Corporate Intelligence

Myths and Realities of Open-Source Intelligence (OSINT)

Myths and Realities of Open-Source Intelligence (OSINT)

Myths and Realities of Open-Source Intelligence (OSINT)

OSINT (Open Source Intelligence, or “white intelligence”) involves the lawful collection and analysis of information from publicly available sources, such as public records, the media, corporate data, and open sanctions databases. Contrary to popular belief, it does not involve hacking or surveillance. Its legality is governed by trade secrets, fair competition principles, and personal data protection regulations when analyzing data on individuals. Professional business intelligence allows for the identification of risks not visible in a financial audit, such as hidden capital ties, inclusion on sanctions lists, or the actual reputation of a company and its management.

Myth #1: OSINT is “hacking” or an activity that borders on illegality

Pop culture has cemented the image of the analyst as someone who breaks security measures and invades privacy. In reality, OSINT, by definition, relies exclusively on public and legally accessible sources: the National Court Register, CEIDG, electronic land registers, debtor registers, press publications, social media, and official sanctions databases. Passive methods—analyzing what is already publicly visible—do not violate the right to privacy or trade secrets, provided that the analyst does not cross the line set by Article 11 of the Act on Combating Unfair Competition, which protects trade secrets.

The real line is drawn elsewhere than pop culture suggests: not between “legal” and “illegal” data collection, but between simply viewing public information—which is legal—and its further processing, if it involves personal data. The collection, analysis, and storage of such data are subject to the strict requirements of the GDPR and require a specific legal basis, most often the controller’s “legitimate interest” in the context of business verification.

Myth #2: OSINT is the same thing as a credit bureau report

A standard BIG report shows debt and unpaid invoices—this is an important but limited part of the picture. An in-depth OSINT investigation goes further: it examines the counterparty’s capital ties, history of legal disputes, the online reputation of owners and key managers, presence on sanctions lists, and—in more advanced analyses—activity in harder-to-access spaces, such as industry forums or the dark web, in the context of data breaches.

This distinction has specific business implications. Screening a business partner against sanctions lists is not a mere formality—the Sanctions Act provides for penalties of up to 20 million zlotys for entities that cooperate with sanctioned individuals or companies, as well as criminal liability for the decision-maker who authorizes such cooperation. The verification should not be limited to the business partner alone—it is advisable to also include entities with which the partner has capital ties.

Myth #3: Due diligence and business intelligence are one and the same

Due diligence is a targeted analysis conducted prior to a specific transaction—such as a merger, acquisition, equity investment, or the establishment of a partnership. Market intelligence, in a broader sense, is a continuous process that encompasses the entire market and a company’s competitive environment, rather than just a single entity at a given moment. In practice, companies with a mature approach to risk use both mechanisms in parallel: ongoing market intelligence supplemented by ad hoc due diligence when a specific transactional decision arises.

Failing to consider any of these dimensions leads to an inaccurate assessment of the situation. Analyzing only “hard” data—financial and legal—without taking “soft” data (reputation, organizational culture, and the counterparty’s actual strategy) into account provides an incomplete picture, on which it is difficult to base a high-risk decision.

Myth #4: It's mainly a tool for spying on the competition

OSINT is often associated primarily with the offensive “spying” on market rivals. Meanwhile, its main use in companies is increasingly a defensive one: verifying one’s own attack surface. Analyzing a company’s digital footprint and that of its key employees, monitoring data leaks, and assessing the organization’s vulnerability to social engineering attacks allow a company to view itself through the eyes of a potential attacker—before someone with truly malicious intent does so.

This perspective—looking at an organization from the outside, as an attacker, competitor, or unscrupulous business partner would—is what distinguishes mature business intelligence from a quick “Google search.”

Delphi Consulting Group conducts business intelligence research and OSINT analysis for management teams and investors — using only legal sources.

Schedule a Consultation →

When a company really needs in-depth business intelligence

  • Prior to an M&A transaction or equity investment—identification of hidden liabilities, legal risks, and the entity’s actual financial condition in a format ready for presentation to the supervisory board.
  • When signing a significant contract with a new business partner, especially a foreign one—verify the partner’s registration, capital ties, and sanctions status.
  • If there is suspicion of a data leak or employee misconduct—identify the source of the leak and the individuals involved, while adhering to evidentiary standards.
  • When recruiting for sensitive positions—verify candidates within the limits strictly defined by labor law and the GDPR, without infringing on privacy beyond what is justified.
  • In compliance and KYC processes—OSINT as part of the customer due diligence required of financial institutions and regulated entities.

Where exactly do the boundaries of legal intelligence end?

Three principles define the actual boundary beyond which economic espionage ceases to be legal:

  1. A competitor’s trade secret —the analysis may be based solely on public and analytical sources, not on obtaining confidential information from a competitor.
  2. GDPR regarding personal data – simply viewing public data is legal, but its systematic processing requires a legal basis and a proportionate purpose.
  3. Passive versus active methods —thorough intelligence gathering is based on observation and analysis of open-source information, rather than on entrapment, impersonation, or inducing the disclosure of confidential information.

FAQ

Does checking a business partner on social media violate their privacy? Analyzing publicly available profiles and posts is legal; however, any further processing of that data—such as saving, cataloging, or combining it with other data—should have a clearly defined business purpose and a legal basis, in accordance with the GDPR.

How does OSINT differ from a standard KRS report? A registry report serves as a starting point, showing an entity’s formal legal status. OSINT adds an analytical layer: ownership ties, a history of disputes, reputation, and inclusion on sanctions lists—information that a registry extract alone will not reveal.

Can a company conduct OSINT on its own, or does it always need to rely on external intelligence? Basic verification can be conducted internally; however, in-depth analysis for high-risk transactions typically requires experience in interpreting signals that an untrained analyst might easily overlook or misjudge.

Delphi Consulting Group conducts business intelligence and OSINT analyses for management teams, investors, and funds—using only legal sources—and provides a report ready for presentation to the supervisory board.

Sources

  1. OSINTownia – OSINT Business Intelligence – How to Check a Business Partner Before Signing a Contract?osintownia.pl
  2. NORD-DETEKTYW – Business Intelligence and OSINT, detektywnord.pl
  3. BDR Detective Agency – Business Intelligence, detektyw.com.pl
  4. Protect Your PESEL – OSINT (Open-Source Intelligence) – What Is It, How Does It Work, and Who Uses It? chronpesel.pl
  5. Prawo.pl – White Papers Also Available to Lawyers, prawo.pl
  6. MIT Sloan Management Review Poland – From Intelligence Operations to the Boardroom: OSINT as Business’s Secret Weapon in the Age of Risk, mitsmr.pl
  7. Demagog.org.pl – Economic OSINT. Verification of foreign business partners, demagog.org.pl

← All Analyses

Do you have a question about this topic?

Let's discuss
your situation.

The initial consultation is complimentary and entails no obligation.

Schedule a Call →