🎯 LAUNCH OFFERSave $700 → $997

Guide

TCPA, EEOC & FCRA — Staffing-Agency Compliance Without the Headache

A practical guide to the three federal compliance regimes that actually matter for US staffing agencies — TCPA for SMS, EEOC for hiring practices, FCRA for background checks. What to do, what to avoid, how to audit.

Not legal advice. This is operational guidance from working with US staffing agencies. Consult a labor attorney for situations specific to your firm.

The three compliance regimes that actually matter

For a US staffing agency, the federal compliance landscape is wider than three regimes, but these are the three that have produced the most expensive incidents we’ve seen in this industry:

  • TCPA (Telephone Consumer Protection Act) — governs SMS and automated calls
  • EEOC (Equal Employment Opportunity Commission) — governs hiring practices and discrimination
  • FCRA (Fair Credit Reporting Act) — governs background checks and consumer reports

Get these three right and you’ve eliminated the most common five-figure-and-up compliance hits.

TCPA — SMS and auto-call

TCPA penalties run $500 per message for negligent violations, $1,500 per message for willful violations. Class actions stack these up fast. A single “we sent 2,000 unauthorized SMS” lawsuit can be a six- or seven-figure event.

What you must have:

  • Prior express written consent before sending any marketing SMS or auto-call to any candidate. Capture this at application intake with a checkbox and timestamp.
  • STOP keyword handling. Replying STOP must immediately opt-out the number from all future automated messages.
  • Opt-out audit log. Be able to show, for any complainant, the exact date/time they opted in or opted out.
  • No purchased lists. Lists you buy come with no consent. Don’t text them.

What the Hiring Snapshot does:

  • Captures consent at intake with a timestamped opt-in checkbox
  • Auto-handles STOP, START, HELP keywords per TCPA spec
  • Maintains an opt-out list that’s checked before every outbound message
  • Keeps a record of opt-ins and opt-outs you can export when you need it

Best practice (not a snapshot guarantee): TCPA’s statute of limitations runs several years, so many agencies choose to retain their opt-in/opt-out records for 4+ years. The snapshot logs the events; your retention policy and any external archiving are up to you. Confirm your approach with counsel.

Recruiter-personal phones

A common compliance gap: recruiters texting candidates from their personal cell phones. There’s no consent capture, no audit log, no STOP keyword handling. If a candidate complains, the agency has no defense. The snapshot’s two-way SMS in the unified inbox solves this — recruiters text from the branded number, all compliance plumbing is automatic.

EEOC — Equal employment opportunity

EEOC enforcement against staffing agencies has been increasing. The agency is treated as the employer for many compliance purposes, including disparate-impact analysis of hiring decisions.

What you must have:

  • EEO-1 reporting if you have 100+ employees, including W-2 contractors on assignment
  • Self-identification (race, gender, veteran status, disability) offered to all applicants, opt-in only
  • No discriminatory job criteria — knockout questions can’t be a proxy for protected categories (e.g., “must speak English natively” raises national-origin issues)
  • Reasonable accommodations during application and interview process

What the Hiring Snapshot does:

  • Self-identification fields are configured as opt-in with the EEOC’s recommended wording
  • Self-ID responses are captured on the application so they stay out of the recruiter’s day-to-day candidate view
  • Application data you can export to support your own EEO-1 reporting

Best practice (not a snapshot guarantee): keep your own record of any changes to job criteria so you can show they weren’t tweaked to exclude protected categories. The snapshot configures the self-ID intake; the analysis and reporting remain your responsibility.

FCRA — Background checks

FCRA governs any third-party “consumer report” used for employment — credit checks, criminal background checks, employment verification, driving records. Violations include real damages plus statutory damages of $100–$1,000 per violation.

What you must have:

  • Standalone disclosure before initiating any background check. The disclosure must be on a separate document, not buried in the application.
  • Written consent signed before the check is run.
  • Pre-adverse action notice if you’re about to reject a candidate based on a background-check result, giving them the report and a chance to dispute.
  • Adverse action notice if you proceed with rejection, including the consumer-reporting agency’s contact info.

What the Hiring Snapshot does:

  • Presents a standalone FCRA disclosure as part of the consent flow (separate from the application)
  • Captures the candidate’s consent before any background check is initiated
  • Templated pre-adverse and adverse action notices you can send if a candidate is rejected post-background-check
  • Keeps a record of the disclosure and consent you can export

Best practice (not a snapshot guarantee): plan your own retention policy for FCRA disclosures and consents. The snapshot captures the events; long-term archiving is up to you and your background-check provider. Confirm with counsel.

State-specific layers

Federal compliance is the floor. States stack on top:

  • California: ban-the-box at application, salary history ban, pay-range posting, CCPA / CPRA privacy
  • New York, Washington, Colorado: pay-range posting, criminal-record consideration limits
  • Massachusetts, Illinois: AI-decision-tool disclosure if using algorithmic screening
  • Massachusetts: wage equity for substantially similar work

These are areas to configure your own templates for. The snapshot’s role and application templates are editable, so you can add pay-range fields or an AI-decision disclosure where your states require them. The snapshot does not police or auto-enforce state posting laws — that judgment stays with you and your counsel.

Best practice (not a snapshot guarantee): pay-range posting and AI-decision disclosure are legal requirements you own. Build them into your templates as standard practice and review them as state laws change.

The audit-ready posture

A “compliant” agency isn’t one that never makes a mistake — it’s one that can prove what happened on any given day for any given candidate. Good records are your defense.

The snapshot records, and lets you export:

  • Consent given (TCPA opt-in, FCRA disclosure/consent, EEO self-ID)
  • Outbound SMS / email with consent status at time of send
  • Background-check disclosure and consent
  • Recruiter actions on a candidate record

When a complaint or audit comes, you export the records for the candidate in question and you have the story. Retention length and any external archiving are your call — see the best-practice notes above.

What we’d recommend

  • Configure consent capture during snapshot setup — don’t leave it for “later”
  • Run a quarterly compliance review — randomly sample 20 candidate records and confirm consent / FCRA / EEO data is complete
  • Train recruiters on STOP, HELP, START keywords so they don’t try to “manually override” an opt-out
  • Don’t use recruiter-personal phones for SMS — this is the most common gap
  • Consult a labor attorney annually for state-specific updates and any new federal guidance

The Hiring Snapshot does the heavy lifting on consent capture, audit logging, and template enforcement. Your job is to keep your team disciplined about using it correctly.

Skip the build — install in 24 hours

Everything in this guide is already built into the $997 Hiring Snapshot.