← Argus Intel · Ukraine due diligence
Legality 29 August 2026 · 8 min read · Argus Intel

Is it legal to check a counterparty? Where the line runs in OSINT and due diligence

Open-source intelligence and due diligence unsettle people because of the phrase "data collection", which suggests something at the edge of the law. In reality the bulk of serious verification is reading what has already been published — by the state, by the courts, by regulators, and by the company itself. The question worth answering is not whether checking is legal, but which methods make it illegal.

The simplest way to take this apart is to split it in two. First: what may lawfully be collected about a counterparty. Second: what may not be done even in service of a legitimate purpose. Confusion usually starts here, because both halves are commonly discussed as one.

What can be collected entirely lawfully

Public information and state registers are open by law. Reading them is not intrusion — it is use of what the state and the parties themselves made public. A company filed its data into a register, a court published a judgment, a sanctions authority compiled a list. Those exist to be consulted.

That category covers company and sole-trader records from the state register, ultimate beneficial owners, judgments from the court register, enforcement proceedings and debts, sanctions lists from Ukraine's NSDC register, OFAC, the EU, the UN and UK OFSI, public procurement data, publicly available leak datasets, satellite imagery, web archives and open profiles.

Depth here does not come from closed sources. It comes from the links between open ones. A register entry leads to a beneficiary, the beneficiary to their other companies, those to litigation and debts, the debts to attachments on property. Every step rests on a public record, and every step is documented with its source and date — which is what makes the result usable rather than merely interesting.

What must not be done — and why it is not about speed

The other half of the work is knowing where not to go. The temptation is real: closed channels give a faster and more colourful result. But that speed is bought at a price you end up paying.

We do not break into accounts, mailboxes, databases or corporate systems, and we do not buy access to any of them. We do not conduct physical surveillance — no following, no covert filming, no movement tracking, no interception. We do not impersonate officials, bank staff, state bodies or the subject's own clients. We do not pay for "lookups", access to closed registers, or insider extracts from banks or telecom operators.

Commissioning anything from that list means one thing: the risk transfers to you. Data obtained unlawfully does not work as evidence — it works as evidence against you. Such material is legally dead before it reaches a hearing.

The logic of anyone selling a "lookup" is straightforward: they take the breach, you take the consequences. At the moment of purchase it looks convenient — fast, cheap, a finished result in hand. The bill arrives later, when that data has to be shown to someone.

The GDPR basis for EU clients

For clients in the European Union the framework differs but the logic holds. The basis for processing is legitimate interest — Article 6(1)(f) GDPR. Counterparty due diligence before a transaction is a recognised legitimate purpose: a business is entitled to know who it is contracting with and where its money is going.

The key requirement is data minimisation. We take what bears on assessing risk in the specific transaction and do not collect surplus material "for later". That is not only a legal requirement but common sense: the less irrelevant content a report carries, the more usable it is.

A common misreading is that GDPR forbids checking a European counterparty. It does not. The Regulation does not prohibit processing — it requires a basis and a measure. The basis for a pre-transaction check exists, and the measure is something we hold ourselves: a defined purpose, a proportionate scope, a stated retention period, and the data subject's rights respected if they exercise them.

Ukrainian law works to the same shape. Access to public information and open registers is expressly permitted; processing of personal data is governed separately and demands minimisation, a lawful purpose and limited retention. A business check meets those conditions when the purpose is genuinely commercial.

The purpose is what decides it

The whole difference between lawful and arbitrary collection runs through purpose. Verifying a partner before transferring funds, a contractor before signing, a hired director before appointment — that is a documented commercial interest. Assembling a dossier on someone out of personal hostility, to pressure them or to interfere in their private life is not, regardless of how open the sources are.

This is why the purpose is fixed in writing before work starts, and why the client confirms that the report serves the protection of their own rights or interests rather than harassment or competitive harm. It is also why some mandates are declined.

Does this extend to individuals?

This is the most frequent question: a company is one thing, a living person another. A prospective employee in a role with financial responsibility, a sole trader as a contractor, a private partner in a deal. In a commercial context, checking a person is lawful on the same two conditions — legitimate purpose, open sources.

An employer has a defensible interest in knowing who is being given access to money or goods; a principal has one in knowing who they are contracting with. We look at that person's public footprint: registers, court cases, sanctions lists, open profiles, professional history. What we do not do is examine private life that has no bearing on the commercial decision.

Some things are closed to everyone. Criminal records, the pre-trial investigation register and conviction data cannot be lawfully supplied by anyone. Where that question matters, it belongs in a direct request to the person, not in an intelligence report.

Why legality is about your safety, not our comfort

It is easy to assume these boundaries are our internal housekeeping and that a client only cares whether the information is there. That is not so. The method of collection determines whether you can use the result at all.

An unlawful "finding" damages you first. In a hearing it does not merely fail to help — it casts doubt on your entire position: if part of the material was gathered improperly, confidence drops across all of it. A lawfully assembled report behaves differently, because every statement carries a source that the other side can open and check.

This shows most clearly where a report passes someone else's scrutiny. A bank compliance officer, opposing counsel, a transaction auditor look not only at the conclusion but at where the facts came from. A report with clean provenance survives that reading. One with convenient but unexplainable data does not.

There are also limits inside the law. Even lawfully, intelligence is not omniscient: some data leaves no public trace at all. Where the answer does not exist in open sources, saying so is more useful than filling the gap with an inference.

Frequently asked questions

Is it legal to check a counterparty?
Yes, when two conditions hold: the purpose is legitimate and the sources are open. State registers, court judgments, sanctions lists, procurement data and public leak datasets exist to be consulted. What makes a check unlawful is the method — hacking, surveillance, purchased "lookups", access to closed databases or impersonation.
What is the legal basis for an EU client?
Legitimate interest under Article 6(1)(f) GDPR. Counterparty due diligence before a transaction is a recognised legitimate purpose. The Regulation does not prohibit processing; it requires a basis and a measure — so scope is limited to what bears on risk in the specific transaction, retention is defined, and data subject rights are respected.
Does GDPR forbid checking a European counterparty?
No. That is a common misreading. GDPR requires a lawful basis and proportionality, both of which a pre-transaction check satisfies. What it does rule out is collecting surplus material "for later", indefinite retention, and processing that serves no genuine commercial purpose.
Is it lawful to check an individual rather than a company?
In a commercial context, yes, on the same two conditions. An employer has a defensible interest in knowing who is given access to money or goods, and a principal in knowing who they contract with. The check covers the person's public and business footprint, not private life unrelated to the decision. Criminal records and conviction data are closed to everyone and cannot lawfully be supplied.
Why does it matter how the data was obtained?
Because the method determines whether you can use the result. Unlawfully obtained material does not merely fail as evidence — it undermines your whole position, since doubt about part of the file spreads to all of it. A report with clean provenance survives scrutiny by a bank compliance officer, opposing counsel or a transaction auditor; one with unexplainable data does not.

Related reading: what the six-phase method looks like in practice, in how to verify a Ukrainian company, and what an evidentiary format requires, in due diligence evidence standards.

Counterparty checks from $149

Open sources only, every fact documented with its source and date — a report that survives reading by a bank compliance officer, opposing counsel or an auditor.

See pricing →