Employee Background Screening Under FCRA
Employee background screening under the Fair Credit Reporting Act (FCRA) is a critical aspect of workplace privacy in the United States. The FCRA regulates how employers obtain, use, and handle consumer reports—including criminal background checks, credit reports, employment history, and other inve… Employee background screening under the Fair Credit Reporting Act (FCRA) is a critical aspect of workplace privacy in the United States. The FCRA regulates how employers obtain, use, and handle consumer reports—including criminal background checks, credit reports, employment history, and other investigative reports—when making employment decisions. **Key Requirements for Employers:** 1. **Disclosure and Consent:** Before obtaining a consumer report, employers must provide a clear, conspicuous, standalone written disclosure to the applicant or employee informing them that a background check may be conducted. The individual must provide written authorization before the employer can proceed. 2. **Permissible Purpose:** Employers must have a permissible purpose under the FCRA to request a consumer report, and employment screening qualifies as one such purpose. 3. **Pre-Adverse Action Notice:** If an employer intends to take adverse action (such as not hiring, terminating, or denying a promotion) based on information in the report, they must first provide the individual with a pre-adverse action notice, a copy of the consumer report, and a summary of their rights under the FCRA. 4. **Adverse Action Notice:** After allowing a reasonable waiting period, if the employer proceeds with the adverse action, they must send a formal adverse action notice that includes the name and contact information of the consumer reporting agency (CRA), a statement that the CRA did not make the decision, and notice of the individual's right to dispute the report's accuracy. 5. **Consumer Reporting Agency Obligations:** CRAs must ensure maximum possible accuracy of reported information, follow reasonable procedures, and comply with specific requirements regarding the age of reportable information. **Enforcement and Penalties:** The Federal Trade Commission (FTC) and the Consumer Financial Protection Bureau (CFPB) enforce the FCRA. Violations can result in statutory damages, actual damages, punitive damages, and attorney fees. Employers who willfully or negligently violate the FCRA face significant legal liability. Understanding FCRA compliance is essential for privacy professionals to ensure lawful and ethical background screening practices while protecting individuals' privacy rights in the workplace.
Employee Background Screening Under FCRA: A Comprehensive Guide for CIPP/US Exam Preparation
Introduction
Employee background screening is one of the most heavily tested topics within the CIPP/US exam's workplace privacy domain. The Fair Credit Reporting Act (FCRA) plays a central role in regulating how employers obtain, use, and handle consumer reports during the hiring and employment process. Understanding the FCRA's requirements for background screening is critical not only for passing the exam but also for practical privacy compliance in the workplace.
Why Employee Background Screening Under FCRA Is Important
Employers routinely conduct background checks on job applicants and current employees to assess suitability for employment, verify credentials, and mitigate risk. However, these checks involve the collection and use of sensitive personal information, including criminal history, credit history, driving records, and more. Without proper regulation, individuals could face discrimination, inaccurate reporting, and unfair denial of employment opportunities.
The FCRA exists to promote the accuracy, fairness, and privacy of information in the files of consumer reporting agencies (CRAs). In the employment context, the FCRA imposes specific obligations on employers (referred to as users of consumer reports), CRAs, and furnishers of information. Violations can result in significant statutory damages, class action lawsuits, and enforcement actions by the Federal Trade Commission (FTC) and the Consumer Financial Protection Bureau (CFPB).
From a privacy professional's perspective, understanding the FCRA's background screening requirements is essential because:
• It is one of the primary federal laws governing workplace privacy in the United States.
• Non-compliance can lead to costly litigation—FCRA class actions have resulted in multimillion-dollar settlements.
• It intersects with state ban-the-box laws, EEOC guidance, and other regulatory frameworks.
• It demonstrates the balance between employer interests and individual privacy rights.
What Is Employee Background Screening Under FCRA?
The FCRA (15 U.S.C. § 1681 et seq.) was originally enacted in 1970 and has been amended several times, including by the Consumer Credit Reporting Reform Act of 1996 and the Fair and Accurate Credit Transactions Act (FACTA) of 2003. While the FCRA broadly covers consumer reports used for credit, insurance, and other purposes, its application to employment is particularly significant.
Key Definitions:
Consumer Report: Any written, oral, or other communication of information by a CRA bearing on a consumer's creditworthiness, credit standing, credit capacity, character, general reputation, personal characteristics, or mode of living, which is used or expected to be used as a factor in establishing the consumer's eligibility for employment, credit, insurance, or other authorized purposes.
Consumer Reporting Agency (CRA): Any person or entity that regularly assembles or evaluates consumer credit information or other information on consumers for the purpose of furnishing consumer reports to third parties. In the employment context, background screening companies are typically CRAs.
Investigative Consumer Report: A special type of consumer report in which information about a consumer's character, general reputation, personal characteristics, or mode of living is obtained through personal interviews with neighbors, friends, associates, or acquaintances. This triggers additional disclosure requirements under the FCRA.
User: In the employment context, the employer who requests the consumer report is considered the user.
Permissible Purpose: The FCRA requires that a consumer report be obtained only for a permissible purpose. Employment is a permissible purpose under Section 604(a)(3)(B), but it comes with special requirements.
How Employee Background Screening Under FCRA Works
The FCRA imposes a structured process that employers must follow when using consumer reports for employment purposes. This process can be broken into several key phases:
1. Pre-Report Obligations (Before Obtaining the Report)
Before an employer can obtain a consumer report for employment purposes, the FCRA requires:
• Clear and Conspicuous Written Disclosure: The employer must provide the applicant or employee with a clear and conspicuous written disclosure, in a document that consists solely of the disclosure, that a consumer report may be obtained for employment purposes. This is a critical requirement—the disclosure must be a standalone document and cannot be embedded within the employment application or other documents.
• Written Authorization: The employer must obtain written authorization from the individual before procuring the report. This authorization can be included in the same standalone disclosure document.
• Additional Requirements for Investigative Consumer Reports: If the employer is obtaining an investigative consumer report, additional disclosure must be provided within three days of requesting the report, informing the individual that an investigative consumer report may be obtained, describing the nature and scope of the investigation, and advising the individual of their right to request additional information about the investigation.
• Certification to the CRA: The employer must certify to the CRA that it has complied with all FCRA requirements, that it has obtained proper disclosure and authorization, that it will not use the information in violation of any applicable law, and that if any adverse action is taken based on the report, it will provide the required notices to the consumer.
2. Obtaining and Reviewing the Report
Once proper disclosure and authorization have been obtained, the employer may request the consumer report from the CRA. The CRA has its own obligations under the FCRA, including maintaining reasonable procedures to ensure maximum possible accuracy of the information in consumer reports and limiting the reporting of certain types of negative information (for example, most negative information cannot be reported after seven years, and bankruptcies cannot be reported after ten years—though these time limits do not apply to positions with an annual salary of $75,000 or more).
3. Pre-Adverse Action Notice
If the employer intends to take adverse action based in whole or in part on the consumer report, it must first provide the individual with:
• A pre-adverse action notice—a notification that the employer is considering taking adverse action.
• A copy of the consumer report that was relied upon.
• A copy of the Summary of Rights under the FCRA (as prescribed by the CFPB).
The purpose of the pre-adverse action notice is to give the individual an opportunity to review the report and dispute any inaccurate information before the employer makes a final decision. The FCRA does not specify a mandatory waiting period between the pre-adverse action notice and the final adverse action notice, but a reasonable period (commonly five business days) is recommended to allow the individual time to respond.
Adverse action in the employment context includes denial of employment, termination, or any other decision that negatively affects the individual's employment status based on the consumer report.
4. Adverse Action Notice
If the employer ultimately decides to take adverse action, it must provide the individual with an adverse action notice that includes:
• The name, address, and phone number of the CRA that furnished the report.
• A statement that the CRA did not make the adverse decision and is unable to provide specific reasons for it.
• A notice of the individual's right to obtain a free copy of the report from the CRA within 60 days.
• A notice of the individual's right to dispute the accuracy or completeness of any information in the report.
5. Disposal of Consumer Report Information
Under FACTA's disposal rule, any person who possesses or maintains consumer report information for a business purpose must properly dispose of such information by taking reasonable measures to protect against unauthorized access to or use of the information. This applies to both physical and electronic records.
Special Considerations and Related Issues
State Law Overlay: Many states have enacted laws that provide additional protections beyond the FCRA. For example, some states restrict the use of credit reports for employment decisions, impose additional notice requirements, or have ban-the-box laws that restrict when an employer can inquire about criminal history. The FCRA sets a federal floor, and state laws may impose stricter requirements.
EEOC Guidance: The Equal Employment Opportunity Commission (EEOC) has issued guidance on the use of criminal background checks in employment, cautioning that blanket policies excluding individuals with criminal records may have a disparate impact on protected classes under Title VII of the Civil Rights Act of 1964. While not part of the FCRA itself, this guidance is closely related to background screening practices.
Workplace Investigations Exception: The FCRA contains a limited exception for workplace investigations. Under Section 603(x), communications made to an employer in connection with an investigation of suspected misconduct relating to employment, or compliance with federal, state, or local laws, are excluded from the definition of consumer report under certain conditions. However, if the employer takes adverse action based on such a communication, it must still provide a summary of the nature and substance of the communication to the individual.
The Role of the CFPB and FTC: Enforcement of the FCRA is shared between the CFPB and the FTC. The CFPB has rulemaking authority and primary enforcement jurisdiction over larger CRAs and certain other entities, while the FTC retains enforcement authority over smaller CRAs and other entities not within the CFPB's jurisdiction. Both agencies have brought significant enforcement actions related to employment screening practices.
Common FCRA Violations in Employment Screening:
• Embedding the disclosure in the employment application rather than providing it as a standalone document.
• Including extraneous information (such as liability waivers) in the disclosure document.
• Failing to provide the pre-adverse action notice before taking adverse action.
• Failing to provide a copy of the consumer report with the pre-adverse action notice.
• Not waiting a reasonable period between the pre-adverse action and adverse action notices.
• Failing to properly dispose of consumer report information.
Exam Tips: Answering Questions on Employee Background Screening Under FCRA
Tip 1: Master the Two-Step Adverse Action Process
This is one of the most frequently tested concepts. Remember that the FCRA requires two separate notices: a pre-adverse action notice (with a copy of the report and Summary of Rights) before the decision is finalized, and an adverse action notice after the decision is made. If an exam question presents a scenario where an employer takes adverse action without the pre-adverse action step, that is a violation.
Tip 2: Remember the Standalone Disclosure Requirement
The written disclosure must be in a document that consists solely of the disclosure. Exam questions may test whether including additional terms (such as a release of liability or acknowledgment of at-will employment) in the disclosure document constitutes a violation. The answer is yes—the disclosure must be standalone.
Tip 3: Distinguish Between Consumer Reports and Investigative Consumer Reports
Know the difference. An investigative consumer report involves personal interviews and triggers additional notice obligations (within three days of requesting the report). Standard consumer reports based on database searches do not require this additional notice.
Tip 4: Know Who Enforces the FCRA
The CFPB and FTC share enforcement authority. The CFPB has rulemaking authority and oversees larger market participants. Individuals also have a private right of action under the FCRA, which can result in statutory damages of $100 to $1,000 per violation for willful noncompliance, plus punitive damages and attorney's fees.
Tip 5: Understand the Employer's Certification Obligations
Before a CRA can furnish a consumer report for employment purposes, the employer must certify compliance. This certification includes confirming that proper disclosure and authorization were obtained and that the employer will follow the adverse action procedures if applicable.
Tip 6: Be Aware of the Workplace Investigations Exception
Section 603(x) creates a narrow exception for workplace investigations of misconduct. However, remember that even under this exception, if adverse action is taken, the employer must provide a summary of the nature and substance of the communication. The full consumer report procedures may not apply, but notice obligations still exist.
Tip 7: Watch for State Law Questions
The CIPP/US exam may include questions about state laws that go beyond the FCRA. Be familiar with the concept that the FCRA provides a federal baseline and that states can impose additional restrictions, particularly regarding the use of credit reports in employment decisions and ban-the-box legislation.
Tip 8: Pay Attention to the Time Limits on Reporting
The general rule is that most negative information cannot be reported after seven years, and bankruptcies after ten years. However, these time limits do not apply to employment positions with an annual salary of $75,000 or more. This exception is a common exam topic.
Tip 9: Read Scenarios Carefully
Many FCRA questions are scenario-based. Pay close attention to the sequence of events described. Did the employer provide disclosure before obtaining the report? Was the disclosure standalone? Was a pre-adverse action notice sent before the final decision? Did the notice include all required elements? These procedural details are where exam questions typically focus.
Tip 10: Remember the Consumer's Rights
The FCRA grants consumers several important rights in the employment context: the right to know what is in their file, the right to dispute inaccurate information, the right to have inaccurate information corrected or deleted, the right to be notified when information in their file has been used against them, and the right to consent before a report is obtained for employment purposes. Understanding these rights from the consumer's perspective will help you answer questions about employer obligations.
Summary
Employee background screening under the FCRA is a carefully regulated process that balances employers' legitimate need for information with individuals' privacy rights and interests in accuracy. The key elements to remember are: standalone written disclosure, written authorization, employer certification to the CRA, the two-step adverse action process (pre-adverse action notice followed by adverse action notice), and proper disposal of consumer report information. Mastering these procedural requirements, along with understanding the roles of CRAs, the CFPB, the FTC, and the interplay with state laws, will prepare you well for the CIPP/US exam and for real-world privacy practice.
Unlock Premium Access
Certified Information Privacy Professional/United States
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 2040 Superior-grade Certified Information Privacy Professional/United States practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- CIPP/US: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!