Disclaimer: Not legal advice. Consult counsel for your specific jurisdiction and use case.
United States
The hiQ Labs v LinkedIn case (Ninth Circuit, remand decision April 2022) established that scraping publicly accessible LinkedIn data does not violate the Computer Fraud and Abuse Act (CFAA), the main federal anti-hacking statute. Public data scraping is generally lawful in the US under that framework.
Caveats: violating LinkedIn's Terms of Service is a separate matter from the CFAA (contract law, not criminal law). State-level privacy statutes like CCPA add another layer entirely, independent of whether the scraping itself was a CFAA violation.
How the hiQ case really ended
Most summaries stop at the 2022 CFAA ruling, which makes the case sound like an unambiguous win for scraping. The fuller story is more useful. After the Ninth Circuit's ruling on the CFAA question, the case continued in district court on LinkedIn's separate claims: breach of contract (violating the User Agreement), trespass to chattels, and California's state computer-access law. In December 2022, after six years of litigation, the parties settled with a $500,000 judgment against hiQ and a permanent injunction requiring it to stop scraping LinkedIn entirely and destroy all data, code, and algorithms built from it. hiQ shut down not long after. The legal principle, that scraping public data isn't a federal crime, held up. The company that established it didn't survive the rest of the lawsuit. That's the realistic takeaway for anyone reading the CFAA headline as a green light.
Meta v Bright Data (2024)
A more recent case reinforces the same public-data principle in a social-media context closer to LinkedIn's own. In January 2024, a federal judge granted summary judgment for Bright Data, a scraping-infrastructure company Meta had sued over collecting public, logged-out data from Facebook and Instagram. The court held that scraping data that's publicly available without an account and without agreeing to any terms doesn't violate the CFAA or function as a breach of Meta's terms of service, since Bright Data was never actually "using" Meta's product in the way the terms govern. Meta dropped the lawsuit the following month and waived its right to appeal. Combined with hiQ, this is now two separate federal rulings, four years apart, reaching the same conclusion about public social-platform data.
European Union
Public LinkedIn data extraction is lawful under GDPR Article 6(1)(f), the legitimate interest basis, provided you can defend the proportionality of the processing and respect data subject rights when they're exercised. See our GDPR guide for the full assessment.
United Kingdom
UK ICO guidance largely mirrors EU GDPR post-Brexit. The same conditions apply: public data only, legitimate interest documented, opt-outs honored when exercised.
What's NOT legal anywhere
- Bypassing LinkedIn's authentication walls or paywalled Sales Navigator/Recruiter data you don't have a license for
- Using credentials you don't own or aren't authorized to use
- Reselling personal data in bulk without a lawful basis for that specific use
- Ignoring a lawful opt-out or erasure request once it's been made
Frequently asked questions
Did hiQ actually win its case against LinkedIn?
Only partly, and the ending is the more instructive part. The Ninth Circuit ruled in 2022 that scraping public LinkedIn data doesn't violate the CFAA, which is the headline most articles cite. But the case then continued on LinkedIn's separate breach-of-contract and trespass claims, and in December 2022 the parties settled with a $500,000 judgment against hiQ, plus a permanent injunction forcing it to stop scraping and destroy everything built from the data. hiQ shut down. The CFAA precedent survived; the company that won it didn't.
What did the Meta v Bright Data case add in 2024?
A more recent, social-media-specific version of the same principle. In January 2024, a federal judge granted summary judgment for Bright Data, holding that scraping Meta's publicly accessible, logged-out pages didn't violate the CFAA or Meta's terms of service, since Bright Data wasn't logged in and hadn't agreed to those terms in that context. Meta dropped the case in February 2024 and waived its appeal.
So is scraping LinkedIn data actually risk-free?
No. Both hiQ and Bright Data show the CFAA isn't the tool platforms win with, but both cases also involved platforms suing over conduct at industrial scale, cloud infrastructure, resale, and in hiQ's case, a direct commercial competitor to LinkedIn's own data products. Ordinary browser-based extraction at human-like rates, for your own outreach, sits in a very different risk category than either lawsuit.
Does using a scraping tool make my own company liable, not just the tool?
The account doing the scraping is the one exposed to LinkedIn's own enforcement (restriction or termination), and the company whose data practices are in question is generally the one responsible for compliance with GDPR, CCPA, and similar laws, regardless of which vendor's software touched the data first.
Sources: Ninth Circuit, hiQ Labs v. LinkedIn opinion (2022), case history and settlement summary. General information only, not legal advice.
Lawful extraction tooling.
Leadsforlinked operates within public-data norms, at human browsing rates. Free 100 leads on signup.
Start free