Is LinkedIn Scrapen Legaal? Wat het Publieke Register Daadwerkelijk Aantoont

hiQ tegen LinkedIn: schikking van $500.000, 6 december 2022

Is LinkedIn Scrapen Legaal? Wat het Publieke Register Daadwerkelijk Aantoont

Zoek eens op "is scraping op LinkedIn legaal" en de meeste antwoorden beperken zich tot één uitspraak van het hof van beroep uit 2022. Dezelfde zaak werd acht maanden later afgesloten met een schikking van $500.000, een permanent verbod en de definitieve sluiting van het bedrijf van de eiser. Die kloof tussen de kop en de afloop is waar deze pagina grotendeels over gaat.
Het korte antwoord
Of LinkedIn-scraping al dan niet legaal is, is niet één vraag, maar drie: of het een federale wet inzake computertoegang overtreedt (de CFAA), of het de eigen algemene voorwaarden van LinkedIn schendt, en of LinkedIn er daadwerkelijk tegen optreedt. Uit openbare jurisprudentie blijkt dat het benaderen van gegevens waarvoor geen inloggen vereist is, over het algemeen op zichzelf geen schending van de CFAA is. Er wordt niets gezegd over het contract van LinkedIn, het spoor waarop LinkedIn daadwerkelijk handhaaft. Deze pagina vat samen wat openbare rechtbankverslagen en het eigen beleid van LinkedIn zeggen. Dit is geen juridisch advies.
Voortbouwen op gekoppelde accounts, gratis te beginnen
Geen juridisch advies
Deze pagina vat samen wat openbare rechtbankdossiers en het eigen gepubliceerde beleid van LinkedIn aangeven, per de datum onderaan deze pagina. Dit is geen aanbeveling over wat u moet doen in uw specifieke situatie, en het is geen voorspelling van wat een rechtbank zou beslissen over uw specifieke product, data of jurisdictie. Lees de bronnen direct en raadpleeg een gekwalificeerde advocaat voordat u een juridische beslissing neemt die afhangt van de details die hier worden behandeld.

Wat telt als "LinkedIn scraping"?"

"LinkedIn scraping" wordt gebruikt voor zeer uiteenlopende opstellingen: een script dat gerenderde profielpagina's uitleest, een browserextensie die leest wat er al op het scherm staat, een no-code tool die is ingelogd op een account, of een service die op deze manier al een database heeft opgebouwd en nu opzoekingen daarin doorverkoopt. Wat ze gemeen hebben is niet het tool, maar het feit dat het verzamelen plaatsvindt buiten het eigen gebruik van een geverifieerd lid van diens eigen sessie, in een volume en patroon dat geen enkel mens produceert die handmatig bladert. Het behandelen van al deze methoden als één ja-nee-vraag is wat de zelfverzekerde, generieke antwoorden oplevert die deze pagina probeert te vermijden. De volgende twee secties splitsen het op: welke data achter welke muur zit, en welke methode je aan wat blootstelt.

De grens tussen openbaar en privaat, per datatype

Niet alle LinkedIn-gegevens bevinden zich achter dezelfde muur, en die muur is belangrijker dan het hulpmiddel dat wordt gebruikt om hem te bereiken. Sommige velden zijn zichtbaar voor iedereen met de URL. Andere vereisen een ingelogde sessie. Een handjevol vereist Sales Navigator of Recruiter, LinkedIn's eigen betaalde producten. Dit is de grens waar de meeste handleidingen aan voorbijgaan:
GegevenstypeZichtbaar zonder inloggenVereist een ingelogde sessieVereist Sales Nav / Recruiter
Naam, koptekst, fotoMeestalGeen
Huidig bedrijf & functieVaakGeen
Volledige werk- en opleidingsgeschiedenisZelden, beperkte weergaveGeen
Connecties & wederzijdse connectiesGeenUitgebreid, netoverschrijdend
Berichten, artikelen, activiteitVaak, als het publiekGeen
Contactgegevens (e-mail/telefoon)GeenGeen extra toegang
Geavanceerde zoekfilters, opgeslagen lijstenGeenVolledige filterset
Dit is ook waar blootstelling verkeerd wordt ingeschat: het openbaar zichtbaar zijn van een veld zorgt er niet voor dat geautomatiseerde verzameling daarvan buiten Sectie 8.2 van LinkedIn's Algemene Voorwaarden valt. Het is van invloed op de CFAA-kwestie die verderop wordt behandeld, niet op de contractkwestie, wat degene is die LinkedIn daadwerkelijk handhaaft.

Vijf methoden, gerangschikt naar risico

Hoe je LinkedIn-gegevens ophaalt, bepaalt meer waar je aan wordt blootgesteld dan welke gegevens je ophaalt. Vijf methoden dekken bijna elke echte opstelling. Geen enkele is risicovrij en deze tabel raadt geen frequentie of drempelwaarde aan, LinkedIn publiceert er geen en wij ook niet. Het laat zien hoe elke methode structureel in elkaar zit.
MethodeWat het kan bereikenWaar het het eerst breektRisicoprofiel
Handmatig bladerenAlles wat een persoon kan lezen en aanklikken, één profiel tegelijk.Your own time. It doesn't scale past casual research.Minimaal
Browser extensionWhat's rendered on screen, inside one browser session, one account.The extension itself: LinkedIn's own client-side detection and Google's Manifest V3 deprecation both target this layer, independently.Elevated
No-code / SaaS automation toolWhatever the vendor's shared infrastructure is built to reach, running against your linked account.The vendor. If LinkedIn identifies the pattern once, every customer sharing that infrastructure is exposed at the same time.Elevated
Custom code, independent indexWhatever your own infrastructure allows, collected outside any single member's session.Nothing, technically, until it's caught. This is the exact structure every case below targeted.Hoog
Account-gebaseerde APIWhat one authenticated, linked member's own account can already see.Nothing structurally new: it removes one failure mode, a shared index taken down for every customer at once, not Section 8.2 from the linked account itself.Different, not zero
The last row is covered in detail in the guide to retrieving LinkedIn data through an API, and again further down under what changes with Unipile.

Kun je hiervoor een ban krijgen?

Every method above carries some exposure to LinkedIn restricting the account behind it. What triggers a review isn't published, and this page won't guess. But the enforcement actions further down, and independent reporting on LinkedIn's own detection systems, point to a consistent set of signals rather than a single tripwire.
VelocityA pace of profile views, connection requests, or messages that doesn't match how a person browses, holds, reads, and pauses.
Behavioral patternThe same sequence repeated identically across sessions, without the variation a human introduces.
Browser & device fingerprintAutomation frameworks and headless browsers leave signatures a normal session doesn't. LinkedIn's own client-side scanning for known extension and automation signatures has been independently documented.
Connection wallsIdentity checkpoints or re-verification prompts LinkedIn triggers when an account's activity looks unusual, whether or not that activity is automated.
None of this is a checklist for staying under a radar, we're not publishing one. LinkedIn doesn't publish thresholds, and a "safe" cadence would be a guess dressed up as a fact. What's documented is that detection is layered, and the consequence, when it lands, ranges from a restricted account to the page removals and lawsuits covered next.

The three legal layers, and how hiQ actually ended

"Is LinkedIn scraping legal" is really three questions. Is it a crime under the Computer Fraud and Abuse Act (CFAA), a US federal statute? Case law says accessing data any visitor can already see without logging in generally isn't, by itself, unauthorized access. Is it a breach of contract, of LinkedIn's Terms of Service? Yes, without ambiguity, Section 8.2 prohibits automated collection regardless of the CFAA question. Will it actually be enforced? That's the question with real consequences, answered in the next section.
The CFAA finding above comes from a single case, hiQ Labs v. LinkedIn, and the part most summaries leave out is how it ended.
DatumWat is er gebeurd
2017hiQ Labs sues LinkedIn after LinkedIn sends a cease-and-desist letter and moves to block hiQ's access to public profile data.
April 2022The Ninth Circuit affirms that accessing publicly viewable LinkedIn profile data likely does not violate the CFAA. This is the ruling most "scraping is legal" articles stop at.
1 August 2022The district court dissolves the preliminary injunction that had kept hiQ's access open, on separate grounds tied to LinkedIn's Terms of Service claim.
6 December 2022Consent judgment: hiQ agrees to pay LinkedIn $500,000, een permanent injunction bars any further collection, and hiQ is ordered to destroy the code, data, and algorithms built on it. hiQ no longer operates.
The April 2022 line is what most "scraping is legal" headlines cite. The ending is what they skip: the same case closed eight months later with the plaintiff paying LinkedIn and shutting its product down, on the contract theory the CFAA ruling never touched. Full docket history: hiQ Labs v. LinkedIn on Wikipedia, de uitspraak in hoger beroep van april 2022, and the December 2022 consent judgment coverage.

The criminal terrain: CFAA

The Ninth Circuit held that accessing publicly viewable pages, without logging in, isn't unauthorized access under the CFAA.
That answers a federal computer-access statute question. It says nothing about LinkedIn's own contract.

The contractual terrain: Terms of Service

Section 8.2 of LinkedIn's User Agreement prohibits automated collection, regardless of whether the data was public.
This is the terrain LinkedIn actually enforces on: account restriction, page removal, or a lawsuit.
hiQ won the first, lost the second. The second is what ended the company, and it's the terrain nearly every case in the next section runs on.

Wat LinkedIn daadwerkelijk doet

Whatever the legal analysis says on paper, the risk that shapes a product decision is what LinkedIn has actually done. Five actions across roughly two years, including two lawsuits, show a pattern rather than an isolated exception.
DatumWat is er gebeurd
Januari 2025LinkedIn files a federal suit against Nubela, the company behind Proxycurl, alleging hundreds of thousands of fake accounts were used to collect millions of LinkedIn profiles, resold through Proxycurl's API. Full detail in our Proxycurl shutdown breakdown.
6 March 2025LinkedIn blocks platform access and removes the company pages of Apollo.io and Seamless.AI. Apollo's CEO states the company is "actively working with LinkedIn to understand the nature of our brand page restriction."
4 juli 2025Proxycurl shuts down after settling. Founder Steven Goh writes publicly that "there is no winning in fighting this."
3 October 2025LinkedIn sues ProAPIs and its CEO, alleging an "industrial-scale fake account mill" reselling access for up to $15,000 a month per client. LinkedIn says it detected the operation "within hours."
25 March 2026LinkedIn removes HeyReach's company page, then followed by roughly 16,400 people, and restricts the personal profiles of its CEO, CTO, CRO, and CMO, with no prior notice.
Not every automated tool touching LinkedIn data gets sued. But the pattern runs on the contract terrain above, not the CFAA. LinkedIn's own Help Center page on prohibited software and extensions states that accounts using unauthorized tools "risk having their accounts restricted or shut down" without notice. The lawsuits above are the visible end of that policy; account and page restrictions are how it plays out for everyone else.

En wat riskeer ik met Unipile?

The account-based row above is the model Unipile runs on: each request executes on behalf of one authenticated, linked account, scoped to what that member can already see. What that changes, and what it doesn't:
Gegevensverwerking OpmerkingNo independent index behind the API
Live ophalen, namens de geauthenticeerde gebruiker: profile and message data moves through the linked account's own session, scoped to what that member already sees.
Geen parallel archief: Unipile doesn't build or resell a database of LinkedIn profiles. What moves through the API reaches your product, not a separate archive.
Hoe Unipile WerktGeen gedeelde inloggegevens, geen verhoging van bevoegdheden
Onafhankelijke technische tussenpersoon: Unipile handelt namens elke geauthenticeerde gebruiker, binnen een sessie die van hen is, niet als gegevensdoorverkoper en niet namens LinkedIn.
Niet gelieerd aan, onderschreven door of gesponsord door LinkedIn. Each linked account is isolated; no credentials are shared across your customers.
Platformlimieten en verantwoord gebruikUnipile relays LinkedIn's own limits, it does not lift them
Limieten worden verplaatst, niet weggenomen: retrieval and messaging stay inside the same limits a member would hit inside LinkedIn's own interface.
Cadence stays a customer-side decision: the API executes what your product and your users decide to send, on a per-user basis. It doesn't set a pace on their behalf.
None of this removes exposure, it changes its scope. LinkedIn's Terms of Service still apply to every linked account exactly as if that member used LinkedIn directly. This narrows one failure mode, a single shared index taken down for every customer at once. It does not put any customer outside those terms, and this page isn't a substitute for reading them.
Eén integratie, één schema, via LinkedIn, WhatsApp, Instagram, Telegram, e-mail en agenda's. Hosted authentication and retrieval on behalf of each linked account, instead of an index built outside it.
Beginnen met bouwen

Doorlicht je eigen product

This isn't a legal test, only a lawyer reviewing your setup can give you that. It's the checklist we can actually publish: five questions mapping roughly to the difference between structures enforcement has targeted, and the ones it hasn't, so far.
01
RekeningenDoes every LinkedIn account your product touches belong to a real member who authenticated it themselves, or does your product create accounts that don't belong to anyone?
02
IndexDoes data stay scoped to what one authenticated member's session can see, or does your product build and retain an index that exists independent of any single member's access?
03
AttributionFor any given action your product takes on LinkedIn, can you point to the one authenticated user who triggered it, or could you not say?
04
LimietenDoes your product relay LinkedIn's own connection, search, and messaging limits to the end user, or does it try to push past them on the user's behalf?
05
Juridische grondslagDo you have a documented legal basis for processing this data, and, if you or your users are in the EU, a DPA in place with whichever provider sits underneath?

If you get a letter, or your page disappears

None of the cases on this page involved a warning. Apollo and Seamless lost their company pages, with a note from LinkedIn after the fact. HeyReach's team wrote about its own removal:
"No notice, no communication. We just couldn't get in anymore."
A handful of documented patterns, not legal advice, on what companies in this spot have actually done:
1
Don't respond in writing before counsel reviews itThe clearest public account of a cease-and-desist response, an HN thread from a Chrome extension developer, converges on one point: what you say before a lawyer reviews it can matter more than what you did.
2
Check what's actually restrictedIn the documented cases, the product kept working, HeyReach's customer accounts and campaigns continued, Apollo's product stayed operational, while the company page or founders' personal profiles were what got hit.
3
Preserve the notice and the timelineWhat changed, when, and what the notice actually said, not a summary of it, is what counsel will ask for first.
4
Revisit the architecture, not just the letterIf more than one answer in the self-check above points the wrong way, the letter is a symptom, not the problem.

Is LinkedIn scraping legal: your questions answered

The CFAA question, the Terms of Service question, detection, and what LinkedIn has actually enforced.

It depends which question is being asked. Case law such as hiQ Labs v. LinkedIn establishes that accessing data any visitor can view without logging in generally does not violate the CFAA. That same case still ended in a $500,000 settlement and a permanent injunction under a separate breach-of-contract theory, and hiQ no longer exists. This page summarizes public case law and policy; it is not legal advice for your specific situation.

It depends on the jurisdiction, whether the data required logging in, and what contract governs the account collecting it. US case law treats publicly viewable data differently from data behind a login wall, and both are separate from a breach of LinkedIn's Terms of Service, its own track.

Not automatically, and not automatically legal either. US case law says collecting publicly visible data doesn't, by itself, violate the CFAA. It says nothing about LinkedIn's Terms of Service, which separately prohibit automated collection and which LinkedIn enforces through lawsuits, page removals, and account restrictions.

Yes. Section 8.2 of LinkedIn's User Agreement prohibits third-party software, crawlers, bots, and browser extensions that collect data or automate activity, regardless of whether that data is publicly visible. LinkedIn's Help Center page on prohibited software and extensions states that accounts using such tools risk being restricted or shut down without notice.

A US case in which the Ninth Circuit found, in April 2022, that collecting data visible without logging in likely doesn't violate the CFAA. It didn't end there: on 6 December 2022, a consent judgment ordered hiQ to pay LinkedIn $500,000, imposed a permanent injunction, and required it to destroy its code and data. hiQ no longer operates.

Each lawsuit covered here targets companies LinkedIn alleges built large-scale fake account networks to collect data at volume and resell it through an API. The suits against Nubela (Proxycurl, January 2025) and ProAPIs (October 2025) both make this allegation, on breach-of-contract grounds tied to LinkedIn's Terms of Service.

LinkedIn heeft in januari 2025 een rechtszaak aangespannen tegen Nubela, het bedrijf achter Proxycurl, met de bewering dat honderdduizenden nepprofielen waren aangemaakt om miljoenen LinkedIn-profielen te verzamelen voor doorverkoop via de API van Proxycurl. De zaak werd geschikt en Proxycurl werd op 4 juli 2025 gesloten.

Public reporting and LinkedIn's own policy point to a layered approach: unusual velocity, repeated identical patterns across sessions, browser and device fingerprinting, and identity checkpoints triggered when activity looks unusual. LinkedIn doesn't publish a specific threshold, and this page doesn't estimate one.

This is not legal advice for your situation, but documented cases show a pattern: don't respond in writing before a lawyer reviews it, confirm what's actually restricted (the product often keeps working while a page or personal profile is what's hit), and preserve the notice and timeline for counsel.

An API retrieving data on behalf of an authenticated member's own linked account, scoped to what that member can already see, is structurally different from the independent, bulk-collected indexes targeted in the cases here. That difference doesn't remove LinkedIn's Terms of Service from applying to the linked account.

No. It narrows one failure mode, a single shared index that can be targeted once and taken down for every customer at once, but it doesn't put any account outside LinkedIn's Terms of Service or make an integration immune to limits, restrictions, or review.

Nee. Unipile is een onafhankelijke technische tussenpersoon, niet gelieerd aan, onderschreven door of gesponsord door LinkedIn. Het handelt namens elke geauthenticeerde gebruiker binnen een sessie die van hen is, niet namens LinkedIn. LinkedIn is een handelsmerk van LinkedIn Corporation.

Heb je nog vragen? Ons team staat klaar om te helpen.

Praat met een expert
Build a LinkedIn data layer scoped to each linked account
Gehoste authenticatie, ophalen namens elk gekoppeld account en één schema over LinkedIn, WhatsApp, Instagram, Telegram, e-mail en agenda's. Geen creditcard vereist om te beginnen.
Bouw je eerste integratie

Bronnen

12 references, September 2026
Every date and figure here traces to the source below. Cases settle and policies update without notice, so treat this as a snapshot, not a permanent status, and not legal advice.
LinkedIn-helpVerboden software en extensies, the official policy referenced throughout.
LinkedIn-gebruikersovereenkomstSectie 8.2, de contractuele basis voor de handhavingsmaatregelen van LinkedIn.
hiQ Labs v. LinkedInAnamnese via Wikipedia.
Negende circuitDe uitspraak in hoger beroep van april 2022 on the CFAA question.
Privacy WorldCoverage of the schikking bij vonnis van december 2022 that ended hiQ's case.
NubelaDe oprichter zelf Proxycurl shutdown announcement, 4 July 2025.
Het RecordLinkedIn t.o.v. ProAPIs, ingediend op 3 oktober 2025.
HeyReachHeyReach's own account of its 25 March 2026 company page removal.
Hacker NewsDe Browserflow cease-and-desist thread, 30 January 2023.
BleepingComputerReporting on LinkedIn's client-side extension scanning, April 2026.
Documenten voor ontwikkelaars van UnipileVol API-referentie en aan de slag-gids voor de LinkedIn-integratie.
Last updated September 2026. This page is not legal advice; it summarizes public court records and platform policy as of the date above, and you should consult a qualified attorney for guidance specific to your situation. Unipile is an independent technical intermediary and is not affiliated with, endorsed by, or sponsored by LinkedIn. Volume, cadence, and content of any action taken through the API remain a customer-side decision, consistent with LinkedIn's Terms of Service and applicable data protection regulations (GDPR).
nl_NLNL