Table of Contents

Author

Former British Army officer, trained in surveillance and target acquisition, and Bain and Company engagement manager, with more than a decade of experience working in consulting, private equity and venture capital across Western Europe.

A surprising amount of guidance aimed at OSINT investigators leads with laws that were never written for them. RIPA and the Investigatory Powers Act get cited constantly in articles about online investigation, and both are real, serious pieces of UK legislation — they just regulate public authorities, not private firms. For a due-diligence team, a corporate investigator, or anyone commissioning that work, knowing which rules actually bind the person doing the research matters as much as knowing the rules exist. Here's what genuinely applies, what doesn't, and what four real UK court cases show about how OSINT findings hold up once they reach a judge.

Key Takeaways

  • RIPA 2000 and the Investigatory Powers Act 2016 govern surveillance and communications-data access by public authorities — police, intelligence services, specified public bodies. They do not apply to a private investigator working for a private client, unless that investigator is specifically acting on a public authority's instructions.
  • What does bind a private OSINT practitioner: the Data Protection Act 2018 and UK GDPR, the Computer Misuse Act 1990, and the Human Rights Act's Article 8 privacy principle as it's applied by courts to private parties through the common-law tort of misuse of private information.
  • UK private investigators currently need no license to operate. The Security Industry Authority was given the power to regulate the sector in 2001; that power has never been brought into force.
  • Four real UK cases show the same pattern: social media evidence is now routinely relevant in court, and in each case the result turned on whether the evidence could be reliably attributed, properly obtained, and fairly used — not on whether it was found at all.
  • Everything here is jurisdiction-specific. This article covers UK law; a practitioner or client operating in another jurisdiction needs that jurisdiction's equivalent analysis, not this one applied by assumption.

The Laws Most OSINT Guides Get Wrong: RIPA and the IPA

RIPA 2000 and the Investigatory Powers Act 2016 are the two pieces of legislation most often cited in general OSINT writing, and they're also the two most often misapplied to private-sector work. RIPA creates a framework under which public authorities can authorise covert surveillance, use of covert human intelligence sources, and access to communications data, subject to oversight. The IPA 2016 extended and modernised that framework, adding judicial oversight to bulk-collection and equipment-interference powers used by law enforcement and the intelligence services.

Neither regulates a private investigator working for a private client. The scope is specifically public-authority conduct — RIPA's authorisation framework only reaches a private investigator where that investigator is engaged by, and acting on the instructions of, a public authority itself. A corporate due-diligence engagement, an insurance-fraud investigation commissioned by an insurer, or a pre-employment background check run for an employer sits outside it entirely. That's not a loophole — it means a different, and in some ways stricter, set of rules applies instead, covered below.

This distinction matters in practice, not just on paper: it's common to see private-investigation content cite RIPA as if it were the operative authority on what a private OSINT practitioner can and can't do, which can leave a reader with false confidence about a defence that doesn't exist for them, or false alarm about a restriction that doesn't apply to them either.

What Actually Governs Private OSINT Work in the UK

Data Protection Act 2018 and UK GDPR. This is the framework that matters most in practice. Anyone collecting, storing, or using personal data gathered through OSINT — including a private investigator or a due-diligence firm — is a data controller or processor under UK GDPR and subject to its core principles: a lawful basis for processing, purpose limitation, data minimisation, accuracy, storage limits, and security. The fact that information is publicly available does not remove these obligations; it affects which lawful basis applies and how a legitimate-interests assessment should be framed, not whether one is needed at all.

Computer Misuse Act 1990. This applies regardless of who's doing the investigating. It criminalises unauthorised access to computer systems and data, which is the clear line between searching what's already publicly indexed or accessible (legitimate OSINT) and attempting to get past a login, paywall, or access control to reach something that isn't (unauthorised access, a criminal offence). Scraping conducted in breach of a platform's terms of service isn't automatically a CMA offence, but it can expose a practitioner to other civil or contractual risk, and courts have treated platform rules as relevant context when weighing how information was obtained.

Human Rights Act 1998 — specifically Article 8. The HRA technically binds public authorities directly; a private investigator isn't a public authority and can't be sued under the Act itself. But Article 8's right to respect for private life has real teeth against private parties too, because UK courts have developed the tort of misuse of private information specifically to give Article 8 effect between private individuals and organisations. In practice, an OSINT practitioner who compiles and publishes or shares information someone had a reasonable expectation of privacy over can face a misuse-of-private-information claim even with no public authority anywhere in the picture. Article 10 (freedom of expression) and Article 6 (fair trial) matter on the other side of that balance, particularly for investigative or journalistic work and for how evidence gets used once a matter reaches court.

No mandatory license for the investigator doing any of this. The Private Security Industry Act 2001 gave the Security Industry Authority the power to license private investigators. That power has never been commenced — anyone can call themselves a private investigator in the UK with no licensing requirement at all. That makes the legal frameworks above, plus voluntary adherence to professional standards, the only real backstop a client has when evaluating a provider. It's a reasonable question to ask any firm doing this work, Molfar included: what governs you if not a license?

What UK Courts Have Actually Said: Four Cases

Legislation sets the boundaries; case law shows what happens when OSINT-sourced evidence actually reaches a judge. These four, all genuine UK cases, cover insurance fraud, employment disputes, and a criminal appeal — and the pattern across all four is the same: the evidence being online was never the issue; whether it could be reliably attributed, fairly obtained, and properly weighed was.

Locke v Stuart [2011] EWHC 399 (QB) — an insurance-fraud case where the defendant insurer's solicitors compiled three lever-arch files of Facebook research, mapping the friend networks of 28 people across a cluster of personal-injury claims, to argue the claims were part of a staged-accident ring rather than genuine, unconnected accidents. The case shows social-network mapping being used exactly the way a due-diligence or fraud investigation uses it today — not to find a single fact, but to demonstrate a pattern of connection between people who claimed not to know each other.

Smyth v St Andrew's Insurance Plc [2012] EWHC 2511 (QB) — a fire-insurance dispute where Facebook messages exchanged between a witness and another party, six days before trial, became part of the court's assessment of that witness's credibility. The messages themselves didn't decide the case; how a witness responded to being confronted, captured in writing, did. It's a useful reminder that social media evidence often matters less for what it shows directly and more for the behaviour it reveals once someone knows they're being watched.

Game Retail Ltd v Laws UKEAT/0188/14/DA — an employee was summarily dismissed after posting roughly 28 offensive tweets over a year on an account that a majority of the stores he was employed to monitor had come to follow. The original tribunal found the dismissal unfair; the Employment Appeal Tribunal allowed the employer's appeal and sent the case back for reconsideration, holding that the tribunal hadn't properly applied the "range of reasonable responses" test and that conduct can't be treated as purely private once an employee has knowingly let employer-connected accounts into their audience. The EAT explicitly declined to set a social-media checklist — every case remains fact-sensitive.

Bucknor v R [2010] EWCA Crim 1152 — a murder conviction was quashed on appeal because Bebo and YouTube material, used at trial to portray the defendant as a gang member, was admitted without the jury being properly directed on a basic problem: nobody could be sure the Bebo page was actually his, or that he had written what was on it. The Court of Appeal found the trial judge should have required the prosecution to address authorship under the hearsay provisions of the Criminal Justice Act 2003 rather than leaving the jury to assume it. This is the case that matters most directly for OSINT practice: a profile's content is only as useful as the certainty that the right person made it.

What This Means for OSINT Practice, Not Just the Law

Read together, these cases point at the same operational lesson Molfar applies to every piece of OSINT-sourced material before it goes into a client deliverable: a social-media post, profile, or document is a lead, and its evidentiary value depends entirely on whether authorship, timing, and context can be established with confidence. Bucknor shows what happens when that step is skipped. Locke and Smyth show what careful, pattern-based or context-aware use of the same kind of material looks like when it holds up — the same discipline we apply in reputational due diligence work, where a pattern of connections or behaviour matters more than any single post. Game Retail shows that even clearly-authored, clearly-public material still has to be weighed proportionately and in context, not treated as an automatic justification for the harshest available response — a standard that applies as much to pre-employment screening as it does to an employment dispute.

Which Law Applies to Which Activity

OSINT activity Law(s) that actually govern it Applies to private investigators?
Covert surveillance, communications-data access RIPA 2000, IPA 2016 No — public authorities only (unless acting on one's instructions)
Collecting, storing, or analysing personal data found via OSINT DPA 2018, UK GDPR Yes — applies to any data controller/processor, public or private
Accessing a system or account beyond what's publicly reachable Computer Misuse Act 1990 Yes — applies to anyone, regardless of sector
Compiling/publishing information with a reasonable expectation of privacy HRA 1998 Art. 8, via the common-law misuse-of-private-information tort Yes, indirectly — through the tort, not the Act itself
Using OSINT findings as evidence (employment, insurance, litigation) Common law / case law (see above) Yes — courts apply the same evidentiary standards regardless of who gathered it
Operating as an investigator at all Private Security Industry Act 2001 (licensing power) No mandatory license currently in force

Covert Online Profiles: Where the Ethics Get Harder

Using a non-attributable online profile to view material that isn't visible to a logged-out or unconnected viewer is a recognised OSINT technique, not an inherently improper one — but it carries real legal and evidentiary weight. A covert profile used to access content normally sits outside the Computer Misuse Act as long as no access control is actually circumvented (viewing what a platform serves to any logged-in user isn't unauthorised access), but it can breach a platform's terms of service, and — as Bucknor shows — material gathered this way faces a harder authorship and reliability test if it's ever relied on as evidence. A responsible practice, which is Molfar's own standard, documents the investigative rationale for using a covert profile before creating one, keeps a clear record of what was viewed and when, and treats anything gathered this way as requiring the same corroboration as any other unverified lead — arguably more, given how directly Bucknor shows this exact category of evidence can fail.

Frequently Asked Questions

Does RIPA apply to private investigators in the UK?

‍Only if the investigator is engaged by, and acting on the instructions of, a public authority. A private investigator working for a private client — a company, a law firm, an individual — isn't covered by RIPA's authorisation framework.

Do UK private investigators need a license?

‍No. The Security Industry Authority has had the legal power to license the sector since 2001, but that provision has never been brought into force, so anyone can operate as a private investigator in the UK without a license.

Can social media evidence actually be used in a UK court?

‍Yes, routinely — all four cases above involved social media or online material being considered by a UK court. What determines whether it's used well is whether authorship and context can be established, not whether it was found online.

Is viewing a public social media profile covered by the Computer Misuse Act?

‍No, as long as no access control is bypassed to see it. The CMA is about unauthorised access — getting past a login, password, or paywall you aren't entitled to pass. Viewing what's already visible to any member of the public, or to a legitimately-held account, isn't unauthorised access.

How does this relate to GDPR if the information is already public?

‍Public availability affects which lawful basis and legitimate-interests analysis applies — it doesn't remove the obligation. A UK GDPR data controller still has to handle personal data lawfully, proportionately, and securely, even when the source was open and public.

Turn Intelligence Into Action
Order a service
Order a service
Black Plus Icon

Recent posts

View all
View all
White Plus Icon
View all
View all
White Plus Icon
Gain the Clarity You Need to Move with Confidence

Let’s connect to explore how tailored intelligence can strengthen your decisions, reveal opportunities, and minimise uncertainty.