Obtainer
Use case

FCRA Compliance Software for Fair Credit Reporting Act Disclosure Requests and Background Checks

A consumer file disclosure request and a state privacy request look almost identical to the person sending them, and they run under two different laws with two different clocks. A background screening company gets both, often from the same consumer in the same week, and has to answer each one out of a different set of systems.

See how it works
Discovery across your systems Human redaction gate Helps you comply, not legal advice
Request Studio
Requester
Compiled the manifest and drafted the response - illustrative sample request
0
records found
0
systems scanned
Data manifest
Response draft

Assembling the cover letter from the template...

You approve what is disclosed before anything ships

Helps you comply, not legal advice

In short

FCRA compliance is the set of duties the Fair Credit Reporting Act places on consumer reporting agencies, on the furnishers that feed them data, and on the employers, landlords and lenders that use their reports. Two of those duties are data subject access requests in everything but name. Section 609, at 15 U.S.C. 1681g, requires an agency to disclose to the consumer, on request and after proper identification, all information in the consumer's file at the time of the request, the sources of that information, and the identity of each person that procured a consumer report about them, reaching back two years for employment purposes and one year for any other purpose, plus a record of the prescreened credit and insurance inquiries received in the past year.

Section 611, at 15 U.S.C. 1681i, adds the clock. A reasonable reinvestigation of disputed information has to finish before the end of the 30-day period that begins when you receive the notice of dispute, extendable by not more than 15 additional days if the consumer gives you relevant information inside that first 30 days, with written results due no later than 5 business days after the reinvestigation is complete. That is a 45-day ceiling on a 30-day default, and it is tighter out of the gate than any comprehensive state privacy law.

What most screening companies underestimate is everything outside the file. Every comprehensive state privacy law carves out the FCRA, and not one of them carves out you. California at Civil Code 1798.145(d) applies its exemption only to the extent that the activity is subject to regulation under the FCRA. Texas writes it the same way at Business and Commerce Code 541.003(11): the activity of a consumer reporting agency, furnisher or user of a consumer report, but only to the extent that the activity is regulated by and authorized under the Fair Credit Reporting Act. Virginia, Colorado, Utah and Connecticut all follow that shape. Then compare how the same statutes treat banks and hospitals. Va. Code 59.1-576(B) and Tex. Bus. and Com. Code 541.002(b) exempt a GLBA financial institution and a HIPAA covered entity as an organization. There is no equivalent line anywhere in the country for a consumer reporting agency.

So the file is exempt and the company is not. Website visitors, marketing lists, sales prospects, your own job applicants and employees, and any product line that is not a consumer report all carry full access, correction, deletion and opt-out rights on a 45-day state clock. When the same person sends a section 609 file request and a CCPA request to know, you owe two answers out of two different sets of systems, and neither dataset should end up inside the other.

Obtainer covers the operational half of that work. It intakes the request, searches your product database, warehouse, support desk, billing, marketing and internal systems, reports the source system behind every record it surfaces, compiles one reviewable manifest, tracks the statutory deadline per request, and keeps a timestamped record of what was searched and when. Nothing is disclosed automatically. A human reviews, redacts and approves before anything leaves. Obtainer helps you comply. It is not legal advice, so permissible purpose, proper identification, the call on whether a record belongs in the FCRA file or in the state privacy response, and any decision to refuse stay with your team. Self-serve from a planned $49/mo.

Last updated August 2026

// THE FIT

Why it fits

Compliance and operations teams at background screening companies, tenant and employment screeners, and other consumer reporting agencies.

Two regimes, two clocks, one consumer

The FCRA dispute clock is 30 days from receipt, stretching to 45 only if the consumer sends you relevant information inside the first 30, and the written result is due within 5 business days of finishing. The state privacy clock is 45 days with a 45-day extension. A screening company that runs one queue on the longer number will be late on the shorter one, and a consumer who files both in the same week gets two responses that have to agree with each other without sharing a scope. Obtainer records when each request arrived and tracks its own deadline per request, which is the only way the two queues stay separable once volume goes up.

No state exempts a consumer reporting agency as an entity

This is the part that surprises people who read the exemption list quickly. Fifteen of the twenty comprehensive state laws lift a GLBA financial institution out of scope entirely, and most of them do the same for a HIPAA covered entity. The FCRA carve-out is never written that way. It is always an activity exemption, always qualified by to the extent, and it protects the consumer report and the work of producing it rather than the business that produces it. Everything you hold that is not part of that activity is ordinary personal information under the state law of wherever the consumer lives.

The FCRA is one of the few privacy statutes a consumer can sue you under

Under 15 U.S.C. 1681n a willful failure to comply exposes you to the consumer's actual damages or statutory damages of not less than $100 and not more than $1,000, plus punitive damages the court may allow and reasonable attorney's fees. Under 1681o a negligent failure carries actual damages, costs and fees. Compare the state privacy laws, where California is the only state with a private right of action and it is limited to breaches of unencrypted data caused by unreasonable security. Mishandling a file disclosure is not a regulator problem you can settle quietly. It is a claim, and statutory damages do not require proof of out-of-pocket loss.

// FAQ

Questions

Common questions about this

What is FCRA compliance?

FCRA compliance means meeting the duties the Fair Credit Reporting Act places on your role in the consumer reporting system. For a consumer reporting agency that means following reasonable procedures to assure maximum possible accuracy, releasing reports only for a permissible purpose, disclosing the consumer's file on request under section 609, and reinvestigating disputes under section 611 within 30 days. Furnishers have accuracy and dispute duties of their own, and users of reports have notice and adverse action duties. The obligations differ by role, so the first compliance question is always which role you are in for a given piece of data.

What does a consumer reporting agency have to disclose under Section 609?

Under 15 U.S.C. 1681g the agency must clearly and accurately disclose all information in the consumer's file at the time of the request, the sources of that information, and the identity of each person that procured a consumer report about the consumer, covering the 2-year period before the request for reports procured for employment purposes and the 1-year period for any other purpose. It must also disclose the record of inquiries received in the past year that identified the consumer for prescreened credit or insurance offers, and it must include the summary of rights prepared by the Bureau. Sources acquired solely for an investigative consumer report have a narrow carve-out.

How long does a consumer reporting agency have to respond to a dispute?

Thirty days from receiving notice of the dispute. Section 611 requires a reasonable reinvestigation to be completed before the end of that 30-day period, and the period may be extended by not more than 15 additional days if the agency receives relevant information from the consumer during the original 30 days, which puts the ceiling at 45. Written notice of the results is then due no later than 5 business days after the reinvestigation is complete. If the agency reasonably determines the dispute is frivolous or irrelevant it may terminate the reinvestigation, but it has to tell the consumer within 5 business days of making that determination.

Is a background check company exempt from the CCPA?

No, not as a company. California exempts the activity, not the entity. Civil Code 1798.145(d) applies only to the extent that the collection, maintenance, disclosure, sale, communication or use of the information by that agency, furnisher or user is subject to regulation under the Fair Credit Reporting Act, and the subdivision expressly does not apply to Section 1798.150, the breach private right of action. So your consumer reports and the work of producing them sit outside the CCPA, while your marketing database, your website analytics, your sales prospects and, since January 1, 2023, your own employees, applicants and contractors sit fully inside it with a 45-day response clock.

What is a 609 dispute letter?

It is a template circulated by credit repair services that cites section 609 and asks a bureau to produce the original signed contract behind an account, on the theory that a failure to produce it forces deletion. Section 609 does not say that. It is a disclosure provision: it entitles the consumer to see what is in the file, where it came from, and who has pulled a report. The provision that can lead to deletion is section 611, and only where information turns out to be inaccurate, incomplete or unverifiable. Accurate information does not come off a file because a letter demanded paperwork.

Who has to comply with the Fair Credit Reporting Act?

Three groups, with different duties. Consumer reporting agencies, meaning any entity that regularly assembles or evaluates consumer credit information or other information on consumers to furnish consumer reports to third parties. Furnishers, meaning the lenders, collectors, landlords and others that report information about consumers to those agencies. And users of consumer reports, meaning the employers, landlords, insurers and lenders that pull them, who owe permissible purpose, disclosure and authorization, and pre-adverse and adverse action notice duties. Many companies occupy more than one of these roles at once, which is where compliance programs usually go wrong.

What are the penalties for an FCRA violation?

Willful noncompliance under 15 U.S.C. 1681n exposes you to the consumer's actual damages or statutory damages of not less than $100 and not more than $1,000 per violation, such punitive damages as the court may allow, and reasonable attorney's fees. Negligent noncompliance under 1681o carries actual damages plus costs and fees. Because statutory damages do not require proof of an out-of-pocket loss, a systemic process failure across a large population is the exposure that matters rather than any single request. The FTC and the CFPB can also bring enforcement actions, and state attorneys general have authority of their own.

Run a data subject access request end to end

Obtainer finds where a person's data lives across your systems, compiles it into one manifest, drafts the deadline-safe response, and tracks the GDPR and CCPA clock. You review, redact, and approve what gets disclosed. Helps you comply; not legal advice.