General data audit trail requirements created for not public data.
Summary
HF398 creates a new general audit-trail requirement for Minnesota government entities handling not public data. Under the bill, the responsible authority must establish procedures so that every action involving not public data—creation, receipt, change, access, sharing, or dissemination—is recorded in an audit trail. The audit trail must capture the date of the action, the identity of the person interacting with the data, and, when applicable, the identity of the sending or receiving government entity or person.
The bill also specifies that the audit-trail records themselves carry the same classification as the underlying data being tracked. It requires retention of the audit trail for at least ten years, or longer if the underlying data is retained under the entity’s approved records retention schedule. The new requirement would take effect August 1, 2025, and it does not replace other audit-trail requirements already found in state law.
Impact
HF398 would amend Minnesota Statutes section 13.05 by adding a statewide baseline requirement for audit logging of not public data across government entities. It would affect records management, data governance, and compliance practices by requiring agencies to document who handled protected data and when, while also extending retention obligations for those logs. Because the audit trail is classified the same as the underlying data, agencies would need to treat these records as protected government data as well.
Sentiment
The available record shows no committee transcript, vote tally, or recorded opposition, so the bill’s sentiment cannot be measured from debate. Based on the bill text and caption, the measure appears to be a technical government-data accountability proposal intended to improve traceability and oversight of sensitive data handling. The absence of recorded votes or discussion suggests there is no documented public controversy in the provided materials.
Contention
No specific points of contention are documented in the provided materials. Potential areas of concern, based on the bill’s requirements, could include the administrative burden on agencies, the cost of implementing and retaining audit logs for at least ten years, and how the new rule interacts with existing data practices and records-retention laws. The bill itself anticipates possible overlap by stating that it does not supersede other audit-trail requirements and that conflicts are to be resolved under existing statutory rules.
Automated license plate reader data restrictions enhanced, data centralized in Bureau of Criminal Apprehension, and use of automated license plate readers by private entities regulated.
Public data classification modified, authorized reimbursement amounts modified, audit amount threshold modified, qualified newspaper publishing notice requirements modified, special district and commission organization provisions modified, and rental licensing provisions modified.