Government Data Protection Law in the State of Virginia
Virginia’s Government Data Collection and Dissemination Practices Act is a data privacy law that was enacted in 2015. As the name of the law suggests, Virginia’s Government Data Collection and Dissemination Practices Act was enacted for the purpose of safeguarding the various forms of personally identifiable information that residents of the state submit to governmental agencies that operate within Virginia. With this being said, the law outlines the responsibilities that government agencies have within Virginia as it concerns ensuring that the personal information of the state’s various residents is collected, maintained, and disseminated in a manner that protects the confidentiality and integrity of said information.
How are government agencies defined under the law?
Under Virginia’s Government Data Collection and Dissemination Practices Act, a government agency is defined as “any agency, authority, board, department, division, commission, institution, bureau, or like a governmental entity of the Commonwealth or of any unit of local government including counties, cities, towns, regional governments, and the departments thereof, and includes constitutional officers except as otherwise expressly provided by law.” Alternatively, the law defines a data subject as “means an individual about whom personal information is indexed or may be located under his name, personal number, or other identifiable particulars, in an information system.”
What are the duties of government agencies under the law?
The data and privacy protection duties that government agencies have under Virginia’s Government Data Collection and Dissemination Practices Act include the following:
- Government agencies are prohibited from creating or maintaining information systems that are hidden from the general public.
- Government agencies may only collect information pertaining to Virginia residents in accordance with a specific need or purpose that has been expressed to them in advance.
Information that a government agency collects must be relevant and appropriate with respect to the purpose for which it was collected.
- Government agencies are prohibited from collecting personal information via fraudulent or deceptive methods.
- Government agencies are only permitted to use personal information that is accurate, reliable, and up to date.
- Government agencies are responsible for ensuring that the personal information in their possession is protected from misuse.
- Government agencies are responsible for developing procedures that will allow individuals to correct, amend, or erase personal information pertaining to them.
- Government agencies must ensure that all personal information they collect is done so in accordance with applicable legislation.
What data elements are protected under the law?
The data elements concerning citizens that are legally protected from unauthorized access or disclosure under Virginia’s Government Data Collection and Dissemination Practices Act include but are not limited to:
- Social security numbers.
- Drivers license.
- State identification cards.
- Student identification numbers.
- Vehicle license plate numbers.
- Education information.
- Property holdings that have been derived from tax returns.
- Financial transactions.
- Medical history.
- Employment records.
- Voice prints.
- Ancestry information.
- Political information.
- Religious information.
How can government agencies comply with the law?
As government agencies will inherently collect large amounts of personal information from their respective citizens, effectively protecting this information can prove to be challenging. To this end, one way in which government agencies can comply with legislation such as Virginia’s Government Data Collection and Dissemination Practices Act is through the use of automatic redaction software. To illustrate this point further, the provisions of the law protect license plate numbers from unauthorized dissemination. Using an automatic redaction software program, government agencies can automatically redaction thousands of license plates within video or images within minutes, ensuring that this information does not become compromised.
The provisions of Virginia’s Government Data Collection and Dissemination Practices Act serve to hold government agencies within the state accountable with regard to the forms of personal data they collect, manage, and disclose in relation to residents within the said state. As this information constitutes the trust that the American populace places in their local institutions and agencies, it is imperative that said information is protected at all times. Through such legislation, citizens within the state of Virginia have the means to hold their local elected officials accountable.