Your Face Is in the Database. You Put It There.
Here's how the OSINT discussion usually starts, whether it's in a graduate seminar or an IR team's Slack channel: I can see it in a browser without logging in, so it's fair game. That logic is intuitive, consistent, and deeply, reliably wrong. It fails for several independent reasons, and the failure mode isn't theoretical—it's the kind of thing that ends careers and cases.
The legal term for why that intuition fails is the aggregation problem. Individual data points can be entirely innocuous in isolation: a home address from public property records, a workplace from a LinkedIn profile, a daily schedule assembled from social media check-ins, a vehicle description from an Instagram photo, a children's school from a Facebook post celebrating a school play. None of those items, standing alone, creates a meaningful privacy concern. Combined, they produce a comprehensive surveillance profile that no single platform intended to enable, and that the subjects of those posts almost certainly never contemplated when they shared them. The Supreme Court put its finger on this directly in Carpenter v. United States (2018), when it held that the government's acquisition of cell-site location data required a warrant—rejecting the third-party doctrine argument that Carpenter had "shared" his location with the carrier and therefore surrendered his privacy interest in it. Courts are increasingly willing to treat aggregated digital data as deserving greater protection than any of its component parts, and the logical extension of Carpenter into the OSINT context has barely begun to be litigated. That's a feature of the developing law, not a reassurance.
The federal legal framework every OSINT practitioner needs to understand runs through three statutes: the Computer Fraud and Abuse Act (CFAA), the Stored Communications Act (SCA), and the Wiretap Act. They create independent liability. Compliance with one does not guarantee compliance with the others, and most practitioners who get into trouble don't think they were doing anything wrong under any of them.
The CFAA's central question for OSINT practice—when does accessing publicly available data become "unauthorized access"—got partially resolved in Van Buren v. United States (2021), when the Supreme Court held 6-3 that "exceeds authorized access" means accessing data you're not entitled to see, not using accessible data for an unauthorized purpose. Van Buren meaningfully narrowed the CFAA's reach, and hiQ Labs v. LinkedIn (2022) extended that reasoning to suggest that scraping publicly visible data likely doesn't violate the statute. Those are real developments, and practitioners should understand them. They should also understand what didn't get resolved: whether creating a fake account to bypass access controls constitutes unauthorized access, whether automated scraping at scale changes the analysis, and whether a cease-and-desist letter from a platform operator transforms the authorization picture entirely. On that last point, the case law is consistent—once you're told to stop and you continue, the legal calculus shifts dramatically against you. "No one has been prosecuted for this" is not a legal strategy.
The deception problem sits at the center of the most uncomfortable conversations in this area. Sock puppet accounts—fake personas created to monitor targets, join private groups, or follow subjects who've restricted their public visibility—are technically straightforward to create and operationally tempting in investigations where a subject has locked down their profile. They're also legally and ethically fraught in ways that practitioners routinely underestimate. The CFAA question after Van Buren is unsettled: if the gate is "up" because you logged in, but you logged in using a fabricated identity, did you have "authorization"? Platform Terms of Service universally prohibit fake accounts, which creates independent civil liability exposure. State anti-pretexting statutes may apply. Evidence obtained through deception faces admissibility challenges. For law enforcement practitioners, the DOJ's Attorney General Guidelines govern online undercover operations, and the entrapment doctrine travels seamlessly from physical to digital environments. For commercial IR practitioners operating outside the Fourth Amendment's constraints, the absence of a legal ceiling doesn't substitute for having an ethical floor. The engagement letter should define OSINT scope. The client should authorize aggressive collection techniques. Someone should be responsible, by name and in writing, for approving the sock puppet before it goes live.
Facial recognition tools bring a distinct layer of legal exposure, and the consent problem they surface is one of the more instructive in the field. When a practitioner uploads a subject's photo to Clearview AI and searches against a database of reportedly 30-plus billion images scraped from social media, the underlying database was built from photos that people posted to share with friends and family—not to be enrolled in a permanent biometric surveillance infrastructure. The Illinois Biometric Information Privacy Act (BIPA) requires informed written consent before any biometric identifier collection, including face geometry, and it carries a private right of action with statutory damages of $1,000 per negligent violation and $5,000 per intentional one. Facebook's BIPA settlement ran to $650 million. Clearview's ACLU settlement required restrictions on commercial sales. Texas's $1.4 billion resolution with Meta over facial recognition should disabuse anyone of the notion that biometric privacy exposure is academic. There is no comprehensive federal biometric privacy statute yet—but the patchwork of state laws and the EU AI Act's classification of real-time biometric surveillance as "high risk" means that the legal obligations an OSINT practitioner carries depend heavily on where the subjects of that search happen to be located.
The international dimension of OSINT practice is where many practitioners are most dangerously underprepared. The GDPR applies to the processing of personal data on EU and EEA residents regardless of where the processor is located—and collecting personal data from public sources is processing under GDPR, full stop. Public availability of data does not create an exemption. Canada's PIPEDA, Brazil's LGPD, China's Personal Information Protection Law, and Australia's Privacy Act each have their own frameworks and enforcement postures, and the Five Eyes intelligence-sharing architecture means evidence collected in one jurisdiction can end up in the hands of authorities in another. Jurisdictional complexity is the norm in modern OSINT practice. Treating it as someone else's problem is a reliable way to turn a completed engagement into a compliance incident.
There's a principle I put on the screen at the beginning of this lecture that bears genuine weight: legal compliance is the floor, not the ceiling. Something can be entirely legal and profoundly unethical. Something that is common practice in the field can be both simultaneously. The question a practitioner should ask before any OSINT collection is not just "can I?" but "should I?"—and the answer to that second question has to be grounded in necessity, proportionality, and accountability. Collect what the investigation requires. Use methods proportionate to the seriousness of the matter. Document the methodology, the authorization chain, and the disposition of every piece of data collected, so the work can be reviewed and challenged by anyone who needs to. If a screenshot of what you're about to do appeared in a courtroom, a deposition, or a news story, would you be comfortable defending it?
If the answer is no—or even "maybe"—that's the answer.
This post is the eighth in a series based on my course, DFOR 671: Topics of Ethics and Law in Computer Forensics, that I have taught at George Mason University for the past fifteen years. Over the series of articles, I'll be looking at the ethical, legal, and practical issues that sit underneath the work: bias, candor, privacy, professional responsibility, reporting, courtroom credibility, incident response pressure, and the messy human realities that never seem to fit neatly into a checklist.
First published on LinkedIn.