Bill
Data Privacy Amendments
- Number
- H.B. 444 (2025GS)
- Sponsor
- Rep. Moss, Jefferson
- Final action
- Governor Signed 3/27/2025
- Outcome
- Became law — signed by Gov. Spencer J. Cox
Summary
This bill modifies provisions related to governmental data privacy and privacy oversight.
What it does
- This bill:
- defines terms;
- modifies requirements for privacy annotations and privacy notices;
- modifies requirements for government website privacy notices;
- modifies provisions related to data breach notification requirements;
- renames and modifies duties of the state privacy auditor;
- modifies enforcement provisions related to privacy requirements; and
- makes technical and conforming changes.
Every vote on this bill
2/25/2025House Comm - Substitute Recommendation
House Economic Development and Workforce Services Committee
9-0-1not eligible / no record2/25/2025House Comm - Favorable Recommendation
House Economic Development and Workforce Services Committee
9-0-1not eligible / no record2/27/2025House/ passed 3rd reading
Senate Secretary
73-0-2YEA3/3/2025Senate Comm - Substitute Recommendation
Senate Economic Development and Workforce Services Committee
4-0-2not eligible / no record3/3/2025Senate Comm - Favorable Recommendation
Senate Economic Development and Workforce Services Committee
5-0-1not eligible / no record3/6/2025House/ concurs with Senate amendment
Senate President
70-0-5YEA3/6/2025Senate/ passed 2nd & 3rd readings/ suspension
Clerk of the House
26-0-3not eligible / no recordBill text
enrolled version · official source
89 63A-12-100.5 63A-12-103 63A-12-104 63A-12-108 63A-12-115 63D-2-105 63A-19-101 63A-19-102 63C-24-201 63C-24-202 63A-19-301 63A-19-401 63A-19-401.1 63A-19-401.2 63A-19-401.3 63A-19-401.4 63A-19-402 63A-19-402.5 63A-19-405 63A-19-406 63A-19-501 63A-19-601 63A-19-602 63C-24-101 63C-24-102 63D-2-101 63D-2-102 63D-2-103 63G-2-103 63G-2-307 63G-2-601 67-3-1 67-3-13 63D-2-104 250 81 Data Privacy Amendments 2025 GENERAL SESSION STATE OF UTAH Chief Sponsor: Jefferson Moss Senate Sponsor: Kirk A. Cullimore LONG TITLE General Description: This bill modifies provisions related to governmental data privacy and privacy oversight. Highlighted Provisions: This bill: defines terms; modifies requirements for privacy annotations and privacy notices; modifies requirements for government website privacy notices; modifies provisions related to data breach notification requirements; renames and modifies duties of the state privacy auditor; modifies enforcement provisions related to privacy requirements; and makes technical and conforming changes. Money Appropriated in this Bill: None Other Special Clauses: This bill provides a special effective date. Utah Code Sections Affected: AMENDS: 63A-12-100.5 , as last amended by Laws of Utah 2023, Chapter 173 63A-12-103 , as last amended by Laws of Utah 2021, Chapter 344 63A-12-104 , as repealed and reenacted by Laws of Utah 2023, Chapter 173 63A-12-108 , as last amended by Laws of Utah 2023, Chapter 173 63A-19-101 , as enacted by Laws of Utah 2024, Chapter 417 63A-19-102 , as enacted by Laws of Utah 2024, Chapter 417 63A-19-301 , as enacted by Laws of Utah 2024, Chapter 417 63A-19-401 , as enacted by Laws of Utah 2024, Chapter 417 63A-19-402 , as enacted by Laws of Utah 2024, Chapter 417 63A-19-405 , as enacted by Laws of Utah 2024, Chapter 417 63A-19-406 , as enacted by Laws of Utah 2024, Chapter 417 63A-19-501 , as enacted by Laws of Utah 2024, Chapter 417 63A-19-601 , as enacted by Laws of Utah 2024, Chapter 417 63G-2-103 , as last amended by Laws of Utah 2024, Chapters 18, 465, 509, and 522 63G-2-307 , as last amended by Laws of Utah 2023, Chapter 173 63G-2-601 , as last amended by Laws of Utah 2023, Chapter 173 67-3-1 , as last amended by Laws of Utah 2024, Chapters 3, 158 67-3-13 , as last amended by Laws of Utah 2024, Chapter 417 ENACTS: 63A-19-401.1 , Utah Code Annotated 1953 63A-19-401.2 , Utah Code Annotated 1953 63A-19-401.3 , Utah Code Annotated 1953 63A-19-401.4 , Utah Code Annotated 1953 63A-19-402.5 , Utah Code Annotated 1953 63A-19-602 , Utah Code Annotated 1953 RENUMBERS AND AMENDS: 63A-16-110 , (Renumbered from 63D-2-105, as last amended by Laws of Utah 2024, Chapter 426) 63A-19-203 , (Renumbered from 63C-24-201, as last amended by Laws of Utah 2024, Chapter 417) 63A-19-204 , (Renumbered from 63C-24-202, as last amended by Laws of Utah 2024, Chapter 417) 78A-2-233 , (Renumbered from 63D-2-104, as last amended by Laws of Utah 2008, Chapter 3) REPEALS: 63A-12-115 , as last amended by Laws of Utah 2024, Chapter 417 63C-24-101 , as last amended by Laws of Utah 2024, Chapter 417 63C-24-102 , as last amended by Laws of Utah 2024, Chapter 417 63D-2-101 , as enacted by Laws of Utah 2004, Chapter 175 63D-2-102 , as last amended by Laws of Utah 2024, Chapter 426 63D-2-103 , as last amended by Laws of Utah 2008, Chapter 382 Be it enacted by the Legislature of the state of Utah: Section 1, Section 63A-12-100.5 is amended to read: 63A-12-100.5 . Definitions. (1) Except as provided under Subsection (2) , the definitions in Section 63G-2-103 apply to this chapter. (2) As used in this chapter: (a) "Chief administrative officer" means the individual designated by a governmental entity to perform the duties described in Section 63A-12-103 . (b) "Division" means the Division of Archives and Records Service. (b) (i) "Executive branch agency" means the same as that term is defined in Section 63A-16-102 . (ii) "Executive branch agency" includes a state agency, as defined in Subsection 67-1-17(1)(d) . (c) (i) "Personal identifying information" means information about an individual that: (A) identifies, or can be used to identify, an individual; (B) distinguishes an individual from one or more other individuals; or (C) is, or can be, logically associated with other information or data, through technology or otherwise, to identify an individual or distinguish an individual from one or more other individuals. (ii) "Personal identifying information" includes information identified as personal identifying information in accordance with the rules described in Section 63A-12-104 . (d) "Privacy annotation" means a summary, described in Subsection 63A-12-115(2) and rules made by the executive director under Subsection 63A-12-104(2) , that, for each record series that an executive branch agency collects, maintains, or uses: (i) discloses whether the record series contains personal identifying information; and (ii) if the record series contains personal identifying information, includes the information described in Subsection 63A-12-115(2)(b) . (e) (c) "Record" means: (i) the same as that term is defined in Section 63G-2-103 ; or (ii) a video or audio recording of an interview, or a transcript of the video or audio recording, that is conducted at a Children's Justice Center established under Section 67-5b-102 , the release of which is governed by Section 77-37-4 . (d) "Records officer" means an individual appointed by the chief administrative officer whose primary responsibility is to care, maintain, use, schedule, dispose, classify, designate, manage access to, and preserve records in accordance with applicable laws. (f) (e) "State archives" means the Division of Archives and Records Service. (g) (f) "Vulnerable adult" means the same as that term is defined in Section 26B-6-201 . (h) (g) "Vulnerable record" means a record or data relating to: (i) national security interests; (ii) the care, custody, or control of a child; (iii) a fiduciary trust over money; (iv) health care of a child; or (v) the following, in relation to a vulnerable adult: (A) protection, health care, or other care; or (B) the provision of food, shelter, clothing, assistance with an activity of daily living, or assistance with financial resource management. Section 2, Section 63A-12-103 is amended to read: 63A-12-103 . Duties of governmental entities. The chief administrative officer of each governmental entity shall Each governmental entity shall designate a chief administrative officer who shall be responsible to : (1) establish and maintain an active, continuing program for the economical and efficient management of the governmental entity's records as provided by this chapter and Title 63G, Chapter 2, Government Records Access and Management Act ; (2) appoint one or more records officers who will be trained to work with the state archives in the care, maintenance, scheduling, disposal, classification, designation, access, and preservation of records; (3) ensure that officers and employees of the governmental entity that receive or process records requests receive required training on the procedures and requirements of this chapter and Title 63G, Chapter 2, Government Records Access and Management Act ; (4) make and maintain adequate and proper documentation of the organization, functions, policies, decisions, procedures, and essential transactions of the governmental entity designed to furnish information to protect the privacy, transparency, legal , and financial rights of persons directly affected by the entity's activities; (5) submit to the state archivist proposed schedules of records for final approval by the Records Management Committee created in Section 63A-12-112 ; (6) cooperate with the state archivist in conducting surveys made by the state archivist; (7) comply with rules issued by the Department of Government Operations as provided by Section 63A-12-104 ; (8) report to the state archives : (a) the designation of each record series that it the governmental entity maintains; (9) report to the state archives (b) the classification of each record series that is the governmental entity has classified; and (c) the name of the governmental entity's: (i) chief administrative officer; and (ii) records officers; (9) ensure that the governmental entity complies with the requirements found in: (a) this part; (b) Title 63G, Chapter 2, Government Records Access and Management Act; and (c) Chapter 19, Part 4, Duties of Governmental Entities; and (10) establish and report to the state archives retention schedules for objects that the governmental entity determines are not defined as a record under Section 63G-2-103 , but that have historical or evidentiary value. Section 3, Section 63A-12-104 is amended to read: 63A-12-104 . Rulemaking authority. (1) In accordance with Title 63G, Chapter 3, Utah Administrative Rulemaking Act : (a) (1) the state archivist may , for an executive branch agency, make rules establishing procedures for the collection, storage, designation, classification, access, mediation for records access, and management of records under this chapter and Title 63G, Chapter 2, Government Records Access and Management Act ; and (b) (2) a department governmental entity may make rules , policies, or ordinances specifying at which level within the department governmental entity the requirements described in this chapter will be undertaken. (2) In accordance with Title 63G, Chapter 3, Utah Administrative Rulemaking Act , the executive director shall, in consultation with the state archivist and the chief privacy officer, make rules for an executive branch agency that establish: (a) requirements for making an inventory of each record series that contains personal identifying information, including: (i) information collected as part of the inventory; (ii) regularly reviewing, updating, and maintaining the inventory; and (iii) reporting the inventory to the chief privacy officer; (b) a list of information, categories of information, or types of information expressly designated as personal identifying information, in accordance with the criteria described in Subsections 63A-12-100.5(2)(c)(i) through (iii) ; (c) criteria, variables, and principles for determining whether information in a record series, not expressly designated under Subsection (2)(b) , is personal identifying information; (d) a list and description of categories or types of personal identifying information that are collected, maintained, or used by executive branch agencies; and (e) requirements for the form, content, format, review, and update of a privacy annotation. (3) The rules described in Subsection (2)(b) may incorporate, by reference, a data dictionary that a records officer appointed under Subsection 63A-12-103(2)(a) shall use in making the determination described in Subsection (2)(c) . Section 4, Section 63A-12-108 is amended to read: 63A-12-108 . Inspection and summary of record series. (1) State archives shall provide for public inspection of : (a) the title and a summary description of each record series ; and . (b) for an executive branch agency, the privacy annotation of each record series. (2) The department shall: (a) post the data dictionary described in Subsection 63A-12-104(3) on the department's website; and (b) maintain and update the data dictionary on a regular basis. Section 5, Section 63A-16-110 , which is renumbered from Section 63D-2-105 is renumbered and amended to read: 63D-2-105 63A-16-110 . Use of authorized domain extensions for government websites. (1) As used in this section , : (a) "authorized top level "Authorized top-level domain" means any of the following suffixes that follows follow the domain name in a website address: (a) (i) gov; (b) (ii) edu; and (c) (iii) mil. (b) "Governmental entity" means the same as that term is defined in Section 63G-2-103 . (c) "Government website" means the same as that term is defined in Section 63A-19-101 . (d) "Person" means the same as that term is defined in Section 63G-2-103 . (e) "School" means a public elementary or secondary school. (2) Beginning July 1, 2025, a governmental entity shall use an authorized top level top-level domain for: (a) the website address for the governmental entity's government website; and (b) the email addresses used by the governmental entity and the governmental entity's employees. (3) Notwithstanding Subsection (2), a governmental entity may operate a website that uses a top level top-level domain that is not an authorized top level top-level domain if: (a) (i) a reasonable person would not mistake the website as the governmental entity's primary government website; and (ii) the governmental government website is: (A) solely for internal use and not intended for use by members of the public; (B) temporary and in use by the governmental entity for a period of less than one year; or (C) related to an event, program, or informational campaign operated by the governmental entity in partnership with another person that is not a governmental entity; or (b) the governmental entity is a school district or a school that is not an institution of higher education and the use of an authorized top level top-level domain is otherwise prohibited, provided that once the use of an authorized top level top-level domain is not otherwise prohibited, the school district or school shall transition to an authorized top level top-level domain within 15 months. (4) The chief information officer appointed under Section 63A-16-201 may authorize a waiver of the requirement in Subsection (2) if: (a) there are extraordinary circumstances under which use of an authorized domain extension would cause demonstrable harm to citizens or businesses; and (b) the executive director or chief executive of the governmental entity submits a written request to the chief information officer that includes a justification for the waiver. Section 6, Section 63A-19-101 is amended to read: 63A-19-101 . Definitions. As used in this chapter: (1) "Anonymized data" means information that has been irreversibly modified so that there is no possibility of using the information, alone or in combination with other information, to identify an individual. (2) "At-risk government employee" means the same as that term is defined in Section 63G-2-303 . (3) "Automated decision making" means using personal data to make a decision about an individual through automated processing, without human review or intervention. (4) "Biometric data" means the same as that term is defined in Section 13-61-101 . (5) "Chief administrative officer" means the same as that term is defined in Section 63A-12-100.5 . (6) "Chief privacy officer" means the individual appointed under Section 63A-19-302 . (2) (7) "Commission" means the Utah Privacy Commission established in Section 63C-24-102 63A-19-203 . (8) "Contract" means an agreement between a governmental entity and a person for goods or services that involve personal data. (9) (a) "Contractor" means a person who: (i) has entered into a contract with a governmental entity; and (ii) may process personal data under the contract. (b) "Contractor" includes a contractor's employees, agents, or subcontractors. (3) (10) "Cyber Center" means the Utah Cyber Center created in Section 63A-16-1102 . (4) (11) "Data breach" means the unauthorized access, acquisition, disclosure, loss of access, or destruction of personal data held by a governmental entity, unless the governmental entity concludes, according to standards established by the Cyber Center, that there is a low probability that personal data has been compromised. (5) (12) "Designated governmental entity" means the same as that term is defined in Section 67-3-13 . "De-identified data" means information from which personal data has been removed or obscured so that the information is not readily identifiable to a specific individual, and which may not be re-identified. (13) "Genetic data" means the same as that term is defined in Section 13-60-102 . (6) (14) "Governing board" means the Utah Privacy Governing Board established in Section 63A-19-201 . (7) (15) "Governmental entity" means the same as that term is defined in Section 63G-2-103 . (16) "Government website" means a set of related web pages that is operated by or on behalf of a governmental entity and is: (a) located under a single domain name or web address; and (b) accessible directly through the Internet or by the use of a software program. (8) (17) (a) " High risk High-risk processing activities" means a governmental entity's processing of personal data that may result in a significant compromise to have a significant impact on an individual's privacy interests, based on factors that include: (a) (i) the sensitivity of the personal data processed; (b) (ii) the amount of personal data being processed; (c) (iii) the individual's ability to consent to the processing of personal data; and (d) (iv) risks of unauthorized access or use. (b) "High-risk processing activities" may include the use of: (i) facial recognition technology; (ii) automated decision making; (iii) profiling; (iv) genetic data; (v) biometric data; or (vi) geolocation data. (9) (18) "Independent entity" means the same as that term is defined in Section 63E-1-102 . (19) "Individual" means the same as that term is defined in Section 63G-2-103 . (10) (20) "Legal guardian" means: (a) the parent of a minor; or (b) an individual appointed by a court to be the guardian of a minor or incapacitated person individual and given legal authority to make decisions regarding the person or property of the minor or incapacitated person individual . (11) (21) "Office" means the Utah Office of Data Privacy created in Section 63A-19-301 . (12) (22) "Ombudsperson" means the data privacy ombudsperson appointed under Section 63A-19-501 . (23) "Person" means the same as that term is defined in Section 63G-2-103 . (13) (24) "Personal data" means information that is linked or can be reasonably linked to an identified individual or an identifiable individual. (25) "Privacy annotation" means a summary of personal data contained in a record series as described in Section 63A-19-401.1 . (26) "Privacy practice" means a governmental entity's: (a) organizational, technical, administrative, and physical safeguards designed to protect an individual's personal data; (b) policies and procedures related to the acquisition, use, storage, sharing, retention, and disposal of personal data; and (c) practice of providing notice to an individual regarding the individual's privacy rights. (14) (27) "Process , " or "processing , " or "processing activity" means any operation or set of operations performed on personal data, including collection, recording, organization, structuring, storage, adaptation, alteration, access, retrieval, consultation, use, disclosure by transmission, transfer, dissemination, alignment, combination, restriction, erasure, or destruction. (28) "Profiling" means the processing of personal data to evaluate or predict an individual's: (a) economic situation; (b) health; (c) personal preferences; (d) interests; (e) reliability; (f) behavior; (g) location; or (h) movements. (29) "Purchase" or "purchasing" means the exchange of monetary consideration to obtain the personal data of an individual who is not a party to the transaction. (15) (30) "Record" means the same as that term is defined in Section 63G-2-103 . (16) (31) "Record series" means the same as that term is defined in Section 63G-2-103 . (17) (32) "Retention schedule" means a governmental entity's schedule for the retention or disposal of records that has been approved by the Records Management Committee pursuant to Section 63A-12-113 . (18) (33) (a) "Sell" means an exchange of personal data for monetary consideration by a governmental entity to a third party. (b) "Sell" does not include a fee: (i) charged by a governmental entity for access to a record pursuant to Section 63G-2-203 ; or (ii) assessed in accordance with an approved fee schedule. (19) (34) (a) "State agency" means the following entities that are under the direct supervision and control of the governor or the lieutenant governor: (i) a department; (ii) a commission; (iii) a board; (iv) a council; (v) an institution; (vi) an officer; (vii) a corporation; (viii) a fund; (ix) a division; (x) an office; (xi) a committee; (xii) an authority; (xiii) a laboratory; (xiv) a library; (xv) a bureau; (xvi) a panel; (xvii) another administrative unit of the state; or (xviii) an agent of an entity described in Subsections (19) (34) (a)(i) through (xvii). (b) "State agency" does not include: (i) the legislative branch; (ii) the judicial branch; (iii) an executive branch agency within the Office of the Attorney General, the state auditor, the state treasurer, or the State Board of Education; or (iv) an independent entity. (20) (35) "State privacy officer" means the individual described in Section 67-3-13 "State privacy auditor" means the same as that term is defined in Section 67-3-13 . (36) "Synthetic data" means artificial data that: (a) is generated from personal data; and (b) models the statistical properties of the original personal data. (37) "User" means an individual who accesses a government website. (38) (a) "User data" means any information about a user that is automatically collected by a government website when a user accesses the government website. (b) "User data" includes information that identifies: (i) a user as having requested or obtained specific materials or services from a government website; (ii) Internet sites visited by a user; (iii) the contents of a user's data-storage device; (iv) any identifying code linked to a user of a government website; and (v) a user's: (A) IP or Mac address; or (B) session ID. (39) "Website tracking technology" means any tool used by a government website to: (a) monitor a user's behavior; or (b) collect user data. Section 7, Section 63A-19-102 is amended to read: 63A-19-102 . State data privacy policy. It is the policy of Utah that: (1) an individual has a fundamental interest in and inherent expectation of privacy regarding the individual's personal data that the individual provides to a governmental entity; (2) a governmental entity shall act process personal data in a manner respecting personal data provided to the governmental entity that is consistent with the interests and expectations described in Subsection (1); (3) the state shall encourage innovation to enhance the ability of a governmental entity to: (a) protect the privacy of an individual's personal data; (b) provide clear notice to an individual regarding the governmental entity's processing of the individual's personal data; (c) process personal data only for specified, lawful purposes and only process the minimum amount of an individual's personal data necessary to achieve those purposes; (d) implement appropriate consent mechanisms regarding the uses of an individual's personal data; (e) provide an individual with the ability to access, control, and request corrections to the individual's personal data held by a governmental entity; (f) maintain appropriate safeguards to protect the confidentiality, integrity, and availability of personal data; (g) account for compliance with privacy related laws, rules, and regulations that are specific to a particular governmental entity, program, or personal data; and (h) meet a governmental entity's and an individual's business and service needs; (4) the state shall promote training and education programs for employees of governmental entities focused on: (a) data privacy best practices, obligations, and responsibilities; and (b) the overlapping relationship with privacy, records management, and security; and (5) the state shall promote consistent terminology in data privacy requirements across governmental entities. Section 8, Section 63A-19-203 , which is renumbered from Section 63C-24-201 is renumbered and amended to read: 63C-24-201 63A-19-203 . Utah Privacy Commission created. (1) There is created the Utah Privacy Commission. (2) (a) The commission shall be composed of 12 members. (b) The governor shall appoint: (i) one member who, at the time of appointment provides internet technology services for a county or a municipality ; (ii) one member with experience in cybersecurity; (iii) one member representing private industry in technology; (iv) one member representing law enforcement; and (v) one member with experience in data privacy law. (c) The state auditor shall appoint: (i) one member with experience in internet technology services; (ii) one member with experience in cybersecurity; (iii) one member representing private industry in technology; (iv) one member with experience in data privacy law; and (v) one member with experience representing municipalities who, at the time of appointment, has expertise in civil liberties law , the ethical use of data, or policy and with specific experience in identifying the disparate the impacts of the use of a technology or a policy on different populations. (d) The attorney general shall appoint: (i) one member with experience as a prosecutor or appellate attorney and with experience in data privacy or civil liberties law; and (ii) one member representing law enforcement. (3) (a) Except as provided in Subsection (3)(b), a member is appointed for a term of four years. (b) The initial appointments of members described in Subsections (2)(b)(i) through (b)(iii), (2)(c)(iv) through (c)(v), and (2)(d)(ii) shall be for two-year terms. (c) When the term of a current member expires, a member shall be reappointed or a new member shall be appointed in accordance with Subsection (2). (4) (a) When a vacancy occurs in the membership for any reason, a replacement shall be appointed in accordance with Subsection (2) for the unexpired term. (b) A member whose term has expired may continue to serve until a replacement is appointed. (5) The commission shall select officers from the commission's members as the commission finds necessary. (6) (a) A majority of the members of the commission is a quorum. (b) The action of a majority of a quorum constitutes an action of the commission. (7) A member may not receive compensation or benefits for the member's service but may receive per diem and travel expenses incurred as a member of the commission at the rates established by the Division of Finance under: (a) Sections 63A-3-106 and 63A-3-107 ; and (b) rules made by the Division of Finance in accordance with Sections 63A-3-106 and 63A-3-107 . (8) A member shall refrain from participating in a review of: (a) an entity of which the member is an employee; or (b) a technology in which the member has a financial interest. (9) The state auditor shall provide staff and support to the commission. (10) The commission shall meet up to 12 times a year to accomplish the duties described in Section 63C-24-202 63A-19-204 . Section 9, Section 63A-19-204 , which is renumbered from Section 63C-24-202 is renumbered and amended to read: 63C-24-202 63A-19-204 . Commission duties. (1) The commission shall: (a) annually develop a data privacy agenda that identifies for the upcoming year: (i) governmental entity privacy practices to be reviewed by the commission; (ii) educational and training materials that the commission intends to develop; (iii) any other items related to data privacy the commission intends to study; and (iv) best practices and guiding principles that the commission plans to develop related to government privacy practices; (b) develop guiding standards and best practices with respect to government privacy practices; (c) develop educational and training materials that include information about: (i) the privacy implications and civil liberties concerns of the privacy practices of government entities; (ii) best practices for government collection and retention policies regarding personal data; and (iii) best practices for government personal data security standards; (d) review the privacy implications and civil liberties concerns of government privacy practices; and (e) provide the data privacy agenda to the governing board by May 1 of each year. (2) The commission may, in addition to the approved items in the data privacy agenda prepared under Subsection (1)(a): (a) review specific government privacy practices as referred to the commission by the chief privacy officer described in Section 63A-19-302 or the state privacy officer auditor described in Section 67-3-13 ; (b) review a privacy practice not accounted for in the data privacy agenda only upon referral by the chief privacy officer or the state privacy officer auditor in accordance with Subsection 63C-24-202 (2)(a) this section ; (c) review and provide recommendations regarding consent mechanisms used by governmental entities to collect personal information; (d) develop and provide recommendations to the Legislature on how to balance transparency and public access of public records against an individual's reasonable expectations of privacy and data protection; and (e) develop recommendations for legislation regarding the guiding standards and best practices the commission has developed in accordance with Subsection (1)(a). (3) At least annually, on or before October 1, the commission shall report to the Judiciary Interim Committee: (a) the results of any reviews the commission has conducted; (b) the guiding standards and best practices described in Subsection (1)(b); and (c) any recommendations for legislation the commission has developed in accordance with Subsection (2)(e). (4) At least annually, on or before June 1, the commission shall report to the governing board regarding: (a) governmental entity privacy practices the commission plans to review in the next year; (b) any educational and training programs the commission intends to develop in relation to government data privacy best practices; (c) results of the commission's data privacy practice reviews from the previous year; and (d) recommendations from the commission related to data privacy legislation, standards, or best practices. (5) The data privacy agenda detailed in Subsection (1)(a) does not add to or expand the authority of the commission. Section 10, Section 63A-19-301 is amended to read: 63A-19-301 . Utah Office of Data Privacy. (1) There is created within the department the Utah Office of Data Privacy. (2) The office shall coordinate with the governing board and the commission to perform the duties in this section. (3) The office shall: (a) create and maintain a strategic data privacy plan framework designed to: (i) assist state agencies assist governmental entities to identify and implement effective and efficient data privacy practices, tools, and systems that: (A) protect the privacy of personal data; (B) comply with data privacy laws and regulations specific to the governmental entity, program, or data; (C) empower individuals to protect and control their personal data; and (D) enable information use and sharing among governmental entities, as allowed by law; and (ii) account for differences in state agency a governmental entity's resources, capabilities, populations served, data types, and maturity levels level regarding data privacy practices; (b) review statutory provisions related to governmental data privacy and records management to: (i) identify conflicts and gaps in data privacy law; and (ii) standardize language; and (iii) consult impacted agencies and the attorney general regarding findings and proposed amendments; (c) work with state agencies governmental entities to study, research, and identify: (i) additional data privacy requirements practices that are feasible for state agencies governmental entities ; (ii) potential remedies and accountability mechanisms for non-compliance of a state agency governmental entity ; (iii) ways to expand individual an individual's control and rights with respect to over the individual's personal data held by state agencies; and processed by a governmental entity; (iv) resources needed to develop, implement, and improve data privacy programs; and (v) best practices regarding: (A) automated decision making; (B) the creation and use of synthetic, de-identified, or anonymized data; and (C) the use of website tracking technology; (d) monitor high-risk data processing activities within state agencies governmental entities ; (e) receive information from state agencies regarding the sale, sharing, and processing personal data; (f) (e) coordinate with the Cyber Center to develop an incident response plan for data breaches affecting governmental entities; (g) coordinate with the state archivist to incorporate data privacy practices into records management; (h) coordinate with the state archivist to incorporate data privacy training into the trainings described in Section 63A-12-110 ; and (i) (f) coordinate with the state archivist to: (i) incorporate data privacy practices into records management; and (ii) include data privacy content in the trainings described in Section 63A-12-110 ; and (g) create a data privacy training program for employees of governmental entities as described in Section 63A-19-401.3 . (4) The data privacy training program described in Subsection (3)(i) shall be made available to all governmental entities, and shall be designed to provide instruction regarding: (a) data privacy best practices, obligations, and responsibilities; and (b) the relationship between privacy, records management, and security. (5) (a) Except as provided in Subsection (5)(b), an employee of a state agency shall complete the data privacy training program described in Subsection (3)(i): (i) within 30 days of beginning employment; and (ii) at least once in each calendar year. (b) An employee of a state agency that does not have access to personal data as part of the employee's work duties is not required to complete the data privacy training program described in Subsection (3)(i). (c) Each state agency is responsible for monitoring completion of data privacy training by the state agency's employees. (6) (4) To the extent that resources permit, the The office may : (a) provide expertise and assistance to governmental entities for high risk high-risk data processing activities . ; (b) create assessment tools and resources that a governmental entity may use to: (i) review, evaluate, and mature the governmental entity's privacy program, practices, and processing activities; and (ii) evaluate the privacy impact, privacy risk, and privacy compliance of the governmental entity's privacy program, practices, and processing activities; (c) charge a governmental entity a service fee, established in accordance with Section 63J-1-504 , for providing services that enable a governmental entity to perform the governmental entity's duties under Section 63A-19-401 , if the governmental entity requests the office provide those services; (d) bill a state agency, as provided in Section 63J-1-410 , for any services the office provides to a state agency; (e) provide funding to assist a governmental entity in complying with: (i) this chapter; and (ii) Title 63G, Chapter 2, Part 3, Classification, and Title 63G, Chapter 2, Part 6, Collection of Information and Accuracy of Records; and (f) make rules in accordance with Title 63G, Chapter 3, Utah Administrative Rulemaking Act, to administer this part. (5) (a) Upon application by a governmental entity, the office may: (i) grant, for a limited period of time, a governmental entity with an: (A) extension of time to comply with certain requirements of Part 4, Duties of Governmental Entities; or (B) exemption from complying with certain requirements of Part 4, Duties of Governmental Entities; or (ii) allow a governmental entity to establish a data privacy training program for the governmental entity's employees to complete, instead of the data privacy training program established by the office under Section 63A-19-401.3 , if the governmental entity's data privacy training program contains the same information contained in the office's data privacy training program. (b) An application for an extension or exemption submitted under Subsection (5)(a)(i) shall: (i) identify the specific duty from which the governmental entity seeks an extension or exemption and the section that imposes that duty; and (ii) include a justification for the requested extension or exemption. (c) If the office grants an exemption under Subsection (5)(a), the office shall report at the next board meeting: (i) the name of the governmental entity that received an exemption; and (ii) the nature of the exemption. (d) The office shall notify the state privacy auditor of any approved extensions or exemptions. Section 11, Section 63A-19-401 is amended to read: 63A-19-401 . Duties of governmental entities. (1) (a) Except as provided in Subsections (1)(b) and (c), a governmental entity shall comply with the requirements of this part. (b) (i) If a governmental entity or a contractor described in Subsection (4)(a) is subject to a more restrictive or a more specific provision of law than found in this part, the governmental entity or contractor shall comply with the more restrictive or more specific provision of law. (ii) For purposes of Subsection (1)(b)(i), Title 63G, Chapter 2, Government Records Access and Management Act, is a more specific provision of law and shall control over the provisions of this part. (b) If any provision in this part conflicts with any other provisions of law, the more specific or more restrictive law shall control. (c) A governmental entity that is exempt under Section 63G-2-702 , 63G-2-703 , or 63G-2-704 from complying with the requirements in Title 63G, Chapter 2, Part 6, Collection of Information and Accuracy of Records, is exempt from complying with the requirements in Sections 63A-19-402 , 63A-19-403 , and 63A-19-404 this chapter . (2) (a) A governmental entity shall : (a) shall implement and maintain a privacy program before May 1, 2025, that includes the governmental entity's policies, practices, and procedures for the process of personal data; (b) shall provide notice to an individual or the legal guardian of an individual, if the individual's personal data is affected by a data breach, in accordance with Section 63A-19-406 ; (c) (i) initiate a data privacy program before December 31, 2025; (ii) shall obtain and process only the minimum amount of personal data reasonably necessary to efficiently achieve a specified purpose; (d) (iii) shall meet the requirements of this part for all new processing activities implemented by a governmental entity after May 1, 2024 ; and (e) (iv) shall for any processing activity implemented before May 1, 2024 May 7, 2025 , as soon as is reasonably practicable, but no later than January July 1, 2027: (i) (A) identify any non-compliant processing activity; (ii) (B) document the non-compliant processing activity; and (iii) (C) prepare a strategy for bringing the non-compliant processing activity into compliance with this part; and (D) include the information described in Subsections (2)(a)(iv)(A) through (C) in the privacy program report described in Section 63A-19-401.3 . (i) (i) that is a designated governmental entity, shall annually report to the state privacy officer: (A) the types of personal data the designated governmental entity currently shares or sells; (B) the basis for sharing or selling the personal data; and (C) the classes of persons and the governmental entities that receive the personal data from the designated governmental entity; and (ii) that is a state agency, shall annually report to the chief privacy officer: (A) the types of personal data the state agency currently shares or sells; (B) the basis for sharing or selling the personal data; and (C) the classes of persons and the governmental entities that receive the personal data from the state agency; and (j) (i) except as provided in Subsection (3), an employee of a governmental entity shall complete a data privacy training program: (A) within 30 days after beginning employment; and (B) at least once in each calendar year; and (k) is responsible for monitoring completion of data privacy training by the governmental entity's employees. (b) A governmental entity that fulfills the reporting requirement under Section 63A-19-401.3 satisfies the requirement to initiate a privacy program under Subsection (2)(a)(i) . (f) (3) A governmental entity may not : (a) establish, maintain, or use undisclosed or covert surveillance of individuals unless permitted by law; (g) (b) may not sell personal data unless expressly required by law; and (h) (c) may not share personal data unless permitted by law ; . (3) An employee of a governmental entity that does not have access to personal data of individuals as part of the employee's work duties is not required to complete a data privacy training program described in Subsection (2)(j)(i). (4) (a) A contractor that enters into or renews an agreement with a governmental entity after May 1, 2024, and processes or has access to personal data as a part of the contractor's duties under the agreement, is subject to the requirements of this chapter with regard to the personal data processed or accessed by the contractor to the same extent as required of the governmental entity. (b) An agreement under Subsection (4)(a) shall require the contractor to comply with the requirements of this chapter with regard to the personal data processed or accessed by the contractor as a part of the contractor's duties under the agreement to the same extent as required of the governmental entity. (c) The requirements under Subsections (4)(a) and (b) are in addition to and do not replace any other requirements or liability that may be imposed for the contractor's violation of other laws protecting privacy rights or government records. Section 12, Section 63A-19-401.1 is enacted to read: 63A-19-401.1 . Privacy annotations. (1) (a) Beginning July 1, 2027, a state agency shall make a complete and accurate privacy annotation for each record series containing personal data that the state agency collects, maintains, or uses. (b) After July 1, 2027, a state agency that has not created a privacy annotation for a record series containing personal data, may not collect, maintain, or use the personal data. (2) If a state agency determines that a record series: (a) does not contain personal data, the privacy annotation shall be limited to a statement indicating that the record series does not include personal data; or (b) contains personal data, the privacy annotation shall include: (i) an inventory of all types of personal data included in the record series; (ii) a description of all purposes for which the state agency collects, keeps, or uses the personal data; (iii) a citation to the state agency's legal authority for collecting, keeping, or using the personal data; and (iv) any other information required by the rules created by the office under Section 63A-19-301 . Section 13, Section 63A-19-401.2 is enacted to read: 63A-19-401.2 . Training requirements. (1) The data privacy training program created by the office under Section 63A-4-301 shall be: (a) designed to provide instruction regarding: (i) data privacy best practices, obligations, and responsibilities; and (ii) the relationship between privacy, records management, and security; and (b) required for all employees of a governmental entity who: (i) have access to personal data as part of the employee's work duties; or (ii) supervise an employee who has access to personal data. (2) The training described in Subsection (1) shall be completed: (a) within 30 days after an employee of a governmental entity begins employment; and (b) at least once in each calendar year. (3) A governmental entity is responsible for: (a) ensuring that each employee of the governmental entity completes the data privacy training as required by Subsection (2); and (b) reporting the governmental entity's compliance with the training requirements as described in Section 63A-19-401.3 . Section 14, Section 63A-19-401.3 is enacted to read: 63A-19-401.3 . Privacy program report. (1) On or before December 31 of each year, the chief administrative officer of each governmental entity shall prepare a report that includes: (a) whether the governmental entity has initiated a privacy program; (b) a description of: (i) any privacy practices implemented by the governmental entity; (ii) strategies for improving the governmental entity's privacy program and practices; and (iii) the governmental entity's high-risk processing activities; (c) a list of the types of personal data the governmental entity currently shares, sells, or purchases; (d) the legal basis for sharing, selling, or purchasing personal data; (e) the category of individuals or entities: (i) with whom the governmental entity shares personal data; (ii) to whom the governmental entity sells personal data; or (iii) from whom the governmental entity purchases personal data; (f) the percentage of the governmental entity's employees that have fulfilled the data privacy training requirements described in Section 63A-19-401.2 ; and (g) a description of any non-compliant processing activities identified under Subsection 63A-19-401(2)(a)(iv) and the governmental entity's strategy for bringing those activities into compliance with this part. (2) The report described in Subsection (1): (a) shall be considered a protected record under Section 63G-2-305 ; and (b) may be made available at the request of the office. Section 15, Section 63A-19-401.4 is enacted to read: 63A-19-401.4 . Requirements for contractors. (1) Except as provided in Subsection (4), a contractor that processes or has access to personal data as a part of the contractor's duties under a contract with a governmental entity is subject to the requirements of this chapter to the same extent as the governmental entity for any personal data the contractor processes or has access to under a contract with the governmental entity. (2) A contract entered into or renewed between a contractor and a governmental entity after July 1, 2026, shall contain specific language that requires a contractor to comply with the requirements of this chapter with regard to the personal data processed or accessed by the contractor as a part of the contractor's duties under a contract to the same extent as required of the governmental entity. (3) The requirements under this section are in addition to and do not replace any other requirements or liability that may be imposed for the contractor's violation of other laws protecting privacy rights or government records. (4) A contractor is not subject to the data privacy training program requirements described in Section 63A-19-401.2 . Section 16, Section 63A-19-402 is amended to read: 63A-19-402 . Personal data collection -- Privacy notice. (1) A governmental entity shall provide a personal data request privacy notice to an individual, or the legal guardian of an individual, from whom the governmental entity requests or collects personal data. (2) The personal data request notice described in Subsection (1) shall include: (a) the reasons the individual is asked to provide the personal data; (b) the intended purposes and uses of the personal data; (c) the consequences for refusing to provide the personal data; (d) the classes of persons and entities that: (i) share the personal data with the governmental entity; or (ii) receive the personal data from the governmental entity on a regular or contractual basis; and (e) the record series in which the personal data is or will be included, if applicable. (3) (2) If the personal data collected by a governmental entity: (a) would be classified as a public record under Section 63G-2-301 , the privacy notice shall be limited to a statement indicating that the individual's personal data may be available to the public as provided by Section 63G-2-201 ; and (b) would not be classified as a public record under Section 63G-2-301 , the privacy notice shall describe: (i) all intended purposes and uses of the personal data; (ii) the consequences for refusing to provide the personal data; (iii) the classes of persons and governmental entities: (A) with whom the governmental entity shares personal data; or (B) to whom the governmental entity sells personal data; and (iv) the record series in which the personal data is included. (3) The governmental entity shall provide the personal data request privacy notice by: (a) posting the personal data request privacy notice in a prominent place where the governmental entity collects the personal data; (b) including the personal data request privacy notice as part of any document or form used by the governmental entity to collect the personal data; or (c) conspicuously linking to or displaying a QR code linked to an electronic version of the personal data request notice as part of any document or form used by the governmental entity to collect the personal data including as part of any document or form used by the governmental entity to collect personal data, a conspicuous link or QR code that links to an electronic version of the privacy notice . (4) The personal data request privacy notice required by this section is in addition to, and does not supersede, any other notice requirement otherwise applicable to the governmental entity. (5) (a) Notwithstanding Subsections (1) through (4), a governmental entity may provide the privacy notice required under this section by posting the privacy notice on the governmental entity's government website, or on the public notice website if the governmental entity does not have a government website, when the privacy notice relates to processing activities that: (i) serve a public safety interest; and (ii) produce a public benefit that is greater than or equal to the potential impact on an individual's privacy interest that the privacy notice protects. (b) The processing activities related to public safety described in Subsection (5)(a) may include: (i) the provision of emergency services; (ii) law enforcement body or dash camera recordings; (iii) security camera monitoring; (iv) ambulance and emergency medical services; and (v) 911 emergency communications. (6) The governmental entity shall, upon request, provide the personal data request privacy notice to an individual, or the legal guardian of an individual, regarding personal data previously furnished by that individual. (6) (7) The governmental entity may only use personal data furnished by an individual for the purposes identified in the personal data request privacy notice provided to that individual. Section 17, Section 63A-19-402.5 is enacted to read: 63A-19-402.5 . Website privacy notice. (1) A governmental entity's government website shall include notice to a user of: (a) the identity of the governmental entity responsible for the government website; (b) how to contact the governmental entity that is responsible for the government website; (c) the method by which a user may: (i) seek access to the user's personal data or user data; (ii) request to correct or amend the user's personal data or user data; and (iii) file a complaint with the data privacy ombudsperson; and (d) how an at-risk employee may request that the at-risk employee's personal information be classified as a private record under Section 63G-2-302 . (2) In addition to the website privacy notice requirement described in Subsection (1)(a), a government website that collects user data shall include in the website privacy notice the following information: (a) any website tracking technology that is used to collect user data on the government website; (b) what user data is collected by the government website; (c) all intended purposes and uses of the user data; (d) the classes of persons and governmental entities: (i) with whom the governmental entity shares user data; or (ii) to whom the governmental entity sells user data; and (e) the record series in which the user data is included. (3) A notice described in Subsection (1) or (2) shall be provided by prominently posting on the homepage of the government website: (a) the notice; or (b) a link to a separate webpage containing the notice. (4) A governmental entity may not collect user data on a government website unless the governmental entity has complied with the requirements in this section. Section 18, Section 63A-19-405 is amended to read: 63A-19-405 . Data breach notification to the Cyber Center and the Office of the Attorney General. (1) (a) A governmental entity that identifies a data breach affecting 500 or more individuals shall notify the Cyber Center and the attorney general of the data breach. (b) In addition to the notification required by Subsection (1)(a), a governmental entity that identifies the unauthorized access, acquisition, disclosure, loss of access, or destruction of data that compromises the security, confidentiality, availability, or integrity of the computer systems used or information maintained by the governmental entity shall notify the Cyber Center. (2) The notification under Subsection (1) shall: (a) be made without unreasonable delay, but no later than five days from the discovery of the data breach; and (b) include the following information: (i) the date and time the data breach occurred; (ii) the date the data breach was discovered; (iii) a short description of the data breach that occurred; (iv) the means by which access was gained to the system, computer, or network; (v) the individual or entity person who perpetrated the data breach; (vi) steps the governmental entity is or has taken to mitigate the impact of the data breach; and (vii) any other details requested by the Cyber Center. (3) For a data breach under Subsection (1)(a), the governmental entity shall provide the following information to the Cyber Center and the attorney general in addition to the information required under Subsection (2)(b): (a) the total number of people individuals affected by the data breach, including the total number of Utah residents affected; and (b) the type of personal data involved in the data breach. (4) If the information required by Subsection (2)(b) Subsections (2)(b) and (3) is not available within five days of discovering the breach, the governmental entity shall provide as much of the information required under Subsection (2)(b) Subsections (2)(b) and (3) as is available and supplement the notification with additional information as soon as the information becomes available. (5) (a) A governmental entity that experiences a data breach affecting fewer than 500 individuals shall create an internal incident report containing the information in Subsection (2)(b) as soon as practicable and shall provide additional information as the information becomes available. (b) A governmental entity shall provide to the Cyber Center: (i) an internal incident report described in Subsection (5)(a) upon request of the Cyber Center; and (ii) an annual report logging all of the governmental entity's data breach incidents affecting fewer than 500 individuals. Section 19, Section 63A-19-406 is amended to read: 63A-19-406 . Data breach notice to individuals affected by data breach. (1) (a) A Except as provided in Subsection (1)(b), a governmental entity shall provide a data breach notice to an individual or legal guardian of an individual affected by the data breach: (a) (i) after determining the scope of the data breach; (b) (ii) after restoring the reasonable integrity of the affected system, if necessary; and (c) (iii) without unreasonable delay except as provided in Subsection (1)(b). (2). (b) A governmental entity is not required to provide a data breach notice to an affected individual as described in Subsection (1)(a) if the: (i) personal data involved in the data breach would be classified as a public record under Section 63G-2-301 ; and (ii) the governmental entity prominently posts notice of the data breach on the homepage of the governmental entity's government website. (2) A governmental entity shall delay providing notification under Subsection (1) at the request of a law enforcement agency that determines that notification may impede a criminal investigation, until such time as the law enforcement agency informs the governmental entity that notification will no longer impede the criminal investigation. (3) The data breach notice to an affected individual shall include: (a) a description of the data breach; (b) the individual's personal data that was accessed or may have been accessed; (c) steps the governmental entity is taking or has taken to mitigate the impact of the data breach; (d) recommendations to the individual on how to protect themselves from identity theft and other financial losses; and (e) any other language required by the Cyber Center. (4) Unless the governmental entity reasonably believes that providing notification would pose a threat to the safety of an individual, or unless an individual has designated to the governmental entity a preferred method of communication, a governmental entity shall provide notice by: (a) (i) email, if reasonably available and allowed by law; or (ii) mail; and (b) one of the following methods, if the individual's contact information is reasonably available and the method is allowed by law: (i) text message with a summary of the data breach notice and instructions for accessing the full notice; or (ii) telephone message with a summary of the data breach notice and instructions for accessing the full data breach notice. (5) A governmental entity shall also provide a data breach notice in a manner that is reasonably calculated to have the best chance of being received by the affected individual or the legal guardian of an individual, such as through a press release, posting on appropriate social media accounts, or publishing notice in a newspaper of general circulation when: (a) a data breach affects more than 500 individuals; and (b) a governmental entity is unable to obtain an individual's contact information to provide notice for any method listed in Subsection (4). Section 20, Section 63A-19-501 is amended to read: 63A-19-501 . Data privacy ombudsperson. (1) The governor shall appoint a data privacy ombudsperson with the advice of the governing board. (2) The ombudsperson shall: (a) be familiar with the provisions of: (i) this chapter; (ii) Chapter 12, Division of Archives and Records Service and Management of Government Records; and (iii) Title 63G, Chapter 2, Government Records Access and Management Act; and (b) serve as a resource for : (i) an individual who is making or responding to a complaint about a governmental entity's data privacy practice . ; and (ii) a governmental entity which is the subject of a data privacy complaint. (3) The ombudsperson may, upon request by a governmental entity or individual, mediate data privacy disputes between individuals and governmental entities. (4) After consultation with the chief privacy officer or the state privacy officer , the ombudsperson may raise issues and questions before the governing board regarding serious and repeated violations of data privacy from: (a) a specific governmental entity; or (b) widespread governmental entity data privacy practices. (5) When a data privacy complaint has been resolved, the ombudsperson shall post on the office's website a summary of the complaint and the resolution of the matter. Section 21, Section 63A-19-601 is amended to read: 63A-19-601 . Enforcement. (1) Upon instruction by the board, the state auditor shall: (a) investigate alleged violations of this chapter by a governmental entity; (b) provide notice to the relevant governmental entity of an alleged violation of this chapter; and (c) for a violation that the state auditor substantiates, provide an opportunity for the governmental entity to cure the violation within 30 days. (2) If a governmental entity fails to cure a violation as provided in Subsection (1)(c), the state auditor shall report the governmental entity's failure: (a) for a designated governmental entity that is not a state agency , to the attorney general for enforcement under Subsection (3); and (b) for a state agency, to the Legislative Management Committee. (3) After referral by the state auditor under Subsection (2)(a), the attorney general may file an action in district court to: (a) enjoin a designated governmental entity that is not a state agency from violating this chapter; or (b) require a designated governmental entity that is not a state agency to comply with this chapter. Section 22, Section 63A-19-602 is enacted to read: 63A-19-602 . Disciplinary action. A governmental entity may take disciplinary action, which may include suspension or discharge, against any employee of the governmental entity who intentionally violates any provision of this chapter. Section 23, Section 63G-2-103 is amended to read: 63G-2-103 . Definitions. As used in this chapter: (1) "Audit" means: (a) a systematic examination of financial, management, program, and related records for the purpose of determining the fair presentation of financial statements, adequacy of internal controls, or compliance with laws and regulations; or (b) a systematic examination of program procedures and operations for the purpose of determining their effectiveness, economy, efficiency, and compliance with statutes and regulations. (2) "Chief administrative officer" means the chief administrative officer of a governmental entity who is responsible to fulfill the duties described in Section 63A-12-103 . (2) (3) "Chronological logs" mean the regular and customary summary records of law enforcement agencies and other public safety agencies that show: (a) the time and general nature of police, fire, and paramedic calls made to the agency; and (b) any arrests or jail bookings made by the agency. (3) (4) "Classification," "classify," and their derivative forms mean determining whether a record series, record, or information within a record is public, private, controlled, protected, or exempt from disclosure under Subsection 63G-2-201 (3)(b). (4) (5) (a) "Computer program" means: (i) a series of instructions or statements that permit the functioning of a computer system in a manner designed to provide storage, retrieval, and manipulation of data from the computer system; and (ii) any associated documentation and source material that explain how to operate the computer program. (b) "Computer program" does not mean: (i) the original data, including numbers, text, voice, graphics, and images; (ii) analysis, compilation, and other manipulated forms of the original data produced by use of the program; or (iii) the mathematical or statistical formulas, excluding the underlying mathematical algorithms contained in the program, that would be used if the manipulated forms of the original data were to be produced manually. (5) (6) (a) "Contractor" means: (i) any person who contracts with a governmental entity to provide goods or services directly to a governmental entity; or (ii) any private, nonprofit organization that receives funds from a governmental entity. (b) "Contractor" does not mean a private provider. (6) (7) "Controlled record" means a record containing data on individuals that is controlled as provided by Section 63G-2-304 . (7) (8) "Designation," "designate," and their derivative forms mean indicating, based on a governmental entity's familiarity with a record series or based on a governmental entity's review of a reasonable sample of a record series, the primary classification that a majority of records in a record series would be given if classified and the classification that other records typically present in the record series would be given if classified. (8) (9) "Elected official" means each person elected to a state office, county office, municipal office, school board or school district office, special district office, or special service district office, but does not include judges. (9) (10) "Explosive" means a chemical compound, device, or mixture: (a) commonly used or intended for the purpose of producing an explosion; and (b) that contains oxidizing or combustive units or other ingredients in proportions, quantities, or packing so that: (i) an ignition by fire, friction, concussion, percussion, or detonator of any part of the compound or mixture may cause a sudden generation of highly heated gases; and (ii) the resultant gaseous pressures are capable of: (A) producing destructive effects on contiguous objects; or (B) causing death or serious bodily injury. (10) (11) "Government audit agency" means any governmental entity that conducts an audit. (11) (12) (a) "Governmental entity" means: (i) executive department agencies of the state, the offices of the governor, lieutenant governor, state auditor, attorney general, and state treasurer, the Board of Pardons and Parole, the Board of Examiners, the National Guard, the Career Service Review Office, the State Board of Education, the Utah Board of Higher Education, and the State Archives; (ii) the Office of the Legislative Auditor General, Office of the Legislative Fiscal Analyst, Office of Legislative Research and General Counsel, the Legislature, and legislative committees, except any political party, group, caucus, or rules or sifting committee of the Legislature; (iii) courts, the Judicial Council, the Administrative Office of the Courts, and similar administrative units in the judicial branch; (iv) any state-funded institution of higher education or public education; or (v) any political subdivision of the state, but, if a political subdivision has adopted an ordinance or a policy relating to information practices pursuant to Section 63G-2-701 , this chapter shall apply to the political subdivision to the extent specified in Section 63G-2-701 or as specified in any other section of this chapter that specifically refers to political subdivisions. (b) "Governmental entity" also means: (i) every office, agency, board, bureau, committee, department, advisory board, or commission of an entity listed in Subsection (11)(a) (12)(a) that is funded or established by the government to carry out the public's business; (ii) as defined in Section 11-13-103 , an interlocal entity or joint or cooperative undertaking, except for the Water District Water Development Council created pursuant to Section 11-13-228 ; (iii) as defined in Section 11-13a-102 , a governmental nonprofit corporation; (iv) an association as defined in Section 53G-7-1101 ; (v) the Utah Independent Redistricting Commission; and (vi) a law enforcement agency, as defined in Section 53-1-102 , that employs one or more law enforcement officers, as defined in Section 53-13-103 . (c) "Governmental entity" does not include the Utah Educational Savings Plan created in Section 53B-8a-103 . (12) (13) "Gross compensation" means every form of remuneration payable for a given period to an individual for services provided including salaries, commissions, vacation pay, severance pay, bonuses, and any board, rent, housing, lodging, payments in kind, and any similar benefit received from the individual's employer. (13) (14) "Individual" means a human being. (14) (15) (a) "Initial contact report" means an initial written or recorded report, however titled, prepared by peace officers engaged in public patrol or response duties describing official actions initially taken in response to either a public complaint about or the discovery of an apparent violation of law, which report may describe: (i) the date, time, location, and nature of the complaint, the incident, or offense; (ii) names of victims; (iii) the nature or general scope of the agency's initial actions taken in response to the incident; (iv) the general nature of any injuries or estimate of damages sustained in the incident; (v) the name, address, and other identifying information about any person arrested or charged in connection with the incident; or (vi) the identity of the public safety personnel, except undercover personnel, or prosecuting attorney involved in responding to the initial incident. (b) Initial contact reports do not include follow-up or investigative reports prepared after the initial contact report. However, if the information specified in Subsection (14)(a) (15)(a) appears in follow-up or investigative reports, it may only be treated confidentially if it is private, controlled, protected, or exempt from disclosure under Subsection 63G-2-201 (3)(b). (c) Initial contact reports do not include accident reports, as that term is described in Title 41, Chapter 6a, Part 4, Accident Responsibilities. (15) (16) "Legislative body" means the Legislature. (16) (17) "Notice of compliance" means a statement confirming that a governmental entity has complied with an order of the State Records Committee. (17) (18) "Person" means: (a) an individual; (b) a nonprofit or profit corporation; (c) a partnership; (d) a sole proprietorship; (e) other type of business organization; or (f) any combination acting in concert with one another. (18) "Personal identifying information" means the same as that term is defined in Section 63A-12-100.5 . (19) "Privacy annotation" means the same as that term is defined in Section 63A-12-100.5 . (20) (19) "Private provider" means any person who contracts with a governmental entity to provide services directly to the public. (21) (20) "Private record" means a record containing data on individuals that is private as provided by Section 63G-2-302 . (22) (21) "Protected record" means a record that is classified protected as provided by Section 63G-2-305 . (23) (22) "Public record" means a record that is not private, controlled, or protected and that is not exempt from disclosure as provided in Subsection 63G-2-201 (3)(b). (24) (23) "Reasonable search" means a search that is: (a) reasonable in scope and intensity; and (b) not unreasonably burdensome for the government entity. (25) (24) (a) "Record" means a book, letter, document, paper, map, plan, photograph, film, card, tape, recording, electronic data, or other documentary material regardless of physical form or characteristics: (i) that is prepared, owned, received, or retained by a governmental entity or political subdivision; and (ii) where all of the information in the original is reproducible by photocopy or other mechanical or electronic means. (b) "Record" does not include: (i) a personal note or personal communication prepared or received by an employee or officer of a governmental entity: (A) in a capacity other than the employee's or officer's governmental capacity; or (B) that is unrelated to the conduct of the public's business; (ii) a temporary draft or similar material prepared for the originator's personal use or prepared by the originator for the personal use of an individual for whom the originator is working; (iii) material that is legally owned by an individual in the individual's private capacity; (iv) material to which access is limited by the laws of copyright or patent unless the copyright or patent is owned by a governmental entity or political subdivision; (v) proprietary software; (vi) junk mail or a commercial publication received by a governmental entity or an official or employee of a governmental entity; (vii) a book that is cataloged, indexed, or inventoried and contained in the collections of a library open to the public; (viii) material that is cataloged, indexed, or inventoried and contained in the collections of a library open to the public, regardless of physical form or characteristics of the material; (ix) a daily calendar ; (x) a note prepared by the originator for the originator's own use or for the sole use of an individual for whom the originator is working; (xi) a computer program that is developed or purchased by or for any governmental entity for its own use; (xii) a note or internal memorandum prepared as part of the deliberative process by: (A) a member of the judiciary; (B) an administrative law judge; (C) a member of the Board of Pardons and Parole; or (D) a member of any other body, other than an association or appeals panel as defined in Section 53G-7-1101 , charged by law with performing a quasi-judicial function; (xiii) a telephone number or similar code used to access a mobile communication device that is used by an employee or officer of a governmental entity, provided that the employee or officer of the governmental entity has designated at least one business telephone number that is a public record as provided in Section 63G-2-301 ; (xiv) information provided by the Public Employees' Benefit and Insurance Program, created in Section 49-20-103 , to a county to enable the county to calculate the amount to be paid to a health care provider under Subsection 17-50-319 (2)(e)(ii); (xv) information that an owner of unimproved property provides to a local entity as provided in Section 11-42-205 ; (xvi) a video or audio recording of an interview, or a transcript of the video or audio recording, that is conducted at a Children's Justice Center established under Section 67-5b-102 ; (xvii) child sexual abuse material, as defined by Section 76-5b-103 ; (xviii) before final disposition of an ethics complaint occurs, a video or audio recording of the closed portion of a meeting or hearing of: (A) a Senate or House Ethics Committee; (B) the Independent Legislative Ethics Commission; (C) the Independent Executive Branch Ethics Commission, created in Section 63A-14-202 ; or (D) the Political Subdivisions Ethics Review Commission established in Section 63A-15-201 ; (xix) confidential communication described in Section 58-60-102 , 58-61-102 , or 58-61-702 ; (xx) any item described in Subsection (25)(a) (24)(a) that is: (A) described in Subsection 63G-2-305 (17), (18), or (23)(b); and (B) shared between any of the following entities: (I) the Division of Risk Management; (II) the Office of the Attorney General; (III) the governor's office; or (IV) the Legislature; or (xxi) the email address that a candidate for elective office provides to a filing officer under Subsection 20A-9-201 (5)(c)(ii) or 20A-9-203 (4)(c)(iv). (26) (25) "Record series" means a group of records that may be treated as a unit for purposes of designation, description, management, or disposition. (27) (26) "Records officer" means the individual appointed by the chief administrative officer of each governmental entity, or the political subdivision to work with state archives in the care, maintenance, scheduling, designation, classification, disposal, and preservation of records. (28) (27) "Schedule," "scheduling," and their derivative forms mean the process of specifying the length of time each record series should be retained by a governmental entity for administrative, legal, fiscal, or historical purposes and when each record series should be transferred to the state archives or destroyed. (29) (28) "Sponsored research" means research, training, and other sponsored activities as defined by the federal Executive Office of the President, Office of Management and Budget: (a) conducted: (i) by an institution within the state system of higher education defined in Section 53B-1-102 ; and (ii) through an office responsible for sponsored projects or programs; and (b) funded or otherwise supported by an external: (i) person that is not created or controlled by the institution within the state system of higher education; or (ii) federal, state, or local governmental entity. (30) (29) "State archives" means the Division of Archives and Records Service created in Section 63A-12-101 . (31) (30) "State archivist" means the director of the state archives. (32) (31) "State Records Committee" means the State Records Committee created in Section 63G-2-501 . (33) (32) "Summary data" means statistical records and compilations that contain data derived from private, controlled, or protected information but that do not disclose private, controlled, or protected information. Section 24, Section 63G-2-307 is amended to read: 63G-2-307 . Duty to evaluate records and make designations, classifications, and annotations. (1) A governmental entity shall, for each record series that the governmental entity keeps, uses, or creates: (a) evaluate all record series; (b) designate each record series as provided by this chapter and Title 63A, Chapter 12, Division of Archives and Records Service and Management of Government Records ; and (c) report to the state archives : the designation described in Subsection (1)(b). (i) the designation described in Subsection (1)(b) ; and (ii) if the governmental entity is an executive branch agency, as defined in Section 63A-12-100.5 , the privacy annotation. (2) A governmental entity may classify a particular record, record series, or information within a record at any time, but is not required to classify a particular record, record series, or information until access to the record is requested. (3) A governmental entity may redesignate a record series or reclassify a record or record series, or information within a record at any time. Section 25, Section 63G-2-601 is amended to read: 63G-2-601 . Rights of individuals on whom data is maintained -- Classification statement filed with state archivist -- Notice to provider of information. (1) (a) Each governmental entity shall file with the state archivist a statement explaining, for each record series collected, maintained, or used by the governmental entity, the purposes for which each private or controlled record in the record series is collected, maintained, or used by that governmental entity. (b) Each executive branch agency, as defined in Section 63A-12-100.5 , shall file with the state archivist a statement explaining, for each record series collected, maintained, or used by the executive branch agency, the purposes for which the personal identifying information in the record series is collected, maintained, or used by the executive branch agency. (c) (b) The statement filed under Subsection (1)(a) or (b) : (i) shall , for each purpose described in Subsection (1)(a) or (b) , identify the authority under which the governmental entity or executive branch agency collects the records or information included in the statement described in Subsection (1)(a) or (b) ; and (ii) is a public record. (2) (a) A governmental entity shall provide the notice described in this Subsection (2) to a person that is asked to furnish information that could be classified as a private or controlled record. (b) An executive branch agency, as defined in Section 63A-12-100.5 , shall provide the notice described in this Subsection (2) to a person that is asked to furnish personal identifying information. (c) (b) The notice required under Subsection (2)(a) or (b) shall: (i) identify the record series that includes the information described in Subsection (2)(a) or (b) ; (ii) state the reasons the person is asked to furnish the information; (iii) state the intended uses of the information; (iv) state the consequences for refusing to provide the information; and (v) disclose the classes of persons and the governmental entities that currently: (A) share the information with the governmental entity; or (B) receive the information from the governmental entity on a regular or contractual basis. (d) (c) The governmental entity shall: (i) post the notice required under this Subsection (2) in a prominent place at all locations where the governmental entity collects the information; or (ii) include the notice required under this Subsection (2) as part of the documents or forms that are used by the governmental entity to collect the information. (3) Upon request, each governmental entity shall, in relation to the information described in Subsection (2)(a) or (b) , as applicable, explain to a person: (a) the reasons the person is asked to furnish information; (b) the intended uses of the information; (c) the consequences for refusing to provide the information; and (d) the reasons and circumstances under which the information may be shared with, or provided to, other persons or governmental entities. (4) A governmental entity may use the information that the governmental entity is required to disclose under Subsection (2)(a) or (b) only for those purposes: (a) given in the statement filed with the state archivist under Subsection (1) ; or (b) for which another governmental entity may use the record under Section 63G-2-206 . Section 26, Section 67-3-1 is amended to read: 67-3-1 . Functions and duties. (1) (a) The state auditor is the auditor of public accounts and is independent of any executive or administrative officers of the state. (b) The state auditor is not limited in the selection of personnel or in the determination of the reasonable and necessary expenses of the state auditor's office. (2) The state auditor shall examine and certify annually in respect to each fiscal year, financial statements showing: (a) the condition of the state's finances; (b) the revenues received or accrued; (c) expenditures paid or accrued; (d) the amount of unexpended or unencumbered balances of the appropriations to the agencies, departments, divisions, commissions, and institutions; and (e) the cash balances of the funds in the custody of the state treasurer. (3) (a) The state auditor shall: (i) audit each permanent fund, each special fund, the General Fund, and the accounts of any department of state government or any independent agency or public corporation as the law requires, as the auditor determines is necessary, or upon request of the governor or the Legislature; (ii) perform the audits in accordance with generally accepted auditing standards and other auditing procedures as promulgated by recognized authoritative bodies; and (iii) as the auditor determines is necessary, conduct the audits to determine: (A) honesty and integrity in fiscal affairs; (B) accuracy and reliability of financial statements; (C) effectiveness and adequacy of financial controls; and (D) compliance with the law. (b) If any state entity receives federal funding, the state auditor shall ensure that the audit is performed in accordance with federal audit requirements. (c) (i) The costs of the federal compliance portion of the audit may be paid from an appropriation to the state auditor from the General Fund. (ii) If an appropriation is not provided, or if the federal government does not specifically provide for payment of audit costs, the costs of the federal compliance portions of the audit shall be allocated on the basis of the percentage that each state entity's federal funding bears to the total federal funds received by the state. (iii) The allocation shall be adjusted to reflect any reduced audit time required to audit funds passed through the state to local governments and to reflect any reduction in audit time obtained through the use of internal auditors working under the direction of the state auditor. (4) (a) Except as provided in Subsection (4)(b), the state auditor shall, in addition to financial audits, and as the auditor determines is necessary, conduct performance and special purpose audits, examinations, and reviews of any entity that receives public funds, including a determination of any or all of the following: (i) the honesty and integrity of all the entity's fiscal affairs; (ii) whether the entity's administrators have faithfully complied with legislative intent; (iii) whether the entity's operations have been conducted in an efficient, effective, and cost-efficient manner; (iv) whether the entity's programs have been effective in accomplishing the intended objectives; and (v) whether the entity's management, control, and information systems are adequate, effective, and secure. (b) The auditor may not conduct performance and special purpose audits, examinations, and reviews of any entity that receives public funds if the entity: (i) has an elected auditor; and (ii) has, within the entity's last budget year, had the entity's financial statements or performance formally reviewed by another outside auditor. (5) The state auditor: (a) shall administer any oath or affirmation necessary to the performance of the duties of the auditor's office; and (b) may: (i) subpoena witnesses and documents, whether electronic or otherwise; and (ii) examine into any matter that the auditor considers necessary. (6) The state auditor may require all persons who have had the disposition or management of any property of this state or its political subdivisions to submit statements regarding the property at the time and in the form that the auditor requires. (7) The state auditor shall: (a) except where otherwise provided by law, institute suits in Salt Lake County in relation to the assessment, collection, and payment of revenues against: (i) persons who by any means have become entrusted with public money or property and have failed to pay over or deliver the money or property; and (ii) all debtors of the state; (b) collect and pay into the state treasury all fees received by the state auditor; (c) perform the duties of a member of all boards of which the state auditor is a member by the constitution or laws of the state, and any other duties that are prescribed by the constitution and by law; (d) stop the payment of the salary of any state official or state employee who: (i) refuses to settle accounts or provide required statements about the custody and disposition of public funds or other state property; (ii) refuses, neglects, or ignores the instruction of the state auditor or any controlling board or department head with respect to the manner of keeping prescribed accounts or funds; or (iii) fails to correct any delinquencies, improper procedures, and errors brought to the official's or employee's attention; (e) establish accounting systems, methods, and forms for public accounts in all taxing or fee-assessing units of the state in the interest of uniformity, efficiency, and economy; (f) superintend the contractual auditing of all state accounts; (g) subject to Subsection (8)(a), withhold state allocated funds or the disbursement of property taxes from a state or local taxing or fee-assessing unit, if necessary, to ensure that officials and employees in those taxing units comply with state laws and procedures in the budgeting, expenditures, and financial reporting of public funds; (h) subject to Subsection (9), withhold the disbursement of tax money from any county, if necessary, to ensure that officials and employees in the county comply with Section 59-2-303.1 ; and (i) withhold state allocated funds or the disbursement of property taxes from a local government entity or a limited purpose entity, as those terms are defined in Section 67-1a-15 if the state auditor finds the withholding necessary to ensure that the entity registers and maintains the entity's registration with the lieutenant governor, in accordance with Section 67-1a-15 . (8) (a) Except as otherwise provided by law, the state auditor may not withhold funds under Subsection (7)(g) until a state or local taxing or fee-assessing unit has received formal written notice of noncompliance from the auditor and has been given 60 days to make the specified corrections. (b) If, after receiving notice under Subsection (8)(a), a state or independent local fee-assessing unit that exclusively assesses fees has not made corrections to comply with state laws and procedures in the budgeting, expenditures, and financial reporting of public funds, the state auditor: (i) shall provide a recommended timeline for corrective actions; (ii) may prohibit the state or local fee-assessing unit from accessing money held by the state; and (iii) may prohibit a state or local fee-assessing unit from accessing money held in an account of a financial institution by filing an action in a court with jurisdiction under Title 78A, Judiciary and Judicial Administration, requesting an order of the court to prohibit a financial institution from providing the fee-assessing unit access to an account. (c) The state auditor shall remove a limitation on accessing funds under Subsection (8)(b) upon compliance with state laws and procedures in the budgeting, expenditures, and financial reporting of public funds. (d) If a local taxing or fee-assessing unit has not adopted a budget in compliance with state law, the state auditor: (i) shall provide notice to the taxing or fee-assessing unit of the unit's failure to comply; (ii) may prohibit the taxing or fee-assessing unit from accessing money held by the state; and (iii) may prohibit a taxing or fee-assessing unit from accessing money held in an account of a financial institution by: (A) contacting the taxing or fee-assessing unit's financial institution and requesting that the institution prohibit access to the account; or (B) filing an action in a court with jurisdiction under Title 78A, Judiciary and Judicial Administration, requesting an order of the court to prohibit a financial institution from providing the taxing or fee-assessing unit access to an account. (e) If the local taxing or fee-assessing unit adopts a budget in compliance with state law, the state auditor shall eliminate a limitation on accessing funds described in Subsection (8)(d). (9) The state auditor may not withhold funds under Subsection (7)(h) until a county has received formal written notice of noncompliance from the auditor and has been given 60 days to make the specified corrections. (10) (a) The state auditor may not withhold funds under Subsection (7)(i) until the state auditor receives a notice of non-registration, as that term is defined in Section 67-1a-15 . (b) If the state auditor receives a notice of non-registration, the state auditor may prohibit the local government entity or limited purpose entity, as those terms are defined in Section 67-1a-15 , from accessing: (i) money held by the state; and (ii) money held in an account of a financial institution by: (A) contacting the entity's financial institution and requesting that the institution prohibit access to the account; or (B) filing an action in a court with jurisdiction under Title 78A, Judiciary and Judicial Administration, requesting an order of the court to prohibit a financial institution from providing the entity access to an account. (c) The state auditor shall remove the prohibition on accessing funds described in Subsection (10)(b) if the state auditor received a notice of registration, as that term is defined in Section 67-1a-15 , from the lieutenant governor. (11) Notwithstanding Subsection (7)(g), (7)(h), (7)(i), (8)(b), (8)(d), or (10)(b), the state auditor: (a) shall authorize a disbursement by a local government entity or limited purpose entity, as those terms are defined in Section 67-1a-15 , or a state or local taxing or fee-assessing unit if the disbursement is necessary to: (i) avoid a major disruption in the operations of the local government entity, limited purpose entity, or state or local taxing or fee-assessing unit; or (ii) meet debt service obligations; and (b) may authorize a disbursement by a local government entity, limited purpose entity, or state or local taxing or fee-assessing unit as the state auditor determines is appropriate. (12) (a) The state auditor may seek relief under the Utah Rules of Civil Procedure to take temporary custody of public funds if an action is necessary to protect public funds from being improperly diverted from their intended public purpose. (b) If the state auditor seeks relief under Subsection (12)(a): (i) the state auditor is not required to exhaust the procedures in Subsection (7) or (8); and (ii) the state treasurer may hold the public funds in accordance with Section 67-4-1 if a court orders the public funds to be protected from improper diversion from their public purpose. (13) The state auditor shall: (a) establish audit guidelines and procedures for audits of local mental health and substance abuse authorities and their contract providers, conducted pursuant to Title 17, Chapter 43, Part 2, Local Substance Abuse Authorities, Title 17, Chapter 43, Part 3, Local Mental Health Authorities, Title 26B, Chapter 5, Health Care - Substance Use and Mental Health, and Title 51, Chapter 2a, Accounting Reports from Political Subdivisions, Interlocal Organizations, and Other Local Entities Act; and (b) ensure that those guidelines and procedures provide assurances to the state that: (i) state and federal funds appropriated to local mental health authorities are used for mental health purposes; (ii) a private provider under an annual or otherwise ongoing contract to provide comprehensive mental health programs or services for a local mental health authority is in compliance with state and local contract requirements and state and federal law; (iii) state and federal funds appropriated to local substance abuse authorities are used for substance abuse programs and services; and (iv) a private provider under an annual or otherwise ongoing contract to provide comprehensive substance abuse programs or services for a local substance abuse authority is in compliance with state and local contract requirements, and state and federal law. (14) (a) The state auditor may, in accordance with the auditor's responsibilities for political subdivisions of the state as provided in Title 51, Chapter 2a, Accounting Reports from Political Subdivisions, Interlocal Organizations, and Other Local Entities Act, initiate audits or investigations of any political subdivision that are necessary to determine honesty and integrity in fiscal affairs, accuracy and reliability of financial statements, effectiveness, and adequacy of financial controls and compliance with the law. (b) If the state auditor receives notice under Subsection 11-41-104 (7) from the Governor's Office of Economic Opportunity on or after July 1, 2024, the state auditor may initiate an audit or investigation of the public entity subject to the notice to determine compliance with Section 11-41-103 . (15) (a) The state auditor may not audit work that the state auditor performed before becoming state auditor. (b) If the state auditor has previously been a responsible official in state government whose work has not yet been audited, the Legislature shall: (i) designate how that work shall be audited; and (ii) provide additional funding for those audits, if necessary. (16) The state auditor shall: (a) with the assistance, advice, and recommendations of an advisory committee appointed by the state auditor from among special district boards of trustees, officers, and employees and special service district boards, officers, and employees: (i) prepare a Uniform Accounting Manual for Special Districts that: (A) prescribes a uniform system of accounting and uniform budgeting and reporting procedures for special districts under Title 17B, Limited Purpose Local Government Entities - Special Districts, and special service districts under Title 17D, Chapter 1, Special Service District Act; (B) conforms with generally accepted accounting principles; and (C) prescribes reasonable exceptions and modifications for smaller districts to the uniform system of accounting, budgeting, and reporting; (ii) maintain the manual under this Subsection (16)(a) so that the manual continues to reflect generally accepted accounting principles; (iii) conduct a continuing review and modification of procedures in order to improve them; (iv) prepare and supply each district with suitable budget and reporting forms; and (v) (A) prepare instructional materials, conduct training programs, and render other services considered necessary to assist special districts and special service districts in implementing the uniform accounting, budgeting, and reporting procedures; and (B) ensure that any training described in Subsection (16)(a)(v)(A) complies with Title 63G, Chapter 22, State Training and Certification Requirements; and (b) continually analyze and evaluate the accounting, budgeting, and reporting practices and experiences of specific special districts and special service districts selected by the state auditor and make the information available to all districts. (17) (a) The following records in the custody or control of the state auditor are protected records under Title 63G, Chapter 2, Government Records Access and Management Act: (i) records that would disclose information relating to allegations of personal misconduct, gross mismanagement, or illegal activity of a past or present governmental employee if the information or allegation cannot be corroborated by the state auditor through other documents or evidence, and the records relating to the allegation are not relied upon by the state auditor in preparing a final audit report; (ii) records and audit workpapers to the extent the workpapers would disclose the identity of an individual who during the course of an audit, communicated the existence of any waste of public funds, property, or manpower, or a violation or suspected violation of a law, rule, or regulation adopted under the laws of this state, a political subdivision of the state, or any recognized entity of the United States, if the information was disclosed on the condition that the identity of the individual be protected; (iii) before an audit is completed and the final audit report is released, records or drafts circulated to an individual who is not an employee or head of a governmental entity for the individual's response or information; (iv) records that would disclose an outline or part of any audit survey plans or audit program; and (v) requests for audits, if disclosure would risk circumvention of an audit. (b) The provisions of Subsections (17)(a)(i), (ii), and (iii) do not prohibit the disclosure of records or information that relate to a violation of the law by a governmental entity or employee to a government prosecutor or peace officer. (c) The provisions of this Subsection (17) do not limit the authority otherwise given to the state auditor to classify a document as public, private, controlled, or protected under Title 63G, Chapter 2, Government Records Access and Management Act. (d) (i) As used in this Subsection (17)(d), "record dispute" means a dispute between the state auditor and the subject of an audit performed by the state auditor as to whether the state auditor may release a record, as defined in Section 63G-2-103 , to the public that the state auditor gained access to in the course of the state auditor's audit but which the subject of the audit claims is not subject to disclosure under Title 63G, Chapter 2, Government Records Access and Management Act. (ii) The state auditor may submit a record dispute to the State Records Committee, created in Section 63G-2-501 , for a determination of whether the state auditor may, in conjunction with the state auditor's release of an audit report, release to the public the record that is the subject of the record dispute. (iii) The state auditor or the subject of the audit may seek judicial review of a State Records Committee determination under Subsection (17)(d)(ii), as provided in Section 63G-2-404 . (18) If the state auditor conducts an audit of an entity that the state auditor has previously audited and finds that the entity has not implemented a recommendation made by the state auditor in a previous audit, the state auditor shall notify the Legislative Management Committee through the Legislative Management Committee's audit subcommittee that the entity has not implemented that recommendation. (19) The state auditor shall, with the advice and consent of the Senate, appoint the state privacy officer state privacy auditor described in Section 67-3-13 . (20) Except as provided in Subsection (21), the state auditor shall report, or ensure that another government entity reports, on the financial, operational, and performance metrics for the state system of higher education and the state system of public education, including metrics in relation to students, programs, and schools within those systems. (21) (a) Notwithstanding Subsection (20), the state auditor shall conduct regular audits of: (i) the scholarship granting organization for the Carson Smith Opportunity Scholarship Program, created in Section 53E-7-402 ; (ii) the State Board of Education for the Carson Smith Scholarship Program, created in Section 53F-4-302 ; and (iii) the scholarship program manager for the Utah Fits All Scholarship Program, created in Section 53F-6-402 , including an analysis of the cost effectiveness of the program, taking into consideration the amount of the scholarship and the amount of state and local funds dedicated on a per-student basis within the traditional public education system. (b) Nothing in this subsection limits or impairs the authority of the State Board of Education to administer the programs described in Subsection (21)(a). (22) The state auditor shall, based on the information posted by the Office of Legislative Research and General Counsel under Subsection 36-12-12.1 (2), for each policy, track and post the following information on the state auditor's website: (a) the information posted under Subsections 36-12-12.1 (2)(a) through (e); (b) an indication regarding whether the policy is timely adopted, adopted late, or not adopted; (c) an indication regarding whether the policy complies with the requirements established by law for the policy; and (d) a link to the policy. (23) (a) A legislator may request that the state auditor conduct an inquiry to determine whether a government entity, government official, or government employee has complied with a legal obligation directly imposed, by statute, on the government entity, government official, or government employee. (b) The state auditor may, upon receiving a request under Subsection (23)(a), conduct the inquiry requested. (c) If the state auditor conducts the inquiry described in Subsection (23)(b), the state auditor shall post the results of the inquiry on the state auditor's website. (d) The state auditor may limit the inquiry described in this Subsection (23) to a simple determination, without conducting an audit, regarding whether the obligation was fulfilled. (24) The state auditor shall: (a) ensure compliance with Title 63G, Chapter 31, Distinctions on the Basis of Sex, in accordance with Section 63G-31-401 ; and (b) report to the Legislative Management Committee, upon request, regarding the state auditor's actions under this Subsection (24). (25) The state auditor shall report compliance with Sections 67-27-107 , 67-27-108 , and 67-27-109 by: (a) establishing a process to receive and audit each alleged violation; and (b) reporting to the Legislative Management Committee, upon request, regarding the state auditor's findings and recommendations under this Subsection (25). Section 27, Section 67-3-13 is amended to read: 67-3-13 . State privacy auditor. (1) As used in this section: (a) "Designated governmental entity" means a governmental entity that is not a state agency. (b) "Independent entity" means the same as that term is defined in Section 63E-1-102 . (c) (a) "Governmental entity" means the same as that term is defined in Section 63G-2-103 . (d) (b) "Personal data" means the same as that term is defined in Section 63A-19-101 . (c) "Privacy practice" means the same as that term is defined in Section 63A-19-101 . (d) "State agency" means the same as that term is defined in Section 63A-19-101 . (e) "State privacy auditor" means the individual appointed as state privacy auditor by the state auditor under Section 67-3-1 . (e) (i) "Privacy practice" means the acquisition, use, storage, or disposal of personal data. (ii) "Privacy practice" includes: (A) a technology use related to personal data; and (B) policies related to the protection, storage, sharing, and retention of personal data. (f) (i) "State agency" means the following entities that are under the direct supervision and control of the governor or the lieutenant governor: (A) a department; (B) a commission; (C) a board; (D) a council; (E) an institution; (F) an officer; (G) a corporation; (H) a fund; (I) a division; (J) an office; (K) a committee; (L) an authority; (M) a laboratory; (N) a library; (O) a bureau; (P) a panel; (Q) another administrative unit of the state; or (R) an agent of an entity described in Subsections (A) through (Q). (ii) "State agency" does not include: (A) the legislative branch; (B) the judicial branch; (C) an executive branch agency within the Office of the Attorney General, the state auditor, the state treasurer, or the State Board of Education; or (D) an independent entity. (2) The state privacy officer state privacy auditor shall: (a) when completing the duties of this Subsection (2), focus on the privacy practices of designated governmental entities; (b) (a) compile information about government the privacy practices of designated governmental entities; (c) (b) make public and maintain information about government the privacy practices of governmental entities on the state auditor's website; (d) (c) provide designated governmental entities with educational and training materials developed by the Utah Privacy Commission established in Section 63C-24-201 that include the information described in Subsection 63C-24-202 (1)(b) guidance and training regarding the data privacy auditing standards developed by the state privacy auditor ; (e) (d) implement a process to analyze and respond to requests from individuals for the state privacy officer to review a designated state privacy auditor to audit a governmental entity's privacy practice; (f) (e) identify annually which designated governmental entities' privacy practices pose the greatest risk to individual privacy and prioritize those privacy practices for review to be audited ; (g) (f) review audit each year, in as timely a manner as possible, the privacy practices that the state privacy officer auditor identifies under Subsection (2)(e) or (2)(f) (2)(d) or (2)(e) as posing the greatest risk to individuals' privacy; (h) (g) when reviewing a designated auditing a governmental entity's privacy practice under Subsection (2)(g), (2)(f), analyze: (i) details about the technology or the policy and the technology's or the policy's application; (ii) information about the type of personal data being used; (iii) information about how the personal data is obtained, stored, shared, secured, and disposed; (iv) information about with which persons the designated the governmental entity shares the information entity's sharing or selling of personal data ; (v) information about whether an individual can or should be able to opt out of the retention , selling, and sharing of the individual's personal data; (vi) information about how the designated governmental entity de-identifies or anonymizes personal data; (vii) a determination about the existence of alternative technology or improved practices to protect privacy; and (viii) a finding of whether the designated governmental entity's current privacy practice practices adequately protects protect individual privacy; and (i) (h) after completing a review an audit described in Subsections (2)(g) (2)(f) and (h) (g) , determine: (i) each designated governmental entity's use of personal data, including the designated governmental entity's privacy practices regarding personal data: (A) acquisition; (B) storage; (C) disposal; (D) protection; and (E) sharing; (ii) the adequacy of the designated governmental entity's practices in each of the areas described in Subsection (2)(i)(i); (2)(h)(i); and (iii) for each of the areas described in Subsection (2)(i)(i) (2)(h)(i) that the state privacy officer state privacy auditor determines to require reform, provide recommendations for reform to the designated governmental entity and the legislative body charged with regulating the designated governmental entity. (3) (a) The legislative body charged with regulating a designated governmental entity that receives a recommendation described in Subsection (2)(i)(iii) (2)(h)(iii) shall hold a public hearing on the proposed reforms: (i) with a quorum of the legislative body present; and (ii) within 90 days after the day on which the legislative body receives the recommendation. (b) (i) The legislative body shall provide notice of the hearing described in Subsection (3)(a). (ii) Notice of the public hearing and the recommendations to be discussed shall be posted for the jurisdiction of the designated governmental entity, as a class A notice under Section 63G-30-102 , for at least 30 days before the day on which the legislative body will hold the public hearing. (iii) Each notice required under Subsection (3)(b)(i) shall: (A) identify the recommendations to be discussed; and (B) state the date, time, and location of the public hearing. (c) During the hearing described in Subsection (3)(a), the legislative body shall: (i) provide the public the opportunity to ask questions and obtain further information about the recommendations; and (ii) provide any interested person an opportunity to address the legislative body with concerns about the recommendations. (d) At the conclusion of the hearing, the legislative body shall determine whether the legislative body shall adopt reforms to address the recommendations and any concerns raised during the public hearing. (4) (a) Except as provided in Subsection (4)(b), if the chief privacy officer described in Section 63A-19-302 is not conducting reviews of the privacy practices of state agencies, the state privacy officer may review the privacy practices of a state agency in accordance with the processes described in this section. (b) (4) Subsection (3) does not apply to : (a) a state agency . ; (b) the legislative branch; (c) the judicial branch; (d) an executive branch agency within the Office of the Attorney General, the state auditor, the state treasurer, or the State Board of Education; or (e) an independent entity. (5) The state privacy officer state privacy auditor shall: (a) quarterly report, to the Utah Privacy Commission: (i) recommendations for privacy practices for the commission to review; and (ii) the information provided in Subsection (2)(i) (2)(h) ; and (b) annually, on or before October 1, report to the Judiciary Interim Committee: (i) the results of any reviews audits described in Subsection (2)(g), (2)(f), if any reviews audits have been completed; (ii) reforms, to the extent that the state privacy officer state privacy auditor is aware of any reforms, that the designated governmental entity made in response to any reviews audits described in Subsection (2)(g); (2)(f); (iii) the information described in Subsection (2)(i) (2)(h) ; and (iv) reports received from designated governmental entities regarding the sale or sharing of personal data provided under Subsection 63A-19-401 (2)(f)(i); and (v) (iv) recommendations for legislation based on any results of a review an audit described in Subsection (2)(g) (2)(f) . Section 28, Section 78A-2-233 , which is renumbered from Section 63D-2-104 is renumbered and amended to read: 63D-2-104 78A-2-233 . Posting certain information on a court website. (1) As used in this section: (a) "Court website" means a government website operated by or on behalf of any court created in Title 78A, Chapter 1, Judiciary. (b) "Government website" means the same as that term is defined in Section 63A-19-101 . (c) "Personal data" means the same as that term is defined in Section 63A-19-101 . (2) Except as provided in Subsections (2) (3) and (3) (4) , a court website: (a) may not display personally identifiable information personal data ; and (b) shall contain a conspicuous notice that includes a list of documents routinely posted on the court website. (2) (3) This section does not prohibit access to any original document as provided by law. (3) (4) This section does not apply to: (a) the Registry of Judgments created in Section 78B-5-201 , if the Registry of Judgments complies with Subsection (3)(b) (4)(b) ; (b) remote access to a document through a network or system that: (i) is secure; and (ii) provides restricted access through security standards developed by the court, including a registration requirement under which a prospective user must provide the prospective user's: (A) identity; (B) business or residence address; and (C) citizenship status; (c) postings related to legitimate law enforcement purposes; (d) postings of documents filed or recorded more than 100 years prior to the posting; (e) postings of: (i) historical information; (ii) genealogical information; (iii) interpretive information about historic persons and events; or (iv) educational information about historic persons and events; or (f) postings of information instructing a user how to contact a website operator, employee, or other representative of the court. Section 29, Repealer. Privacy annotation for records series -- Requirements -- Content. Title. Definitions. Title. Definitions. Collection of personally identifiable information. Section 30. Effective Date. This bill takes effect: (1) except as provided in Subsection (2), May 7, 2025 ; or (2) if approved by two-thirds of all members elected to each house: (a) upon approval by the governor; (b) without the governor's signature, the day following the constitutional time limit of Utah Constitution, Article VII, Section 8; or (c) in the case of a veto, the date of veto override. 3-11-25 3:16 PM