1. Learn
  2. Align
  3. Perform
  4. Review

AlignIntelligence Operations, part 7 of 98 min read

Navigating the Gray Areas: Ethics, Privacy, and Legal Compliance in Intelligence

By J Damien Scott, Trusted Advisor

The difference between effective intelligence gathering and an unlawful invasion of privacy often hinges on how data is collected and subsequently used, not merely what data is collected. A Protective Intelligence program that operates without strict ethical and legal guardrails is not a security asset; it is a liability.

The foundational tension: duty of care vs. privacy rights

Every corporate security program rests on a legal and moral foundation known as the duty of care. This principle requires organizations to take reasonable steps to protect their employees, clients, and the public from foreseeable risks of harm. However, this duty exists in permanent tension with employee and individual privacy rights.

The resolution is not a matter of choosing one value over the other. In the United States, the federal baseline is established by the Electronic Communications Privacy Act. At the state level, California’s CCPA requires that employee monitoring be reasonably necessary and proportionate. For organizations operating internationally, GDPR applies to the personal data of any EU-based employee or subject regardless of where the collecting organization is headquartered.

Intelligence that cannot be defended in court, disclosed to a regulator, or explained to a board of directors is not intelligence; it is a liability.

The principle of proportionality

Proportionality requires that the intrusiveness of intelligence collection be commensurate with the severity and credibility of the threat being investigated. Collecting everything available is not a security strategy; it is a liability. A practical framework involves three sequential questions: Is there a legitimate business purpose tied to a documented risk? Is the proposed method the least intrusive means of answering the intelligence question? Does the scope of collection cease once that question is answered?

Consider a concrete example. An anonymous social media account posts vague complaints about corporate leadership. Launching a full-scale OSINT investigation would be disproportionate. However, if that same account subsequently posts specific, credible threats directed at a named executive’s home address, the severity justifies a substantially more intensive collection effort. Proportionality is not a fixed threshold; it scales with the threat.

Governance: the structural solution

The complexities of privacy law, investigative ethics, and proportionality assessment cannot be managed through individual analyst judgment on a case-by-case basis. They require structural governance embedded in the program’s design. A mature Protective Intelligence program establishes clear written policies that define acceptable sources and methods, require documented approval for sensitive collection activities, and set strict retention and deletion schedules.

Organizations that treat ethics and legality as core operational principles, rather than administrative afterthoughts, produce intelligence that leadership can trust when the stakes are highest. A legally sound, ethically grounded Protective Intelligence program is, by definition, a more effective one.

GRCProportionalityDuty of care vs. privacyGovernance frameworks

Originally published on LinkedIn. Read it there

Field Notes · by email

One email when a new article publishes. Nothing else.

Field notes on converged security from J Damien Scott, Trusted Advisor: the article, its summary, and the phase it belongs to. No digests, no offers, no third party reading over your shoulder.

Email delivery is being set up. The feed carries every article the day it publishes. About Field Notes