mirror of
https://github.com/Jieyab89/OSINT-Cheat-sheet.git
synced 2026-07-28 14:47:03 -07:00
fix hyperlink
This commit is contained in:
@@ -55,17 +55,16 @@ Contains information about OSINT tips, write up usage resouces and more tips abo
|
||||
- Law Enforcer
|
||||
- General
|
||||
|
||||
# Legal Consider and Law International
|
||||
|
||||
## Legal & Ethical Considerations for OSINT
|
||||
# Legal Considerations and International Law for OSINT
|
||||
|
||||
| Country / Region | Legal Framework | Key Legal Considerations | OSINT / PII Implications |
|
||||
|------------------|-----------------|--------------------------|---------------------------|
|
||||
| **Indonesia 🇮🇩** | **Personal Data Protection Law (Law No. 27 of 2022)** — [Official Text (BPK PDF)](https://peraturan.bpk.go.id/Home/Details/224884/uu-no-27-tahun-2022)<br>**Electronic Information and Transactions Law (UU ITE)** — [Law Overview](https://jdih.kominfo.go.id/produk_hukum/view/id/555/t/undangundang+nomor+11+tahun+2008) | Requires a lawful basis for processing personal data (consent, contract, legal obligation, legitimate interest, etc.). Data subjects have rights. UU ITE prohibits unlawful access and misuse of electronic data. | OSINT using publicly available data is generally permissible, **but processing identifiable personal data must comply with PDP Law principles** such as purpose limitation and data minimization. |
|
||||
| **Indonesia 🇮🇩** | **Personal Data Protection Law (Law No. 27 of 2022)** — [UU PDP](https://peraturan.bpk.go.id/Details/229798/uu-no-27-tahun-2022)<br>**Electronic Information and Transactions Law (UU ITE)** — [Law Overview](https://jdih.kominfo.go.id/produk_hukum/view/id/555/t/undangundang+nomor+11+tahun+2008) | Requires a lawful basis for processing personal data (consent, contract, legal obligation, legitimate interest, etc.). Data subjects have rights. UU ITE prohibits unlawful access and misuse of electronic data. | OSINT using publicly available data is generally permissible, **but processing identifiable personal data must comply with PDP Law principles** such as purpose limitation and data minimization. |
|
||||
| **European Union 🇪🇺** | **General Data Protection Regulation (GDPR)** — [Official EU Text](https://eur-lex.europa.eu/eli/reg/2016/679/oj) | Processing requires a lawful basis (consent, legitimate interest, etc.). Transparency, accountability, and data subject rights apply. High-risk processing may require a DPIA. | Public availability does **not** remove GDPR obligations. OSINT involving EU residents’ personal data must meet GDPR compliance standards. |
|
||||
| **Spain 🇪🇸** | **LOPDGDD (Spain’s Organic Law on Data Protection) + GDPR** — [Official Text (BOE)](https://www.boe.es/eli/es/lo/2018/12/05/3) | Supplements GDPR with national rules. Legitimate interest may apply for research under strict necessity and proportionality tests. | OSINT research must document lawful basis and balance privacy impact against legitimate interest. |
|
||||
| **Mexico 🇲🇽** | **Federal Law on Protection of Personal Data Held by Private Parties** — [Official Government Portal](https://www.diputados.gob.mx/LeyesBiblio/pdf/LFPDPPP.pdf) | Requires privacy notice, lawful basis, and safeguards when processing personal data. Individuals have rights to access, rectify, cancel, or oppose data use. | Collecting public data is allowed, but processing personal data still falls under legal protections. |
|
||||
| **United States 🇺🇸** | **Computer Fraud and Abuse Act (CFAA)** — [Cornell Law School Reference](https://www.law.cornell.edu/uscode/text/18/1030)<br>**State Privacy Laws (e.g., CCPA/CPRA)** — [California DOJ](https://oag.ca.gov/privacy/ccpa) | Prohibits unauthorized access to computers and bypassing authentication. Privacy laws vary by state. | OSINT is legal when using publicly accessible sources. Accessing restricted systems or circumventing security controls is illegal. |
|
||||
| **China 🇨🇳** | **Personal Information Protection Law (PIPL)** — [Official Text (NPC)](http://www.npc.gov.cn/englishnpc/c23934/202112/1c7c0b2c4f8b4e3aa6d1b8e0f5afbd1a.shtml)<br>**Cybersecurity Law (CSL)** — [Overview](http://www.npc.gov.cn/englishnpc/c23934/202112/6e5c0e2d1d784d3e9f5f9a2b7a6c8d2f.shtml)<br>**Data Security Law (DSL)** — [Overview](http://www.npc.gov.cn/englishnpc/c23934/202112/9a1b2c3d4e5f67890123456789abcdef.shtml) | PIPL requires lawful basis and strict consent rules for personal data processing. Strong state controls on data handling, cross-border transfer restrictions, and broad definitions of sensitive personal information. | Even publicly available personal data can be regulated under PIPL. Large-scale OSINT data aggregation, profiling, or export outside China may trigger compliance reviews or security assessments. |
|
||||
| **International (Human Rights)** | **International Covenant on Civil and Political Rights (ICCPR), Article 17** — [UN Text](https://www.ohchr.org/en/instruments-mechanisms/instruments/international-covenant-civil-and-political-rights) | Recognizes the right to privacy and protection from arbitrary interference. Applies to digital environments. | OSINT activities should respect fundamental privacy rights even when data is publicly accessible. |
|
||||
| **OSINT Ethical Principles (Non-Legal)** | Community-driven OSINT codes of conduct and research ethics | Use only lawfully and publicly available sources. Avoid doxxing, stalking, harassment, or data resale. Minimize sensitive data collection. | Ethical practice often goes beyond legal requirements and reduces risk of harm, misuse, or reputational damage. |
|
||||
|
||||
|
||||
Reference in New Issue
Block a user