Skip to content
Privacy & Security

LinkedIn Gets ‘Browsergate’ Proposed Class Actions Thrown Out

A federal judge found plaintiffs couldn't demonstrate LinkedIn harmed them by scanning browser extensions.
By

Reading time 2 minutes

Comments (0)

Microsoft-owned LinkedIn has had two separate proposed class actions claiming the site illegally scanned users’ browser extension data thrown out.

In a ruling issued earlier this week, spotted by Ars Technica, Judge Vince Chhabria of the US District Court for the Northern District of California rejected the plaintiffs’ standing to sue, stating that they failed to demonstrate they had “browser extensions installed that conveyed private information to LinkedIn.” Chhabria also suggested that the two plaintiffs—California residents Nicholas Farrell and Jeff Ganan—would have difficulty proving any privacy violations occurred, let alone win the case.

Earlier this year, a German entity called Fairlinked issued a report titled “Browsergate,” Ars reported. Fairlinked argued LinkedIn violates prohibitions on collecting “special category data” (racial/ethnic origin, political beliefs, etc.) under European Union law, since browser extensions can contain sensitive data. The Browsergate report also argued the scanning violated California’s state privacy laws, punishable by a $5,000 fine per LinkedIn user in the state.

Per The Next Web, independent parties like BleepingComputer confirmed the lawsuits’ core allegation that LinkedIn scans visitors for 6,000 browser extensions, collected hardware, and software data, and sent it back with every API request, all without disclosure or a mention in its privacy policy. That said, Fairlinked seems to be run by the staff of Teamfluence, an Estonian firm.

LinkedIn claimed in its motion to dismiss that Teamfluence was actually developing its own browser extension that scraped LinkedIn data, a violation of LinkedIn policies. The company scans browser extensions in part to identify such abusive apps, it argued. Tyler Reguly, an associate director at cybersecurity firm Fortra, told SecurityWeek earlier this year LinkedIn’s scanning appears to have been limited to determining whether extensions are installed, not yanking further data from visitors.

While most coverage framed the suits around the issue of web scraping, Chhabria’s ruling emphasized neither plaintiff could demonstrate harm. Chhabria also appeared to specifically agree with LinkedIn’s argument that users “voluntarily download browser extensions, which by their nature intentionally expose data to websites,” suggesting it was a fatal flaw in the case.

Ganan’s lawyer, J.R. Howell, told Ars Technica he was considering either a federal appeal or re-filing the proposed class action in California state court. Howell added that although he has served as counsel to Fairlinked in a separate case, his “investigative work with Fairlinked e.V. and Browsergate occurred before my office filed the Ganan complaint.”

It’s less clear how the Browsergate complaints might fare in the EU, where Fairlinked argued LinkedIn’s practices violate multiple sections of the General Data Protection Regulation (GDPR). Stateside, LinkedIn is still facing a proposed antitrust class action claiming it illegally holds 97% of the professional social networking market.

Share this story

Sign up for our newsletters

Subscribe and interact with our community, get up to date with our customised Newsletters and much more.