Privacy
Lineage verification asks you for some of the most personal information a person holds: who your people were, where they came from, and the documents that prove it. This page sets out plainly what we collect, who can see it, how long we keep it, and what happens when someone comes asking for it.
This page describes how DOUSCS handles the personal and genealogical information you give us when you apply for Personal Certification, Business Certification, or Community Sponsor certification.
It is the plain-English version of a formal policy adopted by the DOUSCS Board of Directors: the Lineage Verification Privacy, Records Retention and Legal Disclosure Policy. That policy binds every director, officer, employee, genealogist, researcher, contractor, volunteer and committee member who is given access to your file. If you want the full document, ask us and we will send it.
One thing this page is not. It does not cover what happens on our identity verification partner's own system. When you verify your identity, you are dealing directly with that company under their terms and privacy practices. See how identity verification works.
DOUSCS does not collect or retain copies of your driver's license, passport, Social Security card, or any other government-issued identification. Our identity verification partner checks your ID on their own system. What comes back to us is your verified legal name and the fact that verification succeeded.
This is deliberate. A registry that stockpiles scans of identity documents becomes a target, and there is no version of our work that requires us to hold them. We need to know that you are who you say you are. We do not need to keep the proof.
Identity verification and lineage verification are separate processes. Passing the identity check does not establish that your line of descent traces to an ancestor living in America in 1870 - that is what the Research Division review determines. And completing lineage verification does not make you a member or part of the DOUSCS nonprofit organization.
We collect what is reasonably necessary to trace and corroborate your line, and no more. Depending on your application, that may include:
Much of this you supply. Some of it our researchers find in public archives on your behalf - federal records held by the National Archives, historical newspapers, and similar public collections.
Our staff are instructed not to collect any of the following unless it is specifically necessary and specifically authorized:
If you send us something we did not need, we will take reasonable steps to securely remove or destroy it, so long as the law permits us to. Please do not send us documents we have not asked for.
Thirty days after a final decision on your application, the evidence documents you uploaded are deleted. We keep the outcome of the review. We do not keep the family records you entrusted to us.
The thirty days exist so that the appeal window and the deletion clock line up: if you are denied, you have thirty days to appeal, and your evidence is still there to support that appeal. Once the decision is genuinely final, the documents go.
Records are not kept indefinitely simply because we have the storage to keep them. There is one exception, and we would rather state it than bury it: if DOUSCS is served with a subpoena, a court order, or is otherwise legally required to preserve records, deletion is suspended for those records until that obligation is released. See section 9.
We keep a lasting record that verification happened. It contains what is needed to establish that you completed the process, what was determined, the date it was determined, and who authorized it. Nothing more.
This record is deliberately thin. It exists so that a certification issued in 2026 can still be confirmed as genuine in 2046, without our holding a warehouse of your family's private papers to do it.
Why this matters to you. Your certification is a permanent finding. It does not lapse if your annual membership does, and it does not depend on our still holding your documents. The proof of the finding is the finding itself.
Access to your file is limited to people with a genuine, job-related need to open it. We use role-based access, so what a person can see is determined by the work they do:
Holding a seat on the DOUSCS Board, or an officer's title, does not by itself grant access to individual lineage files. Position is not permission. Access follows organizational need to know, and nothing else.
Everyone granted access is bound to keep it confidential. That means your information is not discussed with unauthorized people, not posted publicly, not shared through anyone's personal social media, not sent to personal email accounts, not left sitting on personal devices, and not used for anyone's private purposes. We may require staff and contractors with access to sign a separate confidentiality agreement.
Records created in the course of this program belong to the organization, not to the individual researcher who worked on them. When someone leaves DOUSCS, their access is revoked, organizational records and equipment are returned, and their confidentiality obligations continue.
DOUSCS does not sell applicant lineage information. Not to data brokers, not to genealogy companies, not to anyone.
We also do not hand applicant files to outside organizations for marketing, commercial solicitation, political campaigning, or any other unrelated purpose, without your authorization or another lawful basis for doing so.
Your information is used for the work you came to us for: genealogical research, lineage verification, identity verification where necessary, communicating with you, quality control, our own recordkeeping, confirming certifications we previously issued, preventing fraud, running the program, and meeting our legal obligations. It is not used for unrelated purposes.
A request from a federal, state or local government employee or agency does not by itself give DOUSCS permission to release your records. Our staff are not permitted to hand over lineage files simply because the person asking works for the government.
Every such request goes to our designated Records Officer and, where appropriate, to legal counsel. They determine whether the requester actually has lawful authority to obtain the information, and what - if anything - the law requires us to produce.
If we receive a subpoena, court order, search warrant, summons or similar legal process, we preserve the relevant records, seek legal review before producing anything, establish the scope of what is genuinely required, and produce only what is responsive to that lawful request. One applicant's records do not open the door to anyone else's. We document what was produced, to whom, on what date, and under what legal authority.
Where the law permits it and it is practical to do so, we will tell you that we received legal process asking for your information. Sometimes a court order or the law itself forbids us from telling you. We will not pretend otherwise.
Nothing in our policy requires DOUSCS to voluntarily provide your confidential information merely because a governmental entity has asked for it.
DOUSCS publishes aggregate data about the descendant economy, including the annual State of the Descendant Economy Report. We also report aggregate figures to funders and use them for internal planning and program evaluation.
That reporting uses aggregated or de-identified information only - figures from which individuals cannot reasonably be identified. Personally identifiable lineage information is not published for statistical or promotional purposes.
The business directory is different, and it is your choice. A certified business is listed publicly, because that is the point of a registry - customers need to be able to find you. What is published is business information: the name, what it does, where it operates, and that it holds current certification. The genealogical evidence behind an owner's personal certification is never published, and there is no public directory of certified individuals.
We hold this information under administrative, physical and technical safeguards appropriate to how sensitive it is: records kept in approved organizational systems, access restricted to authorized personnel, strong password requirements, credentials never shared, access revoked promptly when someone's authorization ends, and protected backups.
If we suspect that lineage information has been lost, stolen, accessed without authorization, or otherwise compromised, it is reported immediately to our designated Records Officer. We investigate, contain it, determine what was affected, preserve the evidence, and determine what notification the law requires. Where the law requires that you be told, you will be told.
The Board of Directors designates an officer responsible for this policy: record access controls, retention, legal holds, government information requests, security incidents, and reviewing the policy itself. If you have a question about your records, that is who answers it.
This policy is administered under applicable federal law and the laws applicable to DOUSCS, including applicable Tennessee law. Where any part of it conflicts with a binding legal requirement, we follow the legal requirement. The policy is reviewed periodically and updated when our operations, our technology, the law, or the Lineage Verification Program changes.