Ist das Scraping von LinkedIn legal? Was die öffentlichen Aufzeichnungen tatsächlich zeigen
What counts as "LinkedIn scraping"
The public/private line, by data type
| Data type | Visible without login | Requires a logged-in session | Requires Sales Nav / Recruiter |
|---|---|---|---|
| Name, headline, photo | Usually | Immer | Nein |
| Current company & title | Often | Immer | Nein |
| Full work & education history | Rarely, capped view | Full detail | Nein |
| Connections & mutual connections | Nein | Limited, by degree | Extended, cross-network |
| Posts, articles, activity | Often, if public | Immer | Nein |
| Contact info (email/phone) | Nein | Only if shared | No added access |
| Advanced search filters, saved lists | Nein | Basic search only | Full filter set |
Five methods, ranked by risk
| Methode | What it can reach | Where it breaks first | Risk profile |
|---|---|---|---|
| Manual browsing | Whatever a person can read and click, one profile at a time. | Your own time. It doesn't scale past casual research. | Minimal |
| Browser extension | What's rendered on screen, inside one browser session, one account. | The extension itself: LinkedIn's own client-side detection and Google's Manifest V3 deprecation both target this layer, independently. | Elevated |
| No-code / SaaS automation tool | Whatever the vendor's shared infrastructure is built to reach, running against your linked account. | The vendor. If LinkedIn identifies the pattern once, every customer sharing that infrastructure is exposed at the same time. | Elevated |
| Custom code, independent index | Whatever your own infrastructure allows, collected outside any single member's session. | Nothing, technically, until it's caught. This is the exact structure every case below targeted. | Hoch |
| Account-basierte API | What one authenticated, linked member's own account can already see. | Nothing structurally new: it removes one failure mode, a shared index taken down for every customer at once, not Section 8.2 from the linked account itself. | Different, not zero |
Can you get banned for this
The three legal layers, and how hiQ actually ended
| Datum | Was ist passiert |
|---|---|
| 2017 | hiQ Labs sues LinkedIn after LinkedIn sends a cease-and-desist letter and moves to block hiQ's access to public profile data. |
| April 2022 | The Ninth Circuit affirms that accessing publicly viewable LinkedIn profile data likely does not violate the CFAA. This is the ruling most "scraping is legal" articles stop at. |
| 1 August 2022 | The district court dissolves the preliminary injunction that had kept hiQ's access open, on separate grounds tied to LinkedIn's Terms of Service claim. |
| 6 December 2022 | Consent judgment: hiQ agrees to pay LinkedIn $500,000, ein permanent injunction bars any further collection, and hiQ is ordered to destroy the code, data, and algorithms built on it. hiQ no longer operates. |
The criminal terrain: CFAA
The contractual terrain: Terms of Service
What LinkedIn actually does
| Datum | Was ist passiert |
|---|---|
| Januar 2025 | LinkedIn files a federal suit against Nubela, the company behind Proxycurl, alleging hundreds of thousands of fake accounts were used to collect millions of LinkedIn profiles, resold through Proxycurl's API. Full detail in our Proxycurl shutdown breakdown. |
| 6 March 2025 | LinkedIn blocks platform access and removes the company pages of Apollo.io and Seamless.AI. Apollo's CEO states the company is "actively working with LinkedIn to understand the nature of our brand page restriction." |
| 4. Juli 2025 | Proxycurl shuts down after settling. Founder Steven Goh writes publicly that "there is no winning in fighting this." |
| 3 October 2025 | LinkedIn sues ProAPIs and its CEO, alleging an "industrial-scale fake account mill" reselling access for up to $15,000 a month per client. LinkedIn says it detected the operation "within hours." |
| 25 March 2026 | LinkedIn removes HeyReach's company page, then followed by roughly 16,400 people, and restricts the personal profiles of its CEO, CTO, CRO, and CMO, with no prior notice. |
And with Unipile, what do I risk
Audit your own product
If you get a letter, or your page disappears
Is LinkedIn scraping legal: your questions answered
The CFAA question, the Terms of Service question, detection, and what LinkedIn has actually enforced.
It depends which question is being asked. Case law such as hiQ Labs gegen LinkedIn establishes that accessing data any visitor can view without logging in generally does not violate the CFAA. That same case still ended in a $500,000 settlement and a permanent injunction under a separate breach-of-contract theory, and hiQ no longer exists. This page summarizes public case law and policy; it is not legal advice for your specific situation.
It depends on the jurisdiction, whether the data required logging in, and what contract governs the account collecting it. US case law treats publicly viewable data differently from data behind a login wall, and both are separate from a breach of LinkedIn's Terms of Service, its own track.
Not automatically, and not automatically legal either. US case law says collecting publicly visible data doesn't, by itself, violate the CFAA. It says nothing about LinkedIn's Terms of Service, which separately prohibit automated collection and which LinkedIn enforces through lawsuits, page removals, and account restrictions.
Yes. Section 8.2 of LinkedIn's User Agreement prohibits third-party software, crawlers, bots, and browser extensions that collect data or automate activity, regardless of whether that data is publicly visible. LinkedIn's Help Center page on prohibited software and extensions states that accounts using such tools risk being restricted or shut down without notice.
A US case in which the Ninth Circuit found, in April 2022, that collecting data visible without logging in likely doesn't violate the CFAA. It didn't end there: on 6 December 2022, a consent judgment ordered hiQ to pay LinkedIn $500,000, imposed a permanent injunction, and required it to destroy its code and data. hiQ no longer operates.
Each lawsuit covered here targets companies LinkedIn alleges built large-scale fake account networks to collect data at volume and resell it through an API. The suits against Nubela (Proxycurl, January 2025) and ProAPIs (October 2025) both make this allegation, on breach-of-contract grounds tied to LinkedIn's Terms of Service.
LinkedIn filed suit against Nubela, the company behind Proxycurl, in January 2025, alleging hundreds of thousands of fake accounts were created to collect millions of LinkedIn profiles for resale through Proxycurl's API. The case settled, and Proxycurl shut down on 4 July 2025.
Public reporting and LinkedIn's own policy point to a layered approach: unusual velocity, repeated identical patterns across sessions, browser and device fingerprinting, and identity checkpoints triggered when activity looks unusual. LinkedIn doesn't publish a specific threshold, and this page doesn't estimate one.
This is not legal advice for your situation, but documented cases show a pattern: don't respond in writing before a lawyer reviews it, confirm what's actually restricted (the product often keeps working while a page or personal profile is what's hit), and preserve the notice and timeline for counsel.
An API retrieving data on behalf of an authenticated member's own linked account, scoped to what that member can already see, is structurally different from the independent, bulk-collected indexes targeted in the cases here. That difference doesn't remove LinkedIn's Terms of Service from applying to the linked account.
No. It narrows one failure mode, a single shared index that can be targeted once and taken down for every customer at once, but it doesn't put any account outside LinkedIn's Terms of Service or make an integration immune to limits, restrictions, or review.
Nein. Unipile ist ein unabhängiger technischer Vermittler, der nicht mit LinkedIn verbunden, von LinkedIn unterstützt oder gesponsert wird. Es handelt im Auftrag jedes authentifizierten Benutzers innerhalb einer Sitzung, die diesem gehört, und nicht im Auftrag von LinkedIn. LinkedIn ist eine Marke der LinkedIn Corporation.
Haben Sie noch Fragen? Unser Team ist für Sie da.