Background Checks: Keeping the Records Lawful and Lean — Herarx Blog

Background Checks: Keeping the Records Lawful and Lean

Background checks generate some of the most sensitive records you will ever hold. How to collect only what the purpose needs, restrict it, and delete it on time.

January 21, 2025
Background Checks: Keeping the Records Lawful and Lean
Back to blog

Whether you run background checks for clients as an investigator, or commission them as an employer, landlord or organisation, the records they produce are sensitive: identity documents, addresses, employment history, credit information, sometimes criminal records. What you may check, with what consent, and for how long you can keep the results varies a great deal between countries and sectors. Check your jurisdiction carefully before you start. The record-keeping discipline below applies everywhere.

Start with a defined purpose

Write down, before any searching begins, exactly why the check is being done and what decision it supports. "Verify identity and employment history for a finance role." "Confirm the subject's current address for service of documents." The purpose sets the boundary for everything else: what you search, what you record, who sees it and when it is deleted.

Record the basis and the consent

  • The instruction — who asked for the check, when, and in what terms.
  • The legal basis or permission you rely on, and any consent obtained, with a copy of what the subject was told.
  • The scope agreed — which checks, which sources, which time period.

If you cannot point to these, stop before searching.

Collect only what answers the question

Searches return far more than you need. A check on employment history does not need the subject's relatives, social media photos or unrelated court records. Record what is relevant to the stated purpose and leave the rest. Where you must note that a search was run, record the source, the date and "nothing relevant found", rather than saving the page.

Record sources and method

Each finding should say where it came from, when it was obtained and how it was verified. A finding without a source cannot be relied on, and cannot be corrected if the subject disputes it. Keep your working notes separate from the report you deliver.

Restrict access tightly

  • Only the people conducting the check and the named decision-maker should see the results.
  • Identity documents need particular care; see storing identity documents securely.
  • Do not email reports as attachments where a secure, expiring share is available.
  • Keep an audit trail of who viewed or downloaded the file.

Handle adverse findings fairly

Where a check affects a decision about someone, many jurisdictions give them a right to know and to respond. Even where they do not, good practice is to verify adverse information with a second source and give the person a chance to explain. Record that step and the outcome.

Delete on time

Background check records should have short, defined retention periods tied to their purpose: often months after the decision, not years. Set the deletion date when the file is opened. Keep a minimal record that the check was done, when, under which instruction and with what outcome, and dispose of the detail. Landlords will recognise the pattern from tenant screening records, and the wider approach is in privacy by design for small businesses.

A checklist for each check

  • Purpose written down
  • Instruction, basis and consent recorded
  • Scope agreed
  • Findings sourced and dated
  • Access restricted
  • Adverse findings verified
  • Deletion date set