- Job title
- Co-founder
- Sector
- Security services
- Organization type
- 20-person company
- Joined
- Apr 2022
- Message
- 73
We are a 15-person software and cloud infrastructure company based in Germany. A new senior systems administrator (DevOps / Sysadmin) is joining our team. By nature of the role, this employee will have full access to core production servers, customer databases, and all root-level encryption keys.
One of our board partners argued that before handing over such critical privileges, we must run a comprehensive security screening on the candidate; otherwise, client data could be at risk. However, looking into the German legal framework, we realized things aren't quite that straightforward.
Is it legally possible to conduct an official background check for a sysadmin in the private sector? Under labor law and data protection regulations (DSGVO / BDSG), what checks can we legally require? Should this risk be managed strictly via a criminal record certificate, or through contracts and access architecture?