Credit Header Data: What It Is and Who Can Legally Use It
Somebody told you the professionals use “credit header data.” They were not wrong, and you still cannot get it. A header is the identifying block that sits above the account history in a consumer credit file: the name a lender keyed, the addresses furnishers have reported, a birth date, telephone numbers. Two federal statutes decide who may touch that block and for what. This page names both, quotes them, and shows what the record is worth once you have it lawfully.
The short version, before the statutes
A credit header is the identifying block at the top of a credit file, not the account data beneath it. Name, reported addresses, birth date, phones. Two separate federal statutes govern it. The Fair Credit Reporting Act decides whether a communication counts as a consumer report; the Gramm-Leach-Bliley Act treats the identifying block as nonpublic personal information whatever the answer to that first question turns out to be. No member of the public has a lawful route to it, because the reuse limit in 15 U.S.C. 6802(c) travels with the data to every recipient down the chain. Even a credentialed user gets a lead, not an address. A header tells you where a furnisher last reported someone, which is a place to start looking and never proof of where a person sleeps tonight.
Header data in ninety seconds
Why the identifying block is regulated separately from the report it sits on, and what that means for anyone trying to find a person.
Credit Header Data: How Pros Actually Find People
What the identifying block actually holds
The anatomy matters, because the legal treatment of the top of the file is not the legal treatment of the rest of it.
Open a consumer credit file and the first thing in it is not a loan. It is a description of a human being, assembled from whatever the furnishers reporting to that bureau said the person was called and where they lived when they said it. That description is the header. Beneath it sit the tradelines, and the difference between the two halves of the file is the whole subject of this page.
The header carries the name as keyed by each furnisher, which is why a single file can list a maiden name, a married name, a middle initial that appears on some lines and not others, and one spelling that exists only because a data-entry clerk at a card issuer typed it wrong in 2011. It carries addresses with the dates they were reported, not the dates anyone moved. It carries a date of birth and telephone numbers as supplied on applications, and where a furnisher has passed one along it can carry an employer name that a lender wrote down once and nobody has touched since.
The file also contains a Social Security number field. That field is real, it is why header matching works as well as it does, and it is the reason this record is treated as sensitive rather than clerical. We do not request it, display it, report it, or use it as a search input, and nothing on this page describes a technique that involves it. Where a page anywhere tells you how to work backwards from that field to a person, close the page.
Everything below the header is a different animal. Balances, credit limits, payment history, delinquency codes, charge-offs, inquiry records, the public-record items a bureau appends: that is tradeline data, it is the substance of a credit report, and it has nothing to do with finding an address. We never obtain it, and a locate that claimed to would be describing a service nobody may lawfully provide for that purpose. If you want the wider picture of how identifying records move between the bureaus, the resellers and the sites you have already searched, our explainer on how the data broker industry collects and sells personal information traces that supply chain end to end.
Hold one idea before the law arrives: the header is a reporting artifact, not a residence log, and it never pretended to be one. A person is in it because a company that lends money chose to tell a bureau something about them. Everything further down this page follows from that.
Why two different statutes both reach it
Vendors call header data “non-FCRA” and privacy advocates call selling it unlawful. Both are describing a real thing, and neither explains the mechanism.
Start with the definition, and start with its date, because the gap between the two statutes on this page is the whole story. Congress enacted the Fair Credit Reporting Act in 1970 — Title VI of Pub. L. 91-508, signed 26 October 1970, 84 Stat. 1128, effective a hundred and eighty days after that. Under 15 U.S.C. 1681a(d)(1), a consumer report means a communication by a consumer reporting agency bearing on a consumer’s credit worthiness, credit standing, credit capacity, character, general reputation, personal characteristics, or mode of living which is used, expected to be used, or collected — in whole or in part — for the purpose of serving as a factor in establishing the consumer’s eligibility for credit or insurance to be used primarily for personal, family or household purposes, for employment purposes, or for another purpose the Act authorizes elsewhere.
Read that carefully and you can see the argument the industry ran for three decades. A name and a street address, standing on their own, arguably do not bear on anyone’s creditworthiness, and they are not gathered in order to decide whether someone qualifies for a card. On that reading the identifying block is not a consumer report, and a buyer of it does not need one of the permissible purposes the Act requires. That reading is why an entire location-data industry exists.
Then, twenty-nine years after the FCRA, Congress passed the Gramm-Leach-Bliley Act — Pub. L. 106-102, signed 12 November 1999, 113 Stat. 1436 — and the question stopped being interesting. 15 U.S.C. 6809(4)(A) defines nonpublic personal information as personally identifiable financial information provided by a consumer to a financial institution, resulting from any transaction with the consumer or any service performed for the consumer, or otherwise obtained by the financial institution. Note what that definition does not do: it does not ask whether the information is about money. It asks where the information came from.
The implementing rule closes the loop explicitly. Regulation P, at 12 CFR 1016.3(q), gives examples of what personally identifiable financial information includes, and the list runs from application data and account balances through to two items that decide this whole question: the fact that an individual is or has been one of your customers, and information from a consumer report. A name-and-address record lifted out of a consumer file is, by the regulation’s own example, financial information. It arrived from a lender, which is all the definition needs.
So the two positions you have read online are not in conflict. The header may well sit outside the definition of a consumer report. It sits squarely inside the definition of nonpublic personal information. The first statute governs what a report is and who may receive one; the second governs what may be done with data that came out of a financial institution, whatever anybody calls it. Missing the second statute is why so much of what is written about this subject is confidently wrong.
Who may lawfully touch it, and why you cannot buy it
The restriction that matters is not the one about buying. It is the one about passing it on.
Take the report side first, because it is the shorter half. 15 U.S.C. 1681b(a) opens with a sentence that does all the work: a report may be furnished under the following circumstances and no other. Then it enumerates them. The consumer’s own written instructions. A credit transaction involving extension of credit to the consumer, or the review or collection of an account of the consumer. Employment purposes. Insurance underwriting. Eligibility for a license or government benefit where the granting body is required by law to weigh financial responsibility. Valuation of an existing credit obligation by an investor, servicer or current insurer. A legitimate business need arising from a transaction the consumer initiated, or from reviewing whether an account still meets its terms. A certified child support enforcement request. A court order, a federal grand jury subpoena, or a subpoena of the two kinds the section names. Plus a narrow band of federal and state entries: receivership functions at the FDIC and the NCUA, state child support plan agencies, and government travel charge cards. That is the closed list. Curiosity is not on it, and neither is a dispute with a neighbor.
Now the part that actually stops the sale. 15 U.S.C. 6802 sets out how nonpublic personal information may move. Subsection (e)(6)(A) is the exception that lets a bank hand data to a consumer reporting agency in accordance with the Fair Credit Reporting Act in the first place, which is how the bureaus lawfully hold any of this. Subsection (c) then limits reuse: a nonaffiliated third party that receives nonpublic personal information under that section shall not disclose it to any other person who is a nonaffiliated third party of both parties, unless the disclosure would be lawful if the financial institution had made it directly.
Regulation P states the same rule operationally at 12 CFR 1016.11(a)(1): a recipient of information under an exception may disclose and use it only pursuant to an exception in the ordinary course of business to carry out the activity covered by the exception under which it was received. That single sentence is why header data is a credentialed product rather than a purchasable one. The exception is not a door you walk through once. It follows the record to everyone who ever holds it, and it narrows what each of them may do with it. Nobody in the chain can sell you a copy free of the condition it came in under, because the condition is attached to the data and not to the seller.
What that looks like in practice is unglamorous. Access runs through vetted accounts: a business that has been through underwriting and a site inspection, has signed a certification of permitted use, submits to audit and to sampled query review, and transmits a purpose code with every single search. Queries are logged against that code. Accounts get pulled when the codes and the case files stop matching. There is no consumer tier, no free tier, no trial, and no version of any of this that a member of the public can lawfully reach. If a site offers to sell you “credit header data” for a card payment and an email address, whatever it is selling is not that.
People do ask about the rulemaking, so: in December 2024 the Consumer Financial Protection Bureau proposed treating personal identifiers, credit header data among them, as a consumer report under the Act. That proposal was withdrawn on 15 May 2025. Articles that describe it as pending are out of date, and articles that describe it as law were always wrong. The position today is the one set out above, and it did not need the proposal to restrict anything. If you are weighing what may be used in a decision about a person rather than a search for one, our guide to FCRA compliance in background checks deals with that side of the line.
Element by element: what it proves
Read the row on the right before you act on the row in the middle. Most bad locates come from treating a reported value as an observed one.
| Element in the file | What the header carries | What it does not establish |
|---|---|---|
| Address history | Addresses as reported by furnishers, each stamped with a report dateLead | That anyone lived there on that date, or lives there now |
| Name variants | Every spelling and form any furnisher keyed, including errors | A legal name change; a court file does that |
| Date of birth | A birth date as supplied on credit applications | Identity on its own; it is a disambiguator between same-name subjects |
| Telephone numbers | Numbers given on applications, often years old | A reachable line, a carrier, or a place of residence |
| Employer | Where a furnisher supplied one, a name recorded at application time | Current employment, and it is never used as a service address |
| Everything below the header | Balances, limits, payment history, delinquency, charge-offs and inquiry records are tradeline data, not header data. They are not part of a locate, we do not obtain them, and no permissible purpose for finding an address extends to them. | |
The pattern across that table is one idea repeated: the header records what somebody told a lender, in the form they told it. Every element is a claim with a date attached, which makes it an excellent index and a poor conclusion. That distinction is the discipline behind everything on our skip tracing services page, and it is why a header pull is the first fifteen minutes of a locate rather than the last.
Where the record quietly fails
Six failure modes that a header result will not announce. Each has cost somebody a wasted service attempt.
It only knows people who borrow. A header exists because furnishers report. Someone who has never held a card, a loan, a financed purchase or a utility account reported to a bureau in their own name may have no file at all, and a search that returns nothing has told you about the credit system, not about the person. Recent immigrants, young adults, people who have used cash for a decade and people who have only ever been an authorized user on somebody else’s account all read as absent.
It updates on reporting, not on moving. The address block changes when a furnisher submits a new one. A person who has stopped opening accounts stops generating new reports, so their newest header address can be the address they left three moves ago, and it will look exactly as authoritative as a fresh one. This is the failure mode that catches the most people, because staleness is invisible in the output.
Errors are permanent because they are accurate. A misspelled surname in a header is not a bug. It is a faithful record of what a furnisher reported, so it persists, and the bureau has no basis to remove it. Useful for matching. Misleading if you read the variant list as a history of what someone has called themselves.
Similar people merge. Common surname, overlapping address history, adjacent birth dates: mixed files happen, and the header is where the mixing shows up first, because the header is what matching runs on. A father and son at the same address with the same name are the classic case, and nothing in the output flags it.
A negative result is not evidence. No header address newer than four years means no furnisher reported one. It does not mean the subject stayed put, and it does not mean they are hiding. Reading absence as evasion is how a routine locate turns into a wrong accusation.
It is a hypothesis, and it has to be tested. A header address earns a next step and nothing more. The confirmation has to come from a source with an independent basis to know: a recorded instrument, a filed court paper, a tax roll, a served return of service. Our note on how skip tracers verify address accuracy sets out how that testing is actually done, and the longer treatment of building a timeline from several sources sits in our guide to finding someone’s previous addresses.
Six situations where the header is the wrong tool
Knowing when not to reach for a record is worth more than knowing how to read one.
The subject is credit invisible
No tradelines, no header. A person who has never borrowed in their own name is not in the file, and no amount of access changes that. The work moves to sources that record people for reasons unrelated to lending.
You have no permissible purpose
Curiosity, a personal grievance, a family argument, or wanting to know what an ex is doing. None of these is a circumstance the Act lists, so no header pull happens and we will say so rather than take the file.
The address must survive a challenge
For a motion, an affidavit of diligent search or a due diligence file, a reported header address is not enough on its own. What holds up is an independently sourced record you can name and date in front of a judge.
Two people share the name
Junior and senior at one address, or two unrelated people with a common surname in the same metro. The header is where they merge. Resolution comes from birth dates, middle names and record types that separate individuals properly.
The last report is years old
A subject who stopped using credit leaves a header frozen at whatever was last reported. The file looks confident and is out of date, so the search shifts to sources that update for other reasons entirely.
Someone may be at risk
Where the request suggests an attempt to reach a person who has separated themselves for their safety, we decline it. That is a conversation for law enforcement, a court or a victim services advocate, and not for a records vendor.
A worked locate: judgment creditor, four addresses
How a lawful, header-informed locate is structured, from the certified purpose through to a confirmed address. Composite of routine collection files.
The purpose is established and recorded
A creditor holds an unsatisfied money judgment on its own account. Collection of an account of the consumer is one of the circumstances 15 U.S.C. 1681b(a)(3)(A) names, so the purpose is documented against the case number, and any query touching header data is coded to it by the credentialed party before anything is searched.
The header returns dates, not answers
Under that coded purpose, four addresses come back across eleven years. Three are old enough to be historical. The fourth was reported fourteen months ago, in a county two over from the one on the judgment. That date, not the address, is the finding.
We test it against records no lender supplied
This is the part we do. The county is searched on its own terms: recorded instruments, the tax roll, civil filings, license and registration indexes. Two of the four addresses vanish under that scrutiny. One survives, attached to a document that names the subject and carries a date.
Report the address with its evidence attached
The deliverable names the surviving address, the record that supports it, the office that holds that record and the date it was filed. Most requests come back within 24 hours. The header never appears as the authority for anything.
Our role, stated without softening
This subject sits closer to regulated territory than anything else we write about, so the boundaries are set out in full rather than summarized.
Records research is what we do, and it is all we do. We are not licensed private investigators and do not present ourselves as such. There is no surveillance here, no interviewing, and none of the other investigative activity a license exists to authorize. Locating a person and confirming an address out of records, under a purpose the requester can state, is the entire scope of the engagement.
We are not a consumer reporting agency, and no deliverable of ours is a consumer report. That boundary carries more weight on this page than on any other we publish, because the record under discussion originates inside a consumer file. Do not route our output into an eligibility decision the Fair Credit Reporting Act governs — not partially, not as one input among several. Concretely: no tenant screening and no rental or housing decision; no employment, promotion, retention, contractor or volunteer screening; no credit or insurance underwriting and no account review; no professional licensing or government benefit determination; and nothing else the Act covers. Where the real question is whether to approve somebody rather than where to find them, the lawful route runs through a consumer reporting agency operating under the Act, with the consent, disclosure and adverse action machinery that comes with it. We will point you there instead of taking the file.
We never obtain information by pretext. 15 U.S.C. 6821 makes it a violation to obtain or attempt to obtain customer information of a financial institution by making a false, fictitious or fraudulent statement to an officer, employee or agent of the institution or to one of its customers, and subsection (b) makes it a violation to ask somebody else to do it on your behalf. We do not impersonate anyone, we do not call under a false identity, and we do not brief a third party to do either. This is not a policy we adopted; it is a federal prohibition with a named section, and it is the practical reason header data cannot be talked out of an institution by anyone.
We do not touch private financial contents. No balances, no limits, no payment history, no account numbers, no inquiry records. A locate needs identity and geography, and the rest of the file is neither.
We decline safety-sensitive requests. Where the circumstances suggest that finding a person would put them at risk, including domestic violence, stalking or a protective order matter, we decline the assignment and refer the requester to law enforcement, the court handling the case, or a victim services advocate. We do not attempt to defeat address confidentiality protections, and this page deliberately contains no method for doing so. If you are the person at risk rather than the one searching, the same referral applies and we would rather you have it than a records file.
This page is general information and is not legal advice. It describes federal statutes and a federal regulation as written, and quotes them so you can read the text yourself, but whether a particular purpose is permissible in a particular matter is a question for your counsel. Sector-specific rules also sit alongside these: driver and vehicle records, for instance, run on their own federal statute rather than on either of the two discussed here, which our Driver’s Privacy Protection Act guide covers separately.
Who arrives at this page with a real purpose
Six requester types whose matters routinely support a documented purpose, and what the header contributes to each.
Creditors enforcing a judgment
Collection of an account is a listed circumstance. The header narrows which county to work.
Agencies that already purpose-code
Certifications and audit trails are part of the workflow. The discipline this record adds is reading report dates.
Counsel with a party to reach
A defendant to serve or a witness to subpoena. What goes in the affidavit is the record behind the address, never the header entry.
Servers deciding which door first
A wrong attempt costs a trip and a fee. When four addresses come back, the report dates set the running order.
Estate administrators tracing heirs
Beneficiaries who have moved, and often elderly ones. Thin or absent files are common here, so other sources carry the search.
Recovery and subrogation desks
A responsible party who moved between the loss date and the claim. Rebuilding that interval is the whole task.
None of those six can file a header entry anywhere. Each of them has to hand a judge, an opposing party or an auditor an address with a source attached, which is why the header ends every one of these matters as a search instruction rather than as the answer. Where the whole file turns on one party and one address, our page on how to find a defendant’s address works that narrower problem through.
An address you can point at a source
Every address leaves here attached to the document behind it: which record, which office holds it, what date it bears. Check that yourself, or hand it to whoever will. And when a file has no answer that survives the checking, we say so and close it — an unconfirmed header entry is not a finding, and we will not invoice one as though it were.
Questions people ask about header data
What is a credit header record?
It is the identifying block at the top of a consumer credit file: the name or names furnishers have keyed for a person, the addresses they have reported with the dates of those reports, a date of birth, telephone numbers, and where a furnisher supplied one an employer recorded at application time. It sits above the tradelines, which are the accounts, balances and payment history that make up the credit report proper. The header is about who and where; everything under it is about money.
Is credit header data covered by the Fair Credit Reporting Act?
The long-running industry position is that identifying data alone does not bear on creditworthiness and is not collected to decide eligibility, so it falls outside the consumer report definition in 15 U.S.C. 1681a(d)(1). Whether or not that is right, it does not settle the question, because the Gramm-Leach-Bliley Act reaches the same data by a different route: Regulation P lists information from a consumer report as personally identifiable financial information, which makes the header nonpublic personal information regardless of how the FCRA classifies it.
Can I buy credit header data about someone?
No. There is no lawful route for a member of the public, and the barrier is not price or paperwork. Under 15 U.S.C. 6802(c) and 12 CFR 1016.11, a party who receives nonpublic personal information under an exception may only use and pass it on within that exception, so the restriction travels with the record to every recipient in the chain. Nobody who holds it can sell you a copy stripped of that condition. Sites offering header data for a card payment are not selling what they say they are.
Does a credit header include a Social Security number?
The underlying file does contain that field, and it is a large part of why header matching is accurate. It is also the reason the record is regulated as sensitive. We do not request it, use it as a search input, display it in a deliverable or report it to a client, and we publish nothing about working with it. Any resource that offers a technique built on that field is describing something you should not do and we will not do.
Did the CFPB change the rules on credit header data?
No. In December 2024 the Bureau proposed treating personal identifiers, including credit header data, as a consumer report under the Act. That proposal was withdrawn on 15 May 2025 and never took effect. Commentary describing the change as current or imminent is out of date. The framework that actually restricts the data today is the one that was already in place: the FCRA governs consumer reports and permissible purposes, and Gramm-Leach-Bliley plus Regulation P govern the header as nonpublic personal information.
How current is the address on a credit header?
It is exactly as current as the last furnisher report, which is not the same as the last move. The block updates when a lender submits an address, so an active borrower generates fresh entries and somebody who has stopped opening accounts does not. A header can therefore present a years-old address with the same confident formatting as a recent one. Read the report date first and treat the address itself as the second piece of information, not the first.
Why would a header search return nothing for a real person?
Because the person has no file to have a header on. A file is created by furnisher reporting, so someone who has never held credit in their own name, who has only ever been an authorized user on another person’s account, who arrived in the country recently, or who has used cash for many years may simply not be there. A blank result is a statement about the credit system’s coverage. It is not evidence that a person is concealing anything, and treating it that way leads to bad conclusions.
Can I use a header address for a tenant or employment decision?
No. This is the boundary we hold hardest, so read it twice. We hold no consumer reporting agency status and issue nothing that qualifies as a consumer report, which puts every eligibility use out of bounds: tenant screening, employment or volunteer screening, credit and insurance decisions, and any other determination the Fair Credit Reporting Act reaches. Decisions of that kind require an agency operating under the Act, with the consent, disclosure and adverse action steps it prescribes. A locate answers where somebody is. It is not a basis for deciding anything about them.
Have a purpose? Let us do the pull properly.
Tell us the matter and the basis for it, and we will tell you before any work starts whether the header is even the right place to begin. Plenty of files are better served by records that have nothing to do with lending. Send us the details and you will get a straight answer either way.
Start a locate request