Select Page
Author: Adrian Ramdat (Director of Training & Consultancy)

March 2025

The Regulation of Investigatory Powers Act 2000 (RIPA) has been a significant piece of legislation in England, Wales and Northern Ireland since it was enacted in October 2000. Scotland has its own version called the Regulation of Investigatory Powers (Scotland) Act 2000 (RIPSA).

This article explores some of the issues regarding Directed Surveillance and the use of Covert Human Intelligence Sources (CHIS) under RIPA 2000 and how this applies to online activity by public bodies. All references in this article are to RIPA but these can equally be applied to RIPSA.

The purpose of RIPA is to ensure that such activities respect individual rights such as the right to respect to a private and family life, while balancing the need for effective law enforcement for preventing and detecting crime, matters of national security, public safety or other statutory reasons.

Directed Surveillance & CHIS

Directed Surveillance is in simple terms defined as covert surveillance that is conducted for a specific investigation or operation and is likely to result in the obtaining of private information about a person. It is generally pre-planned and not an immediate response to events.

A CHIS is, in essence, someone who establishes or maintains a personal or other relationship with a person for the covert purpose of facilitating access to or obtaining of information or they covertly disclose information to a member of a public authority. This often involves members of the public who provide information to public bodies but it equally applies to undercover operatives and can also include employees of local authorities or government departments.

Online Research & Investigations

When RIPA came into force in 2000, there was no Facebook, X (Twitter), LinkedIn or the other substantial number of social media platforms that are available today and, I speak from experience, online research certainly didn’t feature in intelligence or investigative activity.

However, over this period the Investigatory Powers Commissioners Officer (IPCO) and their predecessors the Office of Surveillance Commissioners (OSC) interpreted the legislation and when they overlaid the legal definitions discussed above against activities that are regularly conducted in the online world, they formed the opinion that these activities should, where necessary be authorised under RIPA.

The Code of Practice for Covert Surveillance and Property Interference states that in relation to information which is online ´…Much of it can be accessed without the need for RIPA authorisation; use of the internet prior to an investigation should not normally engage privacy considerations. But if the study of an individual’s online presence becomes persistent, or where material obtained from any check is to be extracted and recorded and may engage privacy considerations, RIPA authorisations may need to be considered. ´

This passage in the Code of Practice, while being supportive of the fact that investigators should be able to access lots of online information without an authorisation under RIPA goes on to talk of ´persistent monitoring´ and also of ´extracting information from ANY check´ so this needs to be carefully considered and not overlooked.

Some of the issues that have been seen in this area where errors are being made are a result of staff not being aware of the legal definitions of directed surveillance and CHIS, not understanding the exact point at which their activities meet the legal thresholds or too often, mistakenly, believing that if an individual places something on their personal social media account without them put on any form of protection on it then it is ´fair game´.

The Investigatory Powers Tribunal (IPT), the tribunal established to hear complaints and provide judgements on RIPA activity, said not too long ago, in one of its judgements, about an investigator´s lack of knowledge of RIPA “A detective of any standing, let alone one with several years’ experience, should have knowledge of the legal requirements relating to the investigation of crime, including RIPA, and ignorance is neither excuse nor mitigation.”

It can be said with some certainty that none of us want that to be said of us, especially in a court or tribunal so, we must understand the law and how it is applied to our activities and we should take this very seriously in all of the online research that we undertake.

In my training, I often find that some delegates go on the offensive and tell me that I am trying to make them complete RIPA applications for activities that have always undertaken or I am being too ´safe´. Not too long ago, a group of investigators that I was training said that they “didn´t worry too much about what the law said!”

I was rather shocked, to say the least, and for me, if we work in law enforcement then the law is just as important as the enforcement part of what we do. That view is borne out by the criticism from the IPT to the investigator above and anyone who knows me knows that I have never sought an authorisation ´just to be on the safe side´.

Good quality training should focus on clearly understanding the law, applying it and then if an authorisation is needed, obtain one. Equally, if we conclude that an authorisation is not needed that should be written as a defensible decision, with the relevant legal definition and relevant guidance in the forefront used as our justification.

Through this approach, we can be satisfied that we are legally compliant and safe in the knowledge that the material that we have obtained is not open to challenge which may lead to an acquittal. Plus, in the event of someone complaining to the Investigatory Powers Tribunal (IPT) then we know that we have obtained the material by following the law we won´t be required to destroy the material and we can continue to use it as intelligence or evidence and, we won´t be required to pay potentially significant amounts of compensation to the people whom we have conducted the activity against.

The Codes of Practice, for me, should be the first port of call for anyone involved in investigative activity and if you undertake this online research then you should have a good read of these, particularly the sections on covert online activity as there are some excellent examples of when an authorisation is or isn´t required. There are also some very clear explanations of whether material placed online should be considered as private or not.

For example, people often try to tell me that if someone puts something on their personal social media account with no form of protection then that is their lookout and they can´t have any expectation of privacy over that information.

As much as they may want to believe that is the case, the facts don´t support that view. The Codes of Practice refer to this expectation of privacy by stating ´Whilst a person may have a reduced expectation of privacy when in a public place, covert surveillance of that person’s activities in public may still result in the obtaining of private information. This is likely to be the case where that person has a reasonable expectation of privacy even though acting in public and where a record is being made by a public authority of that person’s activities for future consideration or analysis. Surveillance of publicly accessible areas of the internet should be treated in a similar way, recognising that there may be an expectation of privacy over information which is on the internet, particularly where accessing information on social media websites. 

It then goes on to discuss this in the context of online research by discussing the expectation of privacy when posting online and the use of privacy settings by saying ´This is because the intention when making such information available was not for it to be used for a covert purpose such as investigative activity. This is regardless of whether a user of a website or social media platform has sought to protect such information by restricting its access by activating privacy settings. ´

So, as we can see, it matters not if the person has used the privacy settings on their account or not.

However, let´s not only think that we need an authorisation for directed surveillance for the monitoring of a person’s social media account, as we saw earlier it also states that the extraction of data may require an authorisation.

This often comes as a shock to delegates on training courses, particularly in the intelligence arena, where they often talk of building profiles of people but don´t seem to be aware of the provision of extracting data potentially needing to be authorised as directed surveillance. As much as we might want the situation to be different, it isn´t and the Code of Practice is clear as to what is expected.

Turning our attention to CHIS activity this not only applies to members of the public who provide information to public bodies but it can equally apply to staff members, which can easily be missed when undertaking online activity.

The Code of Practice gives three situations where people may easily meet the threshold of being a CHIS in the online arena. These are:

  1. An investigator using the internet to engage with a subject of interest at the start of an operation, in order to ascertain information or facilitate a meeting in person;
  2. directing a member of the public to use their own or another internet profile to establish or maintain a relationship with a subject of interest for a covert purpose;
  3. joining chat rooms with a view to interacting with a criminal group in order to obtain information about their criminal activities.

Sadly, I have trained investigators in the last 6 months who have done all of these activities and were oblivious to the fact that they should have had an authorisation in place.

Not only does this mean that the information we obtain could be vulnerable to attack in legal proceedings or at the IPT but if the activity should have been authorised and wasn´t then this means it is an error that should be reported to the Investigatory Powers Commissioners Office (IPCO). This type of error could lead to financial penalties, the subject potentially being told of the activity or ultimately, if it is a systemic failing then the powers to undertake this activity being removed.

In conclusion, RIPA (and for Scotland RIPSA) and the Codes of Practice provide the legal framework that protects individual rights and identifies the activities that qualify as directed surveillance or the use of CHIS and require proper authorisation. By adhering to these guidelines, public authorities can balance the investigative demand, effective administration, and privacy rights effectively and maintain the trust and confidence of the public.

In the training that I deliver regarding RIPA and Online Activity, not only do we consider when an authorisation is required but we also examine the twelve or so methods that we can use to gather information online without needing an authorisation.

By operating in this we can feel confident in deciding on whether we do or don´t need an authorisation, to ensure that we are legally compliant and that the material that we obtain can be safely used in our investigations and will stand scrutiny in courts or tribunals.

We also offer our very popular RIPA/RIPSA Bitesize training that examines how the legislation impacts online research. This is delivered via Ms Teams and takes approx. an hour and a half, for up to 50 people.

If you and your colleagues are involved in online research then contact us now, without any obligation to see how we can help in a very cost-effective way.