Open-source intelligence and due diligence unsettle people because of the phrase "data collection", which suggests something at the edge of the law. In reality the bulk of serious verification is reading what has already been published — by the state, by the courts, by regulators, and by the company itself. The question worth answering is not whether checking is legal, but which methods make it illegal.
The simplest way to take this apart is to split it in two. First: what may lawfully be collected about a counterparty. Second: what may not be done even in service of a legitimate purpose. Confusion usually starts here, because both halves are commonly discussed as one.
Public information and state registers are open by law. Reading them is not intrusion — it is use of what the state and the parties themselves made public. A company filed its data into a register, a court published a judgment, a sanctions authority compiled a list. Those exist to be consulted.
That category covers company and sole-trader records from the state register, ultimate beneficial owners, judgments from the court register, enforcement proceedings and debts, sanctions lists from Ukraine's NSDC register, OFAC, the EU, the UN and UK OFSI, public procurement data, publicly available leak datasets, satellite imagery, web archives and open profiles.
Depth here does not come from closed sources. It comes from the links between open ones. A register entry leads to a beneficiary, the beneficiary to their other companies, those to litigation and debts, the debts to attachments on property. Every step rests on a public record, and every step is documented with its source and date — which is what makes the result usable rather than merely interesting.
The other half of the work is knowing where not to go. The temptation is real: closed channels give a faster and more colourful result. But that speed is bought at a price you end up paying.
We do not break into accounts, mailboxes, databases or corporate systems, and we do not buy access to any of them. We do not conduct physical surveillance — no following, no covert filming, no movement tracking, no interception. We do not impersonate officials, bank staff, state bodies or the subject's own clients. We do not pay for "lookups", access to closed registers, or insider extracts from banks or telecom operators.
Commissioning anything from that list means one thing: the risk transfers to you. Data obtained unlawfully does not work as evidence — it works as evidence against you. Such material is legally dead before it reaches a hearing.
The logic of anyone selling a "lookup" is straightforward: they take the breach, you take the consequences. At the moment of purchase it looks convenient — fast, cheap, a finished result in hand. The bill arrives later, when that data has to be shown to someone.
For clients in the European Union the framework differs but the logic holds. The basis for processing is legitimate interest — Article 6(1)(f) GDPR. Counterparty due diligence before a transaction is a recognised legitimate purpose: a business is entitled to know who it is contracting with and where its money is going.
The key requirement is data minimisation. We take what bears on assessing risk in the specific transaction and do not collect surplus material "for later". That is not only a legal requirement but common sense: the less irrelevant content a report carries, the more usable it is.
A common misreading is that GDPR forbids checking a European counterparty. It does not. The Regulation does not prohibit processing — it requires a basis and a measure. The basis for a pre-transaction check exists, and the measure is something we hold ourselves: a defined purpose, a proportionate scope, a stated retention period, and the data subject's rights respected if they exercise them.
Ukrainian law works to the same shape. Access to public information and open registers is expressly permitted; processing of personal data is governed separately and demands minimisation, a lawful purpose and limited retention. A business check meets those conditions when the purpose is genuinely commercial.
The whole difference between lawful and arbitrary collection runs through purpose. Verifying a partner before transferring funds, a contractor before signing, a hired director before appointment — that is a documented commercial interest. Assembling a dossier on someone out of personal hostility, to pressure them or to interfere in their private life is not, regardless of how open the sources are.
This is why the purpose is fixed in writing before work starts, and why the client confirms that the report serves the protection of their own rights or interests rather than harassment or competitive harm. It is also why some mandates are declined.
This is the most frequent question: a company is one thing, a living person another. A prospective employee in a role with financial responsibility, a sole trader as a contractor, a private partner in a deal. In a commercial context, checking a person is lawful on the same two conditions — legitimate purpose, open sources.
An employer has a defensible interest in knowing who is being given access to money or goods; a principal has one in knowing who they are contracting with. We look at that person's public footprint: registers, court cases, sanctions lists, open profiles, professional history. What we do not do is examine private life that has no bearing on the commercial decision.
Some things are closed to everyone. Criminal records, the pre-trial investigation register and conviction data cannot be lawfully supplied by anyone. Where that question matters, it belongs in a direct request to the person, not in an intelligence report.
It is easy to assume these boundaries are our internal housekeeping and that a client only cares whether the information is there. That is not so. The method of collection determines whether you can use the result at all.
An unlawful "finding" damages you first. In a hearing it does not merely fail to help — it casts doubt on your entire position: if part of the material was gathered improperly, confidence drops across all of it. A lawfully assembled report behaves differently, because every statement carries a source that the other side can open and check.
This shows most clearly where a report passes someone else's scrutiny. A bank compliance officer, opposing counsel, a transaction auditor look not only at the conclusion but at where the facts came from. A report with clean provenance survives that reading. One with convenient but unexplainable data does not.
There are also limits inside the law. Even lawfully, intelligence is not omniscient: some data leaves no public trace at all. Where the answer does not exist in open sources, saying so is more useful than filling the gap with an inference.
Related reading: what the six-phase method looks like in practice, in how to verify a Ukrainian company, and what an evidentiary format requires, in due diligence evidence standards.
Open sources only, every fact documented with its source and date — a report that survives reading by a bank compliance officer, opposing counsel or an auditor.