¿Es legal el rastreo de LinkedIn? Lo que muestran realmente los registros públicos

hiQ contra LinkedIn: acuerdo por $500.000, 6 de diciembre de 2022

¿Es legal el rastreo de LinkedIn? Lo que muestran realmente los registros públicos

Si buscas "¿es legal el scraping en LinkedIn?", la mayoría de las respuestas se limitan a una única sentencia de un tribunal de apelación de 2022. El mismo caso se cerró ocho meses después con un acuerdo de $500 000, una orden judicial permanente y el cierre definitivo de la empresa demandante. Esa diferencia entre el titular y el desenlace es, en gran medida, de lo que trata esta página.
La respuesta corta
Si el scraping de LinkedIn es legal no es una sola pregunta, sino tres: si infringe una ley federal de acceso a computadoras (la CFAA), si infringe las propias Condiciones de Servicio de LinkedIn, y si LinkedIn realmente lo penaliza. La jurisprudencia pública indica que acceder a datos que no requieren iniciar sesión generalmente no constituye, por sí solo, una violación de la CFAA. No dice nada sobre el contrato de LinkedIn, que es la vía que LinkedIn realmente aplica. Esta página resume lo que dicen los registros judiciales públicos y la propia política de LinkedIn. No constituye asesoramiento legal.
Construye sobre cuentas vinculadas, gratis para empezar
No es asesoramiento legal
Esta página resume lo que dicen los documentos judiciales públicos y la propia política publicada de LinkedIn, a fecha de la parte inferior de esta página. No es una recomendación sobre qué hacer en su situación específica, ni es una predicción de lo que decidiría un tribunal sobre su producto, datos o jurisdicción en particular. Lea las fuentes directamente y hable con un abogado calificado antes de tomar una decisión legal que dependa de los detalles aquí cubiertos.

Qué se considera "scraping de LinkedIn"

"El "scraping de LinkedIn" se utiliza para configuraciones muy diferentes: un script que lee páginas de perfiles renderizadas, una extensión de navegador que lee lo que ya está en pantalla, una herramienta sin código conectada a una cuenta, o un servicio que ya ha creado una base de datos de esta manera y ahora revende consultas sobre ella. Lo que comparten no es la herramienta, sino que la recolección ocurre fuera del uso que un miembro autenticado hace de su propia sesión, a un volumen y patrón que ningún ser humano produce navegando manualmente. Tratar a todas ellas como una sola pregunta de sí o no es lo que produce las respuestas genéricas y seguras que esta página intenta evitar. Las próximas dos secciones lo dividen: qué datos se encuentran detrás de qué muro, y qué método lo expone a usted a qué.

La línea público/privada, por tipo de dato

No todos los datos de LinkedIn están detrás del mismo muro, y el muro importa más que la herramienta utilizada para llegar a él. Algunos campos son visibles para cualquier persona con la URL. Otros requieren una sesión iniciada. Unos pocos requieren Sales Navigator o Recruiter, los propios productos de pago de LinkedIn. Esta es la línea que la mayoría de las guías pasan por alto:
Tipo de datosVisible sin iniciar sesiónRequiere una sesión iniciadaRequiere Sales Nav / Recruiter
Nombre, titular, fotoPor lo generalNo
Empresa y cargo actualA menudoNo
Historial laboral y académico completoRara vez, vista limitadaNo
Conexiones y conexiones mutuasNoAmpliado, en red cruzada
Publicaciones, artículos, actividadA menudo, si el públicoNo
Información de contacto (correo electrónico/teléfono)NoSin acceso adicional
Filtros de búsqueda avanzada, listas guardadasNoConjunto completo de filtros
Aquí es también donde se juzga mal la exposición: el hecho de que un campo sea públicamente visible no excluye su recopilación automatizada de la Sección 8.2 de las Condiciones de Servicio de LinkedIn. Esto afecta a la cuestión de la CFAA que se trata más adelante, no a la cuestión del contrato, que es la que LinkedIn realmente aplica.

Cinco métodos, ordenados por riesgo

Cómo recuperas los datos de LinkedIn cambia a lo que estás expuesto más que qué datos recuperas. Cinco métodos cubren casi cualquier configuración real. Ninguno está libre de riesgos, y esta tabla no recomienda una frecuencia o umbral, LinkedIn no publica ninguno y nosotros tampoco. Muestra dónde se sitúa estructuralmente cada método.
MétodoLo que puede alcanzarDonde se rompe primeroPerfil de riesgo
Navegación manualTodo lo que una persona puede leer y hacer clic, un perfil a la vez.Your own time. It doesn't scale past casual research.Mínimo
Browser extensionWhat's rendered on screen, inside one browser session, one account.The extension itself: LinkedIn's own client-side detection and Google's Manifest V3 deprecation both target this layer, independently.Elevated
No-code / SaaS automation toolWhatever the vendor's shared infrastructure is built to reach, running against your linked account.The vendor. If LinkedIn identifies the pattern once, every customer sharing that infrastructure is exposed at the same time.Elevated
Custom code, independent indexWhatever your own infrastructure allows, collected outside any single member's session.Nothing, technically, until it's caught. This is the exact structure every case below targeted.Alta
API basada en cuentasWhat one authenticated, linked member's own account can already see.Nothing structurally new: it removes one failure mode, a shared index taken down for every customer at once, not Section 8.2 from the linked account itself.Different, not zero
The last row is covered in detail in the guide to retrieving LinkedIn data through an API, and again further down under what changes with Unipile.

¿Te pueden banear por esto?

Every method above carries some exposure to LinkedIn restricting the account behind it. What triggers a review isn't published, and this page won't guess. But the enforcement actions further down, and independent reporting on LinkedIn's own detection systems, point to a consistent set of signals rather than a single tripwire.
VelocityA pace of profile views, connection requests, or messages that doesn't match how a person browses, holds, reads, and pauses.
Behavioral patternThe same sequence repeated identically across sessions, without the variation a human introduces.
Browser & device fingerprintAutomation frameworks and headless browsers leave signatures a normal session doesn't. LinkedIn's own client-side scanning for known extension and automation signatures has been independently documented.
Connection wallsIdentity checkpoints or re-verification prompts LinkedIn triggers when an account's activity looks unusual, whether or not that activity is automated.
None of this is a checklist for staying under a radar, we're not publishing one. LinkedIn doesn't publish thresholds, and a "safe" cadence would be a guess dressed up as a fact. What's documented is that detection is layered, and the consequence, when it lands, ranges from a restricted account to the page removals and lawsuits covered next.

The three legal layers, and how hiQ actually ended

"Is LinkedIn scraping legal" is really three questions. Is it a crime under the Computer Fraud and Abuse Act (CFAA), a US federal statute? Case law says accessing data any visitor can already see without logging in generally isn't, by itself, unauthorized access. Is it a breach of contract, of LinkedIn's Terms of Service? Yes, without ambiguity, Section 8.2 prohibits automated collection regardless of the CFAA question. Will it actually be enforced? That's the question with real consequences, answered in the next section.
The CFAA finding above comes from a single case, hiQ Labs v. LinkedIn, and the part most summaries leave out is how it ended.
Fecha¿Qué pasó?
2017hiQ Labs sues LinkedIn after LinkedIn sends a cease-and-desist letter and moves to block hiQ's access to public profile data.
April 2022The Ninth Circuit affirms that accessing publicly viewable LinkedIn profile data likely does not violate the CFAA. This is the ruling most "scraping is legal" articles stop at.
1 August 2022The district court dissolves the preliminary injunction that had kept hiQ's access open, on separate grounds tied to LinkedIn's Terms of Service claim.
6 December 2022Consent judgment: hiQ agrees to pay LinkedIn $500,000, a permanent injunction bars any further collection, and hiQ is ordered to destroy the code, data, and algorithms built on it. hiQ no longer operates.
The April 2022 line is what most "scraping is legal" headlines cite. The ending is what they skip: the same case closed eight months later with the plaintiff paying LinkedIn and shutting its product down, on the contract theory the CFAA ruling never touched. Full docket history: hiQ Labs v. LinkedIn on Wikipedia, la fallo de apelación de abril de 2022, and the December 2022 consent judgment coverage.

The criminal terrain: CFAA

The Ninth Circuit held that accessing publicly viewable pages, without logging in, isn't unauthorized access under the CFAA.
That answers a federal computer-access statute question. It says nothing about LinkedIn's own contract.

The contractual terrain: Terms of Service

Section 8.2 of LinkedIn's User Agreement prohibits automated collection, regardless of whether the data was public.
This is the terrain LinkedIn actually enforces on: account restriction, page removal, or a lawsuit.
hiQ won the first, lost the second. The second is what ended the company, and it's the terrain nearly every case in the next section runs on.

Lo que LinkedIn hace en realidad

Whatever the legal analysis says on paper, the risk that shapes a product decision is what LinkedIn has actually done. Five actions across roughly two years, including two lawsuits, show a pattern rather than an isolated exception.
Fecha¿Qué pasó?
Enero de 2025LinkedIn files a federal suit against Nubela, the company behind Proxycurl, alleging hundreds of thousands of fake accounts were used to collect millions of LinkedIn profiles, resold through Proxycurl's API. Full detail in our Proxycurl shutdown breakdown.
6 March 2025LinkedIn blocks platform access and removes the company pages of Apollo.io and Seamless.AI. Apollo's CEO states the company is "actively working with LinkedIn to understand the nature of our brand page restriction."
4 de julio de 2025Proxycurl shuts down after settling. Founder Steven Goh writes publicly that "there is no winning in fighting this."
3 October 2025LinkedIn sues ProAPIs and its CEO, alleging an "industrial-scale fake account mill" reselling access for up to $15,000 a month per client. LinkedIn says it detected the operation "within hours."
25 March 2026LinkedIn removes HeyReach's company page, then followed by roughly 16,400 people, and restricts the personal profiles of its CEO, CTO, CRO, and CMO, with no prior notice.
Not every automated tool touching LinkedIn data gets sued. But the pattern runs on the contract terrain above, not the CFAA. LinkedIn's own Help Center page on prohibited software and extensions states that accounts using unauthorized tools "risk having their accounts restricted or shut down" without notice. The lawsuits above are the visible end of that policy; account and page restrictions are how it plays out for everyone else.

Y con Unipile, ¿qué riesgo corro?

The account-based row above is the model Unipile runs on: each request executes on behalf of one authenticated, linked account, scoped to what that member can already see. What that changes, and what it doesn't:
Nota de Manejo de DatosNo independent index behind the API
Recuperación en directo, en nombre del usuario autenticado: profile and message data moves through the linked account's own session, scoped to what that member already sees.
Sin archivo paralelo: Unipile doesn't build or resell a database of LinkedIn profiles. What moves through the API reaches your product, not a separate archive.
Cómo opera UnipileSin credenciales compartidas, sin elevación de privilegios
Intermediario técnico independiente: Unipile actúa en nombre de cada usuario autenticado, dentro de una sesión que le pertenece, no como un revendedor de datos y no en nombre de LinkedIn.
No afiliado con, respaldado por o patrocinado por LinkedIn. Each linked account is isolated; no credentials are shared across your customers.
Límites de la plataforma y uso responsableUnipile relays LinkedIn's own limits, it does not lift them
Los límites se retransmiten, no se eliminan: retrieval and messaging stay inside the same limits a member would hit inside LinkedIn's own interface.
Cadence stays a customer-side decision: the API executes what your product and your users decide to send, on a per-user basis. It doesn't set a pace on their behalf.
None of this removes exposure, it changes its scope. LinkedIn's Terms of Service still apply to every linked account exactly as if that member used LinkedIn directly. This narrows one failure mode, a single shared index taken down for every customer at once. It does not put any customer outside those terms, and this page isn't a substitute for reading them.
Una integración, un esquema, en LinkedIn, WhatsApp, Instagram, Telegram, correo electrónico y calendarios. Hosted authentication and retrieval on behalf of each linked account, instead of an index built outside it.
Empezar a construir

Audita tu propio producto

This isn't a legal test, only a lawyer reviewing your setup can give you that. It's the checklist we can actually publish: five questions mapping roughly to the difference between structures enforcement has targeted, and the ones it hasn't, so far.
01
CuentasDoes every LinkedIn account your product touches belong to a real member who authenticated it themselves, or does your product create accounts that don't belong to anyone?
02
IndexDoes data stay scoped to what one authenticated member's session can see, or does your product build and retain an index that exists independent of any single member's access?
03
AttributionFor any given action your product takes on LinkedIn, can you point to the one authenticated user who triggered it, or could you not say?
04
LímitesDoes your product relay LinkedIn's own connection, search, and messaging limits to the end user, or does it try to push past them on the user's behalf?
05
Base legalDo you have a documented legal basis for processing this data, and, if you or your users are in the EU, a DPA in place with whichever provider sits underneath?

If you get a letter, or your page disappears

None of the cases on this page involved a warning. Apollo and Seamless lost their company pages, with a note from LinkedIn after the fact. HeyReach's team wrote about its own removal:
"No notice, no communication. We just couldn't get in anymore."
A handful of documented patterns, not legal advice, on what companies in this spot have actually done:
1
Don't respond in writing before counsel reviews itThe clearest public account of a cease-and-desist response, an HN thread from a Chrome extension developer, converges on one point: what you say before a lawyer reviews it can matter more than what you did.
2
Check what's actually restrictedIn the documented cases, the product kept working, HeyReach's customer accounts and campaigns continued, Apollo's product stayed operational, while the company page or founders' personal profiles were what got hit.
3
Preserve the notice and the timelineWhat changed, when, and what the notice actually said, not a summary of it, is what counsel will ask for first.
4
Revisit the architecture, not just the letterIf more than one answer in the self-check above points the wrong way, the letter is a symptom, not the problem.

Is LinkedIn scraping legal: your questions answered

The CFAA question, the Terms of Service question, detection, and what LinkedIn has actually enforced.

It depends which question is being asked. Case law such as hiQ Labs contra LinkedIn establishes that accessing data any visitor can view without logging in generally does not violate the CFAA. That same case still ended in a $500,000 settlement and a permanent injunction under a separate breach-of-contract theory, and hiQ no longer exists. This page summarizes public case law and policy; it is not legal advice for your specific situation.

It depends on the jurisdiction, whether the data required logging in, and what contract governs the account collecting it. US case law treats publicly viewable data differently from data behind a login wall, and both are separate from a breach of LinkedIn's Terms of Service, its own track.

Not automatically, and not automatically legal either. US case law says collecting publicly visible data doesn't, by itself, violate the CFAA. It says nothing about LinkedIn's Terms of Service, which separately prohibit automated collection and which LinkedIn enforces through lawsuits, page removals, and account restrictions.

Yes. Section 8.2 of LinkedIn's User Agreement prohibits third-party software, crawlers, bots, and browser extensions that collect data or automate activity, regardless of whether that data is publicly visible. LinkedIn's Help Center page on prohibited software and extensions states that accounts using such tools risk being restricted or shut down without notice.

A US case in which the Ninth Circuit found, in April 2022, that collecting data visible without logging in likely doesn't violate the CFAA. It didn't end there: on 6 December 2022, a consent judgment ordered hiQ to pay LinkedIn $500,000, imposed a permanent injunction, and required it to destroy its code and data. hiQ no longer operates.

Each lawsuit covered here targets companies LinkedIn alleges built large-scale fake account networks to collect data at volume and resell it through an API. The suits against Nubela (Proxycurl, January 2025) and ProAPIs (October 2025) both make this allegation, on breach-of-contract grounds tied to LinkedIn's Terms of Service.

LinkedIn demandó a Nubela, la empresa detrás de Proxycurl, en enero de 2025, alegando que se crearon cientos de miles de cuentas falsas para recopilar millones de perfiles de LinkedIn para su reventa a través de la API de Proxycurl. El caso llegó a un acuerdo y Proxycurl cerró el 4 de julio de 2025.

Public reporting and LinkedIn's own policy point to a layered approach: unusual velocity, repeated identical patterns across sessions, browser and device fingerprinting, and identity checkpoints triggered when activity looks unusual. LinkedIn doesn't publish a specific threshold, and this page doesn't estimate one.

This is not legal advice for your situation, but documented cases show a pattern: don't respond in writing before a lawyer reviews it, confirm what's actually restricted (the product often keeps working while a page or personal profile is what's hit), and preserve the notice and timeline for counsel.

An API retrieving data on behalf of an authenticated member's own linked account, scoped to what that member can already see, is structurally different from the independent, bulk-collected indexes targeted in the cases here. That difference doesn't remove LinkedIn's Terms of Service from applying to the linked account.

No. It narrows one failure mode, a single shared index that can be targeted once and taken down for every customer at once, but it doesn't put any account outside LinkedIn's Terms of Service or make an integration immune to limits, restrictions, or review.

No. Unipile es un intermediario técnico independiente, no afiliado, respaldado ni patrocinado por LinkedIn. Actúa en nombre de cada usuario autenticado dentro de una sesión que le pertenece, no en nombre de LinkedIn. LinkedIn es una marca comercial de LinkedIn Corporation.

¿Aún tiene preguntas? Nuestro equipo está aquí para ayudarle.

Hable con un experto
Build a LinkedIn data layer scoped to each linked account
Autenticación alojada, recuperación en nombre de cada cuenta vinculada y un único esquema para LinkedIn, WhatsApp, Instagram, Telegram, el correo electrónico y los calendarios. No se necesita tarjeta de crédito para empezar.
Crea tu primera integración

Fuentes

12 references, September 2026
Every date and figure here traces to the source below. Cases settle and policies update without notice, so treat this as a snapshot, not a permanent status, and not legal advice.
Ayuda de LinkedInSoftware y extensiones prohibidos, the official policy referenced throughout.
Acuerdo de usuario de LinkedInApartado 8.2, el base contractual en relación con las medidas coercitivas de LinkedIn.
hiQ Labs contra LinkedInHistorial clínico a través de Wikipedia.
Noveno CircuitoEn fallo de apelación de abril de 2022 on the CFAA question.
Privacy WorldCoverage of the sentencia de conformidad de diciembre de 2022 that ended hiQ's case.
NubelaEl del fundador Proxycurl shutdown announcement, 4 July 2025.
El registroLinkedIn contra ProAPIs, presentado el 3 de octubre de 2025.
HeyReachHeyReach's own account of its 25 March 2026 company page removal.
Hacker NewsEn Browserflow cease-and-desist thread, 30 January 2023.
BleepingComputerReporting on LinkedIn's client-side extension scanning, April 2026.
Documentación para desarrolladores de UnipileCompleto Referencia de la API y guía de inicio para la integración con LinkedIn.
Last updated September 2026. This page is not legal advice; it summarizes public court records and platform policy as of the date above, and you should consult a qualified attorney for guidance specific to your situation. Unipile is an independent technical intermediary and is not affiliated with, endorsed by, or sponsored by LinkedIn. Volume, cadence, and content of any action taken through the API remain a customer-side decision, consistent with LinkedIn's Terms of Service and applicable data protection regulations (GDPR).
es_ESES