LinkedIn Web Scraping: What Section 8.2 Prohibits, and What hiQ Actually Decided
Section 8.2 reaches past running a scraper yourself. It also covers data obtained through aggregators and brokers, which catches buyers as well as builders.

LinkedIn's User Agreement section 8.2 prohibits scraping or copying the Services, using bots or unauthorised automated methods, obtaining data through third-party aggregators and brokers without consent, and circumventing use limits. Its prohibited-software page states that members using such tools risk having accounts restricted or shut down, and that the tools may stop working without notice.
Key takeaways
- The third-party clause catches buyers as well as builders, since it covers information obtained through search tools, data aggregators and brokers without consent.
- The hiQ litigation found public-data scraping outside the Computer Fraud and Abuse Act, and LinkedIn still prevailed on contract grounds.
- LinkedIn states that prohibited tools may become non-operational without notice, so a programme depending on one carries a supply risk separate from enforcement.
- The member account carries the real exposure, and a senior person's decade of connections cannot be replaced the way a sending domain can.
Reviewed and updated August 12, 2026
LinkedIn's User Agreement contains a clause numbered 8.2, and it is the reason this article is not a tutorial. The clause prohibits developing, supporting or using software, devices, scripts, robots or any other means or processes, including crawlers, browser plugins and add-ons, to scrape or copy the Services, including profiles and other data.
Plenty of pages will teach you to do it anyway. We are not going to, and the reason is practical rather than moralistic: the accounts that get restricted belong to the reader, and we spend our working life keeping client LinkedIn accounts alive.
Here is what LinkedIn's own documents say, what enforcement actually looks like, and what you can do instead that stays inside the terms.
What the User Agreement prohibits, verbatim
Section 8.2 is a list of "Don'ts". Four of its clauses bear on data collection, and they are broader than most people expect.
The first prohibits software, scripts, robots, crawlers, browser plugins and add-ons used to scrape or copy the Services, including profiles and other data. The second prohibits bots or other unauthorized automated methods to access the Services, add or download contacts, send or redirect messages, or otherwise drive inauthentic engagement.
The third is the one that catches buyers rather than builders. It prohibits copying, using, displaying or distributing information obtained from the Services whether directly or through third parties, and it names search tools, data aggregators and brokers explicitly, without the content owner's consent.
The fourth prohibits overriding a security feature, or bypassing or circumventing access controls or use limits of the Services, giving search results and profiles as examples.
- Running a scraper yourself
- Browser extensions that harvest profiles
- Bots that send connection requests
- Bypassing a rate limit
- All of that, plus
- Data obtained through third parties, including aggregators and brokers
- Buying a list that was scraped by somebody else
- Circumventing use limits such as search result caps
- Distributing the data onward
That third-party clause matters commercially. A team that buys a LinkedIn-derived dataset rather than scraping it has not stepped outside the clause as written, and "our vendor collected it" is not the exemption it feels like.
LinkedIn's enforcement page is equally direct
Separately from the User Agreement, LinkedIn publishes a page on prohibited software and extensions. It states that LinkedIn does not permit any third-party software, including crawlers, bots, browser plug-ins or browser extensions, that scrape, modify the appearance of, or automate activity on the site, and that all such tools violate the User Agreement.
Then it names the consequences. Any member using tools for those purposes is in violation and risks having their account restricted or shut down. Members also risk the tools themselves becoming non-operational without notice, because LinkedIn says it is continuously improving its technical defences against scraping and automation.
That second consequence is the one worth planning around even if you are relaxed about the first. A prospecting programme whose data supply depends on a prohibited tool has a dependency that can disappear mid-quarter with no warning, no support path and no refund.
The legal position, stated accurately
The most-cited case here is hiQ Labs versus LinkedIn, and it is routinely summarised as "scraping public data is legal", which is half of the story.
The useful distinction is between statute and contract. Scraping publicly available data was found not to violate the US Computer Fraud and Abuse Act, which is the criminal-adjacent statute people worry about. The litigation nonetheless ended with LinkedIn prevailing on contract grounds: the User Agreement is a contract you accepted, and breaching it is actionable regardless of what the CFAA says.
So the accurate summary is that public-data scraping is not a computer-crime problem in the United States and is still a terms-of-service breach you can be sued over, on top of being grounds for losing the account. Anyone telling you it is simply legal has stopped reading at the first holding.
What this means for an outbound programme
The risk is not evenly distributed, and understanding where it lands changes the decision.
- Step 1The tool takes the smallest risk
A prohibited tool that stops working has lost a product. LinkedIn says such tools may become non-operational without notice.
- Step 2The account takes the real risk
Restriction or shutdown lands on the member account running the activity, which is a real person on your team.
- Step 3The network is the unrecoverable part
A shut-down account takes its connections and history with it, and those took years to build.
- Step 4The programme stops either way
Whether the tool dies or the account does, the pipeline gap arrives about ninety days later.
That third step is why we treat this differently from a normal compliance question. A sending domain can be replaced in a fortnight. A senior person's LinkedIn account, with a decade of connections and history, cannot be replaced at all, and it is usually attached to someone whose goodwill you need.
What works instead
None of this means LinkedIn data is off limits. It means using the routes LinkedIn actually sanctions.
- Yes: Sales Navigator as a licensed product, used through its own interface
- Yes: LinkedIn's official API and partner programmes for programmatic access
- Yes: LinkedIn's own export of your data and your connections
- Yes: Finding email addresses through a dedicated waterfall rather than off LinkedIn profiles
- Yes: Manual research, which is slow and is not prohibited
- No: A browser extension that harvests profiles in bulk
- No: Buying a dataset that was scraped by somebody else
Sales Navigator is the licensed answer to most of what people want scraping for. It is a paid product whose entire purpose is finding and filtering prospects, and using it through its own interface is unambiguously permitted. Its published pricing is covered in our Sales Navigator pricing guide, and how to work it is in Sales Navigator lead generation.
Email addresses do not have to come from LinkedIn at all. This is the substitution most teams miss. LinkedIn is a good place to identify who you want to reach and a poor place to obtain contact details, since it does not hand out verified work emails anyway. Identify the person on LinkedIn, then resolve the address through a dedicated finding and verification waterfall. That is a different data supply chain entirely, and it is not covered by section 8.2.
Exports of your own data are explicitly available. LinkedIn provides a route to export your own information and connections, which covers the common case of getting your existing network into a CRM.
The question to ask a vendor
Tool vendors in this space have a standard set of reassurances, and each has a specific answer worth knowing.
"We only collect public data." True and not responsive. The hiQ outcome above establishes that public data is the part where the CFAA does not apply, and the contract claim is what LinkedIn actually won on. Public is not the operative distinction.
"We are cloud-based, not a browser extension." The clause covers software, devices, scripts, robots and any other means or processes, which is drafted to be architecture-neutral. Where the code runs is not the test.
"Thousands of users and nobody has been banned." A statement about enforcement frequency, not about whether the activity is permitted, and enforcement frequency is the thing LinkedIn says it is actively working to increase. It also cannot be verified, since the users who did get restricted are not the ones leaving reviews.
"You are not scraping, we are." The third-party clause covers information obtained through data aggregators and brokers, so receiving it is addressed directly rather than left as a loophole.
None of these answers means a vendor is dishonest. They mean the reassurance offered is about a different question from the one you asked, and the useful follow-up is always the same: if LinkedIn restricts the account, whose account is it and what is your remedy.
Where we stand
We run LinkedIn outreach for clients through HeyReach and we do not scrape. Our email addresses come from a MillionVerifier, Prospeo and Findymail waterfall rather than from LinkedIn profiles, which keeps the contact-data supply entirely outside the User Agreement question.
That is a commercial choice as much as a compliance one. We are paid on attended qualified meetings, so an account restriction costs us the engagement, and the arithmetic of risking a client's team accounts to save some sourcing time has never worked out. Our LinkedIn automation tools guide covers what can be automated safely, and the connection limit page covers the restriction triggers that automation makes worse.
If someone is pitching you a LinkedIn data tool, the question worth asking is not whether it works. It is what happens to the account running it, and who owns that account.
The short version
LinkedIn's User Agreement section 8.2 prohibits scraping and copying the Services, using bots or unauthorised automated methods, obtaining data through third-party aggregators and brokers without consent, and circumventing use limits. Its prohibited-software page says such tools violate the agreement and that members risk having accounts restricted or shut down, and that the tools themselves may stop working without notice. hiQ established that public-data scraping is not a CFAA violation, and LinkedIn still won on contract grounds, so it remains a breach you can be sued over. The sanctioned routes cover most real needs: Sales Navigator as a licensed product, the official API, LinkedIn's own data export, and sourcing email addresses through a verification waterfall rather than from profiles.
You can also see what a campaign would look like for your market, run entirely inside the terms.
Quotations and rules are from the LinkedIn User Agreement section 8.2 and LinkedIn's Help Center page on prohibited software and extensions, both re-fetched with cache-busting and verified as of August 2026. The hiQ Labs versus LinkedIn outcome is summarised as reported in the litigation record and is not legal advice. Verify current terms with LinkedIn, and take your own legal advice before relying on any characterisation of them here.
Frequently asked questions.
Frequently asked questions- Is scraping LinkedIn against the rules?
- Yes, under LinkedIn's own documents. User Agreement section 8.2 prohibits software, scripts, robots, crawlers, browser plugins and add-ons used to scrape or copy the Services, including profiles and other data. The prohibited-software page adds that all such tools violate the agreement, and that members using them risk having their accounts restricted or shut down.
- Did hiQ Labs make LinkedIn scraping legal?
- Not in the way it is usually summarised. Scraping publicly available data was found not to violate the US Computer Fraud and Abuse Act, and the litigation nonetheless ended with LinkedIn prevailing on contract grounds. The User Agreement is a contract you accepted, so a breach is actionable whatever the statute says. This is a summary rather than legal advice.
- Does buying a scraped dataset avoid the problem?
- Section 8.2 addresses that directly. It prohibits copying, using, displaying or distributing information obtained from the Services whether directly or through third parties, and it names search tools, data aggregators and brokers explicitly. A team that buys a LinkedIn-derived dataset rather than collecting it has not stepped outside the clause as written.
- What can you use instead?
- Sales Navigator as a licensed product used through its own interface, LinkedIn's official API and partner programmes, and LinkedIn's own export of your data and connections. For contact details, identify the person on LinkedIn and resolve the address through a dedicated finding and verification waterfall, which is a different supply chain and sits outside section 8.2 entirely.
About the author.
B2B cold email experts helping companies generate qualified leads through done-for-you outreach campaigns.
RevenueFlow Team
Explore more.
Ready to scale your outreach?
We build GTM engines that book real meetings. See the receipts.
Related articles.
LinkedIn CRM: What Sales Navigator Integrates With, and the Tier LinkedIn Quotes
LinkedIn sells no CRM. It sells integrations into the one you already run, and the tier built for that work is the only one it will not price.
Does Sales Navigator Provide Email Addresses? No, on Any Tier
Sales Navigator identifies the person and stops there. No tier supplies a work email address, and the CRM export carries the record with that field empty.