Data (Use and Access) Act 2025: What It Means for Employment Screening
Back To Blog PostsEmployment screening now depends on more connected technology than many employers probably realise.
Candidate information may pass between an ATS, a screening platform, an identity provider, external data sources and other suppliers before a check is complete. Some parts of that process can be automated. Others may take place outside the UK.
That is why the Data (Use and Access) Act 2025 deserves attention from employers and screening providers.
The Act does not create a new legal regime specifically for employment screening, and it does not replace the UK GDPR or Data Protection Act 2018. Instead, it amends the existing data protection framework while creating new statutory infrastructure in areas including digital verification services.
For our industry, the interesting question is what those changes mean when they meet the reality of screening operations.
Several areas stand out.
Digital identity is becoming more formally governed
Identity sits at the start of many screening processes.
If you cannot establish with sufficient confidence that you are dealing with the right person, the reliability of the checks that follow becomes much harder to assess.
The DUAA establishes a statutory framework for Digital Verification Services (DVS), including a government register, a trust framework and certification arrangements for providers that want their services registered.
This is an important development for screening because digital identity is already being used in employment processes, including the digital identity element of eligible Right to Work checks.
At the time of writing, the statutory DVS framework and register are operating under the current arrangements, while version 1.0 of the DVS trust framework has been published ahead of its introduction. Employers and providers therefore need to check the current certification and registration status of the particular service they use rather than treating “digital identity provider” as a single assurance standard.
For screening providers, that raises some practical questions.
Which service is verifying the candidate’s identity? What certification does that specific service hold? Which supplementary requirements apply to the use case? What information comes back from the identity check, and where does that information go next?
Certification is useful assurance. It should not be mistaken for a blanket guarantee that every subsequent use of the candidate’s information complies with data protection law.
Right to Work still leaves responsibility with the employer
Right to Work is a good example.
Employers can use a DVS for digital Right to Work checks on holders of valid British and Irish passports or Irish passport cards. The Home Office recommends using suitably certified providers. But using a DVS does not transfer the employer’s responsibilities to the technology supplier.
The employer still needs to follow the prescribed process and satisfy itself that the check relates to the person presenting for work.
That principle has wider relevance to screening.
A supplier can perform an activity on an employer’s behalf. The employer still needs to understand enough about that activity to govern it properly.
Automation has more room to operate, with safeguards
The changes to automated decision-making are particularly relevant as automation and AI become more common across recruitment technology.
The DUAA widens the circumstances in which organisations can make significant decisions using solely automated processing of most personal data. In broad terms, organisations now have access to the full range of Article 6 lawful bases rather than the narrower set of circumstances that previously applied.
The safeguards have not disappeared.
The law defines a solely automated decision as one involving no meaningful human involvement. Where such a decision has a legal or similarly significant effect on somebody, safeguards include providing information about the decision, allowing the person to make representations or contest it, and giving them the ability to obtain human intervention.
Special-category data remains subject to tighter rules.
There is also an important limitation that could easily be missed: the new recognised legitimate interests lawful basis cannot be used as the basis for a significant solely automated decision.
For employers and screening providers, I think the first task is to be precise about what the technology is actually doing.
Software that gathers documents automatically is not the same as software that evaluates information against rules. A system that flags something for review is different again from one that determines an outcome without meaningful human involvement.
Putting all of those processes under the headings of “AI” or “automation” obscures the questions employers actually need answered.
Where does a decision take place? What information contributes to it? Can a person genuinely review the result? Do they have enough information and authority to change it?
The ICO has already made automated decision-making in recruitment an area of regulatory attention, including transparency, bias, recourse and meaningful human involvement.
Automation can make screening quicker and more consistent. But if nobody can explain or properly review an outcome when a candidate questions it, the operational model is weak regardless of how sophisticated the technology is.
Subject Access Requests are clearer to manage
Screening businesses can hold substantial volumes of personal information: application details, identity evidence, verification results, correspondence, reports, audit records and internal notes.
Subject Access Requests can therefore become operationally demanding very quickly.
The DUAA now expressly confirms that organisations only need to carry out reasonable and proportionate searches when responding to a SAR.
It also allows an organisation to ask for clarification and pause the response period where that clarification is reasonably required to respond effectively to the request.
Those are useful changes, but I would not interpret them as a reason to relax information governance.
An organisation still needs to know where candidate information is held and be able to retrieve it efficiently. The ICO’s current guidance specifically expects organisations to have suitable information-management systems for locating and retrieving personal information.
In screening, poor data architecture tends to reveal itself when somebody exercises their rights.
If responding to one candidate requires staff to search several platforms, inboxes and supplier portals manually, the problem is bigger than the SAR itself.
Complaints now need a defined route
The DUAA also creates explicit requirements around data-protection complaints.
Controllers need to facilitate complaints, acknowledge them within 30 days, take appropriate steps to investigate and respond, keep the complainant informed where appropriate, and communicate the outcome without undue delay.
For screening providers, I think this should be viewed alongside the candidate experience rather than as an isolated compliance process.
A candidate might question the accuracy of a screening result. They might want to know where information came from, why it was processed, how an automated outcome was reached or why information has been retained.
Depending on the circumstances, those concerns can cut across operational support, data-protection rights, disputes and formal complaints.
If different organisations or teams own each part of that journey, there needs to be a clear route between them.
A candidate should not need to understand a screening provider’s organisational chart or supply chain to get an issue investigated.
Recognised legitimate interests should be treated carefully
The introduction of recognised legitimate interests is another change that needs careful interpretation in screening.
The DUAA specifies certain purposes for which organisations may rely on this new Article 6 lawful basis without carrying out the balancing exercise normally associated with legitimate interests.
They include specified processing relating to crime prevention and detection, safeguarding vulnerable people, emergencies, national and public security, defence and certain disclosures connected with public tasks.
There is still a necessity requirement.
Some of these purposes can intersect with employment screening. That does not mean employment screening itself has become a recognised legitimate interest, or that the new basis automatically applies whenever an organisation carries out background checks.
The purpose and processing need to fall within one of the statutory conditions.
Criminal-offence data also continues to have additional protection.
Processing criminal-offence information requires an Article 6 lawful basis and compliance with Article 10 of the UK GDPR. Where an organisation is not processing under official authority, it must also identify an applicable condition under Schedule 1 of the Data Protection Act 2018. Depending on the condition used, further requirements may apply.
So I would resist any suggestion that the DUAA has generally made criminal-record screening easier.
Employers and screening providers still need to understand what information they are processing, why they need it and which legal conditions actually apply.
Know where candidate data goes — and why
Modern screening rarely takes place inside one system.
Candidate information may move between employers, screening providers, identity services, external data sources, cloud infrastructure and subprocessors.
The DUAA changes some of the rules around using personal information for a further purpose. Certain specified uses can now be treated as compatible with the original purpose without carrying out the usual compatibility assessment.
That is not a general permission to reuse candidate information.
An organisation still needs a lawful basis for the processing and must comply with the other data-protection principles.
The same operational discipline applies when information crosses borders.
The DUAA changes the legal test used for international transfers, including introducing the concept that protection must not be materially lower than the UK standard and formalising a reasonable and proportionate approach to assessing certain transfers.
International-transfer controls have not disappeared.
For employers, that means “our platform is hosted in the UK” is not always the end of the conversation.
Candidate information may still be accessible by overseas support teams or processed by suppliers elsewhere. Employers should understand the wider data flow, not simply the location of the primary application.
What employers should review
I would avoid responding to the DUAA by simply adding another policy to the compliance folder.
For employers using screening services, a more useful exercise is to walk through how the process actually works.
Ask:
- What candidate information is processed for each check? Distinguish ordinary personal data from special-category and criminal-offence information.
- Who receives or processes it? Map the screening provider, identity services, subprocessors and other relevant suppliers.
- Where is the information stored and where can it be accessed from? Do not stop at the main hosting location.
- What purpose and lawful basis supports each important processing activity? Where criminal-offence or special-category data is involved, identify the additional condition that applies.
- Where is automation used? Establish whether technology assists a person or actually makes a significant decision without meaningful human involvement.
- What does human involvement look like? Identify who can review an automated outcome, what evidence they receive and whether they can genuinely alter the decision.
- What are candidates told? Privacy information should match what actually happens to their data.
- How can candidates challenge an outcome or raise a data-protection complaint? Make sure the route works across organisational and supplier boundaries.
- How would you respond to a SAR? Know where the information needed for a response is held and who retrieves it.
- How long is screening information retained? Retention should result from a deliberate decision, not simply a software default.
- What assurance applies to digital identity services? Check the certification and registration relevant to the particular service and use case.
These are also useful procurement questions.
An employer should be able to get clear answers before appointing a screening or HR technology supplier, rather than discovering how the system works after a candidate raises a concern.
What this means for screening providers
I see the DUAA as an operational development for our industry as much as a compliance one.
There is more scope to use digital identity and automation effectively. Some existing data-protection processes have also been clarified.
We should make use of that.
But greater technical capability increases the importance of knowing what is happening underneath the process.
Screening providers should be able to explain where candidate information comes from, how it moves through their service, where important decisions take place, which suppliers are involved and what happens when somebody challenges an outcome.
None of that requires technology to stand still.
In fact, I think the opposite is true. The more sophisticated screening becomes, the more important it is that employers, providers and candidates can still understand how the process works.
For me, that is the practical significance of the DUAA for screening: more opportunity to use data and technology effectively, accompanied by a stronger need to understand and account for what we do with them.
Martin Price, Chief Operating Officer, Secure Screening Services
About the author
Martin is Chief Operating Officer at Secure Screening Services, with responsibility for the operational delivery of employment screening services and the technology, processes and governance that support them.
This article provides general information and commentary and should not be treated as legal advice.