Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The policy authorizes ADP to process criminal records data and data relating to criminal behavior or proceedings for due diligence, security, and compliance purposes.
This analysis describes what ADP's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision authorizes processing of criminal records data — classified as a special category under GDPR — for due diligence and security purposes, which may engage fair credit reporting and background check statutes in the United States depending on the context and method of collection.
Interpretive note: Whether ADP's criminal records processing constitutes a consumer report under FCRA, and the applicable legal basis under GDPR Article 10, depends on the specific processing context and applicable national law, which are not detailed in this document.
ADP deleted the cookie preference management tool that previously allowed users to understand and control which cookies were placed on their devices, including functional, analytics, and advertising cookies. The removal eliminates the transparency mechanism through which users could consent to or opt out of different cookie categories. The practical effect depends on whether ADP has replaced this functionality elsewhere or whether cookies continue to be placed without equivalent granular user control.
View change record →Under this clause, ADP may process information about an individual's criminal history or related proceedings for business due diligence and security purposes. Individuals whose criminal records data is processed for purposes beyond those listed are entitled to prior explicit consent under the policy terms.
Cross-platform context
See how other platforms handle Criminal Records Data Processing and similar clauses.
Compare across platforms →Monitoring
ADP has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
"Criminal data (including data relating to criminal behavior, criminal records, or proceedings regarding criminal or unlawful behavior). ADP may Process criminal data as needed to conduct appropriate due diligence on Individuals and in connection with security and compliance activities as needed to protect the interests of ADP.Excerpt from ADP's Privacy Statement
REGULATORY LANDSCAPE: This provision engages GDPR Article 10, which restricts processing of criminal conviction data to official authority control or specific national law authorization. In the United States, the Fair Credit Reporting Act (FCRA) governs the use of consumer reports including criminal records in employment and business contexts and requires specific disclosures and permissible purposes. State-level ban-the-box and fair chance laws may further restrict criminal records use in employment-adjacent contexts. The FTC enforces FCRA compliance. GOVERNANCE EXPOSURE: Medium. The policy's authorization is tied to due diligence and security purposes, which align with recognized permissible use categories. However, the breadth of 'due diligence on Individuals' without further specification of the legal basis or procedural safeguards may require additional documentation to demonstrate GDPR Article 10 compliance. JURISDICTION FLAGS: EU and EEA jurisdictions require explicit national law authorization or official authority processing for criminal conviction data. California, Illinois, New York, and other states with fair chance hiring laws may impose additional restrictions on how criminal records data may be used in employment-related due diligence contexts. CONTRACT AND VENDOR IMPLICATIONS: Organizations using ADP for background screening or due diligence functions should confirm that ADP's criminal records processing procedures comply with FCRA permissible purpose requirements and applicable state background check statutes. Vendor agreements should specify the legal basis and procedural safeguards for criminal records processing. COMPLIANCE CONSIDERATIONS: Compliance teams should verify whether ADP's criminal records processing constitutes a consumer report under FCRA and, if so, confirm that applicable FCRA notice and consent procedures are in place. EU-based processing of criminal records should be assessed against applicable national implementing legislation under GDPR Article 10.
This provision authorizes processing of criminal records data — classified as a special category under GDPR — for due diligence and security purposes, which may engage fair credit reporting and background check statutes in the United States depending on the context and method of collection.
Under this clause, ADP may process information about an individual's criminal history or related proceedings for business due diligence and security purposes. Individuals whose criminal records data is processed for purposes beyond those listed are entitled to prior explicit consent under the policy terms.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by ADP.