EU watchdog: LinkedIn processed email addresses of 18M non-members and targeted them with advertising on Facebook without permission before GDPR became a law
Elaine Edwards / The Irish Times :
Context & Ripple Effects
This 2018 disclosure is the origin point of a six-year enforcement arc: an EU watchdog found that before GDPR took effect, LinkedIn had processed the email addresses of 18M people who never signed up and used them to target advertising at those same people on Facebook — conduct carried out on non-members who had no relationship with the platform at all.
The Irish Data Protection Commission, as lead GDPR enforcer, spent years under fire for moving slowly on cases like this one critics questioned its willingness to crack down on firms dominating Ireland's economy — and the file eventually produced results: a €310M fine over behavioral analysis and targeted ads traced back to a 2018 complaint, alongside a separate ban on advertiser targeting built from LinkedIn Groups participation.
First-order effects
- LinkedIn's pre-GDPR practice of matching uploaded email addresses against non-members and running Facebook ads at them is now formally documented, putting the company's member-acquisition and audience-matching machinery directly in the regulator's sights.
Second-order effects
- Advertisers buying LinkedIn audiences face a shrinking legal toolkit: with Groups-derived targeting already withdrawn after complaints, each enforcement action narrows which data sources can lawfully feed cross-platform campaigns in the EU.
Third-order effects
- If the pattern holds — slow Irish proceedings ending in large retroactive fines — platforms will treat pre-2018 data-matching practices as standing liabilities, pushing EU ad targeting toward explicit-consent, first-party data only.
The trend: GDPR enforcement is converting legacy cross-platform data-matching practices into multi-year financial liabilities for social ad platforms, with Ireland's DPC as the bottleneck and eventual arbiter.