Anyone who bases their pre-employment screening solely on § 26 (1) sentence 1 BDSG (German Federal Data Protection Act) is building on a provision the CJEU has toppled: in its judgment of 30 March 2023 (C-34/21), the Court held that such a general clause does not meet the requirements of Art. 88 (2) GDPR. Screening becomes legally sound when every screening category is based directly on a legal basis under Art. 6 (1) GDPR — lit. b, c or f, depending on the category. This article shows the mapping and the points at which it fails in practice.
What the CJEU Decided — and What Remains
Art. 88 GDPR allows Member States to adopt “more specific rules” for employee data protection. In C-34/21, the CJEU clarified: a national provision that essentially just repeats the general necessity standard is not such a more specific rule and does not satisfy Art. 88 (2) GDPR. That is precisely the criticism levelled at § 26 (1) sentence 1 BDSG — the provision is therefore only of limited use as the sole legal basis for screening. The draft Employee Data Act (Beschäftigtendatengesetz) that was meant to close the gap has stalled and, as of July 2026, has not been enacted.
For practice, this means not a screening ban but a shift in the level of justification: the general legal bases of the GDPR carry the screening — provided they are cleanly assigned per screening category.
Legal-Basis Mapping: Art. 6 GDPR per Screening Category
A blanket “we screen on the basis of the BDSG” no longer suffices. What holds up is a mapping that assigns each category its own legal basis:
- Identity and CV verification — Art. 6 (1) lit. b GDPR: verifying the information the applicant has provided themselves is part of pre-contractual measures.
- Sanctions and watchlists — Art. 6 (1) lit. c GDPR for obliged entities: where a statutory screening duty exists (for instance in the financial sector), the processing is necessary for compliance with a legal obligation.
- Register and adverse media research — Art. 6 (1) lit. f GDPR: legitimate interest with a documented balancing test, justified with reference to the specific position.
The assignment is more than a formality: it determines what information you must give the data subject and how deep the check may go for each position. For institutions within the scope of the GwG (German Anti-Money Laundering Act), we have explored the interplay with the reliability check in our article on pre-employment screening in banks.
The Special Problem of Art. 10 GDPR: Criminal-Law Data
A separate hurdle applies to data on criminal convictions and offences: Art. 10 GDPR permits their processing only under official authority or on the basis of a legal provision with appropriate safeguards. Anyone who, for instance, evaluates press reports on criminal proceedings during screening is operating within this special regime and needs a sound basis and documented safeguards for it. This is exactly where structured, category-based screening parts ways with informal googling by HR — the latter knows neither legal basis nor safeguards.
Transparency Under Art. 13 and 14 GDPR
Regardless of the legal basis, the following applies: the data subject must be informed — under Art. 13 GDPR where data is collected directly, and under Art. 14 GDPR where it is collected from other sources (registers, media, networks). A screening that would be substantively lawful becomes vulnerable if this information is missing. In practical terms: privacy notices in the application process that name the screening categories, source types and legal bases. Which limits apply specifically to social networks is covered in our article on social media screening of applicants; in co-determined companies, involving the works council comes on top.
Recommended Course of Action: The Balancing Test in Four Steps
For the lit. f categories, a documented model balancing test is advisable, worked through for each position:
- Name the legitimate interest: protection of integrity, regulatory expectations, protection of customers and assets — tied concretely to the position.
- Test necessity: Is there a milder means than the respective screening category? Why is it insufficient?
- Balance: weigh the severity of the interference (source type, data categories, Art. 10 relevance) against the screening interest — the closer the role sits to money, data and control functions, the more the balancing supports the check.
- Document and inform: record the outcome in writing, adjust privacy notices, and fix the screening scope per risk class.
An audit-ready report with dated sources and human final review (Art. 22 GDPR) maps exactly this structure — see the Indicium software report for regulated industries.
This article provides general information and does not constitute legal advice.