By The Background Investigator

A landmark decision by Germany’s Federal Labor Court (Bundesarbeitsgericht – BAG, Case 8 AZR 117/24) has clarified the strict boundaries surrounding open-source web searches and social media screening during hiring under the GDPR.

The court ruled that while employers may evaluate publicly available information, conducting ad-hoc web searches without fulfilling strict GDPR transparency requirements—or collecting sensitive data without explicit statutory justification—exposes organizations to statutory non-material damages.

Case Overview

A lawyer applied for a legal position at a German university. During the evaluation process, university staff conducted a general Google search on the applicant. The search revealed news of a non-final criminal conviction for attempted fraud. Based on these findings, the university rejected the applicant, citing doubts about his suitability.

The applicant sued, seeking both:

  1. Material Damages: Compensation for lost wages from non-hiring.
  2. Non-Material Damages: €1,000+ under Article 82 GDPR for loss of control over personal data and privacy violations.

Key Legal Findings & Court Rulings

Issue

Lower Court (LAG Düsseldorf)

Federal Labor Court (BAG) Final Ruling

Legality of Web Searches

Permitted under Art. 6(1)(b) GDPR as necessary pre-contractual processing.

Invalid Basis: Conducting general web searches to unearth criminal data violates Art. 6 & Art. 10 GDPR (which strictly restricts processing offense history).

Transparency Obligations

Failed to inform candidate under Art. 14 GDPR about processing web search data.

Upheld: Organizations cannot secretly scrape or search applicant data without explicit prior notice in privacy disclosures.

Material Damages (Lost Job)

Rejected.

Rejected: The GDPR violation did not cause the non-hiring. The employer had valid, objective suitability concerns regardless of the process flaw.

Non-Material Damages

Awarded €1,000.

Upheld (€1,000): Compensation under Art. 82 GDPR is strict. Fault severity is irrelevant—loss of control over candidate data mandates financial redress.

Critical Operational Takeaways for Background Screening & CRAs

  1. "Googling" Candidates Is Not Free Game: Informal online searches cannot be conducted casually by hiring managers. Open-source intelligence (OSINT) and social media monitoring require clear legal ground, strict necessity, and prior disclosure.
  2. Mandatory Transparency (Art. 14 GDPR): Applicant privacy notices must explicitly state if publicly available web sources or online databases will be queried, defining the categories of data gathered and the processing scope.
  3. Strict Limits on Criminal Record Inquiries: Article 10 of the GDPR strictly restricts handling criminal convictions or pending proceedings without specific national law authorization or official authority oversight.
  4. No Exposure to Hiring Claims, But Modest Fines Add Up: While candidates cannot force a job offer or claim lost salary over a procedural GDPR error, a statutory €1,000 non-material damage award per affected candidate creates significant cumulative class/systemic risk for high-volume screeners.