Competitive intelligence ethics becomes practical when every project passes the same six decisions: purpose, collection, handling, use, outcome, and record.
Ethical questions rarely arrive as a clean choice between acceptable and unacceptable research. A source is public but carries restrictions. A contractor proposes a method the client did not approve. An interview would be useful, but honest identification may change the answer. An AI tool can summarize the material, but its data handling and source lineage are unclear.
Teams need a repeatable way to slow down before convenience becomes permission. Define the purpose, review the collection method, constrain handling, test the intended use, choose proceed, modify, escalate, or stop, and preserve the decision. This article offers operational guidance. It is not legal advice.
Separate professional ethics, company policy, and law
These three sources of responsibility overlap and remain distinct. Passing one does not satisfy the others. Use the strictest applicable boundary and send legal questions to qualified counsel for the relevant jurisdiction and facts.
| Boundary | What it contributes | Who interprets it |
|---|---|---|
| Professional ethical guidance | Shared standards for honest, responsible competitive intelligence practice | Practitioner, professional body, and ethics leadership |
| Company policy | Organization-specific rules for access, interviews, vendors, security, privacy, data, AI, and approvals | Policy owner, security, privacy, compliance, procurement, or leadership |
| Law and regulation | Mandatory obligations and prohibitions that vary by jurisdiction, data, access method, contract, and use | Qualified legal counsel and responsible business owner |
The SCIP Code of Ethics and ethics guidance says the code is a set of guidelines rather than a corporate policy. Its current principles include complying with applicable laws, disclosing relevant identity and organization before interviews, avoiding conflicts, giving honest and realistic recommendations, promoting the code with third-party contractors, and following company policies, objectives, and guidelines.
Those principles provide a professional baseline. A company still needs operating rules, named reviewers, training, and escalation routes. SCIP's ethics-policy implementation resource emphasizes training and monitoring so people can apply a policy in daily decisions.
Use a six-stage ethics decision process
| Stage | Decision |
|---|---|
| 1. Purpose | Is the question legitimate, necessary, proportionate, and owned? |
| 2. Collection | Are the source, access, identity, restrictions, and method acceptable? |
| 3. Handling | Will the team minimize, classify, store, share, retain, and delete the material responsibly? |
| 4. Use | Can the analysis and decision use remain honest, traceable, scoped, and approved? |
| 5. Outcome | Should the project proceed, proceed with modifications, escalate, or stop? |
| 6. Record | Can another reviewer understand what was approved, rejected, changed, and why? |
Pause rule: When the method depends on hiding identity, misusing access, defeating a restriction, collecting unnecessary sensitive material, or obscuring provenance, pause before collection. Convenience does not justify the gap.
Stage 1: define a legitimate and proportionate purpose
Write the business decision, competitor scope, evidence needed, people who may be affected, intended users, and expected benefit. “Gather everything about the competitor” creates no limit. “Verify current public packaging for the two plans buyers compare during renewal” creates a defined need.
Apply a minimum-necessary test before choosing sources. Ask whether a less intrusive source or narrower field can answer the question, whether personal information is needed, and whether the team can act responsibly on the result. Avoid collecting material merely because it might become useful later.
- Named decision and accountable owner.
- Competitors, products, people, markets, and time period in scope.
- Minimum evidence needed and proof threshold.
- Expected use, recipients, and retention period.
- Potential harm, conflict, or unfairness created by collection or use.
- A narrower alternative and the reason it is insufficient, if applicable.
Stage 2: review the collection method
Public access
Public visibility is one input to the review. It does not settle purpose, restrictions, privacy, proportionality, or reuse. Record the original source, access path, date, publisher, terms or notices relevant to the method, and the exact claim the source can support. Prefer first-party and official sources when they can answer the question.
Restricted or authenticated access
Treat login requirements, licenses, paywalls, invitations, contractual limits, role-based permissions, and technical controls as review signals. Use only access and identities the organization is authorized to use for the approved purpose. Shared credentials, borrowed accounts, false accounts, and methods intended to defeat access controls are stop or escalation conditions.
Do not treat a customer's, employee's, or contractor's ability to open a source as automatic permission for a competitive intelligence project. Authorization may be personal, role-limited, contract-limited, or incompatible with the planned collection and sharing.
Identity and interviews
Before an interview, disclose the relevant identity and organization as required by SCIP's guidance and the organization's policy. Define whether the sponsor, recording, attribution, confidentiality, or intended use also needs disclosure. Do not pose as a customer, applicant, student, partner, or another person to obtain information.
Source restrictions and technical barriers
Document source-specific restrictions and technical signals before automating collection. Respect approved rate, scope, authentication, and usage boundaries. If collection succeeds only by working around a barrier or disguising the actor, stop and send the proposed method for policy and legal review. This framework does not provide bypass instructions.
| Collection question | Evidence to keep |
|---|---|
| Who owns or publishes the source? | Verified publisher, domain, and entity relationship |
| How is it accessed? | Public URL, approved account, licensed provider, interview, manual submission, or other named route |
| Which identity is presented? | Person, organization, role, and disclosures made |
| Which restrictions apply? | Terms, license, contract, notice, authentication, access control, and company policy reviewed |
| What is collected? | Exact fields, records, pages, time window, frequency, and exclusions |
| Who approved the method? | Named owner and any security, privacy, compliance, procurement, or legal reviewer |
Stage 3: constrain handling before data arrives
A suitable collection method can still create risk through careless storage, unrestricted sharing, or indefinite retention. Design handling at the field and source level before collection. Raw material may require tighter treatment than an approved, sourced summary.
| Handling control | Required decision |
|---|---|
| Minimization | Which fields and copies are essential to the stated purpose? |
| Classification | Is the material public, licensed, confidential, personal, sensitive, restricted, or uncertain? |
| Storage | Which approved system, location, encryption, and backup rules apply? |
| Access | Which roles need raw evidence, working analysis, and approved conclusions? |
| Sharing | Can the material leave the project, cross borders, enter a presentation, or reach a vendor? |
| Retention | Which event or date triggers deletion, review, archival, or source refresh? |
| Deletion | Who confirms deletion across working files, exports, vendor systems, and backups where applicable? |
| Incident route | Who receives a report if restricted, personal, confidential, or misdirected material appears? |
Quarantine material when its source or permission is unclear. Do not copy it into a general competitor profile, model prompt, or shared folder while the team investigates. Record who supplied it and avoid wider access. The decision owner can delete, return, restrict, or escalate it under company policy.
Stage 4: test the intended use and conclusion
Ethical collection does not guarantee ethical use. Preserve provenance, scope, uncertainty, contradiction, and source restrictions through the analysis. Do not present an estimate as a fact, a single report as a market pattern, a public claim as verified performance, or an absence as proof when coverage is incomplete.
Check conflicts of interest and audience risk before distributing the conclusion. A consultant may serve companies whose interests conflict. A sales team may strip qualifications from a battlecard. A public statement may require a higher proof and approval threshold than an internal working hypothesis. Name the permitted audience and decision use.
Add an AI processing gate
Before sending evidence to an AI service, check whether the provider and account are approved, which data may enter, where it is processed, how it may be retained or used, who can access outputs, and whether deletion and audit requirements can be met. Remove unnecessary personal, confidential, licensed, and restricted material.
Require source IDs, dates, company identity, scope, contradictions, unknowns, and human verification for material claims. The guide to AI competitor analysis with traceable evidence provides the full analysis workflow.
The NIST AI Risk Management Framework is a voluntary framework for managing risks to individuals, organizations, and society across the design, development, use, and evaluation of AI systems. It can inform an organization's AI governance process. It does not replace applicable law, contracts, company policy, or project-specific approval.
Stage 5: choose proceed, modify, escalate, or stop
| Outcome | Use it when | Next action |
|---|---|---|
| Proceed | Purpose, collection, handling, and use meet all applicable boundaries | Record approval, controls, owner, and review trigger |
| Modify | The question is legitimate but method, data, scope, retention, vendor, or audience must change | Document the original proposal and approved modifications before collection |
| Escalate | A material legal, policy, security, privacy, contractual, jurisdictional, or conflict question needs an authorized decision | Pause the disputed activity and send concrete facts to the named reviewer |
| Stop | The purpose is unjustified or the method depends on misrepresentation, unauthorized access, bypass, prohibited handling, or dishonest use | End the activity, protect or delete material as directed, and record the stop decision |
Escalation works best as a specific question. Provide the source, proposed access, identity, fields, frequency, jurisdiction, recipients, retention, vendor, and intended decision. “Can we scrape this?” hides the facts the reviewer needs. Do not continue the disputed part while waiting for an answer.
Govern contractors and subcontractors through the method
Hiring a vendor does not transfer responsibility for the project. Require the contractor to describe source classes, access methods, identity practices, data fields, automation, locations, retention, security, incident response, and every subcontractor before work begins. Contract language should match the actual workflow.
- Approved purpose, source types, methods, exclusions, and jurisdictions.
- Identity and interview-disclosure requirements.
- Prohibition on unauthorized access, false accounts, credential sharing, and control bypass.
- Minimum data, security classification, storage, access, sharing, retention, and deletion terms.
- Advance approval and flow-down requirements for subcontractors.
- AI provider, model, prompt-data, provenance, output-review, and deletion rules.
- Training, audit evidence, incident notification, corrective action, and termination rights.
Sample the vendor's evidence lineage and method records during the project. A polished deliverable does not demonstrate compliant collection. If the vendor refuses to reveal methods or source classes, pause the affected work and escalate the relationship.
Handle unsolicited or questionable material deliberately
A team may receive a confidential-looking file, personal dataset, internal screenshot, misdirected message, or claim from a person who may lack permission to share it. Do not reward speed by distributing the item. Stop analysis, limit access, preserve only what company procedure requires, and notify the designated policy, security, privacy, compliance, or legal contact.
Record the delivery route, sender, date, file state, people who accessed it, and actions already taken without exploring the material further than necessary. Follow the authorized decision to return, delete, quarantine, retain, or investigate it. Do not ask the sender for more information while their authority and the source status remain unresolved.
If an approved public source independently supports part of the same claim, build the analysis from that public source and cite it directly. The questionable item does not become acceptable merely because the conclusion later appears plausible.
Reopen approval when the workflow changes
| Change | Required review |
|---|---|
| Broader purpose | Confirm necessity, fields, affected people, audience, and approval owner again |
| New source or access route | Review publisher, authorization, restrictions, identity, and collection method |
| More frequent or automated collection | Review technical load, rate, controls, coverage, storage, and monitoring |
| New country or data location | Escalate jurisdiction, transfer, storage, contract, and policy questions |
| New contractor, subcontractor, or AI service | Complete method, security, handling, retention, provenance, and contract review |
| Higher-consequence use | Raise the proof, human review, approval, and communication threshold |
Small operational changes can alter the ethical and policy profile of an otherwise approved project. Give team members a simple route to report the change without penalty. A timely pause is part of responsible delivery.
Worked example: LanternField rejects a shortcut
LanternField Research is a hypothetical competitive intelligence provider. A client asks it to investigate a competitor's partner program. The draft method includes posing as a potential partner, using a shared customer login, automating collection behind authentication, retaining all raw data indefinitely, and sending the archive to an uncited AI analysis service.
LanternField stops the proposed collection. The identity plan conflicts with its interview rules and SCIP's disclosure principle. The shared login does not establish authorization for this project. Automated collection behind the access boundary lacks approval. Indefinite retention fails the minimum-necessary purpose, and the AI path has no accepted provider, handling terms, or provenance control.
The provider offers a modified method: review the competitor's public partner pages, official documentation, public announcements, and suitable registry records; conduct any interviews with approved identity disclosure; collect only fields tied to the client decision; store evidence in the approved workspace; set a retention date; and require cited human review for any AI-assisted processing.
If authenticated material remains essential, LanternField sends the exact account, authorization, terms, fields, method, location, recipients, and purpose to the client's policy and legal owners. That activity stays paused unless they approve it. If the public method answers the decision, the restricted route is retired.
| Decision | LanternField record |
|---|---|
| Stop | False identity, shared-login use, unapproved behind-auth automation, indefinite raw retention, and unapproved AI processing |
| Modify | Use named public sources, disclosed interviews, minimum fields, approved storage, retention, and claim-level provenance |
| Escalate | Any authenticated collection that remains decision-essential after the public review |
| Proceed | Only the approved public and honestly disclosed method within its documented limits |
| Unknown | Information unavailable through the approved method remains unknown |
Apply the same controls to Content Radar inputs
Content Radar supports selected public and user-directed inputs. Direct RSS and Atom feeds and public sitemaps can add discovered material to Articles. A user-supplied Google Alerts RSS feed can add matching URLs to Candidate URLs for review. Manual URL paths let users choose material for their research flow.
Product Monitoring is a separate pillar for compatible public Shopify, WooCommerce, and structured custom stores. It uses bounded discovery and later checks to support specified product, same-known-currency price, and availability events. Content Radar does not use CAPTCHA bypass, proxy evasion, deceptive user agents, robots.txt bypass, authenticated-site circumvention, or hostile-site scraping as product capabilities.
The product does not certify a source as ethical or legal, approve a company's purpose, govern contractors, make retention decisions, provide legal advice, or perform AI analysis. Supported collection does not remove the user's obligation to review source restrictions, company policy, applicable law, handling, and use.
Stage 6: preserve the ethics decision record
- Decision question, purpose, owner, and people or interests affected.
- Source, access route, identity, method, fields, frequency, and jurisdictions.
- Restrictions, policy, contracts, ethical guidance, and legal questions reviewed.
- Classification, storage, access, sharing, retention, deletion, and incident route.
- Contractor, subcontractor, and AI provider involvement.
- Provenance, proof limits, contradictions, and unknowns preserved in the analysis.
- Proceed, modify, escalate, or stop outcome with named approver and date.
- Required changes, evidence of completion, and trigger for another review.
Reopen the record when the purpose expands, the source changes access, another jurisdiction enters, new personal or restricted data appears, a contractor changes method, an AI provider changes, or the conclusion moves to a higher-consequence audience. Ethical approval belongs to the defined workflow and time. It is not a permanent label on a source.
Build approved public sources into a reviewable workflow
See how Content Radar supports selected public publishing and compatible ecommerce inputs while leaving purpose, permission, handling, and use decisions with your organization.