Agent skill

Background Check Privacy

by mukul975 in mukul975/Privacy-Data-Protection-Skills

Manages privacy compliance for employee background checks including criminal record processing under Art.

Apache-2.0Auto-check passedLegal & Compliance

Install Background Check Privacy

skills CLI
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill background-check-privacy -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Privacy-Data-Protection-Skills background-check-privacy --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/privacy/background-check-privacy .claude/skills/background-check-privacy && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
background-check-privacy
GitHub stars
301
Token cost
~3.7k tokens
SKILL.md length
1,794 words
Files
5 (incl. scripts, references, assets)
Skills in repo
280
Repo updated
First seen
Licence
Apache-2.0

At a glance

Manages privacy compliance for employee background checks including criminal record processing under Art.

  • Tasks that involve Privacy and GDPR
  • SKILL.md covers Overview, Legal Framework, Proportionality Framework and Data Minimisation and Retention, plus 4 more sections
  • Runs Python scripts from its folder
  • Tasks that involve Authorization and RBAC

What it does

Background Check Privacy is an agent skill from mukul975/Privacy-Data-Protection-Skills. Manages privacy compliance for employee background checks including criminal record processing under Art. 10 GDPR, DBS checks (UK), national law variations, and reference verification. Applies proportionality and data minimisation to pre-employment screening, defines retention limits, and addresses role-based necessity assessments. Keywords: background check, criminal record, Art. 10, DBS, pre-employment screening, vetting, data minimisation, proportionality.

Its SKILL.md is about 3.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/standards.md` and `references/workflows.md`).

It sits in Legal & Compliance, covering Privacy and GDPR and Authorization and RBAC. The repository describes itself as: 282+ structured privacy & data protection skills for AI agents. GDPR, CCPA, EU AI Act, HIPAA, LGPD, PIPL, DPDP Act. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Privacy and GDPR
  • Tasks that involve Authorization and RBAC

Example prompts

  • “Use the background-check-privacy skill to manage privacy compliance for employee background checks including criminal record processing under Art”
  • “/background-check-privacy”

Requirements

  • Python 3

What it can do on your machine

Read from SKILL.md and the folder at commit 9b2ef9e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Background Check Privacy loads about 3.7k tokens when it runs, and up to ~5.7k if it reads all its reference files. Until then it costs about 122 tokens; SKILL.md has 1,794 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~122
When it runs · the whole SKILL.md, loaded when a task matches
~3.7k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~5.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Privacy-Data-Protection-Skills at commit 9b2ef9e, republished under its Apache-2.0 licence (© mukul975). 1,794 words, ~3,748 tokens.

Download SKILL.mdSave it as .claude/skills/background-check-privacy/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
background-check-privacy
description
Manages privacy compliance for employee background checks including criminal record processing under Art. 10 GDPR, DBS checks (UK), national law variations, and reference verification. Applies proportionality and data minimisation to pre-employment screening, defines retention limits, and addresses role-based necessity assessments. Keywords: background check, criminal record, Art. 10, DBS, pre-employment screening, vetting, data minimisation, proportionality.
license
Apache-2.0
metadata.author
mukul975
metadata.version
1.0
metadata.domain
privacy
metadata.subdomain
employee-data-privacy
metadata.tags
background-check, criminal-record, article-10, dbs, pre-employment-screening, data-minimisation

Background Check Privacy

Overview

Pre-employment background checks involve processing personal data that ranges from routine reference verification to highly sensitive criminal record data. Art. 10 GDPR provides specific restrictions on processing data relating to criminal convictions and offences, requiring that such processing be authorised by EU or Member State law providing appropriate safeguards. Beyond criminal data, background checks may involve credit history, educational qualifications, professional registration, social media presence, and right-to-work verification — each carrying distinct proportionality and data minimisation requirements. The principle that governs all background checking is role-based necessity: the scope of a background check must be proportionate to the specific role and its associated risks, not applied uniformly across all positions.

Art. 10 — Criminal Conviction Data

"Processing of personal data relating to criminal convictions and offences or related security measures based on Article 6(1) shall be carried out only under the control of official authority or when the processing is authorised by Union or Member State law providing for appropriate safeguards for the rights and freedoms of data subjects."

Key requirements:

  • Criminal data processing requires specific national law authorisation (not merely a legitimate interest)
  • The national law must provide appropriate safeguards
  • A comprehensive register of criminal convictions may be kept only under the control of official authority
Art. 6(1) — Lawful Basis for Background Checks Generally
Check TypeLawful BasisNotes
Reference verificationArt. 6(1)(b) contract + Art. 6(1)(f) legitimate interestNecessary for employment decision; limited to professional references
Criminal record checkArt. 6(1)(c) legal obligation or Art. 6(1)(e) public taskOnly where national law mandates or authorises the check for the specific role
Credit checkArt. 6(1)(f) legitimate interestLimited to roles with financial responsibility; must pass balancing test
Qualification verificationArt. 6(1)(b) contractNecessary to verify contractual requirements
Right-to-work checkArt. 6(1)(c) legal obligationMandatory under national immigration law
Social media screeningArt. 6(1)(f) legitimate interestHighly restricted; see detailed analysis below
Health screeningArt. 9(2)(b) + national lawOnly where role requires specific fitness standard
National Criminal Record Check Frameworks
United Kingdom — DBS (Disclosure and Barring Service)

Three levels of disclosure:

LevelContentEligible Roles
Basic DBSUnspent convictions onlyAny role; self-applied by the individual
Standard DBSSpent and unspent convictions, cautions, reprimands, final warningsRoles listed in the Rehabilitation of Offenders Act 1974 (Exceptions) Order 1975 (e.g., solicitors, accountants, healthcare professionals)
Enhanced DBSStandard + relevant police intelligence + barred list check where applicableRegulated activity involving children or vulnerable adults, positions of trust in national security

Key GDPR compliance requirements:

  • The Rehabilitation of Offenders Act 1974 prohibits considering spent convictions for most employment purposes
  • DBS certificates belong to the applicant, not the employer
  • Employers should not retain a copy of the DBS certificate; they should record only the DBS certificate number, date of issue, and the result (clear/not clear)
  • DBS Update Service allows ongoing status checks without requesting new certificates
Germany — Führungszeugnis (Certificate of Good Conduct)
  • Belegart N (standard): Shows convictions with sentences exceeding 90 daily rates or 3 months imprisonment (with exceptions)
  • Belegart O (extended): Includes all convictions for roles involving minors
  • Employers may request a Führungszeugnis only where the role justifies it; routine requests for all positions are disproportionate
  • Employers may view the certificate but should not retain a copy; they should record only the confirmation that the check was satisfactory
France — Extrait de Casier Judiciaire
  • Bulletin No. 3 (most common for employment): Shows only the most serious convictions (imprisonment over 2 years without suspension)
  • Employer may request Bulletin No. 3 only for specific roles justified by the nature of the activity
  • For public sector roles, the administration may access Bulletin No. 2 directly
Netherlands — Verklaring Omtrent het Gedrag (VOG)
  • The VOG (Certificate of Conduct) is issued by the Ministry of Justice
  • The VOG states only whether the individual's judicial record contains relevant information for the specific role — it does not disclose the convictions themselves
  • The employer specifies the screening profile (e.g., "persons" for working with vulnerable people, "finances" for financial roles)
Spent Convictions — Rehabilitation Principle

Most European jurisdictions implement the rehabilitation principle: after a specified period, convictions become "spent" and may no longer be considered for employment purposes. Processing spent convictions where they are protected by rehabilitation legislation violates both national law and the GDPR data minimisation principle.

JurisdictionRehabilitation FrameworkKey Rule
UKRehabilitation of Offenders Act 1974Spent convictions may not be disclosed or considered except for excepted roles
GermanyBZRG (Federal Central Register Act)Convictions removed from certificate after specified periods (5-15 years)
FranceArt. 133-16 Code pénalAutomatic rehabilitation after specified periods
NetherlandsWet justitiële en strafvorderlijke gegevensJudicial data removed after 20 years (adults) or 5 years (minors)

Proportionality Framework

Role-Based Necessity Assessment

Not all roles justify the same level of background checking. The proportionality principle requires that the scope of checks be tailored to the specific risks of the role.

Role CategoryAppropriate ChecksDisproportionate Checks
General office workerRight-to-work, references, qualification verificationCriminal record, credit check, social media screening
Financial controllerRight-to-work, references, qualifications, credit check, basic criminal record (fraud offences)Enhanced criminal record, social media screening
Teacher / youth workerRight-to-work, references, qualifications, enhanced criminal record with barred listCredit check, social media screening
Security guardRight-to-work, references, SIA licence verification, standard criminal recordEnhanced criminal record (unless regulated activity), credit check
Warehouse operativeRight-to-work, referencesCriminal record (unless handling high-value goods), credit check, qualification verification
Senior executiveRight-to-work, references, qualifications, directorship checks, basic criminal recordEnhanced criminal record (unless regulated role)

Atlas Manufacturing Group Example: Atlas conducted a proportionality review of its background check programme and found that it was requesting basic DBS checks for all positions including warehouse operatives and canteen staff. Following DPO advice, Atlas implemented a tiered checking framework:

  • All roles: right-to-work verification, two professional references
  • Roles with financial access (finance, procurement, senior management): credit check + basic DBS
  • Roles with access to R&D laboratory: basic DBS (given intellectual property value)
  • Roles working with site visitors under 18 (apprenticeship supervisors): enhanced DBS with barred list
Social Media Screening

Social media screening of candidates is one of the most privacy-invasive background check activities. It may reveal:

  • Political opinions (Art. 9(1))
  • Religious or philosophical beliefs (Art. 9(1))
  • Trade union membership (Art. 9(1))
  • Health information (Art. 9(1))
  • Sexual orientation (Art. 9(1))
  • Racial or ethnic origin (Art. 9(1))

When social media screening may be justified:

  • Public-facing roles where the candidate's public statements may directly affect the organisation's reputation
  • Senior leadership roles with significant public profile
  • Roles requiring security clearance where national law authorises screening

Requirements if conducted:

  • Limited to publicly available information (no friend requests, no fake profiles)
  • Limited to information relevant to the role
  • Conducted at the latest possible stage (after shortlisting, before final offer)
  • Documented with a clear record of what was reviewed and what was found
  • Candidate must be informed that social media screening is part of the process
  • Special category data encountered incidentally must not be recorded or used in the employment decision
Show full SKILL.md (643 more words)Show less

Data Minimisation and Retention

Data Minimisation in Collection
  • Collect only the specific check results relevant to the role, not blanket screening
  • Do not retain copies of identity documents beyond the verification point (photograph the document, verify, delete the image — retain only a record that verification was completed)
  • Do not retain copies of criminal record certificates — record only the certificate reference number, date, and result
  • Do not collect more references than needed (two professional references is standard; personal character references are generally disproportionate)
Retention Limits
Data TypeRetention PeriodJustification
Right-to-work verification recordDuration of employment + 2 yearsLegal obligation (Immigration Act requirements)
Reference responses6 months from hire decisionSufficient for probation period disputes
Criminal record check result (reference number + outcome only)Duration of employmentRequired for ongoing regulatory compliance in regulated roles
Credit check result6 months from hire decisionNo ongoing necessity after employment decision
Qualification verification recordsDuration of employmentOngoing professional registration may be required
Social media screening notes6 months from hire decision or immediately if candidate not hiredMinimal retention; highly sensitive
Unsuccessful candidate background check data6 months maximumLegal claim limitation period (extended to 12 months if discrimination claim risk identified)
Unsuccessful Candidates

Background check data for candidates who are not hired must be:

  • Deleted within 6 months of the hiring decision (12 months where a discrimination claim risk is identified)
  • Not retained in a general candidate database for future recruitment
  • Deleted earlier if the candidate withdraws consent or requests erasure

Candidate Rights

Right to Be Informed — Art. 13

Before conducting any background check, the candidate must be informed of:

  • The specific checks that will be conducted
  • The lawful basis for each check
  • Who will conduct the checks (third-party screening provider, if applicable)
  • What data will be obtained
  • How the data will be used in the employment decision
  • Retention periods
  • Their rights under Arts. 15-22
Right to Challenge
  • Candidates must be given the opportunity to discuss and challenge adverse check results before a final employment decision is made
  • If a criminal record check reveals a conviction, the candidate must be allowed to provide context (rehabilitation evidence, mitigating circumstances)
  • An automatic disqualification policy (rejecting any candidate with any criminal record) is unlawful — each case must be assessed individually, considering the nature of the offence, its relevance to the role, and the time elapsed

Third-Party Screening Providers

Where background checks are conducted by a third-party provider:

  • A Data Processing Agreement under Art. 28 GDPR must be in place
  • The provider is a processor acting on the employer's (controller's) instructions
  • The employer must specify what checks may be conducted; the provider must not conduct checks beyond the scope authorised
  • The provider must delete check data after transmitting results to the employer, per the agreed retention schedule
  • International transfers (common with global screening providers) must comply with Chapter V GDPR

Enforcement Precedents

AuthorityCaseFine/OutcomeKey Issue
ICO (UK)Experian, 2020Enforcement noticeExperian's employment screening services processed personal data without adequate transparency to data subjects
CNIL (France)SAN-2019-007EUR 30,000Employer retained criminal record certificates in personnel files beyond the verification period
AEPD (Spain)PS/00321/2020EUR 50,000Employer conducted social media screening of candidates without informing them and used special category data in hiring decisions
Autoriteit Persoonsgegevens (NL)2021 InvestigationCorrective orderEmployer requested VOG for all roles without role-based necessity assessment
Garante (Italy)Provvedimento 2020-0893WarningEmployer retained background check data for unsuccessful candidates for 5 years — excessive retention

Integration Points

  • Employment Consent Limits: Consent is not the appropriate lawful basis for most background checks (see employment-consent-limits skill).
  • Employee DSAR Response: Candidates and employees may request access to background check data (see employee-dsar-response skill).
  • HR System Privacy Config: Background check data storage and access must be configured with appropriate restrictions (see hr-system-privacy-config skill).
  • Employee Health Data: Pre-employment health screening is governed by separate rules (see employee-health-data skill).

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts, references, assets) in skills/privacy/background-check-privacy of mukul975/Privacy-Data-Protection-Skills.

  • SKILL.md
  • assets/template.md
  • references/standards.md
  • references/workflows.md
  • scripts/process.py

Open the folder on GitHubat commit 9b2ef9e

Compare with similar skills

Background Check Privacy next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Background Check Privacy compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Background Check Privacy this skillmukul975/Privacy-Data-Protection-Skills301—~3.7kAutomated safety check: PassApache-2.0
Cis ControlsSushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~4.2kAutomated safety check: PassMIT
Tos Clause Scannerzebbern/claude-code-guide4.7k1 repos~3.3kAutomated safety check: PassMIT
Healthcare Phi Complianceaffaan-m/ECC276k1 repos~1.4kAutomated safety check: PassMIT
Policy OpaAgentSecOps/SecOpsAgentKit2201 repos~3.5kAutomated safety check: PassCustom licence
Fondo Security Basicsjeremylongshore/tons-of-skills-marketplace2.8k—~1.2kAutomated safety check: PassMIT

Similar skills

  • Cis Controls

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert CIS Controls v8 (CIS Top 18) advisor — implementation group scoping (IG1/IG2/IG3), control gap assessments, safeguard-level guidance, asset inventory, software inventory, data protection…

    946 GitHub starsUsed in 1 repo~4.2k tokens
    Legal & ComplianceAuto-check passed
  • Tos Clause Scanner

    zebbern/claude-code-guide

    Audit Terms of Service, user agreements, and privacy policies for consumer risks, producing a structured report that flags unfair clauses, data traps, and liability issues.

    4.7k GitHub starsUsed in 1 repo~3.3k tokens
    Legal & ComplianceAuto-check passed
  • Protected Health Information (PHI) and PII compliance patterns for healthcare applications: data classification, row-level access control, tamper-proof audit trails, schema tagging, and common leak…

    276k GitHub starsUsed in 1 repo~1.4k tokens
    Legal & ComplianceAuto-check passed
  • Policy Opa

    AgentSecOps/SecOpsAgentKit

    Policy-as-code enforcement and compliance validation using Open Policy Agent (OPA).

    220 GitHub starsUsed in 1 repo~3.5k tokens
    Legal & ComplianceAuto-check passed
  • Fondo Security Basics

    jeremylongshore/tons-of-skills-marketplace

    Apply security best practices for Fondo including OAuth token management, financial data protection, SOC 2 compliance, and access control.

    2.8k GitHub stars~1.2k tokensUpdated today
    Backend & APIsAuto-check passed
  • C15t

    c15t/c15t

    Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.

    1.9k GitHub starsUsed in 1 repo~1.6k tokens
    Legal & ComplianceAuto-check passed

More from mukul975/Privacy-Data-Protection-Skills

All 280 skills in this repo
  • Age Gating Services

    mukul975/Privacy-Data-Protection-Skills

    Implements age-gating mechanisms for online services to restrict access based on user age.

    301 GitHub stars~3.7k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Data Retention

    mukul975/Privacy-Data-Protection-Skills

    Manages AI model retention and machine unlearning requirements.

    301 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Dpia

    mukul975/Privacy-Data-Protection-Skills

    Conducts Data Protection Impact Assessments for AI and ML systems per EDPB Guidelines 04/2025 on AI processing.

    301 GitHub stars~3.4k tokensUpdated 6 mo ago
    Auto-check passed
  • Dpia Mitigation Plan

    mukul975/Privacy-Data-Protection-Skills

    Structures risk mitigation planning and residual risk tracking for Data Protection Impact Assessments under GDPR Article 35(7)(d).

    301 GitHub stars~846 tokensUpdated 6 mo ago
    Auto-check passed
  • Gdpr Accountability

    mukul975/Privacy-Data-Protection-Skills

    Guides implementation of the GDPR accountability principle under Articles 5(2) and 24, including documentation requirements for policies, DPIAs, RoPA, training records, and breach logs.

    301 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • Pia Threshold Screening

    mukul975/Privacy-Data-Protection-Skills

    Conducts pre-DPIA threshold screening to determine whether a full Data Protection Impact Assessment is required under GDPR Article 35.

    301 GitHub stars~880 tokensUpdated 6 mo ago
    Auto-check passed

Questions about Background Check Privacy

What does Background Check Privacy do?

Manages privacy compliance for employee background checks including criminal record processing under Art. Background Check Privacy is an agent skill from mukul975/Privacy-Data-Protection-Skills. Manages privacy compliance for employee background checks including criminal record processing under Art.

When should I use Background Check Privacy?

Background Check Privacy fits situations like: tasks that involve Privacy and GDPR; tasks that involve Authorization and RBAC.

How do I install Background Check Privacy in Claude Code?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill background-check-privacy -a claude-code`. Or copy the skill folder (skills/privacy/background-check-privacy in mukul975/Privacy-Data-Protection-Skills) into .claude/skills/background-check-privacy in your project. Claude Code loads it when a task matches its description.

How do I install Background Check Privacy in Codex?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill background-check-privacy -a codex`. Or copy the skill folder (skills/privacy/background-check-privacy in mukul975/Privacy-Data-Protection-Skills) into .agents/skills/background-check-privacy in your project. Codex loads it when a task matches its description.

Can I use Background Check Privacy in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill background-check-privacy -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/background-check-privacy, .gemini/skills/background-check-privacy, .github/skills/background-check-privacy and .opencode/skills/background-check-privacy in your project.

What does Background Check Privacy need to run?

Going by SKILL.md and its folder, Background Check Privacy needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Background Check Privacy access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Background Check Privacy safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Background Check Privacy use?

Background Check Privacy is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Background Check Privacy use?

About 3.7k tokens (SKILL.md is roughly 15k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2k tokens, read only when the agent opens those files.

What are the alternatives to Background Check Privacy?

Skills that share tags, products or a category with Background Check Privacy: Cis Controls (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 946 stars), Tos Clause Scanner (zebbern/claude-code-guide, 4.7k stars), Healthcare Phi Compliance (affaan-m/ECC, 276k stars) and Policy Opa (AgentSecOps/SecOpsAgentKit, 220 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Background Check Privacy?

mukul975 (a GitHub user) maintains it in mukul975/Privacy-Data-Protection-Skills, which has 301 GitHub stars. The repository holds 280 skills in this directory. The repository was last updated on March 16, 2026.

Source: mukul975/Privacy-Data-Protection-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.