Marin County Adopts New Data Security Policy

Marin County has adopted a new data policy that will govern the sharing of digital information both internally and externally.
The county has a Technology Investment Board that evaluates risks associated with artificial intelligence, digital accessibility and security.
“Now data privacy and security will be part of that informed policy and operational decisionmaking,” said Angie Goldman, the county’s interim chief information officer, at the Board of Supervisors meeting on Aug. 18.
The policy has its debut as a number of government agencies reevaluate their use of Flock Safety license plate reading cameras.
In May, Marin supervisors postponed a decision on whether to approve a $1.5 million contract for improved data sharing among the county’s law enforcement agencies.
According to a staff report, the data policy, “includes protections to prevent misuse of data in ways that could impact residents, especially marginalized or underrepresented communities, thereby supporting fairness and equity in county operations.”
Under the new policy, before data is to be shared between county departments or with external vendors, the digital information first must be evaluated by Jason Balderama, the county’s chief information security officer. Balderama will decide whether to classify the data to be shared as public, confidential or restricted.
The public data category includes information that would create no harm if approved for public release. Examples include press releases, meeting agendas or approved budget summaries.
The confidential data category is defined as information that could harm people, operations or the county’s legal position if disseminated freely. Examples would include personal identification information, financial records or employee home addresses.
The restricted data category, the most sensitive, is information that could cause serious harm or legal liability if disclosed without authorization. Examples include protected health information, criminal justice information or Social Security numbers.
The policy limits access to confidential data to authorized staff with a “need to know.” Technology Investment Board review is required for new contracts, renewals, memorandums of understanding, data use agreements and other written agreements involving confidential data.
Access to restricted data is limited to “explicitly authorized roles only.” The same type of Technology Investment Board review is mandated for restricted data as confidential data.
The Technology Investment Board consists of four assistant county executives, the chief information officer and the chief digital and innovation officer.
The Information Services and Technology Department received comments from supervisors prior to the August meeting and subsequently made one key addition to the data policy. As a result, data sharing contracts and agreements will be audited no later than 12 months following their approval by the Technology Investment Board to ensure compliance with contractual requirements and any condition of approval.
“There are exceptions, but only if it’s to comply with an applicable law or a court order,” said Laura Rosas, an assistant county executive overseeing justice and welfare.
Supervisors Mary Sackett and Dennis Rodoni both expressed concern that the policy hadn’t gone far enough.
“I remain concerned about our ability to know what’s coming at us,” said Sackett. “The example that is coming up is around surveillance cameras. My question is, who’s the keeper of the information?”
Rodoni said, “Mission creep seems to be an issue. We issue a contract to Flock for a certain number of cameras in a certain number of locations then suddenly I see where the locations don’t match up with what I approved. That’s mission creep.”
County Executive Derek Johnson said the county is “tuning up” its purchasing and contract agreements to ensure that if there are any changes for the purpose of collection and use of data that permission is obtained from the county in advance.
Several members of the public voiced their skepticism regarding the effectiveness of the data policy.
“I do support the creation of a data policy that addresses these escalating threats,” said Margaret Fisher of Mill Valley. “However, this policy contains no transparency provisions, so expecting Flock to come back and tell you when there’s a breach is a high bar that will not be reached.”
Tammy Edmondson, a member of the Mill Valley Force for Racial Equity and Empowerment, said, “I’m going to focus on the complete absence of substantive standards and criteria in the policy.”
Edmondson said that at a minimum the county should commit to collecting the minimum amount of data required; prohibiting the use of data for secondary or unrelated purposes; to transparency regarding what is being tracked and when privacy breaches occur; and strict rules for third-party users.
Johnson wrote in an email Monday that the data sharing agreement that the county’s law enforcement agencies were seeking in May “is under consideration and being reviewed under the new applicable data sharing policy and is tentative for a return to the Board of Supervisors by October.”