Modern Hiring Requires More Than Background Checks: Why GDPR and ISO 27001 Matter
Hiring used to feel simple: post a job, run a background check, make an offer. That approach doesn't hold up anymore. Today's candidates’ hand over identity documents, employment history, references, and sometimes biometric or financial data, all before they've signed a single contract. If that data isn't handled properly, a "routine" hire can turn into a regulatory investigation, a data breach, or a lawsuit.
This is where two frameworks quietly shape how serious companies hire: the General Data Protection Regulation (GDPR) and ISO 27001, the international standard for information security management. Neither was written specifically for recruitment, but both now sit at the center of it.
Table of Contents
- Why Background Checks Alone Aren't Enough
- GDPR and Hiring: What It Actually Requires
- ISO 27001 and the Screening Control (Annex A 6.1)
- Where GDPR and ISO 27001 Overlap
- Building a Compliant Hiring Process
- The Business Case: Trust, Risk, and Reputation
- FAQs
Why Background Checks Alone Aren't Enough
A background check answers one question: is this person who they say they are, and do they have the history they claim? It doesn't answer the harder questions modern hiring raises:
- How long should we keep this candidate's data?
- Who inside the company can actually see criminal record results?
- What happens if the screening vendor itself gets breached?
- Can we prove, to a regulator or auditor, that our process was fair and proportionate?
Screening tells you about the candidate. GDPR and ISO 27001 tell you about your organization, how well you handle the sensitive information that screening generates in the first place. A background check with no data governance around it is a liability sitting in a spreadsheet.
GDPR and Hiring: What It Actually Requires
GDPR applies whenever an organization processes the personal data of someone in the EU including job candidates, regardless of where the employer is based. For HR teams, that means every stage of recruitment, not just background checks, falls under its rules.
A few principles matter most in practice:
- Lawful basis first. Before collecting any candidate data, HR needs a valid legal reason typically legitimate interest, a legal obligation (like right-to-work checks), or, in narrower cases, consent. Because of the power imbalance between employer and applicant, consent is often the weakest and least reliable basis for screening, so many organizations lean on legitimate interest or legal necessity instead.
- Data minimization. Collect only what the role genuinely requires. A graduate marketing hire doesn't need the same depth of screening as a finance director with access to payroll systems. Asking for extra documents "just in case" is itself a compliance risk.
- Special category and criminal data get stricter treatment. Criminal records, health information, and similar special categories require additional safeguards and, in many jurisdictions, a specific legal authority to process at all.
- Transparency. Candidates must be told clearly what's being collected, why, and for how long, usually through a privacy notice provided before screening begins.
- Retention and deletion. Data shouldn't linger after a hiring decision is made. Organizations need defined retention periods and a process to securely delete or anonymize candidate data once it's no longer needed.
- Impact assessments for high-risk processing. Large-scale or sensitive screening programs may require a formal Data Protection Impact Assessment (DPIA) to identify and reduce privacy risks before they materialize.
Get these wrong, and the consequences aren't abstract, regulators can investigate, fine organizations, and candidates can claim compensation for mishandled data.
ISO 27001 and the Screening Control (Annex A 6.1)
Where GDPR governs privacy, ISO 27001 governs security and it has its own explicit requirement about hiring. Annex A Control 6.1 (formerly A.7.1.1) requires organizations to run background verification checks on all candidates before they start, and periodically afterward for higher-risk roles.
The standard is deliberately risk-based rather than one-size-fits-all:
- Screening depth should match the role. A receptionist might only need identity verification; a database administrator or finance director handling sensitive systems warrants deeper checks, including criminal and credit history where legally permitted.
- Checks happen before system access is granted. Auditors expect evidence that verification was completed or that access was deliberately restricted before a new hire touches live systems or sensitive data.
- Screening isn't a one-time event. Employees in critical roles should be periodically re-verified, and the same rigor applies to contractors and third-party staff, not just direct employees.
- Documentation is everything. ISO 27001 auditors don't just want a "pass" from a background-check vendor's dashboard, they want to see internal decision logs, recruitment records, and evidence that HR actively reviewed and owns the process.
- Alternatives when screening is delayed. For urgent hires, the standard expects organizations to have a fallback plan delayed onboarding, restricted system access, or withheld equipment rather than skipping verification altogether.
In short, ISO 27001 treats your hiring pipeline as part of your security perimeter. A poorly vetted hire with unrestricted access is, from an information-security standpoint, indistinguishable from an open door.
Where GDPR and ISO 27001 Overlap

The two frameworks reinforce each other more than people expect:
- Both require proportionality, collect and check only what's justified by the role.
- Both demands documented, repeatable processes rather than ad hoc decisions.
- Both hold the organization accountable for third parties, background-check vendors and staffing agencies included.
- Both expect clear ownership, usually shared between HR and information security or legal teams.
A company that builds its screening program around ISO 27001's structure often finds it's already halfway to GDPR compliance, and vice versa. Treating them as separate checkboxes usually creates duplicate work and gaps.
Building a Compliant Hiring Process
A practical framework looks like this:
- Classify roles by data sensitivity, map each position to the type of information it touches and the corresponding level of screening required.
- Define a lawful basis and document it before any check runs, and give candidates a clear privacy notice.
- Standardize vendor contracts with background-check providers to include GDPR-compliant data processing clauses and security expectations aligned with ISO 27001.
- Limit access to screening results to the people who genuinely need them for the hiring decision.
- Set retention periods and automate deletion once they expire.
- Log everything, who was screened, when, by whom, and what was decided so you can demonstrate compliance during an audit or regulatory inquiry.
- Review annually, since both regulations and business risk profiles change.
The Business Case: Trust, Risk, and Reputation
None of this is only about avoiding fines. Candidates increasingly notice how organizations treat their data during recruitment, and it shapes whether they trust the employer before day one. Enterprise clients and procurement teams now routinely ask vendors for evidence of ISO 27001 certification and GDPR-aligned practices before signing contracts, a weak hiring process can quietly cost business deals, not just candidates.
Modern hiring, in other words, isn't just an HR function anymore. It's a data governance function, a security function, and a trust signal all at once. Background checks confirm who someone is. GDPR and ISO 27001 confirm that your organization can be trusted with what it learns about them.
FAQs
Does GDPR apply if my company isn't based in Europe? Yes, if you're processing the personal data of candidates located in the EU. GDPR is extraterritorial, location of the employer doesn't matter, location of the candidate does.
Is ISO 27001 certification mandatory for background screening? No, ISO 27001 is voluntary, but Annex A Control 6.1 becomes mandatory once you pursue certification. Many organizations adopt its screening practices voluntarily because it strengthens hiring hygiene regardless of certification status.
Is candidate consent the best legal basis for background checks under GDPR? It's possible, but risky. Because of the power imbalance in hiring, consent can be considered less freely given, so legitimate interest or legal obligation is often a stronger, more defensible basis.
How long should we keep candidate background check data? There's no single universal number; it depends on local law and your documented retention policy but data should be deleted once it's no longer needed for the hiring decision or related legal obligations.
Do these rules apply to contractors and temporary staff, not just employees? Yes. Both GDPR and ISO 27001 extend to contractors, agency workers, and third-party personnel who access company systems or data.
What's the biggest mistake companies make with hiring compliance? Treating background checks as a one-time vendor task instead of an ongoing, documented process owned jointly by HR, legal, and security teams.