Peace Corps Notice PC-38 of 25 September 2026 Links Google Analytics Client IDs to Its Medical Applicant System, Where Records Stay 50 Years: How Long Must the Encryption Hold?
The United States Census Bureau collects some of the most personal facts a government holds, and the law keeps the individual returns closed for 72 years. The National Archives explains that the restriction is the reason the most recent census open to the public is the one taken in 1950. Seventy-two years is close to a lifetime, so most people counted in a census never see their own answers made public.
On 25 September 2026 a much smaller agency published a retention period of comparable length for a very different kind of file. The Peace Corps' notice of a new system of records, PC-38, joins the identifier that Google Analytics gives a website visitor to named recruitment, applicant and medical records, and it keeps the medical applicant records for 50 years after a volunteer's service ends. The notice raises two questions. The first concerns privacy law and the second cryptography, and the answer to the second depends on the first.
Practical takeaway. PC-38 makes a Google Analytics Client ID a retrieval key for a file that can include medical history, disability, fingerprints and Social Security numbers. Its medical applicant records are kept until 50 years after close of service. Any cryptography protecting that file, in storage or in transit between the systems it links, has to be judged against that horizon. The life of the software that holds it is the wrong yardstick.
What PC-38 does: the Peace Corps notice in the Federal Register of 25 September 2026
The notice, Federal Register document 2026-19684 at 91 FR 60992, is issued by the Peace Corps Office of Planning and Performance under the Privacy Act of 1974 and OMB Circulars A-108 and A-130. It describes a database that will "monitor, track, and analyze all interactions with prospective and current Peace Corps applicants from the time they visit the agency website, its social media pages", through application and volunteer service. Comments are due by 26 October 2026, the same day the system takes effect.
The central sentence concerns what the agency calls the Recruitment Analytics and Identity Resolution Initiative. Under it, the Peace Corps "will sync anonymized Client IDs, currently assigned to leads, with the non-anonymized lead records" in its customer relationship management database and with three internal systems: PCrm, the Volunteer Applicant Tracking System (DOVE) and the Medical Applicant Exchange System (MAXx). The notice also lists the Security Incident Management System, the Volunteer Information Database Application and the Director's Correspondence Log among the platforms it will integrate, so that staff can follow "applicant communications with staff regarding applications, medical clearance, and program success."
The individuals covered begin with "members of the public who interact with the agency's social media and website, and are assigned a client ID through Google Analytics." The records may include name, address, Social Security number, race, ethnicity, disabilities, birth date, fingerprints, citizenship status, criminal history, medical history, health related to service and reasonable accommodation. Records "may be retrieved by name, Client ID, email address, or other personal or unique identifier."
Why the Privacy Act treats a joined Client ID differently from website analytics
The Privacy Act applies to a "system of records", which 5 U.S.C. 552a(a)(5) defines as records retrieved by an individual's name or by "some identifying number, symbol, or other identifying particular assigned to the individual." A Client ID that stays inside an analytics dashboard describes a browser. The notice lists the Client ID among the records in the system and among the keys by which a named person's file may be retrieved. In Quentir's reading, that makes the ID an identifying particular in the statute's sense once the join is made. For anyone else running marketing analytics beside personnel or health data, this is the most useful part of the document: a federal agency has put in writing that an identifier it calls "anonymized" will be synced with named records and used to retrieve them.
Two features of the statute limit what that recognition gives the people concerned. The access and amendment rights belong to an "individual", which section 552a(a)(2) defines as a US citizen or lawful permanent resident, so a website visitor who is neither can appear in the system without holding the statute's access and amendment rights. And the notice lists fourteen routine uses under which records may leave the agency without consent, including disclosure to law-enforcement agencies, to contractors, to the Office of Personnel Management and to US ambassadors in countries where the Peace Corps operates. The notice itself does not say at what point, or whether, a website visitor is told that a later application may be joined to the browsing history behind their Client ID.
How long the records last: 50 years for MAXx, 7 for applicant medical case files
The retention section is where the privacy question turns into an engineering one. Most categories are kept for six years after a cutoff, and the separate Applicant Medical Case Files are destroyed seven years after a final decision or close of service. The Medical Applicant Exchange System is the exception: its records are cut off at close of service or termination and "destroyed 50 years after cutoff." Take a volunteer who first visits the website in 2026, applies, and finishes service in 2029. That volunteer's MAXx records can lawfully exist until 2079. The notice does not say which schedule governs the Client ID link itself, or whether the link is copied into MAXx or held only in the CRM. That is one of the questions the comment period can put to the agency.
The notice states that records sit in a FedRAMP High cloud service and are "encrypted both at rest and in transit using FIPS 140-3 authorized encryption standards." The statement is an assurance about standards, and the notice names no algorithms, module certificates or migration plan. FIPS 140-3 validates cryptographic modules, and the approved algorithms such modules can run include the RSA and elliptic-curve schemes used to establish keys and sign data. NIST's draft transition guidance, IR 8547 (initial public draft, 12 November 2024), proposes that those schemes be deprecated after 2030 at the 112-bit security level and that all of them, at every strength, be disallowed after 2035.
Precision matters here. On current understanding, symmetric encryption of stored data, such as AES with 256-bit keys, holds up against known quantum attacks. Where the systems still rely on quantum-vulnerable public-key methods, the exposure sits in that layer: data exchanged between the CRM, DOVE, MAXx and the cloud provider under quantum-vulnerable key establishment can be recorded today and decrypted later, the harvest-now-decrypt-later pattern, and stored keys wrapped with RSA or elliptic-curve schemes inherit the same weakness. A 50-year retention period keeps MAXx records at rest for decades after 2035, and their protection then depends on that layer being replaced in time. For data in transit, what counts is how long the information stays sensitive, and medical history and disability status stay sensitive for a lifetime.
How Quentir Reads It
PC-38 is a routine document from a small agency. It sets out plainly a practice that many organizations follow without a notice: an anonymous marketing identifier is resolved to a person, the person's file grows to include health and identity data, and a retention schedule written for records management sets the confidentiality horizon. Quentir's Medicine Monitor made the general point in July in The Patient Record Outlives Its Encryption. This notice shows the same arithmetic in a recruitment system, where the medical content arrives with a job application.
The civic stake is concrete. The people in this system are mostly young Americans who volunteered for public service abroad, and the notice asks them to trust that their disability disclosures and medical history will stay confidential into their seventies. Whether that promise holds depends on two decisions the notice does not settle: how narrowly the Client ID join is used, and when the systems it connects move to post-quantum key establishment. The comment period closing on 26 October is the public's chance to ask about both.
For readers who need the migration side in fixed form, Quentir's Signature Brief editions on post-quantum transition add a fixed scope and dated sources, with a license for internal use. The question PC-38 leaves for every organization holding long-lived personal data is simple to state: which of its retention schedules runs past 2035, and what protects those records in the meantime.
Sources: Peace Corps, "Privacy Act of 1974; System of Records", notice of a new system of records, Peace Corps Customer Relationship Management System of Records (PC-38), Federal Register document 2026-19684, 91 FR 60992-60995 (25 September 2026; dated 23 September 2026), GPO text, for the Recruitment Analytics and Identity Resolution Initiative, the systems joined, the categories of individuals and records, retrieval by Client ID, the routine uses, the storage and encryption statement, the retention periods and the 26 October 2026 comment and effective date; Privacy Act of 1974, 5 U.S.C. 552a, subsections (a)(2) and (a)(5); NIST, IR 8547, "Transition to Post-Quantum Cryptography Standards" (initial public draft, 12 November 2024), for the proposed deprecation after 2030 of 112-bit RSA, elliptic-curve and finite-field schemes and disallowance of all of them after 2035 (Tables 2 and 4); National Archives, 1950 Census, for the 72-year access restriction; Quentir Medicine Monitor, "The Patient Record Outlives Its Encryption" (20 July 2026).
Published intelligence, built to inform your own decisions. Published: September 25, 2026.