Global Advice Network
| Borgergade 111 | DK - 1300 Copenhagen K
|
|
|
|
Legal Risks of Social Media Vetting for Australian FirmsAcross Sydney boardrooms and Melbourne compliance departments, screening a potential joint-venture partner through LinkedIn, Facebook and Instagram has become routine shorthand. A few minutes of scrolling often feels faster and cheaper than commissioning a private investigator or waiting on a formal background check. Yet the same casual approach that feels harmless during a video call can quietly cross legal lines once it is written into a vetting workflow. Australian firms are subject to a layered web of privacy, defamation and evidence laws that do not always match the practices baked into popular social platforms. Before social media evidence is added to a compliance file, decision-makers need a clear view of where informal research ends and unlawful surveillance begins. The sections below map the legal terrain, drawing on practical examples from cities such as Brisbane, Adelaide and Perth where international partnerships are frequent. The Allure of Open-Source Intelligence in Partner VettingOpen-source intelligence, often shortened to OSINT, refers to information that is publicly available and gathered without covert intrusion. In the due diligence context, OSINT typically includes corporate registries, court dockets, news archives, professional networks and the public side of social media platforms. The appeal is straightforward: it is fast, inexpensive, and can be carried out by junior staff using only a browser. For a mid-tier engineering firm in Adelaide weighing a partnership with a Singapore-based supplier, scrolling through a director's public posts can reveal affiliations, lifestyle signals and discrepancies with the disclosed bio. That kind of cross-checking used to require expensive field inquiries, and it is now conducted in minutes. The efficiency gain explains why social media screening has been folded into standard onboarding across industries from mining in the Pilbara to fintech in Barangaroo. Still, the legal characterisation of a "public" post is far from settled. Privacy regulators in several jurisdictions have signalled that the mere fact a post is viewable without logging in does not mean it carries no legal protection, particularly when collected, stored or shared at scale. That distinction matters for compliance officers building a defensible record of how partners are approved. Australian Privacy Laws and What They Mean for Social Media ScrapingAustralia's Privacy Act 1988 (Cth) and the thirteen Australian Privacy Principles govern how personal information is collected, used and disclosed. The Office of the Australian Information Commissioner has consistently held that information visible on a public social media profile is still personal information when it is collected by an organisation for its own purposes. Even viewing and saving a post can count as collection under the Act if it is used to inform a business decision. The practical implication is significant for compliance teams. A procurement officer in Brisbane who downloads screenshots of a supplier's Facebook page to attach to an internal file is creating a record of personal information handling that may need to be documented in the organisation's privacy policy. Failure to update the policy or to provide a collection statement can expose the business to complaints, investigations and reputational fallout with regulators and the broader Australian public. Small and medium enterprises often assume the Privacy Act applies only to large turnovers or health data, but the small business exemption has been narrowed repeatedly. Many firms that once fell outside the regime now sit within it, and even those that do not are bound by contractual obligations to counterparties in larger supply chains. Before any social media research is logged, the question is not just whether the information is visible, but whether the manner of collection aligns with the firm's notified practices. Defamation, Misuse of Private Information and the Risks of Going Too FarDefamation law in Australia operates at the state and territory level, with reforms in New South Wales, Victoria, Queensland and Western Australia converging around a serious-harm threshold. A social media post that paints a prospective partner in an unfavourable light, even if it originates from a third party, can become a problem for the firm that reposts or repackages it inside a due diligence report. Internal circulation does not shield the organisation from liability when the content is later shared with bankers, lawyers or regulators. The tort of misuse of private information, recognised in Australian courts following the 2017 decision in ABC v O'Neill, adds a further layer. Where information on a social profile is genuinely private, even if not hidden behind a strict privacy setting, harvesting and using it for commercial vetting can give rise to a cause of action. Courts have shown particular concern for information that reveals personal beliefs, health matters or family circumstances, all of which frequently surface on platforms that users treat as semi-private. Another overlooked exposure is the way platform terms of service function alongside domestic statutes. Aggressive scraping, the use of fake accounts to view restricted content, or circumventing technical access controls can breach those terms and trigger takedown notices, account bans or civil claims from the platforms themselves. A compliance file built on information gathered through deceptive means rarely holds up under scrutiny. Cross-Border Complications When Reviewing Overseas PartnersMany Australian firms pursuing international growth in markets such as India, Indonesia and Vietnam routinely combine local registry checks with social media research on directors and ultimate beneficial owners. The cross-border dimension multiplies the legal variables, because the collection may simultaneously engage Australian privacy law, the privacy regime of the partner's home country, and the terms of the social platform. For example, a team in Melbourne preparing a joint venture with a Mumbai-based manufacturer might be tempted to use a content aggregation service to pull years of posts from a director's accounts. That same activity could fall foul of India's evolving data protection framework, where consent and purpose limitation rules are stricter in several respects than Australia's. Referencing the India country profile before any cross-border collection is a sensible first step, because it helps the team map applicable local obligations. Layered onto this is the risk that a piece of social media content admissible in one jurisdiction will be excluded or treated differently in another. Australian courts and arbitral bodies retain discretion over what evidence they accept, and material obtained in breach of foreign law can be ruled inadmissible or carry reduced weight. Boards operating across the Asia-Pacific corridor should build that variance into their risk assessments rather than treat overseas vetting as a uniform process. Evidence Standards and What Tribunals Will Actually AcceptA surprising amount of due diligence material never sees the inside of a courtroom, but the material that does is judged against strict rules. Screenshots, downloaded videos and cached web pages are routinely challenged on the basis of authenticity, completeness and the manner in which they were obtained. A post that has been edited, deleted or set to private between collection and trial loses much of its evidentiary value, and a chain of custody that cannot be reconstructed will rarely persuade a judge. The Federal Court of Australia and the Australian Securities and Investments Commission have both expressed scepticism toward social media evidence collected without clear protocols. In regulatory investigations, the origin of a screenshot matters as much as its content, which is why FCPA subpoena advice circulated for American matters still carries useful structural lessons for Australian teams preparing for the equivalent domestic inquiries from ASIC or the Australian Federal Police. Another practical point concerns metadata. A downloaded image stripped of its EXIF data carries less weight than one preserved with timestamps, geolocation markers and the URL of origin. Compliance teams that treat social media evidence as casually as a marketing scrapbook will find that work harder to defend later, regardless of what the content actually says about the partner in question. Documentation Trails and the Value of a Defensible ProcessThe strongest protection against legal exposure is a documented process that any reasonable compliance officer could follow and any regulator could audit. That process should describe the legal basis for each collection, the staff member responsible, the source URL, the date and time, and the reason the information is needed for the specific vetting decision. Where audit logging practices are adapted from software engineering into compliance workflows, the same principles of immutability and traceability apply. For a Perth-based mining contractor onboarding a new equipment supplier, that documentation might include a checklist item confirming that the social media review was conducted by an authorised officer, that findings were stored in a restricted folder, and that the supplier was given an opportunity to respond to any adverse content. Each of these steps creates a small but meaningful buffer against complaints of unfairness or unlawful collection. Documentation also helps when the partnership is later terminated on grounds of integrity. If the supplier disputes the decision, the firm's records should be able to demonstrate not only that the information was accurate, but that the process used to obtain it was lawful, proportionate and consistent with internal policy. That evidentiary foundation is what separates a routine compliance step from a future liability. When to Bring in External Investigators and Compliance SpecialistsSome vetting questions go beyond the capacity of in-house teams, particularly when a partner's footprint spans multiple jurisdictions or when the alleged misconduct is serious. External investigators bring access to licensed databases, formal interview techniques and the legal training to collect information in a way that courts will accept. They also carry professional indemnity insurance that absorbs some of the risk inherent in the engagement. Australian firms are well served by specialists who understand both local privacy law and the regulatory expectations of the Australian Transaction Reports and Analysis Centre, the Australian Federal Police and ASIC. Engaging a specialist is not an admission of weakness; rather, it signals that the firm has weighed the legal variables and chosen a defensible route. Many providers will scope the engagement to focus on areas where social media research is genuinely necessary, avoiding the temptation to over-collect. For tailored guidance on the regulatory environment of a specific partner country, or to clarify which tools best suit a particular vetting scenario, compliance leaders can contact the team for a confidential conversation. Early specialist input often turns a legal risk into a manageable compliance step. Practical Steps for Australian Compliance Teams
The most resilient approach treats social media research as one input among many, weighed alongside registry checks, audited financials and direct references. A team that builds a documented, lawful and proportionate process today is far better placed to defend its decisions tomorrow, whether those decisions are scrutinised by a board, a regulator or a courtroom in Sydney, Melbourne or further afield. |