Data Protection Rights – Data Scraping in light of ‘BrowserGate’

Introduction

It has long been thought, ever since the late 1990s and 2000s with the dot-com boom, into the 2020s following films such as ‘The Social Dilemma’, that if something is free, then you are the product. But at what point does the practice of ‘data scraping’ breach a user’s right to privacy, and is the information gathered worth the potential legal risks it comes with? This article considers the same in light of a recent investigation into covert data scraping allegedly carried out by the social media platform, LinkedIn.

What is Data Scraping?

Data scraping is the process of using software to automatically harvest data that is publicly available on the internet. When aggregated, this data has the potential to pose a serious risk to data protection rights that individuals enjoy under the UK GDPR and Data Protection Act 2018. We saw, for example, in 2021 that the aggregated data from 700 million LinkedIn user records had reportedly been sold on the dark web. Rather than a hack of their servers, LinkedIn confirmed that the incident was a result of aggressive data web scraping.

In the EU, the case of Digital Rights Ireland (C-293/12, 2014) demonstrated that the collection of data in masses can be dangerous, even if it is done for the purpose of preventing crime. In this case the court struck out the Data Retention Directive, which required telecommunications companies to retain the data of its customers for the purpose of crime prevention and investigation. The court deemed the Directive to be incompatible with Articles 7 and 8 of the Charter of Fundamental Rights of the European Union, partly because it was considered not to provide sufficient safeguards to protect the data retained against the risk of abuse and unlawful access.

Legal Repercussions of Data Scraping

It is important to note that whilst users may consent to making their personal data publicly accessible – for example, on a site like LinkedIn a user may submit information relating to their job titles, company affiliations, email address, phone number, and even their geolocation – scraping that data without consent does not extinguish the data subject’s rights in relation to how it is subsequently used or processed. In doing so, a controller may (inadvertently or not) commit a number of legal breaches, including in relation to privacy, data protection, and even copyright (see Taylor Hampton’s detailed analysis on this subject here).

‘BrowserGate’ Investigation

Since its acquisition by Microsoft in 2016 for $26.2 billion, LinkedIn has become one of the largest careers development and networking social media platforms in the world. Recently, the company has been the subject of an investigation by a European, not-for-profit, advocacy and privacy group named Fairlinked e.V. The investigation, known as ‘BrowserGate’, alleged that LinkedIn engaged in one of the largest corporate espionage and data breaches in history by silently injecting concealed code into user sessions, probing their devices for their installed browser extensions, fingerprints and scanning more than 6,200 browser extensions in 2026 alone when the platform was opened within a Chrome-based browser. This is important because by reviewing extensions, it had the potential to reveal data about data subjects, including more sensitive information such as political opinions, religious beliefs and disabilities. Under Article 9 GDPR, such data is deemed special categories data and is afforded a higher level of protection under data protection law. Following the investigation, a proposed class action lawsuit, Ganan v. LinkedIn Corporation, was filed on 6 April 2026 in the US District Court, Northern District of California. The case is ongoing.

The ‘BrowserGate’ investigation claimed that LinkedIn did not obtain consent to collect such data from its users, nor make any disclosures regarding the way this data was being collected, or indeed inform users via its privacy statement that it would be doing so. This is not the first time the platform has been accused of data protection breaches; in October 2024 LinkedIn was fined €310 million by the Irish Data Protection Commission for processing personal data without a valid legal basis in the context of targeted advertising.

Legal Risks?

From a commercial perspective, the data gathered through scraping and opt-in processes can be valuable to a business. Training systems through access to millions of data points can improve their efficiency, and scanning user data can result in more targeted advertising.

However, organisations should be aware that data collection for commercial reasons should not outweigh a user’s right to privacy or their data protection rights. Any data collection must at the very least have a lawful basis under Article 6 UK GDPR and there must be a sufficient disclosure to the user regarding the collection of their data to comply with Article 13 UK GDPR. Businesses must be particularly careful regarding how it processes the special categories of data under Article 9 GDPR. Given the allegations made in ‘BrowserGate’, it is possible that LinkedIn may have had access to such personal data. If LinkedIn is found to have breached data protection rights, then it will be left wondering whether such a breach was commercially justified.

Contact Us

Taylor Hampton has extensive experience in helping individuals enforce data protection rights and recover compensation for unlawful breaches. If you are concerned that your rights have been breached, please contact us here, for a free consultation to see how we can help.

Disclaimer: This article is provided for general information purposes only and does not amount to legal advice. Civil procedure rules and case law may change over time. You should always seek professional legal advice tailored to your own circumstances before taking any action.

Search
Archive

For all enquiries please call Taylor Hampton on +44 20 7427 5970

Make An Enquiry