For each personal information system, the information owner shall determine the level of access required for an employee of the secretary of state to fulfill their job duties, consistent with paragraph (C) of this rule. Prior to providing an employee with access to confidential personal information within a personal information system, both the information owner and the employee's supervisor shall grant approval. The information owner shall revise an employee's access to confidential personal information upon a change to that employee's job duties if appropriate. Whenever an employee's job duties no longer require access to confidential personal information in a personal information system, the information owner shall remove the employee's access to confidential personal information .
Upon the signed written request of any individual for a list of confidential personal information about the individual maintained by the agency, the agency shall do all of the following:
The secretary of state director shall designate an employee of the secretary of state to serve as the data privacy point of contact. The data privacy point of contact shall work with the chief privacy officer within the office of information technology to assist the secretary of state with both the implementation of privacy protections for the confidential personal information that the secretary of state maintains and compliance with section 1347.15 of the Revised Code and the rules adopted thereunder.
The following federal statutes or regulations or state statutes and administrative rules make personal information maintained by the secretary of state confidential :
Ohio Admin. Code 111-1-02
Five Year Review (FYR) Dates: 1/10/2022 and 03/15/2027
Promulgated Under: 119.03
Statutory Authority: 149.43, 1347.15
Rule Amplifies: 1347.15
Prior Effective Dates: 03/31/2014, 01/25/2016