Berkeley Protocol on Digital Open Source Investigations — офіційний стандарт ООН (документ ST/HR/PUB/20/2), за яким МКС, ЄСПЛ і національні суди оцінюють OSINT-докази у 2026 році. Українською не перекладено. Розбираємо простою мовою: 5 базових принципів, 4 стовпи ланцюга зберігання, 9-крокова методологія роботи документатора, застосування у справах МКС проти Аль-Верфаллі, Путіна, Al Hassan. З конкретними прикладами SHA-256-хешування, шаблонами звітів і поясненням, чому без цього стандарту ваша робота залишається журналістикою, а не юридичним доказом.
Legal OSINT is a term heard more and more often in the legal community, yet it still has no settled definition. Let’s start not with a definition, but with a question that today is worth more than any definition: why is it no longer enough to simply do OSINT?
Recent years have turned open sources into a full-fledged instrument for establishing facts. Journalists, analysts, investigators, businesses and governments all rely on it. But the moment an OSINT result enters the legal arena — a courtroom, an investigator’s file, a regulator’s desk — an uncomfortable truth surfaces: a brilliant analytical conclusion and a legally usable piece of evidence are far from the same thing.
This is exactly where room for a separate concept appears. A review of the international literature reveals no settled definition of Legal OSINT as a distinct discipline. OSINT is traditionally described as the process of collecting, analysing and using information from open sources to produce practically useful conclusions. Meanwhile, questions of admissibility, procedural documentation and courtroom use live separately — in the literature on electronic evidence, digital forensics and international justice. These two lines have barely met so far. Legal OSINT is an attempt to bring them together.
Definition
Legal OSINT is a branch of OSINT oriented not only toward obtaining information from open sources, but also toward its procedurally correct documentation, verification, assessment and use as evidence or legally significant information.
The key word here is not search. It is proof.
Two different goals
Classic OSINT sets itself a clear goal: to find. Who is the director. Where did they work. Which companies stand behind them. Which accounts, photos, documents. When and where they were present. For most OSINT work, establishing the fact is where it ends.
Legal OSINT begins precisely where the classic approach stops. Its goal is different — not to find, but to answer the question: can what was found be used in a legal process? And that is an entirely different kind of work.
The simplest example
There is a photograph. An OSINT analyst says: “This is Kyiv.”
Legal OSINT is not satisfied with that. It asks a series of other questions:
- How exactly was this established?
- Which features were used?
- Could another specialist independently reproduce the analysis and reach the same conclusion?
- Which alternative versions were considered and ruled out?
- When was the photo captured?
- How was the integrity of the material ensured from the moment of discovery?
- Is this enough for a court?
The difference is not in search skills. The difference lies in what happens after the find.
Classic OSINT vs Legal OSINT: a comparison
| Classic OSINT | Legal OSINT |
|---|---|
| Find information | Obtain legally significant information |
| Tools | Methodology + process |
| Search | Search + preservation |
| Analysis | Analysis + verification |
| Result | Evidentiary material |
| Report | Evidence bundle |
| Accuracy | Reliability + admissibility |
| Intelligence | Intelligence + Evidence |
Five differences worth remembering
First. Classic OSINT ends with the words “we established…”. Legal OSINT only begins there — because the next thing you inevitably hear is: “show us exactly how you established it.”
Second. Classic OSINT loves tools. Legal OSINT loves process. It doesn’t matter whether it is Maltego or anything else. Only one thing matters — whether the result can be reproduced. A tool that leaves no reproducible trail is almost useless for proof.
Third. Classic OSINT works with information. Legal OSINT works with evidence. These are different things: not all information is evidence, and not every piece of evidence carries the same weight. That is why Legal OSINT combines OSINT approaches with the principles of digital evidence, electronic proof and proper verification.
Fourth. Classic OSINT asks: what did we find? Legal OSINT asks: will we be able to explain it to a court?
Fifth. Classic OSINT ends with a report. Legal OSINT does not end. After the report there is still verification, formalisation, preservation, the chain of custody, explanation of methodology, an assessment of reliability and, ultimately, presentation in court.
The seven elements of Legal OSINT
Reduced to a structure, this discipline consists of seven sequential elements:
- Collection — gathering information from open sources.
- Preservation — capture and storage with integrity assurance.
- Verification — checking and confirming reliability.
- Analysis — analysing the collected material.
- Legal Assessment — the legal evaluation of what was obtained.
- Reporting — presenting the results in a usable form.
- Court Readiness — readiness of the material to be used as evidence.
Classic OSINT confidently completes the first four steps. Legal OSINT carries the matter through to the seventh.
Conclusion
The difference between the two approaches fits into a single line:
OSINT answers the question “what happened?” Legal OSINT answers the question “how do we prove it?”
This is precisely what defines the distinct value of the discipline. Classic OSINT ends with a well-founded analytical conclusion. Legal OSINT takes the next step: it ensures that this conclusion is not only convincing to the analyst, but also clear, verifiable and fit for legal procedures. It is not a replacement for classic OSINT — it is its evolution toward proof, procedural reliability and legal significance.
And while a settled definition of Legal OSINT does not yet exist in the world, we have a chance to shape it here.
