DeepSearch
Is It Illegal to Search Someone Online?
Searching publicly available information is generally lawful. Here is what crosses the line — harassment, unauthorized access, breached data — plus the FCRA rules for hiring, tenancy, and credit.
Someone gives you a name. You type it into a search engine. Have you done something wrong? Almost certainly not — reading publicly available information is one of the most ordinary things anyone does online, and it is generally lawful in most jurisdictions. But "search someone online" covers an enormous range of activity, and some of that range is genuinely unlawful.
The distinction that matters is not whether you searched. It is how you obtained the information and what you did with it afterward. Those two questions account for nearly every legal problem that arises from people research. This guide walks through both, explains the specific rules that apply to hiring, housing, and credit decisions, and covers how the answers shift by jurisdiction.
This article is general information, not legal advice. Laws differ by country, state, and context, and they change. Consult qualified counsel for your specific situation, particularly if you are researching people on behalf of an organization.
For the practical methods behind all of this, see our pillar guide on how to find someone online.
The short answer
Searching for publicly available information about a person — running their name through a search engine, reading their public social profile, looking at a company team page, finding a news article that mentions them — is generally lawful. There is no general legal duty to ask permission before reading a public web page, and no general prohibition on being curious about another person.
Legal exposure enters through three doors:
- How you got the information.Circumventing a login, using someone else's credentials, buying breached data, or deceiving a company into handing over records are all problems regardless of how public the underlying facts are.
- What the research is part of. Repeated, unwanted attention can become harassment or stalking even when every individual search was lawful.
- What decision you make with it. Employment, tenancy, credit, and insurance decisions are regulated in ways that ordinary curiosity is not.
Everything below is an elaboration of those three.
The general rule: public information is public
When a person or an organization publishes something on an openly accessible web page — a LinkedIn profile left public, a conference speaker bio, a company leadership page, a court docket posted online, a newspaper article — reading it is not an intrusion in any legal sense that most jurisdictions recognize. Search engines index those pages precisely because they are meant to be found.
Privacy torts in common-law countries generally require something more than reading public material: intrusion upon seclusion requires intrusion into a place or matter where the person had a reasonable expectation of privacy, and public disclosure of private facts requires disclosing something genuinely private. A public web page usually fails both tests by definition.
That said, "generally lawful to read" is not the same as "unlimited to use." Data protection law in many countries regulates what organizations do with personal data after collecting it, even when every field came from a public source. The collection is often the easy part; the retention, aggregation, and use is where duties attach.
What actually crosses the line
Harassment, stalking, and threats
This is the most common way lawful searching becomes unlawful conduct. A single search is research. A pattern of searching, monitoring, and contacting someone who does not want to hear from you can meet the definition of harassment or stalking in most jurisdictions. In the United States, the federal interstate stalking statute (18 U.S.C. § 2261A) covers conduct carried out using electronic communications, and every state has its own harassment and cyberstalking laws. Similar offenses exist across the UK, EU, Canada, and Australia.
If a protective or restraining order exists, the stakes rise sharply — using research to locate or contact a protected person can violate the order directly, with immediate consequences. If someone has blocked you, asked you to stop, or obtained an order against you, no research purpose justifies continuing.
Unauthorized access and circumventing authentication
Getting past a login is categorically different from reading a public page. In the United States, the Computer Fraud and Abuse Act (18 U.S.C. § 1030) addresses accessing a computer without authorization or exceeding authorized access. The UK has the Computer Misuse Act 1990; most other countries have equivalents. Conduct in this category includes:
- Guessing, cracking, or reusing someone else's password
- Logging into an account that is not yours, even with a password you legitimately know
- Initiating password resets on accounts you do not own
- Exploiting a bug or misconfiguration to reach content behind an access control
- Using shared or borrowed credentials to view gated material
The rule of thumb is unambiguous: if a page asks you to authenticate and you are not entitled to, that is where research ends. This applies to platforms with partial login walls too — reading what a site serves publicly is fine, defeating the wall is not. Our guide to finding someone on LinkedIn without an account works entirely within that boundary.
Breached and stolen data
Credential dumps, combo lists, and breach compilations circulate widely and are sometimes marketed as "people search" data. Using them is a serious step outside legitimate research: the data was obtained through a crime, and trafficking in or knowingly using stolen access credentials carries its own liability in many jurisdictions. It is also unreliable — breach data is stale, frequently mis-attributed, and unverifiable.
Pretexting and impersonation
Calling a company's support line pretending to be the subject, creating a fake profile to gain access to restricted content, or impersonating an official to extract records is deception, not research. In the United States, the Gramm-Leach-Bliley Act specifically prohibits obtaining a financial institution's customer information under false pretenses. Impersonation can also breach platform terms and, depending on facts and jurisdiction, constitute fraud or identity offenses.
Scraping and automated collection
Whether automated collection of public pages triggers computer-misuse liability has been litigated repeatedly with fact-specific and sometimes conflicting outcomes. What is far less ambiguous is the contract question: most major platforms prohibit scraping in their terms of service, and breaching those terms can support civil claims, account termination, and injunctions independent of any criminal analysis. Treating unsettled case law as permission is a poor strategy.
Surveillance software and location tracking
Installing monitoring software on a device you do not own, using GPS trackers on another adult's vehicle, or intercepting communications generally falls under wiretapping, computer intrusion, or stalking statutes. This is true even between spouses and family members in many jurisdictions. So-called "stalkerware" is an enforcement priority in a number of countries.
Publishing to cause harm
Compiling public information is one activity. Publishing it with the intent that others use it to harass, intimidate, or harm — doxxing — is another, and a growing number of jurisdictions have enacted specific statutes addressing it. Even where no dedicated statute applies, publication can support harassment, incitement, or civil claims. The aggregation itself matters: scattering a person's employer, neighborhood, gym schedule, and children's school across ten sites is different in kind from assembling them onto one page.
Discrimination
Online research frequently reveals characteristics that anti-discrimination law protects — race, religion, national origin, age, disability, pregnancy, sexual orientation, family status. In the United States, Title VII, the ADA, the ADEA, the Fair Housing Act, and the Equal Credit Opportunity Act prohibit decisions based on protected characteristics in their respective domains. Learning something through a search does not make it lawful to act on, and the informality of a Google search does not lower the standard. It often raises the evidentiary risk, because the search left a record.
The FCRA distinction: the one most people get wrong
If you take one section from this article, take this one. In the United States, the Fair Credit Reporting Act (15 U.S.C. § 1681 et seq.) governs consumer reports used for decisions about employment, housing, credit, and insurance. It imposes duties on both the consumer reporting agencies that assemble those reports and the end users who rely on them:
- Permissible purpose — the requester must have a legally recognized reason to obtain the report
- Disclosure and written authorization — required from the subject in most employment contexts, in a standalone document
- Accuracy obligations — agencies must follow reasonable procedures to assure maximum possible accuracy
- Dispute rights — the subject can challenge inaccurate information and have it investigated
- Pre-adverse and adverse action notices — if the report contributes to a denial, the subject gets a copy, a summary of rights, and a chance to respond before the decision is final
Here is the part that causes trouble. A search you run yourself on the open web is generally not a consumer report, and searching a candidate's public LinkedIn profile is not ordering one. But if you use a non-FCRA tool as though it were a screening product — running it on every applicant, treating the output as a pass/fail input, declining people based on what it returned — you have taken on the risk profile of an FCRA process without any of its protections. The subject has no notice, no copy, no dispute right, and no way to correct a mismatch to a namesake.
DeepSearch is a public web research tool. It is not a consumer reporting agency and does not provide consumer reports. Do not use it as a factor in employment, tenant, credit, or insurance eligibility decisions. When a decision is regulated, route it to an FCRA-compliant provider with the disclosures, consent, and adverse-action process that framework requires. Our full comparison is in people search vs background check, and our FCRA and legal use guide sets out the product-specific boundaries.
Privacy law: GDPR, CCPA, and what they actually require
Data protection law generally regulates processing of personal data by organizations, rather than prohibiting individuals from reading public pages. Knowing what these frameworks require helps you judge when your research crosses from personal curiosity into organizational processing.
GDPR and UK GDPR
The EU and UK regimes apply to processing personal data of people in those territories, and "personal data" includes anything relating to an identifiable person — a name, a profile URL, an inferred employer. Core requirements include having a lawful basis for processing (for most commercial research, legitimate interests, which requires a documented balancing test against the individual's rights), purpose limitation, data minimization, storage limitation, transparency, and honoring data subject rights such as access, correction, objection, and erasure. Notably, the regulation carves out processing carried out by an individual in the course of a purely personal or household activity — which is why an individual looking someone up is treated differently from a company building a candidate database.
Public availability does not remove these duties. A publicly posted email address is still personal data, and collecting it into a CRM is still processing.
CCPA and CPRA
California's regime gives consumers rights over personal information held by businesses that meet defined thresholds — the right to know what is collected, to delete it, to correct it, and to opt out of its sale or sharing. It treats some publicly available government records differently from other data, but the practical point for a researcher is the same: once your organization holds information about a California consumer, obligations attach to how you keep and use it. Several other US states have enacted comparable laws.
Elsewhere
Canada's PIPEDA, Australia's Privacy Act, and similar frameworks impose their own notice, consent, and access obligations. Sectoral rules may apply on top — health, financial, and education data are frequently treated separately.
To be explicit about something readers sometimes assume from an article like this: nothing here asserts that DeepSearch, or any other product, complies with, is certified under, or is exempt from any of these laws. What we describe is what the laws generally require, so you can assess your own obligations. Our Privacy Policy explains what we collect and how we handle it, and our opt-out page handles removal requests. Your organization remains responsible for how it uses anything it exports or saves.
Jurisdiction changes the answer
There is no single global rule, and the gaps are wider than most people expect:
- Court and public records — openly searchable online in some countries, restricted or access-logged in others. Some jurisdictions allow expungement or sealing, and re-publishing a sealed record can carry consequences.
- Employer conduct rules — a number of US states prohibit employers from requesting social media passwords, restrict when criminal history can be considered, or limit decisions based on lawful off-duty conduct.
- Right to erasure — EU and UK residents can request delisting of certain search results about them in defined circumstances, a concept without a direct US equivalent.
- Cross-border research— researching someone in another country can bring that country's data protection regime into play for your organization, particularly under the EU and UK frameworks, which reach organizations targeting people in those territories.
If you research people at scale, across borders, or in a regulated industry, get this reviewed by counsel rather than by an article.
Common scenarios, answered
Googling a job candidate
Looking is generally lawful. Deciding is where the rules bite. Risks include acting on protected characteristics you learned online, using a non-FCRA tool as a de facto screening product, and confusing a namesake with your applicant. If your organization does this, make it a written policy: which stage allows public web research, who performs it, what gets documented, and which decisions require an approved screening vendor. Our recruiter guide covers research-appropriate workflows; screening workflows belong to HR and legal.
Checking someone before a first date
Widely recommended as a personal safety practice, and lawful as ordinary public research. Verify the basics — that the person exists, that their name and job are roughly as described, that nothing publicly documented raises alarm. Stop there. Compiling a dossier or continuing to monitor after a declined second date is a different activity.
Screening a tenant
Rental eligibility decisions using consumer reports fall squarely under FCRA tenant-screening rules in the US, including permissible purpose, disclosure, and adverse action on denial. Confirming that an applicant works where they said they work by reading a public company page is a different category from ordering a tenant report — and the second is what an eligibility decision requires.
Looking up an ex, or someone who blocked you
The highest-risk scenario in this entire article. Individual searches may be lawful, but the pattern is what a court examines, and the pattern is what harassment and stalking statutes address. If a protective order exists, stop entirely. If the person has cut contact, respect it. No research need justifies this.
Due diligence on a business counterparty
Generally lawful and frequently expected. Verifying that a founder, contractor, vendor, or co-investor has the background they claim is standard practice, and public sources are the right place for it. Keep it proportionate to the transaction, document your sources, and route anything touching credit decisions to the appropriate regulated process. Our investor guide covers this workflow.
Journalism and research
Newsgathering has significant protections in many jurisdictions, and public-interest reporting often justifies research that would be hard to defend otherwise. Those protections cover the reporting, not unauthorized access, harassment, or publication designed to endanger someone. Our journalist guide covers sourcing and citation practice.
Researching a neighbor, a coach, or a parent at your child's school
Proportionality is the test. Confirming that a tutor holds the credential they advertise is reasonable. Building a file on a neighbor after a dispute is where ordinary caution turns into something a court might characterize differently.
Searching for yourself
Entirely lawful and genuinely useful. Knowing what the open web says about you lets you correct outdated information, ask sites to remove content, and understand what an employer or counterparty will find. You can request removal from our results on the opt-out page.
Researching a minor
Apply substantially more caution. Beyond any legal question, building a profile of a child raises safeguarding issues, and schools and youth organizations typically have their own policies governing what adults may do. If you are a parent researching your own child's online safety, that is a different situation from researching someone else's child.
Does it matter whether they find out?
Legally, no. Notification is not the test. Whether a search is lawful depends on how the information was obtained and how it is used, not on whether the subject noticed.
Practically, notification varies by platform. LinkedIn can show signed-in members who viewed their profile, depending on both parties' settings. Standard search engines do not notify anyone. DeepSearch searches are private — we do not notify the person you look up, because we work from indexed public sources rather than by interacting with their accounts. See private search for details. Privacy of the search and legality of the search are separate questions, and one never substitutes for the other.
Does using a people search tool change the analysis?
Not in the way people hope. A tool does not launder purpose. If your intended use would be unlawful when you performed it manually, it is unlawful when software performs it faster. If an FCRA-compliant report is required for a decision, no non-FCRA product satisfies that requirement regardless of how thorough its output looks.
What a well-built tool does change is your ability to work responsibly. Source links let you verify a claim instead of trusting a summary. Candidate disambiguation reduces the chance you act against the wrong person — a genuine and underrated legal risk, since the harm from confusing two people with the same name lands on someone who did nothing at all. Our guide to common name disambiguation covers that discipline.
A practical checklist
- Name your purpose before you search, specifically enough to say out loud to the subject.
- Use public sources only. No credential workarounds, no breach data, no pretexting.
- Stop at every access control. A login prompt is an answer, not an obstacle.
- Verify identity across at least two independent sources before acting on anything.
- Record sources and dates so that findings can be checked and corrected.
- Collect only what the purpose needs and delete it when the purpose ends.
- Route regulated decisions — employment, tenancy, credit, insurance — to an FCRA-compliant provider and your legal or HR process.
- Honor removal and objection requests when they reach you.
- Ask counsel for high-volume, cross-border, or regulated-industry research.
If you are the one being searched
You have options, and they are worth knowing:
- Search your own name regularly to see what is actually out there
- Tighten privacy settings on social platforms and restrict public profile visibility
- Ask the site hosting outdated or inaccurate content to correct or remove it
- Exercise data subject rights where they apply to you — access, correction, deletion, and in the EU and UK, search-result delisting in defined circumstances
- Use our opt-out page to request removal from DeepSearch results
- If searching escalates into harassment or stalking, document it and contact law enforcement or a lawyer — that conduct is addressed by statute in most jurisdictions
Frequently asked questions
Is it illegal to search someone's name on Google?
No. Searching for publicly available information about a person is generally lawful. What creates liability is bypassing access controls, harassment, or making regulated decisions without the required process.
Is it illegal to look someone up without them knowing?
Generally no. There is no broad requirement to notify someone that you searched for them. Notification duties arise in specific regulated contexts — most prominently when a consumer report is used for an employment, housing, or credit decision.
Is it illegal to use a people search website?
Using a tool that aggregates publicly available information is generally lawful. The use case determines the rest: research and preparation are fine, regulated eligibility decisions require an FCRA-compliant provider, and harassment is unlawful regardless of the tool.
Can I get in trouble for searching my ex?
A single search is unlikely to be an issue on its own. A sustained pattern of searching, monitoring, and contacting can meet harassment or stalking definitions, and violating a protective order carries immediate consequences. If someone has cut contact or obtained an order, stop.
Is it illegal for an employer to Google a candidate?
Generally not illegal to look, but the surrounding rules are real: anti-discrimination law governs what you may act on, some states restrict requesting social media credentials or considering off-duty conduct, and FCRA applies when a consumer report informs the decision. Written policy and consistency across candidates reduce the risk substantially.
Is saving or screenshotting what I find illegal?
Saving a public page for your own reference is generally unremarkable. Storing personal data in an organizational system brings data protection duties into play — lawful basis, minimization, retention limits, and subject rights. Republishing copyrighted material is a separate question from the privacy analysis.
What if the person lives in another country?
Their jurisdiction's rules may apply to your organization, particularly under the EU and UK frameworks. Cross-border research warrants a conversation with counsel if you are doing it systematically.
Is DeepSearch legal to use?
DeepSearch searches publicly available web sources and cites them, which is a generally lawful activity in most jurisdictions — but legality depends on your use, not on the tool. We are a research product, not a consumer reporting agency, and must not be used for employment, tenant, credit, or insurance eligibility decisions. Misuse violates our Terms of Service. See our FCRA and legal use guide for the full boundaries.
Bottom line
Searching someone online is, in the ordinary case, legal. Public information is public, and looking at it is not an intrusion. The question that decides the outcome is never "did you search?" — it is how you obtained what you found and what you did next.
Stay on public sources. Stop at every login. Never touch breached data or deceive anyone into handing over records. Do not let research become a pattern of unwanted attention. And when the decision on the other end is about someone's job, home, or credit, use the regulated process that exists for exactly that purpose, with the notice and dispute rights it gives the person being decided about.
DeepSearch is built for the lawful half of this: public sources, cited so you can verify them, with candidate matching so you act on the right person. For methods, read how to find someone online; for the screening boundary, read people search vs background check. And once more, because it matters: this is general information, not legal advice. Talk to a qualified lawyer about your specific situation.
Ready to try it?
Try DeepSearch