Record and Personal Data Sharing, Selling, and Purchasing
Maturity Level

Level 0: Non-Existent
The practice is not implemented or acknowledged.
Data is shared freely without formal agreements or consideration for legal basis.Example Strategies
- Identify individuals within the entity who have familiarity or knowledge of data sharing, selling, and purchasing of personal data who can begin an initial inventory of such activities until permanent individuals to perform formal inventorying are established.
Level 1: Ad Hoc
Practice may occur but is undocumented (no policies or procedures), application is reactive and not standardized.
Some informal sharing agreements may exist, but they lack formal privacy clauses or legal review.Example Strategies
- Create standardized data sharing agreement templates and a review process.
- Develop a legal template for Data Sharing Agreements (DSAs) that includes standard privacy clauses (purpose limitation, security requirements, no selling unless expressly required by law), and require all new sharing arrangements to use it.
Level 2: Defined
Practice is implemented and documented, but documentation may not cover all relevant aspects, and application may be informal and inconsistent.
Standardized data sharing agreements are in place for some sharing activities, but they may not cover all relevant aspects, or legal review is inconsistent.Example Strategies
- Mandate and enforce the use of formal DSAs for all data sharing and prohibit unauthorized selling.
- Implement a policy that requires all data sharing (internal and external) to be formalized through a signed DSA reviewed by legal/privacy, and conduct regular internal communication campaigns reinforcing the strict prohibition on selling personal data. Ensure consistent annual reporting to the Chief Privacy Officer.
Level 3: Consistently Implemented
Practice is documented to cover all relevant aspects, application is formal and consistent.
All data sharing activities are governed by formal, legally reviewed agreements with comprehensive privacy clauses (e.g., purpose limitations, security requirements), adhering to Utah Code prohibitions on selling personal data unless expressly authorized. Annual reporting to the Chief Privacy Officer is consistent.Example Strategies
- Centralize and monitor data sharing activities and agreements.
- Create a central registry of all active DSAs, track their expiration dates, and conduct periodic audits of actual data sharing practices against the terms of the agreements and Utah Code.
Level 4: Managed
Practice is actively managed with metrics that are regularly reviewed to assess efficacy and facilitate improvement.
The entity regularly audits data sharing practices, monitors compliance with agreements, and tracks the volume and types of data shared. Metrics inform risk assessments and policy adjustments.Example Strategies
- Implement compliance management software to actively review all legal citations found in a contract related to personal data as well as data sharing agreements to ensure any changes are accounted for and potential issues are flagged for required review.
Level 5: Optimized
Practice is fully embedded in the entity with recognition and understanding across the workforce through active training and awareness campaigns, and inclusion in operations and strategy.
Data sharing is managed through a centralized portal or system, with automated workflows for approvals, agreement management, and compliance monitoring, ensuring adherence to the strictures of Utah Code.