linkedin.com
#01Privacy Audit — linkedin.com
TL;DR
Reject actually works
Clicking Reject stops all trackers — 0 tracking fires post-reject vs 6 post-accept. The consent mechanism meaningfully controls data collection.
Fingerprinting before consent
Five fingerprinting APIs (WebRTC, MediaDevices, WebGL, AudioContext) fire from LinkedIn's own CDN before any consent interaction — an ePrivacy Art. 5(3) concern.
11 cookies before you choose
Including bcookie (tracking, 1 year) and PerimeterX cookies — all set before the consent banner is even acknowledged.
Score breakdown
Consent
Legal Pages
Cross-Border
Dark Patterns
Security Headers
Cookie Management
Pre-Consent Tracking
Full audit deck
GDPR compliance
| Article | Status |
|---|---|
| ePrivacy Art. 5(3) | partial |
| Art. 6(1)(a) | partial |
| Art. 7(3) | fail |
| Art. 13 | pass |
| Art. 25 | partial |
| ePrivacy Art. 5(3) | fail |
Recommendations
Remove pre-consent fingerprinting
WebRTC, MediaDevices, WebGL and AudioContext APIs fire from static.licdn.com before consent. Under ePrivacy Art. 5(3), device fingerprinting requires consent.
ePrivacy Art. 5(3) · EDPB Guidelines 2023 on tracking
Gate bcookie behind consent
bcookie is classified as tracking and persists for 1 year, but is set before consent interaction. Move behind consent or reclassify as essential with justification.
ePrivacy Art. 5(3) · CNIL v. Amazon EUR 35M (Dec 2020)
Add consent revocation mechanism
No way to withdraw consent after accepting. GDPR Art. 7(3) requires withdrawal to be as easy as giving consent.
Art. 7(3) · EDPB Guidelines 05/2020
Add granular consent toggles
Current binary accept/reject doesn't allow per-category choices (analytics vs marketing). Granular control strengthens consent validity.
Art. 6(1)(a)
Add Referrer-Policy and Permissions-Policy headers
Missing 2 of 6 security headers. Referrer-Policy prevents URL leakage to third parties; Permissions-Policy restricts browser API access.
Art. 32
Implement Subresource Integrity for external scripts
0 of 7 external scripts have SRI hashes. Supply chain compromise of static.licdn.com would affect all visitors.
Art. 32