The database returned a clean result. One address at the top, ranked first, cross-referenced against a dozen sources, the newest dates attached. The server drove out and knocked. A stranger opened the door and said the subject moved out two years ago.

Nothing about that result was dishonest. It was a probability that looked like a fact, and somebody treated it like one.

What changed

The platforms most of us use, IRBsearch, TLO, Tracers and their peers, increasingly return consolidated, ranked results rather than raw lists. What used to be four separate pulls and fifteen minutes of cross-referencing by hand now arrives as a single output, ordered, in seconds.

That is a real improvement. It is also a trap, because a ranked list reads like a conclusion. The first address looks like the address. It is not. It is the platform's estimate of which record is most likely current, built from data that was never collected to be accurate about where one specific person sleeps tonight.

The speed is the tool's contribution. The verification was always ours, and it still is.

Why the database is wrong, and it is wrong in patterns

After enough years of locates, you stop being surprised by bad results and start recognizing the shape of them.

The record is old and still ranked high. Data flows in from utility hookups, credit headers, subscriptions, and filings, each on its own schedule. A person who moved without generating new records keeps showing the old address as current, sometimes for a long time.

Two people have merged into one. A father and son with the same name. Two unrelated people with the same name and a similar date of birth in the same county. The file combines them, and the address you are looking at belongs to the wrong one.

The address came through a relative. A subject who once received mail at his mother's house stays attached to her address long after he left. The link is real. It is just not where he lives.

A mailing address was taken as a residence. P.O. boxes, commercial mail receivers, and an old employer's address all show up as places a person is associated with.

The phone number was recycled. Carriers reassign numbers. The number is live, it is associated with the subject, and it belongs to someone else now.

None of these is a flaw you can fix by buying a better database. They are properties of the data. A ranking layer sits on top of them and makes them look tidier, not truer.

The three-leg locate

This is the sequence I use and teach.

First leg: the database. Run the people-search platforms to establish the candidate addresses and the ranking. This is where AI earns its keep. It is fast, it cross-references more than you could by hand, and it gives you a starting order.

Second leg: open source. Search for where the database and the subject disagree. What the subject is posting publicly, where his vehicle is registered, what a recent filing lists, what a new employer's location suggests. The goal is not more addresses. It is inconsistency. Where the paper says one thing and the subject's own recent behavior says another, you have found the thing worth checking.

Third leg: the truck. Field verification of the top candidates. A vehicle in the driveway that matches the registration. A neighbor who has seen him this month. Mail in the box with his name on it. This leg is still you. No tool drives it.

The first two legs narrow the list. Only the third one produces a finding.

What goes in the report

Every address carries its source and the date that source attaches to it. Not "per database." The platform, the record type, and the date.

Separate what the data says from what you verified. "The subject's most recent credit header address is 1400 Calle Aurora, dated March 2025" is a statement about a record. "The subject's vehicle was observed at 1400 Calle Aurora on September 8, 2026" is a finding. They belong in the report in different places, and the reader should never have to work out which is which.

Record what came back empty. A check that found nothing is part of the diligence record, and in a hard-to-serve matter it is often the most important part.

Never write "confirmed" next to an address you did not verify in the field or through a reliable primary record. The attorney reading your report is going to put that address in an affidavit or a motion. If it is wrong, it is your word that carried it there.

Where the law draws lines

The data being easy to get does not make every use of it lawful.

Eligibility decisions are FCRA territory. A "consumer report" is a communication by a consumer reporting agency, bearing on a person's credit, character, reputation or similar characteristics, that is used or expected to be used as a factor in that person's eligibility for credit or insurance primarily for personal, family or household purposes, for employment, or for other purposes the statute authorizes. 15 U.S.C. § 1681a(d)(1). Using a people-search result to make those decisions brings obligations a casual lookup was never built to meet.

The line is real and it has been enforced. In 2012 the Federal Trade Commission alleged that the people-search site Spokeo "operated as a consumer reporting agency and violated the FCRA" by marketing profiles to employers and recruiters, and Spokeo paid $800,000 to settle. Federal Trade Commission press release (June 12, 2012).

Motor vehicle records need a permissible purpose. The Driver's Privacy Protection Act lets a licensed private investigative agency use personal information from motor vehicle records, but only "for any purpose permitted under this subsection." 18 U.S.C. § 2721(b)(8). Read plainly, the license does not supply the purpose. You still need one of the permitted uses behind the request. A narrower category, "highly restricted personal information," covering a person's photograph, Social Security number, and medical or disability information, generally requires that person's express consent. 18 U.S.C. §§ 2721(a)(2), 2725(4).

Pretexting for financial information is generally prohibited. Obtaining or attempting to obtain a financial institution's customer information about another person through false statements or forged documents violates the Gramm-Leach-Bliley Act. 15 U.S.C. § 6821(a). There is one narrow exception for state-licensed investigators, limited to collecting child support from someone a court has adjudged delinquent, where a court order authorizes it. 15 U.S.C. § 6821(g). Outside that, an AI tool will draft a convincing pretext script if you ask it to. Don't ask it to.

The rule that would have tightened data broker accuracy was withdrawn. In December 2024 the Consumer Financial Protection Bureau proposed a rule that would have brought many data brokers under the FCRA as consumer reporting agencies, with the accuracy duties that come with it. 89 Fed. Reg. 101402 (Dec. 13, 2024). The Bureau withdrew it in May 2025, stating that "legislative rulemaking is not necessary or appropriate at this time." 90 Fed. Reg. 20568 (May 15, 2025). Whatever you think of that decision, its practical meaning for an investigator is simple. Much of the data you are reading carries no regulatory promise that it is accurate, and the job of checking it is yours.

Do this before your next locate

  1. Treat the top-ranked address as the first thing to check, never as the answer.
  2. Run the second leg and look specifically for disagreement between the data and the subject.
  3. Write every address with its source and date. Write every empty check down too.
  4. Keep what the data says and what you verified in separate places in the report.
  5. Know the permissible purpose behind every protected record you request, before you request it.

This article is adapted from Chapter 14 of The AI-Powered Private Investigator, which covers AI-enhanced people search alongside the rest of the tool directory. The Skip Trace and Locates module builds the source-and-date discipline into every locate, and Hard to Serve turns the attempts into a diligence record counsel can use.

Jon Jacobson, MBA, is a licensed Arizona private investigator (license #1799200) and principal of Old Pueblo Investigations in Tucson. He is not an attorney, and this is not legal advice. Permissible-purpose and privacy rules vary by state and by data source. Check the rules that govern your jurisdiction and your data provider's terms.

Authorities

  • Fair Credit Reporting Act, 15 U.S.C. § 1681a(d)(1) (definition of "consumer report"). Text
  • Federal Trade Commission, Spokeo to Pay $800,000 to Settle FTC Charges Company Allegedly Marketed Information to Employers and Recruiters in Violation of FCRA (June 12, 2012). Press release
  • Driver's Privacy Protection Act, 18 U.S.C. § 2721(b)(8) (permissible use by a licensed private investigative agency or licensed security service "for any purpose permitted under this subsection"). Text
  • Driver's Privacy Protection Act, 18 U.S.C. § 2721(a)(2) (express consent generally required for highly restricted personal information); 18 U.S.C. § 2725(4) (defining highly restricted personal information as "an individual's photograph or image, social security number, medical or disability information"). Text
  • Gramm-Leach-Bliley Act, 15 U.S.C. § 6821(a) (prohibition on obtaining customer information of a financial institution by false pretenses). Text
  • Gramm-Leach-Bliley Act, 15 U.S.C. § 6821(g) (exception for state-licensed private investigators collecting court-adjudged delinquent child support, where authorized by court order). Text
  • Protecting Americans From Harmful Data Broker Practices (Regulation V), 89 Fed. Reg. 101402 (proposed Dec. 13, 2024), Docket No. CFPB-2024-0044.
  • Protecting Americans From Harmful Data Broker Practices (Regulation V); Withdrawal of Proposed Rule, 90 Fed. Reg. 20568 (May 15, 2025). Text