Privacy Act of 1974; System of Records
Primary source
Metadata and text below are from the Federal Register, a public-domain U.S. government work. Always verify the official published version before relying on it for any legal matter.
Issuing agencies
Abstract
As required by the Privacy Act of 1974, as amended, and the Office of Management and Budget (OMB) Circulars A-108 and A-130, the Peace Corps Office of Planning and Performance (OPP) is issuing a public notice of its new system of records Peace Corps Customer Relationship Management (Agency CRM) System of Records "("PC 38"). The Office of Planning and Performance (OPP) manage and utilizes a management database system to monitor, track, and analyze all interactions with prospective and current Peace Corps applicants from the time they visit the agency website, its social media pages, apply for volunteer service and their volunteer activity throughout their volunteer service. This system of records contains information on members of the public who become leads and visit the Peace Corps websites, social media pages and apply to become applicants as well as those who are current volunteers and through completion of volunteer service.
Full Text
<html>
<head>
<title>Federal Register, Volume 91 Issue 185 (Friday, September 25, 2026)</title>
</head>
<body><pre>
[Federal Register Volume 91, Number 185 (Friday, September 25, 2026)]
[Notices]
[Pages 60992-60995]
From the Federal Register Online via the Government Publishing Office [<a href="http://www.gpo.gov">www.gpo.gov</a>]
[FR Doc No: 2026-19684]
=======================================================================
-----------------------------------------------------------------------
PEACE CORPS
Privacy Act of 1974; System of Records
AGENCY: Peace Corps.
ACTION: Notice of a new system of records.
-----------------------------------------------------------------------
SUMMARY: As required by the Privacy Act of 1974, as amended, and the
Office of Management and Budget (OMB) Circulars A-108 and A-130, the
Peace Corps Office of Planning and Performance (OPP) is issuing a
public notice of its new system of records Peace Corps Customer
Relationship Management (Agency CRM) System of Records ``(``PC 38'').
The Office of Planning and Performance (OPP) manage and utilizes a
management database system to monitor, track, and analyze all
interactions with prospective and current Peace Corps applicants from
the time they visit the agency website, its social media pages, apply
for volunteer service and their volunteer activity throughout their
volunteer service. This system of records contains information on
members of the public who become leads and visit the Peace Corps
websites, social media pages and apply to become applicants as well as
those who are current volunteers and through completion of volunteer
service.
DATES: Submit comments on or before October 26, 2026 This new system
will be effective October 26, 2026.
ADDRESSES: Send written comments, identified by the docket number and
title, to the Peace Corps, ATTN: James Olin, Government Information
Specialist, Office of Compliance and Risk, 1275 First Street NE,
Washington, DC 20526, or by email at <a href="/cdn-cgi/l/email-protection#08786b6e7a48786d696b6d6b677a787b266f677e"><span class="__cf_email__" data-cfemail="6d1d0e0b1f2d1d080c0e080e021f1d1e430a021b">[email protected]</span></a>. Email
comments must be made in text and not in attachments.
FOR FURTHER INFORMATION CONTACT: James Olin, Government Information
Specialist, Office of Compliance and Risk, 1275 First Street NE,
Washington, DC 20526; <a href="/cdn-cgi/l/email-protection#6111020713211104000204020e1311124f060e17"><span class="__cf_email__" data-cfemail="80f0e3e6f2c0f0e5e1e3e5e3eff2f0f3aee7eff6">[email protected]</span></a>; or 202-692-2507.
SUPPLEMENTARY INFORMATION: Section 5 of the Peace Corps Act of 1960, as
amended (codified as 22 U.S. Code Sec. 2504) authorizes the
recruitment and enrollment of Peace Corps volunteers. Under this
section, the agency is granted the authority to enroll qualified United
States citizens and nationals for service abroad, and the operational
power to select, train, and manage volunteers. As part of the
Recruitment Analytics and Identity Resolution Initiative (RAIRI) the
agency will sync anonymized Client IDs, currently assigned to leads,
with the non-anonymized lead records stored in Peace Corps' customer
relationship management database, and with applicant tracking internal
systems, PCrm, Volunteer Applicant Tracking System (DOVE) and Medical
Applicant Exchange System (MAXx).
Pursuant to the Privacy Act of 1974 (5 U.S.C. 552a(e)(4)), which
governs the collection and protection of personal information by
federal agencies, the Peace Corps is establishing a new system of
records to manage personal information from members of the public who
become leads and applicants who interact with Peace Corps' website,
social media and volunteer recruitment activities. The system will also
track applicant responses to recruitment methods, progress through the
application process, and completion of volunteer service. This system
will connect lead and applicant data,
[[Page 60993]]
training, and volunteer service to optimize recruitment strategies and
assess applicant and volunteer retention and volunteer program
outcomes. It will also integrate internal platforms, including PCrm,
Volunteer Information Database Application (VIDA), Security Incident
Management System (SIMS), Peace Corps Recruitment and Marketing (PCrm),
Returned Peace Corps Volunteer Outreach (RPCV Outreach), the Director's
Correspondence Log, MAXx and DOVE, to track applicant communications
with staff regarding applications, medical clearance, and program
success. This initiative underscores the agency's commitment to
safeguarding personal information and improving operational
effectiveness.
SYSTEM NAME AND NUMBER:
Peace Corps Customer Relationship Management System of Records
(Agency CRM), PC-38.
SECURITY CLASSIFICATION:
Moderate.
SYSTEM LOCATION:
Records are maintained in an electronic form on a Software as a
Service (SaaS) platform under contract with the Peace Corps, Office of
Information Systems, 1275 First St. NE, Washington, DC 20002.
SYSTEM MANAGER(S):
The Director of Office of Planning and Performance, and the Chief
Information Officer, Office of Information Systems, Peace Corps, 1275
First St. NE, Washington, DC 20002.
AUTHORITY FOR MAINTENANCE OF THE SYSTEM:
Section 4 of the Peace Corps Act of 1961, as amended (22 U.S.C.
2504; the Privacy Act of 1974, 5 U.S.C. 552a, and Peace Corps Manual
Section (MS) 129: Office of Information Systems and MS 542: Information
Security Program.
PURPOSE(S) OF THE SYSTEM:
The Peace Corps will utilize this system to effectively track,
monitor, and analyze interactions with both potential and current
applicants and volunteers. The primary purpose of the system is to
support the recruitment and retention process, and gain insight into
the best practices in marketing, recruitment, onboarding, retention,
and volunteer matriculation throughout the entire duration of volunteer
service. By collecting, managing, and analyzing the aggregation of
these records and data points, the Peace Corps aims to improve
operational efficiency, maintain accurate documentation, and uphold
best practices for volunteer recruitment, engagement and retention.
CATEGORIES OF INDIVIDUALS COVERED BY THE SYSTEM:
This system covers members of the public who interact with the
agency 's social media and website, and are assigned a client ID
through Google Analytics; applicants, trainees, and volunteers of the
Peace Corps; authorized users who access Peace Corps computer networks,
enterprise servers, or certain agency database systems related to
applicants, trainees and volunteers; and personnel responsible for
maintaining records, privacy and security, and software applications
within these network systems. In addition, this system includes
individuals who recruit prospective applicants and volunteers, as well
as those who analyze applicant and volunteer data for the purposes of
supporting recruitment, onboarding, retention, and program evaluation.
CATEGORIES OF RECORDS IN THE SYSTEM:
The Office of Information Systems is responsible for maintaining
the category of Peace Corps Customer Relationship Management System of
Records. This system includes information pertaining to members of the
public who become leads, applicants seeking to become volunteers,
trainees, volunteers, and returned Peace Corps volunteers. The system
maintains additional records after the leads become applicants, and
volunteers. These records may include personal identifiers such as
name, email address, home address, telephone number, Social Security
Number, demographic information (including race, ethnicity,
disabilities, etc.), birth date, marital status, fingerprints,
citizenship status, government-provided identification documents and
the Client ID provided by Google Analytics. The records may also
contain detailed information about applicants, trainees and volunteers
that include:
<bullet> Their application to become a volunteer (e.g., reason for
applying, educational history, employment history, military history,
prior community service activities, criminal history, medical history,
skills, certifications, and references, etc.).
<bullet> Peace Corps service history and experience (e.g.,
descriptions of activities, performance reviews, disciplinary concerns,
health related to volunteer service, reasonable accommodation, leave
requests, service-related travel and service training).
<bullet> Benefits (e.g., health benefits, stipends, loan
forbearance).
<bullet> Emergency contacts and beneficiaries.
Additionally, the system contains program participant descriptions
and information regarding recruitment program activities, as well as
details about services received by volunteer participants. The records
may also include information obtained after the completion of the
volunteer program.
The records maintained in this system also cover several aspects of
electronic communication and access within the Peace Corps. These
include documentation of interoffice and internet email activity, such
as the email addresses of both sender and receiver, the subject line,
and the date and time each message was sent or received.
Additionally, the system tracks user activity on Peace Corps
networks. Records include user identification, the date and time each
user logs on or logs off, and any instances where access to
unauthorized files or directories is denied. Internet access from Peace
Corps computers is also recorded, capturing the internet Protocol (IP)
address used, the specific sites accessed, and the corresponding date
and time of each connection.
Further records relate to system access, documenting the user ID of
individuals accessing the system, the date and time of access, and the
processes being run on the system. Verification and authorization
activities are also recorded, including details such as user IDs,
passwords, usernames, titles, and agency affiliations, to ensure proper
security and oversight of system access.
RECORD SOURCE CATEGORIES:
The Office of Information Systems is responsible for maintaining
the record source of categories for the Peace Corps Customer
Relationship Management System of Records. The source for information
in the system comes from the individuals who provide their information
or their representative. The information sources may also include
authorized Peace Corps staff members, contractors, Peace Corps
volunteers, and other individuals or entities associated with Peace
Corps and the internal electronic platforms such as PCrm, Medical
Applicant Exchange System (MAXx), Volunteer Applicant Tracking System
(DOVE) and Google Analytics. Most records are generated internally from
computer activity logs individuals covered by the system and management
officials.
[[Page 60994]]
ROUTINE USES OF RECORDS MAINTAINED IN THE SYSTEM, INCLUDING CATEGORIES
OF USERS AND THE PURPOSE OF SUCH USERS:
In addition to those disclosures generally permitted under 5 U.S.C.
552a(b) of the Privacy Act, the Peace Corps may disclose all or a
portion of the records or information contained in this system outside
of the Peace Corps without the consent of the subject individual, if
the disclosure is compatible with the purpose for which the record was
collected, as a routine use pursuant to 5 U.S.C. 552a(b)(3) as follows:
A. Disclosure for Law Enforcement Purposes. Information may be
disclosed to the appropriate Federal, State, local, or foreign agency
responsible for investigating, prosecuting, enforcing, or implementing
a statute, rule, regulation, or order, if the information indicates a
violation or potential violation of civil or criminal law or regulation
within the jurisdiction of the receiving entity.
B. Disclosure Incident to Requesting Information. Information may
be disclosed to any source from which additional information is
requested (to the extent necessary to identify the individual, inform
the source of the purpose(s) of the request, or to identify the type of
information requested); when necessary to obtain information relevant
to a Peace Corps decision concerning retention of an employee or other
personnel action (other than hiring), retention of a security
clearance, the letting of a contract, or the issuance or retention of a
grant or other benefit.
C. Disclosure to Requesting Agency. Information may be disclosed to
a Federal, State, local, or other public authority of the fact that
this system of records contains information relevant to the requesting
agency's retention of an employee, the retention of a security
clearance, the letting of a contract, or the issuance or retention of a
license, grant, or other benefit. The other agency or licensing
organization may then make a request supported by the written consent
of the individual for part or all of the record if it so chooses. No
disclosure will be made unless the information has been determined to
be sufficiently reliable to support a referral to another office within
the agency or to another Federal agency for criminal, civil,
administrative, personnel, or regulatory action.
D. Disclosure to Office of Management and Budget. Information may
be disclosed to the Office of Management and Budget at any stage in the
legislative coordination and clearance process in connection with
private relief legislation as set forth in OMB Circular No. A-19.
E. Disclosure to Congressional Offices. Information may be
disclosed to a congressional office from the record of an individual in
response to an inquiry from the congressional office made at the
request of the individual.
F. Disclosure for Litigation. Information may be disclosed for
litigation purposes. Disclosure for these purposes may be made to the
Department of Justice, or in a legal proceeding before a court,
adjudicative body, or other administrative body before which the Peace
Corps is authorized to appear. This disclosure may be made when: (1).
In any legal proceeding, where pertinent, to which Peace Corps or the
United States is a party before a court, tribunal or administrative
body; (2). any employee of the Peace Corps in his or her official
capacity with a need to know; (3). any employee of the Peace Corps in
his or her individual capacity where the Department of Justice or the
Peace Corps has agreed to represent the employee; or (4). when the
Peace Corps determines that litigation is likely to affect the Peace
Corps or any of its components and has an interest in such litigation,
and the use of such records by the Department of Justice or the Peace
Corps is deemed by the Peace Corps to be relevant and necessary to the
litigation.
G. Disclosure to the National Archives. Information may be
disclosed to the National Archives and Records Administration in
records management inspections.
H. Disclosure to Contractors, Grantees, and Others. Information may
be disclosed to contractors, grantees, consultants, or volunteers
performing or working under a contract, service agreement, grant,
cooperative agreement, job, or other activity for the Peace Corps and
who have a need to have access to the information in the performance of
their duties or activities for the Peace Corps. Recipients will be
required to comply with the requirements of the Privacy Act of 1974 as
provided in 5 U.S.C. 552a(m).
I. Disclosures for Administrative Claims, Complaints, and Appeals.
Information may be disclosed to an authorized appeal grievance
examiner, formal complaints examiner, intake officer, equal employment
opportunity specialist, investigator, arbitrator, or other person
properly engaged in investigation or settlement of an administrative
grievance, complaint, claim, or appeal filed by an applicant, employee,
or volunteer applicant, invitees, trainee or volunteer, but only to the
extent that the information is relevant and necessary to the
proceeding. Agencies that may obtain information under this routine use
include, but are not limited to: the Office of Personnel Management,
Office of Special Counsel, Federal Labor Relations Authority, U.S.
Equal Employment Commission, the Foreign Service Grievance Board and
Office of Government Ethics.
J. Disclosure to the Office of Personnel Management. Information
may be disclosed to the Office of Personnel Management pursuant to that
agency's responsibility for evaluation and oversight of Federal
personnel management.
K. Disclosure in Connection with Settlement. Information may be
disclosed in connection with settlement discussions regarding claims by
or against the Peace Corps, including public filings with a court, to
the extent that disclosure of the information is relevant and necessary
to potential litigation or settlement discussions and except where
court orders are otherwise required under Section (b)(11) of the
Privacy Act of 1974, 5 U.S.C. 552a(b)(11).
L. Disclosure to U.S. Ambassadors. Information from this system of
records may be shared with a U.S. Ambassador or their designated
representative in any country where the Peace Corps operates, when such
disclosure is necessary for the Ambassador to fulfill official duties,
respond to formal inquiries, or address in-country matters within their
area of responsibility.
M. To appropriate agencies, entities, and persons when (1) the
Peace Corps suspects or has confirmed that there has been a breach of
the system of records; (2) the Peace Corps has determined that as a
result of the suspected or confirmed breach, there is a risk of harm to
individuals, the Peace Corps (including its information systems,
programs, and operations), the Federal Government, or national
security; and (3) the disclosure made to such agencies, entities, and
persons is reasonably necessary to assist in connection with the Peace
Corps' efforts to respond to the suspected or confirmed breach or to
prevent, minimize, or remedy such harm.
N. Disclosure to another Federal agency or Federal entity, when the
Peace Corps determines that information from this system of records is
reasonably necessary to assist the recipient agency or entity in (1)
responding to a suspected or confirmed breach or (2) preventing,
minimizing, or remedying the risk of harm to individuals, the recipient
agency or entity (including its information systems, programs, and
operations), the Federal Government, or national
[[Page 60995]]
security, resulting from a suspected or confirmed breach.
POLICIES AND PRACTICES FOR STORAGE OF RECORDS:
All records are stored electronically in a Federal Risk and
Authorization Management Program (FedRAMP) Certified Class D (High)
Software as a Service (SaaS) data backup and recovery solution cloud
service offering. As a FedRAMP Class D (High) certified solution all
records are protected according to federal guidelines. All
electronically stored records are encrypted both at rest and in transit
using FIPS 140-3 authorized encryption standards. The SaaS cloud
service offering leverages a FedRAMP Certified Infrastructure as a
Service (IaaS) as its primary hosting environment, a dedicated cloud
IaaS for U.S Government workloads. Physical security controls to the
system includes high security locks, reinforced doors, 24 hours
security guard management, and PIV cards to access the room.
POLICIES AND PRACTICES FOR RETRIEVAL OF RECORDS:
Records may be retrieved by name, Client ID, email address, or
other personal or unique identifier.
POLICIES AND PRACTICES FOR RETENTION AND DISPOSAL OF RECORDS:
Records in the Volunteer Information Database Application (VIDA)
Records (will be cut off at the end of the fiscal year in which the
Volunteer is separated or resigns. These records will be destroyed 6
years after cutoff.
Records in the Security Incident Management System (SIMS) Will be
cut off when the final action is taken on a case or when the system is
decommissioned. These records will be destroyed no sooner than 10 years
after cutoff but a longer retention is authorized. Recruitment Records
will be cut off at the end of the fiscal year. These records will be
destroyed 6 years after cutoff.
The Returned Peace Corps Volunteers Career Link Database Master
File will be cut off at the end of each calendar year. These records
will be destroyed 6 years after cutoff.
The Executive Correspondence Log will be cut off at the end of each
presidential administrative term. The records will be transferred to
the National Archives 20 years after the end of the presidential
administration.
The Database of Volunteer Experience (DOVE) will be cutoff at the
end of the fiscal year in which the final action is taken on the
application. These records will be destroyed 6 years after cutoff.
The records in MAXx will be cutoff upon the Close of Service (COS)
or termination of the Peace Corps Volunteer. These records will be
destroyed 50 years after cutoff.
The Applicant Medical Case Files will be destroyed 7 years after
either a final decision is rendered for a rejected applicant or Close
of Service for a successful applicant.
Records in the Volunteer Reporting and Grants (VRG) will be
destroyed 10 years after the final action is taken if the Applicant is
successful. The records will be destroyed 3 years after the final
action is taken if the Applicant is unsuccessful.
Records in the Peace Corps Volunteer Database Management System
(PCVDBMS) will be transferred to the National Archives on an annual
basis.
Peace Corps Customer Relationship Management System of Records is
currently unscheduled and no data is authorized for destruction until
the National Archives and Records Administration approves a disposition
schedule.
Google Analytics retains Client IDs and associated data for a
maximum of 26 months before deletion.
ADMINISTRATIVE, TECHNICAL, AND PHYSICAL SAFEGUARDS:
The Peace Corps safeguards records in this system in accordance
with applicable laws, rules, and policies to protect personally
identifiable information against unauthorized access or disclosure.
Specifically, the agency's security and privacy controls comply with
NIST 800-53, rev. 5--Security and Privacy Controls for Federal
Information Systems and Organizations. The Peace Corps has imposed
strict controls to minimize such risks. Administrative safeguards
include but are not limited to: access to the information in this
system is limited to authorized personnel with official duties
requiring access, and whose roles have been authorized with such access
permissions. All such individuals receive the appropriate privacy and
cybersecurity training on an annual basis.
The physical controls in place include the servers storing
electronic data are located offsite in a locked facility with access
limited to authorized personnel. The servers are maintained in
accordance with a government contract that requires adherence to
applicable laws, rules, and policies on protecting individual privacy.
Computerized records are safeguarded in a secured environment. Security
protocols meet the promulgating guidance as established by the National
Institute of Standards and Technology (NIST) Security Standards from
Access Control to Data Encryption and Security Assessment and
Authorization and Peace Corps' privacy and security policies.
The technical controls in place include multiple firewalls, system
access, encrypted data at rest, encrypted data in motion, periodic
vulnerability scans to ensure security compliance, and security access
logs. Access is restricted to specific authorized Peace Corps
individuals who have internet access through work on computers using
Personal Identity Verification (PIV). Individual users can only access
records with the proper pre-approved accreditation. Physical security
measures include but are not limited to the use of data centers which
meet government requirements for storage of sensitive data.
RECORD ACCESS PROCEDURES:
Any individual who wants access to his or her record should make a
written request to the System Manager. Requesters will be required to
provide appropriate identification, such as a driver's license,
employee identification card, or other authorized identifying
documentation. Additional identification may be required in some
instances. Complete Peace Corps Privacy Act procedures are set out in
22 CFR part 308.
CONTESTING RECORD PROCEDURES:
Individuals seeking to challenge the contents of a record after its
submission to the system must submit a written request to the system
manager. The request should include sufficient identification, such as
a driver's license, employee identification card, or other official
documentation; in certain cases, additional identification may be
required. Requests for correction or amendment must clearly specify the
record in question and the desired corrective action. For comprehensive
guidance, refer to the Peace Corps Privacy Act procedures outlined in
22 CFR part 308.
NOTIFICATION PROCEDURES:
See ``Record Access Procedures.''
EXEMPTIONS PROMULGATED FOR THE SYSTEM:
None.
HISTORY:
None.
Dated: September 23, 2026.
James Olin,
Government Information Specialist.
[FR Doc. 2026-19684 Filed 9-24-26; 8:45 am]
BILLING CODE 6051-01-P
</pre><script data-cfasync="false" src="/cdn-cgi/scripts/5c5dd728/cloudflare-static/email-decode.min.js"></script></body>
</html>This is legal information, not legal advice. Laws vary by jurisdiction and change frequently. Always verify current law with official sources and consult a licensed attorney in your jurisdiction for advice on your specific situation.