Skip to content
Seqlense DOC Seqlense Web3 Monitoring Seqlense Notes Audit & Advisory Investigation Crypto OSINT Investigation Training & Advisory Seqlense Immo Pricing Academy Blog Partners Supported Chains Contact My Seqlense Get Started
Back to blog

Building a subject profile from public sources, responsibly

Rigorous, lawful enrichment without overreach or contamination.

Building a subject profile from public sources sounds simple: search a name, collect what comes back, write it up. In a compliance or investigation context it is anything but. The information you gather is personal data, the reasons you gather it are legally constrained, and the way you assemble it decides whether the result holds up under scrutiny or falls apart the first time someone challenges it. Doing this well means enriching a profile from public sources without overreaching and without contaminating the file.


Start from a lawful purpose, not from curiosity

Before the first search, write down why you are building the profile. Enhanced due diligence on a high-risk client, an adverse-media check, a sanctions nexus, a suspected beneficial owner behind a shell structure: each is a legitimate reason, and each sets a boundary. Under EU data protection law you need a lawful basis and a defined purpose, and everything you collect afterward should map back to it.

Two principles from Article 5 of the GDPR do most of the work here:

  • Purpose limitation: data collected for one reason should not quietly be reused for another.
  • Data minimisation: collect what is adequate, relevant and limited to what is necessary, and no more.

A subject profile that pulls in a person's hobbies, family photos or old political posts because they happened to surface is not thorough. It is a liability. If a data point does not serve the stated purpose, it does not belong in the file.


Public does not mean fair game

"Open source" describes where the data sits, not what you are allowed to do with it. A profile assembled from public posts, registries and leaks is still a processing operation, and the subject retains rights over it. Treat the accessibility of a source and the lawfulness of using it as two separate questions.

Practical guardrails:

  • Prefer authoritative sources: company registries, official gazettes, court records, sanctions and PEP lists, regulator publications.
  • Be cautious with scraped social media, data-broker aggregations and breach dumps. They may be lawful to consult in narrow cases, but they carry accuracy and provenance risks.
  • Do not use deception, fake accounts or access to closed groups to reach material that is not genuinely public. That crosses from research into intrusion.
  • Keep collection passive. Building a profile is observation, not contact with the subject.

Guard against contamination

Contamination is the quiet failure mode of open-source work. It happens when a weak claim enters the file and then hardens into a fact because nobody revisited it. A namesake in another country, a satirical article read as news, an AI-generated summary of an event that never happened: any of these can anchor a wrong conclusion.

Reduce the risk with a few disciplines:

  • Separate raw material from analysis. Keep the screenshot or archived page distinct from your interpretation of it.
  • Corroborate identity before you attribute anything. Common names, transliterations and shared dates of birth produce false matches constantly. Attribute a fact to a person only when at least two independent, reliable indicators line up.
  • Record provenance for every item: the source, the URL, the capture date, and who collected it. A claim with no traceable origin should not drive a decision.
  • Grade your confidence. Distinguish confirmed, probable and unverified. Do not let an unverified lead travel through the report as though it were established.

Capture in a way that survives challenge

An open-source finding is only as good as your ability to show where it came from. Pages change, accounts vanish, and "I saw it online" is not evidence. Capture the full context at the moment of collection: the rendered page, the URL, and a timestamp, ideally with an archived copy. If a later reviewer, a regulator or a court asks you to reproduce the chain, you want to hand over a record, not a memory.

The same rigour applies to on-chain enrichment. A wallet address linked to a subject is a strong signal, but the attribution has to be evidenced, not assumed, and clustering heuristics are leads to verify rather than conclusions to state.


Keep the file proportionate over time

A subject profile is not a permanent archive. Once the purpose is served, review what you are still holding. Retention should match the compliance obligation that justified the work, and stale, unnecessary data should be removed. This is both a legal requirement and a quality control: a lean, well-sourced file is easier to defend than a sprawling one full of half-checked material.

Build a short internal standard so every analyst works the same way:

Step What good looks like
Purpose Written down before collection begins
Sources Authoritative first, risky sources flagged
Identity Two independent indicators before attribution
Provenance Source, URL and date captured for each item
Confidence Every claim graded, unverified marked clearly
Retention Reviewed against the original purpose

Where tooling helps

Much of this discipline can be built into the workflow rather than left to individual habit. Seqlense supports the parts that benefit most from structure: Investigation and OSINT services for evidenced open-source work, blockchain Monitoring for attributing and risk-scoring on-chain activity, and Notes as an internal knowledge base where provenance and reasoning stay attached to the finding. The goal is not more data. It is a profile you can stand behind, built from sources you can show, for a purpose you can name.


Sources

Related articles

Mixers, bridges and privacy coins: scoring counterparty risk

A pragmatic view of the hardest-to-trace flows and how to risk-rate them.

Mapping a new regulation to your internal controls

A repeatable method that goes from legal text to a named control owner.