(1) There is created within the department the Office of Data Privacy.

Ask a business law question, get an answer ASAP!
Thousands of highly rated, verified business lawyers.
Click here to chat with a lawyer about your rights.

Terms Used In Utah Code 63A-19-301

  • Agency: means a board, commission, institution, department, division, officer, council, office, committee, bureau, or other administrative unit of the state, including the agency head, agency employees, or other persons acting on behalf of or under the authority of the agency head, the Legislature, the courts, or the governor, but does not mean a political subdivision of the state, or any administrative unit of a political subdivision of the state. See Utah Code 63A-1-103
  • Commission: means the Utah Privacy Commission established in Section 63C-24-102. See Utah Code 63A-19-101
  • Cyber Center: means the Utah Cyber Center created in Section 63A-16-1102. See Utah Code 63A-19-101
  • Department: means the Department of Government Operations. See Utah Code 63A-1-103
  • Governing board: means the Utah Privacy Governing Board established in Section 63A-19-201. See Utah Code 63A-19-101
  • Individual: means the same as that term is defined in Section 63G-2-103. See Utah Code 63A-19-101
  • Office: means the Office of Data Privacy created in Section 63A-19-301. See Utah Code 63A-19-101
  • Personal data: means information that is linked or can be reasonably linked to an identified individual or an identifiable individual. See Utah Code 63A-19-101
  • processing: means any operation or set of operations performed on personal data, including collection, recording, organization, structuring, storage, adaptation, alteration, access, retrieval, consultation, use, disclosure by transmission, transfer, dissemination, alignment, combination, restriction, erasure, or destruction. See Utah Code 63A-19-101
  • State: when applied to the different parts of the United States, includes a state, district, or territory of the United States. See Utah Code 68-3-12.5
  • State agency: means the following entities that are under the direct supervision and control of the governor or the lieutenant governor:
              (19)(a)(i) a department;
              (19)(a)(ii) a commission;
              (19)(a)(iii) a board;
              (19)(a)(iv) a council;
              (19)(a)(v) an institution;
              (19)(a)(vi) an officer;
              (19)(a)(vii) a corporation;
              (19)(a)(viii) a fund;
              (19)(a)(ix) a division;
              (19)(a)(x) an office;
              (19)(a)(xi) a committee;
              (19)(a)(xii) an authority;
              (19)(a)(xiii) a laboratory;
              (19)(a)(xiv) a library;
              (19)(a)(xv) a bureau;
              (19)(a)(xvi) a panel;
              (19)(a)(xvii) another administrative unit of the state; or
              (19)(a)(xviii) an agent of an entity described in Subsections (19)(a)(i) through (xvii). See Utah Code 63A-19-101
(2) The office shall coordinate with the governing board and the commission to perform the duties in this section.
(3) The office shall:

     (3)(a) create and maintain a strategic data privacy plan to:

          (3)(a)(i) assist state agencies to implement effective and efficient privacy practices, tools, and systems that:

               (3)(a)(i)(A) protect the privacy of personal data;
               (3)(a)(i)(B) comply with laws and regulations specific to the entity, program, or data;
               (3)(a)(i)(C) empower individuals to protect and control their personal data; and
               (3)(a)(i)(D) enable information sharing among entities, as allowed by law; and
          (3)(a)(ii) account for differences in state agency resources, capabilities, populations served, data types, and maturity levels regarding privacy practices;
     (3)(b) review statutory provisions related to governmental data privacy and records management to:

          (3)(b)(i) identify conflicts and gaps in data privacy law;
          (3)(b)(ii) standardize language; and
          (3)(b)(iii) consult impacted agencies and the attorney general regarding findings and proposed amendments;
     (3)(c) work with state agencies to study, research, and identify:

          (3)(c)(i) additional privacy requirements that are feasible for state agencies;
          (3)(c)(ii) potential remedies and accountability mechanisms for non-compliance of a state agency;
          (3)(c)(iii) ways to expand individual control and rights with respect to personal data held by state agencies; and
          (3)(c)(iv) resources needed to develop, implement, and improve privacy programs;
     (3)(d) monitor high-risk data processing activities within state agencies;
     (3)(e) receive information from state agencies regarding the sale, sharing, and processing personal data;
     (3)(f) coordinate with the Cyber Center to develop an incident response plan for data breaches affecting governmental entities;
     (3)(g) coordinate with the state archivist to incorporate data privacy practices into records management;
     (3)(h) coordinate with the state archivist to incorporate data privacy training into the trainings described in Section 63A-12-110; and
     (3)(i) create a data privacy training program for employees of governmental entities.
(4) The data privacy training program described in Subsection (3)(i) shall be made available to all governmental entities, and shall be designed to provide instruction regarding:

     (4)(a) data privacy best practices, obligations, and responsibilities; and
     (4)(b) the relationship between privacy, records management, and security.
(5)

     (5)(a) Except as provided in Subsection (5)(b), an employee of a state agency shall complete the data privacy training program described in Subsection (3)(i):

          (5)(a)(i) within 30 days of beginning employment; and
          (5)(a)(ii) at least once in each calendar year.
     (5)(b) An employee of a state agency that does not have access to personal data as part of the employee’s work duties is not required to complete the data privacy training program described in Subsection (3)(i).
     (5)(c) Each state agency is responsible for monitoring completion of data privacy training by the state agency’s employees.
(6) To the extent that resources permit, the office may provide expertise and assistance to governmental entities for high risk data processing activities.