Client Screening and Privacy for Matchmakers: A Practical Framework
A risk-based approach to identity checks, sensitive data, consent, access, retention and escalation before an introduction is considered.
Client screening in matchmaking should reduce a defined risk without creating a false promise of safety. Identity checks, interviews, reference checks and database searches answer different questions. None can guarantee future behavior, and each adds privacy, accuracy and fairness responsibilities.
A sound framework starts with risk, uses the least intrusive effective check and tells clients what the check does—and does not—mean. This article is an operational framework, not legal advice. Requirements differ by jurisdiction.
Separate the screening questions
“Is this person verified?” is too vague for professional use. Break it into specific questions:
- Identity: Is there evidence that the person is who they claim to be?
- Contact: Has a phone number, email or address been confirmed?
- Availability: Has the person made a relevant declaration about current relationship status and capacity to date?
- Profile accuracy: Are material professional, education or location claims supported where necessary?
- Known-record search: Did an authorized search return a relevant public or regulated record?
- Suitability: Does the person understand and accept the service’s conduct expectations?
- Ongoing behavior: Has any interaction, complaint or new information changed the risk assessment?
Record the completed check and its date. Do not collapse all outcomes into a permanent green badge.
Use risk tiers
Apply more intrusive screening only when the context justifies it.
Tier 1: every participant
A reasonable baseline may include:
- verified contact route;
- identity confidence appropriate to the service;
- review of material profile information;
- acceptance of conduct and privacy expectations;
- a structured intake conversation;
- a documented way to report concerns.
Tier 2: defined elevated context
Additional checks may be justified for high-value concierge services, international arrangements, material claims or another documented risk. Examples include a specialist identity provider, credential confirmation or an authorized public-record search.
Tier 3: concern or incident
A credible inconsistency, complaint or safety report requires a controlled escalation: preserve relevant evidence, restrict unnecessary contact, assign an accountable reviewer and determine next steps under policy and local law.
Do not make Tier 3 decisions automatically from a single unverified allegation or opaque vendor score. Urgent protective steps and a fair review can coexist.
Start with data minimisation
Collect only data that is adequate, relevant and necessary for the purpose. The UK Information Commissioner’s Office explains this principle in its data minimisation guidance. Even outside the UK, the question is useful: can you explain why this particular item is needed for this particular check?
Before collecting a document or data point, define:
- the risk it addresses;
- the lawful authority or consent process;
- the person or vendor that will access it;
- the result you retain;
- the deletion or review date;
- how an error can be challenged.
Where possible, retain a verified result and limited metadata rather than a full copy of a document. Whether that is appropriate depends on legal and operational requirements.
Design identity checking proportionately
Identity checking can range from comparing a person on a video call with an approved document to using a specialist provider. Choose the method based on impersonation risk, geography, accessibility and available expertise.
Important controls include:
- an approved collection channel;
- clear instructions about which document fields are needed;
- restricted access to images and results;
- no copies in ordinary chat or personal devices;
- a process for expired or changed documents;
- support for people who cannot use the default method;
- a defined retention period;
- vendor due diligence.
An identity match does not confirm that every profile claim is true or that the person is safe. Communicate it as identity evidence, not character certification.
Treat background checks as scoped searches
Background checks are jurisdiction-specific and can contain incomplete, outdated or mistaken records. In some places, access, consent, permissible purpose, adverse decisions and retention are regulated.
Before offering one:
- obtain qualified legal advice for every relevant jurisdiction;
- define which sources and date ranges the check covers;
- select an appropriate, accountable provider;
- tell the person what will be searched;
- establish a correction and dispute route;
- prevent raw results from circulating broadly;
- define who interprets ambiguous matches;
- document decision criteria and escalation;
- state clearly what the check cannot detect.
A “no result” is not proof that no relevant conduct exists. A result is not automatically proof that it belongs to the person or determines present suitability.
Distinguish declarations from verification
Some important facts cannot be reliably proven through a single database. A relationship-status declaration, for example, may be a contractual representation rather than an independently verified fact.
Label it honestly:
- “self-declared on 4 September” is accurate;
- “verified single” may not be.
When a fact is material, ask the person to reconfirm it before an introduction. Record inconsistencies and resolve them through a defined review rather than silently editing the old answer.
Limit access by task
Screening data should not appear in every client view. Define roles such as:
- intake professional: sees completion status and actions required;
- screening reviewer: sees the evidence needed to assess the check;
- matchmaker: sees the outcome, limitations and relevant restrictions;
- coordinator: sees only operational clearance needed to schedule;
- partner agency: receives no raw screening data unless a specific lawful, agreed process requires it.
Apply least privilege, review access regularly and log important views, exports and changes. OWASP’s Authorization Cheat Sheet is a practical technical reference for deny-by-default and permission checks, though it is not a complete privacy program.
Protect special-category and highly sensitive information
Intake can reveal health, sexuality, religion, ethnicity, biometrics and other sensitive information. Legal classification differs by jurisdiction, but operational caution should be high everywhere.
Do not collect a category merely because clients use it as a search preference. Determine whether using it is lawful, ethical and necessary. Keep sensitive free text out of analytics and AI tools unless those tools and uses have been explicitly assessed and approved.
If a specialist must handle information, share only what is needed for that task. A verification vendor does not need relationship-history notes; a matchmaker does not need a document number.
Establish a retention schedule
“Keep forever in case we need it” is not a defensible operating rule.
Create separate retention periods for:
- incomplete enquiries;
- identity evidence;
- screening result and metadata;
- active-client records;
- inactive candidate profiles;
- consent evidence;
- complaints and incident records;
- financial and contract records.
The periods may differ because purposes and legal duties differ. Set review dates in the system and ensure backups and exported copies are included in deletion design.
When a record cannot be deleted because of a legal claim or obligation, restrict it to that purpose rather than leaving it active in matching.
Handle adverse or uncertain findings fairly
Create a decision path before the first difficult result:
- Verify that the result belongs to the correct person.
- Assess source, date, relevance and confidence.
- Limit access while review is active.
- Give the person an appropriate opportunity to correct factual errors, unless doing so would create a documented safety or legal risk.
- Apply consistent criteria.
- Record the decision, reviewer and next review date.
- Communicate only what recipients need to act safely.
Do not place speculative labels in a permanent profile. Preserve factual source context and distinguish allegation, confirmed record, professional assessment and operational action.
Make screening claims precise
Public and client-facing language should name the check rather than imply a guarantee.
Prefer:
- “We confirm identity using [defined method] before an introduction.”
- “Participants make a current relationship-status declaration.”
- “Where included in the service and legally permitted, an approved provider searches [defined sources].”
- “You can report a concern through [route], and we review it under our safety process.”
Avoid:
- “100% safe members”;
- “fully verified” without a public definition;
- “clean background”;
- “AI-certified trustworthy”;
- any claim that transfers responsibility for personal safety to a badge.
Prepare for concerns and incidents
A report may involve harassment, impersonation, fraud, threatened harm, privacy disclosure or inaccurate data. Your response plan should define:
- urgent-safety instructions and local emergency boundaries;
- the internal owner and backup;
- what contact is paused;
- how evidence is preserved securely;
- who may be informed and on what basis;
- when legal, law-enforcement, insurer or data-protection advice is sought;
- how the reporter receives updates;
- how retaliation and unnecessary disclosure are prevented;
- closure and lessons learned.
Do not investigate serious allegations beyond your competence. A matchmaking service is not law enforcement, a court or a clinical provider.
Audit the framework
Review at least quarterly:
- checks completed by tier;
- incomplete or expired checks;
- false matches and corrections;
- staff access to screening data;
- vendor errors and processing locations;
- retention actions completed;
- complaints and time to initial response;
- public claims compared with actual practice;
- cases where screening did not address the relevant risk.
The goal is not a high number of checks. It is better risk decisions with less unnecessary data.
Integrate the framework with your client intake questionnaire and CRM lifecycle. Screening should be a visible, bounded process—not a marketing label or a hidden collection of sensitive documents.
This article is for general informational purposes and is not medical, legal, or mental-health advice.