Global Workforce, EOR & Cross-Border OperationsPlaybook3 min readUpdated September 2026

Running Background Checks on International Hires Under GDPR

GDPR treats background check data as personal data that needs a specific legal basis, so a US-style screening process can't simply be applied by default to candidates in the EU or UK. Credit history and criminal record checks, routine in US hiring, can require explicit justification and a documented legal basis elsewhere.

This doesn't mean international background checks are impossible. It means the process needs a legal basis, a data minimization discipline, and a retention policy built in from the start, not adapted from a US template after a candidate objects.

Vendors Covered in this Article

Disclosure: We may earn a commission if you buy through some links on this page. It doesn't change what we recommend.

What Legal Basis Do You Need to Run a Background Check Under GDPR?

GDPR requires a specific legal basis for processing background check data, and consent alone is often a weak basis in an employment context, since a candidate's consent isn't considered fully freely given when there's a power imbalance with the employer. Legitimate interest, or a specific legal obligation in regulated roles, is often the stronger basis, but it needs to be documented and specific to the role, not a blanket policy applied to every hire regardless of position.

Work with local counsel to document the legal basis for each category of check you run, criminal record, credit, employment verification, since they may need different justifications depending on the role and the country, and a basis that holds up for one category won't automatically cover the others.

Which Background Checks Does a Role Actually Justify?

Data minimization is a core GDPR principle, which means a background check process that runs every available check on every candidate regardless of role is itself a compliance risk, not just an over-cautious habit. A finance role handling company funds may justify a credit check. A marketing role almost certainly doesn't.

Build role-based check tiers rather than one standard package for every hire, and be prepared to explain why a specific check was run for a specific role if a candidate or a regulator asks.

Set a Retention Policy and Actually Follow It

Background check data shouldn't sit in your systems indefinitely once a hiring decision is made, especially for candidates who weren't hired. Set a specific retention period, tied to a legitimate purpose like defending against a discrimination claim, and delete the data once that period passes rather than keeping everything by default because deleting it feels like extra work.

This applies to rejected candidates' background check data specifically, since that's the category most likely to sit around unnecessarily once a hiring decision has already been made.

Common Mistakes When Extending a US Process Internationally

A few patterns that create real GDPR exposure:

  • Running the same standard background check package on every candidate regardless of country or role
  • Treating candidate consent as sufficient legal basis without documenting a stronger basis for the employment context
  • No retention policy, or one that exists on paper but isn't actually followed for rejected candidates
  • Using a background check vendor that isn't itself GDPR-compliant in how it processes and stores the data

Each of these is worth a direct conversation with your background check vendor and local employment counsel before extending the process to a new country.

Confirm Your Vendor's Compliance, Not Just Your Own Process

Your own legal basis and retention policy don't fully protect you if the background check vendor itself isn't handling the data compliantly, since you remain responsible as the data controller even when a vendor processes the data on your behalf. A compliance platform like Vanta or Drata isn't a background check vendor, but it's useful for documenting that your vendor due diligence and data processing agreements are actually in place and reviewed.

Get a signed data processing agreement with any background check vendor before sending them a single EU or UK candidate's data, not after the fact. Ask the vendor directly where the data is stored and processed, since that answer affects your own cross-border transfer obligations on top of the underlying check itself.

Executive Capability Standard

What Good Looks Like

Good international background check practice means every check has a documented legal basis and role-based justification, with a retention policy that's actually followed, not just written down.

Building The Capability (5-Stage Skill Ladder)

1. Learn:Review which background checks you currently run by role and map each one to a specific legal basis.
2. Do Manually:Document the legal basis and retention period for each check category by hand before extending checks to a new country.
3. Delegate:Give your People lead ownership of confirming role-based check tiers rather than defaulting to one standard package.
4. Automate:Use a compliance platform to keep vendor due diligence and data processing agreements current and reviewed.
5. Buy:Bring in local employment counsel before running background checks in any new EU or UK jurisdiction for the first time.

How to Get Started

Disclosure: We may earn a commission if you buy through some links on this page. It doesn't change what we recommend.

Frequently Asked Questions

Can we use the same background check vendor for US and EU candidates?

Often yes, if the vendor supports GDPR-compliant processing and you have a signed data processing agreement in place. Confirm the vendor's specific EU compliance posture directly rather than assuming a vendor that works well for US hiring automatically handles EU data correctly.

Is candidate consent enough legal basis for a background check under GDPR?

It's often considered weak in an employment context, since consent isn't fully freely given when there's a power imbalance between candidate and employer. Legitimate interest or a specific legal obligation, documented and tied to the role, is typically a stronger basis. Confirm the right approach with local counsel.

How long can we keep a rejected candidate's background check data?

There's no universal answer, but the data shouldn't sit indefinitely without a documented, legitimate purpose. Set a specific retention period tied to a real need, like defending against a potential claim, and delete the data once that period passes rather than keeping it by default.

About the numbers

This guide doesn't quote a sourced benchmark. Figures in it are estimates or general guidance, so check them against your own numbers.

Related Guides