24-73-102. Governmental entity--protection of personal identifying information--definition
  1. (1)
    To protect personal identifying information, as defined in section 24-73-101(4)(b), from unauthorized access, use, modification, disclosure, or destruction, a governmental entity that maintains, owns, or licenses personal identifying information shall implement and maintain reasonable security procedures and practices that are appropriate to the nature of the personal identifying information and the nature and size of the governmental entity.
    1. (a)
      Appropriate to the nature of the personal identifying information disclosed to the third-party service provider; and
    2. (b)
      Reasonably designed to help protect the personal identifying information from unauthorized access, use, modification, disclosure, or destruction.
    1. (a)
      Help protect the personal identifying information from unauthorized access, modification, disclosure, or destruction; or
    2. (b)
      Effectively eliminate the third party's ability to access the personal identifying information, notwithstanding the third party's physical possession of the personal identifying information.
  2. (4)
    A governmental entity that is regulated by state or federal law and that maintains procedures for storage of personal identifying information pursuant to the laws, rules, regulations, guidances, or guidelines established by its state or federal regulator is in compliance with this section.
  3. (5)For the purposes of this section, “third-party service provider” means an entity that has been contracted to maintain, store, or process personal identifying information on behalf of a governmental entity.