forumNew topic

New IT hire getting full server access — is a background check mandatory?

İİlker T***Member
Job title
Co-founder
Sector
Security services
Organization type
20-person company
Joined
Apr 2022
Message
73
#1

We are a 15-person software and cloud infrastructure company based in Germany. A new senior systems administrator (DevOps / Sysadmin) is joining our team. By nature of the role, this employee will have full access to core production servers, customer databases, and all root-level encryption keys.

One of our board partners argued that before handing over such critical privileges, we must run a comprehensive security screening on the candidate; otherwise, client data could be at risk. However, looking into the German legal framework, we realized things aren't quite that straightforward.

Is it legally possible to conduct an official background check for a sysadmin in the private sector? Under labor law and data protection regulations (DSGVO / BDSG), what checks can we legally require? Should this risk be managed strictly via a criminal record certificate, or through contracts and access architecture?

PPolat A***ExpertCommunity member
Joined
Apr 2024
Message
365
Most Helpful#2

Short answer: In Germany, official security vetting can only be conducted by legally authorized agencies in sectors directly tied to public safety, such as defense, intelligence, or critical infrastructure; a standard private sector company cannot request this. The security requirements for this position are addressed not via formal state vetting, but through a proportionate criminal record check, robust contracts, and technical access architecture.

First, the legal boundaries must be clearly established. Under the German Federal Data Protection Act (BDSG), the candidate's fundamental rights are safeguarded during recruitment. However, because the position involves direct access to highly sensitive data and financial systems, requesting a certificate of conduct (Führungszeugnis) is considered legally proportionate. Note that a copy of this document must not be stored permanently in the personnel file; it should merely be inspected and documented in a formal record of review.

The second step involves contractual safeguards. Going beyond a standard Non-Disclosure Agreement (NDA), explicit clauses covering unauthorized data leaks, trade secret protection, and contractual penalties should be built into the employment contract. The contract should clearly state that breaches will trigger both civil liability and criminal charges under the relevant statutes.

The most vital safeguard, however, is your technical architecture. No single employee should hold unchecked root access. Critical server sessions should be recorded using Privileged Access Management (PAM) solutions, dynamic one-time credentials should be enforced, and database exports must require a four-eyes principle (approval from at least two administrators). Trust should be placed in processes and architecture, not individuals.

PPerihanMember
Job title
Corporate communications
Organization type
regional distributor
Joined
Dec 2023
Message
118
#3

Under the German Federal Data Protection Act, employee data collection is bound by the principles of necessity and proportionality. Requesting a criminal record certificate is only valid to the extent the job duties justify it; irrelevant past offenses cannot serve as grounds to withhold employment. Having an employment law specialist document this procedure will prevent potential liability risks.

TTolga K***Member
Job title
IT manager
Sector
E-commerce
Organization type
a company within a holding
Joined
Jul 2024
Message
76
#4

Don't assign generic, shared root access. Hardware-token MFA must be mandatory at login, and all 'sudo' commands should stream in real time to a centralized, immutable log server. The engineer needs to know that every single command leaves an independent audit trail. That deterrent is far more effective than any background check.

İİlker K***Member
Job title
Information Security Specialist
Sector
Glass
Organization type
a company within a holding
Joined
Jul 2025
Message
185
#5

Don't hand over full permissions right off the bat tomorrow. The statutory probationary period (Probezeit) in Germany is the best tool for this kind of trust test. Roll out access rights gradually over the first six months; start with test and development environments, and make access to production systems conditional on pairing up with the team lead.

EEmine A***MemberCommunity member
Joined
Mar 2025
Message
1
#6

Do you have any specific commitments regarding staff vetting in your service level agreements (SLA) or data processing agreements (AVV) with clients? Corporate clients can sometimes require employees to hold certain security certifications or undergo annual security training.

PPolat E***Member
Job title
Technical service technician
Sector
Agriculture
Organization type
cooperative
Joined
Mar 2024
Message
273
#7

Ten years ago, out of similar concerns, we put such strict restrictions on a newly hired sysadmin that the guy quit in his second month; he said, 'if you don't trust me, why did you hire me?' And he was right. Instead of looking for security clearances, we now do extremely thorough reference checks during hiring. Speaking directly with their previous managers to ask about their integrity in crisis moments gives us way more insight than any background check on paper.

JJale D***Member
Job title
Front office accounting
Sector
Logistics
Organization type
boutique agency
Joined
Aug 2025
Message
8
#8

an official background check is a state thing anyway they won't let us run one. I mean we just ask for a clean criminal record plus we disabled root login completely on servers everyone logs in with their own account and uses sudo logs go straight to an external cloud.

Edit: asked below, I wrote the answer in the second message.

YYağmur P***MemberCommunity member
Joined
Jun 2025
Message
286
#9

To properly secure the infrastructure, implement these three steps: 1) Restrict direct access to production databases via VPN and IP whitelisting. 2) Enforce the four-eyes principle for critical configuration changes. 3) Set up a centralized identity provider so that all permissions can be revoked with a single click when an employee departs.

AAslı Y***Member
Job title
QA Tester
Sector
Advertising and promotion
Organization type
two-branch business
Joined
Jan 2024
Message
18
#10

Good call starting this thread.

OOkan U***Member
Job title
Data entry clerk
Sector
Retail
Organization type
workshop
Joined
Nov 2022
Message
84
#11

Let me share what happened to me; it might be useful. Security isn't absolute; it's about making attacks not worth the effort.

If you have questions, write them; I'll answer as best I can.

EEsinMember
Job title
Career counselor
Joined
Jun 2024
Message
94

Doki · Interface design · 2026

#12

Thanks for writing this, that's the right way. The real issue isn't the number, but what it's based on.

The real issue isn't the number, but what it's based on. If you post the result here, it will help others too.

YYasemin E***MemberCommunity member
Joined
Mar 2026
Message
2
#13

Let me speak from the other side; I'm on the supplier side. like the biggest time-waster for us was not knowing who had the final say.

Thats all sorry if I went on too long.

SSinan B***Expert
Job title
Product Manager
Sector
Media and publishing
Organization type
two-branch business
Joined
Apr 2025
Message
223
#14

Thanks for writing this, that's the right way. An untested backup is not a backup.

If I were you, I'd go this route.

GGökhan D***ExpertCommunity member
Joined
Jan 2023
Message
316
#15

Exactly, and not many people know this. Security isn't absolute; it's about making attacks not worth the effort.

AAli Ç***Expert
Job title
Logistics planning
Sector
Tourism
Organization type
workshop
Joined
Nov 2022
Message
188
#16

here's how it went for us.. then when making decisions write down the worst-case scenario too, not just the best.

if you get three different answers on a topiic the question was asked wrong.. and correct me if I'm wrong.

OOkan K***Member
Job title
Store associate
Sector
Healthcare services
Organization type
8-person team
Joined
Aug 2023
Message
5
#17

I'd appreciate it if you shared the outcome.

GGizem A***MemberCommunity member
Joined
Oct 2025
Message
341
#18

We've heard this a lot, but it never happened like that for us. If it's your first time, start small; scaling comes later.

If you have questions, write them; I'll answer as best I can.

TTarkanMember
Job title
Retail manager
Joined
Mar 2024
Message
104
#19

Let me summarize the topic, since several different answers were given. Most incidents start with a leaked password, not a vulnerability.

If it's your first time, start small; scaling comes later. Of course it varies if your situation is different.

RRecep A***Member
Job title
QA Tester
Sector
Retail
Organization type
a company within a holding
Joined
Jul 2025
Message
241
#20

I completely agree. The answer varies greatly by industry; there is no one-size-fits-all rule.

Reply