Building Trust and Staying Compliant Across Romania, the UK, and Europe

Here is the short version, if you want to listen to our AI podcast:
Hiring decisions often involve significant responsibility, particularly when employees have access to sensitive information, customers, systems or company finances. You read a CV, sit through a couple of interviews, maybe check a reference or two, and then you hand someone access to your systems, your clients, sometimes your finances. In many cases, the information provided during recruitment is accurate. However, discrepancies can sometimes emerge only after employment has started.
A polished CV can hide a gap that matters. A confident interview can gloss over a qualification that was never actually earned. And in regulated sectors, one wrong hire in the wrong seat isn’t just awkward. It’s a compliance problem with a price tag attached.
Background screening helps employers make better-informed hiring decisions by verifying information that may be difficult to assess during the recruitment process. Done well, screening protects your team, your customers, and honestly the candidate too (nobody benefits from being placed in a role they were never cleared for).
There is also an important compliance consideration. Background screening involves personal data, and in some cases sensitive personal data, so the applicable requirements need to be considered before the screening process begins. What’s routine in one country can be unlawful in another. So this guide walks through the practices that hold up across Romania, the UK, and the wider EU, with the main legal differences highlighted where relevant.
The following sections outline the main considerations for employers operating across these markets.
1. Know the law where you actually hire
Jumping straight to “run the check” is where plenty of employers trip up. Before anything happens, you need a lawful reason to process the candidate’s data, and that reason has to fit the jurisdiction you’re hiring in.
The three frameworks share a common backbone (the GDPR), but each stacks its own layer on top. The quick comparison below shows where they line up and where they part ways.
| Aspect | Romania | United Kingdom | Wider EU |
| Core data-protection law | GDPR + Law 190/2018 (national implementation) | UK GDPR + Data Protection Act 2018 | GDPR (Reg. 2016/679) + each state’s implementation |
| Key employment / screening rule | Labour Code (Law 53/2003), Art. 29 limits pre-hire enquiries to what’s job-relevant | Rehabilitation of Offenders Act 1974; mandatory right-to-work checks | Member-state employment law varies by country |
| Criminal record checks | Restricted (GDPR Art. 10); must be role-proportionate | Via DBS (Basic, Standard, Enhanced), gated by role eligibility | Restricted (Art. 10) plus national conditions |
| Typical lawful basis | Legitimate interest, Art. 6(1)(f) | Legitimate interest or legal obligation | Legitimate interest; consent generally weak in employment |
| Supervisory authority | ANSPDCP | ICO | National DPA in each country |
There are several practical differences employers should keep in mind.
In Romania, screening sits on top of the GDPR, Law 190/2018 (the national GDPR implementation), and the Labour Code (Law 53/2003). Article 29 of the Labour Code is the one HR teams tend to forget: it limits what an employer can ask a candidate before hiring to information that’s genuinely relevant to the role and the person’s professional capacity. Law 190/2018 then adds special rules for things like the national identification number (CNP) and biometric or health data. The supervisory authority, ANSPDCP, does enforce this in practice.
In the UK, you’re under UK GDPR and the Data Protection Act 2018. Criminal record checks run through the Disclosure and Barring Service (DBS), not a private provider, and they come in three levels: Basic, Standard, and Enhanced. Requesting a Standard or Enhanced check for a role that doesn’t legally qualify can itself be unlawful. Right-to-work checks are mandatory for everyone. And the Rehabilitation of Offenders Act 1974 protects candidates with spent convictions, except in exempt roles.
Across the rest of the EU, the GDPR is the constant, but every member state layers its own employment and data-protection specifics on top. A programme that’s compliant in Bucharest isn’t automatically compliant in Warsaw or Madrid. Although the GDPR provides a common framework, national employment and data-protection requirements can differ significantly between EU member states.
The practical takeaway? For employers operating across multiple jurisdictions, the legal basis should therefore be assessed for each country before the screening process is designed.
2. Set clear criteria, then apply them the same way every time
Two reasons this matters beyond ticking the compliance box:
Write down, for each role, what actually needs checking. A finance position handling client money justifies more scrutiny than a junior marketing hire. That’s not bias. It’s proportionality, and under GDPR it isn’t optional (data minimisation is a core principle).
- Consistency kills discrimination claims. If every candidate for the same role goes through the same checks, you’ve got a documented, defensible process. Screen some people harder than others on a hunch and you’re exposed.
- It keeps you focused. Clear criteria stop scope creep, where a check quietly balloons into digging that has nothing to do with the job.
A simple role-sensitivity model does a lot of the heavy lifting here:
- Standard roles: identity, right to work, employment and education verification.
- Regulated roles: the above plus sector-specific checks (financial probity, sanctions, a role-appropriate criminal record check).
- High-trust roles: deeper verification proportionate to the access, responsibility, or vulnerability involved.
Whatever tiers you land on, put them in writing and apply them uniformly.
3. Consent and transparency: get this nuance right
Consent requires particular attention because it is often confused with the legal basis for processing.
You should always obtain the candidate’s signed, informed consent before running a check. At Mindit it’s a hard operational rule: no consent, no check. It’s the right thing to do and it keeps the whole process transparent. But signed consent is not automatically your GDPR legal basis for the processing.
The distinction is important because GDPR consent must be freely given, and regulators keep pointing out that in an employer/candidate relationship there’s a built-in imbalance of power. A candidate who wants the job may feel they can’t really say no. The European Data Protection Board has been blunt about it: in the employment context, consent is a weak and often invalid basis, and most employers should lean on something sturdier, usually legitimate interest under Article 6(1)(f), backed by a documented balancing test.
So treat them as two separate things doing two separate jobs:
- Signed consent = your authorisation and transparency record. It shows the candidate knew what was happening and agreed to it.
- Legal basis (usually legitimate interest, sometimes a legal obligation) = the thing that actually makes the processing lawful.
Conflating the two is a common and genuinely risky mistake. Keep both in place, keep them distinct, and hold onto your legitimate-interest assessment.
4. Verify what candidates tell you, properly
Verification is a central part of background screening. It involves confirming the accuracy of information provided by the candidate, including employment history, education and professional qualifications. Common areas of verification include:
- Identity and right to work (mandatory in the UK, good practice everywhere).
- Employment history : dates, roles, reasons for leaving, and the gaps.
- Education and professional qualifications : degrees, licences, memberships.
- References : ideally structured, not just “great person, would rehire.”
Time-gap analysis is worth a mention. An unexplained gap isn’t automatically a red flag (people take career breaks, caring responsibilities, sabbaticals), but it’s worth understanding rather than glossing over. The purpose is not to treat every employment gap as a concern, but to ensure that the candidate’s history is properly understood.
One rule runs through all of it: only verify what’s relevant to the role. Data minimisation, again.
5. Conduct criminal record checks appropriately
Criminal history is subject to specific protections under data-protection law. Under GDPR it gets extra care (Article 10 covers data relating to criminal convictions and offences), and you can’t just run a check because you feel like it.
How it works differs sharply by country:
- UK: through the DBS, at the level the role legally permits. Basic shows unspent convictions. Standard and Enhanced reveal more but are restricted to eligible roles under safeguarding and regulatory law. Retention should be short (guidance points to not keeping DBS results much beyond six months after the decision), stored separately from the main personnel file.
- Romania and the EU: criminal-record processing needs both an Article 6 lawful basis and a specific condition permitting the sensitive-data processing, and it’s tightly tied to whether the role genuinely warrants it. Blanket criminal checks across every candidate generally won’t fly.
The test everywhere is the same: is this check necessary and proportionate for this specific role? Where the necessity and proportionality of a criminal record check cannot be clearly established, the check should not be conducted.
6. Work with a professional screening provider
Some organisations manage screening internally, while others work with specialist providers. The appropriate approach depends on the organisation’s geographic coverage, internal resources and compliance requirements. The compliance surface is large, it keeps moving, and it varies by country. A specialist brings access to the right databases, working knowledge of each jurisdiction’s rules, and (crucially) a documented, defensible process.
What to look for:
- Genuine multi-country coverage, not just one market.
- A proper Data Processing Agreement in place (they’re your processor, you’re the controller).
- Transparency about sources and methods.
- Clear turnaround times, and thought given to the candidate experience.
That last point matters more than people assume. A slow, clunky, opaque check is often a candidate’s first real interaction with your company. This can also affect the candidate experience and their perception of the employer.
7. Keep candidate data confidential and secure
Screening produces some of the most sensitive data you’ll ever hold on a person. Treat it accordingly.
- Restrict access to the handful of people who genuinely need it.
- Store criminal-record and sensitive data separately from general HR files.
- Encrypt where you can, and stop emailing unsecured reports around.
- Set retention limits and actually delete data when the clock runs out (storage limitation is a GDPR principle, not a nice-to-have).
Leaving screening reports on a shared drive half the office can open isn’t just sloppy. Under GDPR it can be a reportable breach.
8. Review and update your screening policy regularly
Background screening requirements can change over time as legislation, regulatory guidance and enforcement priorities develop. DBS eligibility shifts, national implementations get amended, regulators issue fresh guidance, enforcement priorities change. A screening policy should therefore be reviewed regularly to ensure that it remains aligned with current legal and operational requirements.
Put a recurring review in the calendar (annually at the very least, sooner if you expand into a new country). Check that your legal bases still hold, your retention periods are current, and your criteria still match the roles you’re actually hiring for.
9. Document everything
Documentation is an important part of demonstrating compliance during an audit. Keep records of:
- Consent forms and the information given to candidates.
- Your legal-basis assessment (especially the legitimate-interest balancing test).
- The criteria applied per role.
- The checks run and their results.
- Retention and deletion actions.
Under GDPR this is the accountability principle in practice. Solid documentation is what turns “trust us, we did it right” into “here’s the evidence.”
Background screening isn’t about catching people out. It’s about making a confident, fair, well-informed decision, and doing it in a way that respects both the candidate and the law. Get the legal basis right, keep it proportionate, stay consistent, document as you go, and most of the rest tends to follow.
If you’d rather not navigate the Romanian, UK, and EU rulebooks on your own, that’s exactly what we do. Mindit Consulting runs compliant, multi-jurisdiction background screening so your team can hire with confidence and stay on the right side of the regulation. If that’s useful, get in touch.


