Skip to main content
This content is for educational use only. Misuse of OSINT techniques for illegal activities, harassment, or violation of privacy is strictly prohibited and may result in legal consequences.
The following table summarizes the key legal frameworks that govern OSINT activities across jurisdictions. Understanding these requirements is mandatory before conducting any investigation.
CountryFrameworkKey requirement
MexicoPDP Law 2018Explicit consent for PII
SpainLOPD-GDPRArt. 6.1-f: legitimate interest (research)
USACFAANo bypass to authentication
EuropeGDPRDPIA if >1000 people
OSINT-Code-EthicsNo doxxing, no stalking, no data selling

Ethical checklist

Before conducting any OSINT investigation, verify each of the following items:
  • Is the source 100% public?
  • Is the data sensitive PII? → minimize
  • Is there verifiable public interest?
  • Can it be de-identified?

Build docs developers (and LLMs) love