Investigations, OSINT

The Internet May Be Public. Your HR Investigation Still Has to Be Lawful

The Internet May Be Public. Your HR Investigation Still Has to Be Lawful

Published

·

12 Minutes

Updated

How open-source intelligence can strengthen workplace investigations without turning HR into a surveillance function

How open-source intelligence can strengthen workplace investigations without turning HR into a surveillance function

The screenshot looks decisive

A screenshot lands in HR’s inbox. It appears to show an employee making offensive comments about a client from an account bearing their name and photograph. The post is publicly visible, colleagues have begun sharing it and a senior manager wants the employee suspended immediately. At first sight, the evidence appears conclusive. It is online, it identifies the employee and it plainly creates a risk for the organisation.

The problem is that almost everything you actually need to know is still unknown. Is the account genuine? Is the screenshot complete? Was the comment taken in context? Does the employee even control the account? Before HR can answer those questions, it must first decide whether looking any further is lawful, proportionate and genuinely necessary.

These are not peripheral legal issues to be considered once the investigation is complete. They determine whether the evidence is reliable, whether the process is fair and whether the organisation is entitled to collect the information at all. Used properly, open-source intelligence can be one of the most valuable sources of evidence available to an investigator. Used carelessly, it can create privacy breaches, discrimination risk, false conclusions and lasting damage to trust.

OSINT is more than searching the internet

Open-source intelligence, usually abbreviated to OSINT, is intelligence produced by collecting, evaluating and analysing publicly available information to answer a defined question. Possible sources include social-media posts, professional profiles, websites, news archives, corporate registers, public regulatory decisions, forums and other material that can lawfully be accessed without circumventing security or privacy controls.

The important words are “answer a defined question”. Searching for evidence that an employee publicly disclosed a particular confidential document may be justifiable because it starts with an allegation and seeks information directly relevant to it. Searching an employee’s name in the hope of finding “anything concerning” is fundamentally different. The first is a line of enquiry; the second is a digital fishing expedition.

Finding information is also not the same as producing intelligence. A public profile may display an employee’s name, but that does not establish that the employee created or controlled it. A photograph may appear to show a particular person, but it may have been misidentified, edited or taken from another account. A genuine post can also be misinterpreted if the surrounding conversation has been removed. Information becomes useful intelligence only after it has been tested for relevance, provenance, reliability and context.

One of the things that has always interested me about investigations is that people often overestimate the value of information and underestimate the value of judgement. Finding another screenshot is relatively easy. Deciding whether it genuinely changes the evidential picture is much harder. That distinction is what separates investigation from internet searching.

For HR professionals, this distinction is critical. The purpose of an investigation is not to assemble the largest possible collection of material against an employee. It is to establish the relevant facts fairly and sufficiently well for the organisation to decide whether there is a case to answer and, if necessary, what should happen next.

Publicly accessible does not mean available for any purpose

One of the most persistent misconceptions about online investigations is that publicly accessible information is free from privacy and data protection restrictions. It is not. The fact that an employee has published information openly may affect their reasonable expectation of privacy, but it does not remove the employer’s obligations under the UK GDPR and the Data Protection Act 2018.

When an employer searches for, records, analyses or shares online information about an identifiable person, it is processing personal data. It therefore needs an appropriate lawful basis and must comply with the wider data protection principles, including fairness, transparency, purpose limitation, data minimisation, accuracy, security and storage limitation. The Information Commissioner’s Office specifically warns that information being publicly available does not automatically remove the individual’s right to be informed about its further use.

Private sector employers may sometimes rely on legitimate interests, but writing “legitimate interests” in an investigation plan does not make the processing lawful. The organisation should identify the interest being pursued, show why the processing is necessary, and balance that need against the employee’s rights and reasonable expectations. If the relevant question can be answered through a less intrusive method, the wider search may be difficult to justify.

Online searches also have a habit of revealing far more than the investigator intended to find. An employee’s profile may disclose political opinions, religious beliefs, trade union membership, health information, sexual orientation or biometric data. A search may also uncover allegations of criminal conduct or information about convictions. These categories are subject to additional legal protections, and their public visibility does not give an employer an unrestricted right to collect or use them.

The Data (Use and Access) Act 2025 introduced a recognised legitimate interests basis for certain specified purposes, including some safeguarding and crime prevention situations. It did not, however, create a general exemption for workplace investigations. The central question remains whether the particular processing is lawful, necessary, fair and proportionate.

Start with purpose, not with the search bar

A sound OSINT investigation begins by defining the allegation and translating it into a limited intelligence question. If an employee is suspected of sharing confidential information, the question might be whether a specified document appeared publicly, when it appeared and whether reliable evidence links the publication to that employee. It should not become a general examination of the employee’s character, relationships, beliefs or online history.

A clear purpose provides the boundary for the investigation. It tells the investigator which sources may be relevant, which information should be recorded and when the search should stop. Without that boundary, searches tend to expand as new information appears, even where it has little connection with the original allegation.

A useful way to structure the decision is through five tests: Purpose, Proportionality, Provenance, Procedural Fairness and Protection. Together, they provide a practical check on why the search is being undertaken, how far it should go, whether the material can be trusted, how the employee will be treated fairly and how the resulting information will be secured.

The purpose must also remain under review. If the search begins to reveal information about family members, protected characteristics or unrelated aspects of the employee’s private life, the investigator should pause and ask whether continuing remains necessary. Information should not be retained simply because it might conceivably become useful later. Relevance depends on whether it helps answer the questions set out in the terms of reference, not on how interesting it appears.

Proportionality should determine how far the investigation goes

The permissible scope of an OSINT search will depend on the seriousness of the issue and the risks involved. A credible threat to an employee’s safety may justify urgent and relatively extensive research. A dispute about an ill judged but minor comment is unlikely to justify the same degree of intrusion. Treating every allegation as grounds for a comprehensive search of an employee’s online life would risk normalising surveillance as a routine HR practice.

Proportionality requires the investigator to consider the importance of the objective, the likely intrusion, the availability of less intrusive evidence and the possible consequences for the individual. It also requires thought about collateral information. A search directed at one employee may expose details about their partner, children, friends or colleagues, none of whom is the subject of the investigation.

This does not mean that employers should avoid OSINT whenever it presents some privacy risk. It means that every step should be capable of explanation. An investigator should be able to say why a particular source was examined, how it related to the allegation and why a less intrusive method would not have been sufficient. If that explanation cannot be given, the search has probably gone too far.

Where the activity is systematic, covert, technologically novel or otherwise likely to create a high risk to individuals, a data protection impact assessment may be required. Even where a formal assessment is not mandatory, recording the purpose, necessity, risks and safeguards is sensible evidence of accountable decision making.

Digital evidence must be verified, not merely captured

Online material can look more conclusive than it really is. Screenshots are particularly persuasive because they appear to freeze an event in time, yet they can omit context, conceal edits and provide little reliable information about their origin. Accounts may be cloned, usernames recycled and images manipulated. Even genuine posts can be misunderstood where irony, quotation, replies or the wider conversation have been removed.

A defensible investigation should preserve more than the damaging extract. The evidence record should ordinarily include the source address, account identifier, visible publication date, date and time of collection, relevant surrounding content and the method by which the material was obtained. The investigator should also record whether the source was publicly accessible and what steps were taken to corroborate authorship or authenticity.

It is equally important to separate observation from inference. “The public profile displayed the employee’s name and photograph” is an observation. “The employee controlled the profile and wrote the post” is a conclusion requiring further support. That support might come from a consistent history of activity, information known independently to the organisation, an admission or other reliable evidence connecting the employee with the account. A name and photograph alone may not be enough.

The same discipline should apply to evidence that undermines the allegation. If a timestamp places the employee elsewhere, another account published the material first or the full exchange changes the apparent meaning, that information should be preserved and considered. An investigator who searches only for confirmation of the allegation is not conducting a balanced investigation, no matter how sophisticated the search techniques may be.

In practice, the most dangerous moment is often when the first apparently convincing result appears. That is when pressure builds to stop testing alternative explanations and start treating an allegation as established fact. A capable investigator should recognise that pressure and deliberately look for evidence that might disprove the emerging conclusion.

The Berkeley Protocol on Digital Open Source Investigations was developed for a different investigative context, but its central disciplines are highly relevant: plan the investigation, evaluate sources, preserve material properly, verify before relying upon it and maintain a clear record of how conclusions were reached. Workplace investigations may operate on a different scale, but they should not be amateur simply because the evidence was found online.

Employment law still governs the decision

OSINT does not create a separate legal test for misconduct. In an unfair dismissal case, the familiar principles remain central: did the employer genuinely believe that misconduct occurred, did it have reasonable grounds for that belief and had it carried out as much investigation as was reasonable in the circumstances? The tribunal will then consider whether the employer acted reasonably under section 98(4) of the Employment Rights Act 1996, including whether the decision fell within the range of reasonable responses.

The social-media authorities reinforce this fact sensitive approach. In Game Retail Ltd v Laws, the Employment Appeal Tribunal declined to create a special legal test for dismissals involving social media. In British Waterways Board v Smith, material posted on Facebook contributed to a fair dismissal, but the outcome rested on the employer’s investigation, policies and decision making. It did not establish a rule that public posts automatically justify disciplinary action.

An employer must therefore consider the connection between the online conduct and the employment relationship. Relevant factors may include whether the employee or employer was identifiable; whether clients or colleagues were affected; whether confidentiality or safety was compromised; the employee’s role and seniority; the wording of relevant policies; the actual or potential harm; consistency with previous cases; and any mitigation offered by the employee.

The employee must also have a meaningful opportunity to answer the evidence. That includes challenging whether the account belongs to them, whether the material is complete, whether the interpretation is correct and whether the conduct has any genuine connection with work. Presenting an employee with a predetermined conclusion and asking them to comment will not repair an investigation that has already ceased to be impartial.

Article 8 of the European Convention on Human Rights may also be relevant where an employer relies on personal communications or material in which the employee had a reasonable expectation of privacy. Garamukanwa v United Kingdom demonstrates that this expectation depends on the context and nature of the material. It should not be reduced to a simple rule that public evidence is usable and private evidence is not.

Why good investigations matter strategically

Good investigations build trust. Bad investigations damage it. If employees believe the organisation will search indiscriminately through their digital lives, trust is eroded. If they believe serious allegations will not be investigated properly, trust is equally damaged. Ethical OSINT sits between those two extremes.

This balance matters beyond the immediate case. An investigation communicates what the organisation means by fairness, how seriously it takes evidence and whether its stated values survive contact with a difficult decision. Leaders may focus on the legal risk of getting the outcome wrong, but the wider organisational risk often comes from losing confidence in the process.

A well governed investigation cannot guarantee that everyone will agree with the outcome. It can, however, demonstrate that the organisation asked the right questions, considered competing explanations and reached a conclusion it can explain. That is an important source of institutional credibility.

Practical applications in HR investigations

OSINT can be particularly helpful where allegations move between the workplace and public digital spaces. If a confidential board paper appears on a public forum, open-source research may help establish when it was published, whether it appeared elsewhere first and whether credible evidence links the account to an employee. A username resembling the employee’s name should be treated as a lead, not proof, and the investigation should remain focused on the disclosure rather than expanding into years of unrelated activity.

It may also assist in cases involving harassment or intimidation. Where an employee reports that a colleague has targeted them through public posts, the online material may help establish chronology, repetition and a connection with the workplace. The investigator must nevertheless distinguish between public posts they locate, private messages provided by the complainant and material obtained from another authority. Each may raise different questions about provenance, privacy, disclosure and evidential weight.

Safety concerns can require a faster response. If a public post appears to threaten a named manager or workplace, the organisation may need to preserve the material, conduct an immediate risk assessment and involve security professionals or the police. Urgency may justify protective action, but it does not justify treating the allegation as proven. The organisation should distinguish between managing an immediate risk and determining responsibility through a fair process.

These examples illustrate why OSINT should be treated as one evidential resource among several. It can provide context, identify further lines of enquiry and test competing accounts, but it should rarely be allowed to carry the entire investigation without corroboration.

AI makes verification more important, not less

Artificial intelligence can help investigators organise large volumes of material, identify possible duplicates, translate content and suggest connections that merit examination. Used carefully, these capabilities may reduce administrative time and allow the investigator to concentrate on analysis. They do not remove the need for human judgement.

AI tools can fabricate sources, merge the identities of different people and present uncertain associations as established facts. They may also remove comments from their original context or reproduce biases present in the source material. An apparently polished AI summary can therefore create false confidence precisely where greater scepticism is needed.

No factual finding should be based on an automated summary that has not been checked against the underlying evidence. Investigators should also understand what happens to information submitted to an AI service, particularly where it includes confidential allegations or personal data. Material use of automated tools should be recorded, appropriate security controls applied and a human investigator should remain accountable for every conclusion.

The more powerful the technology becomes, the more important it is to ask a narrow question, preserve the original evidence and maintain an intelligible audit trail.

Knowing when to stop is an investigative skill

One of the clearest differences between proportionate investigation and surveillance is the existence of a stop point. An investigator should stop when the defined question has been answered, when additional searches are unlikely to produce necessary evidence or when the search is moving into irrelevant aspects of the employee’s private life. They should also pause where identity cannot be verified, special category information is becoming central or specialist legal, security or data protection advice is required.

There should be equally clear boundaries around investigative methods. HR practitioners should not create false identities, circumvent privacy settings, ask colleagues to access restricted profiles or use unlawfully obtained data. They should not confuse technical possibility with professional authority. Such methods materially change the legal and ethical character of the investigation.

The quality of an OSINT investigation is not measured by how much the investigator can uncover. It is measured by whether they found what was necessary, tested it properly and resisted collecting what they did not need.

Building ethical OSINT into investigation governance

Organisations that expect investigators to use online evidence should establish the rules before a difficult case arises. Their investigation and data protection arrangements should explain who can authorise open-source research, when it may be used, how its scope will be documented and when the Data Protection Officer, legal advisers or a specialist investigator must be involved. Privacy notices and social-media policies should reflect the organisation’s actual practices rather than making sweeping claims that employees can be monitored without limit.

Investigators need practical controls as well as policy language. A proportionate search plan, evidence log, retention period and restricted access location will do more to protect the process than a generic statement about complying with the UK GDPR. Training should cover verification, confirmation bias, equality risks, evidence preservation and the distinction between fact and inference. Employees should then be given an appropriate opportunity to challenge online material before it contributes to an adverse finding.

These controls are sometimes dismissed as bureaucracy. In reality, they protect the organisation’s ability to rely on the evidence. A properly governed process is more likely to withstand scrutiny because it shows not only what the organisation found, but why it was entitled to look for it and how it tested its reliability.

The standard HR investigations should meet

OSINT can strengthen workplace investigations. It can help test conflicting accounts, establish chronology, preserve material that might otherwise disappear and identify evidence unavailable from internal systems. It can also expose an organisation to legal, ethical and evidential risk if it becomes an excuse to search indiscriminately through an employee’s private life.

The answer is not to avoid digital evidence. It is to apply the standards that should govern every serious investigation: a clear purpose, proportionate methods, reliable evidence, an open mind and a fair opportunity to respond. Public information must still be handled lawfully, and apparently compelling material must still be tested.

Ultimately, this is not simply a question of what an investigator can find. It is a question of decision quality when the evidence is incomplete, the consequences are significant and several explanations remain possible. That is where professional judgement matters most.

Before relying on open-source material, the investigator should be able to answer one final question: would I be comfortable explaining this search, this evidence and these safeguards to the employee, the ICO and an Employment Tribunal?

If the answer is no, the investigation is probably not ready.


Publication note

This article provides general information, not legal advice. The appropriate approach will depend on the facts, the organisation’s policies, the nature of the data and the legal basis for processing. The scenarios are anonymised composites.


Authoritative Sources

ICO: Employment practices and data protection: monitoring workers — https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/employment/monitoring-workers/

ICO: Right to be informed; publicly available information and Article 14 — https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/individual-rights/individual-rights/right-to-be-informed/

ICO: Lawful basis guidance — https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/lawful-basis/a-guide-to-lawful-basis/

ICO: Special category data guidance — https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/lawful-basis/a-guide-to-lawful-basis/special-category-data/

ICO: Data Protection Impact Assessments — https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/accountability-and-governance/data-protection-impact-assessments-dpias/

Acas: Investigations at work: step-by-step — https://www.acas.org.uk/investigations-for-discipline-and-grievance-step-by-step

Acas: Discipline and grievances at work guide — https://www.acas.org.uk/sites/default/files/2024-08/discipline-and-grievances-at-work-the-acas-guide.pdf

Legislation.gov.uk: UK GDPR — https://www.legislation.gov.uk/eur/2016/679

Legislation.gov.uk: Data Protection Act 2018 — https://www.legislation.gov.uk/ukpga/2018/12/contents

GOV.UK: Data (Use and Access) Act 2025: data-protection changes — https://www.gov.uk/guidance/data-use-and-access-act-2025-data-protection-and-privacy-changes

Employment Appeal Tribunal: Game Retail Ltd v Laws UKEAT/0188/14/DA — https://www.gov.uk/employment-appeal-tribunal-decisions/game-retail-ltd-v-mr-c-laws-ukeat-0188-14-da

Employment Appeal Tribunal: British Waterways Board v Smith UKEATS/0004/15/SM — https://assets.publishing.service.gov.uk/media/58ef6373e5274a06b3000194/The_British_Waterways_Board_trading_as_Scottish_Canals_v_Mr_David_Smith_UKEATS_0004_15_SM.pdf

European Court of Human Rights: Garamukanwa v United Kingdom — https://hudoc.echr.coe.int/eng?i=001-193839

OHCHR / UC Berkeley: Berkeley Protocol on Digital Open Source Investigations — https://www.ohchr.org/en/publications/policy-and-methodological-publications/berkeley-protocol-digital-open-source

CIPD: People analytics factsheet: monitoring and surveillance — https://www.cipd.org/en/knowledge/factsheets/analytics-factsheet/

Your People Team Ltd


cases@yourpeopleteam.co.uk
www.yourpeopleteam.co.uk
LinkedIn

Navigation

Home
Services
Insights
Meet the Team
Contact
Legal

Lawrence Jell FCIPD
Founder & Managing Director
Chartered Fellow of the Chartered Institute of Personnel and Development
Member of the Institute of Directors

© 2026 Your People Team Ltd
Your People Team Ltd is registered in England and Wales. Company number 17238512. Registered office: Yew Tree Farm, Thornhill Road, South Marston, Swindon, England, SN3 4RY.