Reference checking involves processing personal data about both the candidate and the referee. That means GDPR and the Norwegian Personal Data Act apply in full. Here's what you need to do to stay on the right side of the law in Norway in 2026.
What is a lawful basis?
To process personal data you need a lawful basis under GDPR Article 6. For reference checks the most relevant ones are:
- Consent (art. 6(1)(a)) — the candidate explicitly consents.
- Legitimate interest (art. 6(1)(f)) — you have a justified interest in verifying the candidate's suitability, and the candidate can reasonably expect it.
Datatilsynet (the Norwegian DPA) recommends consent as the default for reference checks because it is the clearest and easiest basis to document.
Consent from candidate and referee
The candidate must consent to you contacting specific named referees. A generic "we may contact references" is not enough. The consent must be:
- Voluntary — the candidate cannot be punished for withdrawing it.
- Informed — it must be clear what, why, for how long and by whom.
- Specific — it covers this role and these referees.
- Documented — written form is strongly recommended.
The referee must also be informed when contacted — they have the same rights as the candidate under GDPR.
The duty to inform (art. 13/14)
Both the candidate and the referee must be told:
- Who the data controller is (your company).
- The purpose of the processing.
- The lawful basis.
- How long the data will be stored.
- Their rights (access, rectification, erasure, complaint to Datatilsynet).
- Whether data is transferred to third parties or outside the EEA.
Storage and retention
The general rule is that personal data should not be stored longer than necessary. Practical guidance:
- Hired candidate: References can be kept in the personnel file for the duration of employment plus a reasonable period after.
- Not hired: Delete within 6-12 months of closing the role, unless the candidate consents to longer storage (talent pool).
- Data must be stored securely — encrypted and with access controls.
The data subject's rights
Both candidate and referee have the right to:
- Access what is stored about them.
- Rectification of inaccurate information.
- Erasure (with certain exceptions).
- Restriction of processing.
- Complaint to Datatilsynet.
You must respond to such requests within 30 days. That requires you to have a systematic overview of what is stored.
Deletion and data minimisation
Only collect what you actually need. If the role doesn't require an assessment of leadership skills, don't ask. After the retention period the data must be deleted actively — not just moved to an archive.
How tools like Referansio make it easier
One of the biggest GDPR challenges with manual reference checking is the documentation trail — who consented to what, and when? A digital tool gives you automatically:
- Time-stamped consent from candidate and referee.
- Encrypted storage of database and email in the EU (Frankfurt). AI voice calls are processed via a sub-processor in the US under SCCs — always disclosed in advance.
- Built-in retention period with automatic anonymisation after 12 months of inactivity.
- Data Processing Agreement (DPA) available on request (referansio@webviking.no).
- Audit log of who has seen which data.
Read more about our security, DPA and privacy policy.



