All guides
Outbound & Prospecting 11 min read

LinkedIn Matched Audiences: Thresholds and the Law

LinkedIn Matched Audiences' 300 thresholds, why 300 rows never suffice — and the GDPR threshold before them: joint controllership under EDPB 8/2020.

LC
Founder, CegTec · 15 September 2026

A LinkedIn contact list rarely fails because someone misunderstood the mechanics. It fails at thresholds — and there are two kinds of them, which are rarely considered together. One sits in the product documentation and decides whether the campaign serves. The other sits in the guidelines of the European Data Protection Board and decides whether the list was allowed to be uploaded at all.

The second one comes first. Skip it and you have, at best, a campaign that runs — and at worst, one that runs and should not have.

The technical thresholds

LinkedIn states the limits in its own help page on contact list targeting. They are unremarkable until you notice that two of them measure different things.

ThresholdValueWhat it actually checks
Rows for the uploadat least 300Whether the file is accepted
Matched member accountsat least 300Whether the campaign serves
Recommended list sizeat least 10,000 addressesWhether the 300 matches are reliably reached
Maximum list size20 MB or 300,000 recordsHard ceiling per upload
Processing timeup to 48 hours, rarely longerWhen the audience becomes available
Formatemail in plain text or as a SHA-256 hashUnhashed is hashed locally in the browser

The first two rows carry the same number and mean different things. 300 rows is a file requirement. 300 matched member accounts is a serving requirement, and LinkedIn states it expressly as independent of how many addresses the list contains.

A list with exactly 300 rows will therefore upload cleanly, produce no error — and never serve. It would need a match rate of 100 percent.

The three-percent assumption inside the recommendation

It gets interesting when you put the floor and the recommendation side by side. LinkedIn requires 300 matches and recommends uploading at least 10,000 addresses in order to reach them.

300 out of 10,000 is three percent.

That is not a measured match rate, and it would be wrong to quote it as one. It is the planning assumption the provider itself works with when it has to issue a recommendation that holds for every list — including the worst ones. The practical value lies exactly there: planning against this floor rather than an optimistic estimate produces a list that still serves when your own data quality turns out worse than you thought.

Your own rate will usually be considerably higher. But it is a number you measure — upload the list, read off the matched accounts, form the ratio — not one you take from a blog post. The spread of published match rates is wide enough that any single one of them is useless as a planning basis.

The same applies to the ageing of contact data. That B2B lists decay is uncontested; the annual rates in circulation range from just over 22 percent to more than 70 percent, depending on the survey, the industry and the definition. No plan can be derived from a spread that wide. The robust figure is your own: re-upload the same list after a defined interval and compare the matched accounts. That measures your own decay instead of assuming someone else’s.

The threshold that comes before all technical ones

Uploading a contact list is not a configuration step in data protection terms. It is a transfer of personal data to a third party — and the European Data Protection Board addressed precisely this operation in its Guidelines 8/2020 on the targeting of social media users (version 2.1 of 7 July 2021). Section 5.2.2 describes it as “list-based targeting”: the targeter uploads pre-existing lists of personal data, and the platform matches them against its own records.

Three findings from it are decisive in practice.

First: you are a joint controller, not a client

The Board finds that joint controllership exists between platform and targeter — for a clearly named section of the processing: uploading the identifiers, the matching, the selection of targeting criteria, the subsequent display of the advertisement, and any reporting relating to the campaign. The wording in the guidelines is unambiguous: joint controllership exists “as regards the use of list-based targeting”.

This is not a theoretical finding. It follows the line the Court of Justice of the European Union drew in its judgments on Facebook fan pages (Case C-210/16, Wirtschaftsakademie Schleswig-Holstein, judgment of 5 June 2018) and on the Like button (Case C-40/17, Fashion ID, judgment of 29 July 2019): whoever participates in determining purposes and means is a controller — even without having access to the data themselves.

The practical consequence: you need an arrangement under Art. 26 GDPR, and the allocation of roles in it should reflect who actually steers what.

One distinction the Board draws straight away matters: for the original collection of the addresses you remain the sole controller. The platform plays no part in it. Joint controllership begins with the transmission and ends, in most cases, with the reporting.

Second: legitimate interest does not carry automatically

The guidelines work with two examples that read almost verbatim as a test scheme — and that map exactly onto the two cases that become contentious in practice.

In the first case, a person contacts a bank once to arrange an appointment, then decides against the service — and their address is nevertheless used for the full range of services on offer. Here the Board rejects Art. 6(1)(f) GDPR as a viable basis: there is no reasonable expectation on the part of the data subject that their data will be used for targeting, and a compatibility test under Art. 6(4) GDPR would likely find the processing incompatible with the purpose of collection.

In the second case, the person has been a customer for almost a year, was informed at the moment of collection that their address might be used for advertising services they already use, and was able to object from the outset. Here the Board considers a legitimate interest possible — expressly resting on three features: the information given at the time of collection, the similarity of the advertised services to those already used, and the prior ability to object.

The difference between the two cases does not lie in the technology. It lies in what the person was told when their address was collected.

Third: adding a paragraph to the privacy notice is not enough

This point is regularly overlooked, and it is the sharpest of the three. The Board makes clear that fulfilling the information duties under Art. 13 and 14 GDPR and performing the balancing of interests under Art. 6(1)(f) GDPR are two separate sets of obligations. And further: the mere fulfilment of information duties is not a transparency measure to be taken into account in the balancing in the controller’s favour.

So adding a paragraph on social media targeting to the privacy notice fulfils an information duty. It does not thereby improve the balancing. Both have to be reasoned and documented separately.

And what hashing does not achieve

LinkedIn accepts email addresses in plain text or as a SHA-256 hash; unhashed addresses are hashed locally in the browser. That is a sensible technical safeguard and may count positively in the balancing.

But it changes nothing fundamental: a hash built in order to recognise a person on a platform is a pseudonymous identifier, not an anonymous one. Recognisability is its purpose. The processing remains processing of personal data, and no legal basis becomes dispensable because of it.

Decision aid: may this list go up?

Six questions, before the upload, in this order. The first four are legal, the last two technical — because a list that is not legally permitted is still not permitted when it has 50,000 rows.

  1. Where do the addresses come from, and what was said at the moment of collection? If the answer is “from the CRM” and nobody remembers what was communicated at entry, that answers question 2 as well.
  2. Was the person informed at collection about use for social media advertising, and could they object? Two of the three features on which the Board bases a possible legitimate interest arise at collection — not later.
  3. Does the planned advertising relate to services this person already uses or has enquired about? That is the third feature. The further the advertised service sits from the existing relationship, the weaker the balancing holds.
  4. Is there an arrangement under Art. 26 GDPR, and is the balancing documented? Both are obligations in their own right. The balancing is not satisfied by the privacy notice mentioning the operation.
  5. At a three percent match, does the list still come out above 300 accounts? At the provider’s floor that means roughly 10,000 addresses. Anyone going below should know they are betting on an above-average match rate.
  6. Has time been allowed for up to 48 hours of processing? The audience is not available immediately. For campaigns with a fixed start date, that belongs in the backward planning.

Anyone who lands, on questions 1 to 3, at a well-maintained existing-customer segment that was properly informed at collection has the simplest case. Anyone who lands at a purchased or enriched list has the case the first EDPB example was written for.

What this means for list maintenance

A way of working follows from these thresholds that differs from the usual one.

Segment the list by collection context, not by company size. What matters for the balancing is what the person was told when their address was captured. Keeping segments by collection source — existing customer with notice, inbound enquiry, trade fair contact, enriched — lets you answer questions 2 and 3 per segment rather than per individual. It is the only cut that makes the legal review scalable.

Measure and log the match rate; do not estimate it. Both numbers are visible at upload: rows uploaded and accounts matched. Noting them per segment gives you a robust in-house metric after three uploads — and you no longer need anyone else’s.

Measure decay at the repeat upload. Re-upload the same list after a defined interval and compare the matched accounts. That is the only route to a decay rate that holds for your own database.

Treat the 20 MB limit as a prompt to segment, not as a problem. 300,000 records per upload is, for most DACH audiences, beyond the relevant market anyway. Anyone hitting it usually has a scoping problem, not a size problem.


Not legal advice. This text summarises publicly available guidelines and case law and does not replace legal advice in an individual case. The assessment depends on your specific collection context; for binding guidance, consult a lawyer. Use at your own risk.

Which channel requires which consent — email, phone, LinkedIn, post — is set out together in our channel matrix for promotional outreach. How to derive a target segment from won deals instead of assumptions is covered in deriving your ICP from closed-won.

If you would rather run audiences, list maintenance and campaign control in one place than spread across four tools: GTM Goat can be tried free for four weeks.

Sources

  • European Data Protection Board, Guidelines 8/2020 on the targeting of social media users, version 2.1, 7 July 2021 — section 5.2.2 (list-based targeting), roles, legal basis and allocation of responsibility
  • CJEU, Case C-210/16, Unabhängiges Landeszentrum für Datenschutz Schleswig-Holstein v Wirtschaftsakademie Schleswig-Holstein GmbH, judgment of 5 June 2018 — joint controllership for Facebook fan pages
  • CJEU, Case C-40/17, Fashion ID GmbH & Co. KG v Verbraucherzentrale NRW e.V., judgment of 29 July 2019 — joint controllership for embedded social plugins
  • LinkedIn Marketing Solutions Help, Contact list targeting in Campaign Manager — thresholds, formats and processing time
  • LinkedIn Marketing Solutions Help, Requirements for company targeting lists — thresholds for company lists
LinkedIn AdsMatched AudiencesABMGDPRAudiences

Common questions

What is the minimum number of contacts a LinkedIn contact list needs?

There are two different thresholds, and confusing them is the most common mistake. For the upload itself, LinkedIn requires at least 300 rows. For a campaign to actually serve, at least 300 member accounts have to be matched from that list — regardless of how many email addresses it contains. A list with exactly 300 rows can therefore upload successfully and still never serve, because not all 300 will match.

How large should the list realistically be?

LinkedIn's own documentation recommends at least 10,000 email addresses in order to reliably reach the 300 matched accounts. Put both numbers side by side and you have the provider's own planning assumption: 300 out of 10,000 is three percent. That is not a measured match rate but the conservative floor LinkedIn plans with — your own rate will usually be higher, but it is a number to measure rather than estimate.

Does hashing the email addresses change the GDPR obligation?

Not the legal basis. A SHA-256 hash of an email address is a pseudonymous identifier, not an anonymous one: it is built precisely so that it can be recognised and assigned to a person — that is the purpose of the match. The processing therefore remains processing of personal data. Hashing is a technical safeguard that can count in the balancing test; it does not replace a missing legal basis.

Who is the controller when I upload a list?

Both — you and LinkedIn, as joint controllers. In Guidelines 8/2020 the European Data Protection Board expressly finds that joint controllership exists between targeter and platform for list-based targeting, covering the upload of identifiers, the matching, the selection of targeting criteria, the display of the advertisement and any campaign reporting. From that follows the obligation to have an arrangement under Art. 26 GDPR. The original collection of the addresses, by contrast, remains your sole responsibility.

Does legitimate interest carry the upload of a customer list?

Sometimes — and the EDPB guidelines offer two examples that read almost as a test. Against legitimate interest: someone made contact once, then expressly declined, and their address is nevertheless used for the full range of services. There is no reasonable expectation for that. In favour: the person is already a customer, was informed at the moment of collection about precisely this use, the advertising relates to services similar to those they already use, and an objection was possible from the outset.

Is it enough to add a paragraph to the privacy notice?

No, and this is a subtle but consequential point in the guidelines: fulfilling the information duties under Art. 13 and 14 GDPR and performing the balancing of interests under Art. 6(1)(f) GDPR are two separate sets of obligations. The Board states expressly that the mere fulfilment of information duties is not a transparency measure to be taken into account in the balancing test. Adding a paragraph to the privacy notice fulfils a duty; it does not win the balancing.

Playbooks für B2B Outbound freischalten

Kostenlos. E-Mail eintragen → Passwort erhalten → Playbooks lesen.