Employee screening, a hiring necessity or an invasion of privacy?

Issue 1 2023 Security Services & Risk Management


Nicol Myburgh.

Employee background screening has become an integral part of the recruitment process. Many companies use it as a means to not only verify potential employees’ education, experience and other credentials before appointing them, but also to ensure that they hire the right candidate for the role – someone who will bring value to the business and be a worthy ambassador for the brand.

Checking that recruitment candidates have not falsified their CV information and will be a good culture fit for the organisation is all good and well, but how deeply can employers delve into a person’s background before the screening process becomes an invasion of privacy?

According to Nicol Myburgh, Head of the HCM Business Unit at CRS Technologies, there is a fine line between checking a potential employee’s qualifications and references, and investigating aspects of their lives that have nothing to do with their job application.

“The best indicator of future performance is your record of past performance, and good references usually mean a good employee,” he says. “There is nothing wrong with checking a candidate’s references – in fact, it is highly recommended – but if you start looking at the person’s credit history and behaviour, and whether they have a criminal record, you are treading on thin ice.”

Many companies are not aware of the National Credit Act Amendment 19 of 2014, which came into effect in March 2015. It stipulates that pre-employment checks on consumer credit records may only be performed if the role for which the candidate has applied requires honesty in the handling of cash or finances. Furthermore, this responsibility must be specified in the job description.

“So unless the position are looking to fill involves working with money, checking the candidate’s credit record constitutes a violation of their privacy and is illegal,” says Myburgh.

The same applies to criminal record searches, which are governed by labour legislation. “For example, if a person applies for a position as a driver, but was previously arrested for driving under the influence and as a result has a criminal record, they can be disqualified from the position.

“But if the person is applying for a job as say, an admin clerk, the drunk driving conviction would be irrelevant. Consequently, a criminal record check can only be done if it is pertinent to the job for which you are hiring.”

Employers also need to bear the POPI Act in mind when collecting information for background screening purposes. Accessing information that is available in the public domain – social media accounts, personal blogs and the like – is fine. All other information, including personal identity details, is protected under the POPI Act and therefore off limits.

But whether the background screening you want to do is relevant to the job or not, it is necessary to obtain the applicant’s consent before processing any of their personal information.

How not to overstep

To ensure that companies do not overstep when conducting background checks, Myburgh recommends engaging the services of a reputable background screening and vetting company. “These service providers are fully conversed with the legalities and ethics around employee screening and not only know where the line is, but where not to cross it.”

“Violating someone’s privacy during the recruitment process, or choosing not to hire them for reasons that have nothing to do with the job description can land a business in hot water, and they could find themselves slapped with a lawsuit. This will not only cost the company thousands in legal fees, but could irreparably damage its reputation and brand.”

“Conducting background checks on potential employees mitigates the risk against a bad hire, which can be costly for the business, but these must be done ethically and within the bounds of legislation,” he concludes.

For more information, go to www.crs.co.za




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Global security in 2026
Editor's Choice News & Events Security Services & Risk Management Industrial (Industry) Mining (Industry)
The World Security Report 2026 states: “In a world of increasing volatility, physical security has evolved. It is no longer just a defensive measure; it is a critical driver of corporate value.”

Read more...
Who is to blame for autonomous mistakes?
Editor's Choice Security Services & Risk Management Industrial (Industry) Mining (Industry)
Most supply agreements for AI-integrated equipment still closely resemble plant hire contracts from ten years ago: bilateral, human-focused, and silent on who bears the risk when a machine makes a decision on its own.

Read more...
Cyber resilience is the real defence
Security Services & Risk Management Information Security Infrastructure
Cyber resilience has evolved into a form of strategic agility, ensuring that when an interruption occurs, the business does not just survive; it snaps back into place before the market even notices a pause.

Read more...
Employees are SA’s biggest cyber threat
Security Services & Risk Management Information Security
South Africa experienced a 46% increase in insider cyber risk in 2026, surpassing the global average of 44%. What is more, 63% of South African companies surveyed expect insider-driven data losses to increase.

Read more...
The post-Q1 security checklist
Asset Management Security Services & Risk Management
By this time of year, employees have changed jobs or roles, suppliers may have changed, and devices have moved between offices, homes, and sites. This is the right time for businesses to run a practical post-Q1 security check.

Read more...
PoPIA turns its attention to gated access
News & Events Security Services & Risk Management
The Information Regulator has gazetted its proposed Code of Conduct for the processing of personal information at gated access points. At 65 pages long, the code signals a significant shift in how personal information is collected and managed at entry points.

Read more...
Your company is already breached, you just do not know it yet
Information Security Security Services & Risk Management
Attackers are no longer relying on sophisticated exploits to break-in. Instead, they are systematically targeting weak credentials, misconfigured systems, and exposed devices stemming from preventable gaps such as identity weaknesses and poor visibility across digital environments.

Read more...
Excellerate Services sets a new standard
News & Events Security Services & Risk Management
Excellerate Services relies on specialist expertise and the sophistication of its operations deployment and management. Central to this is an investment in smarter, data-driven operations through the Velocity and Performance Centre platforms.

Read more...
957 women killed in three months
News & Events Security Services & Risk Management
Despite years of summits, task teams and public commitments, South Africa’s femicide rate remains around five times higher than the global average, and too few are using the legal lifelines available.

Read more...
The security debt hidden in residential estates
Security Services & Risk Management Integrated Solutions Residential Estate (Industry)
Many residential estates undermine their own security not through a lack of technology, but through hidden weaknesses in gate design, fragmented systems, recurring software dependence, weak operational ownership, and insufficient estate management input.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.