Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Data Privacy Implementation topic
No spam. Unsubscribe anytime.
Utah presenters outline new privacy tools, ombuds complaint process and audit program
Summary
State privacy officials described a privacy impact assessment template, a newly created data-privacy ombuds role and a state privacy auditor’s audit program, and urged local entities to map data sharing and adopt retention schedules.
Get email alerts on the Data Privacy Implementation topic
No spam. Unsubscribe anytime.
At a public session hosted by the Utah Department of Data Privacy, three state privacy officials outlined implementation steps for the Governmental Data Privacy Act and related guidance, including a privacy impact assessment (PIA) template, an ombuds complaint process and the scope of a newly created state privacy auditor.
The session matters because local governments and agencies across Utah will need to document data flows, limit collection and prepare for audits and potential complaints under the GDPA and related statutes. Officials said completing PIAs, publishing privacy notices and producing data-sharing reports are immediate priorities.
George McEwen, a presenter with the Office of Data Privacy, opened by describing privacy as a complement to cybersecurity and urging agencies to treat PIAs as a risk-management tool. "We refer to it as CIA, which is the confidentiality, the integrity, and the availability of data," McEwen said, adding that privacy requires separate but coordinated business decisions about what data to collect, store and share. He recommended that agencies ask why they collect each data element and warned against keeping data without a legal basis: "If you don't have a legal reason to keep the data, you need to get rid of it." McEwen said PIAs will help agencies map systems, identify the "blast radius" of potential incidents and set requirements for IT to implement.
Lana Taylor, the state's data privacy ombudsperson, described the ombuds role and how the complaint process will work. The ombuds office will accept complaints through a public form that includes a privacy notice and retention schedule, Taylor said, and will follow up with complainants and the governmental entities involved. She said that most complaints the office has handled so far have shown governmental entities were acting within legal authority, but that the ombuds serves as a mediator and educator when transparency or notice is lacking. "The identity of an individual who makes a complaint, is not public information," Taylor said, explaining the office classifies complainant identities as protected.
Nora Kurzawa, the state privacy auditor, outlined audit triggers and the auditor’s mission to "protect privacy and treat it as a fundamental human right." Kurzawa said the auditor’s office will prioritize audits for entities that present the greatest privacy risk, will accept requests from the public and will perform both scheduled and complaint- or breach-triggered audits. She told attendees that, under current guidance, agencies must prepare a data-sharing report by Dec. 31 and begin privacy program work: "By December 31, you have to create a data sharing report internally. You have to initiate your privacy program, and you have to have a data sharing report that outlines how you share data." Kurzawa also summarized “golden rules” for privacy practices: "limit, guard, delete, No surprises, No hostages." She said audits will consider legal compliance and also recommend best practices.
Speakers discussed how the GDPA intersects with existing law such as GRAMA and other statutes; Lana Taylor said the ombuds role does not replace GRAMA appeal routes and that the ombuds' focus is privacy practice and transparency rather than record-access determinations. McEwen and Kurzawa advised agencies to attach sensitive details (for example, security diagrams or full data-flow diagrams) by reference rather than publishing them in full with public PIAs. Taylor said complaint summaries will be published in an educational form that omits identifying information about complainants and is not intended for public shaming.
Audience members asked about data retention when legal requirements are ambiguous and about specific use cases such as voter signature databases and AI use. McEwen warned that public or third-party AI tools can permanently expose personal data if staff paste case-specific information into public models. All three presenters urged agencies to adopt privacy-by-design practices, limit collection to what is legally necessary, document data flows and engage leadership: "If data's lost, it's not the third party cloud provider ... Public officials are ultimately held accountable for the activities of their organization," McEwen said.
Officials said next steps for agencies include completing PIAs to capture baselines for systems, publishing required privacy notices, mapping interagency data sharing and preparing for audits or complaint responses. The auditor's office will publish risk profiles, a portal and audit standards and plans to provide trainings and privacy-audit resources to local governments.
The session closed with reminders about resources and contact points: the Office of Data Privacy’s PIA tools and complaint form, the ombuds’ mediation option and the state privacy auditor’s upcoming standards and training schedule.
