- Learn
- Align
- Perform
- Review
AlignIntelligence Operations, part 7 of 98 min read
Navigating the Gray Areas: Ethics, Privacy, and Legal Compliance in Intelligence
By J Damien Scott, Trusted Advisor
The difference between effective intelligence gathering and an unlawful invasion of privacy often hinges on how data is collected and subsequently used, not merely what data is collected. A Protective Intelligence program that operates without strict ethical and legal guardrails is not a security asset; it is a liability.
The foundational tension: duty of care vs. privacy rights
Every corporate security program rests on a legal and moral foundation known as the duty of care. This principle requires organizations to take reasonable steps to protect their employees, clients, and the public from foreseeable risks of harm. However, this duty exists in permanent tension with employee and individual privacy rights.
The resolution is not a matter of choosing one value over the other. In the United States, the federal baseline is established by the Electronic Communications Privacy Act. At the state level, California’s CCPA requires that employee monitoring be reasonably necessary and proportionate. For organizations operating internationally, GDPR applies to the personal data of any EU-based employee or subject regardless of where the collecting organization is headquartered.
“Intelligence that cannot be defended in court, disclosed to a regulator, or explained to a board of directors is not intelligence; it is a liability.”
The principle of proportionality
Proportionality requires that the intrusiveness of intelligence collection be commensurate with the severity and credibility of the threat being investigated. Collecting everything available is not a security strategy; it is a liability. A practical framework involves three sequential questions: Is there a legitimate business purpose tied to a documented risk? Is the proposed method the least intrusive means of answering the intelligence question? Does the scope of collection cease once that question is answered?
Consider a concrete example. An anonymous social media account posts vague complaints about corporate leadership. Launching a full-scale OSINT investigation would be disproportionate. However, if that same account subsequently posts specific, credible threats directed at a named executive’s home address, the severity justifies a substantially more intensive collection effort. Proportionality is not a fixed threshold; it scales with the threat.
Governance: the structural solution
The complexities of privacy law, investigative ethics, and proportionality assessment cannot be managed through individual analyst judgment on a case-by-case basis. They require structural governance embedded in the program’s design. A mature Protective Intelligence program establishes clear written policies that define acceptable sources and methods, require documented approval for sensitive collection activities, and set strict retention and deletion schedules.
Organizations that treat ethics and legality as core operational principles, rather than administrative afterthoughts, produce intelligence that leadership can trust when the stakes are highest. A legally sound, ethically grounded Protective Intelligence program is, by definition, a more effective one.
Originally published on LinkedIn. Read it there
Field Notes · by email
One email when a new article publishes. Nothing else.
Field notes on converged security from J Damien Scott, Trusted Advisor: the article, its summary, and the phase it belongs to. No digests, no offers, no third party reading over your shoulder.
Email delivery is being set up. The feed carries every article the day it publishes. About Field Notes
Related reading
More from Align
Learn · January 2026
Moving "Left of Boom": The Strategic Value of Protective Intelligence
Executive targeting incidents doubled in 2025. A corporate security program that relies solely on gates, guards, and guns is not just outdated. It is a critical vulnerability. Protective intelligence moves the organization left of boom by identifying, assessing, and dismantling threats before they cross the threshold of the enterprise.
7 min readAlign · January 2026
The Intelligence-Led Executive Protection Detail
The era of the visible deterrent is over. The modern executive protection detail must evolve from a logistics-heavy guarding function into a dynamic, intelligence-driven operation. It is no longer about how close you stand to the principal. It is about how far ahead you can see.
8 min readLearn · January 2026
Decoding the Pathway to Violence: Behavioral Threat Assessment in Corporate Settings
Targeted violence is rarely spontaneous. It is the result of an understandable, evolving, and often discernible process of thinking, behavior, and preparation. Understanding the Pathway to Violence allows corporate security programs to identify warning behaviors and intervene before an attack occurs.
9 min read