Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Data Privacy topic
No spam. Unsubscribe anytime.
State privacy officer outlines broad rewrite of government data privacy law, urges multi-year build of local programs
Summary
Chris (state chief privacy officer) briefed the LPC on HB 444, a comprehensive rewrite intended to modernize government privacy practices, repeal an older web-privacy chapter, and require internal privacy reporting by local entities.
Get email alerts on the Data Privacy topic
No spam. Unsubscribe anytime.
The state’s chief privacy officer briefed League members Feb. 24 on a major data-privacy package, HB 444, saying the bill is part of a multi-year effort to modernize government privacy practices after decades of inconsistent implementation.
“Thirty years of noncompliance” and a path forward
Chris (Chief Privacy Officer, Office of Data Privacy) told attendees that audits and assessments have found widespread noncompliance with the Government Records and Management Act and other archival/records provisions. "We have been noncompliant with the privacy obligations outlined in both GRAMA and the division of archives and record service section of code," he said, and that many entities “have not filed a statement in over 20 years with the state archivist.”
HB 444 would consolidate privacy duties, repeal the older Government Internet Information Privacy Act chapter and move new requirements into the Government Data Privacy Act, create a clearer role for a state privacy auditor (renamed from state privacy officer), and require internal privacy reporting by jurisdictions.
Key features discussed
- Notice and classification: The bill clarifies that collecting personal data requires simple notice, and distinguishes personal data that remains public from data classified as private or protected.
- Repeal and consolidation: The state will repeal the older website-privacy chapter and fold duties into one modernized statute so new sites come into compliance going forward.
- Internal reporting and protections: Local entities would prepare an internal report documenting whether they have started a privacy program; those reports would be protected under GRAMA to allow candid discussions. "This is meant to allow you internally ... to have those sensitive conversations," Chris said.
- Vendor/contractor guidance: The bill anticipates industry-standard privacy training and allows contracting language that requires vendors to complete such training; the state office will explore scalable options and may provide services for a fee on request for smaller jurisdictions.
- Breach notice flexibility: For large breaches of public data that include personal information, the bill would permit notice via the jurisdiction’s website where individualized notice would be impractical.
Questions from cities
City officials raised operational questions about funding, procurement, and how to ensure contractors comply with training and privacy expectations. Chris said the bill contemplates extensions and exemptions where smaller jurisdictions lack capacity and that statewide training resources will be made available; contracting and procurement scale remain workstreams.
Why it matters
HB 444 aims to provide a consistent framework that municipalities can implement over years rather than months. "It's going to take a decade plus to do that," Chris told the committee, arguing the statute builds the tools and governance structure local governments will need.
Ending
League staff and the Office of Data Privacy will continue technical discussions about implementation timelines, procurement strategies for vendor compliance, and the CAO/records-manager responsibilities spelled out in the bill.

