Statewide Privacy Training
Practice Gov-4

Summary
Privacy awareness training educates employees about privacy laws, regulations, best practices, internal policies, and employee responsibilities. The training ensures employees have the knowledge and skills to handle personal data appropriately, recognize and respond to privacy concerns, promote early detection and prevention of privacy incidents, and reduce the risk of a data breach. Overall, privacy training and awareness programs build a privacy-conscious workforce.
Each employee of a governmental entity who has access to personal data or supervises an employee who has access to personal data must complete data privacy training:
- within 30 days after employment; and
- at least once a year.
A governmental entity is responsible for ensuring that these employees complete data privacy training and must include the percentage of the governmental entity's employees who have completed the training in their privacy program report.
Data Privacy Training
A governmental entity may use the data privacy training materials created by the Utah Office of Data Privacy to satisfy this requirement or use their own data privacy training. If a governmental entity provides their own data privacy training, it must include instruction on:
- data privacy best practices, obligations, and responsibilities;
- the relationship between privacy, records management, and security;
- the privacy interests and requirements of this chapter; and
- as applicable, the privacy interests and requirements of GRAMA.
Contact Us
Share your feedback questions & concerns here. You may also reach out to us directly at [email protected]