LinkedIn, the Microsoft-owned professional networking platform, is facing scrutiny over its data-sharing practices related to its user verification process. A report has raised concerns about the extent to which user data is shared with third-party companies during identity verification.
The report, initially highlighted by Inc. magazine and published on the blog The Local Stack, delves into the privacy policies and terms of service of Persona, the third-party service LinkedIn uses for identity verification. The author, identified as rogi, raised concerns about the breadth of data collected and how it is used.
Persona, a company increasingly utilized for age and identity verification across various online platforms, including Discord and Roblox, gains access to a wide array of user data during the verification process, according to the report. This includes full names, passport images, selfies, facial biometrics, NFC chip data from passports, nationality, gender, date of birth, email addresses, phone numbers, physical addresses, IP addresses, geolocation data, device types, MAC addresses, browsers, operating system versions, and language preferences.
Furthermore, Persona reportedly employs frequency detection technology, meticulously tracking the time taken to complete the verification process, points of pause, and instances of copying and pasting.
According to rogi, this data is not only shared with LinkedIn and Persona but also with Persona's “global data partner network,” encompassing a broader range of external vendors, also known as sub-processors. Persona's terms of service also state that data may be disclosed to law enforcement agencies upon request.
Persona's sub-processors include Amazon Web Services and Google Cloud Platform, as well as artificial intelligence companies like OpenAI and Anthropic.
Rick Song, co-founder and CEO of Persona, addressed the report in a LinkedIn comment, stating that personal data processed is solely used to confirm user identities and is not used in AI training or models.
Song also stated that biometric data is deleted immediately after processing and that other personal data is deleted within 30 days. He further clarified that while OpenAI and Anthropic are listed on Persona's website as sub-processors, they are not involved in LinkedIn user identity verification.
Song explained that the sub-processor list is a comprehensive list used across all Persona clients and that the specific sub-processors involved depend on the products chosen by each client. He acknowledged that the listing could be misleading and pledged to provide further clarification in the future.
The increasing use of Persona by prominent online platforms has placed the company under greater scrutiny. A separate report by a security researcher alleges that Persona conducts “269 individual checks” on Discord users.