Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Data Privacy topic
No spam. Unsubscribe anytime.
Davis County adopts ordinance to implement Utah Government Data Privacy Act
Summary
Davis County Commissioners approved Ordinance 2025-5 to implement the Utah Government Data Privacy Act, designate a county chief administrative officer for privacy responsibilities, require annual reporting and audits, and establish an advisory committee role for a commissioner.
Get email alerts on the Data Privacy topic
No spam. Unsubscribe anytime.
Davis County Commissioners voted to adopt Ordinance 2025-5, establishing the county's data privacy program to comply with the Utah Government Data Privacy Act (GDPA). The ordinance designates the county's chief administrative officer for privacy duties, requires annual reporting and audits of the privacy program, and creates an advisory committee that will include a commission member.
Brian McKenzie of the clerk's office summarized the ordinance's development and legal review. He said the county formed an ad hoc committee that worked with the county attorney, information systems and human resources to draft the proposal and that the draft mirrors state guidance. "As you know, back in February 2024, the legislature passed the Utah Government Data Privacy Act," McKenzie told commissioners, noting the county used resources from the Utah Office of Data Privacy and the Utah Association of Counties in preparing the ordinance.
McKenzie described four areas reviewed by county counsel: whether the clerk's designation as the CAO for privacy violates state law, whether the ordinance improperly delegates commission authority to the clerk, how to preserve commission legislative and administrative authority while complying with the state mandate, and whether the ordinance creates legal risk under applicable statutes. He said legal review concluded the clerk's designation does not violate the law and that the ordinance largely implements what the GDPA requires while adding administrative elements (for example, an audit requirement) that the commission may later revise.
Commissioners asked procedural questions and discussed additions made to preserve the commission's authority, including a conspicuous statement that the commission retains the power to change the CAO designation and to require audits. After discussion, a commissioner moved to adopt the ordinance and another seconded; the measure passed on a voice vote.
The ordinance will require county staff to implement employee and volunteer training and to deliver an annual privacy program report to the legislative body. County staff said they have already hired a data privacy administrator and begun training for new hires and annual refresher training for existing employees.
The commission did not record a roll-call vote in the minutes; the action was approved by voice vote. The ordinance was discussed in work sessions on June 7 and June 17 and was provided to commissioners by email on June 10 prior to final consideration.
