Qoyod
Pricing
Qoyod
Pricing

Cybervetting

Term in Qoyod's Business Glossary. Practical definition with examples from the Saudi market.

What cybervetting is

Cybervetting, also called social media screening or a social media background check, is the practice in which an organisation gathers what is published online about a job applicant (their public accounts, what they have written and what they appear in) and bases part of its hiring decision on it.

It differs from verifying a candidate’s credentials in one essential respect: the source of the information. Verification goes back to the body that issued a document in order to confirm what the candidate has stated. Cybervetting gathers, from a third party, information the candidate never stated and was never asked about. That difference is what moves the question out of recruitment practice and into the protection of personal data.

Why cybervetting falls within the Personal Data Protection Law

Article 2(1) of the Personal Data Protection Law (نظام حماية البيانات الشخصية), issued by Royal Decree M/19 of 9/2/1443H and amended by Royal Decree M/148 of 5/9/1444H, applies the law to any processing of personal data relating to individuals that takes place in the Kingdom, by any means. The only carve out, in Article 2(2) of the same law, is an individual processing personal data for purposes that do not go beyond personal or family use, and an organisation screening a candidate is not within it.

Article 1(5) of the Personal Data Protection Law counts collection, recording, storage, retrieval, use, disclosure and sharing as processing. Opening an account, reading it and noting what it contains in the candidate’s file is therefore processing under the definition itself, not an activity outside the law. The same scope reaches a candidate’s score on a cognitive ability test, and it does not depend on whether an employment relationship exists. In this position the organisation is the controller (جهة التحكم) under Article 1(18) of that law.

Cybervetting and Article 10: collection directly from the data subject

The provision closest to the practice is Article 10 of the Personal Data Protection Law. It provides that a controller may collect personal data only directly from the data subject, and may process that data only to achieve the purpose for which it was collected.

Cybervetting is collection from someone other than the data subject, so it falls where that rule applies. Article 10 of the same law then sets out seven situations in which a controller may collect personal data from someone other than the data subject, among them the data subject’s consent and personal data that is publicly available or was collected from a publicly available source, and it leaves the provisions and controls for the situations other than consent to the Implementing Regulations (اللائحة التنفيذية). So we do not conclude that the practice is prohibited, and we do not conclude that it is permitted in a particular case. What we do state is that the starting rule is direct collection, and that an organisation departing from it needs to know which of those situations it is relying on. An organisation that screens and cannot name its basis has not answered the question; it has simply not asked it.

A related point concerns content posted publicly. Publicly available personal data is one of the situations listed in Article 10 of the Personal Data Protection Law, but that does not settle the matter. Article 15 of the Implementing Regulations of the Personal Data Protection Law requires a controller processing personal data collected from someone other than the data subject to ensure that the processing is necessary and proportionate to the specified purpose and does not affect the data subject’s rights and interests, and, where it relies on publicly available data, that the collection from that source was itself lawful. Whether a particular open account meets those conditions is not something the definition of cybervetting settles.

Further rules that apply to cybervetting

  • A purpose connected to the controller. Article 11(1) of the Personal Data Protection Law requires the purpose of collection to relate directly to the controller’s purposes and not to conflict with any provision established in law. The legitimate purpose here is assessing suitability for the job, and anything gathered for another reason finds no basis in that paragraph.
  • The minimum necessary. Article 11(3) of the Personal Data Protection Law requires the content of personal data to be adequate and confined to the minimum necessary to achieve the purpose of its collection. Screening online runs against this by its nature: a person who opens an account does not see only what concerns the job, but sees everything at once. The limit therefore falls on what is kept and relied on, not on what passes before the eye.
  • Accuracy of what is processed. Article 14 of the Personal Data Protection Law bars a controller from processing personal data without taking sufficient steps to verify that it is accurate, complete, up to date and relevant to the purpose for which it was collected. Cybervetting can fall short here in three ways: through a post that is old, one cut off from its context, or one that belongs to someone else with the same name. A post on which a manager builds an impression does not meet the accuracy condition unless it has been checked, and checking it means going back to the person concerned.

Article 11(4) of the same law adds a duty to stop collecting, and to destroy what has been collected without delay, once it is no longer necessary for the purpose. A file that keeps screenshots from the accounts of a candidate who was not hired is a file with no continuing purpose.

Where sensitive data sits in cybervetting

Cybervetting touches a particular class of data, and that is a consideration to be named rather than built upon. Article 1(11) of the Personal Data Protection Law classifies a category of personal data as sensitive, including data indicating religious or intellectual belief, ethnic origin, and health and biometric data. A personal social media account can reveal these categories without anyone intending it: a photograph from an occasion, an opinion in writing, a mention of an illness.

The practice therefore exposes the person screening to categories the law classifies as sensitive, even where nobody asked for them. The law attaches further duties to processing this category, and we have not reviewed what those duties are, so we neither list them nor infer them. What follows in practice is that these categories are recognised for what they are, rather than handled like everything else that appears on the screen.

Consent raises a similar question. Except in the cases the law provides for, Article 5 of the Personal Data Protection Law requires consent to process personal data, or to change the purpose of processing, and makes it withdrawable at any time. Whether a candidate’s consent is a sufficient basis in a particular case is not something the definition of cybervetting settles.

Cybervetting and the quality of the hiring decision

Even if everything above were satisfied, a problem would remain in the quality of the decision rather than in its lawfulness. What appears on a personal account is fertile material for the patterns of error that undermine assessment: the halo effect, in which a single snapshot colours the reading of the whole profile, and implicit bias, in which similarity of background or interests does its work without the assessor noticing.

That makes cybervetting an input that cannot be calibrated: there is no scale on which a particular post can be said to equal a given degree of fit. In that respect it is the opposite of the structured interview, which puts the same questions to every candidate and scores the answers against a written standard. An organisation that has built its process on structured interviews and then adds cybervetting without any control has introduced into a calibrated process an input that cannot be calibrated. The definition of cybervetting also does not settle what follows from a particular decision, such as rejecting a candidate on the strength of what the screening found.

A worked example of cybervetting at scale

Take a single vacancy with 200 applicants, of whom the 40 who reached the second stage are screened online. If two or three screenshots are kept for each of them, the organisation’s files now hold between 80 and 120 items, around 100, gathered from people other than the data subjects, about people of whom 39 will not be hired.

The people concerned do not know these items exist, so they cannot correct any error in them, and once the vacancy is closed no continuing purpose attaches to them. The rules set out above all bear on them at once: collection from someone other than the data subject, going beyond the minimum, and retention after the purpose has ended. An organisation hiring twenty times a year would accumulate material of this kind that it never decided to accumulate. The issue is therefore not the single case, but that the practice produces an archive nobody decided to create.

What cybervetting is not

  • A background check. Such a check verifies facts that can be proved and that were issued by a body answerable for them: a certificate was issued or it was not, a period of employment happened or it did not. Cybervetting gathers impressions from content its author published for a different purpose.
  • Reviewing a professional profile the candidate published. Such a profile was put up by the candidate themselves, to be read in a hiring context, and looking at it is different from following their personal accounts. The first uses the content for the purpose it was published for; the second moves it to another purpose.
  • Employee data privacy. That concerns the data of people already in employment, such as what an employee file holds. Cybervetting concerns a candidate who may never become an employee, which is why the question of destruction once the purpose ends presses harder here.
  • A bring your own device policy. Such a policy governs an employee’s device at work. Cybervetting concerns how an organisation looks at a candidate’s life outside work.

The provisions relied on are those of the Personal Data Protection Law as published by the Saudi Data and Artificial Intelligence Authority (الهيئة السعودية للبيانات والذكاء الاصطناعي): Article 1(5) (what counts as processing), Article 1(11) (sensitive data), Article 1(18) (the controller), Articles 2(1) and 2(2) (scope and the personal use carve out), Article 5 (consent and its withdrawal), Article 10 (direct collection, purpose and the situations in which collection from another source is allowed), Articles 11(1), 11(3) and 11(4) (purpose, the minimum necessary and destruction once no longer necessary) and Article 14 (verifying accuracy before processing), together with Article 15 of the Implementing Regulations of the Personal Data Protection Law (collection from someone other than the data subject).

Before cybervetting begins: the questions to settle

The first practical question is not whether to screen, but what exactly the organisation is looking for, and why it matters for this particular job. A written answer to that question addresses several of the points above at once: it fixes the purpose, narrows what is kept to what serves it, and makes whatever goes into the file something that can be shown to the person it concerns. An unwritten answer means that what enters the file is whatever caught the eye of whoever opened the screen, a standard that changes with the person and with the day.

A second question can be overlooked: who screens, and when? Screening carried out before the interview by the person who makes the decision can colour the whole interview, while screening carried out by someone else after the calibrated assessment is complete comes in at a point where it does not distort what went before. Choosing between the two arrangements costs nothing, and it bears directly on the quality of the decision. What remains is to tell the candidate, because what is not disclosed to a candidate is exactly what they cannot correct if it is wrong.

This is an explanation of the concept and of the statutory provisions cited, not legal advice.

Qoyod HR

A standalone Saudi HR system

One employee file holding the contract, the documents and their expiry dates, the attendance record, leave, salary and end-of-service entitlements. End-of-service, overtime and leave-balance calculations are built into the system.

Explore Qoyod HR

A standalone system on its own subscription. The connection to Qoyod Accounting is now available.

Related terms

Ready to apply accounting the right way?

Qoyod runs your accounting with precision and full ZATCA compliance

Try Qoyod free for 14 days — No credit card required.