It takes seconds to search a candidate’s name online. Facebook, Instagram, TikTok, X and other platforms may reveal far more than a CV ever would.
That is exactly why social media screening creates GDPR and discrimination risks.
”It’s public” is not enough
If a candidate has made a post publicly visible, you may technically be able to see it.
That does not mean an employer is free to collect and use it for any purpose.
The GDPR still requires lawful, fair and transparent processing.
Why social media screening is risky
Personal social media can reveal information about:
- Health
- Religion
- Political opinions
- Trade union activity
- Sexual orientation
- Family circumstances
- Ethnic background
Some of these are special categories of personal data under the GDPR. They may also relate to characteristics protected by employment and anti-discrimination law.
Once a hiring manager sees this information, it can be difficult to demonstrate that it played no role in the decision.
Is the information relevant?
Suppose you are hiring an accountant.
Pictures from a candidate’s holiday are unlikely to tell you whether they can do the job.
A professional public statement directly relevant to a role may present a different situation, but employers should still assess necessity and proportionality.
The test should not be: “Can we find something?”
It should be: “Do we have a legitimate and necessary reason to look for this information?”
Don’t ask for passwords or private access
Attempting to gain access to information the candidate has deliberately kept private is particularly intrusive and may breach applicable laws and platform rules.
Do not ask candidates to provide passwords or accept connection requests merely so you can inspect private content.
If you screen, create rules first
Define:
- Which roles justify screening
- Which platforms may be checked
- At what stage screening occurs
- What information is relevant
- Who performs the screening
- What may be recorded
- How candidates are informed
Consistency also reduces the risk that individual hiring managers conduct their own uncontrolled searches. Where you do screen, your candidate privacy information should say so.
Separate relevant from irrelevant information
Where screening is genuinely justified, consider having a designated person perform it and pass only job-relevant findings to the decision-maker.
This can help reduce exposure to irrelevant sensitive information.
It does not remove your GDPR obligations, but it can be a useful organisational safeguard. Limiting who can open the screening results, in the same way you apply access control to other personal data, reinforces it.
Social media screening should be exceptional, not automatic
A routine search of every candidate’s private online life is difficult to reconcile with data minimisation.
Professional recruitment should remain focused on whether a person can perform the job. A check of professional networking information is usually easier to justify than a sweep of private profiles.
GDPRWise helps organisations document recruitment processes and identify where personal data comes from, including external and public sources.
GDPRWise documents your recruitment processing and the external sources behind it, so screening follows a policy instead of a hunch.