Is Scraping LinkedIn Legal?
You have probably been told a court made this legal. The same case ended with the scraper shut out of LinkedIn for good.
Scraping LinkedIn is three questions wearing one coat. Whether it is a crime: in the United States, usually no. Whether it breaches LinkedIn’s User Agreement: for anyone holding a LinkedIn account, yes. And what data protection law lets you keep once the records are on your disk, which is where the fines have actually landed.
The three carry different bills. A criminal statute reaches a person, a contract reaches your accounts, and a data protection regulator reaches your database. The last two are the ones an ordinary B2B team runs into, and both have a dull way out that nobody argues about: read through an account you connect, with a server holding the pace. On that stack, gtm-api.com reports 20,000+ accounts at under a 1% ban rate.
On this page
- Three questions, three different answers
- What hiQ v. LinkedIn decided, and how it ended
- The crime question, and why it is the wrong worry
- The contract question, the one you already agreed to
- The data protection question, where the fines have landed
- Which of the three reaches a B2B team
- What changes on an account you connect
- FAQ
- Sources
Three questions, three different answers
Three bodies of law answer this, and they answer differently. The Computer Fraud and Abuse Act asks whether a computer was accessed without authorisation, and a public page is open to everybody. LinkedIn’s User Agreement asks whether you promised not to do this, and every account holder did. Data protection law asks what you may hold about a named person.
| The question | What it asks | Who it reaches | Where it has landed so far |
|---|---|---|---|
| Crime (the CFAA) | Was the computer accessed without authorisation | Whoever runs the bot | Signed out on public pages, the Ninth Circuit says no. Fake accounts and the password wall are still live |
| Contract (the User Agreement) | Did you agree not to scrape | Everyone holding a LinkedIn account | hiQ lost this one in 2022, and LinkedIn enforces it against accounts every day |
| Data protection (GDPR and its equivalents) | May you keep and use records about named people | Whoever stores the data, wherever the people live | EUR 240,000 against a LinkedIn contact scraper in France, December 2024 |
Merged, the three produce two confident wrong answers. One says a court made scraping legal, which reads a ruling about a criminal statute as a licence. The other says scraping is illegal, which promotes a contract term into a crime.
What hiQ v. LinkedIn decided, and how it ended
hiQ won the injunction and lost the case. The Ninth Circuit twice upheld an order stopping LinkedIn from blocking hiQ’s bots, on the ground that the CFAA does not fit a site open to the public. The district court then found hiQ had breached the User Agreement, and a stipulated judgment in December 2022 ended the scraping permanently.
The quoted sentence sits in the middle of a sequence that runs from 2017 to the end of 2022, and the sequence moves in both directions.
- 2017, an injunction before any ruling on the merits. hiQ sued after LinkedIn sent it a cease and desist, and the district court ordered LinkedIn to stop blocking hiQ’s access to public profiles. Everything the case became famous for sits on top of that preliminary posture.
- June 2021, the Supreme Court sent it back. Van Buren v. United States, decided 3 June 2021, read the statute as “a gates-up-or-down inquiry”, one either can or cannot access a system or an area inside it. On 14 June 2021 the Court vacated the Ninth Circuit’s hiQ judgment and returned it for a second look in that light.
- April 2022, the sentence everybody quotes. On remand the Ninth Circuit affirmed the injunction again and held that “when a computer network generally permits public access to its data, a user’s accessing that publicly available data will not constitute access without authorization under the CFAA”.
- November 2022, the half that travels less well. On 4 November 2022 the district court held that hiQ had breached the User Agreement, by scraping and by having contractors log in under false identities for quality assurance, while leaving hiQ’s waiver and estoppel defences for a jury.
- December 2022, the ending. The parties filed a stipulated judgment on 6 December 2022, entered two days later. hiQ paid $500,000, took a permanent injunction against scraping LinkedIn and against creating fake accounts, and agreed to destroy the data and the code built on it.
- The concession inside that judgment. hiQ also accepted that LinkedIn “may establish liability” under the CFAA and its California equivalent, based on its collection practices and on “hiQ’s direct access to password-protected pages on LinkedIn’s platforms using fake accounts”. Stipulated conclusions set no precedent, and this one shows what the party that won the appeal was willing to sign.
The opinion itself said what the CFAA ruling left standing. “Entities that view themselves as victims of data scraping are not without resort, even if the CFAA does not apply: state law trespass to chattels claims may still be available”, the court wrote, listing copyright infringement, misappropriation, unjust enrichment, conversion and breach of contract alongside it. LinkedIn used the last of those.
The crime question, and why it is the wrong worry
For a team reading profiles to build a pipeline, the criminal question is the smallest of the three. The statute is about access to a computer, the Ninth Circuit has held that a public site’s data is open to anyone, and the reported cases run against vendors operating at scale. What survives the holding is narrow and specific.
Van Buren supplied the framing the Ninth Circuit then applied. The Supreme Court described liability as a gates-up-or-down inquiry and warned that the government’s wider reading would make criminals of “millions of otherwise law-abiding citizens”, using the example of an employee who reads the news on a work computer against policy. A term of service is a policy. Breaking one stopped being the test for a federal crime.
That line is also where LinkedIn still litigates. On 3 October 2025 it sued ProAPIs and its founder in the Northern District of California over what the complaint calls an “industrial-scale fake account mill” that scraped member information, including data available only behind LinkedIn’s password wall, and resold access for up to $15,000 a month. Nothing in the hiQ line of cases protects that fact pattern.
The contract question, the one you already agreed to
This is the question that reaches an ordinary B2B team, and it reaches it through the account. LinkedIn’s User Agreement bans scraping in section 8.2, and the Ninth Circuit quoted the clause in its opinion. Everyone on your team with a LinkedIn login accepted that agreement at signup, so the promise has already been given on your side.
Section 8.2 tells members not to “Scrape or copy profiles and information of others through any means (including crawlers, browser plugins and add-ons, and any other technology or manual work)”. A second clause in the same list covers manual or automated software, devices, scripts, robots and other processes used to access, scrape, crawl or spider the service. Between the two there is no reading under which an automated read of profiles is permitted.
Whether that agreement reaches a particular scraper turns on the login, and a court has drawn the line. In Meta Platforms v. Bright Data (No. 3:23-cv-00077, Northern District of California, 23 January 2024) the court gave the scraper summary judgment on the contract claim, holding it “did not ‘use’ Facebook and Instagram when it engaged in public logged-off scraping” and stood “in the same shoes as a visitor to whom the Terms cannot apply”. The judge was Edward Chen, who had decided the hiQ contract question about fourteen months earlier.
The distinction is cleaner in a filing than in a sales team. The fields that make LinkedIn worth reading, full profiles, search results, contact details, sit behind the login, so a working stack reads from a member session. Once a member session is doing the reading, the agreement applies, and enforcement arrives as a checkpoint or a restriction on that account long before it arrives as a filing. LinkedIn account restricted covers that ladder and what reopens an account.
The data protection question, where the fines have landed
A LinkedIn profile is personal data about a named person, so copying it is processing, and the page having been public changes nothing about that. Under the GDPR you need a lawful basis for the copy, a retention period you can defend, and a notice to the person, because they never handed you the record themselves.
Article 14 is the one that surprises people. It governs information to be provided where personal data have not been obtained from the data subject, and it puts a clock on the notice: within one month of obtaining the record. A prospecting database built by scraping is the case that article describes, and the duty attaches to whoever holds the copy.
France’s regulator applied all of it to a LinkedIn scraper on 5 December 2024. The CNIL fined Kaspr EUR 240,000 and published the decision on 19 December. Kaspr sold a browser extension that pulled professional contact details off LinkedIn profiles into a database of around 160 million contacts, and the findings read like a list of what a scraped prospecting database gets wrong.
- A visibility setting is not consent to your database. Many of the contacts had limited their details to first and second-degree connections, and the regulator held that this choice did not authorise collection by a third party.
- Retention has to track the purpose. Records kept for five years from the last update went stale as people changed jobs, and the CNIL treated that period as disproportionate.
- The notice has to arrive, in a language the person reads. Kaspr began notifying individuals in 2022, four years after launch, by email written in English.
- “Publicly accessible sources” is no answer to a subject access request. Asked where their data came from, the company offered that phrase without naming the sources listed in its own privacy policy.
Kaspr is a single decision, and the direction of travel is wider. Twelve data protection authorities signed a joint statement on data scraping on 24 August 2023 whose first key takeaway reads “Personal information that is publicly accessible is still subject to data protection and privacy laws in most jurisdictions”, and a follow-up signed by seventeen authorities landed on 28 October 2024. The Dutch regulator’s EUR 30.5 million fine on Clearview AI, decided 16 May 2024 and announced on 3 September, ran the same reasoning over images scraped from the open web.
None of this is theoretical for a B2B list. If a record on your disk describes somebody in the EU or the UK, the obligations attach to your copy, whether a bot collected it, a vendor sold it to you or an API returned it. What the route changes is your ability to say where each record came from and when. How email-finding tools arrive at an address, and why the contact card was the route this decision turned on, is on LinkedIn email scraper.
Which of the three reaches a B2B team
Ordered by the chance of costing you something this quarter: the User Agreement first, data protection second, the CFAA a long way back. The first arrives as restricted accounts. The second arrives as a letter about a database. The third is a vendor-scale question in every reported case, and it turns on fake accounts and the password wall.
LinkedIn does not need a court to act on the contract. The agreement is what lets it throttle, checkpoint, restrict and close the accounts doing the reading, and it applies that self-help long before anything is filed. The bill a scraping stack pays is an account, not a court date, and a closed one takes its connection graph and its message history with it.
Four things follow from that for the coming week.
- Answer the question you are actually being asked. When somebody says scraping is legal because of a court case, they mean the CFAA, and that answer does not travel to the contract question or to the GDPR one.
- Keep the reading inside accounts you control. Fake accounts and password-wall workarounds are the conduct that draws the lawsuits, and they are the two things hiQ conceded on.
- Write the retention position down before the first record lands. A lawful basis, a defensible retention period and a plan for Article 14 notices are cheaper to decide at the start than to reconstruct for a regulator.
- Do not rest a pipeline on one vendor’s legal exposure. LinkedIn sues the vendors, and their customers lose the service on the day it works. A resold scraper is somebody else’s legal position, priced per record.
What changes on an account you connect
An account-based API moves two of the three questions and leaves the third where it is. The criminal question falls away, because there is no fake account and nothing taken from behind a wall you were never admitted through. The data protection answer gets easier, because every record carries a source and a timestamp. The User Agreement question stays.
Mechanically the route is dull. You connect a LinkedIn account you already own, the platform runs it in an isolated cloud browser on a dedicated proxy, and your code calls typed endpoints that return parsed objects. The LinkedIn side of the server exposes 160+ typed tools across 11 toolsets, covering profile and company reads, people and Sales Navigator search, and the write actions on the same credential.
Two honest limits come with it. The API returns what the connected account can see, so it will never match a bulk dataset for raw coverage. And automation through a connected account still runs against LinkedIn’s User Agreement, which is the grey area every vendor in this category operates in, and no tool can make that untrue. What the route buys is control of the pace and a clean answer to provenance. Pricing is per connected account, from $10 per account at volume with the calls unmetered, and the detail sits on LinkedIn API pricing.
The route comparison, scraper against dataset against account-based API, is on LinkedIn scraping vs a safe API. What a profile record contains and how long you may keep it is on LinkedIn profile data API. The session and pacing mechanics that keep an account alive are on Safe LinkedIn automation, and the endpoint reference is in the developer docs.
Frequently Asked Questions
Can you be prosecuted for scraping LinkedIn?
In the United States, a bot reading public pages while signed out is unlikely to be committing a computer crime after the Ninth Circuit’s opinion of 18 April 2022, which held that data a site opens to the public is not accessed without authorization under the CFAA. The exposure concentrates where accounts are faked or a password wall is crossed, which is the conduct hiQ conceded could establish liability in its own consent judgment.
Does LinkedIn’s User Agreement apply if I never created an account?
A court has said it may not. In Meta Platforms v. Bright Data, decided 23 January 2024, the Northern District of California held that a scraper working logged off had not used the service and stood in the same position as any visitor, so the terms did not bind it. The useful LinkedIn fields sit behind the login, so a working stack reads from a member session, and at that point the agreement applies.
Is scraping LinkedIn legal under the GDPR?
Public visibility is not a lawful basis. Copying a profile is processing personal data about a named person, so it needs a basis, a retention period you can defend, and a notice to that person within one month of obtaining the record under Article 14. France’s CNIL fined Kaspr, a LinkedIn contact-scraping browser extension, EUR 240,000 on 5 December 2024 for failing on exactly those points.
What actually happens to a company that scrapes LinkedIn?
The usual outcome is account enforcement. LinkedIn throttles, checkpoints, restricts and then closes the accounts doing the reading, and each closure takes its connection graph and message history with it. The lawsuits go to vendors at scale: LinkedIn sued ProAPIs and its founder on 3 October 2025 over an operation its complaint describes as an industrial-scale fake account mill.
Does an account-based API change the legal position?
It moves two of the three. There is no fake account and nothing taken from behind a password wall, so the computer-crime question falls away, and each record arrives with a source and a timestamp, which is what a data protection answer needs. Automation through a connected account still runs against LinkedIn’s User Agreement, and no vendor can make that untrue.
Sources & Further Reading
- United States Court of Appeals for the Ninth Circuit, hiQ Labs, Inc. v. LinkedIn Corp., No. 17-16783, opinion filed 18 April 2022 (the CFAA holding, the User Agreement section 8.2 text, and the trespass-to-chattels passage)
- Supreme Court of the United States, Van Buren v. United States, No. 19-783, decided 3 June 2021 (the gates-up-or-down reading of the CFAA and the “millions of otherwise law-abiding citizens” passage)
- Proskauer, New Media and Technology Law Blog, analysis of the district court ruling of 4 November 2022 (the breach-of-contract holding and the defences left for trial)
- Proskauer, New Media and Technology Law Blog, the stipulated judgment of 6 December 2022 (the $500,000, the permanent injunction, and hiQ’s CFAA concession)
- Farella Braun + Martel, Meta Platforms, Inc. v. Bright Data Ltd., No. 3:23-cv-00077 (N.D. Cal.), ruling of 23 January 2024 (terms of service and logged-off scraping)
- CNIL, France’s data protection regulator, Data scraping: KASPR fined EUR 240,000, decision of 5 December 2024, published 19 December 2024
- Information Commissioner’s Office and eleven other authorities, joint statement on data scraping and the protection of privacy (PDF), 24 August 2023, and the follow-up statement of 28 October 2024
- Autoriteit Persoonsgegevens, fine on Clearview AI for illegal data collection, announced 3 September 2024 (EUR 30.5 million)
- EUR-Lex, Regulation (EU) 2016/679, Article 14 (information owed where personal data have not been obtained from the data subject, and the one-month deadline)
- Recorded Future News, LinkedIn sues software company allegedly scraping data from millions of profiles, 3 October 2025 (the ProAPIs complaint)
- Related: LinkedIn scraping vs a safe API · LinkedIn profile data API · Safe LinkedIn automation · LinkedIn account restricted · LinkedIn API pricing · Proxycurl shut down · Ethical LinkedIn outreach guidelines
Read the profile from an account you own, and know where it came from.
One typed contract for search, enrichment and outreach, running on LinkedIn accounts you connect, inside budgets the server enforces. On that stack, gtm-api.com reports 20,000+ accounts at under a 1% ban rate. Free plan, then from $10 per account at volume.
Last updated: September 2026 · Court records, the CNIL decision and the regulator statements verified against primary sources on 4 September 2026 and re-read on 6 September 2026
