All In
Back to blog
Prospection LinkedIn 18 min read

LinkedIn Prospecting Tools and US Data Privacy Law in 2026

| By Patrick de Carvalho

Contents


In December 2024, France's data protection authority fined Kaspr, a LinkedIn contact-enrichment browser extension, 240,000 euros for pulling coordinates from profiles whose owners had restricted their own visibility. Nine time zones away, the same category of tool runs a much larger business, largely undisturbed: no comparable federal law exists. LinkedIn prospecting tools, the browser extensions and outbound platforms, Apollo, ZoomInfo, Lusha, Clay among them, pull contact and company data out of LinkedIn to build sales lists. What actually governs their use in the US is not a GDPR-equivalent statute. It is a patchwork: LinkedIn's own contract, a twenty-year-old anti-spam law, and a California statute that only closed its own biggest loophole on December 31, 2022. I have run outbound campaigns off scraped and crowdsourced lists since before "legitimate interest" meant anything to sales, and the American rulebook still surprises people who assume it mirrors Europe's.

In short: There is no US federal privacy law equivalent to GDPR. LinkedIn prospecting in America runs on three instruments: LinkedIn's own User Agreement, which bans scraping and bots in Sections 8.2.2 and 8.2.13; the FTC's CAN-SPAM Act, an opt-out email law, not a consent law; and California's CCPA and CPRA, which stopped exempting B2B and employee contact data on December 31, 2022. The UK runs PECR through its Information Commissioner's Office, and the EU runs GDPR, both stricter on consent than anything American, and both a distant second and third priority for US-focused sales teams.


The gap Americans don't know they have

Ask a European compliance officer what governs a cold email and the answer comes fast: GDPR, article 6, legitimate interest or consent, take your pick. Ask an American sales leader the same question and most guess wrong, assuming something GDPR-shaped exists federally. It does not.

Congress has tried and failed to pass a comprehensive federal privacy law for years. What exists instead is sectoral: health data under HIPAA, financial data under Gramm-Leach-Bliley, children's data under COPPA, and commercial email under the CAN-SPAM Act of 2003, none of it written with LinkedIn scraping in mind. Into that vacuum, states have started legislating on their own, California first and hardest, which is why California functions here as a second federal layer, not one state among fifty.

The four tools actually running US prospecting

Four platforms dominate the conversations I have with US sales leaders in 2026, built on three different data models, which matters more than their marketing pages let on.

Tool Founded / base Data model Verified scale (2026) Compliance posture
Apollo.io 2015, United States Crowdsourced contributions plus proprietary enrichment 40,000 paying customers, over 1 million sales professionals on the platform, per the company Self-describes as GDPR compliant
ZoomInfo Founded 2000s, Vancouver, Washington Web crawling and scraping combined with licensed data $1.21 billion in 2024 revenue, 3,508 employees Multiple privacy class actions filed; agreed to a roughly $30 million settlement over data collection claims
Lusha 2016, Israel and United States Crowdsourced via a browser extension where users trade access for contributed contacts $1.5 billion valuation as of its 2021 Series B Investigated by France's and Italy's data protection authorities under GDPR; the French inquiry closed without enforcement
Clay 2017, United States Orchestration layer pulling from 100+ third-party enrichment sources, not itself a primary data collector $5 billion valuation in January 2026, up from $3.1 billion in 2025 Compliance exposure sits mostly with its connected providers, not Clay itself

None of these four is a European-style compliant-by-design tool, and none is an outlaw. What separates them legally is where the underlying contact record came from, and whether the company can name that source when a regulator or an angry prospect asks.

Crowdsourced, scraped, or licensed: the distinction that matters legally

Three sourcing models feed nearly every prospecting database on the market, and US law treats them differently even where the statute books stay silent.

Crowdsourced data comes from users who install a browser extension or connect their email and share contacts they already have, the model Apollo and Lusha both run variants of. The legal exposure concerns the original consent given when the contact was first uploaded by someone else, not by them.

Scraped data comes from automated collection against a platform's own interface, LinkedIn's public profile pages being the obvious target; ZoomInfo's company profile lists web scraping among its collection methods. The exposure is twofold: a possible terms-of-service violation, and, depending on the state, a possible privacy claim if the person scraped never consented to commercial reuse.

Licensed or public-record data comes from state business registries, professional licensing boards, or paid data-broker feeds. It is the cleanest category legally and the thinnest: it rarely includes a working email address, which is why almost every platform blends it with one of the first two models.

A sales leader who cannot answer "which of these three built this specific contact record" cannot answer the compliance question that follows it either, the same discipline behind reading any prospecting signal critically instead of trusting a vendor's label, the reasoning the All In methods are built around.

hiQ Labs v. LinkedIn: the case everyone cites and half remembers

Every conversation about LinkedIn scraping cites hiQ Labs v. LinkedIn, and most people repeat only the half of the ruling that lets them keep doing what they were already doing.

The facts: in May 2017, LinkedIn sent hiQ Labs, a workforce analytics company, a cease-and-desist letter over its scraping of public profile data. hiQ sued first, winning a preliminary injunction, affirmed by the Ninth Circuit in September 2019. The Supreme Court vacated that ruling in June 2021 and remanded the case in light of its own decision that term in Van Buren v. United States, which narrowed the Computer Fraud and Abuse Act's "exceeds authorized access" language to misuse by someone already inside a system, not to public pages behind no login wall. On remand, in April 2022, the Ninth Circuit reaffirmed its position: automated scraping of publicly accessible data likely does not violate the CFAA, per the Electronic Frontier Foundation's case summary.

That is the half everyone remembers. Here is the half that gets dropped: a district court separately found hiQ had breached LinkedIn's User Agreement, a contract claim distinct from the CFAA's criminal-hacking framework. The two sides settled in November 2022, ending the litigation.

Scraping publicly visible data probably will not get you prosecuted as a hacker under federal computer crime law. It can still get your account terminated and the company sued for breach of contract, since you agreed to LinkedIn's terms the day you created a profile. Those are different risks, and a vendor's confident "the law is on our side" answer usually addresses only the first one.

What LinkedIn's own contract actually forbids

Set the CFAA question aside: the more immediate risk for a US sales team sits in a document almost nobody rereads after signup, LinkedIn's User Agreement.

Section 8.2.2 of the LinkedIn User Agreement prohibits members from developing, supporting, or using "software, devices, scripts, robots or any other means or processes (such as crawlers, browser plugins and add-ons or any other technology) to scrape or copy the Services." Section 8.2.13 separately bans using "bots or other unauthorized automated methods to access the Services, add or download contacts, send or redirect messages." LinkedIn's Professional Community Policies also treat selling scraped data as a restricted activity, the same platform posture behind the "Seems like AI slop" reporting button I examined separately: LinkedIn polices inauthentic use through its own contract, independent of what any court decides.

This is a contract, not a criminal statute, enforced like any other: account restriction, termination, and, in hiQ's case, a lawsuit. A prospecting tool running through a browser extension logged into your LinkedIn session is closer to the conduct that got hiQ sued than most realize. Sales Navigator, LinkedIn's own paid prospecting product, sidesteps this by working inside the platform's rules, the reason it remains the lowest-risk starting point for volume prospecting.

The FTC's real tool is CAN-SPAM, and it is not a privacy law

American federal law does not require consent before a first commercial email, the sentence that surprises most people. The CAN-SPAM Act of 2003, enforced by the Federal Trade Commission, runs on an opt-out model, not an opt-in one.

Under the FTC's CAN-SPAM compliance guide, a sender can email a stranger without prior permission if the message meets a short list of conditions: an accurate "From" line, a subject line that reflects the content, a legitimate physical postal address, and a working unsubscribe mechanism honored within 10 business days of a request. The statute defines coverage by the commercial nature of the message's primary purpose, not by whether the recipient is a business or a consumer, so cold outbound to a work email falls squarely within its scope. CAN-SPAM also preempts state anti-spam statutes, except laws addressing fraud or deception, one of the rare places federal law narrows compliance instead of adding to it.

The EU draws a line CAN-SPAM skips. France's CNIL allows B2B cold email to a named professional address without prior consent, on the basis of legitimate interest, provided the message stays tied to the recipient's role and discloses the address's source at first contact. CAN-SPAM never asks where the sender got the address, only that the email carries a working opt-out.

California closed its own loophole: CCPA, CPRA, and the Delete Act

If the American system has moved toward the European one anywhere, it is California, and the move that matters most for prospecting teams happened quietly at the end of 2022.

The California Consumer Privacy Act took effect January 1, 2020, giving residents rights to know what personal data is collected about them, to opt out of its sale, and to request deletion. It launched with temporary exemptions for employment-related data and for information reflecting business-to-business transactions, the exact categories that cover a LinkedIn-sourced contact's job title, work email, and employer. Those exemptions expired on December 31, 2022, confirmed on the California Privacy Protection Agency's own FAQ page. Since January 1, 2023, a business contact's data enjoys the same CCPA protections as a consumer's.

The CCPA, amended by the CPRA voters passed in November 2020, applies to for-profit businesses meeting at least one of three thresholds: over $25 million in annual gross revenue, buying or selling the personal information of 100,000 or more consumers or households, or deriving more than half of annual revenue from selling personal information. Penalties run $2,500 per unintentional violation and $7,500 per intentional one, enforced by the California Privacy Protection Agency.

California went further with the Delete Act, SB 362, which created a statewide data broker registry and a single deletion portal called DROP, the Delete Request and Opt-out Platform. California residents gained access to DROP on January 1, 2026, and registered data brokers must start processing deletion requests submitted through it from August 1, 2026 onward, per the Agency's published timeline. A prospecting tool holding millions of contact records without an easy deletion path is now operating against a live regulatory deadline, not a theoretical one.

Second and third rank: the UK and the EU

For a US-focused sales operation, the UK and the EU rank after California, but not off the map, especially for any company selling into either market.

The United Kingdom runs its email marketing rules through the Privacy and Electronic Communications Regulations, enforced by the Information Commissioner's Office. PECR requires prior permission by default before sending direct marketing by electronic mail to an individual subscriber, stricter than CAN-SPAM's opt-out model. Breach of an ICO enforcement notice is a criminal matter carrying fines up to £500,000. A named contact pulled from LinkedIn is, on its face, an individual subscriber, so a sales team running the same sequence into the UK and the US operates under two different consent regimes without realizing it.

The European Union runs the GDPR, which requires a documented legal basis, consent or legitimate interest with a proportionality test, before processing a contact's personal data for marketing at all. France's CNIL has already applied that framework directly to LinkedIn enrichment tools: beyond the Kaspr sanction already cited, the authority fined data broker Caloga 80,000 euros in May 2025 and Solocal Marketing Services 900,000 euros the same day, both for prospecting without demonstrable valid consent. Any US company selling into Europe inherits this exposure the moment a French, German, or Irish contact enters its CRM, regardless of incorporation.

US federal (FTC) California (CCPA/CPRA) United Kingdom (PECR) European Union (GDPR)
Consent required before first commercial email? No, opt-out model No, but deletion rights apply once collected Yes, by default, for individual subscribers Yes, consent or documented legitimate interest
Covers B2B contact data? Yes, no B2B carve-out in CAN-SPAM Yes, since January 1, 2023 Yes, for named individuals Yes
Unsubscribe/deletion deadline 10 business days (CAN-SPAM) Statutory response windows under CCPA; DROP processing from August 1, 2026 ICO complaint-driven enforcement Typically one month under GDPR article 12
Maximum penalty Per-violation civil penalty, FTC-enforced $7,500 per intentional violation Up to £500,000 Up to €20 million or 4% of global turnover

None of this requires a legal department. Three questions, asked of every prospecting tool a team already pays for, cover most of the exposure described above.

Source: can you name, for any given contact record, whether it came from crowdsourcing, scraping, or a licensed public register? If the vendor's answer is "the public web," ask what that phrase includes: it does a lot of unexamined work in every privacy policy that uses it.

Consent: does the outbound sequence meet CAN-SPAM's floor, accurate sender identity, real postal address, unsubscribe link honored within 10 business days? For a contact tied to California, Britain, or the EU, does the record have a documented legal basis beyond "we found it on LinkedIn"?

Recourse: if a contact objects, can the team purge that record across every connected tool inside the promised window, and prove it if a regulator or reporter asks? This is the question that sank Solocal Marketing Services in France, and the one that will matter most in California once DROP requests reach registered brokers in August 2026.

A team that can answer all three in one sentence each is in better shape than one relying on a vendor's badge that says "GDPR compliant" on a page nobody reads twice.

What I don't know

I don't know how aggressively California's Attorney General or the Privacy Protection Agency will pursue B2B contact violations in DROP's first year, as opposed to the consumer-facing cases the agency has prioritized so far. The exemption only ended in 2022, and enforcement patterns take years to show themselves. If the first DROP-driven cases against contact-data brokers surface, they will be covered in the weekly All In newsletter.

I don't know whether Congress passes a federal privacy law in this term. Multiple attempts, including the American Data Privacy and Protection Act, have died in committee before, and I have no basis to predict this attempt fares differently.

I don't know LinkedIn's actual internal tolerance threshold for scraping through a legitimate member's own session versus scraping through a fully external, unauthenticated crawler. The User Agreement bans both in its text; enforcement intensity against each is not published, and hiQ remains the only fully litigated example on the public record.

Judge the tool by where the data came from

Every prospecting platform here will tell you it is compliant. Compliant with what is the question that separates a useful answer from a marketing line. Apollo's crowdsourcing, ZoomInfo's blend of scraping and licensed data, Lusha's browser-extension contributions, Clay's third-party orchestration: each carries a different legal profile, and a sales leader who cannot describe it in one sentence is buying a tool, not managing a risk.

The American rulebook is thinner than Europe's on paper and, in California's case, has been catching up fast since 2022. LinkedIn's own contract does more real work against automation than most teams assume. None of that is a reason to slow down. It is a reason to know exactly which of the three questions above your current stack would fail first, the same standard of disclosure we hold ourselves to whenever a piece names a vendor.

FAQ

Scraping publicly visible profile data likely does not violate the federal Computer Fraud and Abuse Act, following the Ninth Circuit's 2022 ruling in hiQ Labs v. LinkedIn. It can still breach LinkedIn's own User Agreement, which explicitly bans scraping in Section 8.2.2, exposing the account and the company to termination or a contract lawsuit, separate from any criminal exposure.

No. CAN-SPAM runs on an opt-out model: a sender can email a business contact without prior consent if the message includes an accurate sender identity, a real physical address, and a working unsubscribe link honored within 10 business days. The law defines coverage by the message's commercial purpose, not by whether the recipient is a consumer or a business.

Does the CCPA apply to business contacts sourced from LinkedIn?

Yes, since January 1, 2023. The CCPA originally exempted employment-related and business-to-business data, but those exemptions expired on December 31, 2022, per the California Privacy Protection Agency. A LinkedIn-sourced contact's name, title, and work email are now covered the same way a consumer's data is.

Can I keep using tools like Apollo, ZoomInfo, or Lusha without violating LinkedIn's terms?

Using them carries some risk regardless of the vendor's compliance claims, since LinkedIn's User Agreement bans both scraping and unauthorized automated access outright. Tools that pull from crowdsourced or licensed data outside LinkedIn's own interface carry lower contractual exposure than browser extensions that automate actions inside an active LinkedIn session.

What did the hiQ Labs v. LinkedIn case actually decide?

It decided two separate things. On the federal criminal question, the Ninth Circuit ruled that scraping publicly accessible data likely does not violate the Computer Fraud and Abuse Act. On the contract question, a district court separately found hiQ breached LinkedIn's User Agreement. The parties settled in November 2022.

What is California's Delete Act and does it affect B2B prospecting data?

The Delete Act, SB 362, created a statewide data broker registry and a single deletion portal called DROP. California residents gained access to DROP on January 1, 2026, and registered brokers must begin processing deletion requests from it starting August 1, 2026. It targets data brokers generally and does not carve out B2B contact data.

Sources

  1. Electronic Frontier Foundation, "hiQ v. LinkedIn," case page, eff.org: CFAA ruling on public scraping, Van Buren connection.
  2. Wikipedia, "hiQ Labs v. LinkedIn": case timeline, 2019 and 2022 Ninth Circuit rulings, breach-of-contract finding, November 2022 settlement.
  3. LinkedIn, "User Agreement," linkedin.com/legal/user-agreement: Sections 8.2.2 and 8.2.13, quoted directly.
  4. LinkedIn, "Professional Community Policies," linkedin.com/legal/professional-community-policies: restriction on sale of scraped data.
  5. Federal Trade Commission, "CAN-SPAM Act: A Compliance Guide for Business," ftc.gov: opt-out model, required disclosures, unsubscribe window, state preemption.
  6. Wikipedia, "CAN-SPAM Act of 2003": header and subject line requirements, preemption scope.
  7. California Privacy Protection Agency, FAQ, cppa.ca.gov/faq.html: B2B and employment exemption expiration, December 31, 2022.
  8. California Privacy Protection Agency, "Data Broker Registry," cppa.ca.gov/data_broker_registry/: Delete Act (SB 362), DROP platform dates.
  9. Wikipedia, "California Consumer Privacy Act": effective dates, thresholds, penalties, CPRA and CPPA.
  10. Wikipedia, "ZoomInfo": data broker model, 2024 revenue and headcount, privacy litigation and settlement.
  11. Wikipedia, "Lusha": crowdsourced model, 2021 valuation, French and Italian DPA inquiries.
  12. Apollo.io, "About," apollo.io/about: customer counts, crowdsourcing description, GDPR compliance claim.
  13. Clay, "About," clay.com/about: January 2026 valuation, orchestration model.
  14. CNIL, "Sanction de 240 000 euros à l'encontre de la société KASPR," cnil.fr, December 5, 2024.
  15. CNIL, sanctions against CALOGA (80,000 euros) and SOLOCAL MARKETING SERVICES (900,000 euros), cnil.fr, May 15, 2025.
  16. Wikipedia, "Privacy and Electronic Communications Regulations 2003": UK scope, ICO enforcement, penalty ceiling.

All In: the compliance question every prospecting stack avoids asking itself

A sales team can run a fast, aggressive outbound motion and still know exactly where each contact record came from. The two are not in tension. The tools that get sanctioned are the ones nobody in the building could explain.

All In is the B2B media that decodes LinkedIn, expert blog, weekly podcast and newsletter for SME leaders and sales directors who want to turn LinkedIn into measurable growth. An original creation by Patrick de Carvalho, on LinkedIn since 2004. Motto: "I Never Lose."

Discover All In and get what matters on LinkedIn, every week.