Analysis and implementation of nanotargeting on LinkedIn based on publicly available non-PII
Ángel Merino, José González-Cabañas, Ángel Cuevas, Rubén Cuevas
TL;DR
This work demonstrates that publicly accessible non-PII data, specifically a LinkedIn user’s location and a small set of professional skills, can uniquely identify individuals within a large user base and enable nanotargeting with high probability. It introduces a data-driven NP metric to quantify how many skills are needed to uniquely identify a user and validates the concept with a low-cost proof-of-concept campaign targeting three authors. The study shows the scope of potential exposure, estimating hundreds of millions of LinkedIn users could have been nanotargeted before a platform fix in 2023, and discusses legal and ethical implications under GDPR. The authors advocate for stronger audience-size thresholds and limited combinability of non-PII attributes to mitigate such privacy risks in advertising platforms.
Abstract
The literature has shown that combining a few non-Personal Identifiable Information (non-PII) is enough to make a user unique in a dataset including millions of users. This work demonstrates that a combination of a few non-PII items can be activated to nanotarget users. We demonstrate that the combination of the location and {5} rare ({13} random) skills in a LinkedIn profile is enough to become unique in a user base of {$\sim$970M} users with a probability of 75\%. The novelty is that these attributes are publicly accessible to anyone registered on LinkedIn and can be activated through advertising campaigns. We ran an experiment configuring ad campaigns using the location and skills of three of the paper's authors, demonstrating how all the ads using $\geq13$ skills were delivered exclusively to the targeted user. We reported this vulnerability to LinkedIn, which initially ignored the problem, but fixed it as of November 2023.%This nanotargeting may expose LinkedIn users to privacy and security risks such as malvertising or manipulation.
