Arsenly_OSINTby XowiaLabs

Legal & Ethics

The line between defensive OSINT and abuse is use, not access. What follows keeps your work lawful, proportionate, and defensible.

Pre-investigation checklist

0/7

Run through this before every engagement. Saved on your device.

Country Framework Key
Mexico PDP Law 2018 Explicit consent for PII
Spain LOPD-GDPR Art. 6.1-f: legitimate interest (research)
USA CFAA No bypass to authentication
Europe GDPR DPIA if >1000 people
OSINT-Code-Ethics No doxxing, no stalking, no data selling

Ethical checklist ☐ Is the source 100% public? ☐ Is the data sensitive PII? → minimize ☐ Is there verifiable public interest? ☐ Can it be de-identified?


Not legal advice. Laws vary by jurisdiction and change often. When in doubt, consult a qualified professional before acting.