Utah Code 63A-19-401. Duties of governmental entities
Current as of: 2024 | Check for updates
|
Other versions
(1)
Terms Used In Utah Code 63A-19-401
- Agency: means a board, commission, institution, department, division, officer, council, office, committee, bureau, or other administrative unit of the state, including the agency head, agency employees, or other persons acting on behalf of or under the authority of the agency head, the Legislature, the courts, or the governor, but does not mean a political subdivision of the state, or any administrative unit of a political subdivision of the state. See Utah Code 63A-1-103
- Chief privacy officer: means the individual appointed under Section
63A-19-302 . See Utah Code 63A-19-101 - Data breach: means the unauthorized access, acquisition, disclosure, loss of access, or destruction of personal data held by a governmental entity, unless the governmental entity concludes, according to standards established by the Cyber Center, that there is a low probability that personal data has been compromised. See Utah Code 63A-19-101
- Designated governmental entity: means the same as that term is defined in Section
67-3-13 . See Utah Code 63A-19-101 - Governmental entity: means the same as that term is defined in Section
63G-2-103 . See Utah Code 63A-19-101 - Individual: means the same as that term is defined in Section
63G-2-103 . See Utah Code 63A-19-101 - Personal data: means information that is linked or can be reasonably linked to an identified individual or an identifiable individual. See Utah Code 63A-19-101
- Process: means a writ or summons issued in the course of a judicial proceeding. See Utah Code 68-3-12.5
- processing: means any operation or set of operations performed on personal data, including collection, recording, organization, structuring, storage, adaptation, alteration, access, retrieval, consultation, use, disclosure by transmission, transfer, dissemination, alignment, combination, restriction, erasure, or destruction. See Utah Code 63A-19-101
- Sell: means an exchange of personal data for monetary consideration by a governmental entity to a third party. See Utah Code 63A-19-101
- State: when applied to the different parts of the United States, includes a state, district, or territory of the United States. See Utah Code 68-3-12.5
- State agency: means the following entities that are under the direct supervision and control of the governor or the lieutenant governor:(19)(a)(i) a department;(19)(a)(ii) a commission;(19)(a)(iii) a board;(19)(a)(iv) a council;(19)(a)(v) an institution;(19)(a)(vi) an officer;(19)(a)(vii) a corporation;(19)(a)(viii) a fund;(19)(a)(ix) a division;(19)(a)(x) an office;(19)(a)(xi) a committee;(19)(a)(xii) an authority;(19)(a)(xiii) a laboratory;(19)(a)(xiv) a library;(19)(a)(xv) a bureau;(19)(a)(xvi) a panel;(19)(a)(xvii) another administrative unit of the state; or(19)(a)(xviii) an agent of an entity described in Subsections (19)(a)(i) through (xvii). See Utah Code 63A-19-101
- State privacy officer: means the individual described in Section
67-3-13 . See Utah Code 63A-19-101(1)(a) Except as provided in Subsections (1)(b) and (c), a governmental entity shall comply with the requirements of this part.(1)(b)(1)(b)(i) If a governmental entity or a contractor described in Subsection (4)(a) is subject to a more restrictive or a more specific provision of law than found in this part, the governmental entity or contractor shall comply with the more restrictive or more specific provision of law.(1)(b)(ii) For purposes of Subsection (1)(b)(i), Title 63G, Chapter 2, Government Records Access and Management Act, is a more specific provision of law and shall control over the provisions of this part.(1)(c) A governmental entity that is exempt under Section63G-2-702 ,63G-2-703 , or63G-2-704 from complying with the requirements in Title 63G, Chapter 2, Part 6, Collection of Information and Accuracy of Records, is exempt from complying with the requirements in Sections63A-19-402 ,63A-19-403 , and63A-19-404 . - State privacy officer: means the individual described in Section
(2) A governmental entity:
(2)(a) shall implement and maintain a privacy program before May 1, 2025, that includes the governmental entity’s policies, practices, and procedures for the process of personal data;
(2)(b) shall provide notice to an individual or the legal guardian of an individual, if the individual’s personal data is affected by a data breach, in accordance with Section 63A-19-406 ;
(2)(c) shall obtain and process only the minimum amount of personal data reasonably necessary to efficiently achieve a specified purpose;
(2)(d) shall meet the requirements of this part for all processing activities implemented by a governmental entity after May 1, 2024;
(2)(e) shall for any processing activity implemented before May 1, 2024, as soon as is reasonably practicable, but no later than January 1, 2027:
(2)(e)(i) identify any non-compliant processing activity;
(2)(e)(ii) document the non-compliant processing activity; and
(2)(e)(iii) prepare a strategy for bringing the non-compliant processing activity into compliance with this part;
(2)(f) may not establish, maintain, or use undisclosed or covert surveillance of individuals unless permitted by law;
(2)(g) may not sell personal data unless expressly required by law;
(2)(h) may not share personal data unless permitted by law;
(2)(i)
(2)(i)(i) that is a designated governmental entity, shall annually report to the state privacy officer:
(2)(i)(i)(A) the types of personal data the designated governmental entity currently shares or sells;
(2)(i)(i)(B) the basis for sharing or selling the personal data; and
(2)(i)(i)(C) the classes of persons and the governmental entities that receive the personal data from the designated governmental entity; and
(2)(i)(ii) that is a state agency, shall annually report to the chief privacy officer:
(2)(i)(ii)(A) the types of personal data the state agency currently shares or sells;
(2)(i)(ii)(B) the basis for sharing or selling the personal data; and
(2)(i)(ii)(C) the classes of persons and the governmental entities that receive the personal data from the state agency; and
(2)(j)
(2)(j)(i) except as provided in Subsection (3), an employee of a governmental entity shall complete a data privacy training program:
(2)(j)(i)(A) within 30 days after beginning employment; and
(2)(j)(i)(B) at least once in each calendar year; and
(2)(k) is responsible for monitoring completion of data privacy training by the governmental entity’s employees.
(3) An employee of a governmental entity that does not have access to personal data of individuals as part of the employee’s work duties is not required to complete a data privacy training program described in Subsection (2)(j)(i).
(4)
(4)(a) A contractor that enters into or renews an agreement with a governmental entity after May 1, 2024, and processes or has access to personal data as a part of the contractor’s duties under the agreement, is subject to the requirements of this chapter with regard to the personal data processed or accessed by the contractor to the same extent as required of the governmental entity.
(4)(b) An agreement under Subsection (4)(a) shall require the contractor to comply with the requirements of this chapter with regard to the personal data processed or accessed by the contractor as a part of the contractor’s duties under the agreement to the same extent as required of the governmental entity.
(4)(c) The requirements under Subsections (4)(a) and (b) are in addition to and do not replace any other requirements or liability that may be imposed for the contractor’s violation of other laws protecting privacy rights or government records.
