Consent and compliance

Social media screening of candidates: FCRA, EEOC and the state password laws

On this page
  1. When social media screening triggers the FCRA
  2. What is and is not covered by the FCRA in practice
  3. What EEOC-enforced law says regardless of the FCRA
  4. State laws that bar employers from demanding account access
  5. Where the risk concentrates: not every platform is the same
  6. Building a firewall between screening and deciding
  7. A worked example: what a filtered report looks like
  8. A documented protocol before you screen anyone
  9. Questions people ask

Social media screening sits under two separate legal frameworks that recruiters often conflate. What you are allowed to look at, and what you do once you see it, are governed by employment discrimination law regardless of who does the looking. Whether the process also has to follow the Fair Credit Reporting Act depends on a narrower question: did a third party compile the report for you. A growing list of states adds a third layer, barring an employer from demanding account passwords or access at all.

This is not legal advice. The citations below were checked against FTC, EEOC and CFPB guidance and the statutes named, as of September 2026. Discrimination law, FCRA enforcement and state social-media-privacy laws are each separately subject to change and to court interpretation. Confirm your process with an employment lawyer before relying on it.

When social media screening triggers the FCRA

In a May 2011 letter to a social media background screening vendor, the FTC concluded that a company that assembles social media information and furnishes it to employers as a factor in hiring decisions is a consumer reporting agency, and that the report it produces is a consumer report under the FCRA. The FTC's general guidance, Using Consumer Reports: What Employers Need to Know, applies the same disclosure, authorization, and pre-adverse and adverse action steps used for any other background check. In practice: the moment a vendor, rather than your own staff, compiles a candidate's social media activity into a report you use to decide, you are back in ordinary FCRA territory, covered in full in the FCRA background check process.

The Consumer Financial Protection Bureau added a further layer in 2024. Its Circular 2024-06 states that background dossiers and algorithmic scores assembled from public and social media data, including tools that generate a fit or risk score, can also be consumer reports subject to the FCRA when a third party assembles them for use in an employment decision, not just traditional criminal or credit reports.

What is and is not covered by the FCRA in practice

SituationFCRA status
A recruiter personally browses a candidate's public LinkedIn profileGenerally not covered; no third-party consumer reporting agency is involved
A vendor compiles a report of a candidate's public social media activity for youGenerally covered, per the FTC's 2011 position
A vendor's algorithm scores a candidate's online presence for "risk" or "culture fit"Can be covered under the CFPB's 2024 guidance, even without a traditional background-check format
An in-house team member manually reviews and summarizes public posts for the hiring managerA gray area; the FTC's letter focused on third-party vendors, and in-house compilation has not been tested the same way

What EEOC-enforced law says regardless of the FCRA

The FCRA question is separate from discrimination law, and discrimination law applies whether or not a vendor is involved. The EEOC's Background Checks: What Employers Need to Know guidance, issued jointly with the FTC, states plainly that it is unlawful to make an employment decision based on race, color, national origin, sex, religion, disability, genetic information, or age 40 or older, and that this rule applies to information gathered from any source, social media included. A social media profile routinely reveals several of these: a photo can suggest race, age or pregnancy; a bio can disclose religion, national origin or a disability; a group membership can disclose all of the above. None of that information has to be asked for to create exposure. Once a decision-maker has seen it, the burden shifts to the employer to show it did not influence a rejection.

State laws that bar employers from demanding account access

A separate set of state statutes does not regulate what an employer may look at once it is public. It bars an employer from requiring a candidate to hand over the means to see what is not public.

StateStatuteWhat it bars
California Lab. Code § 980 Requiring a username or password, requiring access in the employer's presence, or requiring the candidate to divulge personal social media content. Carries a narrow exception for an internal misconduct investigation
Illinois 820 ILCS 55, Right to Privacy in the Workplace Act Requesting or requiring a password or other account information to gain access to a personal online account; does not restrict information already in the public domain
Michigan MCL §§ 37.271–37.278, Internet Privacy Protection Act Requiring access to, observation of, or disclosure of a personal internet account; a knowing violation is a misdemeanor with a fine of up to $1,000

These three are examples, not a full count; a substantial number of additional states have similar statutes with their own wording and exceptions, and we did not attempt to verify every one for this page. The pattern across the states we did verify is consistent: public content stays fair game under these particular statutes, and the restriction is specifically about passwords and forced access, layered on top of the EEOC and FCRA questions above, not a replacement for them.

Where the risk concentrates: not every platform is the same

What is reviewedWhy it is lower or higher risk
A candidate's own portfolio site, GitHub, or published writingLower risk: content is usually job-relevant by design, and profile photos or personal details are less prominent
LinkedIn activity and postsModerate risk: mostly professional content, but photos, group memberships and life updates can still disclose protected characteristics
Personal Facebook or Instagram, even when publicHigher risk: designed to surface personal life, family, religion, health and political views, which is exactly the content EEOC-enforced law says should not reach the decision-maker
A vendor's aggregated "digital footprint" or sentiment scoreTreat as an FCRA consumer report under the CFPB's 2024 guidance, and confirm the vendor gives you the disclosure and adverse-action support that requires

A practical rule follows from the table: the more a platform is built around personal life rather than professional activity, the more a screener needs a written, job-related reason before opening it, and the more useful the firewall in the next section becomes.

Building a firewall between screening and deciding

Because the discrimination risk comes from what the decision-maker saw, not from what was searched for, the standard practice for employers who do social media screening in-house is to separate the two roles:

  • A screener who is not the hiring decision-maker reviews public content against a written, job-related standard set in advance, such as evidence of professional misconduct or misrepresented credentials.
  • The screener reports only job-relevant findings, in writing, to the hiring manager, filtering out anything that reveals a protected characteristic.
  • The hiring manager never sees the candidate's raw profile, only the filtered summary, so a later claim that a protected characteristic influenced the decision has less to point to.
  • The same standard is applied to every candidate for the role, not just the ones a recruiter happens to think to search for.

A third-party vendor that is itself a consumer reporting agency effectively builds this firewall for you, which is part of why many employers who screen social media at scale use one rather than doing it in-house, accepting the FCRA's disclosure and adverse-action steps in exchange.

A worked example: what a filtered report looks like

This is an invented example, not a real candidate. Suppose an agency recruiter is filling a bookkeeper role and a screener reviews the finalist's public LinkedIn and a personal, public Instagram as part of a standard, job-related check applied to every finalist for the role.

  • What the screener found: a LinkedIn post describing a dispute with a former employer over expense reporting, and an Instagram photo showing the candidate at a religious holiday gathering with family.
  • What goes in the report to the hiring manager: "Public post describes a disagreement with a prior employer over expense documentation; no other job-relevant findings." Nothing about the religious gathering is included, because it has no bearing on the bookkeeper role and disclosing it would hand the hiring manager information the law says cannot factor into the decision.
  • What the hiring manager does with it: asks the candidate directly, in the next interview, an open question about a time they disagreed with an employer over documentation or process, and evaluates the answer the candidate actually gives rather than the online post itself.

The filter is doing the real work here. A hiring manager who saw both details unfiltered would have a harder time showing, if ever challenged, that the family photo played no part in the decision.

A documented protocol before you screen anyone

  1. Decide in writing what you are looking for, tied to the job, before you look at any profile: misrepresented credentials, evidence contradicting the application, public professional conduct.
  2. Apply the same search to every candidate for a given role, not only the ones who raise a question.
  3. If using a vendor, confirm it is FCRA-compliant and follow the standard disclosure, authorization, and pre-adverse and adverse action sequence in the FCRA background check process.
  4. Never request a password or account access, and train hiring managers not to ask a candidate to "just show me your profile" on a call.
  5. Route findings through a screener separate from the decision-maker where you screen in-house, and strip anything revealing a protected characteristic before it reaches the hiring manager.
  6. Keep records of what was reviewed and why for each candidate, so a consistent process is demonstrable later, not just claimed.

For the broader set of topics protected-characteristic law restricts asking about directly, see illegal interview questions. For how AI-assisted screening tools are regulated on top of these rules, see AI hiring laws by state.

Questions people ask

Does looking at a candidate's public LinkedIn or Facebook profile count as a background check under the FCRA?

Not by itself. The FCRA is triggered when a consumer reporting agency, meaning a third party in the business of assembling this kind of information, compiles the report for you. A recruiter personally browsing a public profile is not using a consumer report, though it still carries discrimination risk under EEOC-enforced law if protected-class information influences the decision.

Can an employer ask a candidate for their social media password?

In a growing number of states, no. California, Illinois and Michigan are examples of states that bar an employer from requiring an employee or applicant to disclose a social media password or otherwise grant account access, subject to narrow exceptions such as an internal misconduct investigation. Check the specific state before making any password or access request.

What happens if a social media check reveals a candidate's protected characteristics, like religion or disability, even though the recruiter did not ask for that information?

The information does not have to be asked for to create risk. Once a decision-maker has seen it, a rejected candidate can argue it influenced the decision, and the employer bears the burden of showing it did not. This is why many employers route social media checks through a screener who is walled off from the hiring decision, or through a vendor bound by the FCRA.

Do these rules apply to a recruiter checking a candidate's public posts without using a vendor?

The FCRA generally does not apply without a third-party consumer reporting agency in the loop. Discrimination law enforced by the EEOC applies regardless of who does the looking, and a handful of state password-access statutes apply specifically to account credentials rather than public content.