DPPA permissible use, explained
The Driver's Privacy Protection Act (DPPA, 18 U.S.C. §§ 2721–2725) is the federal law that restricts who may obtain and use personal information from state motor-vehicle records — the data held by DMVs: names, addresses, driver's license details, and vehicle registrations. Enacted in 1994 after DMV records were used to locate and murder actress Rebecca Schaeffer, it flipped the default: DMV data is closed unless your use fits an enumerated permissible use.
If you work with people-search, skip-tracing, or investigative data products, you will hit DPPA attestations constantly, because vendors whose data includes DMV-sourced records must collect a permissible-use certification from every customer.
The permissible uses
The DPPA enumerates fourteen permissible uses. The ones that matter in commercial practice:
- (b)(1) Government functions — use by any government agency carrying out its functions.
- (b)(3) Business verification — verifying the accuracy of personal information *submitted by the individual to the business*, and obtaining corrected information to prevent fraud or pursue legal remedies against them. This is the workhorse use for fraud prevention: it covers checking details the person gave you, not researching strangers.
- (b)(4) Litigation — use in connection with a civil, criminal, administrative, or arbitral proceeding, including service of process and judgment execution. This is what process servers and legal skip tracers rely on.
- (b)(6) Insurance — use by an insurer in connection with claims investigation, antifraud activities, rating, or underwriting.
- (b)(8) Employment verification of commercial drivers — narrowly, verifying information about holders of commercial driver's licenses.
- (b)(9) Towing and impound — notifying owners of towed or impounded vehicles.
- (b)(10) Private investigators — licensed investigators or security services, but only *for a use otherwise permitted* — being a PI is not itself a blank check.
Marketing use of DMV data requires the state to have obtained express consent — which, post-2000 amendments, effectively ended bulk marketing use.
How attestation works in practice
Because downstream users, not just DMVs, are bound by the DPPA, every reseller in the chain must ensure its customers have a permissible use. In practice that means:
- You certify a specific permissible use when you open the account (and often per search).
- The certification is recorded — who, when, from what IP, which use.
- Misuse is a federal offense: criminal fines, a $2,500 civil penalty per violation for knowing misuse, and a private right of action for the person whose data was obtained.
Treat a DPPA attestation like a legal filing, not a checkbox. If your actual use case changes, your certification has to change with it.
DPPA vs FCRA — different laws, different triggers
The two regimes are easy to conflate and completely independent. The FCRA is triggered by *eligibility purposes* (credit, employment, housing, insurance decisions) regardless of data source; the DPPA is triggered by *data source* (motor-vehicle records) regardless of purpose. A single workflow can implicate both, either, or neither — and a use that is DPPA-permissible (say, litigation skip tracing) can still be FCRA-prohibited if you also use the result to decide someone's tenancy.
Where CoverFi stands
CoverFi's records are built from consumer marketing files — the data dictionary lists every field — not from DMV feeds, so DPPA permissible-use certification is not a gate for using the service today. The FCRA boundary is: every account and API key requires a non-FCRA attestation, and locating and verification workflows are the intended uses. If you routinely rely on DPPA (b)(3), (b)(4), or (b)(6) uses in your work, those same workflows — verifying submitted details, litigation support, claims investigation — are what the records API serves, from a non-DMV source.
*Plain-language orientation, not legal advice — the statute and your state's implementation control.*