This informal CPD article ‘The potential applications of artificial intelligence in private investigation and the data protection issues they raise under the EU GDPR and the UK GDPR’ was provided by Educage Training, a team of legal and technical professionals specializing in data protection, information security, and regulatory compliance.
Introduction
Artificial intelligence (hereinafter: AI) has become one of the most defining technological tools of the private investigation profession over the past few years. Open source intelligence (OSINT), image recognition, large language models and automated data analysis systems are significantly speeding up and expanding work that was previously carried out exclusively by human investigators using manual methods. At the same time, however, new and highly complex data protection risks have emerged, which are regulated both by the European Union’s General Data Protection Regulation (GDPR), the UK GDPR applicable in the United Kingdom, and the newly effective EU Artificial Intelligence Act (AI Act).
The purpose of this article is to review the most important areas of application of AI in private investigation, and then to present in detail the legal tensions between effective evidence gathering and data subjects’ right to informational self-determination and privacy. The article covers the Clearview AI case as one of the most significant European and British legal cases concerning AI-based facial recognition, presents the special regulatory solutions applicable to the private investigation sector in the United Kingdom, and finally outlines some relevant elements of Hungarian regulatory practice.
1. Applications of AI in private investigation work
Private investigation work has traditionally been based on surveillance, interviews, the examination of public and semi-public records, and document analysis. AI-based tools can be applied in almost every phase of these activities.
1.1 Open source intelligence (OSINT) and social media analysis
AI-based OSINT tools can automatically map a target person’s social media presence, network of contacts, public posts and digital footprint, and then generate patterns and behavioural profiles from this data. Such systems are orders of magnitude faster than manual research, but it is precisely this large-scale, automated processing that raises the sharpest data protection concerns, since profiling in itself qualifies as a processing operation under the GDPR.
1.2 Facial and image recognition, biometric identification
Biometric facial recognition systems, which are typically built on photographs gathered from the internet (social media sites, blogs, news portals) using automated scraping ("web scraping") technology, enable an unknown person to be identified from a single photograph by searching a vast, pre-built database9,10. This technology can be particularly attractive in missing person, fraud detection or infidelity cases, but it constitutes one of the most serious categories of GDPR infringement.
1.3 Voice recognition and audio recording analysis
AI-based audio analysis software can identify speakers, estimate emotional state, and quickly transcribe and make searchable by keyword large volumes of recorded conversations. In a notice issued in December 2024, the Hungarian data protection authority (NAIH) specifically emphasised that a natural person’s voice, and any recording made of it, qualifies as personal data, so its recording, use and any further processing, including AI-based analysis, constitutes data processing and must be carried out in accordance with all the principles of the GDPR21.
1.4 Document and large dataset analysis using large language models
Large language models (LLMs) are capable of reviewing large volumes of documents (contracts, emails, company information, court records) in a short time, uncovering connections, and producing structured reports. This significantly reduces the time required for classic due diligence and asset tracing investigations.
1.5 Predictive analysis and risk assessment
Some providers offer AI models that generate a risk score, ranking a target person or event for further investigation based on the available data. Where such a score alone, without human intervention, leads to a decision producing legal or similarly significant effects for someone, for example the initiation of disciplinary proceedings or a report to an authority, it may fall within the restriction on automated decision-making under Article 22 of the EU GDPR and Article 22A of the UK GDPR2.
1.6 Agentic AI systems
The latest autonomous, self-planning and self-acting “agentic” AI systems are able independently to sequence and carry out investigative steps (for example, approaching further data sources) without human instruction. According to legal experts, this simultaneously increases both efficiency and risk:
- the agent may collect data more broadly than planned,
- it may process the collected data for a new purpose without human oversight, and
- it may cause accountability problems when several tools and providers operate together in the course of an investigation2.
2. The principles of the GDPR and their tensions with private investigation activity
By its very nature, private investigation activity almost inevitably conflicts with the principles of the GDPR, since the effectiveness of an investigation often depends precisely on the data subject not becoming aware of the collection of data concerning them. The sector-specific code of conduct approved by the UK Information Commissioner’s Office (ICO)1 therefore provides guidance specifically for identifying and documenting the legal basis for “invisible” processing, such as covert surveillance, the use of tracking devices, background checks and social media monitoring4.
2.1 Legal basis: legitimate interest and the balancing test
The typical legal basis for data processing by private investigators is legitimate interest (Article 6(1)(f) GDPR), the application of which requires a careful assessment of necessity, proportionality and the data subject’s interests (a Legitimate Interests Assessment)3. In the United Kingdom, from February 2026 a new legal basis, the so-called “recognised legitimate interest”, has also been introduced under the Data Use and Access Act (DUAA), which exempts the controller from carrying out the detailed balancing test for five predefined purposes, including the prevention and detection of crime and national security purposes6,7.
However, this legal basis is expressly not applicable as the sole basis for automated decision-making, and the objective requirement of necessity, which is not based on the controller’s subjective preference, continues to apply8.
2.2 Data minimisation and purpose limitation
AI-based OSINT and profiling tools tend, by their very nature, to collect substantially more data than necessary, since the performance of the models often increases with the volume of input data. This directly conflicts with the principle of data minimisation. The private investigator must be able to demonstrate that only data necessary and relevant to the purpose of the investigation was collected, and that data collected for one purpose is not used unjustifiably for another3.
2.3 Transparency and the limits of information to data subjects
As a general rule, the GDPR requires that the data subject be made aware of the processing of their data. In investigative situations, however, providing such information would often defeat the purpose of the investigation itself, so the legislation permits (narrowly construed) exceptions where providing the information would defeat or endanger the purpose of the investigation3. However, the Hungarian data protection authority has emphasised that the exceptional justification for covert audio recording cannot hollow out the constitutional guarantees protecting privacy, and in every such case expects the controller to carry out a careful, thorough and accountable assessment21.
2.4 Special category data and the processing of biometric data
Biometric characteristics extracted from a facial image fall within the special category of data under Article 9 of the GDPR, the processing of which requires a stricter legal basis than the general one. As the EU data protection authorities’ proceedings against Clearview AI clearly established, the mass scraping of publicly available photographs and their conversion into a biometric database is not lawful even where the source is a public website, since data subjects cannot reasonably expect their photographs to be processed for such a purpose9.
3. The impact of the EU AI Act on the use of AI by private investigators
The prohibited practices under Article 5 of the EU Artificial Intelligence Act (AI Act, (EU) 2024/1689) have been in effect since 2 February 2025, forming a second layer of regulation that applies independently of, and in parallel with, the GDPR15,17.
3.1 The prohibition on real-time remote biometric identification
The AI Act expressly prohibits real-time remote biometric identification in publicly accessible spaces for law enforcement purposes, subject to narrowly defined exceptions (e.g. the prevention of a terrorist attack, the search for a missing person). However, these exceptions apply exclusively to law enforcement authorities and do not extend to private individuals or private companies, including private investigation firms15,16,17. Non-real-time (retrospective) remote biometric identification, as well as a significant proportion of emotion recognition and biometric categorisation systems, fall within the high-risk category or are subject to transparency obligations18.
3.2 The combined application of the GDPR and the AI Act
According to expert analyses, one of the most common mistakes is for an organisation to regard GDPR compliance alone as sufficient: a facial recognition or biometric categorisation function may be properly documented from a data protection perspective, yet may still remain prohibited or high-risk under the AI Act, which regulates the AI system itself, not merely the personal data17. Opinion 28/2024 of the European Data Protection Board (EDPB) adds to this by stating that the principles of lawfulness, fairness and transparency must be observed throughout the entire lifecycle of the development and operation of AI models, and that reliance on legitimate interest alone is not sufficient if the controller does not apply risk-mitigating technical and organisational measures19.
4. Case study: the Clearview AI case as a lesson for the private investigation sector
The US-based company Clearview AI collected tens of billions of photographs from social media and other public websites using automated scraping technology, and built a biometric database from them, which it sold primarily to law enforcement agencies and private companies as a facial recognition service10,14. The case is particularly relevant to the private investigation profession because Clearview’s business model, the automated collection of public data, its conversion into a biometric profile, and its subsequent sale to third parties, closely resembles the underlying model of many AI-based investigative tools.
The French data protection authority (CNIL) imposed a fine of EUR 20 million on the company in 2022, the maximum under the GDPR, finding that the collection and use of biometric data had taken place unlawfully, without a legal basis, and that the company had not properly ensured data subjects’ rights of access and erasure9. Similar fines totalling approximately EUR 70.5 million were imposed in Italy, Greece and the Netherlands11, while the Austrian data protection advocacy organisation noyb filed a criminal complaint against the company and its executives in 2025 under the criminal provisions of the Austrian data protection act13.
In the United Kingdom, the case followed a particularly instructive path. The ICO imposed a fine of GBP 7.5 million on Clearview in 2022 and ordered the deletion of UK data subjects’ data; the company, however, successfully appealed, arguing that its clients were exclusively foreign law enforcement bodies whose activities fall outside the scope of the UK GDPR11,12.
The First-Tier Tribunal upheld this argument in 2023, but following the ICO’s appeal, the UK Upper Tribunal found in October 2025 that a private company cannot enjoy state sovereign immunity merely because it provides services to foreign law enforcement bodies, and further that Clearview’s activity is closely linked to the "behavioural monitoring" carried out by its clients, and therefore falls within the scope of the UK GDPR11,12.
The most important lesson of the case, one that is also transferable to private investigation activity, is that
- Data originating from a public source does not automatically mean that its AI-based processing is lawful,
- The authorities and courts interpret the concept of behavioural monitoring broadly, so that it can also cover a party that merely provides a tool for others to carry out surveillance, and
- The existence of a client in a third country (e.g. a foreign client or authority) does not in itself exempt a European or British provider from the application of the GDPR or the UK GDPR12.
5. The United Kingdom’s special regulatory environment
There is currently no mandatory statutory licensing regime for private investigation activity in the United Kingdom, although its introduction has been on the agenda for years3. The absence of licensing does not, however, mean that the activity is unregulated. Investigative work is subject to the UK GDPR, the Regulation of Investigatory Powers Act 2000 (RIPA) and the Investigatory Powers Act 2016 (IPA 2016), which regulate surveillance powers, the Human Rights Act, and the Computer Misuse Act 1990. Obtaining the content of private communications, telephone calls, emails or messaging app content, without the data subject’s consent or lawful authorisation, constitutes a criminal offence under RIPA, the IPA and the Computer Misuse Act, and no lawfully operating private investigator may carry this out3.
5.1 The ABI sector code of conduct
It marks a milestone that in October 2024 the ICO approved the UK GDPR code of conduct developed by the Association of British Investigators (ABI) for investigative and litigation support services. As such, this was the first such sector-wide, regulator-approved code in the United Kingdom4,5. The code provides practical guidance for distinguishing between the roles of controller, joint controller and processor, for carrying out data protection impact assessments (DPIAs), and for documenting the legal basis for invisible forms of processing, including covert surveillance, tracking devices, background checks and social media monitoring4. Compliance with the code is monitored by the Security Systems and Alarms Inspection Board (SSAIB) as an independent monitoring body.
5.2 The new "recognised legitimate interest" legal basis
Following the DUAA amendments, which entered into force on 5 February 2026, the "recognised legitimate interest" under Article 6(1)(ea) of the UK GDPR allows the balancing test to be dispensed with for five predefined purposes, including the prevention and detection of crime and national security purposes7,8. In theory, this may simplify establishing the legal basis for certain investigative processing activities; however, the objective requirement of necessity and proportionality, together with the additional conditions applicable to special category data, continue to limit its application, and reliance on it as a basis for exclusively automated decision-making remains unavailable8.
6. Hungarian aspects: NAIH practice
In Hungary, the National Authority for Data Protection and Freedom of Information (NAIH) issued a separate notice in December 2024 drawing attention to a recent increase in unlawful practices relating to the making and use of covert audio recordings, that is, recordings made without the data subject’s knowledge. The authority stated that the making of an audio recording in any form qualifies as processing under the GDPR, and that any reliance on an overriding public interest can only exceptionally, and only through a careful and accountable assessment, override the constitutional guarantees protecting privacy21. According to the NAIH, such practice may give rise to civil and criminal liability in addition to data protection consequences, and may infringe the right to human dignity as well as trust-based social communication21.
The authority also addressed the data protection issues raised by the use of artificial intelligence in a separate decision, in which it examined how the obligation to inform, the right to object, transparency, data security, legitimate interest and the principles of data protection by design and by default apply in the AI context23. Domestic legal literature also emphasises that Hungarian and EU controllers must, if their AI systems process personal data, simultaneously and consistently comply with at least three regulatory layers: the AI Act’s transparency rules, consumer protection information obligations, and the information requirements under the GDPR22.
7. Key risks and compliance recommendations
Based on the above, the key GDPR and AI Act risks associated with the private investigation sector’s use of AI can be summarised as follows:
- Absence of a legal basis: reliance on legitimate interest cannot be sustained without a documented balancing test (a Legitimate Interests Assessment) and without an assessment of necessity and proportionality3.
- Excessive data collection: AI tools are automatically inclined to collect and store more data than necessary, in breach of the principle of data minimisation3.
- Unlawful processing of biometric data: the mass scraping and processing of public photographs for facial recognition purposes may, as established in the Clearview cases, be unlawful in itself, regardless of the public nature of the source9,10,20.
- Disregarding the AI Act’s prohibited practices: compliance with the GDPR does not replace the need to examine the prohibitions under Article 5 of the AI Act and the separate obligations applicable to high-risk systems15,17.
- Lack of transparency in automated decision-making: the use of risk scores without human review, for decisions carrying legal consequences, may infringe Article 22 of the GDPR and Article 22A of the UK GDPR.
- Loss of control over agentic AI: autonomously acting AI systems may exceed the originally defined scope of data collection and may create accountability gaps where several providers are used together.
Recommended compliance measures include carrying out a regular data protection impact assessment (DPIA) before introducing any new AI-based tool, documenting the legal basis and the balancing test for each individual investigation, technically enforcing data minimisation (e.g. targeted queries rather than retrieving a full profile), and joining sector codes of conduct (such as the ABI’s code approved in the United Kingdom), which has been shown to increase client trust and reduce the risk of regulatory action.
Summary
Artificial intelligence has undoubtedly opened up a new dimension for the private investigation profession: it makes information gathering and analysis faster, broader in scope and, in many respects, more accurate. At the same time, however, the GDPR, the UK GDPR and the AI Act together form a strict, multi-layered legal framework that significantly limits these technological possibilities. The Clearview AI case clearly shows that relying on a public data source and on technological innovation does not in itself exempt a party from liability, and that regulators in both the European Union and the United Kingdom are taking an increasingly firm stance against AI-based, biometric or mass surveillance practices. For the long-term lawful operation and trustworthiness of the private investigation sector, it is therefore essential that the use of AI tools be closely aligned with documenting the legal basis, the principle of data minimisation, and sector self-regulation initiatives.
We hope this article was helpful. For more information from Educage Training, please visit their CPD Member Directory page. Alternatively, you can go to the CPD Industry Hubs for more articles, courses and events relevant to your Continuing Professional Development requirements.
REFERENCES
- Artificial intelligence, Information Commissioner's Office.
- WilmerHale - AI and Data Privacy in Investigations: What Legal Teams Need to Know
- National Private Investigators – GDPR and UK Surveillance Laws for Private Investigators: What's Legal, What's Restricted, and Compliance Rules
- ICO - NEW data protection code of conduct launched for UK private investigators
- Stephenson Harwood - Setting a New Standard: UK's First ICO-Approved UK GDPR Code of Conduct
- ICO - Recognised legitimate interest.
- A&O Shearman - New and updated UK guidance on recognised legitimate interest, general legitimate interest and purpose limitation
- Crowell & Moring LLP – Pre-Approved: ICO Publishes Guidance on "Recognised Legitimate Interests"
- CNIL - Facial recognition: 20 million euros penalty against CLEARVIEW AI
- Privacy International - Challenge against Clearview AI in Europe.
- Privacy International - Tribunal Confirms Clearview AI Bound by GDPR
- EM Law - Clearview AI Case: UK Tribunal Clarifies the Reach of the GDPR and Behavioural Monitoring
- noyb - Criminal complaint against facial recognition company Clearview AI
- Chicago Journal of International Law - Clearview AI, TikTok, and the Collection of Facial Images in International Law.
- European Commission, AI Act Service Desk - Article 5: Prohibited AI practices.
- Future of Privacy Forum (FPF) – Red Lines under the EU AI Act: Restricting Real-time Remote Biometric Identification Systems for Law Enforcement Purposes
- Bundesnetzagentur – Prohibited practices (EU AI Act).
- Biometric AI and the EU AI Act: Identification, Verification, and Categorisation
- The European Data Protection Board Shares Opinion on How to Use AI in Compliance with GDPR (EDPB Opinion 28/2024)
- Fines for GDPR violations in AI systems and how to avoid them
- NAIH notice on the negative effects of covert audio recording on the right to informational self-determination and privacy protection, and on the spread of this unlawful practice
- The EU AI Act and its links with the GDPR
- Data protection issues in the use of artificial intelligence (NAIH Decision No. 85/2022)
- LexisNexis - ICO approves first UK GDPR code of conduct for private investigators
- Investigatory Powers Act 2016 (IPA 2016).