Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
The LinkedIn Share button and related plugins allow visitors to share web pages to LinkedIn. Loading the LinkedIn platform script contacts LinkedIn servers, sets multiple LinkedIn cookies and exposes the visitor IP address to LinkedIn and Microsoft.
The LinkedIn Share button is a social plugin that allows website visitors to share a page directly to their LinkedIn feed with a single click. It is implemented by loading the LinkedIn platform JavaScript from platform.linkedin.com. Beyond the share functionality, the script may also power Follow company buttons and LinkedIn insight tags if present. LinkedIn is owned by Microsoft Corporation.
LinkedIn sets several cookies when the platform script loads. The bcookie (1 year) is a browser identifier. The lidc cookie (1 day) handles routing between LinkedIn data centres. The li_gc cookie (2 years) stores the visitor consent state for non-essential LinkedIn cookies. The UserMatchHistory and AnalyticsSyncHistory cookies (30 days each) are used for advertising audience matching and analytics synchronisation. The bscookie (1 year) is a security cookie for verified logins. The visitor IP address is exposed to LinkedIn on every script load and on any share or follow action.
The LinkedIn platform script sets advertising and analytics cookies as soon as it loads, before the visitor takes any sharing action. This triggers the ePrivacy Directive requirement for prior consent. Under GDPR the website operator and LinkedIn may be regarded as joint controllers for the initial data collection. The li_gc consent cookie set by LinkedIn reflects LinkedIn's own consent mechanism, which does not replace the website operator's obligation to obtain consent under their own privacy notice before loading the script.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
The LinkedIn platform script must not load until the visitor has given consent covering at minimum the analytics and marketing categories. Block the script via your consent management platform or tag manager. There is no cookieless alternative for the LinkedIn Share button so if consent is declined the button should be hidden or replaced with a plain share URL link that opens LinkedIn without pre-loading any script.
LinkedIn Ireland Unlimited Company acts as the EU data controller but transfers data to LinkedIn Corporation and Microsoft Corporation in the United States. The transfer relies on the EU US Data Privacy Framework and standard contractual clauses. Website operators should note the involvement of Microsoft as parent company and include the transfer details in their privacy notices.
Block the LinkedIn platform script until the visitor opts in to analytics and marketing cookies. If the user declines, display a static share link as a fallback. Update your cookie policy to list all LinkedIn cookies and their purposes. Include LinkedIn and Microsoft as data recipients in your privacy notice, referencing the US transfer mechanism. Conduct a DPIA given the high risk rating and advertising profile built across sites. Review whether the share button is needed on all pages or only on relevant content.
Websites using LinkedIn Share must obtain user consent under GDPR regulations.
DPIA considerations
A DPIA is recommended before deploying the LinkedIn Share plugin due to its high risk classification. LinkedIn (a Microsoft company) processes visitor IP addresses and cookie identifiers in the United States for advertising and analytics purposes triggered by the mere loading of the platform script, before any sharing action by the visitor. Assess the necessity of including the plugin on every page versus only on content pages where sharing is relevant.
Sample consent text
We embed a LinkedIn Share button on this website. When you enable this feature, LinkedIn will load scripts on your device, set cookies and receive your IP address. LinkedIn and Microsoft may use this data for advertising and analytics purposes. Data is processed in the United States. You can withdraw your consent at any time.
Third-party domains contacted
platform.linkedin.comwww.linkedin.compx.ads.linkedin.comCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| bcookie | Analytics | 1 year | Browser identifier cookie used by LinkedIn to identify the browser across sessions |
| lidc | Functional | 1 day | Routing cookie used by LinkedIn to select the appropriate data centre for the visitor |
| li_gc | Functional | 2 years | Stores the visitor consent state for non-essential LinkedIn cookies |
| UserMatchHistory | Marketing | 30 days | Used by LinkedIn to synchronise advertising audience lists across partner sites |
| bscookie | Security | 1 year | Security cookie used by LinkedIn to verify authenticated user sessions |
LinkedIn Share places tracking cookies for advertising — comply with GDPR using FlowConsent.
LinkedIn sets several cookies when the platform script loads. The bcookie (1 year) is a browser identifier. The lidc cookie (1 day) handles routing between LinkedIn data centres. The li_gc cookie (2 years) stores the visitor consent state for non-essential LinkedIn cookies. The UserMatchHistory and AnalyticsSyncHistory cookies (30 days each) are used for advertising audience matching and analytics. The bscookie (1 year) is a security cookie for verified logins.
Yes. The LinkedIn platform script sets advertising and analytics cookies including UserMatchHistory as soon as it loads, before any sharing action. Under the ePrivacy Directive these are non-essential cookies that require prior consent. You must block the platform script via your consent management platform until the user opts in to the analytics and marketing categories.
The legal basis is consent under Article 6(1)(a) of the GDPR for the advertising and analytics cookies set by the platform script. The li_gc cookie LinkedIn sets reflects LinkedIn's own consent layer, but this does not replace your obligation to obtain consent under your own privacy notice before the script loads. There is no non-consent basis for the advertising cookies.
Yes. LinkedIn Ireland Unlimited Company acts as the EU data controller but transfers data to LinkedIn Corporation and Microsoft Corporation in the United States. The transfers rely on the EU US Data Privacy Framework and standard contractual clauses. Website operators should include LinkedIn and Microsoft as data recipients and reference the transfer mechanism in their privacy notices.
A DPIA is recommended given the high risk classification. The platform script enables LinkedIn and Microsoft to build an advertising profile of every visitor who loads the page, regardless of whether they click the share button. The combination of cross-site tracking cookies, US data transfers and the involvement of Microsoft as a parent company increases the risk to data subjects.
Block the LinkedIn platform script until the user opts in to analytics and marketing cookies. If consent is declined display a static share link that opens LinkedIn without pre-loading the script. Update your cookie policy to list all LinkedIn cookies. Include LinkedIn and Microsoft as data recipients in your privacy notice and reference the US transfer safeguards. Conduct a DPIA given the high risk rating.
Yes. You can replace the LinkedIn platform script with a plain anchor link pointing to the LinkedIn share URL (linkedin.com/sharing/share-offsite/) using the current page URL as a parameter. This opens LinkedIn in a new tab without loading any LinkedIn script or setting cookies on your site. The trade-off is the absence of the styled LinkedIn button, but the share functionality is preserved.
Your cookie policy should list bcookie (1 year, browser identifier), lidc (1 day, data centre routing), li_gc (2 years, consent storage), UserMatchHistory (30 days, advertising audience sync), AnalyticsSyncHistory (30 days, analytics sync) and bscookie (1 year, security). Identify LinkedIn Ireland Unlimited Company and Microsoft Corporation as the data controllers, state the legal basis as consent, and reference the EU US Data Privacy Framework and standard contractual clauses for US transfers.