Curriculum / Module 2

Ethics and law

The boundaries of lawful, ethical open-source research: access, privacy, harm, and when to stop.

50 min

2.1 Why ethics comes first

Open-source research is about the world, and the world is full of real people. Every technique in this course can be used to inform or to harm. Mistakes are not abstract: a wrong identification can lead strangers to harass an innocent person, and a careless post in a war zone can put lives at risk.

One effect deserves special attention. Facts that are harmless one at a time can become dangerous when combined. A first name, a gym check-in, a photo of a street and a school logo are each unremarkable; together they can reveal where a person lives and when they are alone. This is often called the mosaic effect, and it is why "each piece was public" is never a complete defence.

2.2 Public is not a permission slip

Something being accessible tells you that you can see it. It does not tell you that you should collect it, keep it or publish it. Before collecting information about a person, ask:

  • Is it necessary? Does it help answer the requirement, or is it just interesting?
  • Is it proportionate? Is the intrusion justified by what is at stake?
  • Would the person reasonably expect this use? A post written for friends is not written for an intelligence report.
  • Could the result harm someone who has done nothing wrong?

If you cannot answer these well, do not collect it.

2.3 Lawful access: what this course does not teach

This course teaches research using information as it is published. It does not teach any of the following, and SITREP's Terms of Service and Community Guidelines forbid several of them on SITREP itself (for example scraping without permission, fake accounts, and locating a private person):

  • bypassing logins, paywalls, rate limits or other technical access controls
  • using someone else's credentials, or guessing private links and addresses
  • exploiting software vulnerabilities
  • deceiving people, for example with false identities, to join closed groups or obtain information
  • buying, downloading or redistributing hacked, leaked or stolen data
  • tracking or following a private individual, online or offline

Many countries have laws against unauthorised access to computer systems, and they can apply even when the information behind the control seems harmless. Platform terms of service also matter: breaking them can close your accounts and, in some places and circumstances, carry legal consequences. Automated collection (scraping) in particular should be cleared with counsel before you start.

2.4 Privacy and personal data

Many legal systems protect personal data even when it has been made public. For example, the European Union's General Data Protection Regulation (GDPR) applies to personal data whether or not it was published by the person it describes. Rules vary, but a set of principles appears in most data protection frameworks, and they are good practice everywhere:

PrincipleIn practice
Lawful basisKnow why you are allowed to process this data at all.
Purpose limitationCollect for a stated purpose and do not reuse it for unrelated ones.
Data minimisationCollect only what the requirement needs. Leave the rest.
AccuracyCorrect or delete what turns out to be wrong.
Storage limitationDecide in advance how long you keep it, then delete it.
SecurityProtect what you keep from loss and unauthorised access.

Some categories of information need extra care in most frameworks and in any ethical practice: health, sexual life or orientation, religious or political beliefs, ethnic origin, biometric data, and anything about children. If your research touches these, slow down and seek advice.

2.5 Assessing harm before you publish

Before you publish or share a finding, work through the ways it could hurt someone.

  • Misidentification. Two people can share a name, a face or a car. Never name a private individual on the strength of a single match, and be slow to name anyone.
  • Doxxing. Never publish a private individual's home address, family members, workplace or daily routine. On SITREP, locating a private person or a private home is never allowed: geolocation proposals whose reasoning names one or contains contact details are refused, and staff remove any others.
  • Victims and graphic material. Protect the dignity of people who are hurt or killed. Blur faces and identifying details where you can, warn readers before distressing content, and share no more of it than the purpose requires.
  • Sources at risk. The person who filmed an event may be in danger if you credit them by name. Weigh attribution against their safety.
  • Amplification. Repeating a false claim, even to debunk it, can spread it further. Quote the minimum needed.
  • Allegations. Saying that a person or organisation did something wrong, without adequate evidence, can cause serious harm and can create legal liability, such as a defamation claim. Attribute claims, state your confidence and ask counsel before publishing serious allegations.

Public figures acting in their public role are open to more scrutiny than private individuals. That difference is one of degree: it does not remove the duty to be accurate and fair.

2.6 Armed conflict: no live positions

In an armed conflict, information about where people and equipment are right now can get people killed. Never share, publish or geolocate:

  • the current or recent position or movement of military units, equipment or personnel
  • where civilians are sheltering or evacuating
  • the routes or timings of humanitarian convoys

Delay, generalise or leave it out. SITREP applies the same rule: community geolocations in active conflict areas are held for review before anyone else sees them, and military positions never appear on the community map.

2.7 Other people's content

Photos, videos and writing belong to someone. Copyright and related rules apply to open sources as much as to anything else.

  • Prefer linking to the original over re-uploading it.
  • Credit the creator when it is safe to do so (see 2.5 on sources at risk).
  • Quote and show only what your purpose needs.
  • Ask counsel before commercial reuse of other people's material.

2.8 A pre-publication checklist

Before you share a finding, you should be able to answer yes to each of these:

  1. Every piece of information was obtained lawfully, as published, without deception.
  2. I collected only what the requirement needed, and I know when I will delete it.
  3. I have checked for misidentification and have not named a private individual on thin evidence.
  4. Nothing reveals a private individual's home, family, workplace or routine.
  5. Nothing reveals a live position or movement in an armed conflict.
  6. Distressing material is minimised, blurred where possible and flagged.
  7. Allegations are attributed, supported and phrased with calibrated confidence.
  8. Sources and creators are credited, unless crediting would endanger them.

Escalate to a lawyer when research involves children, sensitive categories of personal data, serious allegations against identifiable people, leaked material that someone else has published, moving personal data across borders, or any doubt about whether access was lawful.

Module 1: Foundations of PAI and OSINTTake the module 2 quiz

Next: Module 3: OPSEC for researchers