Every account carries legal exposure the moment it moves past due, whether you collect it in-house or place it with a partner.
That exposure runs through the Fair Debt Collection Practices Act (FDCPA), Regulation F, the Fair Credit Reporting Act (FCRA), and state law. The litigation under these laws keeps climbing, too. FCRA filings rose 37.4% year over year in 2025, while FDCPA filings rose 7.8%, per the WebRecon 2025 Litigation Review.
Compliance exposure is a growing worry for any business managing receivables, and a partner’s mistake still lands on your desk.
This guide covers which laws apply to your collection activity and what your team or partner can and cannot do. It also shows how to check a partner’s compliance before you place accounts.
What are the laws for collecting a debt?
Laws for collecting a debt are the federal and state rules that limit collection activity. They govern how a creditor or its collection partner may contact, report, and pursue payment on an unpaid account.
The core federal law is the Fair Debt Collection Practices Act (FDCPA), enforced through Regulation F, with states adding a layer of their own.
Four layers make up that framework:
- Federal statute: The FDCPA sets the baseline obligations for collection communication and practice.
- Federal implementing rule: Regulation F operationalizes the FDCPA with specific requirements, like contact frequency limits and electronic opt-outs.
- State law: Many states pass their own mini FDCPA statutes, and some go further than federal law.
- Credit reporting law: The Fair Credit Reporting Act (FCRA) governs how collection accounts get furnished, maintained, and disputed on a credit report.
One distinction matters before you go further: not every layer applies to every collector. As per the ACA International FDCPA Compliance Center, the FDCPA and Regulation F regulate third-party debt collectors specifically.
That line decides what applies in-house versus what applies once you place the account.
The federal laws that govern debt collection
Which federal law applies depends on who is collecting the debt and at what stage. Four statutes make up the federal compliance stack, and each one covers a different piece of the process. Skipping any one of them because it “doesn’t seem relevant” is usually where exposure starts.
- Fair Debt Collection Practices Act (FDCPA): governs third-party debt collectors and debt buyers directly, setting the baseline obligations for outsourced collection activity under 15 U.S.C. § 1692. If you place accounts with an outside partner, this is the law your vendor’s entire contact strategy has to be built around. This includes covering everything from what they can say on a call to how they identify themselves.
- Regulation F: the Consumer Financial Protection Bureau (CFPB)’s rule that operationalizes the FDCPA, laid out under 12 CFR Part 1006. It sets the seven-contacts-in-seven-days limit and requires an opt-out on every electronic message. It also modernized the FDCPA for digital channels, giving collectors a defined path to use email, text, and other electronic communication instead of relying on calls and letters alone. For a vendor running any real volume of outreach, this rule is what turns “we follow the FDCPA” into a specific, auditable set of controls.
- FCRA: governs how reporting information gets furnished, maintained, and disputed under 15 U.S.C. § 1681c. That covers any collection account reported to a credit bureau, including how quickly a dispute has to be investigated and how a resolved or paid account gets updated. This matters even after an account is collected, since inaccurate reporting can create liability long after the balance is settled.
- TCPA: restricts autodialed and prerecorded calls or texts sent without consent under 47 U.S.C. § 227. It applies regardless of who owns the account, whether that’s an in-house team or an outside partner, and it operates independently of the FDCPA. A collector can be fully FDCPA-compliant and still violate the TCPA if consent for automated outreach was never properly captured or documented.
A compliant program treats these four laws as one system, not four separate checklists. Contact windows, channel opt-outs. Consent records must hold up against every law at once, and a gap in one usually creates exposure under another.
FCS builds compliance controls into its contact workflows. This includes call-frequency controls, consent documentation, opt-out management, and audit trails, while accounting for applicable federal and state requirements.
That is what separates a partner managing compliance as one connected system from one treating each law as a separate, disconnected checkbox.
What your collection practices must and must not include

Regulation F and the FDCPA draw the line clearly on what debt collectors can and cannot do.
Generally permitted:
- Contacting the account holder by phone, mail, email, text, and certain social media messages, within the required windows
- Furnishing qualifying account information to consumer reporting agencies
- Setting up payment plans, promise-to-pay arrangements, and settlement offers
- Pursuing lawful remedies where state and federal law allow it, as outlined in the CFPB Regulation F final rule
Generally prohibited:
- Harassment or abuse, including repeated or continuous calls intended to annoy the account holder
- More than seven calls about one debt within seven consecutive days, or a call within seven days of a prior conversation about that debt under Regulation F § 1006.14.
- False or misleading statements, including misstating the amount owed or implying legal action that is not planned
- Charging pay-to-pay fees unless the agreement creating the debt expressly allows it
- Contact before 8 a.m. or after 9 p.m. local time, or disclosing the debt to third parties beyond permitted exceptions under Regulation F § 1006.6.
Here’s how those obligations map to the statute, side by side:
| Permitted | Prohibited |
| Phone, mail, email, text, or approved social media contact | Repeated or continuous calls meant to harass, as per 15 U.S.C. § 1692d |
| Contact between 8 a.m. and 9 p.m. local time, as per 15 U.S.C. § 1692c | Contact before 8 a.m. or after 9 p.m. local time |
| Up to seven calls about one debt in seven days, as per 12 CFR § 1006.14 | An eighth call, or a call within seven days of a prior conversation |
| Accurate statements about the balance owed, as per 15 U.S.C. § 1692e | False or misleading statements about the debt |
| Furnishing qualifying data to credit bureaus | Disclosing the debt to unrelated third parties |
| Fees expressly authorized by the debt agreement, as per the CFPB Advisory Opinion on Pay-to-Pay Fees | Pay-to-pay fees the agreement does not authorize |
| Settlement offers and payment plans | Implying legal action that is not planned or possible |
| Lawful remedies permitted under state or federal law | Threats to take action the collector cannot legally take |
| Did you know? The FDCPA includes a bona fide error defense. A collector is not liable for a violation that was unintentional and resulted from a genuine error, but only if the collector kept procedures reasonably designed to avoid that kind of error, as per 15 U.S.C. § 1692k(c). |
A documented, tested procedure is what turns an honest mistake into a defensible one. Without it, the same error becomes a violation.
FCS follows this approach by embedding documented compliance procedures and ongoing oversight into its collection operations.
State debt collection laws and mini FDCPAs
Federal law sets the baseline for debt collection rules by state, and states may add requirements or extend broader obligations on top of that baseline, as per 12 CFR § 1006.104. If you collect across multiple states, review the licensing and collection requirements in every state where you place accounts.
That distinction matters because some states extend FDCPA-style obligations to original creditors doing their own first-party collection. That is a meaningful gap if your business collects in-house rather than through a third-party partner. Check your state’s rules before assuming federal law alone covers your internal collection activity.
The same state-by-state differences can affect who is authorized to collect. Many states require collection agencies to hold a license, registration, or bond before they can operate. Confirm that any partner you use is authorized to collect in every state where you place accounts.
Licensing tells you who can collect. Statute of limitations tells you how long that collection window stays open.
Statute of limitations and time-barred debt
The statute of limitations varies by state and by type of debt. Do not apply a single nationwide timeframe to every account in your portfolio.
Regulation F prohibits a collector from bringing or threatening legal action to collect a time-barred debt, as per 12 CFR § 1006.26. If you use a third-party collector, confirm they have a process to flag potentially time-barred accounts before escalation.
Build statute-of-limitations tracking into your placement and vendor-management process from the start. This matters most for portfolios that span several states, where limitation periods differ account by account.
How to audit a collection partner’s compliance

Choosing a collection partner means inheriting their compliance posture along with their recovery results. A documented, verifiable process protects you both.
Before you place accounts, ask your partner to show you:
- Documented Regulation F contact frequency controls, not just a policy statement
- Proof of state licensing and bonding in every state where you place accounts
- Timing requirements for initial account communication built into their standard workflow
- Evidence of consent tracking and electronic opt-out handling
- Fee practices that are disclosed and compliant with the pay-to-pay prohibition
That documentation matters beyond the sales conversation. If your partner’s practices trigger an FDCPA violation, your business often shares reputational and contractual exposure, even when the fault sits with the vendor.
This is the same standard you should hold any partner to: checkable, documented, and built into day-to-day operations rather than asserted once during a sales call. A strong debt collection compliance program holds up under that kind of direct verification. If a partner cannot produce the documentation, treat that as a red flag rather than a formality.
FCS builds these same controls, consent tracking, frequency limits, and channel orchestration, directly into its platform as accounts move, so compliance travels with the account instead of sitting on the client to monitor.
Conclusion
Staying compliant with debt collection laws comes down to three things. Know which laws apply to your collection activity. Understand the operational obligations they create and then confirm that whoever handles your accounts is meeting them.
The FDCPA, Regulation F, the FCRA, the TCPA, and the relevant state statutes are not separate boxes to check. They function as one system, and a compliant program treats them that way, in-house or outsourced.
A partner operating within every obligation covered here is the standard to expect, not the exception. That is the baseline for evaluating any collection partner, and it should shape how you place accounts going forward.
Considering how a partner handles compliance risk? See how FCS handles compliant account placement by connecting with the team today.
FAQs
1. What laws govern how a business or its collection partner can pursue a debt?
The primary federal laws are the FDCPA, Regulation F, the FCRA, and the TCPA, along with state debt collection statutes. Together, they set the obligations a business and any third-party collector must follow when contacting, reporting, or pursuing payment on an account, regardless of collection stage.
2. Does the FDCPA apply to in-house, first-party collection?
No. The FDCPA regulates third-party collectors and debt buyers, not original creditors collecting their own debt. Some states extend similar obligations to first-party collection through their own mini FDCPA statutes, so this needs to be checked on a state-by-state basis before assuming coverage.
3. What happens if a collection partner violates the FDCPA?
Violations can result in actual damages, statutory damages up to $1,000 per action, and attorney’s fees. Businesses that outsource collection should also weigh contractual, regulatory, and reputational exposure when a vendor fails to follow required collection practices, since that exposure often lands on the business too.
4. What should a business check before hiring a debt collection agency?
Businesses should evaluate an agency’s compliance controls, state licensing, collection practices, reporting capabilities, data security, fee structure, and experience with similar portfolios. A strong partner documents these processes with evidence rather than simply describing them during the sales conversation.
5. Do debt collection compliance requirements differ by state?
Yes. Federal law sets a baseline, but states can add licensing, bonding, and disclosure requirements on top of it. Some states also extend protections to first-party collection that federal law doesn’t cover, so multi-state operations need a process built for that variation.
6. How long can a business legally pursue a debt before it’s considered time-barred?
The statute of limitations depends on the state and type of debt involved. Regulation F restricts collectors from bringing or threatening legal action on time-barred debt, so businesses should have a process to flag potentially time-barred accounts before escalating to legal action.

