State Agencies and Government Privacy Law in Arkansas
How is a state agency defined under the law?
Under Ark. Code § 25-1-114, a state agency is defined as “an agency, authority, board, bureau, commission, council, department, office, or officer of the state receiving an appropriation by the General Assembly, including without limitation a state-supported institution of higher education. State agency does not include the following unless the Legislative Council adopts rules under subsection (h) of this section that include one (1) or more of the following in the definition of “state agency”: The Arkansas State Game and Fish Commission, if the rule is not promulgated under the authority of a statute enacted by the General Assembly; An institution of higher education.”
What are the duties of state agencies under the law?
- A description of the data elements that the state agency intends to collect via their website, as well as how this data will be used.
- The circumstances under which the state agency will share personal information with other agencies or entities, and the purpose for such disclosure.
- Whether a state agency’s data collection policies are mandatory or allow for users to opt-out of their consent, as well as the consequences an Arkansas resident stands to face for refusing to provide their personal information.
- An explanation of the data elements pertaining to Arkansas residents that may be accessed in accordance with the provisions of the Freedom of Information Act or FOIA for short.
- State agency websites must ensure that their privacy policies are in a machine-readable format.
What data elements are protected under the law?
The data elements regarding citizens of the state of Arkansas that are legally covered in the event of a data breach or other related security incident include but are not limited to:
- Online log-in credentials.
- Full names.
- Dates and places of birth.
- Telephone numbers.
- Postal addresses.
- Email addresses.
- Social security numbers.
- Medical and healthcare information.
- Financial information.
- Drivers licenses.
- Mother’s maiden name.
- Unique online identifiers.
- Demographic information.
- Religious information.
How can state agencies within Arkansas comply with the law?
One primary way that state and government agencies can comply with legislation such as Ark. Code § 25-1-114 is by investing in an automatic redaction software program. As state agencies will be charged with storing personal information concerning a wide range of citizens within their respective states, adequately protecting this information can be extremely difficult. To this point using redaction software programs, government and state agencies can ensure that the personal information in their possession remains confidential and secure at all times. Moreover, these government and state agencies can also maintain compliance with applicable privacy and data protection laws.
While the provisions of Ark. Code § 25-1-114 have been amended several times since the law was introduced in 2004, with the most recent amendments occurring in 2015, the purpose of the law remains the same. As U.S. citizens have the right to access certain public records and information under federal legislation such as FOIA, state agencies must take the steps and measures necessary to facilitate such requests. To this end, Ark. Code § 25-1-114 provides residents within the state with the legal authority to access public records within their local jurisdictions while simultaneously protecting their personal privacy.