One of the most complex questions in background checks is not how to find information.
It is what you are allowed to do with it after you have found it.
The difficulty stands out especially when, during a background check based on open sources, information surfaces that relates to a criminal offense, an investigation, a legal proceeding or conduct of a criminal nature.
It can be a court ruling published in a legal database.
An old article on a news site.
An announcement by a public authority.
A report about an indictment.
A publication about a conviction.
Or even a public document that describes a factual event without using the words "criminal record" at all.
In such a situation a natural question arises:
If the information did not come from the police and was not pulled from the criminal register, but was found in an ordinary internet search, is it permitted to pass it on to the employer and take it into account in a hiring decision?
The answer is not a simple yes or no.
And the reason is that you have to separate three different questions:
1. Is it permitted to collect the information?
2. Is it permitted to pass it on to the party making the decision?
3. Is that party permitted to use it in an employment decision?
These are three entirely different stages.
First of all: what is "criminal information" under the law in the first place?
Israel's Criminal Information and Rehabilitation of Offenders Law, 2019, defines "criminal information" as information from the criminal register and from the police register.
The criminal register includes, among other things, details of convictions and certain decisions listed in the law.
The police register includes other types of information, such as pending cases and additional police information in accordance with the provisions of the law.
The initial implication matters:
Not every piece of information describing criminal conduct is necessarily "criminal information" in the technical sense of the law.
A newspaper article is not the criminal register.
A court ruling published to the public is not the police database.
An announcement by a public authority does not become a police register just because it describes an offense.
But this is exactly where the complexity begins.
The source of the information is not the end of the discussion
It is very easy to reach the following conclusion:
"If I found it on Google, I am allowed to use it."
That is a dangerous conclusion.
The Criminal Information Law does not deal only with how a person obtains information.
Section 38 provides that whoever is not entitled to receive certain criminal information, or criminal information at all, shall not take it into account in making a decision.
The section goes on to provide that "additional information relating to the said criminal information" shall not be taken into account either.
In other words, the fact that information came from an open source does not necessarily detach it from the restrictions that apply to the use of criminal information.
The test is not only:
"Where did the information come from?"
You also have to ask:
"What did we actually learn from it?"
And:
"What do we intend to do with this information?"
This is a critical distinction.
OSINT cannot become a bypass route for obtaining information whose use the law was designed to restrict.
In other words:
If an employer is not entitled to receive certain information from the criminal register, it is wrong to assume that it can simply reconstruct that same information through a search of open sources and then use it as if the restriction did not exist.
But the opposite direction is not correct either
Here it is important to avoid the opposite mistake.
The fact that a public source describes criminal conduct does not automatically turn every detail in it into information that must not be collected, reported or considered.
A background check may uncover factual information with clear significance for risk assessment.
Sometimes that information is also connected to a criminal proceeding.
The question is not only which legal label can be attached to it.
You have to understand the context.
Is it a conviction?
An investigation?
An indictment?
A closed case?
An acquittal?
A claim made by a party in a civil proceeding?
A factual finding by a court?
A press report whose outcome is unclear?
Or documented conduct relevant to the role, even if the legal proceeding itself is not the focus of the check?
Each of these cases is different.
An example: a candidate who is supposed to manage money
Suppose a person is a candidate for the role of CFO.
The role includes signing off on payments, access to bank accounts, permissions in financial systems and responsibility for significant sums of money.
During a background check, a public and reliable court ruling is found describing that person's past involvement in an act of financial fraud.
Here, two extreme reactions would be problematic.
The first reaction:
"It is a public court ruling, so we are automatically allowed to pass it on and recommend against hiring."
That conclusion is too broad.
The second reaction:
"There is a connection to a criminal offense here, so we are not allowed to relate to the information at all."
That conclusion is also too broad.
A professional background check needs to break the finding down.
What exactly did the ruling determine?
Is it a conviction or only a description of a claim?
When did the event take place?
What was the person's part in it?
Did the proceeding end in a way that changes the meaning of the finding?
Are there additional sources that corroborate it?
And the central question from a risk management perspective:
What is the connection between the finding and the role being assessed?
When a person is about to receive control over money, a reliable finding concerning fraudulent financial conduct may carry far clearer significance than in a role with no access to funds, assets or financial permissions.
But here too, relevance to the role is not a "get out of the law" card.
It is part of the check, not a substitute for the legal analysis.
Relevance is a central condition, but not the only condition
This is perhaps the most important distinction.
In the background check world we are used to thinking in terms of relevance.
Rightly so.
The purpose of a background check is not to collect every detail that can be found about a person.
The purpose is to identify information with a real connection to the risk arising from the role.
For example:
A history of financial fraud may be highly relevant to a role that includes access to funds.
An incident of information misuse may be relevant to a role with permissions to sensitive databases.
Violent behavior may take on special significance in a role that includes responsibility for the safety of others.
A material breach of trust can be relevant to a role in which the employee will receive broad independence and access to sensitive assets.
But relevance alone is not enough.
Even highly relevant information can be information whose use the law restricts.
So the correct order is:
Legality first.
Relevance after.
And not the other way around.
Not every press mention equals a "criminal record"
There is another professional problem as well.
The internet almost never provides a complete legal picture.
You can find an article from 2018 saying a person was arrested.
But what happened afterwards?
Was an indictment filed?
Was the case closed?
Was the person acquitted?
Is it even the right person?
Was a correction to the article published?
Did a higher court overturn the ruling?
A background check that collects the first mention and stops there can be worse than not conducting a check at all.
Especially when the information has the potential to harm a person.
That is why such a finding requires verification, context and updating.
The acquittal is a good example of the trap
Suppose a search of a candidate's name brings up dozens of articles about a high profile criminal trial.
At first glance the impression is severe.
But after reading the ruling it turns out the person was acquitted.
If the analyst settles for the old headlines, they are effectively creating a picture that is the opposite of the legal reality.
This is one of the reasons a background check cannot amount to a keyword search.
You have to understand the sequence of events and the outcome.
The age of the information matters too
A finding that is one year old is not necessarily the same as a finding that is twenty years old.
The Criminal Information Law itself is built, among other things, on a concept of limitation periods, expungement and rehabilitation.
The purpose is not only to protect information.
It is also to allow a person not to carry forever the full weight of an event from their past.
So when old information appears online, the fact that the internet "remembers" it does not mean an employer must necessarily remember it the same way.
This is especially true for information whose influence the law itself sought to reduce over time.
And what about information that is not a conviction?
Here even greater caution is required.
An arrest is not a conviction.
An investigation is not a conviction.
An indictment is not a conviction.
A closed case is certainly not a conviction.
An article about a suspicion is not proof that the suspicion was correct.
And yet, an OSINT search can bring up all of these.
That is why a professional background check cannot settle for the words:
"We found a negative publication."
You have to say exactly what was found.
Who published it.
When.
What its legal status is.
And what happened afterwards.
The difference between:
"The candidate was convicted of fraud"
And:
"In 2019 it was reported that the candidate was questioned on suspicion of fraud"
Is enormous.
Three questions to ask before such a finding goes into a report
When information connected to a criminal proceeding surfaces during a background check, it is right to separate three layers.
1. Is it permitted to collect it?
Is it information from a legitimate public source?
Was the way the information was obtained lawful?
Is there no attempt here to bypass a legal restriction through a third party?
2. Is it right and permitted to report it?
Even information found lawfully does not have to enter the report automatically.
Its reliability, currency, severity and relevance have to be examined.
You also have to consider whether passing it on could put the decision maker in a position of being exposed to information the law does not allow them to take into account.
3. Is the employer permitted to use it in the decision?
That is a separate question.
An employer may be authorized to receive one type of information and not another.
Certain roles are subject to special arrangements.
Certain bodies hold powers that an ordinary private employer does not have.
And sometimes the law allows information to be taken into account only under certain conditions.
So there is no single answer that fits every organization and every role.
Amendment 10 to the law demonstrates exactly this principle
In 2026 a new and narrowly focused arrangement concerning certain terrorism offenses was added to the law.
Under the conditions set, the law allows an employer to ask the police for a notice stating whether or not an adult candidate has a criminal record entry relating to a serious terrorism offense or to certain offenses under the Counter-Terrorism Law.
The request is conditional on the candidate's written consent, and the notice does not provide the employer with the full details of the register.
The amendment came into force on August 24, 2026.
The very fact that the legislator needed to create such a specific route illustrates an important point:
Access to criminal information for employment purposes is not a matter of "there is consent" or "I found the information".
It is a matter of authority, conditions and purpose.
So what is the role of an OSINT-based background check?
A background check is not a substitute for the criminal register.
And it is not supposed to be a way to reconstruct it.
Its role is far broader and different.
OSINT can uncover information about:
Conflicts of interest.
Companies and business connections.
False claims in a resume.
Professional history.
Sanctions.
Connections to high risk parties.
Civil proceedings.
Media reports.
Public statements.
Unusual business activity.
Behavioral patterns.
Information related to trustworthiness, when it is relevant to the role and collected and analyzed lawfully.
And sometimes, within that space, information with a connection to the criminal world will surface as well.
At that point the professional responsibility is not to make it disappear automatically, and not to rush to pass it on either.
The responsibility is to understand exactly what was found.
The question is not only "what did we find?"
It is:
What is the source of the information?
What is its level of reliability?
What is its legal status?
Is there a later development?
How old is the finding?
Is it the right person?
Is it permitted to pass it on?
Is the employer permitted to use it?
And what is its real connection to the risk arising from the role?
Only after all of these questions are answered can you decide whether the finding should be included in the background check, and in what form.
The bottom line
"Public information" and "information that may be used in a hiring decision" are not synonyms.
But "information relating to criminal conduct" and "information that must never be reported" are not synonyms either.
Reality is more complex.
OSINT is not a way to bypass the Criminal Information Law.
But a background check should not ignore public, reliable and relevant information just because it relates to conduct that may be criminal.
The professional test lies in the combination of four things:
The legal framework.
The source and quality of the information.
The relevance to the role.
And the way the information will be used in making the decision.
Finding information online is the easy part.
Professionalism begins with the question of what is permitted, right and fair to do with it after we have found it.