Is reverse phone lookup legal?

What public-records search is and isn't allowed to be used for, why the FCRA line matters, and the decisions you must never make with a lookup result.

Updated 6 min read

Short answer: in the United States, the United Kingdom, and most of the EU, searching public information about a phone number is legal. What you then do with the result is where the law actually bites — and that part gets far less attention than it deserves.

This is a general explainer, not legal advice. Rules differ by country and change; if a decision matters, take proper advice.

Why the search itself is generally fine

A reverse phone lookup searches sources that are already public: business directories, websites, public social profiles, published records, news. Reading publicly available information is not, in itself, a regulated activity. If a plumber lists their mobile number on their website, finding it by searching for that number is no different from finding it by searching for "plumber".

What separates a legitimate service from an illegitimate one is the source. A service that offers you call logs, text message contents, carrier records, live location, or data from a breach is offering something that was never public. Obtaining those typically requires legal process, and buying them can put you on the wrong side of computer-misuse and data-protection law. The absence of those capabilities is a feature, not a limitation.

The line that actually matters: FCRA

In the United States, the Fair Credit Reporting Act governs "consumer reports" — information used to decide someone's eligibility for employment, credit, housing, insurance, or tenancy.

If a search product is used for one of those decisions, it is being used as a consumer report, and consumer reports must come from a consumer reporting agency operating under FCRA. That framework carries obligations that a general web search cannot satisfy:

  • the subject must consent to an employment screening
  • the subject has the right to see what was reported about them
  • the subject has the right to dispute inaccuracies and have them investigated
  • the user must follow adverse-action procedures before rejecting someone

A public-web search meets none of these. There is no consent step, no dispute mechanism, no accuracy guarantee. This is exactly why services like ours state plainly that they are not consumer reporting agencies and must not be used for those decisions — and it's why that disclaimer is a real constraint rather than boilerplate.

So: looking up a number that called you is fine. Looking up a job applicant to decide whether to hire them is not, regardless of which tool you use. Use an FCRA-compliant screening provider for that, with the candidate's consent.

Europe and the UK: public doesn't mean unrestricted

Under the GDPR and the UK GDPR, personal data is protected whether or not it is publicly accessible. "I found it on a public website" is not a lawful basis on its own.

For most individuals this matters less than it sounds, because there is a household exemption: processing personal data for purely personal or household purposes falls outside the regulation. Checking whether the person you're meeting from a dating app is real is a personal purpose.

That exemption disappears the moment the activity becomes professional or organisational. If you are researching people as part of a business — screening, due diligence, lead generation, journalism — you need a lawful basis, usually legitimate interests, and you need to have thought about proportionality. You may also owe the person notice that you hold data about them.

The practical test: could you explain your purpose to the person you searched and have them accept it as reasonable? If the honest answer is no, the legal analysis is probably going the same way.

Where it stops being legal regardless of source

Some uses are unlawful no matter how public the underlying information was. These are not edge cases; they're the reason this whole category attracts scrutiny:

Stalking and harassment. Repeatedly contacting, following, or monitoring someone who does not want it. Assembling public information into a profile that enables that is part of the offence in many jurisdictions, not a separate neutral act.

Doxxing. Publishing someone's home address, workplace, or contact details with the effect of exposing them to harassment. The individual facts being public is not a defence; the aggregation and publication is the harm.

Impersonation and pretexting. Posing as someone else — a bank, a colleague, the account holder — to extract information. In the US, pretexting to obtain phone records is specifically prohibited by the Telephone Records and Privacy Protection Act.

Unauthorised access. Trying to get into an account you don't own, in any way. Illegal essentially everywhere.

A workable test before you search

Three questions, in order:

  1. Why do I want this? If you can't say the purpose in one plain sentence without flinching, stop.
  2. Is this one of the regulated decisions? Employment, credit, housing, insurance, tenancy — if yes, use a proper screening provider with consent.
  3. What am I going to do with it? Verifying that a caller is legitimate is a use. Contacting someone who has asked you not to is not.

Uses that are straightforwardly fine

To be clear that the answer isn't "nothing is allowed", these are ordinary and lawful in most places:

  • identifying an unknown or repeated caller
  • checking that an online seller or buyer is a real trading entity
  • confirming a person you met online is who they claim, before meeting in person
  • checking a business's public details before sending money
  • reconnecting with someone you've lost contact with, respecting their response
  • journalism and research in the public interest, within your jurisdiction's rules

What we do about it

Since it's fair to ask what a company selling this actually enforces: we search public sources only, we don't buy or serve breach data, we don't offer call or message contents, and we state in our terms that we're not a consumer reporting agency and results must not be used for FCRA-covered decisions. Every claim in a result links to the public source it came from, so you can check it rather than trust it.

That combination is deliberate. A tool that can't show you where a fact came from can't be verified, and a tool that can't be verified shouldn't be trusted with a decision about a person.

Tools mentioned in this guide