Short answer: in the United States, the United Kingdom, and most of the EU, searching public information about a phone number is legal. What you then do with the result is where the law actually bites – and that part gets far less attention than it deserves.
This is a general explainer, not legal advice. Rules differ by country and change; if a decision matters, take proper advice.
Why the search itself is generally fine
A reverse phone lookup searches sources that are already public: business directories, websites, public social profiles, published records, news. Reading publicly available information is not, in itself, a regulated activity. If a plumber lists their mobile number on their website, finding it by searching for that number is no different from finding it by searching for "plumber".
What separates a legitimate service from an illegitimate one is the source. A service that offers you call logs, text message contents, private carrier subscriber records, live location, or leaked credential contents is offering something outside an ordinary public-information lookup. Licensed numbering data can identify a carrier, line type, and assignment region without revealing the subscriber or device location. Obtaining private records typically requires legal process, and buying them can put you on the wrong side of computer-misuse and data-protection law.
The line that actually matters: FCRA
In the United States, the Fair Credit Reporting Act governs reports supplied by a consumer reporting agency for decisions about employment, credit, housing, insurance, or other eligibility purposes. The FTC's guidance for employers explains the steps required when an employer obtains one of those reports from a company that compiles background information.
The important distinction is not simply whether someone searched the web whilst making a decision. It is whether a third-party service assembled or supplied a consumer report for an FCRA purpose. That framework carries obligations a general public-web search product is not designed to satisfy:
- the subject must consent to an employment screening
- the subject has the right to see what was reported about them
- the subject has the right to dispute inaccuracies and have them investigated
- the user must follow adverse-action procedures before rejecting someone
A public-web search meets none of these. There is no consent step, no dispute mechanism, no accuracy guarantee. This is exactly why services like ours state plainly that they are not consumer reporting agencies and must not be used for those decisions – and it's why that disclaimer is a real constraint rather than boilerplate.
So: looking up a number that called you is an ordinary personal use. If you need a third-party background report to make an employment, housing, credit, insurance, or similar eligibility decision, use a provider designed to comply with the relevant screening law and follow the required consent and notice processes. DeepSearch is not such a provider and prohibits those uses. The longer decision note is A people-search result is not a consumer report.
South African context
In South Africa, the Protection of Personal Information Act (POPIA) regulates the processing of personal information. Under POPIA, data subjects have the right to object to processing by submitting Form 1 to the responsible party if they can show legitimate grounds. When collecting personal information, organisations must inform data subjects of what is being collected, the purpose, retention period, and the right to access, rectify and object to processing.
If you believe your personal information has been unlawfully processed, you can lodge a complaint with the Information Regulator using Form 5. The form and complaint submission are available through the Information Regulator eServices portal or via email to POPIAComplaints@inforegulator.org.za. The Regulator will not accept complaints where the cause of action arose before 1 July 2021, or complaints lodged more than three years after the claim arose. For general enquiries, contact the Information Regulator toll-free at 0800 017 160 or email enquiries@inforegulator.org.za.
Be aware of phone scams: ICASA warned in February 2025 about scammers impersonating ICASA representatives and falsely claiming that people's phone numbers are being used for illegal activities. ICASA does not make such calls. Report suspected phone fraud to ICASA and at your nearest police station.
Europe and the UK: public doesn't mean unrestricted
Under the GDPR and the UK GDPR, personal data is protected whether or not it is publicly accessible. "I found it on a public website" is not a lawful basis on its own. The ICO's current guidance requires organisations relying on legitimate interests to identify the interest, show the processing is necessary, and balance it against the person's rights and freedoms.
For most individuals this matters less than it sounds, because there is a household exemption: processing personal data for purely personal or household purposes falls outside the regulation. Checking whether the person you're meeting from a dating app is real is a personal purpose.
That exemption disappears the moment the activity becomes professional or organisational. If you are researching people as part of a business – screening, due diligence, lead generation, journalism – you need a lawful basis, usually legitimate interests, and you need to have thought about proportionality. You may also owe the person notice that you hold data about them.
The practical test: could you explain your purpose to the person you searched and have them accept it as reasonable? If the honest answer is no, the legal analysis is probably going the same way.
Where it stops being legal regardless of source
Some uses are unlawful no matter how public the underlying information was. These are not edge cases; they're the reason this whole category attracts scrutiny:
Stalking and harassment. Repeatedly contacting, following, or monitoring someone who does not want it. Assembling public information into a profile that enables that is part of the offence in many jurisdictions, not a separate neutral act.
Doxxing. Publishing someone's home address, workplace, or contact details with the effect of exposing them to harassment. The individual facts being public is not a defence; the aggregation and publication is the harm.
Impersonation and pretexting. Posing as someone else – a bank, a colleague, the account holder – to extract information. In the US, the Telephone Records and Privacy Protection Act criminalises fraudulent acquisition or unauthorised disclosure of confidential phone-record information.
Unauthorised access. Trying to get into an account you don't own, in any way. Illegal essentially everywhere.
A workable test before you search
Three questions, in order:
- Why do I want this? If you can't say the purpose in one plain sentence without flinching, stop.
- Is this one of the regulated decisions? Employment, credit, housing, insurance, tenancy – if yes, use a proper screening provider with consent.
- What am I going to do with it? Verifying that a caller is legitimate is a use. Contacting someone who has asked you not to is not.
Uses that are straightforwardly fine
To be clear that the answer isn't "nothing is allowed", these are ordinary and lawful in most places:
- identifying an unknown or repeated caller
- checking that an online seller or buyer is a real trading entity
- confirming a person you met online is who they claim, before meeting in person
- checking a business's public details before sending money
- reconnecting with someone you've lost contact with, respecting their response
- journalism and research in the public interest, within your jurisdiction's rules
What we do about it
Since it's fair to ask what a company selling this actually enforces: we use public sources, licensed carrier and numbering metadata, and public breach-notification indexes that name incidents without exposing passwords, hashes, or breached-record contents. We don't offer call or message contents, private subscriber records, or live location, and our terms say results must not be used for FCRA-covered decisions. Public-web claims link to their source so you can check them rather than trust them.
That combination is deliberate. A tool that can't show you where a fact came from can't be verified, and a tool that can't be verified shouldn't be trusted with a decision about a person.