Privacy Policy
Global Checks Privacy Policy
We believe you should know exactly what happens with your personal data. This policy explains it in clear, simple language - no legal jargon, no surprises.
Version 2.0 | Effective: 28 July 2026
Global Checks is committed to protecting your privacy. This Privacy Policy explains - in simple, clear language - exactly what personal data we collect, why we collect it, how we use it, who we share it with, and what rights you have over it.
This Policy applies to all individuals whose personal data we process, including job candidates, employees of our client organisations, and visitors to our website.
We are a background verification services company. Our clients are employers and organisations who ask us to verify the credentials and backgrounds of their prospective or existing employees. This means your personal data may come to us through your employer as well as directly from you.
In connection with our own website, portals, and direct client relationship management, Global Checks acts as a Data Fiduciary. In connection with our BGV services, Global Checks acts as a Data Processor processing personal data of candidates on behalf of our client organisations (who are the Data Fiduciaries under DPDPA 2023).
For privacy-related complaints and requests, please contact our Grievance Officer (Clause 16).
To make this Policy easy to understand, here is a plain-language explanation of the key terms we use:
| You / Data Principal | The individual whose personal data is being collected and processed - in most cases, a job candidate or an employee of one of our client companies. |
|---|---|
| Data Fiduciary | Any person or entity that determines the purpose and means of processing personal data. |
| Data Processor | Any person who processes personal data on behalf of a Data Fiduciary. |
| Personal Data | Any information that identifies you or can be used to identify you - such as your name, phone number, employment history, or government ID. |
| Processing | Anything we do with your data - collecting, storing, using, sharing, or deleting it. |
| Consent | Your free, clear, and informed agreement to us processing your personal data for a specific purpose. You can always withdraw your consent - see Clause 13. |
| Data Breach | An incident where your personal data is accidentally or unlawfully accessed, disclosed, altered, or lost. |
| Data Protection Board | The Data Protection Board of India - the government authority that handles complaints and enforces the DPDP Act. |
| Consent Manager | A registered platform through which you can give, manage, or withdraw your consent to data processing under the DPDP Act. |
Data Minimisation Principle
We only collect the data that is necessary for the specific background check commissioned by your employer. We never collect data beyond what is needed. Here is what we may collect depending on the type of verification:
| Category | Examples | When Collected |
|---|---|---|
| Identity & Contact | Full name, date of birth, gender, mobile number, email, address | All verifications |
| Employment Details | Past employers, job titles, dates, designation, references | Employment checks |
| Educational Records | Degrees, certifications, roll numbers, institution details | Education checks |
| Identity Documents | Aadhaar, PAN, Passport, Driving Licence, Voter ID | Identity verification |
| Legal & Court Records | Criminal history, court judgments, litigation records | Criminal background checks |
| Financial Information | Credit history | Only with your explicit consent, for specific roles |
| Social & Public Records | Publicly available social profiles and public records | Social media checks (when relevant) |
| Communication Preferences | Marketing preferences, opt-in/out records | When you interact with us |
Where We Get Your Data From
We collect your data from:
- Directly from you - when you submit information for a background check.
- Your employer or prospective employer - our client who has engaged us for the verification.
- Public sources - government databases, court records, publicly available information lawfully accessible.
- Third-party verification partners - credentialing agencies and reference databases.
Purpose Limitation
We only use your personal data for the specific purposes described at the time of collection. We will never use your data for an unrelated purpose without telling you first and, where required, getting your consent again.
- Running background checks - verifying employment, education, identity, and other credentials on behalf of employer-clients.
- Legal compliance - meeting our obligations under applicable laws, court orders, and regulatory directions.
- Reporting to employers - sharing verified information with the authorised employer or client that requested the check.
- Improving our services - making our verification processes faster and more accurate.
- Fraud prevention - ensuring the integrity and accuracy of the verifications we conduct.
- Record-keeping - maintaining audit trails and processing records as required by law.
- Marketing - marketing communications relating to our services are sent only where legally permitted or with your consent.
We only process your personal data when we have a valid legal reason to do so. These reasons are:
Your Consent (Section 6)
When you agree, clearly and freely, to let us process your data for a specific purpose. You can withdraw your consent at any time. Withdrawal will not affect anything we lawfully did before you withdrew. To withdraw, contact our Grievance Officer or use the Consent Manager, if applicable.
Legitimate Uses - No Consent Needed (Section 7)
In some situations, the DPDP Act allows us to process your data without consent. These are called "Legitimate Uses":
- Background verification for employment: When you have voluntarily provided data for a job application, or when your employer is legally authorised to commission a background check.
- Compliance with law: When a court order, statute, or regulatory authority requires us to process or share your data.
- Public interest & national security: When directed by a competent authority for purposes of national security or public order.
- Medical emergency: To protect your life or the life of another person in an emergency.
Contractual Necessity
Where necessary to provide our background verification services, we process personal data in accordance with the contractual arrangements between us and your employer or prospective employer, who has engaged us to conduct the background verification. Such processing is carried out only to the extent permitted under applicable law.
Storage Limitation
We keep your data only for as long as is necessary for the purpose it was collected, or as required by law. Once no longer needed, your data is securely deleted.
Deletion upon request: If you make a valid request for erasure (see Clause 13), we will delete your data within 30 days, unless we are legally required to keep it.
Security Safeguards
We take the security of your personal data seriously. We implement technical and organisational measures that are appropriate to the nature and sensitivity of the data we hold:
- Encryption: All personal data is encrypted at rest and in transit using industry-standard protocols (AES-256 / TLS 1.2+).
- Access Controls: Only authorised staff who need your data to do their job can access it - on a strict need-to-know basis.
- Regular Audits: We regularly review our security practices and maintain compliance with ISO 27001 standards.
- Data Processor Contracts: All third parties who process data on our behalf are contractually required to maintain the same level of security and to follow our instructions.
- Breach Response: We have an incident response plan to detect, contain, and report any data breach - see Clause 15.
Our technology infrastructure includes the following controls to keep your data safe: we use secure cloud infrastructure with physical and logical security controls. All cloud services we use are bound by contractual security obligations.
We share your personal data only when necessary, and only with the following categories of recipients:
- Verification Partners (Data Processors): Credentialing agencies, reference databases, and background check providers who assist us. Each is bound by a written agreement requiring them to process your data only on our instructions and to maintain equivalent security standards.
- Your Employer / Prospective Employer (our Client): The verified report is shared with the specific employer who commissioned the check, only to the extent necessary for the employment decision.
- Legal & Regulatory Authorities: We may share data when required by a court order, statute, or direction from a government authority. Where legally permitted, we will tell you about such disclosures.
- Consent Managers: If you manage your consents through a registered Consent Manager under the DPDP Act, we will honour instructions received from that platform.
We are an Indian company and primarily process data within India. If we ever transfer your personal data outside India, we will only do so to countries approved by the Central Government of India under Section 16 of the DPDP Act, and subject to any restrictions or conditions notified under applicable law.
Our website uses cookies - small text files stored on your device to improve your browsing experience. Here is what we use:
- Essential Cookies: These are required for the website to work. You cannot opt out of these, as without them the site will not function.
- Performance & Analytics Cookies: These help us understand how visitors use our website, so we can improve it. These are only used with your explicit consent.
Your choice: You can accept or reject non-essential cookies through our cookie consent banner when you first visit our website, or any time through your browser settings. Withdrawing cookie consent will not affect anything we did before you withdrew.
As a Data Principal, you have the following rights over your personal data. To exercise any of these rights, contact our Grievance Officer (Clause 16). We will acknowledge your request within 48 hours and respond within 30 days.
Right to Access
Request a summary of the personal data we hold about you and how it is being processed.
Right to Correction & Updating
Ask us to correct inaccurate or incomplete personal data, or update it where it has changed.
Right to Erasure
Request deletion of your personal data once it is no longer needed for the purpose it was collected.
Right to Grievance Redressal
Raise a complaint with our Grievance Officer about how your data has been handled.
Right to Nominate
Nominate another individual to exercise your rights on your behalf in the event of death or incapacity.
Our background verification services are designed for adults only. We do not knowingly collect personal data from anyone under the age of 18. If we discover that a child's data has been provided to us:
- We will obtain verifiable consent from a parent or legal guardian before processing any data.
- We will not track or monitor children's online behaviour or activities.
- We will not target advertising at children.
- We will not process data in any way that could harm a child's well-being.
- We will delete the data promptly if parental/guardian consent cannot be obtained.
Despite our strong security measures, no system is completely immune to breaches. If a data breach occurs that is likely to affect your rights or interests, here is what we will do:
- Notify the Data Protection Board of India as soon as possible after discovering a breach, in the manner prescribed under the DPDP Act & Rules.
- Notify You Directly - we will tell you what happened, what data was affected, the likely impact, and the steps we are taking to fix it and prevent it from happening again.
- Contain and Investigate - we will immediately work to contain the breach, limit any harm, and investigate the root cause.
- Remediate and Record - we will fix the issue, implement preventive measures, and maintain a record of the breach and our response for regulatory review.
Under the DPDP Act, we are required to appoint a Grievance Officer - a dedicated point of contact for all privacy-related concerns. If you want to exercise any of your rights, raise a complaint, or have any question about this Policy, please reach out to our Grievance Officer:
Acknowledgement
We will acknowledge your complaint or request within 48 hours of receiving it.
Resolution
We will resolve your complaint within 30 days of receipt. In complex cases, we may take up to 45 days and will notify you in writing with the reason for the extension.
Escalation to the Data Protection Board
If you are not satisfied with our response, you can file a complaint with the Data Protection Board of India under the DPDP Act. Visit www.dpb.gov.in (to be updated when the Board is operational).
We may update this Privacy Policy from time to time - to keep up with changes in the law, our business, or our data practices. Here is how we will let you know:
- On our website: A clear notice will appear on our website when we update this Policy.
- By email: We will send you an email notification if we have your contact details.
- Fresh consent: If an update requires us to use your data in a new way that requires fresh consent under the DPDP Act, we will ask for it before making that change.
Continued use of our services after an update takes effect means you accept the revised Policy, except where the law requires us to get fresh consent from you.
For general enquiries about our services or this Privacy Policy, please reach out to us at:
Privacy Concerns: Contact Grievance Officer → Clause 16
If you have a complaint about how we have handled your personal data, here is the process to follow:
- Talk to Our Grievance Officer: Start by contacting our Grievance Officer (Clause 16). Most issues can be resolved quickly at this stage within 30 days.
- Data Protection Board of India: If not resolved, you may file a complaint with the Data Protection Board of India under the DPDP Act, 2023. The Board's order is binding and can be appealed to the Appellate Tribunal.
- Mediation / Arbitration: For commercial disputes between us and our employer-clients (not Data Principal complaints), disputes may be resolved through mediation or arbitration as per the services agreement.
- Courts of Law: Subject to the DPDP Act, disputes may be referred to courts of competent jurisdiction at Gurugram, Haryana - India.
Governing Law: This Privacy Policy is governed by the laws of the Republic of India, including the DPDP Act, 2023, the IT Act, 2000, and all applicable rules framed thereunder.