By Navid Sobbi, Founder and CEO, NSI Global
Executive Summary
A private-investigator licence permits the holder to provide specified investigative services. It does not confer police powers, create a general right to enter property, authorise interception or tracking, unlock protected databases, or make an otherwise unlawful instruction legitimate. A corporate investigation remains constrained by the authority of the client, the investigator’s licence conditions and the laws governing the particular method.
For boards and executives, the central risk is not simply whether an investigator is licensed. The more important question is whether every proposed activity can pass seven tests: lawful purpose, correct jurisdiction, documented authority, proportionate method, controlled data handling, fair reporting and defensible closure.
The legal position is not uniform across Australia. State and territory laws regulate investigative and security activities, surveillance devices and workplace monitoring. Commonwealth law governs areas including telecommunications interception, unauthorised computer access, privacy and credit reporting. Contract, employment, discrimination, confidentiality and evidence rules may also affect an assignment.
Three conclusions should govern corporate practice:
- A public location is not a law-free surveillance zone. The method, persistence, purpose, subject, technology and manner of entry or observation all matter.
- Client authority has limits. Ownership of a device, mailbox or workplace does not automatically authorise every form of access, recording, monitoring or disclosure.
- Evidence quality begins before collection. Material can be accurate yet obtained unlawfully, taken out of context, handled insecurely or given little weight. Illegally or improperly obtained evidence is not automatically inadmissible, but its use may be contested and exclusion may be available.
Since 10 June 2025, the Commonwealth Privacy Act has also provided a statutory tort for serious invasions of privacy. Intentional or reckless intrusion upon seclusion or misuse of information may be actionable where the statutory elements are satisfied. Crime and fraud prevention can be relevant to the public-interest balance, but it is not a blanket exemption for corporate investigations.
The practical response is a controlled commissioning model. Legal, HR, risk and security leaders should approve the purpose and permitted methods in writing, define stop conditions, restrict access to collected material, require neutral reporting and close the matter with a documented retention decision.
Purpose and Scope
This white paper is intended for organisations considering or managing private investigations in Australia. It addresses internal misconduct, fraud, due diligence, insurance and claims inquiries, asset tracing, litigation support and related corporate matters.
The paper explains the Commonwealth legal overlay and examines New South Wales and the Australian Capital Territory in more detail. It is not an exhaustive statement of every state and territory regime. Licensing, mutual-recognition arrangements and permitted methods must be confirmed for each place in which investigative activity will occur.
The paper also distinguishes investigative authority from evidentiary outcome. It does not predict whether a court, tribunal, regulator or employer will accept a particular item of evidence. Those decisions depend on the governing forum, applicable evidence rules and the facts of the matter.
1. A Licence Is Permission to Operate, Not a Grant of Special Powers
In New South Wales, a Class 2E security licence authorises the holder to act as a private investigator or in a similar capacity. A business that provides security operatives must also hold the appropriate master licence, and the operative must hold the relevant individual authority. NSW Police’s Security Licensing and Enforcement Directorate administers the regime.
The licensing framework answers whether a person or business may provide the regulated service. It does not give the investigator the coercive powers of police, a regulator or a court-appointed officer. A private investigator generally cannot compel an interview, execute a search warrant, seize property, demand protected account information or require a third party to disclose records merely because a client has retained them.
The ACT’s security industry licensing information uses different categories from NSW. Organisations should not assume that a licence issued in one jurisdiction automatically covers the activity, business model or location proposed elsewhere. The engagement file should record the licence class, business authority and any recognition basis relied upon.
Licensing is therefore the first gate, not the final answer. The investigator must still identify a lawful basis for each collection technique and operate within contract, privacy, surveillance, workplace and criminal law.
2. Define the Purpose Before Choosing the Method
An instruction such as “find out what happened” is too broad to govern an intrusive investigation. The client should first state the business decision the investigation is intended to inform. Examples include whether to commence a disciplinary process, preserve assets, notify an insurer, respond to suspected fraud, test representations made in a transaction or prepare for litigation.
The written scope should identify:
- The allegation or risk being examined, without presenting it as an established fact
- The relevant people, entities, systems, locations and date range
- The information already held and the authority under which it is held
- The proposed methods, excluded methods and approval points
- The person authorised to vary or stop the assignment
- The reporting audience, legal-privilege position and retention requirements
Purpose limitation is both a legal and investigative safeguard. It reduces collection of irrelevant personal information, prevents an inquiry from drifting into unrelated conduct and makes proportionality easier to assess. If the purpose changes materially, the organisation should re-scope the matter rather than treat the original instruction as continuing authority.
3. Surveillance: Public Visibility Does Not Equal Unrestricted Use
Surveillance law is method-specific. An observation made with the naked eye, a video recording, an audio recording and a location tracker can engage different statutory rules even when they relate to the same subject.
| Activity | Lawful only when | Immediate stop or review trigger |
| Observation or photography | The investigator remains lawfully located and the conduct is necessary, proportionate and consistent with privacy, workplace and other applicable law | Entry onto private premises, persistent conduct causing safety concerns, or collection unrelated to the approved purpose |
| Conversation recording | The recording complies with the relevant surveillance-device law and any consent or lawful-interest exception actually applies to the person making it | The investigator is not a party, consent is absent, or the proposed exception has not been legally tested |
| Tracking | Express or implied consent, or a specific statutory authority, covers the person or object and the proposed use | Attaching or using a device without the required consent or extending tracking beyond the authorised period |
| Digital monitoring | The client has documented authority and the method does not involve interception, credential misuse or unauthorised access | Live interception, bypassing access controls, use of another person’s credentials, or collection outside the approved system and date range |
3.1 Listening Devices and Private Conversations
The Surveillance Devices Act 2007 (NSW) restricts the installation, use and maintenance of listening devices to record private conversations. Limited exceptions can apply, including circumstances involving a principal party and protection of that party’s lawful interests. Those exceptions are fact-dependent. A client cannot assume that an investigator who is not a party to the conversation can record it simply because the client wants evidence.
Consent should be analysed carefully. Consent to speak with an investigator is not necessarily consent to record, publish or circulate the conversation. The engagement plan should also address how any lawful recording will be stored, transcribed, disclosed and ultimately destroyed or retained.
3.2 Optical Surveillance, Entry and Trespass
In NSW, the optical-surveillance prohibition focuses in part on installation or use on premises, a vehicle or another object where that conduct involves unauthorised entry or interference. Other legal risks can remain even when the camera is operated from a public place. Persistent or highly intrusive observation may engage the new privacy tort, stalking or intimidation provisions, employment duties, confidentiality, property law or site-specific restrictions.
“Filming through a window is illegal” is therefore not a reliable universal rule. The correct analysis asks where the investigator is standing, whether any entry or interference occurred, what could reasonably be expected to remain private, how intrusive the observation is, why it is necessary and what will happen to the footage.
3.3 Tracking Devices
NSW law places strict limits on knowingly installing, using or maintaining a tracking device to determine the location of a person without the required consent, or the location of an object without the consent of the person in lawful possession or control. Narrow statutory exceptions exist, but ordinary corporate suspicion is not itself an authority.
Physical ownership also may not answer who has lawful possession or control of a vehicle or object at the relevant time. Before using telematics, a GPS device or another location technology, the organisation should examine consent, employment notice, policy wording, device ownership, off-duty use and the exact jurisdiction.
3.4 Use and Disclosure Are Separate Decisions
Lawful collection does not automatically permit unrestricted use, circulation or publication. Surveillance-device laws, privacy duties, employment processes, confidentiality and court orders can each restrict what may happen next. The report distribution list should be set before collection and expanded only after a documented need-to-know review.
4. Workplace Investigations Require an Employer-Specific Analysis
Hiring an external investigator does not allow an employer to bypass workplace-surveillance requirements. If the investigator acts for the employer, the organisation may still be causing the surveillance and remain responsible for notice, policy, consultation, covert-authority and use restrictions.
| Issue | New South Wales | Australian Capital Territory |
| Notified surveillance | Prior written notice is generally required; the notice must address the type and method of surveillance and ordinarily precedes commencement by at least 14 days unless a shorter period is agreed | Prior written notice is generally required, ordinarily at least 14 days; prescribed details and good-faith consultation obligations apply |
| Camera, computer and tracking controls | Method-specific rules apply, including visibility or policy requirements; covert surveillance requires statutory authority | Optical devices, data surveillance and tracking have method-specific notice or visibility requirements; covert surveillance requires authority |
| Private or non-work settings | Change rooms and bathrooms are protected; employer surveillance while an employee is not at work is restricted, subject to statutory detail | Surveillance is prohibited in specified private areas; surveillance of a worker outside the workplace is restricted, with narrow covert-authority provisions |
The Workplace Surveillance Act 2005 (NSW) and the Workplace Privacy Act 2011 (ACT) should be read before employee monitoring begins. The ACT regime includes good-faith consultation during the notice period. Both jurisdictions distinguish notified surveillance from covert surveillance and protect particular private areas.
Off-duty surveillance creates additional risk. In NSW, employer use of a work-surveillance device when the employee is not at work is restricted. In the ACT, surveillance of a worker outside the workplace is prohibited subject to the Act’s limited covert-authority provisions. A suspicion of moonlighting, misconduct or a false claim does not remove these statutory questions.
HR and legal teams should also consider whether the proposed inquiry is procedurally fair. Surveillance may identify conduct requiring explanation, but footage rarely supplies the entire context. Decision-makers should separate the investigator’s observations from conclusions about credibility, misconduct, medical capacity or legal liability.
5. Digital Access: Company Ownership Is Not Unlimited Authority
Corporate investigations increasingly involve mailboxes, cloud platforms, mobile devices, logs and collaboration systems. The legal analysis must distinguish authorised access to stored organisational data from interception of communications in transit.
The Telecommunications (Interception and Access) Act 1979 controls interception and access to telecommunications. A private investigator does not acquire an interception power through a retainer. The Criminal Code Act 1995 also criminalises forms of unauthorised access to or modification of restricted data and impairment of electronic communications.
An organisation may be able to authorise a properly scoped examination of information it lawfully controls, subject to employment, privacy, confidentiality and sector-specific rules. That is not authority to:
- Bypass a password or security control without a clear legal basis
- Use credentials obtained through deception, leakage or another person’s account
- Access a personal account because it was opened on a company device
- Capture live communications merely because the business owns the network
- Extend collection into unrelated systems, dates or personal material
The written authority should identify the system owner, account type, lawful custodian, approved data sources, date range and investigative purpose. Technical personnel should preserve relevant information in a manner that records source, time, method and integrity. Where compromise or deletion is suspected, NSI Global’s digital forensic investigation services can support a separately authorised technical examination.
6. Background Checks, Due Diligence and Open Sources
Private investigators can lawfully examine many public and consent-based sources. The crucial distinction is between information that is publicly searchable, information available through a regulated consent process and information that remains protected.
Examples of legitimate sources may include ASIC company records, the Personal Property Securities Register, the National Personal Insolvency Index, court material that is lawfully accessible, professional registers and information supplied by the subject or client. A nationally coordinated criminal history check should be obtained through an accredited body or police agency with informed consent, as explained by the Australian Criminal Intelligence Commission.
Public availability does not eliminate obligations concerning accuracy, relevance, platform terms, privacy, discrimination or procedural fairness. Search results may concern a different person, be outdated, omit the result of proceedings or lack necessary context. Material findings should be corroborated and the report should distinguish source fact from analytical inference.
The phrase “financial records” is particularly risky. Company extracts, registered security interests and public insolvency information are not the same as bank records, transaction histories or regulated consumer credit-reporting information. The Privacy Act’s credit-reporting provisions tightly control access and use. A client request does not open protected databases.
NSI Global’s corporate investigation services can be scoped around lawful due diligence, misconduct and fraud questions without presenting public-record research as unrestricted access to private information.
7. Interviews Are Voluntary Evidence-Gathering Activities
A private investigator generally has no power to compel a witness to attend, answer questions, produce a device or provide documents. Participation should be voluntary unless a separate lawful employment, contractual or statutory process applies and is managed by the authorised decision-maker.
At the start of an interview, the investigator should state their identity, role and the purpose of the meeting accurately. The investigator should not impersonate police, a regulator, a lawyer or another person to obtain access or information. Any recording should be assessed under the applicable surveillance-device law and the participant should not be misled about a consent process.
Good interview records distinguish the witness’s account from the investigator’s interpretation. Notes should record date, time, location, attendees, breaks, documents shown and any corrections. The final report should avoid declaring that a person is guilty, dishonest or fraudulent unless that is a properly authorised conclusion supported by the applicable decision-making process.
8. Insurance, Claims and Asset Tracing Need Neutral Reporting
Surveillance and interviews can test a claim, identify inconsistency or locate further lines of inquiry. They cannot by themselves establish a medical diagnosis, determine legal liability or “put fraud to rest once and for all”. A short video can be authentic while remaining unrepresentative of a person’s condition or normal activities.
Claims investigations should define the proposition being tested and the professional discipline responsible for interpreting the result. An investigator may document observed movement; a suitably qualified medical practitioner addresses medical significance. A forensic accountant may interpret transactions; legal advisers address the implications for proceedings or recovery.
Asset tracing should likewise distinguish public ownership records, corporate structures and registered interests from beneficial ownership conclusions or hidden assets that have not been proved. The report should identify gaps, conflicts and alternative explanations rather than converting indicators into findings.
9. Privacy Governance Now Includes a Statutory Tort
The Australian Privacy Principles (APP) regulate covered entities’ handling of personal information. They include requirements concerning lawful and fair collection, necessity, notice, use and disclosure, accuracy, security and disposal. Coverage must be analysed rather than assumed: the Privacy Act contains exemptions and qualifications, and the private-sector employee-records exemption is narrower than a general permission to investigate employees.
The Office of the Australian Information Commissioner explains the APP framework in its Australian Privacy Principles quick reference. APP 3 requires solicited collection to be reasonably necessary for a covered organisation’s functions or activities and to occur by lawful and fair means. Direct collection is generally expected unless it would be unreasonable or impracticable. The possibility that direct collection would compromise a genuine investigation can be relevant, but it requires assessment; it is not a standing exemption.
Since 10 June 2025, Schedule 2 to the Privacy Act 1988 has created a statutory tort for serious invasions of privacy. A plaintiff must establish the statutory elements, including an intentional or reckless intrusion upon seclusion or misuse of information, a reasonable expectation of privacy and seriousness. The plaintiff’s privacy interest must outweigh countervailing public interests. The tort is actionable without proof of damage.
Prevention and detection of crime or fraud can be a countervailing public interest. It does not automatically prevail. An organisation should be prepared to explain why its method was necessary, why a less intrusive alternative was inadequate, how collection was limited and who could access the result.
10. Lawful Collection and Admissibility Are Different Questions
The statement that unlawfully obtained material is automatically inadmissible is incorrect. Section 138 of the Evidence Act provides a discretionary balancing process for evidence obtained improperly or in contravention of Australian law. The court considers the desirability of admitting the evidence against the undesirability of admitting evidence obtained in that way. Different forums and proceedings may apply different rules.
The Judicial Commission of NSW summarises the statutory discretion. Organisations should not interpret the possibility of admission as permission to collect unlawfully. Illegal or improper collection can still lead to exclusion, civil claims, criminal exposure, regulatory action, adverse costs, reputational harm and damage to the substantive case.
Evidence handling should address:
- Chain of Custody: who obtained the item, from where, under what authority and at what time
- Integrity: whether an original or verified copy exists and what changes were made
- Context: what occurred before and after the recorded event and what the material cannot show
- Continuity: each transfer, custodian, access event and storage location
- Security: encryption, access control, logging, backup and breach response
- Reporting: clear separation of observation, source statement, inference and opinion
Digital material may require preservation of native files, metadata, audit logs and cryptographic hash values. These steps support authenticity and reliability; they do not guarantee admissibility. Where proceedings are anticipated, legal counsel should coordinate collection with appropriately qualified litigation-support specialists.
11. The Client Retains Governance Responsibility
An investigation contract allocates work; it does not transfer away every legal responsibility. Depending on the facts, a client may face exposure for authorising, procuring, adopting or misusing unlawful conduct. The exact basis can involve statute, accessorial liability, agency, employment, negligence, breach of confidence, privacy, contract or other law.
The organisation should appoint a responsible executive and an internal legal or compliance contact. Instructions should be issued through those people, not through informal messages from multiple stakeholders. Any request to expand surveillance, access a new account, contact a new witness or obtain protected information should return to the approval gate.
Vendor due diligence should cover:
- Licence class, business authority, jurisdiction and expiry
- Professional indemnity and public-liability insurance appropriate to the engagement
- Investigator qualifications and experience relevant to the method
- Subcontractor approval, location and supervision
- Information-security controls, breach notification and data location
- Evidence-handling, reporting, complaint and conflict procedures
- Retention, deletion, return and legal-hold arrangements
Payment method is not a reliable proxy for ethics. More meaningful indicators are transparent authority, a documented scope, lawful-method explanations, contemporaneous records, secure handling and a willingness to decline an improper instruction.
12. The Seven-Gate Commissioning Framework
| Gate | Decision required | Minimum evidence of control |
| 1. Purpose | What specific decision or risk will the inquiry address? | Written allegation, objective, scope and success criteria |
| 2. Jurisdiction | Which laws, licences and locations govern each activity? | Licence verification and jurisdiction map |
| 3. Authority | Who controls the premises, system, record, account or object? | Written client authority, consent or identified statutory basis |
| 4. Method | Is the proposed technique necessary and proportionate? | Alternatives considered, legal checkpoint and stop conditions |
| 5. Data | What will be collected, protected, shared and retained? | Collection plan, access list, security controls and retention rule |
| 6. Reporting | How will facts, statements and inferences be distinguished? | Source-referenced neutral report and review process |
| 7. Closure | What happens when the purpose is met or cannot be met? | Return, deletion, legal hold, lessons learned and licence record |
No single gate cures failure at another. A strong fraud allegation does not correct an unlawful tracking method. Consent to access one mailbox does not authorise unrelated personal accounts. A technically sound recording does not justify disclosure beyond the approved audience.
The framework should be applied at commissioning and revisited whenever the facts, jurisdiction, subject, technology or intended use changes.
Questions the Board and General Counsel Should Ask
- Which investigations are active, who authorised them and what decision is each intended to inform?
- Have the operative and provider authorities been verified for every jurisdiction involved?
- Does the written scope identify methods that are prohibited without further approval?
- Who confirmed the client’s authority over each system, device, premises and record?
- Could the objective be achieved using a materially less intrusive method?
- How are workplace notice, covert-authority and off-duty restrictions addressed?
- What information is accessible to the investigator, and how is unrelated material excluded?
- Can the organisation reconstruct every transfer and access event for important evidence?
- Does the report distinguish observed fact, witness statement, public-record data and inference?
- When is collected material returned, destroyed, de-identified or placed on legal hold?
Conclusion
Private investigators can provide valuable, independent fact-gathering for corporate decisions. Their value depends on disciplined scope and lawful method, not secrecy or special access. The investigator’s licence establishes an ability to operate in a regulated field; it does not remove the client’s duties or the legal boundaries surrounding surveillance, data and evidence.
The defensible approach is to authorise narrowly, verify jurisdiction, test proportionality, protect the collected material and report without advocacy. When those controls are built into the engagement from the outset, an organisation is better placed to use the findings in employment, insurance, governance or litigation processes without allowing the investigation itself to become a new source of exposure.
NSI Global provides private-investigation support and broader investigations services for corporate matters in which the objective, authority and permitted methods are defined at the start. For a confidential scoping discussion, contact NSI Global.
Frequently Asked Questions
Can a Private Investigator Follow Someone in Public?
Observation from a lawful location may be permissible, but public visibility is not blanket authority. The investigator must consider surveillance-device law, workplace restrictions, the privacy tort, stalking or intimidation risks, property boundaries, purpose and proportionality. Persistent or intrusive conduct should be reviewed before it continues.
Can a Private Investigator Record a Conversation Without Consent?
The answer depends on the jurisdiction, whether the conversation is private, who is a party, the device used and whether a statutory exception applies. A client should not assume that an investigator can rely on an exception belonging to a participant. Obtain advice before covertly recording a conversation.
Can a Private Investigator Put a GPS Tracker on a Vehicle?
Not merely because the client owns the vehicle or suspects misconduct. NSW law restricts tracking a person or object without the required consent, and workplace laws may also apply. Possession, control, policy, notice, off-duty use and jurisdiction must be examined before deployment.
Can an Employer Ask an Investigator to Read Work Email?
An authorised, targeted examination of stored company information may be possible, subject to employment, privacy, confidentiality and sector rules. That is different from intercepting communications or accessing personal accounts. The authority, custodian, system, date range and purpose should be documented before access.
Can a Private Investigator Obtain a Police Check?
A nationally coordinated criminal history check is obtained through an accredited body or police agency and requires informed consent. A private investigator cannot bypass that consent process. Other lawfully accessible court or regulatory records may be researched, but identity, relevance and context must be verified.
Does Hiring a Licensed Investigator Protect the Client From Liability?
No automatic protection applies. Licensing is important, but the client must still issue lawful instructions, verify authority, control scope and handle the result properly. Responsibility depends on the applicable law and facts.
Can an Employer Commission Covert Employee Surveillance?
Only within the statutory framework that applies. NSW and ACT workplace laws regulate notified and covert surveillance, and they restrict monitoring in private areas and certain off-duty settings. A general misconduct suspicion does not replace the required authority.
Sources and Further Reading
Research for this paper prioritised legislation, regulators and current Australian Government guidance available at the cut-off date. Requirements should be revalidated for the actual jurisdiction, assignment and technology before publication or use.
- NSW Police SLED: Class 2 security licences
- NSW Police SLED: Master licences
- Security Industry Act 1997 (NSW)
- Surveillance Devices Act 2007 (NSW)
- Workplace Surveillance Act 2005 (NSW)
- Access Canberra: Security industry licences
- Security Industry Act 2003 (ACT)
- Crimes (Surveillance Devices) Act 2010 (ACT)
- Workplace Privacy Act 2011 (ACT)
- Privacy Act 1988, including Schedule 2
- OAIC: Australian Privacy Principles quick reference
- OAIC: Employee records exemption
- Telecommunications (Interception and Access) Act 1979
- Criminal Code Act 1995
- Australian Criminal Intelligence Commission: Nationally coordinated criminal history checks
- Evidence Act 1995 (NSW)
- Judicial Commission of NSW: Discretions to exclude evidence