In recent years, we have witnessed a significant tightening of privacy protection requirements around the world. Regulations such as GDPR in Europe, CCPA in California, PIPEDA in Canada, and additional legislation in many countries have created a new standard for managing personal information. In Israel, Amendment 13 to the Privacy Protection Law represents another significant step in this direction.
For organizations that conduct background checks based on open-source intelligence (OSINT), the question sometimes arises as to whether these regulations will make such checks impossible or undermine their effectiveness.
The professional answer is no.
Regulation changes the way in which the check is performed, but it does not eliminate the need for it, and it does not prevent the conduct of high-quality checks when they are carried out in a professional, lawful, and proportionate manner.
What is Amendment 13 to the Privacy Protection Law? Amendment 13 is intended to strengthen the enforcement capabilities of the Privacy Protection Authority and to align Israeli law with modern international standards. Among other things, the amendment grants the Privacy Protection Authority broader enforcement powers, significantly increases the level of financial sanctions, requires organizations to manage personal information more responsibly, increases the accountability of database owners and data processors, and strengthens the rights of data subjects. In practice, the implication for organizations is that violating privacy provisions may become a significant business, legal, and reputational risk.
How do privacy regulations affect background checks? The most common mistake is to think that privacy legislation prohibits the collection of information. In fact, most regulations around the world do not impose a blanket prohibition on collecting personal information. They require that collection be carried out on the basis of clear principles: a legitimate purpose, proportionality, transparency, data minimization, data security, and limited retention over time. In other words, the question is not "is it permitted to collect information?" but rather "what information is collected, why is it collected, and how is it used?".
The use of OSINT is not exempt from privacy laws. There is another mistaken perception according to which information published online is "free to use". The fact that information is found online does not negate the fact that it is personal information. For example: a LinkedIn profile, social media posts, news articles, business records, and forum content. All of these may be considered personal information and subject to privacy laws. Therefore, an organization conducting background checks cannot rely on the claim that the information was merely "public".
How can high-quality background checks be conducted in compliance with regulation?
Defining a clear purpose: A background check should be directly related to the risk that the organization seeks to mitigate. For example: detecting conflicts of interest, identifying past fraud, detecting behaviors that may harm the organization, examining reputational risks, and identifying problematic business relationships. Collecting information unrelated to this purpose may be considered a deviation from the principle of proportionality.
Collecting only relevant information: A professional check is not measured by the quantity of information collected but by the quality of the information. In many cases, an excess of information actually makes decision-making more difficult. The correct approach is to focus on information of genuine business value and to link it to the required risk assessment.
Using human analysts: One of the central problems in automated checks is the massive collection of information without context. A professional analyst knows how to distinguish between fact and opinion, cross-reference sources, identify errors in identification, understand cultural and linguistic contexts, and exercise judgment. Precisely in a world of stringent regulation, the value of the human element grows.
Transparency and consent when required: In recruitment processes or certain engagements, it is recommended to obtain explicit consent to conduct a background check. Even when the law does not fully require this, clear consent strengthens the legitimacy of the process and reduces legal risks.
Deletion of information and limited retention: One of the fundamental principles in most privacy regulations is limiting the duration of retention. After completing the check and making the business decision, one should examine whether there is justification for continuing to retain the information, whether the reports can be deleted, and whether only partial retention of the data is necessary. This approach reduces data security risks and lowers regulatory exposure.
The advantage of OSINT precisely in the age of privacy: Paradoxically, privacy regulations actually strengthen the standing of high-quality OSINT checks. In the past, many organizations relied on collecting information from numerous databases, some of which were legally problematic. Today, the emphasis is shifting to information gathered from open, lawful, documented, and verifiable sources. When the check is conducted professionally, it is possible to reach significant insights even without access to private or confidential information. In many cases, it is precisely the open information that provides the most important indications regarding behavior, business relationships, reputational risks, or conflicts of interest.
The key is Governance, not prohibition: The central message of Amendment 13 and of privacy regulations around the world is not "do not conduct background checks". The message is: conduct them responsibly. Organizations that build orderly work processes, adhere to proportionality, operate control mechanisms, and use professional analysts will be able to continue conducting highly effective background checks even under stringent regulation.
In fact, in a world where insider threats, fraud, AI-based impersonation, and conflicts of interest are becoming more complex, the need for professional background checks is only growing.
The new challenge is not to find information. The challenge is to know how to collect the right information, use it lawfully, and derive from it insights of genuine value for decision-making.