Are LinkedIn messages private? What recruiters need to know
Are LinkedIn messages private? Find out who sees your messages, how visibility works in Recruiter, and how to protect sensitive candidate data under UK GDPR.

Technically private, but functionally public if screenshotted. Never send generic spam that a candidate would mock on their public feed. Reputation is key.
As a recruiter, you send messages on LinkedIn every day. Connection requests, InMails, follow-ups, salary negotiations. But how private are those messages, really? Are LinkedIn messages private? The short answer: they're shielded, but not watertight. And if you work from a Recruiter seat, the situation is more complex than you might think.
In this article, we explain exactly who can see your LinkedIn messages, how visibility works within LinkedIn Recruiter, and what the GDPR rules mean for UK recruiters.
Who can see my LinkedIn messages?
LinkedIn messages are, in principle, only visible to the sender and the recipient. Other users, your connections, your followers or random LinkedIn members, have no access to your inbox. That applies to regular messages, InMails and group messages (where, naturally, every group member can read along).
But there are a few important exceptions.
LinkedIn itself can read your messages
LinkedIn uses TLS encryption (Transport Layer Security) for messages in transit. That protects against interception by third parties. But there is no end-to-end encryption. That means LinkedIn itself is technically able to read messages. They do this in specific cases:
- Enforcing the terms of service: when a report comes in about spam, harassment or other misuse.
- Spam detection: automated systems scan messages for suspicious patterns.
- Court orders: if a government authority or court demands access, LinkedIn is legally required to cooperate.
- Product improvement: LinkedIn can use anonymised message data to train algorithms.
Practical advice: write every LinkedIn message as if it could one day become public. No sensitive information about candidates, no internal rejection reasons, no salary details. Use an encrypted channel such as email or phone for that kind of communication.
Can my employer see my LinkedIn messages?
No. Your employer has no access to your personal LinkedIn messages. LinkedIn does not share this data with employers or IT departments, even if you use LinkedIn on a company network. This is protected under UK GDPR (and the Data Protection Act 2018).
But be aware: if you send messages from a LinkedIn Recruiter seat paid for by your employer, the situation is different. More on that in the next section.
Visibility within LinkedIn Recruiter
This is where it gets interesting for recruiters. Within LinkedIn Recruiter, messages are not as private as you might think. Visibility depends on your role and the settings at contract level.
Admin vs. regular seat holder
LinkedIn Recruiter has two roles with different visibility levels:
- Admin seat holders see all seat holders on the contract, their jobs, shared projects and recruiting activity on candidate profiles.
- Regular seat holders see each other's recruiting activity and shared projects, but not each other's private notes (unless the "Public Notes Viewer" permission is switched on).
InMail visibility settings
Admins can set the default InMail visibility at contract level. This determines whether fellow recruiters can see the InMails you send. Only the author of a message can change the visibility setting afterwards.
So always check your contract's settings. If the default is set to "visible to the team", your colleague reads along with every message you send. That can be useful for collaboration, but awkward if you're having confidential conversations with candidates.
Delegated Inbox
With the Delegated Inbox feature, you can give a colleague access to your inbox. That colleague can then read your conversations and reply on your behalf. Replies are sent from their own account, but they see your full message history.
Only use this feature when it's genuinely necessary, for example while you're on holiday. And let candidates know if someone else is managing your inbox.
Screenshots and forwarding
LinkedIn offers no screenshot detection. Unlike Snapchat or Instagram, LinkedIn doesn't send a notification if someone takes a screenshot of your message. The recipient is therefore free to copy, screenshot or forward your message.
This also applies after you delete a message. If the recipient has already read or screenshotted your message before you delete it, it's too late.
Note: messages you've sent via InMail or regular messages remain visible to the recipient, even if you delete your LinkedIn account. Once sent, it's sent.
GDPR and candidate privacy for UK recruiters
As a UK recruiter, you work under UK GDPR. This has a direct impact on how you use LinkedIn messages in your recruitment process.
Can you just approach candidates via LinkedIn?
Yes, under certain conditions. If a candidate has a public LinkedIn profile, you can rely on legitimate interest as your lawful basis for processing. That applies especially when the profile makes clear that the person is open to new opportunities, for example via the "Open to Work" badge or an explicit mention of what they're looking for.
But you do need to meet a number of conditions:
- You approach the candidate with a relevant opportunity that matches their profile.
- You offer a simple way to object to further contact.
- You document your lawful basis in advance.
Retention periods for candidate data
Data you gather from LinkedIn, whether profile information or message history, falls under your responsibility as a data controller. UK GDPR requires that you don't keep personal data for longer than necessary.
In practice, many agencies apply a retention period of a maximum of 1 year after the last contact. Document your retention periods and make sure you have a process for deleting data once that period expires.
Candidate rights
Under GDPR, candidates have the right to:
- Access: what data you hold about them.
- Rectification: correction of inaccurate data.
- Erasure: deletion of their data once there is no longer a lawful basis for processing it.
- Objection: stopping any further contact.
If a candidate requests deletion, you must action this within 30 days. That applies to your ATS, your email and your LinkedIn notes.
Practical tips for recruiters
Based on everything above, here's a concrete checklist:
- Check your InMail visibility settings in LinkedIn Recruiter. Know who's reading along.
- Don't send sensitive information via LinkedIn. Salary negotiations, medical information or internal feedback don't belong in a LinkedIn message.
- Use personalised connection requests instead of generic templates. That's better not just for privacy, but for your response rate too.
- Document your GDPR processes. Prove that you know what data you process, why, and for how long.
- Tell candidates if someone else has access to your inbox via Delegated Inbox.
- Be careful with screenshots. Assume that anything you write could be shared.
Are LinkedIn messages safe enough for recruitment?
LinkedIn messages are shielded from other users and offer basic protection through TLS encryption. For most recruitment communication, that's sufficient. But it's not an end-to-end encrypted channel, and within Recruiter contracts, visibility is broader than many recruiters realise.
The bottom line: LinkedIn messages are technically private, but functionally semi-public. Your colleagues can read along, screenshots can't be prevented, and LinkedIn itself has access. Treat every message with the professionalism you'd expect if it ever became public. That's not just better for your privacy, it's better for your employer brand too.
Keep your outreach reputation flawless?
Elvatix ensures every message you send is highly personalised and respectful, completely eliminating the "spam risk" to your brand.

