresses of approximately 18 million non-LinkedIn members and targeted these individuals on Facebook without necessary permission, a new report has revealed.

The investigation covered the activities of the Microsoft-owned professional networking platform during the first six months of 2018, The Verge reported on Saturday.

In its report published on Friday, DPC said that it concluded its audit of LinkedIn Ireland Unlimited Company (LinkedIn) in respect of its processing of personal data following an investigation of a complaint notified to the DPC by a non-LinkedIn user.

The complaint concerned LinkedIn's obtaining and use of the complainant's email address for the purpose of targeted advertising on the Facebook.

The investigation revealed that that LinkedIn Corporation in the US did not have the required permission from the data controller - LinkedIn Ireland -- to process hashed email addresses of 18 million non-LinkedIn members.

The complaint was ultimately "amicably resolved", with LinkedIn implementing a number of immediate actions to cease the processing of user data for the purposes that gave rise to the complaint, DPC said in its report.

However, the body was "concerned with the wider systemic issues identified" in its report, and undertook a second audit to see if LinkedIn had adequate "technical security and organisational measures."

DPC found that the site was "undertaking the pre-computation of a suggested professional network for non-LinkedIn members," and ordered them to stop and delete associated data that existed prior to May 25 of this year, the day when General Data Protection Regulation (GDPR) came into effect.

"We appreciate the DPC's 2017 investigation of a complaint about an advertising campaign and fully cooperated," Denis Kelleher, Head of Privacy, Europe, the Middle East and Africa, for LinkedIn, told TechCrunch in a statement.

"Unfortunately the strong processes and procedures we have in place were not followed and for that we are sorry. We've taken appropriate action, and have improved the way we work to ensure that this will not happen again," Kelleher said.

As TechCrunch pointed out LinkedIn did not get fined in this process because until the implementation of GDPR at the end of May, the regulator had no power to enforce fines.

It is still not clear how LinkedIn got hold of those 18 million email addresses.

--IANS

gb/vm

Disclaimer: No Business Standard Journalist was involved in creation of this content

*Subscribe to Business Standard digital and get complimentary access to The New York Times

Smart Quarterly

₹900

3 Months

₹300/Month

SAVE 25%

Smart Essential

₹2,700

1 Year

₹225/Month

SAVE 46%
*Complimentary New York Times access for the 2nd year will be given after 12 months

Super Saver

₹3,900

2 Years

₹162/Month

Subscribe

Renews automatically, cancel anytime

Here’s what’s included in our digital subscription plans

Exclusive premium stories online

  • Over 30 premium stories daily, handpicked by our editors

Complimentary Access to The New York Times

  • News, Games, Cooking, Audio, Wirecutter & The Athletic

Business Standard Epaper

  • Digital replica of our daily newspaper — with options to read, save, and share

Curated Newsletters

  • Insights on markets, finance, politics, tech, and more delivered to your inbox

Market Analysis & Investment Insights

  • In-depth market analysis & insights with access to The Smart Investor

Archives

  • Repository of articles and publications dating back to 1997

Ad-free Reading

  • Uninterrupted reading experience with no advertisements

Seamless Access Across All Devices

  • Access Business Standard across devices — mobile, tablet, or PC, via web or app

More From This Section

First Published: Nov 26 2018 | 11:24 AM IST

Next Story