A US judge dismisses two lawsuits against LinkedIn over its scanning of browser extensions, saying users voluntarily expose data by downloading extensions
First reported by Ars Technica ·
LinkedIn's user data collection practices for browser extensions are not considered illegal in federal court.
A U.S. judge has dismissed two lawsuits filed against LinkedIn, alleging the company illegally scanned users' browser extensions. Judge Vince Chhabria ruled that the plaintiffs failed to demonstrate they had suffered a concrete privacy violation or had standing to sue. The lawsuits, known as "BrowserGate," stemmed from a report claiming LinkedIn illegally searched users' computers. LinkedIn argued that it scans extensions to detect scraping and bot activity, a practice it claims is disclosed in its privacy policy. The judge suggested that users voluntarily expose data by installing browser extensions, making it unlikely for plaintiffs to prove a privacy violation. While the judge allowed plaintiffs to amend their complaints, he expressed doubt about their ability to establish a valid case, noting that they never alleged their specific extensions conveyed private information to LinkedIn.
This ruling sets a precedent for how privacy claims related to browser extension data collection will be handled in federal courts, potentially making it harder for future plaintiffs to establish standing. The decision hinges on the argument that users implicitly consent to data exposure by installing extensions, shifting the burden of proof onto individuals to demonstrate specific harm rather than generalized surveillance. This could embolden companies to continue similar data collection practices, provided they are disclosed in privacy policies and the alleged harm is not specific enough.
The legal strategy may shift to state courts or focus on appeals, as plaintiffs' attorneys explore alternative venues to litigate the merits of LinkedIn's surveillance practices. The core dispute remains whether LinkedIn's detection of browser extensions constitutes an "unpermitted probe" that violates user privacy, regardless of the data's ultimate use or disclosure. Future litigation will likely hinge on more precise allegations of specific private information being accessed and transmitted, moving beyond the general claim of unauthorized scanning.
AI-written summary. May contain errors.