Employee sanctions screening means checking employees against relevant sanctions lists. For many European companies, this creates an immediate conflict. Compliance wants to avoid paying a listed person, while HR, data protection and the works council want to know whether the check is lawful and proportionate.
The legal position sits between two extremes. GDPR does not ban employee screening, but EU sanctions law also does not contain one general rule telling every employer to screen every employee at a fixed interval. The need for the control comes from the asset-freeze rules, which prohibit companies from making funds or economic resources available to listed people.
Salary, bonuses and expense payments are clear examples. If an employee becomes listed, normal payments may no longer be allowed. Employee screening is one way to identify that risk before the next payroll, but the company still needs to explain why it screens, who is included and how possible matches are handled.
Why can an employee create sanctions risk?
EU asset-freeze rules apply even where the listed person is an employee. An employment contract does not remove the restriction. Salary is the clearest example, but bonuses, reimbursements and other financial benefits may also need to be stopped or reviewed if a match is confirmed.
Consider an employee who joined the company in 2019 and was not listed at the time. Several years later, the person is added to an EU sanctions list shortly before payroll. If the company only checked the employee when they were hired, it may not see the new listing before the next payment.
This is the gap employee screening is meant to close. EU law does not prescribe one standard process, but the company still needs a reasonable way to identify relevant listings before it provides more funds or resources.
Is employee sanctions screening legally required?
There is no general EU rule saying that every company must screen every employee against every sanctions list. The need for screening follows indirectly from the asset-freeze prohibition. If a company is not allowed to pay a listed person, it needs a reliable way to find out whether somebody it pays has become listed.
For companies with Authorised Economic Operators (AEO) security status, the position is more specific. The EU guidelines for AEO status refer to checks on people working in security-sensitive roles. A German court confirmed in 2012 that customs could require an AEO applicant to check employees in those roles against the EU anti-terrorism lists.
That decision supports screening in the AEO context, but it does not create one universal rule for every employee and every company. Companies should therefore separate the general asset-freeze risk from the more specific AEO expectations for security-sensitive roles.
Does GDPR allow employee sanctions screening?
GDPR does not automatically prevent employee screening, but the company needs a valid legal basis for using the data. Some companies rely on Article 6(1)(c) GDPR, which covers processing needed to meet a legal obligation. Others rely on Article 6(1)(f), which allows processing for a legitimate interest where the company can show that the check is necessary and fair.
There is no single approach used in every EU country. The correct basis can depend on national law, the sanctions lists used, the employees included and the design of the process. The company should document this before screening begins.
The choice of list is especially important. Screening employees against EU asset-freeze lists is easier to connect to an EU compliance purpose than screening every European employee against all US or foreign watch lists available in a database. A group policy is not enough on its own. Each European company still needs to explain why a list is relevant and why the processing is necessary.
How should the screening process be designed?
The process should start with a clear written scope. The company should define who is screened, which lists are used, which data is compared, who can see a match and when unnecessary data is deleted.
The company should use as little personal data as possible. In many cases, the first comparison only needs the employee’s name. Additional information, such as date of birth, nationality or address, should be used only to resolve a possible match. The full personnel file should not be copied into the screening system.
Access must also be limited. A possible sanctions match can affect a person’s employment and reputation, even when the match later proves false. The information should only be visible to the people who need to investigate the case, provide legal advice or take action.
Employees should receive clear information about the process, including its purpose, legal basis, list types and retention period. Larger or regular screening programmes should also consider whether a data protection impact assessment is needed.
Does the works council need to agree?
This depends on national law and on how the screening process works. In Germany, the Federal Labour Court decided that a specific automated name comparison against the EU anti-terrorism lists did not create a co-determination right under the rule covering systems used to monitor employee behaviour or performance.
The decision was narrow because the system only compared names. Other participation rights may still apply, especially if the system uses more data or connects to employment decisions. The procedure should therefore be clearly documented.
Who should be screened, and how often?
There is no single answer for every company. If the purpose is to prevent salary payments to a listed person, the company may decide that employees receiving payments should be included. For AEO security requirements, the focus is narrower and normally covers people working in security-sensitive positions.
Temporary workers, freelancers or contractors may also need to be considered. Applicants need more care because they usually receive no salary or access at the start of recruitment. Screening later, for example before an offer, may be easier to justify.
EU sanctions law does not set one standard screening frequency. An employee may screen clean in January and be listed in February, which means an annual check could leave the company making payments for months without seeing the change. A delta check against new and changed list entries can reduce unnecessary processing while still finding new risks before the next payroll.
What happens when there is a match?
A screening alert does not prove that the employee is listed. Most alerts are caused by similar names, so the analyst must compare the employee’s details with the sanctions entry. This can include names, aliases, date of birth, nationality, address and identification details.
The investigation should remain confidential. A possible match should not be treated as misconduct or shared with people who do not need to know. If the details do not match, the alert can be cleared as a false positive, but the case note should show what was compared and why.
If the details appear to match, the situation becomes urgent. Payments, benefits or access may need to be stopped while the company gets legal advice and contacts the relevant authority. It may also need to check whether an authorisation or exception is available.
The company should not move directly from an alert to dismissal. The first questions are sanctions questions: is this the listed person, which rule applies, which payments or resources are affected and which authority needs to be contacted? The employment-law questions come afterwards.
What should the company document?
The company needs two types of record. The first proves that screening took place and should show the date, employee group, list version, reason for the check and overall result.
The second explains how each alert was decided. For a false positive, it should show the listed candidate, employee details compared, sources used, reasoning, decision, reviewer and date. For a confirmed or unresolved match, it should also show the escalation, legal advice, contact with authorities and any action taken.
“Screened, no hit” is not enough if the company cannot show when the screening happened or which list was used. “Reviewed and cleared” is not enough if the company cannot explain why the alert did not relate to the employee.
The company should keep enough information to prove the process worked, without keeping unnecessary screenshots or no-match results forever. The retention and deletion rules should be written down, and the process should appear in the company’s GDPR record of processing activities.
What does a defensible process look like?
A defensible process begins with a written plan. The company explains why screening is needed, who is included, which lists are relevant, which GDPR basis it uses and when the checks take place. It then limits the data, restricts access and gives analysts a clear process for handling possible matches.
The company also keeps proof that screening took place and proof of how each alert was resolved. That allows customs, auditors, data protection teams and employee representatives to understand what the company did and why.
The asset freeze explains why employee screening may be needed. GDPR and employment law decide how the company should run it. Whether the process holds up depends on what the company can show.
☰