FCRA Compliance, Criminal‑History Protections, and the Structural Failures That Create Liability

The Fair Credit Reporting Act (FCRA) is one of the most technical and unforgiving employment laws. It governs every step of how employers obtain, use, store, share, and act on background checks, and drug screening results. Yet most employers — especially those with decentralized hiring, multiple DBAs, or limited HR infrastructure — violate the FCRA without realizing it. And because background checks are used across the entire applicant pool, a single mistake can become a systemic violation, which is exactly how class actions begin. See this article on a real world FCRA class action lawsuit»

This white paper explains what the FCRA actually requires, why employers keep violating it, and how state and local criminal‑history laws create additional compliance obligations that many companies overlook. It also highlights the often‑ignored requirement that background checks be kept confidential internally — even within the same entity.

If you need immediate assistance with your FCRA compliance, contact us to schedule a confidential consultation.

The FCRA’s Mandatory Compliance Framework: What Employers Must Do Every Time

The FCRA requires employers to follow a strict, sequential process before obtaining or using a background check or drug screening results. The law is designed to protect applicants from unfair treatment, inaccurate information, and opaque decision‑making. When employers skip steps — even unintentionally — they violate the statute.

Clear, Standalone Disclosure

Before pulling a background check, employers must provide a disclosure that is:

  1. clear

  2. conspicuous

  3. standalone

  4. not combined with any other document

This is where many employers fail. They bury the disclosure inside an application, onboarding packet, or policy acknowledgment. The moment the disclosure is combined with anything else, it violates the FCRA.

If your disclosure is embedded in your job application or onboarding packet, your company is already out of compliance. Contact us to schedule a confidential consultation about your HR compliance concerns.

Written Authorization

The applicant must sign a written authorization before the background check is pulled. Verbal consent, implied consent, or “the recruiter said it was fine” does not satisfy the statute. In fast‑moving hiring environments or talent acquisition departments using inexperienced staff, this step is often skipped entirely.

Certification to the Background‑Check Vendor

Before receiving the report, the employer must certify that it:

  1. provided the standalone disclosure

  2. obtained written authorization

  3. will follow the adverse‑action process

  4. will not use the report in violation of equal employment laws

Most background check companies force employers to make this certification, but doing so without complying with the requirements, creates additional liability under the FCRA.

Pre‑Adverse Action Notice

Before denying employment based on a background check, employers must provide:

  1. a copy of the report

  2. a summary of rights

  3. reasonable time for the applicant to dispute inaccuracies

This is the step employers skip most often — and the step that creates the most litigation. In the lawsuit, the applicant was denied employment immediately, without any chance to correct the errors.

If your team denies employment the moment a background check comes back, you are violating the FCRA. A pre‑adverse action audit is the fastest way to reduce risk. Contact us for assistance.

Final Adverse Action Notice

After the applicant has had a chance to respond, the employer may finalize the decision — but must send a final adverse‑action notice confirming the decision. Skipping this step is also a violation.

Internal Confidentiality: The Overlooked FCRA Requirement Employers Routinely Violate

The FCRA does not just regulate how background checks are obtained — it also regulates how they are stored, accessed, and shared internally. Background checks must be treated as confidential consumer reports. They may only be accessed by individuals who:

  1. have a legitimate business need

  2. are involved in the hiring decision

  3. are authorized to review consumer reports

They may not be shared casually within the organization, even within the same entity. They may not be forwarded to managers “for awareness.” They may not be shared with unrelated departments. They may not be circulated to multiple decision‑makers unless each person has a permissible purpose.

If background checks are emailed, forwarded, or shared with anyone who is not directly involved in the hiring decision, your company is violating the FCRA.

Why Employers Keep Violating the FCRA: Structural Weaknesses and Operational Gaps

FCRA violations rarely stem from bad intent. They stem from structural problems in how companies hire.

Multiple DBAs and Brand Names: Companies operating under several DBAs often blur the lines between entities. Applicants apply to one brand, but another entity handles onboarding or background checks. This creates unauthorized pulls.

Subsidiaries Conducting Interviews: A subsidiary may interview the applicant, but a parent company or sister company may run the background check. If the applicant never applied to that entity, it lacks a permissible purpose.

Decentralized or Improvised Hiring Processes: When hiring is handled by operations managers, recruiters, field supervisors, contractors, or franchisees, FCRA steps are often skipped because no one is trained on compliance.

Lack of HR Infrastructure:

Growing companies often lack:

  1. experienced HR staff

  2. centralized HR oversight

  3. standardized onboarding

  4. documented processes

  5. compliance training

  6. background‑check governance

Without structure, background checks are handled inconsistently — and inconsistency is where liability lives.

Criminal‑History Laws: The Web of State and Local Protections Employers Must Follow

Beyond the FCRA, employers must comply with a complex network of state and local laws governing how criminal‑history information may be used. These laws vary widely, but most include:

Restrictions on Using Arrests: Many states prohibit employers from using arrests or non‑convictions as a basis for employment decisions. In the lawsuit, the employer allegedly confused arrests with convictions, violating both federal and state law.

Limits on Using Old Records: Several jurisdictions prohibit employers from using criminal records older than seven years. The lawsuit involved outdated charges that should not have appeared at all.

Individualized Assessments: States increasingly require employers to consider the following before making a final decision:

  1. the nature of the offense

  2. the time elapsed

  3. relevance to the job

  4. evidence of rehabilitation

Notice and Opportunity to Respond: Many states require employers to notify applicants of the criminal‑history information being used and allow them to respond before a final decision is made.

Ban‑the‑Box Laws: Dozens of jurisdictions prohibit employers from asking about criminal history on job applications or early in the hiring process.

Equal Employment Opportunity Considerations: Using criminal‑history information in a way that disproportionately impacts protected groups may violate Title VII.

If your criminal‑history process has not been updated in the last 24 months, you may be out of compliance with new state and local laws, making a multi‑state criminal‑history review is a leadership‑level priority.

Final Takeaway: FCRA Compliance Is Not Optional — And Violations Scale Quickly

A single background‑check failure — including confusing arrests with convictions, skipping the adverse‑action process, or sharing reports improperly — can escalate into a class action when the same flawed process is used for every applicant.

Companies with decentralized hiring, multiple DBAs, or limited HR infrastructure or HR experience must be especially careful. When roles are unclear, compliance breaks down. And when compliance breaks down, applicants lose their rights — and employers face large‑scale litigation.


A growing company’s HR compliance is the foundation of its entire business. You can build a mansion on a weak foundation — and it may look impressive for a while — but eventually it cracks, shifts, and collapses. When that happens, all the money, effort, and growth you invested disappears overnight. If your HR infrastructure isn’t structurally sound, a lawsuit is just the first sign of deeper instability.

Now is the time to reinforce the foundation before a collapse costs you significantly more than prevention. Contact us for assistance.