For any staffing agency evaluating AI sourcing tools, one question should come before speed, price, or integrations: where does the candidate data actually come from? Tools that scrape public profiles without authorization carry a specific, documented category of legal and reputational risk — one that a compliant, bring-your-own-credential model avoids by design.
What actually happened when a company tried to scrape LinkedIn at scale?
The defining case is hiQ Labs v. LinkedIn. After six years of litigation — including a Ninth Circuit ruling that initially sided with hiQ's right to access public profile data, remanded following the Supreme Court's Van Buren ruling on the Computer Fraud and Abuse Act — the case ended in December 2022 with a confidential settlement. That settlement included a $500,000 judgment against hiQ, a finding of liability under California common-law torts of trespass to chattels and misappropriation, and an injunction permanently barring hiQ from scraping LinkedIn (Morgan Lewis legal analysis). The key nuance: hiQ ultimately prevailed on the criminal CFAA theory — accessing public data isn't automatically "hacking" — but still lost decisively on tort and contract grounds. Scraping public profile data isn't criminally prosecutable, but it remains civilly and contractually risky (case summary).
Is this an isolated case, or part of a bigger pattern?
Part of a bigger, ongoing enforcement pattern. Clearview AI, built on scraped public images for facial recognition, was fined more than £7.5 million by the UK Information Commissioner's Office for unlawful data processing. The fine was overturned on a jurisdictional technicality — Clearview served only non-UK/EU law enforcement clients — but the ICO explicitly stated the ruling doesn't remove its ability to act against international scraping companies processing UK residents' data (BBC News). It's a cautionary analogy for recruiting-data vendors rather than a direct precedent, but the direction of regulatory travel is unmistakable: scraped-data businesses remain a live enforcement target.
What does GDPR/CCPA specifically require?
Both frameworks treat professional profile information — names, employment history, skills, contact details — as personal data subject to lawful-basis, consent, and data-subject-rights obligations. Bulk scraping of candidate data without a clear lawful basis creates direct GDPR/CCPA exposure, entirely separate from any platform Terms-of-Service violation. For a staffing agency handling candidate data across jurisdictions, this is a compliance obligation that exists regardless of which specific platform the data originated from.
So what does a compliant alternative actually look like?
A bring-your-own-credential model: sourcing operates through the agency's own authorized accounts and licensed data channels, not unauthorized scraping of third-party platforms. This sidesteps the exact terms-of-service and tort exposure that produced the hiQ judgment, while still reaching passive candidates — roughly 75% of the professional workforce is employed and not actively job-searching, meaning the majority of strong candidates will never apply to a posting and can only be reached through proactive outreach (LinkedIn Talent Solutions).
Does staying compliant mean sacrificing the sourcing tool stack's speed?
Not necessarily. The value of AI sourcing tools comes from continuous, multi-channel reach and fast first-touch outreach — not from the specific mechanism of data acquisition. A sourcing engine built on authorized, licensed channels can run just as continuously and reach just as broadly as one built on scraping; the difference is entirely in data provenance and downstream legal exposure, not in candidate-facing speed.
How should an agency evaluate a sourcing vendor's compliance claims?
By asking for specifics, not reassurance. A vendor should be able to state plainly whether candidate data originates from the agency's own authorized accounts and licensed channels, or from third-party scraped datasets — and should be able to describe how outreach respects platform terms of service and data-protection obligations under frameworks like GDPR and CCPA. Agencies that skip this diligence step inherit the vendor's data-provenance risk without necessarily realizing it, since the legal exposure from a case like hiQ Labs v. LinkedIn ultimately attached to the party doing the scraping and using the data — not just the platform being scraped (Morgan Lewis).
The regulatory direction of travel matters here too: enforcement actions like the Clearview AI case demonstrate that data-protection authorities remain willing to act against scraping-based businesses even when the underlying technology has legitimate uses, which means the compliance calculus for any sourcing vendor is unlikely to loosen over time (BBC News). Agencies evaluating vendors today should assume today's compliance bar, not a more permissive future one.
None of this is theoretical risk-aversion: GDPR enforcement bodies across the EU have shown a consistent willingness to act on unlawfully processed personal data regardless of the processor's business model, which means an agency's compliance posture on sourcing data should be treated as an operational requirement, not a legal afterthought to be addressed only if a complaint arises.
UPPER's POV: For an agency, compliance isn't a constraint on sourcing speed — it's a design choice about where the data comes from. UPPER operates exclusively through the agency's own authorized accounts and licensed channels, never scraping, which keeps candidate data handling defensible under GDPR/CCPA and platform terms while still reaching the passive majority of the workforce that never sees a job posting.
Key data points
- hiQ Labs v. LinkedIn ended in a $500,000 judgment and permanent injunction against scraping (Morgan Lewis).
- Clearview AI was fined more than £7.5 million by the UK ICO for unlawful scraped-data processing (BBC News).
- GDPR and CCPA classify candidate profile data as personal data requiring a lawful basis, separate from Terms-of-Service issues.
- ~75% of the professional workforce is passive and only reachable through proactive outreach (LinkedIn Talent Solutions).
