Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Data Privacy topic
No spam. Unsubscribe anytime.
New Office of Data Privacy outlines training, ombud role and concerns about digital license data retention
Summary
Christopher Bramwell, the state's chief privacy officer, told legislators that the Office of Data Privacy — created by recent legislation — will roll out statewide training, operate an ombud service and advise the Legislature on limits for scanned digital driver's-license data.
Get email alerts on the Data Privacy topic
No spam. Unsubscribe anytime.
Christopher Bramwell, the state's chief privacy officer and director of the Office of Data Privacy, told the General Government Appropriations Subcommittee that the new office will standardize privacy practices across state government, roll out a large employee training program and operate a data-privacy ombudsperson service.
"The Office of Data Privacy is now about 6 and a half months old," Bramwell said, describing the office's origin in prior legislation and the policy framework it published last December. He cited House Bill 243 as the first step that created a precursor privacy role and House Bill 491 as the legislation that established the Office of Data Privacy.
Bramwell said the office has three core areas of work: monitoring high-risk data processing in government, coordinating breach and incident plans with the state's cyber center and implementing a statewide privacy-awareness training program for public employees. The office also operates an ombud process to receive and resolve individual complaints; Bramwell said the ombud process received seven complaints and produced three findings since its Nov‑end launch.
On a question about scanned electronic driver's licenses, Bramwell told the committee that current code requires bars and taverns to retain scanned license data for seven days but contains no mandatory disposition or maximum retention period. "The risk of that is that if you have a breach and you've kept all the data forever, you're going to have a big breach," Bramwell said. He recommended the Legislature consider adding a maximum retention period in statute or in the underlying digital-license authorizing bill.
Bramwell said the office lacks rulemaking authority to define "high-risk processing" thresholds and that the office is coordinating with the Division of Archives and Records Services (DARS) to align GRAMA records requirements with privacy obligations. Bramwell also said the statewide training program will be rolled out within weeks and that the legislative performance target of 90% agency employee completion is currently unmet because the training has not been deployed yet.
Ending: Bramwell asked the committee to consider clarifying statutory language for retention of digital-license data and to support the Office of Data Privacy's rollout of training and monitoring tools; the committee asked for periodic performance updates.
