Select Page
Author: Adrian Ramdat (Director of Training & Consultancy)

November 2025

The Investigatory Powers Tribunal’s decision in Davies v British Transport Police remains one of the clearest and most powerful warnings to investigators and intelligence professionals about the consequences of failing to understand surveillance law.

In Davies, the Tribunal found that officers had engaged in covert activity without lawful authorisation under the Regulation of Investigatory Powers Act 2000 (RIPA). The judgment was unequivocal:

“A detective of any standing should have knowledge of the legal requirements relating to the investigation of crime, including RIPA, and ignorance is neither excuse nor mitigation.”

The Tribunal highlighted “a disturbing lack of familiarity with the relevant requirements of RIPA by almost every officer involved”, concluding that the failures stemmed from “inexcusable ignorance” and a lack of organisational training. It directed the Chief Constable to implement urgent and comprehensive RIPA training across the force.

Although the case arose in England under RIPA, the same principles apply equally to those operating under the Regulation of Investigatory Powers (Scotland) Act 2000 (RIP(S)A).

Why This Matters Beyond Conventional Surveillance

The lessons from Davies extend far beyond conventional surveillance activities. Every investigator, intelligence officer, analyst, and researcher now operates in a digital environment where routine online enquiries can inadvertently cross into RIPA or RIP(S)A territory.

Common examples include:

  • Monitoring or recording a suspect’s social media activity.
  • Systematically viewing or collecting online material linked to a person of interest.
  • Using a false identity or profile to obtain information. 

The Covert Surveillance and Property Interference Code of Practice makes it clear that surveillance is not confined to physical observation.

RIPA and RIP(S)A both define surveillance as:

“Monitoring, observing or listening to persons, their movements, conversations or other activities and communications, or the recording of anything so monitored, observed or listened to.”

The Code further explains that extracting or recording information obtained through such monitoring may amount to directed surveillance if it is covert, carried out as part of a specific investigation, and likely to obtain private information. 

In practical terms, this means that digital research, social media monitoring, or profile-building, if persistent, systematic, or targeted, is likely to require formal authorisation.

A legal adviser from a local authority recently told me that investigators regularly discuss “monitoring people’s social media accounts”, yet the organisation’s records show no directed surveillance applications for more than a decade. This disconnect is widespread and dangerous.

Close reading of the Code of Practice confirms that extracting information to build intelligence profiles is precisely the kind of activity that may need authorisation under RIPA or RIP(S)A.

Many intelligence professionals argue that such authorisations create excessive bureaucracy. Having worked in intelligence for many years, I understand the sentiment but the law is unambiguous. Failure to comply is not a shortcut; it is an operational risk that can jeopardise investigations and potentially careers.

Knowledge is Compliance

RIPA and RIP(S)A exist to balance investigative necessity with the protection of individual rights. Breaching these safeguards risks:

  • Legal challenge and civil claims.
  • Compromised evidence and failed prosecutions.
  • Loss of public confidence and reputational harm.
  • Disciplinary or even in some cases criminal liability for staff.

In today’s digital landscape, the line between overt and covert activity is thin and easily crossed. Understanding the law and seeking early advice from authorising officers or legal advisers are essential professional safeguards.

Practical Checklist for Investigators

Before undertaking any online, covert, or intelligence-led research, consider the following areas:

Purpose and focus

  • Is this activity part of a specific investigation or operation?
  • Could it result in the acquisition of private information about a person?

If so, it may amount to directed surveillance and require authorisation.

Covert nature

  • Would the subject know this activity is taking place?

If not, it is likely to be covert under RIPA/RIP(S)A. 

Frequency and pattern

  • Is this a one-off check, or part of persistent monitoring or profiling?

Persistent or systematic activity increases the likelihood of authorisation being required.

Identity used

  • Are you using your real identity or an assumed identity or false account?

Using a false persona means you are acting covertly and if you to interact with anyone you may engage Covert Human Intelligence Source (CHIS) provisions which must be authorised accordingly.

Recording and storage

  • Are you capturing screenshots, notes, or downloaded material?

Ensure compliance with the product safeguards in the Code of Practice, your organisation’s policy, and data protection requirements.

Advice and authorisation

  • If there is any doubt, stop and seek advice from your Gatekeeper, RIPA Coordinator, or legal adviser before proceeding.

Once information is gathered, it cannot be “unseen”, so get it right from the start.

Returning to the Legal Test

Ultimately, investigators should return to the legal definition of directed surveillance, the standard by which the courts, the Investigatory Powers Tribunal (IPT) and the Investigatory Powers Commissioner’s Office (IPCO) will assess any activity:

“Surveillance is directed if it is covert, conducted as part of a specific investigation or operation, and is likely to result in the obtaining of private information about a person (whether or not one specifically identified for the purposes of the investigation or operation).”

This is the benchmark. If your activity meets these three conditions, covert, for a specific investigation or operation and likely to obtain private information then it requires authorisation.

The safest professional approach is simple: start with the legal definition and work backwards. If you cannot clearly demonstrate why the activity falls outside that definition, you should assume that authorisation is necessary and seek it before proceeding.

Conclusion

Whether operating on the street or behind a keyboard, every investigator and intelligence professional must remember that lawful authority is the foundation of professional legitimacy.

The Davies case is not just a lesson in compliance; it is a warning. The courts, the Investigatory Powers Tribunal and the Investigatory Powers Commissioner’s Office, will always return to the legal definition of directed surveillance when assessing whether activity was properly authorised.

If your actions meet the legal definition then by law they require an authorisation. Failure to recognise that is not a procedural oversight, it is a breach of primary legislation.

Ignorance of RIPA or RIP(S)A is not a defence. It represents an operational risk, a reputational risk, and a compliance failure.

Knowledge and compliance are the only credible safeguards when your decisions are later scrutinised by IPCO, the IPT or the courts.

If your organisation has not reviewed its RIPA/RIP(S)A, policy or had and training recently, now is the time to act.

Contact us now to discuss how we can support your organisation with RIPA/RIP(S)A awareness, initial training for applicants and authorising officers, refresher sessions, or bite-sized workshops such as our in-demand session on RIPA/RIPSA and social media or a policy review.

Ensuring your staff understand the boundaries of lawful surveillance isn’t optional, it’s a professional obligation.

Give us a call on 020 3883 5843 or email us at info@thesignaturebrand.co.uk