LinkedIn.
LinkedIn — owned by Microsoft since 2016 — turned on generative-AI training using your profile, posts, resume, and public activity by default, and in September 2024 it started doing so before it even updated its privacy policy §2. The opt-out exists (Settings → Data privacy → Data for Generative AI improvement) but it isn't retroactive and only covers content-generating AI — stopping the rest takes a separate objection form §6. On November 3, 2025 LinkedIn extended the default-on AI training to EU/UK/Swiss/Canada/Hong Kong users under a 'legitimate interest' theory §1 and began sharing more member data with parent Microsoft for cross-product ad targeting §5. Private messages are excluded §4 — a real, meaningful limit. But regulators aren't convinced: the Irish DPC hit LinkedIn with a €310M fine in October 2024 for unlawful consent and targeted advertising §8, and a California suit accused it of sharing private messages to train AI §9.
TL;DR — 8 answers.
The eight things you actually want to know, at a glance.
The questions, answered.
No legalese. Every answer the way your most cynical friend would put it.
Do they sell your data?
LinkedIn runs an ad business and, since Nov 2025, shares more member data with Microsoft and its affiliates for cross-product ad targeting — default-on in the US and most of the world.
Are they tracking you on other sites?
LinkedIn feeds in Microsoft's Universal Event Tag (UET), which records what you do across other websites and reports it back for ad measurement.
Can your data train their AI?
Default. Yes. Your profile, resume, posts, and public activity train LinkedIn's generative-AI models unless you turn it off. In Sept 2024 they started before updating the privacy policy; in Nov 2025 they extended it to the EU/UK under 'legitimate interest.'
Who can see what you do?
Public profile & posts: everyone, plus LinkedIn's AI and Microsoft's ad stack. Private messages and private posts are excluded from training [[S4]] — though a California lawsuit alleges DMs were shared anyway [[S9]].
Can you delete everything?
You can delete your account, but training already done on your data cannot be undone — LinkedIn says opting out 'does not affect training that has already taken place.'
Do they honor your opt-out?
The Generative-AI toggle works going forward, but it only covers content-generating AI. To stop non-content AI (personalization, security, anti-abuse) you must file a separate Data Processing Objection Form, and GPC isn't honored.
Special handling for minors?
Minimum age is 16 in most regions (18 in some). LinkedIn says it does not use data from members it knows to be minors for AI training, but the platform is built for adults and offers little beyond the age gate.
Been fined for this before?
€310M (Irish DPC, Oct 2024) for unlawful consent and tracking-based targeted advertising — one of the largest GDPR fines ever [[S8]]. A California suit also accused LinkedIn of sharing private messages to train AI [[S9]].
At a glance, honestly.
Eight signals, color-coded. Like a model card for a machine — except the machine is reading your data.
The Privacy Label, honestly.
An Apple-style label for what's collected and a Cranor-style back-of-pack for what they do with it. Every cell links to the exact line in their policy.
The receipts, translated.
Five of the worst clauses, lifted verbatim. Strikethroughs are theirs. Marginalia is ours.
Dark patterns spotted.
Tricks the policy and surrounding UX use to make you "consent" without really consenting.
Your rights, by where you live.
Same company, wildly different rights depending on your jurisdiction. Direct links to the specific opt-out / delete / access flows.
- ✓ Right of access
- ✓ Right to erasure
- ✓ Right to object to processing (incl. AI training)
- ✓ Right to data portability
- ✓ Right against solely-automated decisions
Source: §7
The actual sources.
Every claim above is anchored to a line in the policy we analyzed. Click any section ID to view it in context.
SOURCE: https://www.linkedin.com/legal/privacy-policy · POLICY VERSION: 2025-11-03 · SNAPSHOT HASH:
- §1LinkedIn Privacy Policy / User Agreement · AI model training (effective Nov 3, 2025)"We and our affiliates may use your personal data, including your profile and public content you post, to develop and train artificial intelligence models. We will not use the content of your private messages to train these models."
- §2404 Media · LinkedIn began training on user data before updating its policy (Sept 18, 2024)"LinkedIn introduced a new privacy setting and opt-out form before updating its privacy policy to reflect that data collected from the platform would be used to train AI models."
- §3LinkedIn Privacy Policy · data we collect"We collect the data you provide, including your profile, work experience, education, skills, resumes, and content you post, as well as data about your use of our Services."
- §4LinkedIn Help · what data is used for generative AI (exclusions)"LinkedIn does not use the content of your private messages to train generative AI models, and private posts are excluded from training."
- §5LinkedIn User Agreement · sharing with affiliates / Microsoft (ads, Nov 2025)"We share data with our affiliates, including Microsoft, so they can deliver and measure ads. Affiliates are companies related by common ownership, including Microsoft Corporation and its subsidiaries."
- §6LinkedIn Settings · Data for Generative AI improvement & objection form"You can turn off 'Use my data for training content creation AI models' in Settings. Opting out does not affect training that has already taken place. To object to other AI uses, submit a Data Processing Objection Form."
- §7LinkedIn · legal basis for AI training in the EU/UK (legitimate interest)"Where permitted, we rely on legitimate interests to process member data for the development and training of AI models."
- §8Irish Data Protection Commission · €310M fine against LinkedIn (24 Oct 2024)"The DPC found that LinkedIn relied on invalid consent, and relied unlawfully on legitimate interests and contractual necessity, for its processing of members' personal data for behavioural analysis and targeted advertising, and imposed administrative fines totalling €310 million."
- §9California lawsuit · alleged sharing of private messages to train AI (2025)"A proposed class action alleged LinkedIn disclosed Premium customers' private messages to third parties to train generative AI models; LinkedIn denied the claims."
- §10LinkedIn Privacy Policy · recommendations & automated processing"We use data and automated systems to make recommendations, rank your feed, suggest jobs and connections, and personalize the Services."
- §11LinkedIn User Agreement · minimum age"You must be at least 16 years old, or older where required by local law, to use the Services."
- §12LinkedIn / Microsoft · Universal Event Tag (cross-site ad tracking)"Microsoft has its own Universal Event Tag (UET) for ad performance tracking, which records what customers do on various websites and shares that information back to Microsoft, which LinkedIn will incorporate into its ad offering."