Hiring the wrong person is expensive, so it is natural for employers to want to know as much as possible about a candidate before making an offer. But in Sweden the space for background checks is narrower than many employers assume, and the GDPR sits over the whole process. Overstepping can turn a routine hire into a data protection problem. This article sets out what employers can and cannot do.
Why this is a compliance issue, not just an HR one
Everything an employer collects about a candidate is personal data, and the more sensitive it is – criminal history, health, financial standing – the more carefully the law treats it. Swedish labour law, data protection law and specific rules on criminal record extracts all interact here. Treating background checks as a purely practical HR exercise, rather than a regulated processing activity, is where employers get into trouble.
Criminal record extracts: the biggest misconception
A common assumption is that an employer can simply require a criminal record extract (utdrag ur belastningsregistret) from any applicant. In fact, the right to obtain such extracts is reserved for specific sectors where the law provides for it – notably work involving children, such as schools and childcare, and certain other regulated roles. Outside those cases, an employer has no legal right to demand the extract, and asking a candidate to retrieve and hand over their own extract to sidestep the limits is legally and ethically fraught. The safe position is to treat criminal record data as off-limits unless a specific legal basis applies to the role.
What checks are generally acceptable
Employers can normally verify the information a candidate has provided: confirming qualifications with the awarding institution, checking references the candidate has offered, and verifying professional authorisations where the role requires them. Public information relevant to the role can be considered, but even here the principles of relevance and proportionality apply – you collect what you genuinely need for the specific job, not everything you can find.
Social media and internet searches
Searching a candidate online is tempting and technically easy, but it carries real risk. Much of what surfaces is irrelevant to the role, some of it is sensitive, and acting on it can expose the employer to discrimination and data protection concerns. If any such checks are done, they should be limited, relevant, documented and applied consistently rather than ad hoc.
The GDPR ground rules
Any background check must rest on a lawful basis, collect only data that is necessary for the role, and be transparent to the candidate. Consent is a weak basis in the employment context because of the imbalance of power between employer and applicant, so employers usually rely on other grounds and must be able to justify what they collect. Candidates should be told what checks are carried out, and the data should not be kept longer than needed.
Practical example: hiring for a finance role
An employer recruiting a finance manager might legitimately verify the candidate’s stated qualifications and professional references, and confirm any required authorisations. It would not, without a specific legal basis, be entitled to demand a criminal record extract or run a broad financial probe simply because the role touches money. The line is drawn by what the specific position genuinely requires and what the law permits, not by how reassuring extra information would feel.
Common mistakes companies make
Employers routinely ask for criminal record extracts without a legal right to them, rely on candidate consent as though it settles the matter, run informal online searches with no policy, keep background-check data indefinitely, and apply checks inconsistently between candidates – which itself raises discrimination concerns. Each of these turns a defensible process into a risky one.
Recommended actions
Decide in advance which checks each role genuinely justifies, confirm whether any criminal-record right actually applies before requesting an extract, tell candidates what you check, collect only what is necessary, apply the same approach to everyone, and delete the data once the decision is made. A short written policy makes all of this consistent and defensible.
Frequently asked questions
Can we ask a candidate for their own criminal record extract?
Asking a candidate to retrieve and hand over their own extract to work around the legal limits is problematic and should be avoided unless a specific legal basis genuinely applies to the role. When in doubt, treat criminal record data as unavailable.
Is candidate consent enough to justify a check?
Rarely. Because of the power imbalance in hiring, consent is generally not a reliable lawful basis under the GDPR, so employers should be able to justify checks on other grounds and limit them to what the role needs.
How long can we keep background-check information?
Only as long as necessary for the purpose. Once the hiring decision is made, most of it should be deleted, with narrow exceptions where there is a specific ongoing legal reason to retain it.
Conclusion
Background checks in Sweden are lawful only within clear limits: relevant to the role, proportionate, transparent and, for criminal records, restricted to the sectors the law allows. Employers who understand those limits hire with confidence; those who ignore them risk complaints and penalties. Lawgent helps businesses design recruitment processes that are effective and compliant. Contact us to review your hiring checks before your next round of recruitment.