
Short answer: After the Homebuyers Privacy Protection Act (HBPPA), loan officers should treat mortgage trigger-lead activity as a legal and operational review question, not as a simple replacement for a purchased-lead campaign. The safer operating path is to document the lead source, confirm the applicable relationship or authorization, review the intended use with qualified counsel, and build first-party borrower and partner workflows that can be measured separately.
This checklist is operational guidance for mortgage professionals. It is not legal advice and does not determine whether a specific alert, report, contact, or campaign is permitted. The enacted law, applicable FCRA provisions, other federal and state requirements, company policy, and source-provider documentation should be reviewed before a workflow is activated.
What changed for mortgage teams
The HBPPA changed the conditions under which consumer reporting agencies may furnish mortgage-related trigger-lead information after a residential mortgage credit inquiry. The practical result for an MLO is that a broad third-party trigger-lead workflow should not be treated as interchangeable with a known borrower relationship, a documented authorization, or an existing customer process.
The first question is not whether a CRM can receive a signal. The first question is whether the team has a documented basis to receive, use, and act on that information in the specific situation. A CRM can organize evidence and review steps, but it does not decide the legal status of a record.
Source hierarchy for the checklist
| Source | Use it for | Operating rule |
|---|---|---|
| Public Law 119-36 | Enacted statutory text and definitions. | Start with the law before relying on a summary. |
| FCRA Section 604 reference | Existing consumer-reporting context. | Confirm the current legal framework with counsel. |
| Source-provider agreement and documentation | What data is supplied, to whom, and under what controls. | Do not infer permission from a product label or integration logo. |
| Company compliance policy | Internal approval, retention, and outreach rules. | Use the stricter approved process when sources conflict. |
Five questions before activating an alert workflow
- What is the source? Record the provider, signal type, delivery date, and the exact documentation supplied with the data.
- What relationship or authorization is being relied on? Identify whether the record is an existing borrower, current customer, servicer relationship, documented authorization, or another category counsel has approved.
- What is the intended use? Write down whether the workflow creates a task, sends a message, routes a lead, updates a record, or triggers another action.
- Who approved the workflow? Name the compliance or legal owner, product owner, and operational owner. Do not leave approval implied.
- How is the decision recorded? Keep the source, eligibility state, review date, disposition, and suppression outcome connected to the record.
What to build instead of a single-source acquisition plan
Mortgage teams should build a balanced acquisition and relationship system. That can include documented referrals, consent-aware inbound inquiries, past-client education, partner follow-up, annual mortgage review programs, and a carefully controlled database recapture process. These are not legal substitutes for a permitted trigger-lead workflow. They are separate channels that should be measured on their own terms.
| Workflow | Useful operating evidence | Review question |
|---|---|---|
| Past-client recapture | Relationship type, last interaction, owner, approved channel, suppression status. | Why is this known relationship entering the workflow? |
| Referral-partner follow-up | Partner identity, source, activity history, permission and message review. | Does the follow-up match the partner relationship and policy? |
| Inbound lead routing | Form source, timestamp, consent record, assigned owner, first human action. | Can the team prove where the inquiry came from? |
| Annual mortgage review | Customer status, review date, reason for contact, outcome, opt-out. | Is the workflow based on an existing relationship and approved purpose? |
MLO implementation checklist
- Create a source register for every alert or lead feed.
- Keep relationship and authorization fields separate from general contact data.
- Use explicit states such as needs review, approved for workflow, suppressed, and rejected.
- Log who reviewed a record and when the decision was made.
- Separate signal receipt from automatic outreach.
- Make opt-outs and suppression updates visible to every downstream workflow.
- Measure first-party database activity separately from purchased or third-party lead activity.
- Re-review the workflow when the law, vendor documentation, product behavior, or company policy changes.
How a mortgage CRM can support the process
A mortgage CRM can provide the record structure, ownership, activity history, review queue, suppression state, and measurement layer that a controlled workflow needs. It should make it easier to see what is known, what is missing, what needs approval, and what should stop. It should not be presented as a legal decision engine.
The BNTouch mortgage database recapture workflow describes a 30/60/90-day operating sequence. The database recapture benchmark worksheet explains how to define a cohort and denominator. Teams evaluating the product can request a configuration-specific review through the BNTouch demo request process.
Questions for legal, compliance, and vendors
- Which exact data element is being delivered?
- What relationship, authorization, or other statutory basis is documented?
- What records must be retained to support the decision?
- Which actions are allowed automatically, and which require human review?
- How are opt-outs, disputes, and corrections propagated?
- Which jurisdictions, investor rules, and company policies add requirements?
- What happens when source documentation is missing or contradictory?
Important: HBPPA, FCRA, TCPA, RESPA, CAN-SPAM, state law, investor requirements, and company policy can intersect differently by workflow. Have qualified counsel and the responsible compliance owner review the exact process before activation.