A US federal judge dismissed two class-action lawsuits accusing LinkedIn of illegally scanning users’ browser extensions, saying the plaintiffs failed to allege concrete privacy violations or demonstrate standing to sue.

  • Judge dismisses claims for lack of standing and plausible privacy violation.
  • LinkedIn argues scanning targets malicious scraping and is disclosed in privacy policy.
  • Plaintiffs consider appeals or filing in California state court with different standards.

What happened

LinkedIn successfully won the dismissal of two lawsuits in US District Court for the Northern District of California challenging its practice of scanning users’ Chrome browser extensions. The suits, brought by California residents Nicholas Farrell and Jeff Ganan, alleged that LinkedIn's scanning infringed on privacy rights by collecting sensitive user data through extensions. The presiding judge ruled that neither plaintiff demonstrated they had extensions that actually transmitted private information to LinkedIn, which is necessary to establish standing and a valid privacy claim.

The court gave the plaintiffs an opportunity to amend their complaints but expressed skepticism about their ability to make a credible case. LinkedIn disclosed in its privacy policy that it uses cookies and similar technologies to identify browser add-ons, and it argued the scanning mechanisms were primarily designed to detect automated scraping tools. The judge noted that users voluntarily install browser extensions, which inherently share some data with websites.

Why it matters

This ruling clarifies the legal challenges associated with claims against companies that scan browser extensions or browser activity, especially when users voluntarily install such extensions. It underscores the difficulty plaintiffs face in demonstrating concrete privacy harms necessary for standing in federal court, particularly when the scanning serves security functions like blocking unauthorized data scraping.

The case also highlights tensions between user privacy advocacy and platforms’ efforts to protect their data and networks from automated abuse. LinkedIn’s connection to its privacy policy disclosures and its judicial success may set precedents impacting future privacy litigation involving browser scanning technologies, influencing how transparent companies need to be and how courts interpret standing in digital privacy lawsuits.

What to watch next

Plaintiffs’ attorneys are exploring whether to appeal the dismissal to the Ninth Circuit Court of Appeals or pursue their suits in California state court, which applies different standing requirements and potentially offers a more favorable venue for privacy claims. How state courts respond to these types of claims could impact the broader litigation landscape around browser extension scanning and data collection.

Additionally, attention will likely remain on how LinkedIn and other tech platforms disclose their data collection practices and the extent to which courts accept the justification of scanning as a defense against privacy violations. Regulators and privacy advocates will also monitor if the legal environment evolves to impose stricter rules on transparency and user consent for scanning technologies.

Source assisted: This briefing began from a discovered source item from Ars Technica Tech Policy. Open the original source.
How SignalDesk reports: feeds and outside sources are used for discovery. Public briefings are edited to add context, buyer relevance and attribution before they are published. Read the standards

Related briefings