← All posts
GDPROSINT

Why "everyone does OSINT anyway" isn't a legal defense

12 February 2026

It's a real objection, and worth taking seriously rather than dismissing: informal OSINT-style checks on founders, candidates, and counterparties are extremely common across venture, recruiting, and M&A. If everyone does it, does it really carry meaningful legal risk?

Regulators have answered a version of this question before, in adjacent contexts — widespread practice hasn't historically been treated as a defense once a complaint or audit actually happens. "Common" describes how often something occurs, not whether it clears Article 6.

The practical risk calculus for most funds and recruiters isn't "will GDPR enforcement specifically target informal founder diligence" — it's "what happens if one founder, one time, formally objects, requests their data, or files a complaint." That's the scenario a documented, consent-based process is actually insurance against, regardless of how common the informal alternative is.

General framing, not a prediction about enforcement priorities or legal advice for a specific situation.

See how a consent-based check actually works.

See pricingTry the free badge

More from the blog

Due diligence for recruiters: same problem, different subjectHow to read a Growth Readiness Score without over-indexing on one numberThe real cost of skipping diligence on a co-founder