Scaut

Tag: Compliance

  • NIS2 and ZKI: When Background Screening Became a Legal Obligation

    NIS2 and ZKI: When Background Screening Became a Legal Obligation

    For the better part of two decades, background screening in European organisations occupied an ambiguous middle ground. It was widely understood to be good practice. It was recommended in ISO 27001 and various sector-specific codes of conduct. It was common in financial services and aviation, where regulators had long imposed personnel integrity requirements. But for the broad majority of European employers, including those operating critical infrastructure, it was optional.

    That changed with the NIS2 Directive. And in the Czech Republic, it changed again with the updated Zákon o kybernetické bezpečnosti – the national cybersecurity law implementing NIS2 with specific domestic provisions. Background screening has moved, in a relatively short period, from a discretionary HR decision to a legal obligation with enforcement consequences.

    What NIS2 actually requires

    NIS2 – officially Directive (EU) 2022/2555 – entered force in January 2023 and required member state transposition by October 2024. Its scope is broader than its predecessor, NIS1, covering a significantly expanded set of sectors and entities. Essential entities include energy, transport, banking, financial market infrastructure, health, drinking water, wastewater, digital infrastructure, ICT service management, and public administration. Important entities extend to postal services, waste management, manufacturing of critical products, food production, and digital providers.

    The Directive requires entities in these categories to implement appropriate technical and organisational measures to manage cybersecurity risks. Article 21 specifies that these measures must include policies on human resources security, access control, and asset management. Recital 89 makes explicit that human resources security policies should include measures to address the risks posed by employees and contractors.

    This is not ambiguous language. It is a direct statement that personnel security – the systematic assessment of the trustworthiness of people with access to critical systems and data – is a required element of NIS2 compliance. Supervisory authorities in member states are empowered to inspect, require evidence of, and sanction failures in this area.

    The Czech ZKI: a more specific standard

    The Czech Republic’s implementation of NIS2 through the updated cybersecurity act introduces obligations that are, in some respects, more specific than the Directive itself. The ZKI applies to a substantial number of Czech entities, including those operating critical infrastructure under the parallel Critical Infrastructure Act and those identified by the National Cyber and Information Security Agency (NUKIB) as regulated entities.

    Under the ZKI framework, regulated entities must implement personnel security measures that include, among other things, the verification of employee and contractor reliability before granting access to sensitive systems. The law does not prescribe a specific screening methodology, but it is clear that relying on a self-declared CV is insufficient. Entities are expected to demonstrate, in the event of an audit, that they took proportionate steps to verify the backgrounds of those with access to critical systems.

    NUKIB has published guidance indicating that criminal record checks, identity verification, and employment history verification are among the appropriate measures for personnel with privileged access. The deadline for full compliance passed in 2024, meaning that regulated entities that have not yet established screening processes are already in breach.

    Who is affected, and the scale of exposure

    The number of Czech entities subject to ZKI obligations runs into the thousands when critical infrastructure operators, essential service providers, and important entities are counted together. In Germany, the NIS2UmsuCG – the national implementation legislation – imposes similar obligations across an even larger industrial base, given Germany’s scale and its concentration of critical manufacturing, energy, and financial services.

    For Poland, NIS2 transposition has created obligations for entities across the energy, transport, and digital infrastructure sectors, with enforcement authority vested in the national cybersecurity regulator. Across the CEE region as a whole, the combined effect of NIS2 and its national implementations is a significant shift in the legal baseline for personnel security.

    The enforcement consequences are substantial. NIS2 mandates minimum fines for essential entities of at least 10 million euros or 2% of global annual turnover, whichever is higher. For important entities, the minimum is 7 million euros or 1.4% of turnover. These are not symbolic penalties. They are calibrated to be financially meaningful even for large organisations.

    The gap between obligation and practice

    Despite the clarity of the obligation and the scale of the consequences, many European organisations subject to NIS2 have not yet implemented systematic screening processes. The reasons vary. Some organisations are in the process of mapping their compliance obligations and have not yet reached the personnel security workstream. Others have concluded, incorrectly, that their existing pre-employment reference checking satisfies the requirement. Others still are waiting to see whether enforcement authorities prioritise this area.

    The experience from GDPR enforcement offers a relevant parallel. When GDPR came into force in 2018, many organisations adopted a wait-and-see approach, betting that enforcement would be slow and that procedural compliance was sufficient to avoid sanction. Enforcement was initially slow. But it accelerated. The fines issued since 2020 have been substantial, and the pattern of enforcement has followed a clear trajectory: early action against the most visible failures, followed by increasingly systematic scrutiny of organisational practices.

    NIS2 enforcement is following a similar pattern. NUKIB and its counterparts in Germany and Poland have begun supervisory inspections of regulated entities, and personnel security practices are within scope.

    What a compliant screening programme looks like

    A compliant personnel security programme under NIS2 and ZKI does not need to be elaborate. It needs to be proportionate, documented, and consistently applied.

    For employees and contractors with access to sensitive systems or data, the minimum defensible standard includes identity verification, criminal record checks appropriate to the individual’s country of residence and nationality, and verification of the employment or engagement history they have represented to the organisation. For roles with privileged access – system administrators, security personnel, those with access to personal data at scale – enhanced checks including adverse media screening and, where relevant, financial probity checks are appropriate.

    Critically, the programme must be documented. An organisation that has conducted screening but cannot demonstrate what it did, when, and for whom, is in a weak position relative to a regulator seeking evidence of compliance. The screening process should generate records that can be produced on request.

    Finally, the programme must extend to contractors, temporary staff, and agency workers, not just permanent employees. NIS2 and ZKI do not distinguish by employment type. If an individual has access to regulated systems, they should be within scope of your screening programme regardless of how they are engaged.

    The window for proactive compliance

    Organisations that have not yet implemented structured screening can still approach this proactively rather than reactively. Establishing a screening programme now, with clear documentation of what is covered, at what standard, and how results are recorded and acted upon, creates a defensible position against regulatory scrutiny.

    The alternative – waiting until an inspection reveals a gap – is a significantly less attractive option. Supervisory authorities are not only empowered to impose fines: they can require remediation within tight timeframes, impose operational restrictions, and publicise enforcement actions in ways that create reputational as well as financial consequences.

    Background screening is no longer a nice-to-have. In regulated sectors across Europe, it is the law.

  • 2026: Critical Infrastructure Compliance in Europe

    2026: Critical Infrastructure Compliance in Europe

    Introduction

    European organizations are bracing for significant regulatory changes as 2026: The Year of Critical Infrastructure Compliance Across Europe approaches. With the NIS2 Directive, CER Directive, and DORA regulations converging, this year represents a watershed moment for businesses operating essential services. From energy providers to healthcare systems, financial institutions to transportation networks, companies must align their cybersecurity practices and operational resilience with stringent new requirements. Understanding these mandates and preparing adequately isn’t just about avoiding penalties – it’s about building a more secure and resilient infrastructure foundation for the future.

    Key Benefits of Compliance

    Achieving compliance with Europe’s critical infrastructure regulations delivers substantial advantages beyond regulatory adherence. Organizations that meet these standards significantly reduce their vulnerability to cyberattacks, which have increased by over 40% targeting critical infrastructure in recent years. Enhanced security protocols mean better protection of sensitive data, operational continuity, and customer trust.Compliance also opens doors to new business opportunities. Many government contracts and partnership agreements now require demonstrated adherence to NIS2 and CER standards.

    Companies that achieve compliance early gain competitive advantages in procurement processes and can leverage their security posture as a market differentiator. Financially, proactive compliance is far more cost-effective than reactive measures. Organizations that establish robust security frameworks now avoid the exponential costs associated with data breaches, operational disruptions, and regulatory penalties that can reach millions of euros. Additionally, insurance premiums often decrease for organizations demonstrating strong cybersecurity and operational resilience measures.

    How It Works: Practical Steps for 2026 Compliance

    Beginning your compliance journey requires a structured approach. First, determine whether your organization falls under the scope of NIS2, CER, or DORA regulations. NIS2 applies to medium and large entities across 18 sectors including energy, transport, banking, and digital infrastructure. The CER Directive focuses on physical resilience of critical entities, while DORA targets financial sector digital operational resilience. Conduct a comprehensive gap analysis comparing your current security measures against regulatory requirements. This assessment should evaluate cybersecurity controls, incident response capabilities, supply chain security, governance structures, and reporting mechanisms. Many organizations discover significant gaps in third-party risk management and incident reporting procedures.

    Implement a risk management framework aligned with regulatory expectations. This includes establishing clear governance with board-level oversight, deploying technical security controls such as encryption and access management, developing incident response playbooks, and creating business continuity plans. Documentation is critical—regulators expect evidence of risk assessments, security policies, and training programs.

    Don’t overlook supply chain security, which has become a focal point of European regulations. Map your critical vendors, assess their security practices, and establish contractual requirements that cascade compliance obligations throughout your supply chain. Regular audits and assessments ensure ongoing adherence.Invest in training and awareness programs for all staff levels. Human error remains a leading cause of security incidents, making employee education essential. Executive leadership particularly needs understanding of their legal responsibilities under these directives.

    Conclusion and Next Steps

    As 2026: The Year of Critical Infrastructure Compliance Across Europe unfolds, organizations cannot afford complacency. The convergence of multiple regulatory frameworks creates both challenges and opportunities for European businesses. While the compliance journey may seem daunting, breaking it into manageable phases makes the process achievable. Start by securing executive buy-in and allocating appropriate resources. Engage with industry peers, participate in regulatory forums, and consider partnering with compliance specialists who understand the nuanced requirements across different sectors.

    Establish realistic timelines with milestones, recognizing that meaningful compliance requires cultural change alongside technical implementations.Regulatory authorities across Europe are ramping up enforcement capabilities, making 2026 a year when compliance transitions from optional to mandatory. Organizations that view this not as a burden but as an investment in resilience will emerge stronger, more competitive, and better positioned for sustainable growth in an increasingly digital and interconnected European market. The time to act is now – begin your compliance roadmap today to ensure your organization thrives in this new regulatory landscape.

  • Are you ready for NIS 2? You should be

    Are you ready for NIS 2? You should be

    Legal Implications of Non-Compliance

    NIS 2 places legal obligations on companies to ensure they have adequate security measures in place, including the vetting of employees who have access to sensitive systems and data. Organizations found to be negligent in their background checks risk severe penalties, which can include fines up to €10 million or 2% of the global annual turnover, whichever is higher. Non-compliance can also lead to additional sanctions such as exclusion from public contracts or mandatory reporting to regulatory bodies. The directive applies to a broader range of sectors than its predecessor, covering industries such as healthcare, energy, transport, and finance. These industries are considered essential to the functioning of society, meaning any insider threat—whether malicious or inadvertent—could have devastating consequences.

    Real-World Examples of Punitive Actions

    Recent cases across the EU have demonstrated the potential consequences of failing to comply with security standards, including inadequate background checks. For instance, in 2023, a major energy provider in Germany faced significant legal action after a contractor with a criminal history compromised sensitive customer data. The organization had failed to conduct a thorough background check, resulting in both financial penalties and long-term reputational damage.

    Similarly, in the UK, a financial services company was fined heavily for hiring an individual with a history of fraud, who later exploited his access to the firm’s systems. This incident highlights how failing to implement robust background screening not only violates legal obligations but also creates vulnerabilities that can be exploited by malicious insiders.

    Trends in Employee Screening and Cybersecurity

    With the rise of sophisticated cyberattacks and the growing reliance on critical infrastructure in the digital space, background screening has become a key focus for organizations. According to recent studies, insider threats now account for over 30% of all cybersecurity incidents, many of which could be mitigated with thorough vetting processes. Cybersecurity professionals are increasingly advocating for continuous, rather than one-time, background checks. With cybercriminals leveraging techniques like social engineering and deepfake technology, ensuring that employees maintain their integrity and reliability over time is crucial. Moreover, the rise of remote work, especially post-pandemic, has expanded the attack surface for cyber threats, making the need for stringent background checks on remote workers even more pressing. Workers who access critical infrastructure from offsite locations introduce new risks, and verifying their credentials thoroughly can help mitigate these.

    Why Background Checks are Necessary for NIS 2 Compliance

    For organizations operating within the EU, compliance with NIS 2 is not optional—it’s a legal obligation. Given the critical nature of the sectors covered by the directive, including healthcare, energy, and transport, the integrity of the workforce cannot be left to chance. Background checks serve as a vital tool to verify that employees entrusted with sensitive systems are qualified, reliable, and trustworthy. By conducting robust and thorough background screening, organizations can:

    • Ensure that they meet legal requirements under NIS 2.
    • Reduce the risk of insider threats that could compromise sensitive infrastructure.
    • Protect against financial penalties and reputational harm.
    • Foster a culture of security within the organization, which is crucial for maintaining compliance and operational resilience.

    Background screening is no longer just a best practice—it is a critical component of any organization’s cybersecurity strategy, especially under NIS 2. Organizations that neglect this aspect of compliance are not only putting their operations at risk but also exposing themselves to severe legal and financial consequences.

  • Geopolitical tensions driving workforce screening

    Geopolitical tensions driving workforce screening

    Nations and non-state actors alike are exploring wide ranging methods to undermine or exert pressure on their adversaries, not the least of which is the human attack vector. This reality transforms workforce screening from a routine HR function into a critical component of national and organizational security strategies. It is not just about verifying the backgrounds and competencies of personnel but also about ongoing vigilance to ensure that employees do not become vectors for foreign interference or cyber espionage.

    International conflicts, trade wars, regional instability, and global recession only serve to accentuate the risk of insider threats, underscoring the importance of not just initial vetting but ongoing monitoring and training to ensure organizations have trusted and secure employees, contractors, and supply chains. These developments underscore the critical importance of standards that bolster the resilience of organizations through comprehensive workforce screening processes.

    Standards like ISO27001 and SOC 2 advocate for a comprehensive information security management system, emphasizing the critical need to scrutinize employees’ access to sensitive data. Similarly, CER and NIS2 stress the importance of basic cyber hygiene and robust risk management, which include ensuring that employees’ practices do not jeopardize organizational defenses. We explore some of the standards in more depth below:

    ISO27001 and the Imperative for Information Security

    ISO27001 remains a cornerstone for organizations aiming to secure their information management systems against breaches. It mandates a risk management process that considers the human element as much as the technical defenses. In a world where cyber threats are increasingly used as geopolitical tools, the standard demands more than ever that organizations implement rigorous workforce screening to ensure that every individual with access to sensitive data is trustworthy and well-versed in best security practices.

    SOC 2: Elevating Trust in Service Providers

    SOC 2’s role in this complex environment is to foster trust between service providers and their clients. As businesses increasingly rely on cloud services and third-party vendors, SOC 2 ensures that service providers adhere to high standards of security, including thorough workforce screening. This becomes particularly relevant as geopolitical tensions can lead to targeted attacks on supply chains, making the integrity and reliability of every employee a matter of paramount importance.

    CER Directive: Strengthening the Resilience of Critical Entities

    The introduction of the Critical Entities Resilience Directive is a response to the recognition that critical infrastructure sectors are prime targets in the geopolitical arena. The directive necessitates a comprehensive approach to resilience, of which workforce screening is an integral part. Screening under CER ensures that individuals in critical positions are not only skilled but also free from vulnerabilities that could be exploited by adversaries seeking to disrupt or gain access to essential services.

    NIS2 Directive: Expanding the Scope of Digital Security

    The NIS2 Directive broadens the scope of entities under its purview, reflecting the understanding that digital security is a matter of national and international security. With geopolitical actors increasingly looking to cyber operations to advance their interests, the directive emphasizes the need for a robust security culture within organizations. Workforce screening, in this context, is about ensuring that all employees adhere to security policies designed to protect against both conventional cyber threats and those with geopolitical motives.

    Conclusion: Navigating the Geopolitical Threat Landscape

    The increasing volatility of the geopolitical landscape in 2024 has elevated the importance of standards like ISO27001, SOC 2, CER, and the NIS2 Directive in driving the adoption of comprehensive workforce screening. These standards provide a structured framework for organizations to not only vet their workforce more thoroughly but also ensure ongoing education and vigilance against security threats that are increasingly sophisticated and politically motivated. As organizations navigate these turbulent waters, the role of workforce screening in building a culture of security awareness and preparedness becomes ever more critical, highlighting the human element as both a potential vulnerability and a formidable asset in any organisational security strategy.

  • Understanding GDPR in HR Screening: A Guide for Recruiters

    Understanding GDPR in HR Screening: A Guide for Recruiters

    The Essence of GDPR in Workforce Screening

    GDPR, a set of guidelines aimed at ensuring data protection and privacy in the European Union, doesn’t explicitly mention HR screening. Instead, it offers a framework based on general principles that guide the correct processing of personal data. Contrary to common misconceptions, GDPR does not prohibit screening but emphasizes adherence to basic principles such as legality, correctness, transparency, purpose limitation, data minimization, accuracy, storage limitation, and the integrity and confidentiality of data.

    Legal Bases for Conducting Screenings

    Screening candidates is not just about collecting data; it’s about verifying that data against certain standards or requirements, without necessarily needing the candidate’s consent. In fact, relying solely on consent for screening may not be ideal since consent must be freely given and can be withdrawn at any time. A more suitable legal basis for processing personal data during screening is the legitimate interest of the employer. This basis requires a balance test to ensure that the employer’s interests do not outweigh the rights and freedoms of the candidate.

    Compliance with Other Legal Regulations

    While GDPR sets the overarching framework for data protection, other legal regulations also come into play, especially when screening involves employee-related data. The Labour Code, for example, limits the information that can be requested from job applicants to that which is directly related to the employment contract. It prohibits inquiries about personal aspects such as sexual orientation, origin, and political or religious affiliations, except in cases where specific information is legally justified or required.

    Implementing GDPR-Compliant Screening Processes

    To align HR screening processes with GDPR, organizations must start with a clear understanding of why they are conducting the screening. They must define the purpose of processing and ensure that they only collect data that is necessary and relevant to the job role. It is important to remember that screening is simply checking the authenticity of information that the candidates are voluntarily providing, and not based on anything that isn’t freely given, legally obtained or publicly available.

    Once these foundations are laid, companies must also prepare proper documentation to support their screening processes. This includes informing candidates about the data collection and processing activities, maintaining records of processing activities and legal assessments, and handling any requests or incidents related to personal data protection promptly and effectively.

    The Takeaway

    Navigating the complexities of GDPR in the context of HR screening requires an understanding of both legal obligations and the practical aspects of recruitment – but it is not something to fear. By grounding their screening processes in the principles of legality, necessity, and transparency, employers can make informed decisions that protect both their interests and the rights of candidates. It is about balancing the need for comprehensive background checks with the imperative to uphold data protection standards, ensuring a fair, lawful, and efficient recruitment process.

    For more detailed insights and assistance in setting up GDPR-compliant HR screening processes, legal consultation from experts who specialize in personal data protection, can provide invaluable guidance.

    This article transforms and elaborates upon the original insights provided by Jiří Hradský of Sedlakova Legal, exploring the role of GDPR compliance in HR screening practices. To further understand GDPR’s implications on HR screening and data handling, exploring additional resources and legal advice is recommended to ensure full compliance and effective screening processes.

    This link will take you to the Youtube video of the webinar that explores this topic, please note the video is in Czech.

  • Do you need ISO certification? You can’t get it without a background check!

    Do you need ISO certification? You can’t get it without a background check!

    What is ISO?

    The International Organization for Standardization (ISO) brings together standardization bodies and authorities from different countries.

    The term standardisation has a rather ugly, or rather discredited, connotation in our experience. Let us therefore be clear that we are using the word in a technical sense to refer to the standardisation or the setting of objective criteria, i.e. standards for a certain activity.

    Food quality, information protection, environmental protection, occupational health and safety, but also, for example, a compliance system, protection of personal data or standardised requirements for certain types of products and protective equipment arer all areas, along with many more, for which the ISO issues standardised sets of requirements and rules to ensure quality and reliability.

    How do ISO standards work?

    ISO standards define generally established and recognised principles in a particular field, for example food safety or anti-corruption. They also contain specific requirements to ensure and demonstrate the application of these principles in the organisation’s activities.

    In practice, ISO standards can be approached in two ways:

    • Put the procedures of a specific ISO standard into practice to ensure that what is key to the organisation is done correctly and to a high standard, whether it is producing a specific product, protecting internal information or reducing the negative environmental impact of an activity.
    • An organisation may also choose not only to implement the requirements of the ISO standard, but to have them certified as being applied effectively and correctly. An independent third party will assess whether the ISO standard is actually applied in practice. If so, it will confirm this with a generally recognised certificate.

    Who are ISO standards suitable for?

    ISO standards can again be used in two ways: internally and externally.

    What does it mean to use an ISO standard internally?

    Management wants to make sure that it has its key processes under control, produces safe products, ensures the safety of employees in the workplace, has a good system in place to prevent bribery, meets the requirements of changing legislation, etc. Therefore, it will follow the examples of best practices summarised in the relevant ISO standard and implement them in its own internal processes, procedures and guidelines.

    However, for many organisations it is also important to demonstrate their compliance with the ISO standard externally. Being able to demonstrate clearly and quickly to their customers, business partners, parent company, regulators and anyone else that they are serious about production quality, information protection or bribery prevention. That’s what certification is for: an independent and trustworthy confirmation that an organisation actually follows the chosen ISO standard in practice.

    Standard ISO 27001:2022 and background check

    ISO also issues standards for information protection systems.

    In October this year, a new version of the relevant standard, ISO 27001:2022, was released, containing specific requirements and measures to ensure systemic information protection, cybersecurity and data protection.

    This is not a new issuance, but an update of a set of requirements issued in 2013. The requirements for security measures are organised differently in the updated standard (there are four categories instead of the previous 14), some of the requirements and controls are merged, and others are specified. The standard also introduces 11 new controls to demonstrate that an organisation is serious about protecting information.

    One of the requirements that has remained virtually unchanged in ISO 27001:2022 is the requirement to verify and screen job applicants.

    The ISO standard requires setting up a process for background check, i.e. verifying the professional history and credibility of all applicants before they become employees. The standard also requires periodic verification of findings during the employment relationship. All this, of course, taking into account the specific needs of the organisation, the relevant legislation affecting its activities as well as the the job and its associated risks.
    In other words, without an individualized and organizationally appropriate process for verifying the trustworthiness of applicants and employees, compliance with ISO/IEC 27001:2022 cannot be achieved. Processes for protecting information will not be complete either internally or externally, nor can they be supported by certification.

    Other standards and regulations

    The requirement to verify job applicants can also be found in other standards. And it is often important, if not necessary, to ensure compliance with generally binding legislation.

    A few examples:

    • ISO 37001:2016: this standard defines the requirements for a system to prevent corrupt behaviour. One of the key elements is the verification of new employees with respect to the subject of the standard and in relation to their previous behaviour, involvement in bribery cases, links to public officials, etc.
    • ISO 19600:2014: this standard defines the requirements for a compliance management system, which is an internal process for ensuring compliance with the legal and ethical requirements imposed on an organisation. Among the controls that support the achievement of the stated objective of compliance with legal and ethical requirements, it too includes a process for the verification of applicants for employment in the organization.
    • Cybersecurity: the Cybersecurity Act requires a number of private and public sector organisations to put in place sufficient technical and organisational measures to protect critical information systems. The forthcoming NIS2 Directive will both extend the scope of these measures (to other, supporting, information systems) and increase the number of organisations affected by these obligations by an order of magnitude. In a number of cases, in order to comply with the Cybersecurity Act, or its new wording after the NIS2 amendment, a process will also need to be established and documented for the vetting of job applicants. Are you ready for the new NIS2 cybersecurity regulation? Even when recruiting employees?
    • Data protection or GDPR is still alive: Rules for processing personal data should be set up as a process, with responsibilities, defined procedures, roles, security measures and appropriate documentation. Otherwise, the GDPR’s requirement for the so-called demonstrable responsibility of the controller or processor will not be met. This in itself can be an offence punishable in particularly serious cases by a fine of up to €20 million or 4% of the worldwide turnover of the group of companies to which the offender belongs. And of course, poorly set up internal governance can lead to data loss, unauthorised disclosure, misuse, unlawful alteration, etc., with all the negative consequences for the individuals concerned and the data controller as such. Personnel measures are an integral part of the measures to protect any personal and sensitive data processed. If an organisation experiences a data loss or leak or other security incident affecting personal data, it is its responsibility to document what security measures it has put in place, what it has not put in place and why. And it may not be easy to justify a lack of trustworthiness verification for employees who have direct access to sensitive personal data, and this can negligently or intentionally lead to a major problem.
    • Sector regulation: many organisations are required by sector regulations to address the trustworthiness of their employees. For example, the civil service law for civil servants, financial regulation for employees involved in offering and servicing certain financial products (consumer credit, insurance, etc.), or regulation to protect classified information.

    How to solve it?

    Internal information, personal data, cybersecurity, consumer protection, market confidence, parent company requirements, sector regulation… If any of these are important to your organization, you can’t avoid a background check.

    Or at the very least, you should think about it thoroughly and be able to justify why you are not conducting this important check. At best, you’ll justify it in an audit, a discussion with a parent company or business partner, at worst in a supervisory review or in court.

    It can be expensive, inefficient and ineffective to vet job applicants on your own. It is therefore a good idea to consider, and perhaps at least try, a specialist and professional service. Especially when it is easy, verified and available literally at a few clicks. Employee verification quickly and cheaply? Yes, you can!

  • Verify candidates in accordance with the law!

    Verify candidates in accordance with the law!

    In a nutshell, failing to conduct a background check on a job candidate’s professional history and qualifications can cost an organisation dearly when, for example, having to part with a newly hired colleague who has dishonestly embellished their CV, the company is forced to begin another costly hiring process. Worse still, a candidate with nefarious intentions may be inadvertantly hired. Someone who wants to steal from the organisation, misuse its resources, data, information, or cause damage.

    A systematic and appropriate process for vetting candidates is important not only for protecting an organization’s tangible and intangible assets, but also for meeting a range of regulatory obligations, ensuring due diligence by management, and obtaining or maintaining various ISO certifications.

    What are the limits of a background check?

    Everything has its limits. Even a background check.

    The vetting of job applicants and the screening and monitoring of existing employees inherently involves extensive processing of personal data and encroachment on privacy. We are guided therefore primarily by the General Data Protection Regulation (GDPR) and the Labour Code.

    Does this mean that background checks cannot actually be carried out? Absolutely not!

    It is perfectly legitimate to check prospective and current employees, their work histories and other facts. And it is even legal to do so. The important thing is to be aware of your obligations, the rights of applicants and employees, and to conduct the process from start to finish in a regulatory-compliant and completely transparent manner.

    What if we go too far in vetting candidates?

    We will address the main requirements of the GDPR and the Labour Code in a moment. But first, let’s answer the question: what is the risk to an organisation if it carries out the job applicant verification process in a haphazard, incorrect manner,, fails to inform applicants or uses illegally obtained data?

    There are several risks:

    • Penalty In extreme cases, violations of the GDPR are punishable by fines of up to EUR 20 million or 4% of the annual turnover of a company group, such as, for example, where massive illegal surveillance of employees has taken place.

    Is this threat only theoretical? I wouldn’t say so. Not far from us, in Germany, H&M has just been fined EUR 35.3 million by the local data protection authority for excessive monitoring, some would even say snooping, of its employees. Of course, in our country, the fine would probably be an order of magnitude less. But even a few million euros could be quite a high price to pay for wanting to know more about applicants and employees than is strictly necessary.

    • Changing internal processes backwards The consequences of a violation of the rules does not have to be limited to a fine. They may also require the organisation to change or cease certain processes, and to destroy any illegally processed information. This has been done several times by the Czech Data Protection Authority.
    • Unusability of illegally obtained outputs Information about job applicants obtained illegally are unusable in practice. And it can be very costly to reject an applicant or dismiss an existing employee on the basis of improperly gathered data. In addition to a fine, such an employer could face a claim for invalid dismissal or for compensation for non-pecuniary damage.
    • Damaged reputation of the employer Despite the turbulent economic and political situation in the Czech Republic, employees are still rather scarce, especially in some sectors. “Improving” your reputation as an employer by spying on job applicants or existing employees and finding out all sorts of things about them, and getting fined for it, will certainly notimprove your position on the labour market.

    Background check and GDPR

    How to proceed?

    How can you ensure that job applicant or employee screening is carried out in accordance with the GDPR?

    GDPR is a comprehensive regulation, so let’s highlight the most important ones:

    • Establish and clearly describe the purpose of processing applicants’ personal data.
    • Find sufficient legal authority for processing data in the context of a background check. Sometimes the legitimate interest of the employer is sufficient. In other cases (more extensive background checks, certain sources of information or categories of data) the consent of the candidate concerned is already required: informed, voluntary, and, above all, retrospectively verifiable consent.
    • Determine the scope, manner and duration of retention of personal data collected. For these rules, the GDPR likes to employ the vague concept of “necessity”. Personal data must be collected only to the extent necessary to achieve the stated purpose, retained only for the necessary period of time, etc. It may not always be easy to define and justify why a particular piece of data is actually necessary to verify an applicant for a particular job.
    • Demonstrably inform job applicants and employees about the processing of their personal data.
    • Take sufficient security measures, both technical and organisational, to ensure that the information obtained does not fall into unauthorised hands. Whether outside the organisation or inside.
    • In particular, in the case of more extensive screening or monitoring of individuals (multiple individuals, larger data volumes, advanced tools for recruiting and assessing applicants and employees), the organisation may be required to appoint a Data Protection Officer.
    • The entire process for processing personal data and protecting the rights of individuals needs to be documented so that the organisation can demonstrate its compliance with the GDPR requirements.

    Verification of job applicants from the perspective of the Labour Code

    The GDPR is not the only regulation that governs workplace privacy in employment relationships. The other, no less important, is the Labour Code. In fact, the Labour Code regulates some specific aspects or details that are not in the general regulation, the GDPR. And as a specific legal regulation, it even takes precedence over the GDPR in these parts.

    By the way, did you know that the control of privacy protection in the workplace is not carried out by the Data Protection Authority (DPA), but by labour inspectorates? There are many more of them, they have local branches and more capacity. While the OOOO carries out a total of 50 inspections per year (offices, hospitals, banks, e-shops, municipalities, schools), the Labour Inspectorate found 26 violations of legal rules for monitoring employees and job applicants last year alone? And it can also immediately issue a fine for such violations.

    What does the Labour Code say about employee privacy?

    First, it defines the categories of data that an employer may not request from job applicants or employees, nor obtain through third parties. This typically includes data on sexual orientation, church membership, trade union membership or political beliefs.

    Certain other categories of data may be used by the employer, but** only if the employer can justify** its necessity in relation to a specific job,for example, information relating to family and financial circumstances or a criminal record.

    The Labour Code also protects employees from unreasonable surveillance at work by, for example, cameras, monitoring of communications and internet activity, use of equipment on the job, etc. If an employer wishes to implement any of these practices, it must again be able to justify and document why it is necessary in the particular circumstances of the workplace. And it must directly and demonstrably inform the employees concerned.

    Background check quickly, efficiently… and legally!

    There is no shortage of legal requirements and conditions for performing a background check. Complying with and documenting these requirements in practice is not an easy task. This is especially true in companies where there is not much experience of HR compliance, or candidate screening, or where there are insufficient resources for doing so.

    What to do?

    Outsource these worries along with the entire background check. Engage the services of an experienced professional who specializes in job applicant verification and** can effectively deal with the requirements of the law**, and can also document his client’s compliance with the relevant legal requirements.