By The Background Investigator
A landmark decision by Germany’s Federal Labor Court (Bundesarbeitsgericht – BAG, Case 8 AZR 117/24) has clarified the strict boundaries surrounding open-source web searches and social media screening during hiring under the GDPR.
The court ruled that while employers may evaluate publicly available information, conducting ad-hoc web searches without fulfilling strict GDPR transparency requirements—or collecting sensitive data without explicit statutory justification—exposes organizations to statutory non-material damages.
Case Overview
A lawyer applied for a legal position at a German university. During the evaluation process, university staff conducted a general Google search on the applicant. The search revealed news of a non-final criminal conviction for attempted fraud. Based on these findings, the university rejected the applicant, citing doubts about his suitability.
The applicant sued, seeking both:
- Material Damages: Compensation for lost wages from non-hiring.
- Non-Material Damages: €1,000+ under Article 82 GDPR for loss of control over personal data and privacy violations.
Key Legal Findings & Court Rulings
Issue
Lower Court (LAG Düsseldorf)
Federal Labor Court (BAG) Final Ruling
Legality of Web Searches
Permitted under Art. 6(1)(b) GDPR as necessary pre-contractual processing.
Invalid Basis: Conducting general web searches to unearth criminal data violates Art. 6 & Art. 10 GDPR (which strictly restricts processing offense history).
Transparency Obligations
Failed to inform candidate under Art. 14 GDPR about processing web search data.
Upheld: Organizations cannot secretly scrape or search applicant data without explicit prior notice in privacy disclosures.
Material Damages (Lost Job)
Rejected.
Rejected: The GDPR violation did not cause the non-hiring. The employer had valid, objective suitability concerns regardless of the process flaw.
Non-Material Damages
Awarded €1,000.
Upheld (€1,000): Compensation under Art. 82 GDPR is strict. Fault severity is irrelevant—loss of control over candidate data mandates financial redress.
Critical Operational Takeaways for Background Screening & CRAs
- "Googling" Candidates Is Not Free Game: Informal online searches cannot be conducted casually by hiring managers. Open-source intelligence (OSINT) and social media monitoring require clear legal ground, strict necessity, and prior disclosure.
- Mandatory Transparency (Art. 14 GDPR): Applicant privacy notices must explicitly state if publicly available web sources or online databases will be queried, defining the categories of data gathered and the processing scope.
- Strict Limits on Criminal Record Inquiries: Article 10 of the GDPR strictly restricts handling criminal convictions or pending proceedings without specific national law authorization or official authority oversight.
- No Exposure to Hiring Claims, But Modest Fines Add Up: While candidates cannot force a job offer or claim lost salary over a procedural GDPR error, a statutory €1,000 non-material damage award per affected candidate creates significant cumulative class/systemic risk for high-volume screeners.
