
Article
OSINT: What You Can Find Out — and What Others Already Know About You
Open source intelligence isn't a manhunt toolkit. It's a method for verifying information under pressure — and for measuring your own exposure. European legal framework included.
An industrial fire breaks out three kilometres from your home.
Within twenty minutes your feed contains: a spectacular video, two accounts claiming a toxic plume is heading for the town centre, an official statement saying the opposite, and a photo that clearly belongs to a different fire. You have to decide now: shelter in place, evacuate, or do nothing.
That's the real use case for OSINT — open source intelligence. Not tracking an individual: the ability to establish, within minutes and from public sources, what is actually true.
This article covers the verification method, what European law permits and forbids, and the part most content skips entirely: what those same techniques reveal about you.
What OSINT is, and what it isn't
OSINT is a methodology: collecting, cross-checking and exploiting freely accessible information — press, social media, public records, satellite imagery, company registries.
It is neither hacking nor access to protected systems. The boundary is sharp and it is legal: the moment you have to bypass a protection, guess a password or exploit a flaw, you leave OSINT and enter criminal territory.
Three legitimate uses for a civilian:
- Verify information during a crisis, before acting on it.
- Understand an environment — a neighbourhood, a route, a nearby industrial risk.
- Protect yourself by measuring your own exposure surface.
A fourth use exists, the one that fills YouTube: finding and tracking people. It's out of scope here, and usually outside the law.
What European law says — and the misunderstanding that costs
The misunderstanding fits in one sentence: the fact that information is publicly accessible gives you no rights over it.
In Europe, as soon as you collect and retain information about an identifiable person — even found freely online — you are processing personal data under the GDPR. That implies a legal basis, a defined purpose, data minimisation, and a retention period. National data protection authorities put it plainly: reusing publicly available information isn't prohibited in principle, but it must respect fairness of collection, legal basis and purpose limitation.
Two important carve-outs for a private individual:
Strictly personal and household use falls outside the GDPR. Verifying information to decide whether to evacuate your home has nothing to do with building a file on someone. The switch happens the moment you retain, structure or publish.
Non-personal data — the location of an industrial site, weather history, satellite imagery of an area, a repeater's frequencies — raises no issue at all. Most preparedness-relevant OSINT falls into this category.
Where the doors close, however:
- Publishing what you found about a person can amount to defamation, invasion of privacy, or distribution of data that identifies or locates them.
- Identifying a target in order to harass them is a criminal offence in its own right, whatever the legality of each individual step.
- Mass scraping of personal data, even public, leaves the household exemption and engages your liability.
The practical rule fits in one question, asked before every search: what decision will this information help me make? If the answer isn't immediate, the search has no purpose — and purpose limitation is exactly what the law enforces.
The method: four questions before believing anything
In a crisis, the hard part isn't finding information. It's discarding nine tenths of it. Four questions, in this order.
1. Who is posting, and how old is the account?
An account created three days ago, with no history, posting something spectacular about an unfolding event: treat it as non-existent until confirmed. Conversely, an old specialised account that gets something wrong remains useful — a regular's mistake gets corrected, a fresh account's fabrication propagates.
2. Is this image actually from this event?
The most common form of disinformation, and the easiest to dismantle: a real photo, of a real event — but from another place or another year. Reverse image search settles most cases in thirty seconds. Check several engines: they don't index the same databases.
3. Where and when was it filmed?
This is the heart of the discipline: geolocation and chronolocation. You match the fixed elements in the frame — terrain, rooflines, signage, vegetation, shadow direction — against satellite imagery and available street-level views. The sun's position gives a time window; the state of the vegetation, a season.
It's laborious, and that's exactly what makes it reliable: a geolocated element no longer depends on anyone's word.
4. What does the official source say, and what does it not say?
Local authorities, the site operator, emergency services. These sources are slow and cautious, often behind social media. But they carry legal liability, which no anonymous account does. Good practice: treat social media as an early sensor, and the official source as validation.
The reflex that sums it all up: before sharing, stop. Find out who is behind it, what other sources say, and trace back to the original information rather than whoever relayed it. Thirty seconds of pause removes most of what circulates.
The part nobody covers: your own exposure
Turn the method on yourself. It's the most useful exercise in this article, and the only one that is unambiguously legal: you are the data subject.
Your photos. An image published from home may carry GPS coordinates in its metadata. Even stripped, the background is often enough: a window view, a street number, a recognisable shopfront. The photo of your gear taken on your balcony locates you better than your address does.
Your habits. A running app publishing your routes maps your home, your workplace and your schedule within three weeks. The problem isn't one outing, it's the regularity.
Your public records. Company registries, directories, electoral rolls depending on the country, old personal sites, forgotten accounts: the accumulation builds a profile that no single element revealed.
Your breaches. Your email addresses are probably in compromised databases. Check on a dedicated service — free and instant — and change the affected passwords.
The exercise, one hour, once a year: search for yourself. Name, handles, email addresses, phone number. Reverse image search on your profile picture. Note what surfaces, and what can be removed. You will almost certainly find something you had forgotten.
The limits, and the classic mistake
What OSINT gives you: fast verification, an understanding of the terrain, a measure of your exposure, and the habit of not relaying just anything.
What it doesn't give you: certainty. Information corroborated by three sources that all copy the same origin isn't corroborated at all — it's one source, repeated. Always trace back to the origin.
The classic beginner's error is confirmation bias: searching until you find what you already suspected. The discipline is to state the opposite hypothesis and actively look for what would support it. If you never find anything contradicting your conclusion, it isn't that you're right — it's that you're searching badly.
Intelligence isn't a collection of information. It's an answer to a question you took the trouble to formulate before starting.
Where to actually start
- Formulate the question before opening a browser. "Is the plume heading for my neighbourhood?" is a question. "What's going on?" is not.
- Practise cold. Geolocate a holiday photo — your own. The skill is built on stakes-free cases, never during the crisis.
- Build your list of local official sources — authorities, nearby industrial operators, emergency services — before you need it. In a crisis you don't look for an official account, you already have it.
- Archive what matters. A page can vanish within hours. Web archiving services freeze a page at a given moment.
- Run your annual exposure audit (previous section). It's the best benefit-per-hour action in this whole article.
This capability complements, without replacing, the other two pillars: communications that hold when networks fail and the equipment system you actually carry.
Conclusion
OSINT that is useful to a civilian isn't a tracking toolkit. It's a hygiene: formulate a question, search methodically, doubt what suits you, know the legal framework, and know what you yourself are exposing.
The highest-return skill in this entire article requires no software and no subscription: the thirty-second pause before sharing information you haven't verified.
Formulate the question. Trace back to the origin. Look for what contradicts you.
Sources and further reading
- Mathias Avocats — OSINT: overview of the main legal issues (in French) — the French DPA's position on reusing public information and GDPR obligations.
- Village de la Justice — What is the legal framework of OSINT? (in French) — step-by-step analysis: collection, retention, republication, evidential value.
- CNPD Luxembourg — OSINT and GDPR compliance — a data protection authority's dossier on civil and private OSINT use.
- Bellingcat — First Steps to Getting Started in Open Source Research — the global reference for open source investigation.
- Bellingcat — Online Investigation Toolkit — inventory of verification, mapping and archiving tools.
- Berkeley Protocol on Digital Open Source Investigations — the reference methodological and ethical protocol (Berkeley Human Rights Center and the United Nations).