A US judge dismisses two lawsuits against LinkedIn over its scanning of browser extensions, saying users voluntarily expose data by downloading extensions
LinkedIn beat two lawsuits over its practice of scanning users' browser extensions, with a judge granting the Microsoft subsidiary's motion to dismiss the cases.
Context & Ripple Effects
LinkedIn’s legal fights have repeatedly centered on who controls information around its service: it sought to block external collection of public-profile data, but a court ordered it to remove those barriers in the 2017 hiQ scraping dispute, and an appeals court upheld that result in 2019. The Supreme Court later sent the public-profile scraping case back for further review.
The extension-scanning ruling addresses the inverse privacy boundary: information exposed from a user’s browser to LinkedIn rather than information outsiders seek from LinkedIn. The judge’s voluntary-exposure reasoning gives LinkedIn a favorable dismissal in that narrower setting.
First-order effects
- LinkedIn avoids liability in the two dismissed extension-scanning suits, while the plaintiffs’ privacy theory fails on the pleaded allegation that downloading an extension voluntarily exposed the relevant data.
Second-order effects
- Privacy plaintiffs challenging browser-based collection face a higher practical burden to distinguish data a service can observe through a user-authorized browser environment from data that remains private despite that authorization.
Third-order effects
- If courts continue to treat browser-extension installation as meaningful disclosure, browser privacy disputes may turn less on whether software observes data and more on the scope of the permission users delegated to the browser and service.
The trend: The case is part of a widening legal effort to define privacy and access boundaries around data exposed through user-authorized software rather than publicly posted on a platform.