A bill for an act relating to matters under the purview of the department of management, and including effective date and applicability provisions. (Formerly HF 756, HSB 72.) Effective date: 07/01/2026, 07/01/2027. Applicability date: 07/01/2026.
HF 1028 is a broad Department of Management bill that revises state information technology governance, contracting rules, data practices, and some criminal-justice planning functions. It increases and extends funding for the technology reinvestment fund, directs the department to prioritize IT projects based on strategic value, feasibility, return on investment, rural access, and long-term sustainability, and requires annual reporting on funded projects. The bill also changes how interdepartmental transfers may be used, including a higher cap on transfers to non-entitlement appropriations and specific treatment for entitlement appropriations such as indigent defense and certain human services programs.
The bill also creates a detailed framework for state technology contracts. It prohibits a long list of contract terms viewed as unfavorable to the state, such as broad indemnification, foreign governing law, mandatory arbitration, confidentiality over pricing, venue outside Iowa, and automatic renewal notice requirements for software licenses. At the same time, it requires certain terms to be included, including Iowa governing law, Iowa venue, and provisions stating that state data remains the property of the state and must be returned in usable form and deleted after the contract ends, subject to retention requirements. It also authorizes limited vendor liability caps in IT contracts, but voids liability limits that would excuse cybersecurity incidents or other serious misconduct.
The bill strengthens cybersecurity confidentiality by making communications with the chief information security officer confidential and generally exempt from open records, discovery, and evidentiary use, with narrow exceptions for threat response, serious harm, minor safety, law enforcement, and confidential briefings to the governor or legislators. It also expands the department’s role in criminal justice data analysis by authorizing an integrated information system, access to a wide range of juvenile, child welfare, corrections, and criminal-history data for research and evaluation, and a multiagency tracking system for juveniles and adults moving through the justice system. Related provisions amend and repeal several sections of chapter 216A and update references to the statistical analysis center.
Overall, the bill appears to have been broadly supported, passing the House and Senate with large margins and only a small number of dissenting votes. The vote history suggests general agreement on the need to modernize state IT management, improve cybersecurity protections, and tighten state contracting standards. The lack of committee transcript material limits insight into detailed debate, but the final votes indicate the bill was not highly controversial as a whole.
The main points of contention likely center on the bill’s confidentiality provisions and expanded data-sharing authority. Critics could be concerned that shielding cybersecurity communications and allowing access to sensitive juvenile, child welfare, and criminal-justice records may reduce transparency or raise privacy concerns, even though the bill says existing confidentiality laws still apply. Another possible issue is the bill’s strong restrictions on vendor contract terms, which favor state control and may be seen by vendors as limiting flexibility in IT procurement and risk allocation.
HF 1028 amends Iowa Code provisions governing the Department of Management, technology reinvestment funding, state contracting, criminal-justice data coordination, and related confidentiality rules. It increases ongoing appropriations to the technology reinvestment fund, changes reporting and carryforward rules for that fund, revises interdepartmental transfer authority under section 8.39, and makes several changes to chapter 216A by repealing some criminal-justice planning provisions and redirecting statistical-analysis-center functions to new section 8.98. The bill also applies new contract rules to Department of Management and supported-entity contracts entered into or renewed on or after July 1, 2026, and makes certain funding changes effective July 1, 2027.
The overall sentiment around HF 1028 appears positive and pragmatic. The bill passed both chambers with overwhelming support, indicating broad bipartisan acceptance of its goals: modernizing state technology, improving cybersecurity, clarifying data governance, and protecting the state’s interests in IT contracts. The small number of no votes suggests that any reservations were limited rather than reflecting broad opposition.
The most notable contention points are the bill’s privacy and transparency tradeoffs and its aggressive state-centered contracting rules. The confidentiality of chief information security officer communications and the expanded access to sensitive juvenile, child welfare, and criminal-justice data may worry privacy advocates or transparency proponents. On the contracting side, vendors may object to the prohibition of arbitration, foreign law, broad confidentiality, and liability-limiting terms, while state officials likely view those restrictions as necessary to protect public funds, preserve legal rights, and keep control over state data and litigation.