IndiciumIndicium
Log in
← Back to blog
Background checks for HR, Legal and Compliance

Turn public-source risk signals into audit-ready decisions.

Indicium helps regulated teams screen candidates, counterparties and sensitive hires — with dated sources, human review and reports your Legal team can defend.

The Indicium report replaces informal Google research with a documented screening process with dated sources — legally defensible instead of vulnerable.

Social Media Screening of Applicants: What Is Permitted?

Social media screening of applicants: permitted on LinkedIn and Xing, off-limits for private profiles. Legal framework, DSK line and information duties.

Social media screening of applicants is permitted if it is limited to professional networks such as LinkedIn or Xing, rests on a documented balancing test under Art. 6 (1) lit. f GDPR, and the person concerned is informed about it. By contrast, the routine, cause-independent review of private profiles, covert research or circumventing privacy settings are unlawful — regardless of how easy the content is to find. The red line therefore does not run between “public” and “privately accessible”, but between professional and private.

The Dividing Line: Professional vs. Private Networks

The German data protection supervisory authorities (the DSK line — the position of the Conference of German Data Protection Authorities) distinguish consistently by the purpose of the network: anyone presenting themselves on LinkedIn or Xing does so precisely in order to be perceived professionally — evaluating this self-presentation in the application context is regularly defensible within the balancing test. Private networks, by contrast, serve people’s private lives; the fact that a profile is technically publicly viewable does not by itself make its evaluation necessary or proportionate. Added to this is the principle of data minimisation (Art. 5 (1) lit. c GDPR): only what is actually relevant to the hiring decision may be collected. In practical terms: the question is not whether you can find something, but whether you may search for it for the specific position — and whether, if challenged, you could justify that search to the supervisory authority.

What Is Permitted

Within this framework, meaningful room for assessment remains:

  • Cross-checking professional profiles — do career stages, titles and periods on LinkedIn/Xing match the CV?
  • Profession-related public activity — specialist articles, talks, company mentions, insofar as relevant to the position.
  • Cause-based deepening — where concrete contradictions or indications arise, documented and with a stated justification.
  • Adverse media research in editorial sources — press reporting is not social media screening and follows its own standards; on the legal-basis framework more generally, see our article on the GDPR legal bases of pre-employment screening.

What Is Not Permitted

The no-go zones are equally clear — and they apply even where the position is security-relevant:

  • Covert research and fake profiles to gain access to protected content,
  • circumventing privacy settings, for instance via third parties with contact-level access,
  • routine, cause-independent review of visibly private profiles with no connection to the role,
  • inferences about special categories of data under Art. 9 GDPR — health, political opinion, religion and sexual orientation are ubiquitous in social profiles and must not feed into the decision.

The last point in particular is what makes the hiring manager’s “quick Google search” risky: anyone reviewing private profiles inevitably perceives Art. 9 data and can hardly prove later that it did not influence the decision.

Duty to Inform: Art. 14 GDPR Applies Even to Public Sources

A widespread misconception holds that publicly accessible data may be processed without further ado. In fact, Art. 14 GDPR requires informing the person concerned even where the data was not collected from them directly — that is, precisely in research across networks and other public sources. Where data is collected directly, Art. 13 GDPR applies. In practice, every application process therefore needs a privacy notice naming which source types are evaluated for which purpose. A blanket reference to “publicly accessible sources” does not suffice; the notice should specify source types, purpose and legal basis. A screening without this information is vulnerable even if it was substantively flawless.

If you want to use social media research in recruiting, the following framework is advisable:

  1. Written policy: define permitted networks, no-go zones and triggers for deeper research — and expressly rule out informal one-off research by managers.
  2. Document the balancing test: for each position group, justify why which sources are necessary.
  3. Establish transparency: extend privacy notices to cover the screening sources (Art. 13/14 GDPR).
  4. Involve the works council: early, in co-determined companies — how to get this right is shown in our article on co-determination in background checks.

Professional, documented screening with defined categories, dated sources and human final review (Art. 22 GDPR) beats DIY research on every legal point — see how the Indicium software report implements this in a demo.

This article provides general information and does not constitute legal advice.

Ready to move from reading to doing?

See how a reviewable risk report is built — from name to verdict in minutes, not weeks.

Book a demo See a sample report