IndiciumIndicium
Log in
← Back to blog
Background checks for HR, Legal and Compliance

Turn public-source risk signals into audit-ready decisions.

Indicium helps regulated teams screen candidates, counterparties and sensitive hires — with dated sources, human review and reports your Legal team can defend.

The Indicium report documents every screening category with dated sources, giving you a defensible basis for your hiring decision.

Pre-Employment Screening in Banks: What § 26 BDSG Permits

What § 26 BDSG permits in pre-employment screening at banks: lawful sources, proportionality by position, and the limits set by data protection law.

Pre-employment screening in banks is lawful where the data processing is necessary for the decision on establishing the employment relationship — that is the standard set by § 26 (1) sentence 1 BDSG (German Federal Data Protection Act), and § 26 (8) BDSG expressly places applicants on an equal footing with employees. For banks there is an additional layer: the reliability check of staff is a statutorily defined internal safeguard under § 6 (2) no. 5 GwG (German Anti-Money Laundering Act). There is thus no contradiction between anti-money-laundering prevention and data protection — only a necessity standard that a structured screening process can map cleanly.

The GwG Duty and Data Protection Follow the Same Standard

Many HR departments treat screening and data protection as opposites: compliance demands a check, the data protection officer applies the brakes. Legally, the relationship is simpler. An obliged entity under the GwG that must ensure the reliability of its staff has a sound substantive reason for processing applicant data — but only to the extent necessary for the specific position. Alongside § 26 BDSG, the general legal bases of the GDPR come into play; we have explored the details in our article on the legal bases of pre-employment screening under the GDPR.

Necessity is not a blank cheque but a balancing exercise: the closer a position sits to money, customer data and control functions, the more may — and must — be checked.

What § 26 BDSG Permits

Permissible is whatever has a demonstrable connection to the hiring decision and originates from lawfully accessible sources. In practice, clearly defined screening categories have proven their worth, for example:

  • Identity and document verification — do the person, CV and supporting documents match?
  • Register sources — commercial register, insolvency publications and comparable public directories, insofar as relevant to the position.
  • Sanctions and watchlists — regularly indispensable for obliged entities under the GwG.
  • Adverse media research — profession-related reporting from publicly accessible media.
  • References and certificates — with the applicant’s knowledge.

What matters is less the individual source than the process: a defined, category-based screening procedure with a documented justification per category is considerably safer under data protection law than the informal “googling” by the hiring manager, which knows neither legal basis nor documentation.

Where the Red Line Runs

The limits are equally clear. Not necessary — and therefore regularly unlawful — are in particular:

  • the routine, cause-independent review of visibly private social media profiles,
  • research with no connection to the specific role, such as family circumstances or worldview,
  • covert methods that deliberately circumvent the data subject,
  • stockpiling data “for later” without a concrete screening purpose.

Crossing these lines gains you no security but creates new risks: findings from unlawful sources cannot be used in the hiring decision and may count against the institution in a dispute. In co-determined organisations, the works council also belongs at the table early on; how to get that involvement right is covered in our article on co-determination in background checks.

Proportionality: Screening Depth by Position

Practical implementation works through risk-based tiering. A position in payments, asset management or with administrator rights justifies a deeper check than a role without customer or system access. Banks that sort their positions into two or three risk classes and assign each class a fixed catalogue of screening categories satisfy both requirements at once: the safeguarding duty under the GwG and the necessity standard of the BDSG. The classification itself should be justified in writing — it is the document with which you will later explain to the data protection authority and to data subjects why each position was screened to which depth. What the reliability check under the GwG looks like in substance is explained in our foundational article on employee screening under § 6 (2) no. 5 GwG.

If you want to put your pre-employment screening on a legally sound footing, a three-step approach is advisable:

  1. Classify positions: Define risk classes and assign each class a fixed screening scope — documented, not ad hoc.
  2. Map sources and legal bases: For each screening category, record why it is necessary for the position.
  3. Process over case-by-case: Conduct checks in a standardised manner and document the results in an audit-proof way.

A structured report with dated sources and human final review (Art. 22 GDPR) takes the most delicate work off your hands — Indicium delivers exactly that as an audit-ready software report, tailored to regulated industries.

This article provides general information and does not constitute legal advice.

Ready to move from reading to doing?

See how a reviewable risk report is built — from name to verdict in minutes, not weeks.

Book a demo See a sample report