On 24 October, the Consumer Financial Protection Bureau (CFPB) released Circular 2024-06, addressing critical aspects concerning the use of third-party consumer reports by companies. This guidance particularly cautions against misuse by organisations employing surveillance-based “black box” or AI algorithmic scores, underscoring the necessity to adhere to the Fair Credit Reporting Act (FCRA) in handling workers' personal data. This advisory signifies an expanding legal framework aimed at safeguarding employees from potentially detrimental AI applications.
The CFPB acknowledges a rising trend among employers employing third-party consumer reports in making employment decisions. The scope of these reports has extended beyond traditional background checks to include the monitoring of employee behaviour through various digital means such as apps and other data collection sources, thus broadening the extent of employee surveillance.
According to the Bureau, background reports generated from databases containing public records, employment histories, and analyses of workers' risk levels or performance qualify as “consumer reports” under the FCRA. Therefore, employers utilising such reports for hiring or ongoing employment evaluations must comply with FCRA stipulations. This includes obtaining workers' consent for procuring a consumer report and delivering requisite notices before enacting any adverse employment decisions, along with restrictions on report usage to permissible purposes defined by the FCRA.
The guidance specifically identifies several types of reports used by employers, facilitated by background screening companies and consumer reporting agencies. It mentions that certain employers hire third parties to oversee workers' sales engagements, assess driving patterns, evaluate task completion times, scrutinise the frequency of outgoing messages, and monitor off-task time through methods such as tracking web browsing, taking computer screenshots, and measuring keystrokes. Oftentimes, this collected data might be distributed to prospective or current employers by consumer reporting agencies, thereby implicating FCRA considerations. Additionally, some companies analyse such data to produce reports that evaluate worker productivity or risk.
Key protections highlighted by the CFPB under the FCRA for third-party consumer reporting include:
Consent: Workers' consent must be secured by employers prior to the purchase of these reports, ensuring transparency of data utilisation.
Transparency: Detailed information must be provided to employees when these reports result in adverse job actions like termination, denied promotions, or demotions. More specifically, in alignment with Section 604(b), employers must furnish a notice and a copy of the report to workers before undertaking such adverse actions.
Disputes: Should a worker dispute report information, companies are obligated to amend or expunge inaccurate or unverifiable details, thereby averting unfair penalties and resolving discrepancies.
Limits: The use of such reports by employers is confined to legally acceptable purposes, prohibiting the exploitation of data for unrelated activities like marketing.
Moreover, consumer reporting agencies are also subject to additional requirements. Upon a worker’s request, these agencies must disclose the identity of any entity that accessed the worker’s consumer report for employment purposes within the previous two years, a period longer than the one-year span stipulated for other uses.
This CFPB circular arrives alongside broader regulatory efforts, exemplified by New York City's Automated Employment Decision Tools (AEDT) law, effective from 1 January 2023, setting standards for AI usage in employment decisions. Federal entities like the Equal Employment Opportunity Commission (EEOC) have similarly taken strides by issuing guidance under its Artificial Intelligence and Algorithmic Fairness Initiative, providing technical assistance documents, and executing enforcement against discriminatory AI hiring practices.
Consequently, the CFPB's advisory surfaces amid a milieu of increased scrutiny from federal and state regulators to mitigate potentially harmful implications of AI on workers, reflecting an assertive movement towards reinforcing employee protections in the digital age.
Source: Noah Wire Services