An employer in the United States is preparing to hire a candidate living in France. The candidate previously worked in Singapore, studied in the United Kingdom and has records that may need to be verified across several jurisdictions. The screening provider may operate from yet another country.
At first glance, this looks like one hiring decision. From a compliance perspective, however, it can involve several different legal and privacy questions.
This is where a global background check becomes considerably more complex than a standard domestic screening process. Employers may need to consider rules governing employment screening, personal data, international data transfers and access to particular records. Two frameworks that frequently enter the discussion are the U.S. Fair Credit Reporting Act (FCRA) and the European Union’s General Data Protection Regulation (GDPR).
They address different legal concerns, and neither should be treated as a universal rulebook for international screening.
Why International Screening Is More Complicated Than Domestic Screening
Domestic screening typically takes place within a more clearly defined legal environment. International hiring can introduce multiple jurisdictions at once.
The relevant considerations may depend on factors such as:
- Where the candidate lives or works
- Where the employer operates
- Where the records being requested are held
- Which organisation processes the information
- Where personal data is transferred
- What type of information is being collected
- The laws governing access to that information
Criminal-history information, employment records, education records and financial information may each be subject to different restrictions.
A screening process that is permissible in one country therefore should not automatically be replicated in another.
Businesses expanding across multiple countries can also benefit from structured international HR services that help coordinate employment, HR and compliance requirements across jurisdictions.
Understanding FCRA in Employment Screening
In the United States, the FCRA regulates consumer reports supplied by consumer reporting agencies and can apply when employers obtain qualifying background reports for employment purposes.
For covered employment screening, employers generally need to follow specific procedural requirements. These can include providing a clear and conspicuous written disclosure that a consumer report may be obtained for employment purposes and obtaining the individual’s written authorisation.
Additional procedures become particularly important when an employer is considering adverse action based on information contained in a consumer report.
Before taking adverse action, the employer generally must provide the individual with a copy of the report and the required summary of rights. If adverse action is subsequently taken, further notice requirements apply.
The FCRA therefore places significant emphasis on how covered consumer reports are obtained and used during employment decisions.
Employers should also remember that federal FCRA compliance does not necessarily resolve every U.S. screening requirement. State and local laws can impose additional restrictions.
For companies hiring internationally, this is one reason a broader global background check strategy may be necessary rather than relying exclusively on a domestic screening process.
Understanding GDPR in Background Screening
GDPR approaches the issue primarily through the protection and lawful processing of personal data.
Organisations conducting screening involving people within GDPR’s territorial scope need to determine whether the regulation applies and, where it does, establish an appropriate legal basis for each processing activity.
Lawful Processing
Personal data cannot simply be collected because it may be useful to an employer.
Processing requires a lawful basis under GDPR. Depending on the circumstances, potential bases can include legal obligation or legitimate interests. Consent exists as another lawful basis, but its suitability in an employment relationship requires careful assessment because of the imbalance of power between employer and candidate.
Criminal-conviction and offence data receives additional protection under Article 10 and cannot be treated like ordinary personal data.
Transparency
Candidates should receive appropriate information about how their personal information is collected and used.
This can include the purposes of processing, categories of data involved, recipients, retention periods and applicable rights.
Data Minimisation
Employers should collect personal information that is adequate, relevant and limited to what is necessary for the stated purpose.
A broader check is not automatically a better check.
Screening should therefore be proportionate to the role, risk and legitimate purpose involved.
Retention
Personal data should not normally be retained indefinitely simply because it has already been collected.
Organisations need appropriate retention practices based on the purpose of processing and applicable legal requirements.
Individual Rights
Depending on the circumstances, GDPR provides individuals with rights concerning their personal data, including rights of access, rectification and, in certain situations, erasure, restriction or objection.
Screening workflows need processes capable of handling applicable rights requests.
FCRA vs. GDPR: Where the Approaches Differ
FCRA and GDPR should not be viewed as interchangeable compliance systems.
| Area | FCRA | GDPR |
| Primary focus | Consumer reporting, including covered employment screening | Processing and protection of personal data |
| Geographic relevance | Primarily United States | EU/EEA processing and certain processing outside the EU/EEA falling within GDPR’s territorial scope |
| Candidate authorisation | Written authorisation is generally required for covered employment consumer reports | Processing requires a lawful basis, consent is only one possible basis and may be problematic in employment contexts |
| Transparency | Specific disclosure and notification obligations apply | Broad transparency obligations govern personal-data processing |
| Data scope | Consumer reports provided by consumer reporting agencies | Personal data broadly, with additional rules for certain categories |
| Adverse decisions | Specific pre-adverse and adverse-action procedures can apply | No equivalent FCRA-style universal adverse-action sequence, although other GDPR obligations and individual rights may be relevant |
| Data minimisation | Not structured around GDPR’s data-minimisation principle | Explicit GDPR principle |
| Retention | Subject to applicable FCRA and other legal requirements | Storage limitation is an explicit principle |
| Cross-border transfers | Not the FCRA’s central regulatory framework | Transfers of personal data outside the EEA can require specific safeguards |
The important point is not deciding which regime is “stricter.” They regulate screening from different legal perspectives, and in some international situations multiple frameworks may need to be considered simultaneously.
What If the Candidate, Employer and Records Are in Different Countries?
This is where international background screening becomes particularly challenging.
Consider this structure:
Employer: United States
Candidate: European Union
Previous employer: Asia
Screening provider: International
It would be risky to assume that U.S. requirements alone determine the entire screening process simply because the hiring company is American.
The employer may need to consider FCRA obligations if a qualifying consumer report is obtained for employment purposes. At the same time, processing the EU candidate’s personal information may fall within GDPR depending on the circumstances and territorial scope of the regulation.
Then there is the country where the records are located.
Local laws may determine whether particular employment, education, criminal or other records are accessible, what information can be disclosed and whether additional procedures are necessary.
The screening provider’s location can introduce another issue: international transfers of personal data.
Under GDPR, transfers of personal data outside the EEA require an appropriate transfer mechanism or another recognised basis where the destination does not benefit from an applicable adequacy decision. Depending on the circumstances, this might involve Standard Contractual Clauses and related safeguards.
A compliant global background check process therefore needs to be mapped across the complete information journey:
- Candidate
- Employer
- Screening provider
- Record source
- Data storage and transfer
Compliance cannot reliably be determined by looking only at the employer’s headquarters.
International Screening Mistakes Employers Should Avoid
Several mistakes can create unnecessary compliance exposure when screening candidates internationally:
- Applying a U.S. screening policy unchanged in every country
- Assuming candidate consent automatically makes all data processing lawful
- Requesting information that is unnecessary for the position
- Overlooking special restrictions surrounding criminal-record information
- Failing to determine where candidate data will be processed or stored
- Retaining screening information without a defined retention rationale
- Ignoring local employment, privacy and record-access rules
- Failing to provide required disclosures or notices
- Assuming a screening provider automatically removes the employer’s compliance responsibilities
Standardisation can make global hiring more efficient, but compliance often requires controlled local variation.
Companies expanding their workforce internationally should also consider broader global labour compliance requirements rather than treating background screening as an isolated HR activity.
Build Compliance Into the Screening Workflow
Instead of addressing privacy and employment requirements after a screening issue appears, employers can design them into the process from the beginning.
1. Map the Jurisdictions Involved
Identify where the employer, candidate, screening provider and relevant records are located.
2. Define the Purpose of Each Check
Determine why each category of information is necessary for the particular role.
3. Identify Applicable Legal Frameworks
Review employment-screening, privacy, record-access and sector-specific requirements in the relevant jurisdictions.
4. Establish the Appropriate Processing Basis
Where GDPR applies, determine the lawful basis and any additional conditions required for protected types of information.
5. Limit Data Collection
Request information that is relevant and proportionate rather than automatically ordering the broadest available screening package.
6. Control International Transfers and Access
Understand where information travels, who receives it and which safeguards may be required.
7. Create Retention and Deletion Rules
Define how long screening information should remain available and how it will be securely removed when no longer needed.
8. Prepare for Candidate Rights and Employment Decisions
Build processes for applicable privacy requests, disputes, corrections, notices and adverse-action requirements.
This approach makes compliance part of the architecture of a global background check, rather than an administrative step added at the end.
Screening Should Travel as Carefully as Your Workforce
International hiring creates opportunities to access talent across borders, but background screening must move across those borders with equal care.
At Aadmi, we help organisations navigate the practical challenges of building international workforces, including global background checks and wider employment and compliance considerations. Our approach is designed around the jurisdictions involved rather than assuming that one country’s screening process can simply be exported everywhere else.
Businesses establishing international teams can also explore Employer of Record services when they need an employment structure in a country where they do not yet have their own local entity.
For organisations building international workforces, international HR services can also help coordinate employment administration and compliance requirements across multiple jurisdictions.
When your candidates, records and business operations span multiple countries, we can help you build a screening process that is practical, proportionate and aligned with the relevant requirements.
Frequently Asked Questions
1. Does FCRA apply to every international background check?
No. FCRA applicability depends on the circumstances, including whether a consumer report from a consumer reporting agency is being obtained for an employment purpose within the scope of the Act. International screening can also trigger laws outside the United States.
2. Does GDPR require consent for employee background checks?
Not necessarily. GDPR requires a lawful basis for processing personal data, but consent is only one potential basis. Because of the power imbalance associated with employment relationships, employers should carefully assess whether consent can genuinely be considered freely given.
3. Can an employer check a candidate’s overseas criminal record?
Potentially, but availability and legality vary considerably between jurisdictions. Criminal-record information may be subject to specific access, privacy and employment restrictions. Under GDPR, data relating to criminal convictions and offences is additionally governed by Article 10.
4. What happens when candidate data is transferred outside Europe?
Where GDPR applies, transferring personal data outside the EEA may require an adequacy basis or appropriate safeguards, such as Standard Contractual Clauses, depending on the destination and circumstances.
5. Can one background screening policy be used worldwide?
A global framework can establish consistent principles, but applying exactly the same checks and procedures everywhere can create compliance problems. Local rules concerning privacy, criminal records, employment decisions and access to information may require country-specific adaptations.
6. Who is responsible for compliance when a third-party screening provider is used?
Using a screening provider does not automatically transfer every compliance responsibility away from the employer. Responsibilities depend on the applicable law and the parties’ respective roles, so employers should understand how information is collected, processed, transferred, retained and used.

