Last reviewed: Next review due:
What makes large data leaks different from regular source material
A single document from a source is manageable. A dataset containing millions of records — emails, financial transactions, corporate filings, personal records — is a different kind of challenge entirely. The scale changes everything: the security risk, the verification workload, the legal exposure, the editorial resource required, and the ethical obligations to people whose information appears in the data.
The major international data leak investigations — the Panama Papers (2016), Paradise Papers (2017), Pandora Papers (2021), and others — were handled by the International Consortium of Investigative Journalists (ICIJ) using a structured collaborative methodology that UK journalists can learn from even when working at a smaller scale. The core principles are: receive securely; analyse in isolation; verify against primary sources; apply minimum-necessary disclosure; get legal review; coordinate publication.
This guide is for UK journalists who receive a data dump of any scale — from a few hundred leaked emails to a large dataset. The principles are the same whether the data is from a local council, a regional company, or a multinational corporation.
The data leak workflow
When these protocols are non-negotiable
- 1Any dataset containing personal data of private individuals — UK GDPR creates specific obligations on publication.
- 2Data from government systems — potential Official Secrets Act exposure if classified material is present.
- 3Data involving criminal proceedings — check for reporting restrictions before any publication.
- 4Data obtained from a hacked source — receiving and publishing stolen data is not automatically illegal but requires specific legal advice.
- 5Data that could identify individuals as victims of crime or subjects of safeguarding proceedings.
- 6Large corporate datasets likely to be the subject of an injunction application.
Red flags when receiving a data dump
- The source cannot explain how they obtained the data — consider whether it may be stolen or obtained through illegal means.
- The data appears too clean or too conveniently structured — consider whether it has been fabricated or manipulated.
- The source is pressuring you to publish quickly without adequate verification — resist urgency pressure.
- The dataset contains material suggesting it originated from a state intelligence service — exercise extreme caution.
- Key records in the dataset cannot be cross-referenced against any external source — unverifiable claims require more corroboration, not less.
- The file contains executable content, macros, or links to external servers — malware risk; open on an isolated machine only.
Data dump handling checklist
- I have received the data via a secure channel and briefed my editor before opening it.
- I have scanned the data for malware on an isolated machine before opening any files.
- I have assessed the scope and structure of the dataset and identified what specialist resources I may need.
- I have cross-referenced a sample of records against primary public sources to verify authenticity.
- I have documented the chain of custody for the data.
- I have identified the specific stories of public interest rather than planning to publish the dataset wholesale.
- I have applied the minimum-necessary disclosure principle and identified what must be redacted.
- I have obtained legal review of the intended publication before going to the subject for right of reply.
- I have given the subject a fair right of reply with a clear deadline.
- I have co-ordinated with my outlet's legal team on injunction preparation.
Tools for data leak investigations
Use our Investigation Risk Register to track the legal, editorial, and security risks across a complex data leak investigation, and the FOI Request Builder to chase complementary public records.
Common mistakes
- Opening files from a data dump on a networked device before malware scanning — a single malware infection can compromise your investigation and your source.
- Publishing raw datasets rather than applying minimum-necessary disclosure — exposes innocent third parties and creates legal liability.
- Not seeking legal review before publication — data dumps often contain material that creates specific legal risks.
- Failing to verify the authenticity of the data — a manipulated dataset can destroy your credibility.
- Ignoring the personal data of private individuals who appear in the leak — UK GDPR obligations apply to journalists when publishing personal data.
- Not planning for an injunction attempt — major subjects of data leak stories regularly seek emergency injunctions; plan your response in advance.
- Sharing unredacted data with third parties before publication without appropriate security controls.
Related guides
Primary sources
- ICIJ — Offshore Leaks database and methodology documentation
- OCCRP — Aleph document and data platform
- Freedom of the Press Foundation — SecureDrop and digital security resources
- ICIJ Data Journalism Academy — handling large datasets
- UK GDPR guidance — journalism and personal data (ICO)
- Datasette — open source tool for publishing and exploring data
- Bellingcat — investigations methodology
Frequently asked questions
What was the methodology used in the Panama Papers investigation?
How do I verify that a leaked dataset is authentic and unmanipulated?
What is the minimum-necessary disclosure principle?
Do I need legal review before publishing from a data dump?
What obligations do I have to innocent third parties in a leaked dataset?
Related guides
Primary sources
- ICIJ Offshore Leaks Database— ICIJ
- OCCRP Aleph — Document and Data Platform— OCCRP
- Freedom of the Press Foundation — Digital Security Resources— Freedom of the Press Foundation
- ICO — UK GDPR Guidance: Journalism and Public Interest— ICO
- ICIJ Data Journalism Academy — Handling Large Datasets— ICIJ
- Bellingcat — Investigations Methodology— Bellingcat