Verification and screening
Two different things travel under one name, and separating them clarifies what a check is for.
| Activity | Question it answers | Typical checks |
|---|---|---|
| Verification | Is what the candidate told us true | Employment dates, qualifications, identity, address |
| Screening | Is there something that disqualifies them | Criminal record, regulatory disqualification, sanctions or watchlists |
Verification is appropriate for almost any role, because a material misstatement is itself relevant regardless of what was misstated. Screening is appropriate only where the role gives it a reason: handling money, working with children or vulnerable people, holding a regulated position, or access to something that creates genuine risk.
Running screening across all roles because a provider offers a package is where most disproportionate checking comes from. It collects sensitive information about people for no articulable reason connected to their job.
The legal basis, and the current employer
Background checking is processing of personal data, and the Digital Personal Data Protection Act, 2023 is the governing instrument. Two things about it are commonly got wrong, and they pull in opposite directions.
The first is timing. The duties described here are not yet in force. Under the commencement notification of 13 November 2025, sections 3 to 17 of the Act, which carry the grounds for processing, notice, consent, the obligations of a data fiduciary and the data principal rights, take effect on 13 May 2027. What commenced in November 2025 was the definitions, the Data Protection Board and the penalty machinery. Designing to the Act now is sensible; describing it as binding today is not.
The second is consent, and this entry previously had it backwards. Section 4 permits processing for a lawful purpose on one of two footings: consent, or certain legitimate uses. Section 7(i) makes it a legitimate use to process personal data for the purposes of employment, or those related to safeguarding the employer from loss or liability, and processing on that footing does not require consent. Section 7(a) separately covers data the person has voluntarily provided for a specified purpose without indicating that she does not consent to its use. So consent is one route rather than the foundation.
What this entry does not decide is whether pre-employment verification of a candidate falls inside section 7(i). The wording is directed at employment purposes and its closing example speaks of a benefit sought by a data principal who is an employee, and a candidate is not yet one. Section 17, which carries the exemptions, has not been read. Take advice on the footing you are relying on rather than assuming either answer, and note that the practical advice below does not depend on which it is.
Three duties do bear directly on verification once they commence. Under section 8(1) and (2) the data fiduciary is responsible for compliance in respect of processing carried out on its behalf by a processor, irrespective of any agreement to the contrary, which is the answer to an employer who treats a screening vendor's assurance as the end of the matter. Under section 8(3) completeness, accuracy and consistency are required where the data is likely to be used to make a decision affecting the person, which is precisely what a verification file is for. Under section 8(7) and (8), and unless retention is necessary for compliance with any law, the data must be erased when the specified purpose is no longer served, and the processor caused to erase it too.
The single most damaging routine error is contacting a current employer without telling the candidate. A candidate who has not told their employer they are looking can lose their job over it, and the harm is immediate and unrecoverable. That is true whatever legal footing the processing rests on, and it is a reason to ask before approaching rather than a consequence of any particular section.
What discrepancies usually mean
Verification produces mismatches routinely, and most are not dishonesty.
- Dates that differ by a month, because the candidate remembers when they started work and the employer records when the contract began.
- Job titles that differ, because internal titles and the ones used externally frequently diverge.
- An employer that no longer exists, has been acquired, or has no record retention beyond a few years.
- A qualification recorded under a previous name.
- A gap the candidate did not think to mention because it was unremarkable to them.
The response that works is to ask, once, without treating the discrepancy as established dishonesty. What distinguishes a genuine concern is not the existence of a mismatch but the quality of the explanation and whether the account changes when questioned.
A material misstatement about something the candidate would have known to be false, particularly a qualification or a dismissal, is a different matter and is relevant precisely because it says something about candour rather than about the underlying fact.
Criminal record checks specifically
These deserve separate treatment because they are the most sensitive and the most often over-collected.
The threshold question is whether the role gives a reason. Where it does, the check is proportionate and defensible. Where it does not, running one collects sensitive information about a person with no connection to the work they would do.
Where a check is run and something is found, the relevant question is whether it bears on this role rather than whether it exists. An old, unrelated matter generally says nothing about whether someone can do the job, and treating any record as automatically disqualifying excludes people permanently from work for reasons that have already been dealt with.
A consistent approach matters here more than anywhere else, because inconsistent application of criminal screening produces exactly the pattern that is hardest to defend: some candidates checked and others not, with no rule explaining the difference.
Retention, which nobody configures
Verification generates a file about a person, and in most organisations nothing ever deletes it.
That file frequently concerns people who never became employees, which makes it harder to justify holding. It accumulates because retention was never configured rather than because anyone decided to keep it.
- Set a retention period for verification data on unsuccessful candidates, and apply it automatically rather than by intention.
- Keep the outcome rather than the underlying documents where the outcome is what you need.
- Record who verified what and when, since that is the part with lasting value if a decision is questioned.
- Hold it in the system that will still exist in three years, rather than in the mailbox of whoever ran the check.
The last is the ordinary failure. Verification results sitting in an individual's email disappear when that person leaves, which is usually the moment someone needs them.
Statutory reference
- Act
- Digital Personal Data Protection Act, 2023
- Section
- Digital Personal Data Protection Act, 2023: section 4 (personal data may be processed only for a lawful purpose, on consent or on certain legitimate uses); section 7(i) (legitimate use for the purposes of employment, or those related to safeguarding the employer from loss or liability, without consent); section 7(a) (legitimate use where the data principal voluntarily provided the data for a specified purpose and has not indicated that she does not consent); section 5 (notice accompanying or preceding a request for consent under section 6); section 8(1) and (2) (the data fiduciary is responsible for processing carried out on its behalf by a processor, irrespective of any agreement to the contrary); section 8(3) (completeness, accuracy and consistency where the data is likely to be used to make a decision affecting the data principal); section 8(7) and (8) (erasure once the purpose is no longer served, unless retention is necessary for compliance with any law). Sections 3 to 17 commence on 13 May 2027 under G.S.R. 843(E) of 13 November 2025.
- Key limits
- Section 4 gives two footings, consent or certain legitimate uses, and section 7(i) makes processing for the purposes of employment, or for safeguarding the employer from loss or liability, a legitimate use that does not require consent. They commence on 13 May 2027. The provisions bearing on verification are s. 8(1) and (2) for vendor responsibility, s. 8(3) for accuracy where a decision will be made, and s. 8(7) and (8) for erasure.
Frequently asked questions
What is a background check?
Verification of the claims a candidate has made, and where the role warrants it, screening for disqualifying matters. Verification covers employment dates, qualifications, identity and address; screening covers criminal records or regulatory disqualification.
Should every role get the same checks?
No. Verification suits almost any role, since a material misstatement is relevant whatever it concerns. Screening needs a reason connected to the job. Running a provider's full package across all roles collects sensitive information for no articulable purpose.
Can we contact a candidate's current employer?
Only with explicit consent, named and specific. A candidate who has not told their employer they are looking can lose their job over an unannounced approach, and a refusal should be accepted without being treated as suspicious.
What should we do about a discrepancy?
Ask once, without treating it as established dishonesty. Most mismatches are date recollection, diverging internal and external job titles, or an employer that no longer keeps records. What distinguishes a real concern is the quality of the explanation and whether the account changes.
How long should background check data be kept?
Only as long as the purpose requires, with a retention period configured and applied automatically. Most of this data concerns people who never became employees, and it accumulates because nobody configured deletion rather than because anyone decided to keep it.
How Engage records verification
Engage keeps verification outcomes and who confirmed them against the candidate record and then the employee record, rather than in the mailbox of whoever ran the check. Retention periods apply to that data as configured, which is what stops verification files on people who never joined accumulating indefinitely.
See candidate records in Engage