Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Data Privacy topic
No spam. Unsubscribe anytime.
Utah privacy office outlines how government entities can "initiate" data-privacy programs; posts templates, training and website scans
Summary
State privacy officials said government entities can meet a revised GDPA deadline by submitting an annual privacy program report that "initiates" a program, and they outlined a report template, an employee training rollout and a website-scanning partnership to help local and state entities comply.
Get email alerts on the Data Privacy topic
No spam. Unsubscribe anytime.
Chris Bramwell, a presenter with the Utah Office of Data Privacy, told attendees at a data governance summit breakout session that the state has revised its Government Data Privacy Act (GDPA) timeline and that local and state entities can “initiate” a privacy program by submitting an annual privacy program report on or before Dec. 31, 2025.
That report — which the privacy office plans to publish as a template on privacy.utah.gov — is designed to satisfy the GDPA’s initiation requirement without requiring full program maturity. The office said the initial report is currently treated as a protected record under Utah’s Government Records Access and Management Act (GRAMA) so entities can disclose vulnerabilities internally without public exposure.
The draft template and related resources are intended to give entities a practical way to comply with the law’s minimum requirements while the state builds longer-term tools, training and cooperative contracts to reduce implementation burdens.
Officials said the revised timeline replaces an earlier requirement that would have required full program implementation by May 1, 2025. “If you complete this whole report, it counts as initiating your program,” Bramwell said, summarizing the simplest path to meet the statutory initiation requirement. He added the office will accept other mechanisms if an entity’s legal counsel prefers them, but for many cities and counties the annual report will be the easiest compliance path.
What the report must include
Bramwell outlined the template’s principal sections: basic governmental-entity information; the chief administrative officer (CAO) responsible for records and privacy compliance; an inventory estimate of the number of unique individuals whose personal data the entity processes; a checklist of implemented privacy practices and planned strategies to mature them; identification of defined high-risk activities; disclosure of categories of personal data shared/sold/purchased and the legal basis for those exchanges; and a summary of workforce privacy training completion.
He said the office maps each report section to the relevant statutory language (as cited during the session) and a maturity model so entities can document current practice and set achievable targets. Examples of high-risk activities listed in the presentation included facial recognition, automated decision-making and profiling, genetic and biometric data and geolocation systems; officials said entities should simply check whether they perform any such activity and plan to provide more guidance later.
Chief administrative officer and protected status
The privacy office emphasized that the CAO is the accountable official for completing the report. Bramwell told the room the CAO requirement has existed in Utah law for decades and the CAO — or a designee identified by the CAO — should sign and file the report annually. He reiterated the office’s plan to make the draft template publicly available on privacy.utah.gov and to solicit feedback for iterative improvement.
Training requirement and rollout
Shane Paul, identified in the session as the state’s privacy training director, described the statewide employee-training requirement under the GDPA. Paul said the statewide awareness course targets all employees who, as part of their job duties, have access to personal data; it must be completed for new hires within 30 days and annually thereafter for existing staff.
“The training is actually 8 minutes long,” Paul said, explaining the choice of a short, scalable video to reach general staff across many entities. He said the statewide rollout will include downloadable formats (MOV, MP4 and a SCORM package for learning-management systems), a communications campaign beginning July 1 and periodic reminders through the end of the year to help entities reach completion goals.
Paul also noted one statutory exception: contractors are not subject to the state’s employee-training requirement under the current code language, though entities may choose to train or require training for contractors under contract terms.
Website privacy notices and technology scans
Brian Nelson of the Office of Data Privacy and Dylan Sellers of ObservePoint described an offered service to help entities inventory website tracking technologies and produce website privacy notices. Nelson said his office will make a draft website-privacy-notice template available on privacy.utah.gov and that ObservePoint will scan pages to report cookies, tags and third-party technologies that may capture or share user data.
Dylan Sellers of ObservePoint explained that cookies and tags are tracking mechanisms and urged entities to disclose any tracking technologies used on public websites. The presenters said the privacy office has a limited number of prepaid website scans available and that website stewards can sign up through a simple intake form on the privacy office site to get prioritized scanning and reporting assistance.
Questions and clarifications from attendees
During audience Q&A, officials clarified several recurring points: the initial report’s protected status under GRAMA is intended to allow candid internal inventories; entities may estimate unique individuals served (for example using population or single-count methods) rather than provide exhaustive transaction counts; “subprocessor” concepts (third parties such as SaaS vendors) will be clarified in future guidance; and the legislature and auditor’s office will be engaged as the program matures and audits ramp up over time.
Next steps
The privacy office said it will publish the draft report template and related templates (privacy policy, notices and inventory templates) on privacy.utah.gov after the summit and will run workshops and virtual trainings to help entities complete the report. Officials encouraged entities to collect homepage URLs and other website details so the office and ObservePoint can run scans and return cookie-and-tag inventories that communities can use to build website privacy notices.
Contact and resources
Presenters pointed attendees to privacy.utah.gov for the template and tools, to the Office of Data Privacy email (officeofdataprivacy@utah.gov) for assistance, and to the Observ ePoint intake form linked on the privacy website for website scanning support.
