Legal & Ethics
The line between defensive OSINT and abuse is use, not access. What follows keeps your work lawful, proportionate, and defensible.
Pre-investigation checklist
0/7Run through this before every engagement. Saved on your device.
| Country | Framework | Key |
|---|---|---|
| Mexico | PDP Law 2018 | Explicit consent for PII |
| Spain | LOPD-GDPR | Art. 6.1-f: legitimate interest (research) |
| USA | CFAA | No bypass to authentication |
| Europe | GDPR | DPIA if >1000 people |
| — | OSINT-Code-Ethics | No doxxing, no stalking, no data selling |
Ethical checklist ☐ Is the source 100% public? ☐ Is the data sensitive PII? → minimize ☐ Is there verifiable public interest? ☐ Can it be de-identified?
Not legal advice. Laws vary by jurisdiction and change often. When in doubt, consult a qualified professional before acting.