Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Data Privacy Legislation topic

No spam. Unsubscribe anytime.

Utah League webinar lays out municipal duties under 2024–25 data privacy laws

Utah League of Cities and Towns webinar · September 17, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

A Utah League of Cities and Towns representative summarized new requirements under HB 491 (2024) and HB 444 (2025), including designated records officers, expanded notice rules, privacy program reports, contractor obligations after July 2026, training mandates and enforcement steps; attendees asked about record-series classification, new vs. old processing activities, and contractor immunity.

A representative of the Utah League of Cities and Towns told municipal officials in a webinar that recent state privacy bills — HB 491 in 2024 and HB 444 in 2025 — largely carry forward earlier rules while introducing new reporting, notice and contractor requirements that cities and towns must implement.

The presenter said municipalities must "only obtain and process the minimum amount of personal data that is reasonably necessary" to provide a service and must identify a records chief administrative officer and records officers to manage notices, training and reporting. The presenter advised creating a single, comprehensive privacy policy on a municipal website and linking to it from forms or using a QR code to meet notice requirements.

Why it matters: The Government Data Privacy Act expands the types of records that trigger required privacy notices and creates a new data-privacy program and report cities must prepare. The report must indicate whether the entity has initiated a privacy program, list privacy practices in use, document noncompliant processing activities and planned remediation steps, and identify high-risk processing activities such as facial recognition, biometric or genetic data, automated profiling, or geolocation that could significantly affect individual privacy.

Key details and timelines: The presenter said activities previously in use before May 7, 2025, are treated as "old" processing activities and that municipalities have a transition period (discussed in the webinar as through 2027) to revise old activities to comply. Entities may request exemptions or extensions for specific code duties; approved exemptions and extensions are reported to the Utah privacy governing board and state privacy auditor. The presenter noted that contractors already must follow most GDPA requirements now (training excepted) and that, starting July 1, 2026, new or renewed municipal contracts must include a clause requiring contractor compliance with the GDPA, a change the presenter warned could prompt some vendors to decline work.

Training and compliance metrics: The Office of Data Privacy will provide a training course; employees with access to personal data and their supervisors must complete it (new hires within 30 days; current staff at least annually). Municipalities must report the percentage of required employees who have completed training as part of their privacy program report.

Enforcement and oversight: The presenter outlined an enforcement pathway in which the privacy governing board can instruct the privacy auditor to investigate alleged violations; entities found in violation receive 30 days to cure a validated issue before a matter may be referred to the attorney general. The webinar introduced a privacy ombudsperson (named in the session as Lena Taylor) and listed Office of Data Privacy staff (including Chris Bramwell, Micah Gorwala and Shane Paul) as resources offering templates and scanning tools for website tracking technology.

Audience questions and clarifications: During Q&A, attendees asked whether record-series classification must occur before a GRAMA (public-records) request; the presenter said classification by the city need not precede a GRAMA request and that record series are proposed locally and submitted to the State Archives for approval. The presenter also said converting a paper form to an electronic form is generally considered a "new" processing activity even if it collects the same fields. On data breaches, the webinar noted that breaches of public records do not trigger individual notice but do require a prominent website notice under the 2025 changes.

Outstanding concerns: Several attendees raised procurement and legal-liability questions. One attendee asked whether holding contractors to GDPA duties could erode governmental immunity for unauthorized access to government records; the presenter declined to answer the technical legal question on the call and invited offline follow-up with counsel, saying that issue requires deeper legal analysis.

Next steps and resources: The presenter encouraged attendees to begin by mapping processing activities, completing the privacy program report, designating officers, and using Office of Data Privacy templates and scanning tools. Slides and the recording will be shared with registrants; contact information given in the webinar included jtingey@ulct.utah.gov and a general league address in the chat. The Office of Data Privacy website (government entities tab) hosts training and draft templates the presenter said municipalities should consult.

Provenance: This article summarizes the presenter’s webinar remarks and the Q&A as recorded in the webinar transcript.