Running Background Checks on International Hires Under GDPR
GDPR treats background check data as personal data that needs a specific legal basis, so a US-style screening process can't simply be applied by default to candidates in the EU or UK. Credit history and criminal record checks, routine in US hiring, can require explicit justification and a documented legal basis elsewhere.
This doesn't mean international background checks are impossible. It means the process needs a legal basis, a data minimization discipline, and a retention policy built in from the start, not adapted from a US template after a candidate objects.
Vendors Covered in this Article
Disclosure: We may earn a commission if you buy through some links on this page. It doesn't change what we recommend.
What Legal Basis Do You Need to Run a Background Check Under GDPR?
GDPR requires a specific legal basis for processing background check data, and consent alone is often a weak basis in an employment context, since a candidate's consent isn't considered fully freely given when there's a power imbalance with the employer. Legitimate interest, or a specific legal obligation in regulated roles, is often the stronger basis, but it needs to be documented and specific to the role, not a blanket policy applied to every hire regardless of position.
Work with local counsel to document the legal basis for each category of check you run, criminal record, credit, employment verification, since they may need different justifications depending on the role and the country, and a basis that holds up for one category won't automatically cover the others.
Which Background Checks Does a Role Actually Justify?
Data minimization is a core GDPR principle, which means a background check process that runs every available check on every candidate regardless of role is itself a compliance risk, not just an over-cautious habit. A finance role handling company funds may justify a credit check. A marketing role almost certainly doesn't.
Build role-based check tiers rather than one standard package for every hire, and be prepared to explain why a specific check was run for a specific role if a candidate or a regulator asks.
Set a Retention Policy and Actually Follow It
Background check data shouldn't sit in your systems indefinitely once a hiring decision is made, especially for candidates who weren't hired. Set a specific retention period, tied to a legitimate purpose like defending against a discrimination claim, and delete the data once that period passes rather than keeping everything by default because deleting it feels like extra work.
This applies to rejected candidates' background check data specifically, since that's the category most likely to sit around unnecessarily once a hiring decision has already been made.
Common Mistakes When Extending a US Process Internationally
A few patterns that create real GDPR exposure:
- Running the same standard background check package on every candidate regardless of country or role
- Treating candidate consent as sufficient legal basis without documenting a stronger basis for the employment context
- No retention policy, or one that exists on paper but isn't actually followed for rejected candidates
- Using a background check vendor that isn't itself GDPR-compliant in how it processes and stores the data
Each of these is worth a direct conversation with your background check vendor and local employment counsel before extending the process to a new country.
Confirm Your Vendor's Compliance, Not Just Your Own Process
Your own legal basis and retention policy don't fully protect you if the background check vendor itself isn't handling the data compliantly, since you remain responsible as the data controller even when a vendor processes the data on your behalf. A compliance platform like Vanta or Drata isn't a background check vendor, but it's useful for documenting that your vendor due diligence and data processing agreements are actually in place and reviewed.
Get a signed data processing agreement with any background check vendor before sending them a single EU or UK candidate's data, not after the fact. Ask the vendor directly where the data is stored and processed, since that answer affects your own cross-border transfer obligations on top of the underlying check itself.
What Good Looks Like
Good international background check practice means every check has a documented legal basis and role-based justification, with a retention policy that's actually followed, not just written down.
Building The Capability (5-Stage Skill Ladder)
How to Get Started
Disclosure: We may earn a commission if you buy through some links on this page. It doesn't change what we recommend.
Vanta doesn't run background checks itself, but it helps document that your vendor due diligence and data processing agreements are actually in place.
Drata plays a similar supporting role, useful for showing that your background check vendor relationships are reviewed on a real schedule.
Frequently Asked Questions
Can we use the same background check vendor for US and EU candidates?
Often yes, if the vendor supports GDPR-compliant processing and you have a signed data processing agreement in place. Confirm the vendor's specific EU compliance posture directly rather than assuming a vendor that works well for US hiring automatically handles EU data correctly.
Is candidate consent enough legal basis for a background check under GDPR?
It's often considered weak in an employment context, since consent isn't fully freely given when there's a power imbalance between candidate and employer. Legitimate interest or a specific legal obligation, documented and tied to the role, is typically a stronger basis. Confirm the right approach with local counsel.
How long can we keep a rejected candidate's background check data?
There's no universal answer, but the data shouldn't sit indefinitely without a documented, legitimate purpose. Set a specific retention period tied to a real need, like defending against a potential claim, and delete the data once that period passes rather than keeping it by default.
About the numbers
This guide doesn't quote a sourced benchmark. Figures in it are estimates or general guidance, so check them against your own numbers.
Related Guides
GDPR and Data Localization: A Checklist for Global Employers
A practical checklist for handling employee data under GDPR and country-specific data localization rules once you hire across borders.
When to Convert an International Contractor to a Full-Time Hire
How to tell when an international contractor relationship has become an employment risk, and how the conversion to an EOR-based hire actually works.
Overtime Across Borders: Why One Policy Doesn't Travel
Why one US-style overtime policy breaks across countries, and how exempt status, working-time limits, and hours tracking rules differ from the FLSA.
Granting Equity to International Hires Without a Tax Mess
A step-by-step look at granting stock options to employees outside the US: why the default US plan doesn't travel, and what to check before you extend it.
SafetyWing vs Cigna Global: Choosing International Coverage
How SafetyWing and Cigna Global differ for covering a distributed team, and when local EOR-provided benefits make more sense than either.
Retaining International Talent Against Local Competition
Why international hires leave for local competitors, and what actually moves the needle beyond matching pay: growth path, benefits, and belonging.