Summary
- Why employment screening legislation matters in 2026
- What's changed in UK employment screening?
- Right to work legislation
- Digital identity verification (IDVT) and the DVS Trust Framework
- DBS and criminal record legislation
- Data protection and UK GDPR: What's changed for screening
- Sector-specific screening requirements: 2026 update
- AI and automated screening emerging legislation
- What should employers do to stay compliant in 2026?
- How Access Screening helps you stay compliant
Why employment screening legislation matters in 2026
The case for thorough screening has never been stronger. Cifas recorded 444,993 fraud cases to the National Fraud Database in 2025, a 6% rise on 2024 and the highest total on record. Identity fraud made up over 242,000 of those cases, still the most common type despite falling slightly as criminals shift toward account takeover instead. Cifas members prevented £2.4 billion in fraud losses; the wider cost to the UK economy is estimated at £219 billion a year. On hiring fraud specifically, 30% of UK employees consider using fraudulent reference houses to fake credentials justifiable, and 19% say they, or someone they know, have used one to cover an employment gap.
None of that risk sits outside the hiring process. An unverified identity, a right to work check run through the wrong route, a lapsed criminal record check: each is a compliance gap and a safeguarding one. Illegal working penalties now reach £60,000 per worker for a repeat breach, and from October 2026 that liability can travel up the supply chain to businesses with no direct contract with the worker.
Legislation is also where fairness gets built in. The right to work code of practice and the DVS trust framework both carry explicit non-discrimination requirements. Get screening wrong and it's not just a regulatory risk, it's a route to a tribunal claim with no cap on compensation for race discrimination.
What's changed in UK employment screening?
| Year | Change | Impact |
| 2022 | Identity Document Validation Technology (IDVT) introduced for right to work and DBS checks | Digital identity verification permitted for the first time |
| 2024 | Civil penalties for illegal working increased to up to £60,000 per worker | Higher financial exposure for non-compliant employers |
| Dec 2025 | Data (Use and Access) Act 2025 Part 2 comes into force; DVS Trust Framework given statutory footing | Digital identity verification placed on a legal basis |
| Jan 2026 | Self-employed individuals gain access to Enhanced DBS checks from 21 January 2026 | Significant change for sole traders in regulated activity roles |
| Jun 2026 | New statutory right for individuals to complain directly to data controllers (DUAA s.103), in force 19 June 2026 | Employers must update privacy notices and complaints processes |
| Jun 2026 | DVS Trust Framework v1.0 published (9 June 2026) | New certification standard for digital identity providers |
| Sep 2026 | DVS Trust Framework v1.0 comes into effect; new certifications issued against v1.0 only | Gamma-certified providers follow a tailored uplift route |
| Sep 2026 | Regulated activity definition changes; supervision exemption for volunteers removed (Crime and Policing Act 2026) | Supervised volunteers working with children may now require Enhanced DBS with barred list check |
| Oct 2026 | Right to Work reforms take effect; expanded employer liability across supply chains | Wider definition of "employer"; extended civil penalty exposure |
| Ongoing | Home Office guidance updates | Compliance processes must be reviewed regularly |
Right to work legislation
What changed
The Border Security, Asylum and Immigration Act 2025 received Royal Assent on 2 December 2025. Section 48 amends the Immigration, Asylum and Nationality Act 2006 to extend right to work obligations well beyond traditional employment relationships. The Home Office published a draft Code of Practice on Preventing Illegal Working on 30 June 2026, due to come into force on 1 October 2026.
From 1 October 2026, the right to work regime applies to a broader range of working arrangements, including:
- Workers engaged under contracts, not just traditional employment contracts
- Individual subcontractors
- Online matching service providers that charge a fee or commission
The most significant change is the introduction of extended liability. Where the direct employer cannot be identified or fails to comply, civil penalty exposure can move through the contractual chain to other organisations in the supply chain. Penalties remain up to £60,000 per illegal worker, with criminal liability in cases of deliberate breach.
The extended provisions apply only to working arrangements that commence on or after 1 October 2026.
Who is affected
Any organisation that engages labour through supply chains, subcontracting arrangements, or online platforms needs to review its position. Organisations that have not historically regarded themselves as the "employer" for right to work purposes may fall within scope from October.
Genuinely self-employed individuals providing services directly to clients through their own independent businesses are excluded from the expanded scheme.
What employers should do
- Audit your current checking method against the October 2026 Code of Practice. Confirm you are using one of the three permitted routes consistently: manual document check, IDVT via a certified provider, or Home Office online service.
- Map your workforce models and supply chains to identify who falls within the expanded scheme.
- Review and update contracts with labour providers and subcontractors to include appropriate contractual controls, audit rights, and supplier oversight arrangements.
- Ensure your end-to-end audit trail is in place. The Home Office expects organisations to demonstrate that controls operate effectively in practice, not just on paper.
Sources: Lewis Silkin, Laura Devine Immigration, Fragomen, DLA Piper
Digital identity verification (IDVT) and the DVS Trust Framework
What changed
The Data (Use and Access) Act 2025 received Royal Assent on 19 June 2025. Part 2, which governs digital verification services, came into force on 1 December 2025, placing the existing Digital Identity and Attributes Trust Framework on a statutory footing for the first time. The framework was simultaneously renamed the UK Digital Verification Services (DVS) Trust Framework to align with the Act's terminology.
Version 1.0 of the DVS Trust Framework was published on 9 June 2026, accompanied by final supporting documents and supplementary codes for digital right to work, right to rent, and DBS identity checks. Version 1.0 comes into effect on 1 September 2026, subject to successful accreditation of Conformity Assessment Bodies (CABs) by the UK Accreditation Service (UKAS).
Starting September 2026, new certifications are issued against v1.0 only. Providers certified under the Beta (0.3) framework are already non-compliant, as Beta certifications expired on 31 March 2026. Providers certified under Gamma (0.4) have a tailored uplift route to v1.0 and can follow that path rather than restarting the certification process from scratch.
The framework covers organisational governance, information security, privacy and data protection, technical specifications, and user experience. Certified providers gain access to the UK CertifID trust mark, a government-endorsed signal that a service meets the framework's requirements.
What employers must do
- Confirm that your digital identity provider is certified under the Gamma (0.4) framework. Providers still on Beta (0.3) are already non-compliant and you should switch.
- Confirm your provider has a v1.0 uplift plan in place ahead of September 2026.
- Check that your provider appears on the Office for Digital Identities and Attributes (OfDIA) statutory register.
- For right to work digital checks, ensure your provider holds a current Right to Work Digital Verification Service Provider (RtW DVSP) registration.
- From October 2026, employers can outsource impersonation checks to approved RtW DVSPs using facial recognition technology, provided the provider is registered with OfDIA.
Sources: GOV.UK OfDIA Annual Report 2026, GOV.UK DVS Trust Framework collection, Enabling Digital Identity blog
DBS and criminal record legislation
Updated DBS identity document guidance (October 2025)
On 21 April 2025, the Disclosure and Barring Service announced updated guidance for manually checking identity documents. A six-month transition period ran until 29 October 2025, from which point the new guidance became the required standard.
Key changes include:
- A unified three-route process for all applicants, with no separate route for non-UK nationals
- Updated guidance on virtual identification where an in-person check is not possible
- Clearer guidance on how to view documents, with example scenarios
Responsible bodies and responsible organisations should ensure that their processes reflect the October 2025 guidance and that records are retained for 24 months.
Self-employed access to Enhanced DBS checks (January 2026)
From 21 January 2026, self-employed individuals and personal employees who are paid for their roles can apply for Enhanced and Enhanced with Barred List(s) DBS checks through a DBS-registered Umbrella Body, without needing an employer to submit the application.
Previously, only an employing organisation could become a Registered Body. Self-employed professionals working with children or vulnerable adults had no consistent lawful route to obtain the correct level of DBS check. From January 2026, that route exists.
Eligibility rules are unchanged. Enhanced checks remain restricted to roles that legally qualify under the Rehabilitation of Offenders Act 1974 (Exceptions) Order 1975. The application route has changed; the eligibility threshold has not.
What employers should do
- Update identity document verification processes to reflect the October 2025 DBS guidance.
- Ensure 24-month record retention for all DBS identity checks.
- If you engage self-employed individuals in regulated activity roles, check whether they now need to obtain their own Enhanced DBS via an Umbrella Body.
- If you manage supervised volunteers working with children, review roles against the September 2026 regulated activity definition change, as the supervision exemption is being removed entirely.
Sources: uCheck, bytestart.co.uk, Personnel Checks
Data protection and UK GDPR: What's changed for screening
The Data (Use and Access) Act 2025
The DUAA received Royal Assent on 19 June 2025 and amends the UK GDPR and the Data Protection Act 2018 without replacing either. Its requirements are being phased in throughout 2025 and 2026.
The most operationally significant change for employers running background screening is the new statutory right for individuals to complain directly to data controllers. From 19 June 2026, Section 103 of the DUAA (inserting Section 164A into the Data Protection Act 2018) gives candidates and employees the right to raise data protection complaints directly with the organisation processing their data, before escalating to the ICO.
Under Article 77 of UK GDPR, individuals could previously complain directly to the ICO. The DUAA removes that as a direct individual right. Individuals must now raise complaints with the organisation first, and can escalate to the ICO afterwards. The sequencing has changed; the right to reach the ICO has not.
Controllers must:
- Provide at least one accessible way for individuals to submit data protection complaints
- Acknowledge complaints within 30 days and respond without undue delay
- Update privacy notices to inform individuals of this new right
- Maintain documented complaints handling procedures with appropriate governance and audit mechanisms
Complaints can arise in relation to any alleged infringement of UK GDPR, including subject access requests, retention practices, transparency obligations, and the lawful basis relied upon for processing, all of which are directly relevant to background screening.
What this means for background screening
Screening processes handle sensitive personal data at scale. Every candidate whose data is processed has the right to complain directly to you from 19 June 2026. If your privacy notice does not reflect this, you are already non-compliant.
The DUAA also replaces Article 22's near-blanket prohibition on automated decision-making with a permitted-with-safeguards regime under Articles 22A to 22D. Where AI or automated tools are used in screening decisions, employers must now evidence transparency, contestability, and meaningful human involvement.
What employers should do
- Update your privacy notice to include the new data complaint right, in force from 19 June 2026.
- Implement a formal, documented complaints handling process before any candidate or employee raises a complaint.
- Review AI screening tools for special category data compliance. Processing health, biometric, or ethnic origin data without explicit consent is a significant compliance risk.
- Audit your data retention policies for screening records.
Sources: CMS Law, Mayer Brown, DLA Piper Privacy Matters
Sector-specific screening requirements: 2026 update
Financial services (FCA)
Financial services firms remain subject to the FCA's Senior Managers and Certification Regime (SM&CR), which requires regulatory reference checks and fitness and propriety assessments for certified and senior manager roles. The FCA and PRA published Phase 1 SM&CR reforms in April 2026 (PS26/6), with most changes effective from 24 April 2026 and further reporting and process changes applying from 10 July 2026. Firms should ensure their screening processes align with the updated framework, particularly for roles that fall within the certification regime.
Education
Schools, colleges, and other education providers must follow Keeping Children Safe in Education (KCSIE) statutory guidance, which requires Enhanced DBS checks with a barred list check for all staff working in regulated activity. The January 2026 self-employed DBS changes are relevant here. Private tutors and freelance education professionals can now obtain their own Enhanced DBS, which schools may wish to verify independently.
Healthcare
The Care Quality Commission (CQC) requires providers to carry out Enhanced DBS checks for all staff working with vulnerable adults and children. NHS organisations follow NHS Employment Check Standards, which include right to work verification, professional registration checks, and criminal record checks. The updated DBS identity guidance from October 2025 applies to all healthcare screening processes.
Security industry
The Security Industry Authority (SIA) requires a Standard DBS check as part of the licence application process for all security operatives. The SIA runs this check itself as part of the application, so operatives do not need to apply separately. A Standard check covers both spent and unspent convictions, cautions, reprimands, and warnings. Employers in the security sector must also comply with right to work requirements, which from October 2026 extend to subcontractors and labour supply chain arrangements. The expanded liability provisions are particularly relevant for security firms operating through complex staffing models.
AI and automated screening emerging legislation
AI-assisted screening tools are now embedded in many UK recruitment and background checking processes. The legal framework governing their use has tightened significantly in 2025 and 2026.
Equality Act 2010 considerations
The Equality Act 2010 does not specifically mention AI or automated decision-making. Liability arises from the effect of a decision, regardless of whether bias was intentional. If an AI screening tool puts candidates sharing a protected characteristic at a particular disadvantage, and the employer cannot objectively justify it, that is indirect discrimination under Section 19 of the Equality Act 2010.
The employer using the tool carries the liability. Buying the software from a vendor does not transfer the risk. The ICO reviewed evidence from more than 30 UK employers in early 2026 and found that most use AI to screen and score candidates in ways that constitute automated decision-making under UK data protection law, and most are not applying the required safeguards.
Home Office non-discriminatory outcomes requirement for DVS providers
The DVS Trust Framework v1.0 includes requirements for inclusive design. Certified providers must follow web accessibility standards, accept a wide range of evidence types, and submit annual inclusion monitoring reports. Employers using DVS-certified providers for right to work or DBS checks should confirm their provider meets these requirements, particularly where the workforce includes candidates who may not hold standard UK identity documents.
What employers should check when using automated screening software
Before deploying or continuing to use AI-assisted screening tools, employers should:
- Confirm the tool does not constitute solely automated decision-making under Articles 22A to 22D of the DUAA. Where it does, the required safeguards must be in place: transparency, contestability, and meaningful human involvement.
- Ask vendors for documented bias testing results covering protected characteristics under the Equality Act 2010.
- Verify how the tool handles special category data. Processing health, biometric, or ethnic origin data requires explicit documented consent.
- Ensure a meaningful human makes the actual hiring or screening decision.
- Document your governance arrangements so you can demonstrate compliance if challenged.
What should employers do to stay compliant in 2026?
The changes across right to work, digital identity, DBS, and data protection all require action before October 2026. Here is a practical checklist.
-
Right to work
Audit your current checking method against the October 2026 Code of Practice. Confirm you are using one of the three permitted routes consistently. Review labour supply chain arrangements in light of the expanded liability provisions and ensure an end-to-end audit trail is in place.
-
IDVT and DVS
Confirm your digital identity provider is certified under the Gamma (0.4) framework and has a v1.0 uplift plan in place ahead of September 2026. Providers still on Beta (0.3) are already non-compliant and you should switch. Check they appear on the OfDIA statutory register.
-
DBS
Update identity document verification processes to reflect the October 2025 guidance. Ensure 24-month record retention for all DBS checks.
-
Self-employed workers
If you engage self-employed individuals in regulated activity roles, check whether they now need to obtain their own Enhanced DBS via an Umbrella Body.
-
Volunteers
If you manage supervised volunteers working with children, review roles against the September 2026 regulated activity definition change. From 1 September 2026, the supervision exemption is removed. Volunteers who work with children frequently or overnight in a regulated activity setting will require an Enhanced DBS with Children's Barred List check, regardless of supervision arrangements.
-
Data protection
Update your privacy notice to include the new data complaint right, in force from 19 June 2026. Implement a formal complaints handling process. Review AI screening tools for special category data compliance.
-
Recruitment agencies
Review labour supply chain arrangements in light of the Section 48 expanded liability. Ensure contractual controls, audit rights, and supplier oversight arrangements are in place before any new engagements commence on or after 1 October 2026.
How Access Screening helps you stay compliant
Access Screening is built to reflect current UK legislation. As right to work routes, DBS identity guidance, and data protection requirements change, the platform updates to match, so your team is always checking against the right standard.
For more on the October 2026 right to work changes specifically, read our detailed guide: Right to Work Check changes 2026: What UK employers need to know.
AU & NZ
SG
MY
US
IE