LinkedIn Privacy vs. ISO 29100: A Technical Compliance Audit

Compliance of the LinkedIn Privacy Policy with the Principles of the ISO 29100:2011 Standard

2015-01-01
Alexandra K. Michota, Sokratis K. Katsikas
Summary
Problem
Method
Results
Takeaways
Abstract

The paper evaluates the LinkedIn Privacy Policy (March 2014 version) against the international ISO 29100:2011 Privacy Framework. Using a structured mapping methodology, the researchers assess how well LinkedIn's policy components adhere to 11 globally recognized privacy principles, finding significant compliance gaps in areas such as information security and data minimization.

TL;DR

This research conducts a forensic audit of LinkedIn's privacy policy through the lens of the ISO 29100:2011 standard. While LinkedIn excels at providing "Openness and Transparency" (telling you they are taking your data), it significantly underscores in Information Security and Data Minimization, often favoring a business model that encourages "over-sharing" over user protection.

Background: The Gap Between Policy and Protection

Privacy policies in Social Networking Sites (SNS) are notoriously difficult to navigate. Most users treat them as a "click-through" obstacle. However, as PII (Personally Identifiable Information) becomes a goldmine for data mining and marketing, the lack of a standardized framework for these policies creates a "digital oversight" risk. This paper bridges the gap by mapping LinkedIn's March 2014 policy update against the 11 principles of the ISO 29100:2011 framework.

Problem & Motivation

The researchers identified a recurring issue: Social Network Service Providers (SNSSP) claim transparency because they publish policies, yet these policies are often too verbose for end-users to understand the implications of their data disclosure. The core motivation was to determine if LinkedIn's "path to compliance" is an uphill battle and where exactly the "mismatches" occur.

Methodology: Mapping the Privacy Landscape

The authors broke down the LinkedIn Privacy Policy into its core components—Registration, Profile Information, Cookies, Ad Technologies, etc.—and mapped them against the 11 ISO principles.

The ISO 29100 Privacy Framework

The framework acts as the "motivating force" for a privacy-respectful architecture. The principles include:

  • Consent and Choice
  • Purpose Legitimacy
  • Collection Limitation & Data Minimization
  • Accountability & Information Security

ISO 29100 privacy framework components Figure 1: The components of the ISO 29100:2011 framework used as the audit baseline.

The mapping process (Fig. 6 in the paper) analyzed every statement in the policy to determine if the PII involved was required, what the processing procedures were, and who could see the data.

Key Findings: The "Over-Sharing" Conflict

The study found a major conflict between LinkedIn's business objectives and the Data Minimization principle.

  1. The Transparency Paradox: LinkedIn is excellent at "Openness, Transparency, and Notice." The policy clearly states they will collect your address book, sync your calendar, and track your location. However, knowing a site is taking your data doesn't satisfy the principle of Collection Limitation.
  2. Subsidiary Integration: By absorbing services like SlideShare and Pulse, LinkedIn creates a unified data profile that users might not have explicitly consented to in a granular fashion.
  3. Security Concerns: Principles like Information Security and Privacy Compliance were rated poorly across almost all policy parts. The researchers note that PII integrity and confidentiality are "difficult to guarantee" in an environment designed for maximum interaction and external service integration.

Workflow for mapping study Figure 2: The research workflow for mapping the LinkedIn policy to ISO guidelines.

Clinical Analysis: Why This Matters

The most striking insight is that LinkedIn (and similar OSNs) uses transparency as a substitute for security. By being "open" about their extensive data collection, they technically satisfy some legal notice requirements but fail the "Accountability" and "Security" tests of the ISO standard.

Limitations

  • Snapshot in Time: The study analyzes the 2014 policy. In the post-GDPR era (2018+), many of these findings might be mediated by stricter European laws, though the fundamental conflict between "data-hungry" business models and "data-minimizing" standards remains.
  • Subjectivity: The mapping scale ("+" vs "O") contains inherent researcher bias in interpreting policy legalise.

Conclusion & Future Outlook

The paper concludes that SNS infrastructures must move toward default data protection. Instead of expecting users to navigate complex settings to opt-out of over-sharing, the ISO principles suggest that systems should be "Privacy Respectful" by design. Future work should look at the automated extraction of these components to provide users with real-time "Privacy Scores" based on international standards.

Takeaway: Transparency is not a placeholder for privacy. Just because a company tells you they are sharing your data with "affiliates and third parties" doesn't mean the policy is ISO-compliant.

Find Similar Papers

Try Our Examples

  • Search for recent studies evaluating the compliance of modern social media privacy policies (2020-2024) with updated ISO 29100 or GDPR standards.
  • Which paper originally proposed the "Privacy Data Lifecycle" model used in the mapping of ISO 29100 components, and how has it evolved for AI-driven platforms?
  • Explore research papers and technical reports that apply ISO 29100 principles to the development of decentralized social networks or privacy-preserving data mining.
Contents
LinkedIn Privacy vs. ISO 29100: A Technical Compliance Audit
1. TL;DR
2. Background: The Gap Between Policy and Protection
3. Problem & Motivation
4. Methodology: Mapping the Privacy Landscape
4.1. The ISO 29100 Privacy Framework
5. Key Findings: The "Over-Sharing" Conflict
6. Clinical Analysis: Why This Matters
6.1. Limitations
7. Conclusion & Future Outlook