Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
Sign In with LinkedIn lets visitors authenticate using their LinkedIn account, loading the LinkedIn SDK which sets cookies and shares data with LinkedIn, a Microsoft company.
Sign In with LinkedIn is an authentication option that lets users log in or register on your site using their LinkedIn account, through the OAuth protocol. Implementing it usually means loading LinkedIn scripts or redirecting to LinkedIn, and LinkedIn is owned by Microsoft. It is popular on professional and B2B sites.
When the LinkedIn button or SDK loads, LinkedIn can set cookies such as bcookie and lidc that are used for security and for LinkedIn own analytics and advertising. During sign in, the user shares profile data such as name, email and headline with your application, and LinkedIn receives the request details including the IP address.
The authentication a user actively chooses can rely on their request, but the LinkedIn tracking cookies that load alongside are non essential and need consent under Article 5(3) of the ePrivacy Directive. The profile data you receive is personal data you must handle under the GDPR.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
Do not load the LinkedIn SDK or its tracking cookies before consent; ideally trigger it only when the user clicks the sign in button. Tell users what profile fields you will receive and why, and obtain consent for any LinkedIn advertising cookies separately.
LinkedIn operates from the United States with an EU establishment in Ireland. Data may be processed in the United States, relying on the EU US Data Privacy Framework, under which Microsoft is certified, or Standard Contractual Clauses. Reference this in your privacy notice.
Load LinkedIn only on user action, request the minimum profile scopes, document the data you receive and gate any LinkedIn tracking cookies behind consent. Disclose the Microsoft and United States involvement and offer an alternative sign in method.
Websites using Sign In with LinkedIn must obtain user consent under GDPR regulations.
DPIA considerations
A DPIA is usually not required for optional social sign in, but consider one if you combine LinkedIn data with profiling or process it at scale. Assess the tracking cookies, the profile scopes and the United States transfer.
Sample consent text
You can sign in with LinkedIn. Using it loads LinkedIn, which sets cookies and shares data with LinkedIn in the United States. LinkedIn tracking cookies load only if you accept.
Third-party domains contacted
linkedin.comlicdn.compx.ads.linkedin.comCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| bcookie | Advertising | 1 year | Browser identifier cookie set by LinkedIn for security and to enable advertising and analytics features. |
| lidc | Functional | 1 day | Used by LinkedIn for data centre routing and to support the sign in flow. |
| li_gc | Functional | 6 months | Stores the visitor consent state for the use of non essential LinkedIn cookies. |
Sign In with LinkedIn is an essential service, but transparency matters. Manage all your consent with FlowConsent.
Yes, the LinkedIn SDK can set cookies such as bcookie and lidc used for security, analytics and advertising, in addition to processing the sign in request and the visitor IP.
The authentication the user actively starts can rely on their request, but the LinkedIn tracking and advertising cookies are non essential and require prior consent.
Use contract or the user request for the sign in itself, and consent under Article 6(1)(a) plus the ePrivacy rule for LinkedIn tracking cookies. Handle the profile data you receive under a clear basis.
Yes, LinkedIn is a Microsoft company operating from the United States with an EU establishment in Ireland. Transfers rely on the EU US Data Privacy Framework or Standard Contractual Clauses.
Optional social sign in rarely needs a DPIA, but consider one if you profile users or process LinkedIn data at scale. Assess the tracking cookies, scopes and transfer.
Load LinkedIn only when the user clicks sign in, request minimal scopes, gate tracking cookies behind consent and disclose the Microsoft and United States involvement. Offer an alternative login.
You can offer email and password login, a European identity provider or other social logins. Minimising third party sign in reduces tracking and transfer concerns.
List the LinkedIn cookies such as bcookie and lidc with their purpose and duration, state that tracking cookies load only after consent and disclose the United States transfer.