Background check data sources and matching limits - DataImpulse

A background check report looks like a lookup against a central record. It is not. It is a synthesis across thousands of independent sources, joined on weak identifiers, and the parts of it that go wrong go wrong in ways that affect real people’s jobs and housing.

This guide covers the four record types behind a report, why false matches are structural rather than accidental, and the legal regime that governs how the data may be used rather than how it may be obtained.


Key Facts

  • There is no national criminal database available to private companies in the United States. Commercial products are assembled from thousands of county and state sources.
  • Identity matching is the main source of error. Court systems rarely expose strong identifiers, so matching runs on name and date of birth.
  • Using a report for employment, credit, housing or insurance triggers the FCRA, with obligations around consent, accuracy, notice and dispute.
  • Expunged and sealed records must be removed, and stale copies held downstream are the mechanism by which they resurface.
  • A clean result means clean within that provider’s coverage, which is a narrower statement than it appears.

What goes into a background check?

Every background check api assembles the same four record types, each from a different system. We call it the 4-part record model.

Record type Source Practical limit
1. Criminal records County and state courts, some state repositories No public national database; coverage is county by county
2. Identity and address history Credit header data, utilities, public filings Used to decide which counties to search; errors cascade
3. Verification records Employers, educational institutions, licensing boards Requires contact and consent; slow and partly manual
4. Watchlists and sanctions Government-published lists Name-only matching; very high false positive rate

Row two is the hidden dependency. A search covers the counties where a person is believed to have lived, derived from address history, so a gap in that history produces a gap in the criminal search without anything appearing wrong in the report.


Why do false matches happen?

Because the join is weak by design.

Court records generally do not publish strong identifiers such as national identity numbers, so commercial matching relies on name plus date of birth, occasionally with an address. Common names collide, transliterations vary, dates are entered inconsistently, and name changes break the link in the other direction.

The result is two error types with asymmetric consequences. A false positive attaches someone else’s record to a person and can cost them a job. A false negative reports clean when a record exists in a county that was never searched. Providers tune toward one or the other, and that choice is rarely disclosed.

Two practices reduce it: require the provider to state its matching criteria, and verify any adverse finding at the source court before acting on it. The second step is also a legal requirement in many circumstances, not just good practice.


What does the law actually govern?

Purpose Use a compliant provider when Avoid when
Employment decisions Always: FCRA consent, disclosure and adverse action apply Never use a general data product for hiring decisions
Tenant screening Always: housing decisions fall under the same regime Informal checks on an applicant; the obligations still apply
Credit and insurance Always, with the additional rules for those sectors Any process without a documented permissible purpose
Research or journalism Public records directly, from the source Redistributing a compiled report for other purposes

The distinction that matters is that FCRA obligations attach to the use, not to the data. Assembling public records into a report and then using it to decide on employment makes the assembler a consumer reporting agency with the duties that follow, regardless of every record being individually public.

Outside the US, several regimes restrict criminal record processing tightly: under the GDPR, offence data is a special category with a narrow lawful basis, and some jurisdictions prohibit commercial screening almost entirely. General information, not legal advice.


What are the limits?

Coverage is the biggest unstated variable. Ask any provider which counties it searches directly versus which it covers through a state repository or a purchased database, and how often each refreshes.

Removals must propagate. When a court seals or expunges a record, the source removes it. Copies held by aggregators disappear only if that aggregator refreshes and honours removals, which is the mechanism behind records that resurface years later.

Watchlist screening is noisy. Name-only matching against sanctions lists produces very high false positive rates, and treating a hit as a finding rather than as a prompt for review is the common failure.

Scraping court portals for this purpose is a bad idea on two grounds: many prohibit automated access in their terms, and a self-assembled dataset used for hiring puts you in the regulated position without the compliance apparatus.

Related: public court records, is web scraping legal.


Frequently Asked Questions

Is there a national criminal database for background checks?

Not one available to private companies in the United States. Commercial products are assembled from thousands of county courts, some state repositories and purchased databases, which is why coverage differs between providers and why the same person can return different results.

Why do background checks return the wrong person?

Because court records rarely publish strong identifiers, so matching runs on name and date of birth. Common names collide, transliterations vary and name changes break the link, producing both false attributions and missed records.

What does the FCRA regulate?

Use rather than access. Using a report to decide on employment, credit, housing or insurance in the United States brings consent, disclosure, accuracy and adverse action obligations, and makes the compiler a consumer reporting agency, even though every underlying record is public.

Can I build my own background check system?

Technically possible and legally hazardous. Many court portals prohibit automated access, and using a self-assembled dataset for hiring places you in the regulated position without the compliance processes that regime requires.

Why do expunged records reappear?

Because removal at the source does not propagate automatically. Downstream copies persist until the holder refreshes and honours the removal, so a record a court ordered erased can still surface from a stale commercial database.


Reach public record portals reliably

County and state portals restrict or degrade access by origin, and the failure looks like missing data rather than an error. DataImpulse residential proxies give country and state-level exits at $1 per GB across 195 countries. Create an account for the research side of public records.

Related: public court records · is web scraping legal · government contract data.

Last updated: September 17, 2026.


Share article: