Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Data Privacy topic

No spam. Unsubscribe anytime.

State privacy office gives Utah cities a compliance roadmap, templates and a May 1, 2025 deadline

Utah League of Cities and Towns · January 16, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

The State of UtahOffice of Data Privacy told municipal officials the Government Data Privacy Act requires each jurisdiction to adopt a documented privacy program by May 1, 2025, and that the state will post a 21-practice framework, a policy template and short trainings to help small towns comply.

Shane Paul, training director at the State of UtahOffice of Data Privacy, told municipal officials in a Utah League of Cities and Towns webinar that cities must adopt a documented privacy program by May 1, 2025, under the Government Data Privacy Act and that the state will provide templates, trainings and case-by-case assistance to help small jurisdictions comply.

The Office of Data Privacy has published a framework built from statutory requirements and organized into 21 baseline privacy practices and a maturity model. "It's really just you guys deciding where you're at on this privacy roadmap," Paul said, describing how a jurisdiction can meet the May 1 deadline by documenting current maturity, setting priorities and adopting a short-term strategy. He added that "it's gonna be a multiyear effort for sure," and that the initial enforcement posture will be limited if entities show a documented plan to progress toward compliance.

Why this matters: The Government Data Privacy Act creates a new baseline for how government entities handle personal information and requires local governments to show they have a privacy program. For many small towns that lack IT staff or dedicated records personnel, the Office is relying on existing records infrastructure and partner programs to provide practical help.

Key facts and state support - Minimum requirements: The Office distilled statutory obligations (including GRAMA and related records laws) into 21 privacy practices covering items such as inventorying processing activities, incident response and breach notification, retention schedules and privacy notices. Jurisdictions should assess each practice on a maturity scale and document a 12-month strategy for priorities. - Deadline: Jurisdictions must have a privacy program in place by May 1, 2025; the Office said documenting where a city stands and a realistic roadmap satisfies the near-term requirement. - Templates and training: Paul said a privacy program policy template that covers the 21 practices will be posted at privacy.utah.gov within weeks and can be adapted by cities; short micro-trainings for CAO and records roles will accompany the materials. - Records help: The Division of Archives and Records (DARS) can assist cities that lack capacity. Paul posted contact information for Heidi Steed (DARS) in the webinar chat and said DARS can help designate Chief Administrative Officers (CAOs) and Appointed Records Officers (AROs), organize records and apply retention schedules. - Small-town practicality: Participants from small jurisdictions raised concerns about limited staff. Paul and host John said many small towns will designate existing officials (mayor, recorder or clerk) as CAO/ARO and use the state's templates and LAA/AOG partners for implementation.

What officials should do next Officials should (1) determine and document who will serve as the jurisdiction's CAO and ARO, (2) use the privacy.utah.gov framework and the upcoming policy template to assess and document their status across the 21 practices, and (3) prioritize a short list of practices to advance in the next 12 months. Paul said the Office and the LAA program will help jurisdictions directly and that most steps can be met by copying the state's template and scheduling incremental improvements.

Quotes from the webinar "If your goal is to be compliant 10 years from now, where are you right now? Where do you want to go?" Paul asked, urging officials to document a realistic roadmap. "For many of the small towns, the CAO will probably be the mayor or the clerk," the host (John) said, noting local staffing constraints.

Next steps and where to find resources The Office of Data Privacy has posted the framework and other resources at privacy.utah.gov and will add a downloadable policy template and micro-trainings in the coming weeks. Officials with immediate needs can contact the Office at opsofdataprivacy@Utah.gov or DARS representative Heidi Steed (contact posted in the webinar chat) for help designating CAOs/AROs and organizing records. The Office said it is coordinating with common vendors to help them be compliant with state law.

The webinar closed with the recommendation that jurisdictions treat implementation as an incremental, multiyear process but meet the immediate documentation requirement before May 1, 2025.