III The Method

The Cost of Looking

Commissioning an investigation changes the thing being investigated, and the exposure is created long before any report exists.

A glass office facade photographed from street level, its panels reflecting cloud, with a canopy of louvres overhead.
Samuel Zeller · CC0 1.0

Most firms in this sector sell discretion as a property of the report: your findings will be held closely, your name will not appear, the file will be destroyed on request. All of that is worth having and none of it addresses the actual exposure, which is created before any report exists.

The firm's own counterintelligence page puts it differently. "We operate with the understanding that the existence of an investigation is itself a vulnerability." That is a claim about the operation, not about the document. It says that enquiry is an intervention — that the act of looking changes the thing being looked at, and can be detected, and can be used.

If that is true, the decision to investigate is a decision to act, and it should be taken the way an action is taken rather than the way a report is ordered.

Four surfaces

The instruction. The first people to learn that a subject is under enquiry are inside the commissioning organisation. An engagement is procured, budgeted, minuted, invoiced and filed. Someone approves it. Someone books it to a cost centre with a name. In a dispute, in an acquisition, in a family matter, the population that knows a question is being asked is frequently larger than the population that will ever read the answer, and it is drawn from exactly the group with a motive to mention it. Compartmentation on the investigator's side is worthless if the mandate is visible on the client's.

The collection. The method this firm advocates is human: "the people around a subject — former colleagues, counterparties, communities — reveal what filings never record." That is correct, and it carries a cost that follows from the same property. The people around a subject are, by definition, connected to the subject. What makes them informative makes them conductive. Every approach is a signal with a direction, and the direction is inward. A database query is inert; a conversation is not. A firm that argues for human enquiry — as this one does — owes the reader the second half of that argument.

The record. An investigation creates personal data, and the architecture of access to that data is not controlled by the person who commissioned it. Where personal data are obtained from a source other than the individual concerned, Article 14 of the GDPR requires the controller to give that individual specified information — including the source and the purposes — within a reasonable period and at the latest within one month. The exemptions in Article 14(5), including impossibility and disproportionate effort, are narrower than they are usually assumed to be: the European Data Protection Board expects a documented balancing exercise weighing the controller's effort against the consequences for the individual of not being told, and the UK regulator's position is that the more significant the effect of the processing, the less likely reliance will succeed. The obligation has been enforced. The Polish supervisory authority's first GDPR fine, imposed in March 2019, concerned a data analytics company that had aggregated information on more than seven and a half million people from publicly available sources and had notified only the several hundred thousand for whom it held an email address.

In the United Kingdom the exemptions in Schedule 2 to the Data Protection Act 2018 are qualified throughout by the words "to the extent" — they apply to the specific information that meets the test, not to a whole file. The practical consequence is simple and is regularly overlooked at scoping: a subject may have a route to learn that they were a subject, and that route is a matter of law rather than of the investigator's discretion.

The pattern. A sophisticated counterparty watches for enquiry the way a client watches for them. Approaches to former employees, an unusual pattern of registry requests, a lawyer's letter that reveals what its author already knows — these are read. The exposure is not that the subject discovers the findings. It is that the subject discovers the timing, and adjusts before the findings can be used.

The argument

Two positions follow, and the second is the one worth disagreeing with.

The first is that an investigation should be scoped as an operation. That means a stated cover plan, a compartmentation model that includes the client's own organisation, an identified lawful basis in each jurisdiction touched, a decision in advance about what happens if the enquiry is detected, and a defined moment at which the mandate ends. None of that is exotic; it is simply what "security is our baseline protocol" means when written out.

The second is that some questions should not be asked. Where the value of an answer is lower than the cost of the subject learning that the question was put, the correct mandate is a narrower one — or none. This is not a comfortable position for a firm that is paid to answer questions, and it has a price: it means declining the broad exploratory screen in favour of the specific one, and it sometimes means telling a client that the enquiry they want is more dangerous to them than the ignorance they currently have.

The objection is obvious and fair: this is an investigator's caution presented as ethics, and it conveniently justifies slow, expensive, narrow work. The answer is that the position is testable. A firm that holds it will refuse mandates, will scope down rather than up, and will accept a standard it can be measured against — that every mission remains invisible to the opposition until the point of resolution. A firm that does not hold it will take the broad brief, and the broad brief is where detection happens.

Where the cost is low

The cost of looking is not uniform, and pretending otherwise would be its own distortion.

Where enquiry is expected, it is close to free. Consented pre-employment screening, standard onboarding diligence, sanctions and watchlist checks conducted within the data protection and privacy law of each jurisdiction involved and only where a lawful basis exists — in these the subject knows that screening is routine, and discovering it tells them nothing they did not assume. The same applies to diligence disclosed as part of a transaction process.

The cost rises sharply in a narrow band: where the subject does not expect to be examined, where they have the capacity to react, and where their reaction can defeat the purpose. That band contains most of the matters that are worth investigating at all, which is precisely why the exposure is underpriced. It is invisible in the ordinary case and decisive in the exceptional one.

The consequence for scoping

The right first conversation is not about what a client wants to know. It is about what happens if the subject learns the question was asked — and whether the answer, obtained at that price, would change any decision the client is actually able to take. Where it would not, the enquiry is expenditure with a downside and no upside. Where it would, the enquiry should be built so that the subject learns nothing until the point at which learning it no longer matters.

Nothing here states a legal position. Data protection and privacy obligations differ materially between jurisdictions, and their application to a specific enquiry is a question for counsel in each relevant territory.

The posture described here is the one set out under Counterintelligence & Sovereign Decision Intelligence and Sensitive Investigations; where the concern runs the other way — that someone is looking at you — it is Counter Surveillance & TSCM.

Sources

  1. GDPR Article 14 — Information to be provided where personal data have not been obtained from the data subject
  2. ICO — A guide to the data protection exemptions
  3. Data Protection Act 2018, Schedule 2 (legislation.gov.uk)
  4. Rethinking the 'disproportionate effort' exemption under GDPR (on the Polish DPA's first GDPR fine, March 2019)