Part 8: Enforcement and Audit
Utah Code §§ 63A-20-801 and 63A-20-802 establish the enforcement and audit framework for the SEDI program. While primarily administrative and legal in nature, these sections have technical implications for logging, evidence preservation, and auditability.
|
Req ID |
63A-20 |
Requirement |
Control |
Governance |
|---|---|---|---|---|
|
Complaint submission mechanism |
EXPT |
Statute |
||
|
801(4)-(6) |
Attorney general enforcement support |
ADMN |
Statute |
|
|
Legislative audit |
EXPT |
Statute |
||
|
Anti-surveillance architectural proof |
EXPT |
Statute |
||
|
Audit report deadline |
ADMN |
Statute |
SEDI-ENF-01: Complaint submission mechanism
An individual may submit a complaint to the data privacy ombudsperson alleging a violation by the department, a digital wallet provider, a verifier, or a relying party.
Utah Code § 63A-20-801(1)
Requirement: The SEDI program SHALL provide a complaint submission mechanism accessible to holders. Complaint records SHALL be maintained by the ombudsperson's office.
Criticality: High — Without an accessible complaint mechanism, individuals have no statutory avenue to report violations, undermining the enforcement framework.
Roles: Department, Data Privacy Ombudsperson
Assessment Objectives
Determine if:
- a complaint submission mechanism is provided and accessible to holders;
- the complaint submission endpoint is reachable and accepts valid complaint payloads;
- submitted complaints generate a confirmation and tracking identifier for the complainant;
- complaint records are maintained by the ombudsperson's office, searchable, and linked to resolution status;
- the complaint mechanism is accessible to individuals without SEDI (physical submission option exists);
- the complaint mechanism is publicly documented and discoverable;
- complaint volume and resolution metrics are tracked.
Verification Methods
|
Method |
Applicability |
Performed By |
Frequency |
Limitations |
|---|---|---|---|---|
|
AUTO |
Recommended |
Conformance test suite |
Per-release |
Cannot assess accessibility for non-digital users or verify that complaints reach the ombudsperson's office |
| EXPT |
Mandatory |
Independent assessor |
Annual |
Point-in-time; does not detect service degradation between assessments |
|
ADMN |
Recommended |
Program auditor |
Annual |
Cannot verify technical availability or user experience quality |
Objective coverage: AUTO → 2, 3; EXPT → 1, 4, 5; ADMN → 6, 7
Assessment objects: Complaint submission interface (digital and physical channels); complaint record database and search functionality; confirmation and tracking identifier generation logic; ombudsperson office staffing and procedural documentation; public-facing complaint mechanism documentation and discoverability assessment; complaint volume and resolution metric reports.
Statutory compliance: Expert review is mandatory because complaint mechanism adequacy requires human assessment of accessibility, usability, and end-to-end procedural completeness. Automated checks supplement by verifying technical availability.
SEDI-ENF-02: Attorney general enforcement support
Derived: Attorney general enforcement powers including civil investigative demands, civil actions, and remedies.
(Utah Code § 63A-20-801(4) through -(6)
Requirement: All ecosystem participants SHALL maintain records sufficient to support civil investigative demands. Compliance evidence SHALL be producible upon lawful request.
Criticality: Medium — Insufficient recordkeeping could impede enforcement actions, but the primary obligation is organizational rather than system-critical.
Roles: All ecosystem participants
Assessment Objectives
Determine if:
- recordkeeping policies exist and specify retention periods sufficient for investigative timelines;
- evidence preservation procedures are documented and staff are trained on their execution;
- records are producible in formats suitable for legal proceedings;
- compliance evidence is producible upon lawful request within required timelines;
- prior civil investigative demands (if any) were satisfied within required timelines.
Verification Methods
|
Method |
Applicability |
Performed By |
Frequency |
Limitations |
|---|---|---|---|---|
|
AUTO |
N/A |
— |
— |
Recordkeeping for legal enforcement and evidence preservation are organizational and legal compliance processes outside the SEDI system boundary |
|
ADMN |
Mandatory |
Program auditor |
Annual |
Cannot verify completeness of records or that preservation procedures will function under actual legal process |
| EXPT |
N/A |
— |
— |
Attorney general enforcement powers are legal authorities; no technical specification to review |
Objective coverage: ADMN → 1, 2, 3, 4, 5
Assessment objects: Recordkeeping policies and retention schedules; evidence preservation procedures and training records; record export and production capabilities documentation; prior civil investigative demand responses and timelines; staff training materials for legal hold and evidence preservation; record format specifications and legal production templates.
Statutory compliance: Only administrative verification is feasible because recordkeeping for legal enforcement and evidence preservation are organizational and legal compliance processes, not technical controls that can be programmatically validated.
SEDI-ENF-03: Legislative audit
Subject to prioritization of the Legislative Audit Subcommittee created in Utah Code § 36-12-8, the Office of the Legislative Auditor General shall conduct an audit of the program beginning on January 1, 2028.
Utah Code § 63A-20-802(1)
Requirement: The Department SHALL maintain auditable records of all program operations, technical decisions, security incidents, and compliance activities. Records SHALL be organized to support the audit scope defined in Utah Code § 63A-20-802(2).
Criticality: High — Inadequate audit records would prevent the legislative auditor from fulfilling the statutory audit mandate and could indicate program governance failures.
Roles: Department
Assessment Objectives
Determine if:
- audit log infrastructure is operational and accepting entries;
- log entries contain required fields (timestamp, actor, action, outcome);
- log retention meets the minimum audit-readiness period for the 2028 legislative audit;
- auditable records cover program operations, technical decisions, security incidents, and compliance activities;
- records are organized to support the audit scope defined in Utah Code § 63A-20-802(2) (surveillance restrictions, program effectiveness, privacy protections);
- records are retrievable and producible for the legislative auditor;
- a recordkeeping policy exists and references Utah Code § 63A-20-802(2) audit scope;
- staff are trained on audit-ready documentation practices.
Verification Methods
|
Method |
Applicability |
Performed By |
Frequency |
Limitations |
|---|---|---|---|---|
|
AUTO |
Recommended |
Conformance test suite |
Quarterly |
Cannot assess whether log content is substantively complete or organized for the audit scope in Utah Code § 63A-20-802(2) |
| EXPT |
Mandatory |
Independent assessor |
Annual |
Point-in-time; cannot guarantee records will remain complete and organized through the 2028 audit |
|
ADMN |
Recommended |
Program auditor |
Annual |
Cannot verify technical completeness or accuracy of records |
Objective coverage: AUTO → 1, 2, 3; EXPT → 4, 5, 6; ADMN → 7, 8
Assessment objects: Audit log infrastructure configuration and health monitoring; log entry samples and field completeness reports; log retention policies and storage capacity planning; program operation records and decision documentation; security incident records and response reports; compliance activity documentation; record organization schema mapped to Utah Code § 63A-20-802(2) scope; staff training records for audit-ready documentation; record retrieval and export procedures.
Statutory compliance: Expert review is mandatory because audit readiness requires professional assessment of whether records substantively cover the legislative audit scope. Automated checks supplement by verifying log infrastructure is operational and retaining entries.
SEDI-ENF-04: Anti-surveillance architectural proof
The audit shall evaluate whether the department has met the restrictions on monitoring, surveillance, and tracking described in Utah Code § 63A-20-301.
Utah Code § 63A-20-802(2)(b)
Requirement: The Department SHALL be able to demonstrate, through architectural documentation, system logs, and independent analysis, that its systems are incapable of monitoring, surveilling, or tracking presentations. This is a "prove the negative" requirement that demands architectural evidence, not merely policy assertions.
Criticality: Critical — Inability to prove anti-surveillance architecture would fail the legislative audit and undermine the foundational privacy guarantee of the program.
Roles: Department
Assessment Objectives
Determine if:
- Department systems do not contain presentation metadata fields (verifier identity, presentation timestamp correlations, holder-verifier linkage);
- no API endpoints in Department systems accept or return presentation tracking data;
- status-list queries are unlinkable to specific credentials;
- systems are structurally incapable of monitoring, surveilling, or tracking presentations;
- no Department system contains data that could reconstruct presentation patterns;
- architectural documentation demonstrates anti-surveillance design and is current;
- independent security assessments of anti-surveillance architecture have been completed and findings addressed;
- Department policy prohibits collection or retention of presentation metadata.
Verification Methods
|
Method |
Applicability |
Performed By |
Frequency |
Limitations |
|---|---|---|---|---|
|
AUTO |
Recommended |
Conformance test suite |
Per-release + CI |
Cannot detect metadata leakage through side channels, operational logs, or infrastructure-level telemetry |
| EXPT |
Mandatory |
Security assessor / Independent assessor |
Annual + pre-audit |
Point-in-time; architectural changes after review could introduce surveillance capability |
|
ADMN |
Recommended |
Program auditor |
Annual |
Policy assertions alone are insufficient; cannot substitute for technical architectural proof |
Objective coverage: AUTO → 1, 2, 3; EXPT → 4, 5, 6; ADMN → 6, 7, 8
Assessment objects: System architecture diagrams and anti-surveillance design documentation; API endpoint inventories and data field specifications; status-list implementation and query linkability analysis; data flow diagrams showing absence of presentation metadata paths; system log configurations and retention policies; independent security assessment reports and remediation records; Department policy documents on presentation metadata; infrastructure telemetry and operational log configurations.
Statutory compliance: Expert review is mandatory because "prove the negative" requires independent professional analysis of architecture, data flows, and system capabilities, not merely automated scans. Automated testing supplements by continuously verifying no presentation metadata surfaces in Department systems.
SEDI-ENF-05: Audit report deadline
Complete the audit report by October 31, 2028.
Utah Code § 63A-20-802(3)(a)
Requirement: Administrative timeline; no direct technical requirement. The Department SHALL cooperate fully with audit activities to support timely completion.
Criticality: Medium — The deadline is a statutory obligation of the Legislative Auditor General; the Department's role is to ensure its cooperation does not cause delay.
Roles: Legislative Auditor General
Assessment Objectives
Determine if:
- the audit engagement timeline is on track for October 31, 2028 completion;
- the Department has responded to audit requests within agreed timelines;
- no outstanding audit information requests are overdue;
- the Department has cooperated fully with audit activities to support timely completion.
Verification Methods
|
Method |
Applicability |
Performed By |
Frequency |
Limitations |
|---|---|---|---|---|
|
AUTO |
N/A |
— |
— |
Audit timeline compliance is an administrative coordination obligation between the Department and the Legislative Auditor General, not a technical property of the SEDI system |
|
ADMN |
Mandatory |
Program auditor |
As needed (pre-deadline) |
Cannot enforce audit completion by an external legislative office; Department can only control its own cooperation |
| EXPT |
N/A |
— |
— |
Audit scope and methodology are organizational decisions; no technical system to review |
Objective coverage: ADMN → 1, 2, 3, 4
Assessment objects: Audit engagement letter and project timeline; Department response logs for audit information requests; outstanding request tracker and overdue item reports; Department cooperation records and correspondence with the Legislative Auditor General.
Statutory compliance: Only administrative verification is feasible because this is a statutory deadline for a legislative office. No technical control can enforce audit completion timing.