Institute of Political Science

CIRP LinkedIn Data Protection Evaluation

According to the general rule of Article 35, Paragraph 1 of the European General Data Protection Regulation (GDPR), a data protection impact assessment must be carried out if a form of processing, in particular when using new technologies, is likely to result in a high risk to the rights and freedoms of natural persons due to the nature, scope, circumstances and purposes of the processing. The LfDI guideline on the use of social networks by public bodies makes it mandatory to assess the consequences of the intended processing operations for the protection of personal data in anticipation of and in line with the GDPR, which has been applicable since May 25, 2018.

The LinkedIn offering of the Centre for International Relations/Peace and Conflict Research (CIRP) itself does not trigger this consequence due to the very limited scope of its own data processing (see the privacy policy in this regard), in particular in view of the fact that its contributions mainly involve the sending of content without any personal reference, and when referring to other LinkedIn users, only the data that they have provided themselves and voluntarily is processed (since LinkedIn is a career network, information about the employer and position can often be found in addition to the user name and contributions).

However, from the CIRP's point of view, the use of LinkedIn in itself represents a high-risk processing operation due to its far-reaching effects, in particular with regard to the evaluation of the data by LinkedIn for advertising purposes etc., for which a data protection impact assessment (by LinkedIn) must be carried out.

Because by using a LinkedIn account, the respective user places himself under systematic observation by LinkedIn. This can also reveal sensitive data such as political views, sexual orientation or health problems, which can be linked together and used to create a personality profile. Particularly vulnerable people such as young people can also be LinkedIn users and thus affected, although these are naturally not part of LinkedIn's target group, even if official registration is permitted from the age of 16 (see also "Risk Assessment").

Even if you simply read LinkedIn passively without your own account, sensitive data can be collected by collecting log data, such as the websites previously visited or the user's location data.

This is all the more true as LinkedIn cannot be checked or can only be checked to a limited extent. Since the data of German users is not processed within Germany but in non-European countries, there are higher hurdles to accessing (judicial) legal protection than with a company based in Germany. If data protection issues cannot be clarified directly with LinkedIn, the contact person is the Irish Data Protection Officer.

The CIRP therefore assumes that public bodies that use a social network for public relations and to provide general information share responsibility.

Shared responsibility does not mean that the CIRP confirms or guarantees the data protection compliance of LinkedIn products. It cannot do this under the given circumstances. Shared responsibility means that the CIRP makes itself and others aware of the risks of social networks. Social networks currently need to be improved in many areas from a data protection perspective.

Users are informed of the risks that generally accompany the use of social media in the CIRP's privacy policy for LinkedIn. This can be found on the CIRP website. LinkedIn itself does not currently offer this option on the LinkedIn company page.

The CIRP has committed itself to these measures in its usage concept. The advantages and disadvantages of using LinkedIn are then evaluated once a year, taking into account the terms of use of LinkedIn.com.

LinkedIn use is thus embedded in a package of measures. Against this background, the CIRP’s assessment of the consequences of LinkedIn usage is as follows:

1. Risk identification:
The risks described at the beginning that come with using LinkedIn exist in principle independently of the CIRP's own LinkedIn use. In the majority of cases, the CIRP's posts do not make any reference to personal data; instead, they disseminate their own, factual content.

After all, the data that is processed through interaction with the CIRP's LinkedIn account or other accounts - namely the posts and/or the account name of a LinkedIn user - is already public/generally accessible/freely available on the Internet.

However, by appearing on the CIRP's LinkedIn page and the interaction, they are made available to a broader/"more specific" public and may thus attract greater attention and be more widely distributed than without this interaction.

The fact that the CIRP follows other accounts or they follow it also creates additional cross-connections and information about the respective LinkedIn user; for example, B. Areas of interest can be determined from subscriber/follower status, regular contributions, activities and group memberships.

Finally, LinkedIn also collects log data when users passively read the page.

By using LinkedIn itself, the CIRP increases the amount of data that LinkedIn uses and evaluates.

2. Risk analysis:
By expanding the distribution circle and increasing the number of linking options, LinkedIn's processing of data for other purposes and secret profiling are encouraged. Openness to visitor contributions can also lead to adverse social consequences such as inappropriate or discriminatory comments or the dissemination of sensitive data, or as a career network, particularly in relation to the current or future workplace and professional environment.

Although these damages may be significant if caused by LinkedIn itself, they are only increased to a very limited extent by the CIRP's LinkedIn profile. This is because a significant part of the data is already available to LinkedIn. In particular, the CIRP's offer does not create any obligation to create a LinkedIn account, as there are sufficient alternative contact and information options for the CIRP. In principle, almost all contributions shown on the CIRP's LinkedIn account are also available on the CIRP website, so that they can be consumed without generating any data.

The CIRP's topics, such as science and research, are also only suitable to a limited extent for triggering hateful debates, so that the likelihood of damage occurring is very limited in this respect too.

3. Risk assessment
Overall, the additional risk caused by the CIRP's LinkedIn account can therefore be classified as low to medium.

In addition, it is possible to implement remedial measures that further reduce the risk, which the CIRP also points out in its privacy policy for LinkedIn.

However, a large part of these measures are in the user's sphere: the user can protect themselves to a certain extent through various settings, for example by deleting their browser history, deactivating cookies, or not sharing their location when using photos.

With regard to particularly vulnerable people such as young people, it can be seen that they are generally not part of LinkedIn's target group. Even though registration on LinkedIn is possible from the age of 16, LinkedIn as a career network is mainly aimed at specialists and managers who want to network with each other worldwide on their own initiative.

This target group is usually much older and has the appropriate training and therefore has to weigh up the professional benefits of the service against the protection of their data. Nevertheless, it should be emphasized that there is an increased risk of fake profiles and identity theft, especially in business networks, as the business/professional environment of LinkedIn users is often described in detail.

In addition, some LinkedIn practices, such as feigning membership of existing contacts of LinkedIn users and independently sending email invitations to join LinkedIn, can arouse suspicion among LinkedIn users' circle of acquaintances or even damage their professional reputation.

LinkedIn users should therefore be particularly advised to prevent LinkedIn from accessing address books and other external services and to deactivate the automatic sending of email invitations, as LinkedIn also contacts contacts outside of their own network and stores their data. For additional security, the user can be advised to only use LinkedIn from the desktop in the browser and do not install LinkedIn apps on your smartphone/mobile device.

As a further remedial measure, the continuous editorial support enables intervention in the event of comments that are defamatory or defamatory, including blocking the account.

4. Result
The use of LinkedIn by the CIRP is justifiable in view of the risks described and the mandatory measures provided. The CIRP undertakes to monitor further developments and to regularly repeat the review carried out here and to develop it further if necessary.