A bill for an act relating to matters under the purview of the department of management, making appropriations, and including applicability provisions.(Formerly SSB 1083; See SF 630.)
SF 307 is a Department of Management bill that makes a broad set of changes to how Iowa manages technology funding, information security, contract terms, and certain criminal-justice data functions. It updates confidentiality rules for budget-related transmittals to the department, revises the Technology Reinvestment Fund to create a continuing annual appropriation and a project-prioritization framework, and requires annual reporting to the legislature on funded technology projects. The bill also shortens the interval for FBI criminal history checks for certain department and supported-entity personnel from every 10 years to every 5 years.
The bill further establishes detailed rules for information technology contracts entered into by the department or supported entities. It voids a long list of prohibited contract terms, including indemnification clauses, foreign governing-law provisions, mandatory arbitration, jury-trial waivers, broad confidentiality provisions, and certain liability-shifting terms, while deeming Iowa law and Polk County venue to be included in covered contracts. It also authorizes limited vendor-liability caps, but invalidates caps that eliminate liability for cybersecurity incidents or other specified misconduct. In addition, the bill makes communications with the chief information security officer confidential, expands the department’s role in criminal justice data analysis and multiagency information systems, and transfers the Iowa statistical analysis center functions from the Department of Health and Human Services to the Department of Management, while repealing several related code sections.
The bill amends multiple sections of the Iowa Code, especially chapter 8 and chapter 216A, and creates several new sections governing technology procurement, cybersecurity confidentiality, public-records treatment, and criminal-justice data coordination. It changes the administration of the Technology Reinvestment Fund, creates ongoing appropriations, and imposes new reporting and project-selection requirements on the Department of Management. It also alters open-records and custody rules by limiting access to certain records held by the department in an IT-storage capacity and by making cybersecurity communications confidential. Finally, it shifts statistical analysis center duties and related data-access authority from the Department of Health and Human Services to the Department of Management and updates cross-references throughout juvenile-justice and child-welfare statutes.
The available voting history suggests the bill was well received in committee, passing the Senate State Government report unanimously 16-0. The bill’s structure and detailed operational changes indicate a strong policy focus on centralizing technology oversight, tightening cybersecurity and contracting rules, and improving data analysis capacity. No committee transcript is provided, so there is no recorded debate to show broader support or opposition beyond the favorable committee action.
The most likely points of contention are the bill’s broad confidentiality provisions, especially those shielding budget transmittals and cybersecurity communications from public disclosure and limiting their use in litigation or discovery. Another possible area of dispute is the transfer of criminal-justice statistical analysis and data-access authority to the Department of Management, including access to juvenile, child welfare, and criminal-history data, which may raise privacy and agency-control concerns. The contract provisions may also be controversial because they restrict vendor-favored terms and invalidate clauses common in technology procurement, while the new vendor-liability rules attempt to balance state protection with private-sector risk allocation.