LinkedIn Takes On Secret Data Demands
Microsoft's legal chief says secrecy orders in government subpoenas should be the exception, not the rule, as LinkedIn pushes back in court.
A customer's inbox goes quiet, their connections keep messaging, and nothing on the screen hints that anything unusual has happened. Behind that silence, a government subpoena may have arrived at LinkedIn asking for that person's data, with a secrecy order attached that bars the company from saying a word about it. That collision between routine law enforcement work and a user's right to know is now headed to federal court.
LinkedIn, which Microsoft owns, is pushing back against what it describes as overly broad subpoena demands from the US government, some of which arrive with gag orders preventing the company from alerting the customers whose information is being sought. Microsoft's chief legal officer, Jon Palmer, laid out the company's position in a Tuesday blog post, arguing that legislators "must make secrecy [orders] the exception" in subpoenas aimed at LinkedIn users.
The company wants federal courts to rein in both the reach of those demands and the silence that can come with them. The underlying mechanics are not exotic: prosecutors issue subpoenas to a service provider, and in some cases a judge approves a secrecy order that keeps the provider from notifying the account holder. That order is meant to stop a suspect from destroying evidence or disappearing before investigators can act. What LinkedIn is contesting is how routinely that tool gets used.
Palmer's case for adversarial review
In the blog post, Palmer wrote that the company is asking federal courts "to enforce meaningful limits on both the scope of government demands and the secrecy that can accompany them." He framed the request as a recognition that investigations sometimes need to be covert, rather than a blanket objection to law enforcement access.
"We recognize law enforcement's important role in protecting public safety and investigating crime, and sometimes that does need to be done covertly. At the same time, customers and users deserve meaningful limits and independent oversight through an adversarial process."
— Jon Palmer, chief legal officer at Microsoft
Palmer tied the argument to how much sensitive material now lives on hosted platforms, rather than in filing cabinets. "People and organizations increasingly entrust their most sensitive information to online services," he wrote. "If providers cannot challenge demands they know are overbroad—or if courts may silence them without a rigorous, adversarial review—the safeguards the law requires will be weakened precisely when they are most needed."
His reasoning leans on two constitutional provisions. Palmer invoked the Fourth Amendment's protection against unreasonable searches and seizures, noting that it applies to records stored online just as it does to papers kept in a desk. He also raised the First Amendment, arguing that service providers have a speech right to tell customers when the government obtains an order to search their private information. "Secrecy may sometimes be justified, but it should be tailored to demonstrated needs and subject to meaningful review," he wrote.
What a narrowed subpoena might look like
Microsoft is not asking for an outright ban on secrecy in investigations. Palmer's post sets out a set of conditions he says should govern government demands: relevance, justification, and restraint. "The government must seek only relevant information, justify secrecy with specific evidence and infringe on speech to the least extent possible," he wrote. In practice, that framing asks courts to weigh each request rather than approve broad categories of data or open-ended gag provisions.
The company also points to a legislative avenue. Palmer cited a recent legislative effort in the US House of Representatives that he said would address the issue if it becomes law. "On August 31, the House passed legislation to rein in secret surveillance and strengthen notice protections when the government seeks data held by technology providers," he wrote. In his account, the reforms would cap secrecy orders more clearly, demand more accountability, and push secrecy toward being the exception rather than the default. "The Senate should act promptly to send these historic reforms to the President," he added.
That places the dispute on two tracks at once — litigation over individual subpoenas in federal court, and a legislative fix that still needs Senate action and a presidential signature before it changes anything on the ground.
LinkedIn's own privacy record complicates the pitch
The company's argument arrives while it is defending itself on a separate privacy front. LinkedIn is fighting litigation that accuses it of directly violating the privacy rights of its customers. This month, a federal judge dismissed another similar case, but gave the plaintiffs permission to refile with a caveat, according to the source account.
US District Court Judge Vince Chhabria wrote, "Given LinkedIn's further arguments that users voluntarily download browser extensions, which by their nature intentionally expose data to websites, it seems unlikely that the plaintiffs will ever be able to allege a privacy violation, much less prevail at the end of the day." He added, "But in an abundance of caution, dismissal is with leave to amend." The judge also set a deadline: if an amended complaint is not filed within 14 days, "dismissal will be with prejudice."
That parallel case gives critics an opening. The same company arguing that customers deserve notice when the government comes asking is simultaneously contesting claims that it mishandled user data on its own platform.
The irony problem, in observers' own words
Jeff Valdes, a director at Acceligence, put the tension bluntly: "There is definitely some irony here." He argued that the standard Microsoft wants applied to government requests will inevitably be turned back on the company itself. "If Microsoft wants customers to view it as a steward of their privacy when the government comes asking for their information, customers are naturally going to apply that same standard to how Microsoft and LinkedIn collect, use, protect, and disclose information themselves," he said. "Privacy is difficult to compartmentalize. You cannot have one philosophy of customer privacy for government access, another for product design, and another for your own commercial data practices without eventually creating a credibility problem."
Mike Wilkes, enterprise CISO at Aikido Security, focused on what happens to a person who never learns a request was made. "Without meaningful limits, judicial scrutiny, and an expiration mechanism, a temporary investigative necessity starts looking a lot like a permanent architecture for invisible surveillance," he said. "The individual may never have an opportunity to challenge the scope of the request, because they may never even know the request existed until prosecutors show up with an indictment." Wilkes added that this is "why Microsoft's argument matters, despite the obvious irony of LinkedIn simultaneously defending itself against privacy claims from its own users."
Not everyone reads the filing as a principled stand. Ryan O'Leary, a research director at IDC, said Microsoft's commercial incentives and its legal argument should be considered separately. "Microsoft makes no bones about using the data contained within its own systems for its own purposes. Both things can be true: Microsoft can fight for the privacy of its platform while still not necessarily respecting the privacy rights of its end users," he said. "This seems to come down to protecting its own proprietary data sets, not some altruistic privacy crusade."
Valdes, meanwhile, said the blog post reflects how the privacy portfolio inside large enterprises has widened. "Privacy is rapidly becoming a much broader data stewardship obligation," he said. "Companies holding sensitive information increasingly have to think simultaneously about government requests, third-party access, their own collection practices, AI use, data retention and what they tell customers about all of it. If you want to be trusted as the custodian of the world's data, customers are going to judge how you protect that data in every direction."
Wilkes, for his part, separated the messenger from the message. "Microsoft does not need to be a perfect privacy saint to be right about this particular problem," he said.
The numbers behind the fight
- August 31 — the date the House passed legislation to rein in secret surveillance and strengthen notice protections for data held by technology providers.
- 14 days — the window Judge Chhabria set for plaintiffs to file an amended complaint in the dismissed LinkedIn privacy case, after which dismissal would be with prejudice.
- Two constitutional claims — the Fourth Amendment protection against unreasonable searches and the First Amendment right to notify customers, both invoked by Palmer in the blog post.
What the litigation track actually asks for
Microsoft's court request is narrower than a demand to end sealed subpoenas. The company is asking federal courts to enforce limits on the scope of government demands and on the secrecy that accompanies them. The company says that as a provider, it should be able to contest demands it believes are overbroad, and that courts should not be able to silence it without a rigorous, adversarial process.
Palmer's post repeatedly returns to tailoring, an approach that puts the burden on the government to show why a specific secrecy provision is needed. The argument sketches what that could look like: a request limited to relevant information, a secrecy justification backed by specific evidence, and a gag that restricts speech no more than necessary. Each of those elements is the kind of detail courts would have to weigh case by case rather than through blanket rules.
Where the Senate comes in
The House legislation Palmer highlighted is not yet law. He wrote that the reforms would place clearer limits on secrecy orders, require greater accountability, and help ensure secrecy becomes the exception rather than the rule, then pressed the Senate to move quickly to send the reforms to the President. Until that happens, the practical footing for providers remains the courts — which is why LinkedIn's litigation and Microsoft's advocacy are running side by side.
The dispute also sits inside a broader set of demands on companies that hold large volumes of user data. Third-party access, internal collection practices, AI use, and retention policies all fall under the same scrutiny, according to Valdes. A single blog post about government subpoenas does not resolve any of those questions, but it does put the company's stated standard on the record.
Why this matters beyond LinkedIn
For any business that stores customer data with a third-party provider, the core question here is notice: whether you will learn that your records were handed over, and whether the provider can object before that happens. If courts read the Fourth and First Amendments the way Palmer argues, providers could get more room to challenge overbroad demands and to tell customers when a request arrives, which in turn would give account holders a chance to contest the scope of a search. If the House bill clears the Senate and reaches the President, those limits would arrive as statute rather than case law.
The irony Valdes and Wilkes both flag is not incidental. A company can argue for stronger notice protections for government requests while still facing its own users' privacy claims in court — and customers may end up judging the sincerity of the first by how the second is resolved. For the industry, the outcome could shape how providers document their handling of legal demands, how much they tell users, and what they promise in privacy policies they can actually keep. Until the Senate acts or a court rules, the answer remains unresolved, and the silence a secrecy order imposes may continue to be the only signal a user gets.
Sources
- CSO Online Original source
- a Tuesday blog post Also reporting
- recent legislative effort Also reporting
- directly violating the privacy rights Also reporting
- another similar case Also reporting
- Jeff Valdes Also reporting
- Ryan O’Leary Also reporting
Continue Reading
Windows 11 Update Breaks Domain Trust
Administrators report that the KB5124008 security update breaks domain trust on some enterprise systems, pointing to a security feature as the likely cause.
ASM Summit Takes Aim at Blind Spots
SecurityWeek's Attack Surface Management Summit runs today, with sessions on asset visibility, SBOMs, red teaming, and AI-driven defense.
Oracle's Monthly Patch Push Targets Fusion Middleware
Oracle's September update delivers 673 patches across 17 product families, with Fusion Middleware carrying five maximum-severity flaws.