Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Data Privacy topic
No spam. Unsubscribe anytime.
Davis County adopts ordinance to implement state data privacy law, names clerk as privacy officer
Summary
The Davis County Commission unanimously approved Ordinance 2025-5 to establish a county data privacy program consistent with the Utah Government Data Privacy Act, designate the county clerk as the chief administrative officer (CAO) for privacy, require annual audits and reports, and create an advisory committee that includes a commissioner.
Get email alerts on the Data Privacy topic
No spam. Unsubscribe anytime.
Davis County commissioners on July 22 approved Ordinance 2025-5 to establish a countywide data privacy program and set the administrative structure for complying with the Utah Government Data Privacy Act (GDPA).
County Clerk Brian McKenzie, who led the presentation, said the ordinance mirrors state guidance and routine duties already tied to the county’s records and administrative functions. McKenzie described the work of an ad hoc committee that developed the draft and the county’s steps to implement the program, including hiring a data privacy administrator and rolling out employee and volunteer training.
"To summarize, I have, to the best of my ability, followed the direction of the commission in setting up and preparing the county to be successful in our obligations to GDPA," McKenzie said. He told commissioners the ordinance was drafted with input from the county attorney, information systems and human resources offices and that attorneys had reviewed the text for compliance with state law.
The ordinance designates the county clerk as the chief administrative officer (CAO) for purposes of the county privacy program and includes provisions to preserve the commission's legislative and administrative authority. McKenzie said the ordinance was revised after review to add a commissioner to the advisory committee, explicitly reserve the commission's authority to change the CAO designation, require the CAO to follow statutory limits, provide a formal method to resolve disagreements between the CAO and administrative offices, and allow the commission to require audits if necessary.
McKenzie said attorneys concluded the clerk’s designation as CAO does not violate state law and does not constitute an improper delegation of commission authority because the GDPA contemplates that a government entity will designate a CAO. The ordinance also requires an annual report by the CAO and an annual audit of the county privacy program.
Commissioners voted in favor of the ordinance after the presentation. The motion to approve was made and seconded during the meeting; the clerk recorded the vote as "Aye." No roll-call vote with member-by-member names was recorded in the public transcript.
The county began preparing for the statute’s requirements months earlier: McKenzie said committee members divided work across training, breach document review, legal drafting and program design, and that a data privacy administrator position was placed in the budget and is now filled. McKenzie told the commission that training for employees and volunteers has been implemented.
The ordinance text, as presented, largely enacts statutory requirements and adds audit and reporting features the commission may later modify. McKenzie recommended passage to allow the county to accelerate compliance work.
The commission approved Ordinance 2025-5 without amendment and directed staff to continue implementation work.
