EU watchdog: LinkedIn processed email addresses of 18M non-members and targeted them with advertising on Facebook without permission before GDPR became a law
Elaine Edwards / The Irish Times : Tweets: @wolfiechristl Tweets: Wolfie Christl / @wolfiechristl : 18 million data subjects affected, a very large company as a data controller, under the GDPR such a violation should result in a MASSIVE fine.Here's the article on the LinkedIn case by @ElaineEdwardsIT: http://www.irishtimes.com/...
Context & Ripple Effects
This 2018 disclosure landed weeks after the Irish Data Protection Commission began operating as the EU's lead GDPR enforcer, and just a month after it sized Facebook's security breach at roughly 3M Europeans — establishing a pattern of the Dublin regulator handling the biggest platform cases. The conduct itself predates GDPR: LinkedIn matched email addresses of 18 million people who never signed up and aimed ads at them through Facebook, meaning the affected had no account, no settings page, and no way to object.
First-order effects
- LinkedIn faces exposure under the new regime for conduct committed before GDPR took force, with commentators like Wolfie Christl arguing the scale — 18M data subjects, a very large controller — warrants a massive fine.
- The 18M non-members are affected with no recourse available inside either platform, since consent mechanisms only reach registered users.
Second-order effects
- Advertisers leaning on cross-platform audience matching built from scraped or purchased email lists face tightening rules; LinkedIn later cut off advertisers' ability to target EU users via LinkedIn Groups data after a complaint, showing the same pressure applied to adjacent targeting channels.
- Facebook's own data-handling record stays under the same microscope, with the DPC investigating its 533M-account leak in 2021 — cross-platform ad infrastructure becomes a shared compliance liability for both companies.
Third-order effects
- The arc runs from this 2018 finding to the DPC's eventual €310M fine over behavioral analysis and targeted ads, validating critics who had questioned the regulator's willingness to crack down on firms dominating Ireland's economy — enforcement lag measured in years, but arriving at material sums.
- If the pattern holds, pre-consent data matching — profiling people who never agreed to be profiled — becomes structurally unviable in the EU, pushing ad platforms toward consent-gated audiences regardless of where the underlying data was collected.
The trend: GDPR enforcement is converting pre-regulation data-matching practices into multi-year, nine-figure liabilities that progressively dismantle consent-free behavioral advertising in the EU.