Pre-employment screening sits squarely inside UK data protection law: you're processing identity documents, employment history, sometimes criminal record and financial data, about a person who really wants the job and therefore can't meaningfully refuse. That power imbalance is exactly why the rules are strict. They're also entirely navigable.
First principles
- Lawful basis: every check needs one. For most checks it's legitimate interests or steps prior to a contract; consent alone is shaky in hiring because of the power imbalance, which is why documentation of necessity matters.
- Purpose limitation: data collected for screening is used for screening. Not for building a marketing list, not "just in case".
- Data minimisation: run the checks the role justifies, and no more. A credit check on a barista fails this test on its face.
The two special cases
Criminal offence data
Processing criminal record data requires a specific condition under the Data Protection Act 2018, and, crucially, you can only ask for the DBS level the role is eligible for. Ineligible deep checks aren't diligence; they're unlawful processing. See DBS levels explained.
Biometric identity data
Facial matching in digital identity verification involves biometric data, a special category. It needs explicit consent, clear notice, and a processor that treats storage and deletion seriously.
Candidate rights you must be ready for
- Access: candidates can request everything you hold from their screen, reports, notes, the lot.
- Rectification: screening data is sometimes wrong; there must be a route to challenge and correct it.
- Erasure and retention: keep screening data only as long as justified, then delete it, on a schedule you can evidence, not "whenever someone remembers".
The question a regulator asks isn't "did you check?", it's "can you show the lawful basis, the notice, the consent, and the retention schedule for what you checked?"
Making compliance the default
The practical fix is to stop treating compliance as paperwork around the process and build it into the process: notice and consent in the candidate flow, checks constrained to role-eligible levels, audit trails generated automatically, retention policies that execute themselves. That's the architecture HireCheck is built on, the compliant path and the easy path are the same path.