In most companies, interim managers, consultants and service-provider staff slip through every screening grid: they go through no HR onboarding, no application process and no reliability check — yet often receive more far-reaching access than permanent employees. Legally, there is an additional point: § 26 BDSG (German Federal Data Protection Act) regularly does not apply to them — § 26 (8) BDSG defines the concept of employee, and externals are regularly not covered by it. Screening externals therefore rests on Art. 6 (1) lit. b and f GDPR — and in regulated industries it has long ceased to be optional; it is part of third-party obligations.
Why Externals Slip Through the Grid
The finding has organisational causes: externals enter the company via procurement or the business unit, not via HR. The service contract governs performance and liability, but rarely the integrity of the individuals deployed. And because the interim CFO or the external administrator is formally employed by the sending firm, nobody feels responsible for vetting them — the sending firm points to the client, the client relies on the sending firm. The result: the person with blanket access to ERP, payments or production control is frequently the least screened person in the entire building. Interim managers sharpen the pattern further: they arrive precisely in situations of upheaval — vacancy, restructuring, crisis — and thus at moments when internal controls are weakened anyway. Put pointedly: the most expensive access to the company is the unvetted one.
Legal Basis: Art. 6 (1) lit. b and f GDPR
That § 26 BDSG does not apply is not an obstacle but a clarification — the general legal bases of the GDPR carry the screening:
- Art. 6 (1) lit. b GDPR: verifying the information with which the external or their sending firm presents themselves (qualifications, career history, reference projects) is part of pre-contractual measures and contract performance.
- Art. 6 (1) lit. f GDPR: register, sanctions and adverse media checks rest on the legitimate interest in granting critical access only to persons of integrity — with a documented, role-based balancing test.
Transparency obligations and a sense of proportion apply here too; we have developed the general framework in our article on the GDPR legal bases of screening.
What Additionally Obliges Regulated Industries
In regulated sectors, screening externals is increasingly required explicitly:
- Financial sector: the DORA Regulation (Regulation (EU) 2022/2554, Art. 28 et seq.) requires due diligence on ICT third-party service providers before contract signature — responsibility remains with the financial entity. Details in our article on DORA and the human factor.
- Critical infrastructure: the BSIG (German Act on the Federal Office for Information Security) obliges affected entities to adopt concepts for personnel security and the supply chain — external staff included.
- GwG obliged entities: the due-diligence duties under § 10 GwG (German Anti-Money Laundering Act) cover business relationships — including the one with the service provider.
Screening Framework: Assess the Person and the Sending Firm Together
The special feature of screening externals: there are two objects of assessment. A robust framework covers both —
- The person: identity, CV and qualification verification, position-relevant registers, sanctions lists, adverse media, conflicts of interest (mandates, shareholdings).
- The sending firm: register extract and master data, ultimate beneficial owners (UBO), sanctions and adverse media check of the company, identifiable interconnections.
- The access: role-based classification — the more critical the systems and data, the deeper the check and the sooner a repeat during the engagement; when continuous monitoring makes sense is shown in our comparison one-off check or continuous monitoring.
The screening depth follows the same necessity standard as for permanent employees — what matters is the access, not the contractual status. Contractual backing is also important: anchor the screening as a condition in the service contract — including the sending firm’s duty to inform the person concerned and to report personnel changes.
Recommended Course of Action
First take stock of which externals hold which access today — experience shows this list is longer than expected. Then define a screening obligation above a clear criticality threshold, anchor it in the procurement process, and assess the person and the sending firm together. Indicium maps exactly this in its combined individual and company report, with dated sources and human final review (Art. 22 GDPR) — we would be happy to show you what this looks like for your industry in a demo.
This article provides general information and does not constitute legal advice.