Background check data is the information an employer receives or generates through pre-employment screening: criminal history, employment and education verification, credit reports where permitted, driving records, and professional license checks. It is among the most tightly regulated categories of information an employer handles, and among the most sensitive, because it frequently contains material the candidate would not otherwise disclose.
It also carries a distinctive property: the rules govern not only how the data is stored but how it may be obtained, when it may be considered, and what process must be followed before acting on it.
Federal fair credit reporting requirements apply whenever an employer uses a third-party screening company. They impose a sequence that must be followed in order: a clear, standalone written disclosure that a report may be obtained, the candidate's written authorization, and — before any adverse decision based on the report — a pre-adverse action notice with a copy of the report and a statement of rights, a reasonable opportunity for the candidate to respond, and then a final adverse action notice.
The most common failure is procedural rather than substantive. The disclosure must be a standalone document; burying it inside an application form or combining it with a liability waiver is a frequent and well-litigated error. So is skipping the pre-adverse action step and moving straight to rejection, which denies the candidate the opportunity to dispute inaccurate information.
These process requirements have generated substantial class litigation, often against employers whose underlying hiring decisions were entirely reasonable. The exposure comes from the paperwork sequence, not the judgment.
A large and growing number of jurisdictions restrict the timing and scope of criminal history inquiries. California's requirements are among the most detailed: for covered employers, conviction history generally may not be sought until after a conditional offer, and an adverse decision requires an individualized assessment considering the nature of the offense, the time elapsed, and its relationship to the specific job duties — followed by written notice and an opportunity to respond.
Local ordinances layer additional requirements in some cities. Multi-state employers face genuinely different rules by location, which makes a single national screening process difficult to operate compliantly. The practical answer is usually a process built to the most restrictive applicable standard, or one that varies by jurisdiction with clear internal guidance on which applies.
Screening results should be segregated from general personnel and recruiting files, with materially tighter access. The population that legitimately needs criminal or credit history is far smaller than the population with access to a candidate file — typically one or two people in HR, not hiring managers across the business.
Hiring managers generally need a decision, not the underlying report. Circulating the full report to everyone involved in a hiring process expands exposure without improving the decision and increases the chance that information which should not have been considered influences someone who saw it.
Retention requires reconciling competing rules. Anti-discrimination record-keeping obligations generally require retaining application and selection records for defined periods. Privacy principles and some state rules push toward limiting retention of sensitive screening material. A documented schedule that satisfies the mandatory minimum and then deletes is the defensible position; indefinite retention is not.
Screening firms are consumer reporting agencies with their own legal obligations, but selecting one does not transfer the employer's responsibilities. Diligence worth performing includes confirming the vendor's accuracy and dispute-handling practices, understanding what data sources they use, confirming they support the jurisdiction-specific timing rules the employer is subject to, and establishing what happens to the data when the relationship ends.
Accuracy matters more than it may appear. Screening reports do contain errors — mismatched identities are a recurring problem, particularly for common names — and an employer that acts on an inaccurate report without following the dispute process has both harmed a candidate and created liability.
A screening file typically contains name, date of birth, Social Security number, address history, and often more. That combination is precisely what identity fraud requires, which makes screening data a high-value target and makes encryption and access limits proportionate rather than excessive.
Delivery is a common weak point. Reports emailed as attachments and left in inboxes create copies outside any managed system. Retrieving results through the vendor's portal rather than accepting emailed copies materially reduces the number of places the data exists.
Employer's Guardian helps employers structure screening processes, notices, and record handling through onboarding documentation compliance, including the sequencing and documentation these requirements depend on.
This article provides general educational information, not legal advice. Screening requirements vary significantly by jurisdiction and change over time. Consult qualified counsel before establishing or changing a screening process.