FCRA Exemption From State Privacy Laws: Why No State Exempts a Consumer Reporting Agency
Last updated August 2026 · Obtainer
found
scanned
Assembling the cover letter from the template...
Helps you comply, not legal advice
Every comprehensive US state privacy law carves out the Fair Credit Reporting Act. None of them carves out you. The exemption is written as an activity exemption in all twenty states, always qualified by the words "to the extent", and it protects the consumer report and the work of producing it rather than the company that produces it.
That is a real structural difference, not a drafting quirk. Fifteen states lift a GLBA financial institution out of scope entirely, and most of them do the same for a HIPAA covered entity. No state does that for a consumer reporting agency. So a background screening company, a tenant screener, an employment screener or a credit bureau is a covered business under the privacy law of wherever the consumer lives, for everything it holds that is not part of a consumer report.
What does the FCRA exemption in a state privacy law actually cover?
It covers an activity, defined by the role you are playing and the law you are playing it under. The standard formulation, which most states copied from California, exempts the collection, maintenance, disclosure, sale, communication or use of personal information bearing on a consumer's credit worthiness, credit standing, credit capacity, character, general reputation, personal characteristics or mode of living, by a consumer reporting agency, by a furnisher that provides information for use in a consumer report, or by a user of a consumer report, but only to the extent that the activity is regulated by and authorized under the FCRA.
Read the qualifier slowly, because two words in it do the work. Regulated by means the data has to fall inside the FCRA's scope. Authorized under means the use has to be one the FCRA permits. Data that starts life inside a consumer report and is then used for something the FCRA never authorized, marketing to the subject, product analytics, training a model, selling to an audience platform, does not carry the exemption with it. The carve-out attaches to the activity, and it ends when the activity does.
FCRA exemption by state
The table sets the FCRA carve-out beside the GLBA exemption in the same statute, because that comparison is what makes the shape obvious. Privacy statutes are amended every session, so confirm a row against the current text before you build a scoping decision on it.
| Law | FCRA carve-out | Exempts the data or the company? | GLBA financial institution | The limit that matters |
|---|---|---|---|---|
| California CCPA, Civ. Code 1798.145(d) | Activity of an agency, furnisher or user | Data only | Data only. California offers no entity exemption to anyone | Applies only to the extent the activity is subject to FCRA regulation, and expressly does not apply to Section 1798.150, the breach private right of action |
| Virginia VCDPA, 59.1-576(C) | Same activity language | Data only | Entity, at 59.1-576(B) | The entity exemptions for GLBA institutions and HIPAA covered entities sit in subsection (B). The FCRA carve-out sits in (C), with the data |
| Colorado CPA, C.R.S. 6-1-1304(2) | Activity regulated by the FCRA, where data is used only as the FCRA authorizes | Data only | Entity | The exemption fails at the moment data is used outside what the FCRA authorizes, and the burden of proving an exemption sits with the controller |
| Texas TDPSA, Bus. and Com. Code 541.003(11) | Activity of an agency, furnisher or user | Data only | Entity, at 541.002(b)(2) | The statute says it plainly: "but only to the extent that the activity is regulated by and authorized under" the FCRA |
| Utah UCPA, 13-61-102(2) | Activity of an agency or a user of a report | Data only | Entity | Utah's exemption list is the most generous in the country on nearly every other axis and still gives a consumer reporting agency no entity pass |
| Connecticut CTDPA, Conn. Gen. Stat. 42-517 | Activity language, unchanged | Data only | Entity, narrowed July 1, 2026 to banks, credit unions, certain insurers and regulated broker-dealers | Connecticut tightened its GLBA entity exemption in 2026 and left the FCRA carve-out exactly where it always was |
Why the FCRA carve-out is written differently from the GLBA and HIPAA ones
Because the FCRA regulates conduct rather than institutions. GLBA and HIPAA both define a class of covered organization and then regulate nearly everything that organization does with personal information, which makes an entity-level exemption coherent: if the bank is already comprehensively regulated, a second regime adds friction more than protection. Several state legislatures accepted that argument, and five of them have since walked it back for GLBA.
The FCRA never worked that way. It attaches duties to a role in a transaction. You are a consumer reporting agency for the reports you assemble, a furnisher for the data you send, and neither for the newsletter list you keep. Writing an entity exemption around a role-based statute would have exempted companies for activities the FCRA does not touch, which is exactly the gap legislatures were closing. The same instinct explains why six states exempt only PHI rather than the covered entity and why FERPA protects education records rather than schools.
Is a background check company exempt from the CCPA?
No, not as a company. California exempts the activity. Civil Code 1798.145(d) applies only to the extent that the collection, maintenance, disclosure, sale, communication or use of the information by that agency, furnisher or user is subject to regulation under the Fair Credit Reporting Act, and the subdivision states expressly that it does not apply to Section 1798.150. Your reports sit outside the CCPA. Your company sits inside it, and the breach private right of action reaches you regardless.
What stays in scope at a consumer reporting agency
More than most privacy programs assume, because the exempt activity is narrow and the business around it is not. In scope, on a 45-day clock, with rights to know, correct, delete and opt out:
- Website and app data. Visitors, cookies, session recordings, ad pixels, and the dispute portal itself where it collects more than the FCRA requires.
- Marketing and sales. Prospect lists, CRM records, event registrations, webinar attendees, and every enrichment vendor feeding them.
- Your own workforce. California removed the HR exemption on January 1, 2023, so employees, former employees, contractors and applicants have full rights. That includes the resumes arriving through your careers page and whatever a tool that reads every inbound resume extracted from them before a human saw it.
- Non-FCRA product lines. Identity verification, fraud signals, people search, continuous monitoring, and analytics products sold outside the permissible purpose framework. If it is not a consumer report, the carve-out does not reach it.
- Client-side records. The employer contacts, billing records and account histories of the businesses that buy from you, to the extent those are individuals.
The operational consequence is that one person can be in your systems twice under two legal regimes at once: as a consumer with a file, and as a website visitor, applicant or marketing contact. Answering either request correctly means knowing which records belong to which, which is a discovery problem before it is a legal one.
Does the FCRA preempt state privacy law?
Only within its own subject matter. Section 1681t contains preemption provisions that bar states from imposing requirements on subjects the FCRA regulates, notably the content of consumer reports and the responsibilities of furnishers. That is a shield around consumer reporting, not around your company. A state law giving a resident the right to delete a marketing profile is not a requirement with respect to the subject matter regulated by the FCRA, so nothing in the federal statute displaces it. Treat preemption the way you treat the exemption: it follows the activity.
Did the CFPB bring data brokers under the FCRA?
It proposed to and then withdrew the proposal. The Bureau published Protecting Americans From Harmful Data Broker Practices (Regulation V) on December 13, 2024, which would have treated the sale of certain identifiers and financial attributes as consumer reporting and pulled a large population of data brokers into the FCRA as consumer reporting agencies. The withdrawal notice ran in the Federal Register on May 15, 2025, on the stated ground that rulemaking was not necessary or appropriate at this time.
So the federal line held where it was, and the pressure moved to the states. If you sell data without a permissible purpose framework around it, the FCRA carve-out was never going to cover you anyway, and four states now require data broker registration with penalties measured per day.
What this changes about how you answer a request
Run two queues, not one. A section 609 file disclosure and a section 611 dispute are FCRA work with a 30-day reinvestigation clock that stretches to 45 only when the consumer sends relevant information inside the first 30 days. A state privacy request is separate work, on its own 45-day clock, against a different set of systems. The two answers should never be assembled from the same search, and neither should quietly include the other's data.
Then decide the boundary once, in writing, rather than per request. For each system you operate, record whether it holds FCRA-regulated data, non-FCRA personal information, or both, and who makes the call when a record is ambiguous. Teams that skip this end up making the classification decision under deadline pressure, one request at a time, with different answers each time. That inconsistency is what turns into a claim, because unlike the state privacy laws, the FCRA gives the consumer a private right of action: 15 U.S.C. 1681n allows statutory damages of not less than $100 and not more than $1,000 for a willful failure, plus punitive damages and attorney's fees, with no requirement to prove an out-of-pocket loss.
If you want the operational side of this handled in one place, our FCRA compliance software for file disclosure and dispute requests intakes each request, searches your systems, reports the source system behind every record, tracks the right clock for the right regime, and holds everything at a human review and approval gate before it ships. It helps you comply. The legal calls, permissible purpose, proper identification and the classification boundary above, stay with your team.
A short checklist
- Confirm which FCRA roles you occupy: agency, furnisher, user, or more than one.
- Map every system to FCRA-regulated data, non-FCRA personal information, or both.
- Check the state thresholds you actually cross, since applicability turns on resident counts and revenue, not on your industry.
- Separate the 30-day dispute queue from the 45-day state privacy queue, with different templates and different search scopes.
- Verify identity to the standard of the regime you are answering under, since the FCRA proper identification standard and the CCPA verification standard are not the same test.
- Write down who decides when a record is ambiguous, before the next request arrives.
Run a data subject access request end to end
Obtainer finds where a person's data lives across your systems, compiles it into one manifest, drafts the deadline-safe response, and tracks the GDPR and CCPA clock. You review, redact, and approve what gets disclosed. Helps you comply; not legal advice.