¿Es legal el rastreo de LinkedIn? Lo que muestran realmente los registros públicos
Qué se considera "scraping de LinkedIn"
La línea público/privada, por tipo de dato
| Tipo de datos | Visible sin iniciar sesión | Requiere una sesión iniciada | Requiere Sales Nav / Recruiter |
|---|---|---|---|
| Nombre, titular, foto | Por lo general | Siempre | No |
| Empresa y cargo actual | A menudo | Siempre | No |
| Historial laboral y académico completo | Rara vez, vista limitada | Todos los detalles | No |
| Conexiones y conexiones mutuas | No | Limitado, por grado | Ampliado, en red cruzada |
| Publicaciones, artículos, actividad | A menudo, si el público | Siempre | No |
| Información de contacto (correo electrónico/teléfono) | No | Solo si se comparte | Sin acceso adicional |
| Filtros de búsqueda avanzada, listas guardadas | No | Solo búsqueda básica | Conjunto completo de filtros |
Cinco métodos, ordenados por riesgo
| Método | Lo que puede alcanzar | Donde se rompe primero | Perfil de riesgo |
|---|---|---|---|
| Navegación manual | Todo lo que una persona puede leer y hacer clic, un perfil a la vez. | Your own time. It doesn't scale past casual research. | Mínimo |
| Browser extension | What's rendered on screen, inside one browser session, one account. | The extension itself: LinkedIn's own client-side detection and Google's Manifest V3 deprecation both target this layer, independently. | Elevated |
| No-code / SaaS automation tool | Whatever the vendor's shared infrastructure is built to reach, running against your linked account. | The vendor. If LinkedIn identifies the pattern once, every customer sharing that infrastructure is exposed at the same time. | Elevated |
| Custom code, independent index | Whatever your own infrastructure allows, collected outside any single member's session. | Nothing, technically, until it's caught. This is the exact structure every case below targeted. | Alta |
| API basada en cuentas | What one authenticated, linked member's own account can already see. | Nothing structurally new: it removes one failure mode, a shared index taken down for every customer at once, not Section 8.2 from the linked account itself. | Different, not zero |
¿Te pueden banear por esto?
The three legal layers, and how hiQ actually ended
| Fecha | ¿Qué pasó? |
|---|---|
| 2017 | hiQ Labs sues LinkedIn after LinkedIn sends a cease-and-desist letter and moves to block hiQ's access to public profile data. |
| April 2022 | The Ninth Circuit affirms that accessing publicly viewable LinkedIn profile data likely does not violate the CFAA. This is the ruling most "scraping is legal" articles stop at. |
| 1 August 2022 | The district court dissolves the preliminary injunction that had kept hiQ's access open, on separate grounds tied to LinkedIn's Terms of Service claim. |
| 6 December 2022 | Consent judgment: hiQ agrees to pay LinkedIn $500,000, a permanent injunction bars any further collection, and hiQ is ordered to destroy the code, data, and algorithms built on it. hiQ no longer operates. |
The criminal terrain: CFAA
The contractual terrain: Terms of Service
Lo que LinkedIn hace en realidad
| Fecha | ¿Qué pasó? |
|---|---|
| Enero de 2025 | LinkedIn files a federal suit against Nubela, the company behind Proxycurl, alleging hundreds of thousands of fake accounts were used to collect millions of LinkedIn profiles, resold through Proxycurl's API. Full detail in our Proxycurl shutdown breakdown. |
| 6 March 2025 | LinkedIn blocks platform access and removes the company pages of Apollo.io and Seamless.AI. Apollo's CEO states the company is "actively working with LinkedIn to understand the nature of our brand page restriction." |
| 4 de julio de 2025 | Proxycurl shuts down after settling. Founder Steven Goh writes publicly that "there is no winning in fighting this." |
| 3 October 2025 | LinkedIn sues ProAPIs and its CEO, alleging an "industrial-scale fake account mill" reselling access for up to $15,000 a month per client. LinkedIn says it detected the operation "within hours." |
| 25 March 2026 | LinkedIn removes HeyReach's company page, then followed by roughly 16,400 people, and restricts the personal profiles of its CEO, CTO, CRO, and CMO, with no prior notice. |
Y con Unipile, ¿qué riesgo corro?
Audita tu propio producto
If you get a letter, or your page disappears
Is LinkedIn scraping legal: your questions answered
The CFAA question, the Terms of Service question, detection, and what LinkedIn has actually enforced.
It depends which question is being asked. Case law such as hiQ Labs contra LinkedIn establishes that accessing data any visitor can view without logging in generally does not violate the CFAA. That same case still ended in a $500,000 settlement and a permanent injunction under a separate breach-of-contract theory, and hiQ no longer exists. This page summarizes public case law and policy; it is not legal advice for your specific situation.
It depends on the jurisdiction, whether the data required logging in, and what contract governs the account collecting it. US case law treats publicly viewable data differently from data behind a login wall, and both are separate from a breach of LinkedIn's Terms of Service, its own track.
Not automatically, and not automatically legal either. US case law says collecting publicly visible data doesn't, by itself, violate the CFAA. It says nothing about LinkedIn's Terms of Service, which separately prohibit automated collection and which LinkedIn enforces through lawsuits, page removals, and account restrictions.
Yes. Section 8.2 of LinkedIn's User Agreement prohibits third-party software, crawlers, bots, and browser extensions that collect data or automate activity, regardless of whether that data is publicly visible. LinkedIn's Help Center page on prohibited software and extensions states that accounts using such tools risk being restricted or shut down without notice.
A US case in which the Ninth Circuit found, in April 2022, that collecting data visible without logging in likely doesn't violate the CFAA. It didn't end there: on 6 December 2022, a consent judgment ordered hiQ to pay LinkedIn $500,000, imposed a permanent injunction, and required it to destroy its code and data. hiQ no longer operates.
Each lawsuit covered here targets companies LinkedIn alleges built large-scale fake account networks to collect data at volume and resell it through an API. The suits against Nubela (Proxycurl, January 2025) and ProAPIs (October 2025) both make this allegation, on breach-of-contract grounds tied to LinkedIn's Terms of Service.
LinkedIn demandó a Nubela, la empresa detrás de Proxycurl, en enero de 2025, alegando que se crearon cientos de miles de cuentas falsas para recopilar millones de perfiles de LinkedIn para su reventa a través de la API de Proxycurl. El caso llegó a un acuerdo y Proxycurl cerró el 4 de julio de 2025.
Public reporting and LinkedIn's own policy point to a layered approach: unusual velocity, repeated identical patterns across sessions, browser and device fingerprinting, and identity checkpoints triggered when activity looks unusual. LinkedIn doesn't publish a specific threshold, and this page doesn't estimate one.
This is not legal advice for your situation, but documented cases show a pattern: don't respond in writing before a lawyer reviews it, confirm what's actually restricted (the product often keeps working while a page or personal profile is what's hit), and preserve the notice and timeline for counsel.
An API retrieving data on behalf of an authenticated member's own linked account, scoped to what that member can already see, is structurally different from the independent, bulk-collected indexes targeted in the cases here. That difference doesn't remove LinkedIn's Terms of Service from applying to the linked account.
No. It narrows one failure mode, a single shared index that can be targeted once and taken down for every customer at once, but it doesn't put any account outside LinkedIn's Terms of Service or make an integration immune to limits, restrictions, or review.
No. Unipile es un intermediario técnico independiente, no afiliado, respaldado ni patrocinado por LinkedIn. Actúa en nombre de cada usuario autenticado dentro de una sesión que le pertenece, no en nombre de LinkedIn. LinkedIn es una marca comercial de LinkedIn Corporation.
¿Aún tiene preguntas? Nuestro equipo está aquí para ayudarle.