Privacy program report.

Utah Code § 63A-19-401.3, under Part 63A-19-4: Duties of Governmental Entities.

Utah Code § 63A-19-401.3

63A-19-401.3. Privacy program report.

(1) On or before December 31 of each year, the chief administrative officer of each governmental entity shall prepare a report that includes: how the governmental entity has initiated the governmental entity's privacy program; a description of: the governmental entity's privacy program including privacy practices; strategies for improving and maturing the governmental entity's privacy program and practices; and the governmental entity's high-risk processing activities; a list of the types of personal data the governmental entity currently shares, sells, or purchases; the legal basis for sharing, selling, or purchasing personal data; the category of individuals or entities: with whom the governmental entity shares personal data; to whom the governmental entity sells personal data; or from whom the governmental entity purchases personal data; the percentage of the governmental entity's employees required to complete the data privacy training under Sectionthat have completed the training; and 63A-19-401.2 a description of any non-compliant processing activities identified under Subsectionand the governmental entity's strategy for bringing those activities into compliance with this part. 63A-19-401(2)(a)(iv)

(2) The report described in Subsectionshall be: (1) considered a protected record under Section; 63G-2-305 shared with the office, in accordance with Section, on or before December 31 each year; and 63G-2-206 retained by the governmental entity for no less than five years.