
Here is the AI podcast if you want to listen to this topic:
Every HR team wants a clean report. Most of the time, that’s exactly what shows up. But screening earns its keep in the moments it doesn’t, and what you do next says more about your hiring process than a hundred smooth hires ever will.
A red flag isn’t a verdict. It’s a prompt. A criminal record that surfaces, an employment gap that doesn’t add up, a reference who goes quiet, a qualification nobody can verify. Each one asks the same question: what does this actually mean for this role, and what are we legally allowed to do about it?
Get that wrong and the costs stack up fast. A discrimination claim. A data-protection complaint. A strong candidate lost to a lazy assumption, or a risky hire waved through because nobody wanted the awkward conversation.
So here’s a practical walk through handling red flags properly, from the first “hang on a second” to the final decision, with the legal rules that apply in Romania, the UK, and the US built in, not added later.
1. Get the full picture before you react
The instinct, when something odd shows up, is to draw a conclusion. Resist it. A red flag at first glance is rarely the whole story, and acting on half the picture is where most screening mistakes begin.
Start with the basics. Is the finding accurate, current, and about the right person? Name mismatches, stale records, and plain mistaken identity happen more often than people think, especially with common names or third-party databases that don’t get refreshed. Verify the source. Re-check anything that looks shaky before it goes any further.
This matters legally, too. In the US, if you use a third-party screening provider (a “consumer reporting agency” under the FCRA), report accuracy is central, because the candidate has a right to dispute what’s in it. Across the EU and UK, the GDPR accuracy principle expects you to keep personal data correct and up to date, and candidates can ask you to fix it. In other words, gathering more information isn’t just good manners. It’s written into the rules.
One habit that pays off: keep a short internal checklist for what counts as “enough” before a finding moves to evaluation. It stops each recruiter from quietly setting their own bar.
2. Evaluate relevance and impact, not just severity
This is where a lot of employers slip. They spot a red flag and treat it as automatically disqualifying, without asking whether it has anything to do with the actual job.
The sharper question is this: does the finding actually affect this person’s ability to do this specific role, safely and responsibly? A financial fraud conviction is highly relevant for a treasury position. It may be close to irrelevant for a warehouse job. Blanket “any record is a no” policies aren’t just unfair. In several places, they’re a legal liability.
The US gives HR a useful approach here. EEOC guidance points to three factors (often called the Green factors) when weighing a criminal record: the nature and gravity of the offense, how much time has passed since it or the end of the sentence, and the nature of the job. Treating a record as an automatic bar, with no case-by-case review, can create a disparate-impact (when a neutral rule hits one group harder) discrimination risk. Many states and cities push further with fair chance and “ban-the-box” laws that limit when you can even ask.
The UK gets to a similar place by a different route. Under the Rehabilitation of Offenders Act 1974, most convictions become “spent” after a rehabilitation period, and once spent a candidate usually doesn’t have to disclose them and you usually can’t hold them against the person, outside specific excepted roles that need a DBS check. Those periods were shortened on 28 October 2023: as a rough guide, a custodial sentence of up to a year is spent one year after it ends, one to four years is spent after four years, and sentences over four years can now become spent after seven, while serious violent, sexual, and terrorist offences never become spent. For HR, the key point is: a conviction appearing on a report is not the same as a conviction you’re allowed to act on.
In Romania and across the EU, data-protection law reinforces the need to check relevance. Processing criminal-conviction data is tightly restricted under GDPR Article 10, and you generally need a clear legal basis and appropriate safeguards to handle it at all. If a finding isn’t relevant to the role, you probably shouldn’t be weighing it, and in many cases shouldn’t have collected it in the first place.
Here’s how the three jurisdictions compare at a glance:
| Jurisdiction | Key legal framework | What it means when a red flag appears |
|---|---|---|
| Romania / EU | GDPR (Art. 5 principles, Art. 10 on criminal-conviction data), Law 190/2018, Labour Code Art. 29 | Criminal-conviction data is tightly restricted. You may only request information relevant to the role, and you need a clear legal basis and proper safeguards to process it. |
| United Kingdom | Rehabilitation of Offenders Act 1974 (periods shortened Oct 2023), DBS regime, UK GDPR | Most convictions become “spent” and generally can’t be held against a candidate, except for “excepted” roles that require Standard or Enhanced DBS checks. |
| United States | FCRA, EEOC guidance (the “Green factors”), state and local fair chance / “ban-the-box” laws | No automatic bars. A case-by-case review is expected, and a formal two-step adverse action process applies before rejecting someone on a third-party report. |
3. Conduct follow-up interviews and let the candidate respond
People aren’t their worst data point. A follow-up conversation often turns a scary-looking flag into a non-issue, or surfaces context that changes everything.
Treat it as fact-finding, not an interrogation. The goal is to understand, not to trap. Explain what came up, keep it specific, and give the person room to answer. An employment gap might be caregiving or a health issue. A date discrepancy might be a genuine slip. A past conviction might come attached to years of demonstrated change.
And this step isn’t only decent. In some places it’s required. The EEOC’s case-by-case review expects you to give the individual a chance to show the exclusion shouldn’t apply to them. The US adverse action process requires you to wait before making a final call so a candidate can review and dispute a report. Skip the conversation and you don’t just risk a bad decision. You can land on the wrong side of the law.
Take notes. What you asked, what the candidate said, and how their answer was weighed all belong in the file.
4. Seek legal and compliance guidance
Screening sits within a complex mix of employment law, data-protection law, and sector-specific rules, and it varies wildly by country, by state, sometimes even by city. When a red flag carries real consequences, bring in someone who knows the current rules.
A few of the moving parts worth naming:
- In the US, the FCRA governs how you act on a third-party report, the EEOC governs discrimination risk, and more and more state and local fair chance laws change what you can ask and when.
- In the UK, the Rehabilitation of Offenders Act, the DBS regime, and UK GDPR all interact, and the rules shift for “excepted” roles.
- In Romania and the wider EU, GDPR, Law 190/2018 (which sets national rules for applying the GDPR), and the Labour Code, including the Article 29 duty to ask candidates only about matters relevant to the role, shape what’s lawful.
Regulated sectors such as banking, healthcare, and financial services have extra rules on top of all this. When in doubt, don’t guess. Ask. An hour of legal review is trivial next to the cost of a claim.
5. Look for ways to manage the risk instead of defaulting to rejection
A valid concern doesn’t always mean “no.” Sometimes it means “yes, with controls.” Framing every red flag as a straight hire-or-reject decision throws away good people that a bit of structure could safely bring on board.
Worth considering: a probationary period with defined checkpoints, extra supervision or mentoring early on, targeted training, restricted access or duties for a set time, or placing someone in a role where the specific risk simply doesn’t arise. A driving-related conviction matters for a job behind the wheel and may be irrelevant for one that isn’t.
Aim for a proportionate response: match it to the actual risk, not to how uncomfortable the finding made you feel. Mitigation also makes your decision easier to defend legally, because it shows you engaged with individual circumstances rather than reaching for a reflex.
6. Maintain consistency and fairness
If two candidates present the same red flag and get different outcomes without a good reason, you have a problem. Possibly an ethical one, definitely a legal one.
Consistency is your best defence against bias, both the conscious kind and the kind nobody admits to. Apply the same criteria, the same process, and the same standard of evidence to everyone. Decisions should trace back to the role and the risk, never to a gut feeling about a person, and never to a protected characteristic.
This is exactly where disparate-impact claims are born. A policy that looks neutral on paper can still fall harder on one group than another. In the US that’s an EEOC concern; in the UK and Romania it falls under equality and anti-discrimination law. A clear, consistent process, applied the same way every time, is what keeps you clear of that territory.
7. Document the process
If it isn’t written down, it didn’t happen. That’s the working assumption of every regulator, tribunal, and opposing lawyer you might ever meet.
Record the finding, the steps you took to verify it, the relevance assessment, the candidate’s response, any mitigation you considered, and the reasoning behind the final call. In the US, guidance suggests keeping adverse-action records for several years, because that file is your main defence if a decision is ever challenged. Without it, regulators and tribunals are likely to assume the worst about the employer.
There’s a data-protection flip side that’s easy to miss, though. Under GDPR’s rules on how long you can keep data, you keep what you need for as long as you can justify, and no longer. So the goal isn’t “keep everything forever.” It’s keep the right things, securely, for a clear, justifiable period, then delete them. That’s exactly why retention schedules exist.
8. Communicate the decision clearly and lawfully
However a case ends, the candidate deserves a clear, respectful response, and in some places the law dictates exactly how that response has to happen.
The US is strictest. If you’re going to reject someone based even partly on a third-party background report, the FCRA requires a two-step adverse action process: first a pre-adverse action notice, sent with a copy of the report and a summary of the candidate’s FCRA rights; then a reasonable pause (five business days is the commonly cited standard, and some states require longer) so the person can review and dispute; and only then a final adverse action notice. Collapsing those two steps into one, or firing them off a day apart, is a common and expensive mistake.
Elsewhere the process rules are lighter but the principle still bites. Under GDPR, candidates have rights to access the personal data you hold and to understand decisions that affect them, so vague or evasive communication can backfire. Whatever the jurisdiction: protect confidentiality, stick to what’s relevant, and don’t overshare. A short, honest, human explanation beats both stony silence and a legal-sounding brush-off.
How to turn red flags into better hiring decisions
Red flags aren’t the enemy of good hiring. They’re part of it. The employers who handle them well aren’t the ones who never see a worrying finding. They’re the ones with a process that reliably separates real risk from false alarms, treats people as individuals, and is well documented if a decision is ever challenged.
You can learn this process, and it pays for itself in better hires, fewer claims, and a reputation candidates actually trust.
At Mindit Consulting, we help HR and compliance teams build background screening that holds up across Romania, the UK, and the US, with documented candidate consent, verified legal accuracy, and fair decision-making from day one. If you’d like a second set of eyes on your screening process, reach out at office@mindit.ro or visit https://mindit.ro.
Further reading
FTC: background checks, what employers need to know (ftc.gov)
UK GOV: spent convictions and telling an employer about a criminal record (gov.uk)
EEOC: enforcement guidance on arrest and conviction records in employment (eeoc.gov)


