Log in Contact
July 14, 2026 · PESCHECK Team · screening

Avoid GDPR Fines: What Article 10 Means for Background Checks in Hiring

Does Article 10 GDPR really ban criminal background checks? No, but most HR teams misunderstand what it actually requires. Here's the practical guide.

HR manager explaining background screening process to a job candidate in office meeting

Contents

5 min read

Background screening, pre-employment screening and employee vetting have become increasingly important for organizations managing integrity, security, financial and compliance risks. However, when a background screening process involves information relating to criminal convictions or offences, additional GDPR requirements apply.

A common misconception is that Article 10 GDPR prohibits employers from processing criminal offence data altogether, which is not entirely true. Instead, Article 10 GDPR creates an additional legal threshold (Art. 10 GDPR, 2018). Criminal conviction and offence data may be processed only under the control of official authority or where processing is authorized by EU or Member State law that provides appropriate safeguards.

For HR, Legal and Compliance teams, this means that the question should not simply be: “Can we perform a background check?”

Instead, organizations should determine: Why is the screening necessary, which data is required, what Article 6 GDPR lawful basis applies and, where criminal offence data is involved, what additional legal authorization exists?

How does Article 10 GDPR apply to background screening?

Article 10 GDPR covers personal data relating to criminal convictions, criminal offences and related security measures. It adds an additional requirement to the normal GDPR lawful-basis framework.

In practice, organizations conducting background screening or pre-employment screening should therefore consider two separate legal questions:

First:

Do we have a lawful basis under Article 6 GDPR to process personal data for this screening?

Second:

If the vetting process involves criminal offence data, are we legally authorized to process that information under Article 10 GDPR and the applicable national legislation?

A legitimate interest under Article 6(1)(f) GDPR does not, by itself, provide the additional authorization required by Article 10.

Not Sure If Your Screening Process Is Legally Authorized?

Getting Article 6 and Article 10 right isn't always straightforward, especially when criminal offence data is involved. Our support team can help you check whether your current screening process holds up, and what to adjust if it doesn't.

Talk to Our Compliance Team


Article 6 and Article 10 GDPR perform different functions

Article 6 addresses the general lawful basis for processing personal data. Depending on the circumstances, an organization may rely on a legal obligation, legitimate interests or another appropriate Article 6 basis.

Where legitimate interests are relied upon for background screening, the organization should assess the purpose of the screening, whether the processing is necessary and whether its interests are appropriately balanced against the rights and interests of the candidate or employee.

In many cases the context matters. A CFO with extensive payment authority, an engineer with privileged access to critical infrastructure, or an employee handling highly sensitive intellectual property can present materially different risks from a low-risk administrative role. This is one reason why pre-employment screening should be risk-based rather than one-size-fits-all.

Article 10 then addresses the additional question of whether criminal offence data may be processed. Under the GDPR, this requires additional authorization under EU or applicable Member State law.

Want the Full Picture Across Europe?

GDPR compliance rules for background checks vary significantly from country to country. Our 2026 guide breaks down what's legally required for compliant hiring across Europe, jurisdiction by jurisdiction.

Read the Full Europe Guide

Pre-employment screening and criminal offence data

Not every background check involves criminal offence data. Identity verification, employment history verification and education verification, for example, do not automatically fall within Article 10. However, criminal record checks and certain forms of investigative vetting may involve information covered by Article 10.

It is therefore important to determine what information is actually being processed, rather than treating every background screening component in the same way. This distinction is especially relevant for international pre-employment screening programmes containing multiple screening components.

National law matters in background screening

Article 10 GDPR deliberately allows EU and Member State law to determine when criminal offence data may be processed and under which safeguards. This has an important consequence for international employers: a background screening process that is legally available in one country may not automatically be available in another.

A multinational organization can maintain a global screening policy defining risk levels and screening principles, while individual checks may need to be adjusted according to local legislation.

Criminal record access, employment vetting requirements and the role of authorized screening providers can differ substantially between jurisdictions.

One Global Policy. Every Local Requirement Covered

Building a screening programme that holds up in every country you hire in is complex and getting it wrong carries real legal risk. See how PESCHECK helps you run one consistent global framework while staying compliant with local law in every jurisdiction.

See It In Action

Licensed private investigation providers: a practical example

The Netherlands offers a clear, real-world example of how national legislation intersects with Article 10 GDPR in practice and why compliant background screening depends on more than the GDPR text alone.

Private investigation and vetting agencies carrying out regulated screening and investigative activities in the Netherlands must operate under the Wet particuliere beveiligingsorganisaties en recherchebureaus (Wpbr), holding a license issued within the Dutch Ministry of Justice and Security's regulatory framework. This licensing requirement applies specifically to organizations conducting investigative background checks, employee vetting and related compliance screening on behalf of employers.

Dutch implementation law goes a step further, adding a specific provision that governs how licensed screening providers may process criminal record data as part of a regulated background check.

Under Article 33(4)(a) of the Dutch GDPR Implementation Act (UAVG), controllers operating under a Wpbr license have a defined national legal route to process criminal offence data on behalf of third parties, effectively enabling compliant criminal background checks for employers within the Dutch regulatory system.

This is a textbook illustration of why Article 10 compliance can't be assessed from the GDPR alone: organizations running pre-employment screening or vetting programmes need to check the applicable Member State law governing licensing, authorization and data processing. Other EU countries apply different rules, licensing regimes and restrictions for background check providers, so what's legally authorized in one jurisdiction may not be authorized in another.

Not Sure Which Rules Apply in Your Case?

Speak with one of our screening experts to find out exactly what's required for your specific hiring markets.

Talk to a Screening Specialist

Does a screening or investigation license mean anything can be investigated?

A license does not override the GDPR and should never be interpreted as an unrestricted right to collect information about candidates or employees.

The fundamental principles of data protection continue to apply, including:

  • lawfulness and fairness
  • purpose limitation
  • data minimization
  • transparency
  • appropriate security
  • appropriate retention
  • necessity and proportionality

The scope of a background screening or vetting programme should therefore correspond to the actual risks associated with the position.

Legitimate interests and Article 10: an important distinction

One of the most common mistakes in background screening is to treat legitimate interests as the complete legal answer. They are not necessarily the same question.

A simplified compliance framework can be represented as follows:

Business, security or compliance risk

Defined screening purpose

Article 6 GDPR lawful basis

Necessity and proportionality assessment

Does the screening involve criminal offence data?

Article 10 GDPR

Applicable EU or Member State authorization

Appropriate safeguards

This provides a more defensible framework for pre-employment screening than simply asking a candidate to approve a generic background check.

Use Article 10 as a Guardrail, Not a Barrier

Precise purpose, lawful authority, necessity, and proportionality make your screening more defensible and less risky. Get a proposal tailored to your regulated hiring needs.

Get a proposal for compliant screening

Does candidate consent sufficient for pre-employment screening?

Not necessarily. Candidates should of course be properly informed about the screening process and may need to actively participate by providing documents or information. However, transparency or candidate acknowledgement should not automatically be confused with relying on consent as the GDPR lawful basis.

Employment relationships can create an imbalance of power, which may affect whether consent can genuinely be considered freely given. Organizations should therefore identify the appropriate lawful basis for their screening activities rather than treating consent as a universal solution.

Why background screening and vetting should be risk-based

A compliant screening programme starts with the risk of the role, not with the amount of information that can be collected. For example, an organization may distinguish between:

  • Standard-risk roles: identity, employment and qualification verification may be sufficient.
  • Elevated-risk roles: additional integrity or compliance screening may be appropriate because of access to sensitive systems, information or assets.
  • Critical or regulated roles: more extensive vetting may be justified where the employee has significant financial authority, privileged access, responsibility for critical infrastructure or is subject to specific regulatory requirements.

This approach helps organizations demonstrate why particular screening components are necessary and supports the GDPR principle of data minimization.

Criminal record screening is not the same in every country

There is no single global “criminal background check”. Countries differ significantly in their criminal record systems, rehabilitation rules, access restrictions and privacy requirements.

Depending on the jurisdiction:

  • candidates may obtain an official certificate themselves
  • employers may only request criminal information for particular roles
  • authorized providers may perform specific investigative activities
  • certain information may not legally be available at all

International background screening therefore requires local legal execution within a consistent global screening framework.

Employer and screening provider responsibilities

Using a professional pre-employment screening provider does not remove the employer's own responsibilities. The employer should be able to explain why a particular screening is appropriate for the role and why the selected checks are necessary and proportionate.

At the same time, a screening or investigation provider may have its own privacy, regulatory and professional obligations. The exact GDPR roles of the employer and screening provider should therefore be determined according to the actual processing activities and decision-making responsibilities rather than assuming that every screening provider is merely a data processor.

Still Unsure Who's Responsible for What?

Visit our Help Center for clear answers on data protection responsibilities, screening obligations and how to stay covered on both sides.

Get Clear Answers

How PESCHECK approaches background screening

At PESCHECK, we believe that effective background screening should be risk-based, transparent and proportionate. A mature pre-employment screening and vetting framework should determine:

  1. the risks associated with the role;
  2. the purpose of the screening;
  3. the appropriate screening components;
  4. the applicable Article 6 GDPR lawful basis;
  5. whether Article 10 GDPR is triggered;
  6. the applicable national legal framework; and
  7. the safeguards required for candidates and employees.

For relevant investigative activities in the Netherlands, PESCHECK operates within the applicable Wpbr licensing framework. For international background screening, local legal requirements must be assessed separately because Article 10 authorizations, criminal record access rules and employment screening legislation can differ between jurisdictions.

See our risk-based screening approach in action

Discover how PESCHECK's pre-employment screening software helps you apply the right checks, for the right role, in line with GDPR and local legal requirements.

Explore pre-employment screening

What HR, Legal and Compliance teams should remember

Article 10 GDPR is not a general prohibition on background screening, pre-employment screening or vetting. However, neither does an Article 6 legitimate interest automatically provide permission to process criminal offence data.

A defensible screening framework considers several layers:

  • Article 6 GDPR -> What is the lawful basis for the processing?
  • Article 10 GDPR -> Does the screening involve criminal offence data?
  • National legislation -> Is there additional legal authorisation for that processing?
  • Necessity and proportionality -> Is the selected screening appropriate for this particular role?

Therefore, the foundation of responsible and defensible pre-employment screening starts with a question: “Is this specific background screening, for this specific role, necessary, proportionate and supported by the correct lawful basis and applicable legal framework?”