Close Menu
FSNN | Free Speech News NetworkFSNN | Free Speech News Network
  • Home
  • News
    • Politics
    • Legal & Courts
    • Tech & Big Tech
    • Campus & Education
    • Media & Culture
    • Global Free Speech
  • Opinions
    • Debates
  • Video/Live
  • Community
  • Freedom Index
  • About
    • Mission
    • Contact
    • Support
Trending

Plans for a UK Digital Gilt Instrument, or DIGIT, hinge on one missing piece: onchain cash

18 minutes ago

US Federal Officials Barred Until 2029 from Issuing or Sponsoring Tokens under CLARITY’s Proposed Ethics Rules

19 minutes ago

Franklin Templeton Says Agentic AI Is Crypto’s ‘Killer Use Case’

20 minutes ago
Facebook X (Twitter) Instagram
Facebook X (Twitter) Discord Telegram
FSNN | Free Speech News NetworkFSNN | Free Speech News Network
Market Data Newsletter
Wednesday, July 22
  • Home
  • News
    • Politics
    • Legal & Courts
    • Tech & Big Tech
    • Campus & Education
    • Media & Culture
    • Global Free Speech
  • Opinions
    • Debates
  • Video/Live
  • Community
  • Freedom Index
  • About
    • Mission
    • Contact
    • Support
FSNN | Free Speech News NetworkFSNN | Free Speech News Network
Home»News»Legal & Courts»State Chief Privacy Officers Can Have Real Power
Legal & Courts

State Chief Privacy Officers Can Have Real Power

News RoomBy News Room2 hours agoNo Comments9 Mins Read1,958 Views
Share Facebook Twitter Pinterest Copy Link LinkedIn Tumblr Email VKontakte Telegram
State Chief Privacy Officers Can Have Real Power
Share
Facebook Twitter Pinterest Email Copy Link

Listen to the article

0:00
0:00

Key Takeaways

Playback Speed

Select a Voice

Subscribe to the Free Future Newsletter
Or get immediate notifications of new posts via Substack
Free Future home

I’ve been writing in recent months about how digital identity systems are potentially disastrous for privacy and how the state of Utah is being uniquely thoughtful in its approach to the technology. But Utah seems to be taking an interesting approach to privacy in ways that go beyond the digital ID issue. An example is the role it has created for a state chief privacy officer (CPO).

Though Utah is not always good on privacy — its commercial privacy law is one of the weakest in the nation, for example, and its new law targeting the use of VPNs threatens the use of that vital privacy-protecting technology nationwide. Nevertheless, Utah has long been an occasional bright spot on privacy, and its current governor, Spencer Cox, has shown genuine concern about both governmental and consumer privacy.

My sense is that a lot of people in the privacy world haven’t really focused on state CPOs; I certainly haven’t. But as the ACLU has long held, privacy laws need to be backed up by institutions that enforce them or they may wither on the vine, as we have seen with laws such as the federal Privacy Act of 1974. Good privacy oversight institutions should include both independent oversight bodies (such as the California Privacy Protection Agency) and privacy officials working within government agencies. State CPOs are not independent from a state’s political leadership but with the support of such leadership can play an important role.

I recently spoke to Utah’s dynamic CPO, Christopher Bramwell, and asked him about how Utah is approaching the role, how it has institutionalized privacy in general, and how that differs from most other states. He made several interesting arguments during our conversation (quotes edited for length and clarity).

1. The CPO role should be bigger than compliance

First I asked Bramwell about the general role of CPOs in the states, and how many states even have CPOs. Pointing to a survey from the National Association of State Chief Information Officers that has a lot of information about the role across states, he told me:

Twenty-five states have somebody in an executive privacy officer role. Some of them are “privacy analyst.” Some of them are a “privacy manager.” Some of them are just “other duties as assigned.” So it’s very different what states have in terms of the formality of the role.

 

Now, most of those, though — this is where you need to separate out Utah’s approach from other states — most states are looking at privacy from a compliance perspective: “What are we required to do and are we doing it?” Not from a “What should the public policy be to have the best privacy to protect our citizens?”

2. Don’t have your CPO report to the Chief Information Officer (CIO)

Utah has been very intentional about creating checks and balances around privacy. As a result, the Chief Privacy Officer serves as the director of an independent office within the Utah Department of Government Operations and does not report to the Chief Information Officer.

 

Most CIOs are responsible for helping government modernize systems, improve service delivery, and enable the effective use of data. Those are critical responsibilities. At the same time, privacy leaders are tasked with ensuring that modernization efforts appropriately account for individual rights, transparency, accountability, and long-term public trust.

 

This is not a criticism of CIOs or the important work they do. As government digitizes, there will inevitably be situations where competing interests must be balanced. The question isn’t whether modernization or privacy should prevail, it’s whether privacy interests are represented by an independent voice in those discussions. Utah’s approach has been to create clear separation of duties so that both perspectives can be fully considered as part of the decision-making process. We work very closely with our CIO and technology leadership. Privacy is integrated into the discussion early, which creates alignment, reduces friction, and allows us to move forward with greater confidence.

 

I report actually to a cabinet member, the head of the Department of Government Operations. He’s also the chair of the Utah Privacy Governing Board, which is made up of the five highest elected officials in the state or their designees.

3. Institutionalize privacy beyond just one office or officer

Utah is one of only a handful of states where the Chief Privacy Officer is established in statute and it’s actually a governor-appointed position. So having statutory duties and being appointed by the governor elevates privacy from an administrative function to a matter of statewide public policy and governance.

 

We also have the Government Data Privacy Act, which I believe may be the most comprehensive state government privacy law in the country governing how governmental entities process personal data.

 

More importantly, Utah has made sure not to rely on a single office or individual to advance privacy. We’ve intentionally built a broader governance framework that includes the Office of Data Privacy, the Utah Privacy Governing Board, and an independent privacy audit function within the Office of the State Auditor.

 

There’s also our Utah Privacy Commission, which is an independent advisory body composed of public employees and private citizens appointed by the Governor, Attorney General, and State Auditor. Its role is to study emerging privacy issues and provide policy recommendations.

 

My role exists within that larger framework. The objective is not simply to assess compliance, but to help implement a long-term statewide privacy strategy to steadily increase privacy maturity across government over the course of a decade.

4. Getting privacy fundamentals right is vital in the age of AI and big tech

The privacy challenges facing governments today are fundamentally different from those of even a decade ago. Advances in artificial intelligence, surveillance technologies, large-scale data collection, and digital identity systems are creating new opportunities, but also new risks that many existing governance frameworks were never designed to address.

 

There will be growing pressure to automate decisions and optimize outcomes, but those objectives have to be be balanced against transparency, accountability, and an individual’s ability to make informed choices about their own life. That concern drives much of the work we are doing in Utah. States need more than isolated privacy requirements — they need comprehensive privacy strategies that can adapt to these rapidly evolving technologies.

5. Many states are ignoring key aspects of their privacy laws

Most states adopted records management and retention laws in the sixties and seventies. As governments modernized, many replaced paper processes with digital technologies but never fully adapted those systems to comply with those laws. The result is that many systems were built to retain data indefinitely, even where laws require it to be disposed of.

 

One of the foundational questions states should be asking is whether their data governance practices have kept pace with their technology modernization efforts. In many cases, they have not.

 

Last year, we conducted research across all 50 states to identify generally applicable laws and policies related to key data governance practices. We compiled the results into a publicly available spreadsheet that allows users to navigate directly to the applicable laws in each state.

 

The purpose was to make these requirements more accessible and transparent. In many cases, policymakers, researchers, journalists, and members of the public don’t even know what questions to ask or what legal requirements already exist. Our resource is intended to help states assess where they stand today, identify gaps in their governance frameworks, and ask important questions about whether existing laws are being enforced.

6. All the agencies and local governments in a state can’t do privacy right without help

One of the most important roles a Chief Privacy Officer can play is helping governmental entities in the state understand not just what privacy requirements exist, but how to systematically implement them over time.

 

We have a statewide privacy framework — 24 practices that all Utah government entities are supposed to comply with. We actually lay out, here’s the high-level strategy for the state, and here are the practices that you should be implementing. That means: Who’s accountable, who should be doing the work? How do you do transparency? How do you give notice? How do you ensure individuals have access to their data?

 

Meaningful privacy modernization doesn’t happen overnight. Most states will require years of sustained effort to build mature privacy programs across hundreds or thousands of governmental entities. We use a maturity model to help entities assess where they are today and identify practical steps for improvement. State law also requires annual reporting on privacy program maturity and planned improvements. The goal is to create a cycle of assessment, planning, and implementation that steadily increases privacy maturity across government over time.

7. Political support is crucial

None of this would be possible without support from elected leadership. One of the reasons Utah has been able to move quickly is that privacy has been recognized as a strategic issue that deserves attention at the highest levels of government.

 

Governor Cox has been a strong advocate for privacy, issuing a statewide privacy executive order, supporting the creation of the Office of Data Privacy, and helping advance broader discussions around digital identity and his pro-human AI approach.

 

We have also worked closely with the Legislature. Members of both the House and Senate participate in the Utah Privacy Governing Board, which helps make sure privacy priorities remain aligned across branches of government.

 

I’m not enough of an expert on state government and privacy governance to have informed opinions on all these details, but based on what I’ve seen from Bramwell in the digital ID arena in which I do work, his views are very much worth considering.

Read the full article here

Fact Checker

Verify the accuracy of this article using AI-powered analysis and real-time sources.

Get Your Fact Check Report

Enter your email to receive detailed fact-checking analysis

5 free reports remaining

Continue with Full Access

You've used your 5 free reports. Sign up for unlimited access!

Already have an account? Sign in here

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Telegram Copy Link
News Room
  • Website
  • Facebook
  • X (Twitter)
  • Instagram
  • LinkedIn

The FSNN News Room is the voice of our in-house journalists, editors, and researchers. We deliver timely, unbiased reporting at the crossroads of finance, cryptocurrency, and global politics, providing clear, fact-driven analysis free from agendas.

Related Articles

Media & Culture

Trump’s New DOJ Nominee Wants To Ban Online Porn and Prosecute Big Tech

56 minutes ago
Campus & Education

The new war on political satire

2 hours ago
Media & Culture

Nobody Likes Red Tape, Not Even Mamdani

2 hours ago
Media & Culture

American Public Schools Lost 1.4 Million Students Since COVID. Their Budgets Grew by 34 Percent Anyway.

3 hours ago
Campus & Education

Does MLB’s Pride Night policy violate the First Amendment?

4 hours ago
Media & Culture

We’ve Been Wrong About Nuclear Power

4 hours ago
Add A Comment
Leave A Reply Cancel Reply

Editors Picks

US Federal Officials Barred Until 2029 from Issuing or Sponsoring Tokens under CLARITY’s Proposed Ethics Rules

19 minutes ago

Franklin Templeton Says Agentic AI Is Crypto’s ‘Killer Use Case’

20 minutes ago

DOJ Now Citing Fake AI-Generated Cases To Keep ICE Detainees Locked Up

55 minutes ago

Trump’s New DOJ Nominee Wants To Ban Online Porn and Prosecute Big Tech

56 minutes ago
Latest Posts

SEC’s Pierce warns some DeFi vaults, onchain lending may fall under securities laws

1 hour ago

Anthropic joins UK FCA’s AI regulatory sandbox as second cohort launches

1 hour ago

Clarity Act Latest Draft Bars Trump From Crypto Ventures—But Only Until 2029

1 hour ago

Subscribe to News

Get the latest news and updates directly to your inbox.

At FSNN – Free Speech News Network, we deliver unfiltered reporting and in-depth analysis on the stories that matter most. From breaking headlines to global perspectives, our mission is to keep you informed, empowered, and connected.

FSNN.net is owned and operated by GlobalBoost Media
, an independent media organization dedicated to advancing transparency, free expression, and factual journalism across the digital landscape.

Facebook X (Twitter) Discord Telegram
Latest News

Plans for a UK Digital Gilt Instrument, or DIGIT, hinge on one missing piece: onchain cash

18 minutes ago

US Federal Officials Barred Until 2029 from Issuing or Sponsoring Tokens under CLARITY’s Proposed Ethics Rules

19 minutes ago

Franklin Templeton Says Agentic AI Is Crypto’s ‘Killer Use Case’

20 minutes ago

Subscribe to Updates

Get the latest news and updates directly to your inbox.

© 2026 GlobalBoost Media. All Rights Reserved.
  • Privacy Policy
  • Terms of Service
  • Our Authors
  • Contact

Type above and press Enter to search. Press Esc to cancel.

🍪

Cookies

We and our selected partners wish to use cookies to collect information about you for functional purposes and statistical marketing. You may not give us your consent for certain purposes by selecting an option and you can withdraw your consent at any time via the cookie icon.

Cookie Preferences

Manage Cookies

Cookies are small text that can be used by websites to make the user experience more efficient. The law states that we may store cookies on your device if they are strictly necessary for the operation of this site. For all other types of cookies, we need your permission. This site uses various types of cookies. Some cookies are placed by third party services that appear on our pages.

Your permission applies to the following domains:

  • https://fsnn.net
Necessary
Necessary cookies help make a website usable by enabling basic functions like page navigation and access to secure areas of the website. The website cannot function properly without these cookies.
Statistic
Statistic cookies help website owners to understand how visitors interact with websites by collecting and reporting information anonymously.
Preferences
Preference cookies enable a website to remember information that changes the way the website behaves or looks, like your preferred language or the region that you are in.
Marketing
Marketing cookies are used to track visitors across websites. The intention is to display ads that are relevant and engaging for the individual user and thereby more valuable for publishers and third party advertisers.