Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Data Privacy topic

No spam. Unsubscribe anytime.

Kamas hears overview of Government Data Privacy Act; council urged to appoint officers and complete program report

5681226 · August 27, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

Mountainland Association of Governments staff presented requirements of Utah’s Government Data Privacy Act (GDPA), including a privacy program report due Dec. 31, 2025, appointment of a chief administrative officer and records officer(s), and annual staff training.

KAMAS — A Mountainland Association of Governments (MAG) representative told the Kamas City Council that Utah’s Government Data Privacy Act requires every government agency to adopt and begin implementing a privacy program, beginning with a privacy program report due by Dec. 31, 2025.

Spencer, MAG’s local administrative adviser assisting Kamas, summarized the law and immediate steps the city must take. “This law, the GDPA, was passed in 2024, and it really was to standardize how government handles personal data,” Spencer said. He said the law (cited in the meeting as Utah Code 63A-19) applies to cities, towns, school districts and special districts and sets staged implementation deadlines: the privacy program report this year and fuller data-system compliance by Jan. 1, 2027.

What the council must do: Spencer said the city must appoint program leadership — a chief administrative officer (CAO) and one or more records officers — and suggested using a resolution that names positions (for example, “mayor” or “recorder”) rather than individuals so the appointment carries forward when personnel change. He recommended the CAO be the mayor and said records officers should be staff trained in GRAMA and records information management (RIM).

Training and reporting: Spencer explained a required eight-minute state training video for anyone who “touches” the city’s personal data, including vendors and contractors, and said the privacy program report is an internal document the Office of Data Privacy may request for proof of compliance. He said the report asks agencies to indicate whether they have a privacy policy, training completion percentages, and other details. “The only requirement for this year is that the privacy program report has to be filled out by each agency,” Spencer said.

Program-building steps: The presentation urged the city to inventory what personal data it collects, limit collection to data it needs, document where the data resides and who has access, and adopt a written privacy policy in the next year. Spencer recommended an annual “maturity” self-assessment to show continuous improvement. He said the state is taking a gradual approach and has not yet set strict penalties for noncompliance.

Next steps recommended in the meeting: watch the state training video (Spencer said he will provide links and the slide deck), appoint officers via resolution or comparable action, and begin the privacy program report. City staff (Kim and Dory) were identified as points of contact for the implementation effort; Spencer said he will help them and the council as the city completes the report.

Ending: Council members asked for a resolution template and a direct link to the training video; Spencer said he would email those materials and help coordinate the city’s work on the report. No formal council vote on appointments or a resolution was recorded during the meeting.