GetMySAR

Organisation

Subject Access Request to LinkedIn

What LinkedIn holds about you, where to send the request, and what to expect back.

GetMySAR is an independent service and is not affiliated with, endorsed by, or acting on behalf of LinkedIn. The contact details below are published so you can make a request yourself free of charge.

Where to send your request

Verified 18 August 2026
Postal address
LinkedIn Corporation Attn: Legal Dept. (Privacy Policy and User Agreement) 1000 W. Maude Avenue Sunnyvale, CA 94085 USA
Contact
Data Protection Officer
ICO registration
ZB722109
ID they ask for
LinkedIn asks for no identity documents. It verifies you by requiring you to be signed in to the account the request is about: the data download, the Data Access Request Form and the form for contacting LinkedIn's Data Protection Officer all return "Please sign in so we can provide the best support possible." to anyone who is not. The one place LinkedIn does ask for documents is a request to close the account of a member who has died, where it says "For requests to close the account, you'll also need a copy of the member's death certificate and one of the following legal documents to show you have the authority to act on behalf of the deceased member: Letters of Administration, Letters of Testamentary, Letters of Representation, Other court order appointing the requestor as an authorized representative for the deceased member's estate." Merely reporting a death or memorialising a profile needs no documents.

Source: LinkedIn published information. Organisations change these details — tell us if this is out of date.

Specific to LinkedIn

For a UK member the controller is LinkedIn Corporation in Sunnyvale, California — not LinkedIn Ireland. LinkedIn's European Regional Privacy Notice says: "If you are located in the United Kingdom, LinkedIn Corporation with its address at 1000 W Maude Avenue, Sunnyvale, CA, is the data controller of your personal data." That turns on a definition worth knowing: LinkedIn uses "Designated Countries" to mean the EU, the EEA and Switzerland, and the UK is not one of them. The UK gets the European notice for its extra rights and the rest-of-world answer on who holds the data. There are two online routes and they do different jobs. Download my data, in your settings under Data Privacy, is the self-service export. When that does not cover what you want, LinkedIn publishes a separate Data Access Request Form and names it: "If you would like access to data that's not included in the data files described above, you may complete LinkedIn's Data Access Request Form." It asks what personal data you want and where you think it is held, and it requires you to have downloaded the archive first. Both of those need you signed in, and so does the form for contacting LinkedIn's Data Protection Officer. Signed out, all of them return the same sentence: "Please sign in so we can provide the best support possible." The postal address above is the only route on LinkedIn that a person who is not signed in can enter. LinkedIn publishes no email address for data protection anywhere on its own pages; dpo@linkedin.com appears on both of its ICO register entries as a registration contact, which is not the same as a published way of making a request. LinkedIn publishes two postal blocks and they are not interchangeable. The one above, from its help centre, is complete and postable. The one in the European Regional Privacy Notice is addressed "℅ Data Protection Officer, 1000 W Maude Avenue, Sunnyvale, CA" with no company name, no ZIP code and no country — the same street, but not a block a letter from the UK will reach. Do not combine them; only the version above appears on a LinkedIn page as written. The export leaves things out and LinkedIn says which. It gives you only your own personal data and not other members'; it does not include People You May Know or Who's Viewed Your Profile; it is not available on mobile; and if you close your account you lose access to it altogether. LinkedIn does publish how quickly the download arrives — "If you select a specific type of data, we'll email you within minutes" and "If you select the larger download, you'll receive an email within 24 hours" — and says the Data Access Request Form "may take several days to receive a response". None of those is the statutory deadline; the one month you are entitled to comes from the law. One thing the UK does not get. LinkedIn runs an API programme letting members access their data programmatically, and it is scoped to the EU, the EEA and Switzerland — the same definition that decides who your controller is. If you want to word the request yourself, our free letter generator will write it, and if a reply arrives and you cannot tell whether it is complete, our free response checker will show you what is missing.

Making a request to an organisation

Made under UK GDPR Article 15

Any organisation that decides how and why your personal data is used is a data controller, and must respond to a subject access request. That covers retailers, employers, membership bodies, landlords, charities, gyms and online services alike.

The organisation must confirm whether it is processing your data, provide a copy of it, and explain why it holds it, who it shares it with and how long it keeps it. There is normally no fee.

What people commonly ask for

  • All personal data held about you
  • Correspondence and internal notes referring to you
  • Account, order or membership history
  • Call recordings and chat transcripts
  • Marketing preferences and consent records

Watch out for

  • Identify the right legal entity — brand names and registered companies often differ.
  • Large groups may hold your data across several companies, each a separate controller.
  • Be specific about what you want if the organisation is likely to hold a lot.

Your rights, whoever you are asking

Deadline. An organisation must respond without undue delay and within one month. It may extend by up to two further months where the request is complex or you have made a number of requests, but it must tell you within the first month that it is doing so, and why.

Cost. There is normally no fee. A reasonable fee may only be charged where a request is manifestly unfounded or excessive, or where you ask for further copies.

Proving who you are. An organisation may ask you to verify your identity, but only where it has reasonable doubts about who you are, and it should ask for the minimum needed. Where it needs further information to deal with your request, the one-month clock pauses until you provide it.

How hard they have to look. An organisation has to carry out a reasonable and proportionate search — not an exhaustive one. What counts as reasonable depends on the volume of information, the difficulty of locating it, and the size and resources of the organisation. This is a common reason for a partial response, and it is worth being specific about what you want.

If they ignore you. Complain to the organisation first. Since 19 June 2026 every organisation has had a legal duty to give you a clear way to raise a data protection complaint, to acknowledge it within 30 days, to look into it properly and to tell you the outcome. If it does not, or the answer is incomplete, you can then complain to the Information Commissioner's Office.

Send it to LinkedIn

You can do this yourself for free using the details above. If you would rather not handle the wording, the submission and the chasing, GetMySAR prepares, sends and follows up your request for a fixed £20 fee.

This page is general information about your right of access under UK data protection law. It is not legal advice. If your situation is complex or contested, consider speaking to a solicitor or contacting the Information Commissioner’s Office.