← Back to list

Linkedin Cornering Users To Submit Unique Identifier

Under GDPR or PDPA, organisations need to provide a way for withdrawal, however, for Linkedin, the only way for Withdrawal is to Login the…

Patrick Oh · 2022-07-22 11:08 · 0 claps · 2.2 min read
#linkedin-pdpa-violation #linkedin-privacy #linkedin #pdpa-violation #gdpr-violation
Open on Medium ↗
Wiki topics: 🔒 · Cybersecurity

Linkedin Cornering Users To Submit Unique Identifier

Under GDPR or PDPA, organisations need to provide a way for withdrawal, however, for Linkedin, the only way for Withdrawal is to Login the account then you can request for Withdrawal.

Many platforms also used similar approach, but these platforms like Facebook, Google, etc. will use the mobile phone or email as a means of authentication. However, for Linkedin, they required the submission of scanned copy of the Identity Card, Passport or Driving License, all these are important documents which once leaked out will have major consequences, thus Singapore’s PDPC has made it known that organisations are not supposed to collect unless truly needed.

Although Linkedin said after they have verify, they will dispose of the scanned copy submitted but how trustworthy is Linkedin?

Who in their right mind will simply trust an organisation word for granted?

We have seen many breaches occurred through IT personnel who have accessed to personal data, and taking this personal data to sell in the black market.

Identity Card, Passport or Driving License are important documents that can be duplicated once you have the scanned copy quite easily especially with today’s technology and counterfeit capability of these counterfeiters.

So the question here is WHY Linkedin did not follow the Best Practice used by most platforms?

Why are they increasing the RISK of Data subjects’ important Unique Identifier from been breached?

I have emailed Linkedin on this matter, but they choose to ignore all communication.

This is a plain violation to prevent the Withdrawal of Consent and the Right to Erasure of personal data.

The Risk Management of Linkedin is also questionable, because they did not conduct a Data Protection Impact Assessment (DPIA) on their system, especially with such a process they have introduced into their system.

Not sure how to get Linkedin aware of this matter, since they are ignoring email sent to them too.

Under the PDPA, the DPO contact information must be made available for the data subject to contact them when there is an issue to address. Linkedin did not seems to bother about this too.

Furthermore, Linkedin has bad track records of being hacked in the past, and yet they did not pay special attention to their Information Security and Privacy Management.

Linkedin is commonly use for work related or business, and under the PDPA, Business Contact Information (BCI) is exempted from the PDPA, thus all the more Linkedin should not be collected important scanned copy of Unique Identifier like the NRIC, Passport or Driving License because there are spider software that can spider out data from other websites.

Looks like quite a number of platforms selling even Private Linkedin personal data….Did Linkedin sell them the API?

https://brightdata.com/products/datasets/linkedin http://datanyze.com/

Microsoft owns Linkedin, and it seems they release the Linkedin API to approved developers.

https://docs.microsoft.com/en-us/linkedin/shared/integrations/people/profile-api?view=li-lms-2022-07


메타데이터
post_id
bfac3b34581
slug
linked-cornering-user-to-submit-unique-identifier-bfac3b34581
url
https://medium.com/@patrick-oh-sglion65/linked-cornering-user-to-submit-unique-identifier-bfac3b34581
canonical_url
https://medium.com/@patrick-oh-sglion65/linked-cornering-user-to-submit-unique-identifier-bfac3b34581
author_url
https://medium.com/@patrick-oh-sglion65
status
ok
fetched_at
2026-07-31 01:12:09