Skip to main content

Handling Data Leaks and Document Dumps Responsibly

How to receive, verify, securely analyse, and responsibly publish large datasets and document dumps — from initial receipt to legal review and publication.

Last reviewed: Next review due:

What makes large data leaks different from regular source material

A single document from a source is manageable. A dataset containing millions of records — emails, financial transactions, corporate filings, personal records — is a different kind of challenge entirely. The scale changes everything: the security risk, the verification workload, the legal exposure, the editorial resource required, and the ethical obligations to people whose information appears in the data.

The major international data leak investigations — the Panama Papers (2016), Paradise Papers (2017), Pandora Papers (2021), and others — were handled by the International Consortium of Investigative Journalists (ICIJ) using a structured collaborative methodology that UK journalists can learn from even when working at a smaller scale. The core principles are: receive securely; analyse in isolation; verify against primary sources; apply minimum-necessary disclosure; get legal review; coordinate publication.

This guide is for UK journalists who receive a data dump of any scale — from a few hundred leaked emails to a large dataset. The principles are the same whether the data is from a local council, a regional company, or a multinational corporation.

The data leak workflow

1
Secure receipt
Receive data via the most secure channel available (SecureDrop, OnionShare, encrypted USB in person). Do not open on a regular networked device. Brief your editor immediately.
2
Malware scan on isolated machine
Before opening any file, scan for malware on an air-gapped machine (never connected to the internet) or a dedicated analysis device with up-to-date antivirus. A data dump can be a delivery mechanism for malware — particularly state-sponsored attacks on journalists.
3
Assess scope and structure
What format is the data in (CSV, PDF, emails, database)? How many records? What entities does it concern? This assessment tells you what legal advice you need, whether you need specialist data analysis support, and whether collaboration with other outlets is appropriate.
4
Verify authenticity
Cross-reference a sample of records against publicly available primary sources. Look for internal consistency. Note any anomalies. Seek corroboration from independent sources for key claims in the data.
5
Analyse for stories
Identify the public interest stories in the dataset. Not everything in a leak is newsworthy. Focus on wrongdoing, concealment, public interest, and verifiable facts. Use tools like Nuix, Relativity, or Datasette for large structured datasets.
6
Apply minimum-necessary disclosure
Decide what to publish. The default should be: publish only what serves a specific identified public interest, not the entire dataset. Redact innocent third parties' personal data. Get legal review before publication.
7
Right of reply
Give the subject organisation and named individuals a right of reply. Be careful not to reveal your source or the nature of the full dataset in your approach. Set a reasonable but firm deadline.
8
Coordinate publication
For large datasets, coordinate timing with partner organisations if applicable. Be prepared for the subject to seek an injunction — have a legal response ready.

When these protocols are non-negotiable

  • 1Any dataset containing personal data of private individuals — UK GDPR creates specific obligations on publication.
  • 2Data from government systems — potential Official Secrets Act exposure if classified material is present.
  • 3Data involving criminal proceedings — check for reporting restrictions before any publication.
  • 4Data obtained from a hacked source — receiving and publishing stolen data is not automatically illegal but requires specific legal advice.
  • 5Data that could identify individuals as victims of crime or subjects of safeguarding proceedings.
  • 6Large corporate datasets likely to be the subject of an injunction application.

Red flags when receiving a data dump

  • The source cannot explain how they obtained the data — consider whether it may be stolen or obtained through illegal means.
  • The data appears too clean or too conveniently structured — consider whether it has been fabricated or manipulated.
  • The source is pressuring you to publish quickly without adequate verification — resist urgency pressure.
  • The dataset contains material suggesting it originated from a state intelligence service — exercise extreme caution.
  • Key records in the dataset cannot be cross-referenced against any external source — unverifiable claims require more corroboration, not less.
  • The file contains executable content, macros, or links to external servers — malware risk; open on an isolated machine only.

Data dump handling checklist

  • I have received the data via a secure channel and briefed my editor before opening it.
  • I have scanned the data for malware on an isolated machine before opening any files.
  • I have assessed the scope and structure of the dataset and identified what specialist resources I may need.
  • I have cross-referenced a sample of records against primary public sources to verify authenticity.
  • I have documented the chain of custody for the data.
  • I have identified the specific stories of public interest rather than planning to publish the dataset wholesale.
  • I have applied the minimum-necessary disclosure principle and identified what must be redacted.
  • I have obtained legal review of the intended publication before going to the subject for right of reply.
  • I have given the subject a fair right of reply with a clear deadline.
  • I have co-ordinated with my outlet's legal team on injunction preparation.

Tools for data leak investigations

Use our Investigation Risk Register to track the legal, editorial, and security risks across a complex data leak investigation, and the FOI Request Builder to chase complementary public records.

Common mistakes

  • Opening files from a data dump on a networked device before malware scanning — a single malware infection can compromise your investigation and your source.
  • Publishing raw datasets rather than applying minimum-necessary disclosure — exposes innocent third parties and creates legal liability.
  • Not seeking legal review before publication — data dumps often contain material that creates specific legal risks.
  • Failing to verify the authenticity of the data — a manipulated dataset can destroy your credibility.
  • Ignoring the personal data of private individuals who appear in the leak — UK GDPR obligations apply to journalists when publishing personal data.
  • Not planning for an injunction attempt — major subjects of data leak stories regularly seek emergency injunctions; plan your response in advance.
  • Sharing unredacted data with third parties before publication without appropriate security controls.

Related guides

Primary sources

Frequently asked questions

What was the methodology used in the Panama Papers investigation?
The Panama Papers were 11.5 million leaked files from Panamanian law firm Mossack Fonseca, received by German newspaper Süddeutsche Zeitung and shared via ICIJ with over 400 journalists in 80 countries. The methodology involved: receiving the data via encrypted channel; analysing on air-gapped machines; using ICIJ's bespoke document analysis platform (Nuix and Relativity); cross-referencing with public databases; structured coordination between partner organisations under embargo; and simultaneous global publication to maximise impact and prevent the story being killed in any single jurisdiction.
How do I verify that a leaked dataset is authentic and unmanipulated?
Verification of large datasets is multi-layered. First, cross-reference a sample of entries against independent public sources — do the company numbers, dates, and names match Companies House or equivalent? Second, look for internal consistency: are formats uniform? Do dates fall within plausible ranges? Are there anomalies that suggest insertion or modification? Third, seek corroboration from additional sources who can confirm specific elements. Fourth, consider consulting a forensic data specialist if there is any reason to suspect the data has been manipulated to discredit your outlet.
What is the minimum-necessary disclosure principle?
The minimum-necessary disclosure principle holds that you should publish only as much of a leaked dataset as is necessary to serve the public interest of the story, and no more. Publishing a dataset in its entirety — even if it was provided to you — may expose innocent third parties whose information appears in it (bank customers, private individuals listed as contacts, etc.) without any corresponding public interest. The ICIJ's approach in the Panama Papers was to publish specific records of public interest, not to release the full dataset to the public.
Do I need legal review before publishing from a data dump?
Almost certainly yes. Legal risks in large data dumps include: defamation claims from individuals named in the data; privacy claims under the UK GDPR for individuals whose personal data is published; contempt of court if any individual is subject to active proceedings; breach of confidence; and potential Official Secrets Act exposure if the material originated from government systems. Get legal review before publication, not after. Build the legal review timeline into your publication planning from the start.
What obligations do I have to innocent third parties in a leaked dataset?
Individuals whose data appears in a leak but who are not the subject of any wrongdoing have a reasonable expectation of privacy. Publishing their personal information — bank account details, addresses, private correspondence — without public interest justification for doing so specifically about them breaches UK GDPR and may give rise to a misuse of private information claim. The ethical obligation is to apply a proportionality test to each individual: does the public interest in publishing their specific details outweigh their privacy interest? For most people in a large corporate leak, the answer is no.