CoverFi

DPPA permissible use, explained

The Driver's Privacy Protection Act (DPPA, 18 U.S.C. §§ 2721–2725) is the federal law that restricts who may obtain and use personal information from state motor-vehicle records — the data held by DMVs: names, addresses, driver's license details, and vehicle registrations. Enacted in 1994 after DMV records were used to locate and murder actress Rebecca Schaeffer, it flipped the default: DMV data is closed unless your use fits an enumerated permissible use.

If you work with people-search, skip-tracing, or investigative data products, you will hit DPPA attestations constantly, because vendors whose data includes DMV-sourced records must collect a permissible-use certification from every customer.

The permissible uses

The DPPA enumerates fourteen permissible uses. The ones that matter in commercial practice:

Marketing use of DMV data requires the state to have obtained express consent — which, post-2000 amendments, effectively ended bulk marketing use.

How attestation works in practice

Because downstream users, not just DMVs, are bound by the DPPA, every reseller in the chain must ensure its customers have a permissible use. In practice that means:

Treat a DPPA attestation like a legal filing, not a checkbox. If your actual use case changes, your certification has to change with it.

DPPA vs FCRA — different laws, different triggers

The two regimes are easy to conflate and completely independent. The FCRA is triggered by *eligibility purposes* (credit, employment, housing, insurance decisions) regardless of data source; the DPPA is triggered by *data source* (motor-vehicle records) regardless of purpose. A single workflow can implicate both, either, or neither — and a use that is DPPA-permissible (say, litigation skip tracing) can still be FCRA-prohibited if you also use the result to decide someone's tenancy.

Where CoverFi stands

CoverFi's records are built from consumer marketing files — the data dictionary lists every field — not from DMV feeds, so DPPA permissible-use certification is not a gate for using the service today. The FCRA boundary is: every account and API key requires a non-FCRA attestation, and locating and verification workflows are the intended uses. If you routinely rely on DPPA (b)(3), (b)(4), or (b)(6) uses in your work, those same workflows — verifying submitted details, litigation support, claims investigation — are what the records API serves, from a non-DMV source.

*Plain-language orientation, not legal advice — the statute and your state's implementation control.*

Related reading

Run a free identity check — no signup, no ID upload.