Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Records Management Privacy Integration topic

No spam. Unsubscribe anytime.

Privacy office, records officers debate folding GRAMA Part 6 into Utahs Government Data Privacy Act

3628540 · May 2, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

State privacy officials, municipal records officers and the state archivist on Oct. 26 discussed proposals to move provisions now in Part 6 of the Government Records Access and Management Act (GRAMA) into the newer Government Data Privacy Act (GDPA), aiming to reduce redundancy and clarify how agencies must document what personal data they collect and how it may be used.

SALT LAKE CITY

State privacy officials, municipal records officers and the state archivist on Oct. 26 discussed proposals to move provisions now in Part 6 of the Government Records Access and Management Act (GRAMA) into the newer Government Data Privacy Act (GDPA), aiming to reduce redundancy and clarify how agencies must document what personal data they collect and how it may be used.

Micah Borweller, deputy chief privacy officer at the Utah Office of Data Privacy, said the office is trying to "identify duplication [and] gaps in the law" and to make privacy and records-management requirements easier to understand and follow. "There is a difficult relationship between the GDPA and GRAMA," Borweller said, adding that the GDPA "talks about personal data" while GRAMA "talks about records." He said the office plans a standardized filing system for privacy annotations in coordination with the Division of Archives and Records Services (DARS) ahead of the 2027 compliance deadline.

Jared Taney, legal director for the League of Cities and Towns, told the session that GRAMAs existing requirement that every record series file a "statement to the archivist" listing what data an entity collects and how it will be used is not being met. "Do you know how many entities are complying with that? Exactly. Zero," Taney said, noting the exception of education agencies. He and other local-government participants emphasized that many small towns lack dedicated staff or technical systems and urged flexibility in any expanded GDPA filing obligations.

State archivist Ken (first name only in the session) described a gradual shift in how record series are approved and said DARS has seen agencies begin to fold privacy-impact information into record-series descriptions. "We're trying to give power back to the records officers so that we can advise them, provide best practices, and then have a much more robust and nimble general retention schedule," Ken said.

Discussion focused on several recurring issues:

- Privacy annotation and reporting scope: GDPA currently requires a privacy annotation for state agencies and authorizes the Office of Data Privacy to adopt rules specifying annotation content. Presenters and attendees debated whether GDPA should be expanded to require privacy annotations from political subdivisions (cities, towns, counties) or whether DARS and the Office of Data Privacy should coordinate so a single repository avoids duplicate reporting.

- Statement to the archivist and purpose limitations: GRAMA Section 6-1 (the panel referenced GRAMA and code sections such as 63G-2-103) contains a statement-to-archivist requirement that also functions as a statutory limitation on uses of collected data. Speakers observed that few entities have filed those statements and that GDPAs privacy-annotation and purpose/use rules overlap with that GRAMA provision.

- Notice to individuals and operational exceptions: Attendees raised practical concerns about when a privacy notice must be provided. One records attorney asked whether investigators must recite a notice before interviewing a subject. Borweller pointed to GDPA notice exceptions for public safety and said agencies can include a privacy notice on a public website or in email signatures to meet many requirements.

- Amendment and correction of records: GRAMA allows an individual to request amendment of records "concerning the requester" and requires agencies to attach a requesters disagreement statement to the contested record. By contrast, GDPA contains a broader amendment procedure for personal data but does not require amendment in all circumstances; presenters recommended replacing the GRAMA amendment section with GDPA language while preserving GRAMAs exceptions for certain controlled medical or title records that must remain in original form.

- Definitions and edge cases: Panelists and an assistant attorney general noted gaps around whether GDPAs "individual" definition and "personal data" coverage adequately address records about business entities that nonetheless contain personal identifiers (for example, sole proprietors who use Social Security numbers). The panel acknowledged this is an outstanding issue to be resolved through future rulemaking or legislation.

- Implementation burden for small entities: Taney emphasized that the League represents 255 cities and towns, some with only a handful of staff, and urged graduated or feasible compliance steps for smaller jurisdictions. One attendee reported a municipal office processed about 15,000 GRAMA requests in a single year, illustrating wide variation in operational load across jurisdictions.

No formal vote or rulemaking occurred at the session. Presenters repeatedly asked attendees for complaints, redlines and examples of operational conflicts so the Office of Data Privacy and DARS can propose statutory or rule changes to the legislature and records-management committees.

The session also touched on related statutes and programs: HB 491 (2024) was cited as the large bill that established the GDPA and the Utah Office of Data Privacy; the Governmental Internet Information Privacy Act (GIIPA) and state administrative procedure law (UAPA) were referenced in discussion of notice and appeal processes. Panelists urged agencies to review existing record-series descriptions and update retention schedules or privacy-impact language through the Records Management Committee when necessary.

Attendees were encouraged to submit examples of redundancy or conflicting guidance to the Office of Data Privacy so staff can prepare redlines for the next legislative cycle. Micah Borweller said the office will publish a general system and repository in coordination with DARS in advance of 2027 filing dates; participants asked that smaller jurisdictions receive technical help and clearer templates.

The panel also discussed protections for at-risk government employees (for example, staff who have been threatened or stalked), noting GDPA and other HR-related statutes can be used to limit public disclosure of home addresses or other sensitive information for those employees.

The meeting was a stakeholder listening and drafting session; no regulatory changes or legislative amendments were adopted at the event.