How Does GDPR Affect DBS Checks?

What Is GDPR?

GDPR stands for General Data Protection Regulation. It’s a set of laws that span the EU, and the UK uses them too. The regulations determine how long companies can keep individuals’ personal data, as well as what it can be used for.

How Does GDPR Affect DBS Checks?

How Does GDPR Affect DBS Check Certificates?

The information disclosed on DBS certificates remained the same following the introduction of DBS certificates. However, employer responsibilities relating to DBS certificates have been updated:

  • Employers shouldn’t keep the original DBS certificate – this belongs to the applicant.
  • It’s permitted to take a copy of your applicant’s DBS certificate, but you shouldn’t retain it any longer than necessary. This is often interpreted by employers as 6 months.
  • If a copy has been made, digitally or physically, it must be stored securely in a lockable/password-protected, non-portable container.

How Does GDPR Affect DBS Check Applications?

When GDPR was introduced in 2018, there was one major change to our online DBS application process here at Aaron’s Department. User information can now only be held for 3 months from the date the certificate is printed & posted. This is because GDPR prevents personal data from being held any longer than necessary. At Aaron’s Department, we interpret this as being 90 days.

Furthermore, Users’ personal data must be password-locked and secured by two-factor authentication. To implement this, we simply required Users to create an account that they can use to apply for checks from. This account holds and secures all their data behind an extra layer of password-protection.

How Does GDPR Affect DBS Checks?


You’d hope that even before GDPR came into effect, DBS Umbrella Bodies and employers were taking precautions to keep DBS data secure.

Since it came into effect, Umbrella Bodies have had to password-protect applicant data so only a limited number of relevant people can access it, and delete applicant data after a set period of time.

If you’re considering using Aaron’s Department for your staff DBS checks, but have queries about our data protection policies, you can find them by clicking here. Alternatively, feel free to drop us an email at – we’ll get right back to you.

Forward someone this article!

Further Reading

If you’ve found our article, “How Does GDPR Affect DBS Checks?” useful, these related posts might also be handy:

About The Author

How Does GDPR Affect DBS Checks?

Kellie Dawson

Kellie is our in-house legal expert when it comes to DBS checks. With a background in the legal sector, she has become a recognised authority in this area.

Notify of
Inline Feedbacks
View all comments