top of page

Reference calls : you doing it wrong

In today's global marketplace, the process of conducting reference checks for potential hires has become increasingly complex, necessitating a keen understanding of both legal requirements and cultural nuances.

This comprehensive guide delves into the intricacies of international reference checks, spotlighting the legal frameworks governing them in key jurisdictions, including France, Germany, Spain, Italy, and the UK.

Legal Frameworks Across Different Jurisdictions

European Union: Highlighting France, Germany, Spain, Italy, and the UK

  • France: French labor law, particularly the "Code du travail," stresses the importance of consent and the relevance of the information collected during reference checks. The National Commission on Informatics and Liberty (CNIL) provides guidelines on data protection, aligning with the General Data Protection Regulation (GDPR).

  • Germany: The Federal Data Protection Act (Bundesdatenschutzgesetz - BDSG) and GDPR dictate the need for explicit consent and transparency in reference checks. German law also peculiarly mandates that references should tend to be positive, reflecting the principle of "Tendenz zur Gute."

  • Spain: Reference checks are regulated under the Organic Law on Data Protection and Guarantee of Digital Rights (LOPDGDD), emphasizing consent, data minimization, and purpose limitation, in line with GDPR principles.

  • Italy: Italian privacy law, governed by the Personal Data Protection Code and GDPR, requires employers to obtain consent before conducting reference checks, ensuring the information is directly relevant to the job's requirements.

  • United Kingdom: The Data Protection Act 2018, in conjunction with GDPR, oversees the conduct of reference checks, necessitating transparency, fairness, and lawful processing of personal data, with the candidate’s consent as a foundational requirement.

Cultural Nuances and Compliance Strategies

The legal frameworks underscore the necessity of adapting reference check processes to comply with local laws and respect cultural expectations. Key strategies include:

  • Obtaining Informed Consent: Clearly explaining the purpose and scope of the reference check in accordance with local laws is essential across all jurisdictions.

  • Navigating Local Regulations: Employers must familiarize themselves with the specific legal and cultural context of each country to conduct reference checks appropriately.

  • Ensuring Privacy and Data Protection: Adhering to principles of data minimization and safeguarding collected information are critical for respecting candidates' privacy rights and aligning with global data protection standards.

Step by Step guide

Here's how organizations can align their reference checking process with the legal requirements in each of these jurisdictions:


  1. Obtain Written Consent: Secure explicit written consent from the candidate before initiating reference checks, specifying what information will be collected and how it will be used.

  2. Limit Scope of Inquiry: Ensure that the information requested is strictly relevant to the job position, in line with the principles set out by the CNIL and GDPR.

  3. Document Processes: Keep a record of the consent obtained and the information gathered during the reference check for accountability and compliance purposes.

  4. Provide Access to Information: Upon request, allow the candidate to access the information collected about them, as per their right under French law.


  1. Secure Explicit Consent: Obtain clear and explicit written consent from the candidate, outlining the nature of the reference checks to be conducted.

  2. Adhere to Positivity Principle: When providing references, ensure they are constructed positively or at least neutrally, adhering to the "Tendenz zur Gute" principle.

  3. Ensure Transparency: Be transparent with candidates about the reference checking process, including the types of information collected and their rights to access and rectify this information.

  4. Practice Data Minimization: Collect only the information that is necessary and directly relevant to the candidate’s job application, in compliance with the BDSG and GDPR.


  1. Inform and Obtain Consent: Clearly inform the candidate about the reference check process and obtain their explicit consent, detailing the specific purposes for which their personal data will be used.

  2. Follow GDPR Guidelines: Ensure that all reference checks adhere to the GDPR principles of data protection, including data minimization, accuracy, and limited storage.

  3. Respect Candidate's Rights: Allow candidates the right to access, rectify, and delete their personal data collected during the reference check process, as stipulated by the LOPDGDD.

  4. Document Compliance: Maintain records of consent and the procedures used in collecting and processing personal data for reference checks.


  1. Obtain Consent with Transparency: Before conducting reference checks, obtain the candidate’s consent through a clear and transparent process, explaining the purpose and scope of data collection.

  2. Limit Information Collection: Collect only information that is essential and directly relevant to the job role, adhering to the principles of the Personal Data Protection Code and GDPR.

  3. Protect Candidate Data: Implement appropriate security measures to protect the personal data collected during reference checks from unauthorized access or breaches.

  4. Facilitate Data Access: Ensure candidates have the right to access the personal data obtained about them and can request correction or deletion as per Italian data protection law.

United Kingdom

  1. Secure Consent: Obtain written consent from the candidate before starting the reference check process, making sure they are informed about the nature and purpose of the data collection.

  2. Conduct Fair Processing: Collect, use, and store data obtained through reference checks in a manner that is fair, transparent, and compliant with the Data Protection Act 2018 and GDPR.

  3. Ensure Accuracy: Take reasonable steps to ensure that the information collected is accurate and, where necessary, kept up to date.

  4. Respect Data Subject Rights: Recognize and respect the rights of candidates, including their right to access personal data and request its correction or deletion.


Successfully conducting international reference checks requires a delicate balance between legal compliance and cultural sensitivity. By understanding and respecting the unique legal landscapes and cultural norms of countries such as France, Germany, Spain, Italy, and the UK, employers can navigate the complexities of international reference checks, ensuring a process that is both respectful and effective. This approach not only safeguards the organization against legal pitfalls but also fosters a respectful and inclusive hiring process that values the rights and dignity of all candidates.

11 views0 comments

Recent Posts

See All

Implementing an employee referral program

Implementing an employee referral program can be a highly effective strategy for attracting top talent to your organization. It leverages the networks of your current employees, potentially reducing h


bottom of page