{"id":9515,"date":"2026-09-16T19:50:34","date_gmt":"2026-09-16T19:50:34","guid":{"rendered":"https:\/\/cybersecurityinfocus.com\/?p=9515"},"modified":"2026-09-16T19:50:34","modified_gmt":"2026-09-16T19:50:34","slug":"linkedin-fights-for-the-right-to-tell-customers-when-the-feds-want-their-data","status":"publish","type":"post","link":"https:\/\/cybersecurityinfocus.com\/?p=9515","title":{"rendered":"LinkedIn fights for the right to tell customers when the feds want their data"},"content":{"rendered":"<div>\n<div class=\"grid grid--cols-10@md grid--cols-8@lg article-column\">\n<div class=\"col-12 col-10@md col-6@lg col-start-3@lg\">\n<div class=\"article-column__content\">\n<div class=\"container\"><\/div>\n<p class=\"wp-block-paragraph\">Microsoft\u2019s top lawyer argued Tuesday that legislators \u201cmust make secrecy [orders] the exception\u201d in government subpoenas demanding information about LinkedIn users.<\/p>\n<p class=\"wp-block-paragraph\">LinkedIn, which is owned by Microsoft, is fighting what it calls overly broad subpoena demands from the US government, which sometimes come with secrecy orders that prevent LinkedIn from alerting customers whose information is being requested.<\/p>\n<p class=\"wp-block-paragraph\">The company is asking federal courts \u201cto enforce meaningful limits on both the scope of government demands and the secrecy that can accompany them,\u201d wrote Jon Palmer, Microsoft\u2019s chief legal officer, in <a href=\"https:\/\/blogs.microsoft.com\/on-the-issues\/2026\/09\/15\/protecting-customer-privacy-means-standing-up-for-transparency\/\" target=\"_blank\" rel=\"noopener\">a Tuesday blog post<\/a>. \u201cWe recognize law enforcement\u2019s important role in protecting public safety and investigating crime, and sometimes that does need to be done covertly. At the same time, customers and users deserve meaningful limits and independent oversight through an adversarial process.\u201d<\/p>\n<p class=\"wp-block-paragraph\">He pointed out: \u201cPeople and organizations increasingly entrust their most sensitive information to online services. If providers cannot challenge demands they know are overbroad\u2014or if courts may silence them without a rigorous, adversarial review\u2014the safeguards the law requires will be weakened precisely when they are most needed.\u201d<\/p>\n<h2 class=\"wp-block-heading\">A tricky issue<\/h2>\n<p class=\"wp-block-paragraph\">The issue is a tricky one. Law enforcement often use this type of subpoena as an investigative tool, seeking those who are engaged in illegal activities. The theoretical justification for secrecy is to avoid alerting the investigative target to make it less likely the suspect will try to destroy evidence or flee the jurisdiction.<\/p>\n<p class=\"wp-block-paragraph\">Government lawyers are supposed to only make secrecy requests when absolutely essential. Microsoft is suggesting that courts and congress need to step in to curtail blanket government efforts.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">\u201cThe Fourth Amendment protects the right to be free from unreasonable searches and seizures. That right applies to papers kept in a desk and it also applies when personal and business records are stored online,\u201d Palmer wrote. \u201cOnline service providers, like LinkedIn and Microsoft, also have a First Amendment right to speak to their customers when the government obtains an order to search their private information. Secrecy may sometimes be justified, but it should be tailored to demonstrated needs and subject to meaningful review.\u201d<\/p>\n<p class=\"wp-block-paragraph\">He added: \u201cThe government must seek only relevant information, justify secrecy with specific evidence and infringe on speech to the least extent possible.\u201d In his post, he pointed to a <a href=\"https:\/\/blogs.microsoft.com\/on-the-issues\/2026\/08\/31\/house-passes-historic-reforms-to-rein-in-secret-surveillance\/\" target=\"_blank\" rel=\"noopener\">recent legislative effort<\/a> in the US House of Representatives that might mitigate the issue if it ends up becoming law.\u00a0<\/p>\n<p class=\"wp-block-paragraph\"><strong>\u201c<\/strong>On August 31, the House passed legislation to rein in secret surveillance and strengthen notice protections when the government seeks data held by technology providers,\u201d he wrote. \u201cThe reforms would place clearer limits on secrecy orders, require greater accountability, and help ensure that secrecy is the exception \u2013 not the rule. The Senate should act promptly to send these historic reforms to the President.\u201d<\/p>\n<h2 class=\"wp-block-heading\">LinkedIn privacy battles<\/h2>\n<p class=\"wp-block-paragraph\">LinkedIn itself is currently fighting litigation that accuses it of <a href=\"https:\/\/www.csoonline.com\/article\/4156064\/questions-raised-about-how-linkedin-uses-the-petabytes-of-data-it-collects.html\" target=\"_blank\" rel=\"noopener\">directly violating the privacy rights<\/a> of its customers, and a federal judge this month dismissed <a href=\"https:\/\/storage.courtlistener.com\/recap\/gov.uscourts.cand.467271\/gov.uscourts.cand.467271.47.0.pdf\" target=\"_blank\" rel=\"noopener\">another similar case<\/a>, but gave plaintiffs permission to refile, with a caveat.<\/p>\n<p class=\"wp-block-paragraph\">\u201cGiven LinkedIn\u2019s further arguments that users voluntarily download browser extensions, which by their nature intentionally expose data to websites, it seems unlikely that the plaintiffs will ever be able to allege a privacy violation, much less prevail at the end of the day,\u201d US District Court Judge Vince Chhabria wrote. \u201cBut in an abundance of caution, dismissal is with leave to amend.\u201d <\/p>\n<p class=\"wp-block-paragraph\">But, he added, if the amended complaint isn\u2019t filed within 14 days, \u201cdismissal will be with prejudice.\u201d<\/p>\n<h2 class=\"wp-block-heading\">Privacy now a \u2018data stewardship obligation\u2019<\/h2>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/acceligence.com\/talent\/profiles\/jeff-valdes\/\" target=\"_blank\" rel=\"noopener\">Jeff Valdes<\/a>, a director at Acceligence, noted, \u201cthere is definitely some irony here.\u201d<\/p>\n<p class=\"wp-block-paragraph\">\u201cIf Microsoft wants customers to view it as a steward of their privacy when the government comes asking for their information, customers are naturally going to apply that same standard to how Microsoft and LinkedIn collect, use, protect, and disclose information themselves,\u201d he said. \u201cPrivacy is difficult to compartmentalize. You cannot have one philosophy of customer privacy for government access, another for product design, and another for your own commercial data practices without eventually creating a credibility problem.\u201d<\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.linkedin.com\/in\/eclectiqus\/\" target=\"_blank\" rel=\"noopener\">Mike Wilkes<\/a>, enterprise CISO at Aikido Security, agreed, pointing out, <strong>\u201c<\/strong>without meaningful limits, judicial scrutiny, and an expiration mechanism, a temporary investigative necessity starts looking a lot like a permanent architecture for invisible surveillance. The individual may never have an opportunity to challenge the scope of the request, because they may never even know the request existed until prosecutors show up with an indictment.\u201d <\/p>\n<p class=\"wp-block-paragraph\">That, he said, \u201cis why Microsoft\u2019s argument matters, despite the obvious irony of LinkedIn simultaneously defending itself against privacy claims from its own users.\u201d<\/p>\n<p class=\"wp-block-paragraph\">But <a href=\"https:\/\/my.idc.com\/getdoc.jsp?containerId=PRF005059\" target=\"_blank\" rel=\"noopener\">Ryan O\u2019Leary<\/a>, an IDC research director, offered a different perspective.<\/p>\n<p class=\"wp-block-paragraph\">\u201cMicrosoft makes no bones about using the data contained within its own systems for its own purposes. Both things can be true: Microsoft can fight for the privacy of its platform while still not necessarily respecting the privacy rights of its end users,\u201d O\u2019Leary noted. \u201cThis seems to come down to protecting its own proprietary data sets, not some altruistic privacy crusade.\u201d<\/p>\n<p class=\"wp-block-paragraph\">\u00a0At the same time, Valdes pointed out, Palmer\u2019s post highlights how deeply privacy has become a top-tier enterprise IT priority.<\/p>\n<p class=\"wp-block-paragraph\">\u201cPrivacy is rapidly becoming a much broader data stewardship obligation,\u201d he said. \u201cCompanies holding sensitive information increasingly have to think simultaneously about government requests, third-party access, their own collection practices, AI use, data retention and what they tell customers about all of it. If you want to be trusted as the custodian of the world\u2019s data, customers are going to judge how you protect that data in every direction.\u201d<\/p>\n<p class=\"wp-block-paragraph\">However, Wilkes noted, \u201cMicrosoft does not need to be a perfect privacy saint to be right about this particular problem.\u201d<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>Microsoft\u2019s top lawyer argued Tuesday that legislators \u201cmust make secrecy [orders] the exception\u201d in government subpoenas demanding information about LinkedIn users. LinkedIn, which is owned by Microsoft, is fighting what it calls overly broad subpoena demands from the US government, which sometimes come with secrecy orders that prevent LinkedIn from alerting customers whose information is [&hellip;]<\/p>\n","protected":false},"author":0,"featured_media":9516,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-9515","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-education"],"_links":{"self":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9515"}],"collection":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=9515"}],"version-history":[{"count":0,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9515\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/media\/9516"}],"wp:attachment":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=9515"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=9515"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=9515"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}