Privacy Impact Assessment (PIA) for the

Private Collection Agencies (PCA's) 1/27/2020

Name/Title: Diana O'Hara Principal Office: Federal Student Aid (FSA)

1. Introduction 1.1. Describe the system including the name, acronym, and a brief description of the program or purpose for the system.

This Privacy Impact Assessment (PIA)) covers all Private Collection Agencies (PCAs) systems and the respective systems they operate on behalf of Federal Student Aid (FSA) to support the Student Aid Fiscal Responsibility Act of 2009 (SAFRA), and the Debt Collection Improvement Act of 1996 (DCIA), Not-ForProfit Loan Servicing Processing operations. PCA systems perform the following functions: borrower account management, interim/repayment servicing, borrower correspondence, call scheduling, collection, skip-tracing, and other correspondence history files. PCAs communicate with internal FSA platforms, borrowers, other loan servicers, third-party providers, consumer reporting agencies, and government agencies.

1.2. Describe the purpose for which the personally identifiable information (PII)1 is collected, used, maintained or shared.

The information is collected, stored, and updated by PCA's on behalf of the Department of Education Office (DoED) of Federal Student Aid (FSA), is used to enable effective location and recovery of defaulted student loans. The information is used only to support the collection or administrative resolution of debts associated with a borrower's defaulted student loan(s) and to provide additional processing capacity and augment the U.S. Department of Education, Federal Student Aid Debt Management and Collection System (DMCS) Major Application.

1.3. Is this a new system, or one that is currently in operation?

Currently Operating System

1.4. Is this PIA new, or is it updating a previous version?

Updated PIA

1.5. Is the system operated by the agency or by a contractor?


1.5.1. If the system is operated by a contractor, does the contract or other acquisitionrelated documents include privacy requirements?


2.1. What specific legal authorities and/or agreements permit and regulate the collection and use of data by the system? Please include name and citation of the authority.

The Higher Education Act of 1965 (Public Law 89-329), as amended, section 428,484, and 485B:31 U.S.C 7701: and Executive Order 9379 (November 22, 1943), as amended by Executive Order 13478 (November 18, 2008).

SORN 2.2. Is the information in this system retrieved by an individual's name or personal identifier

such as a Social Security Number or other identification?


2.2.1. If the above answer is YES, this system will need to be covered by Privacy Act System of Records Notice(s) (SORN(s)).2 Please provide the SORN name, number, Federal Register citation and link, or indicate that a SORN is in progress. N/A PCA's are covered the following System of Records Notice: "Common Services for Borrowers (CSB) Contract, SORN#(18-11-16), Federal Register 3503-3507. Federal Register date September 2, 2016.

2.2.2. If the above answer is NO, explain why a SORN was not necessary. For example, the information is not retrieved by an identifier, the information is not maintained in a system of records, or the information is not maintained by the Department, etc. N/A Click here to enter text.

2.3. What is the records retention schedule approved by National Archives and Records Administration (NARA) for the records contained in this system? Please provide all relevant NARA schedule numbers and disposition instructions.

DOED Record Schedule: 075 Title: FSA Loan Servicing, Consolidation, and Collection Records NARA Disposition Authority: N1-441-09-16 Disposition Instruction: Record copy (temporary)- cut off annually upon payment or discharge of loan. Destroy/delete 15 years after cut off.

2.4. Is the PII contained in this system disposed of appropriately, and in accordance with the timelines in the records disposition schedule?


3. Characterization and Use of Information

Collection 3.1. List the specific PII elements (e.g., name, email, address, phone number, date of birth, Social Security, etc.) that the system collects, uses, disseminates, or maintains.

PCA's collect and maintain the following PII data pertaining to borrower/coborrower/co-signers/students:

? Full Name ? Maiden Name

? Social Security Number ? Date of Birth ? Bank Account Numbers ? Student Loan Account Number ? Alien Registration Number ? Home Address ? Related Demographic Data ? Home, Work, Alternate, Mobile Telephone Numbers ? Personal Email Addresses ? Checking Account Information ? Employment Information ? Financial Information

3.2. Does the system collect only the minimum amount required to achieve the purpose stated in Question 1.2?


3.3. What are the sources of PII collected (e.g., individual, school, another agency, commercial sources, etc.)?

The source of information is from FSA's Debt Management and Collection System (DMCS) and obtained from schools/education institutions, lenders/financial institutions, employers, U.S. Department of Education (DoED), National Student Clearing House (NSC), external database directory assistance, consumer reporting agencies, skip-tracing vendors, U.S. Military, commercial person locator, and U.S, Department of Treasury.

3.4. How is the PII collected from the stated sources listed in Question 3.3 (e.g., paper form, web page, database, etc.)?

Information is retrieved via the following channels: ? Phone calls with customer service agents ? Entries via Interactive Voice Response (IVR) service ? Incoming correspondence ? Entry via the Borrower Portal Website ( ? Bulk file transfer from third-party data providers

