Information Governance Policy Requirements for State Governments
State agencies must align records, security, and transparency rules that often conflict.

Information governance in state government is a layered system covering how data gets collected, classified, protected, used, and eventually destroyed across the full life of an agency's work, and it rests on five pillars that lean on each other whether anyone planned it that way or not.
Here's a distinction that trips up agency staff early: there's a real gap between voluntary standards and legally enforceable rules. Voluntary standards are the "nice to have" version, an ISO framework you adopt because a consultant told you to. Legally enforceable regulations carry fines, corrective orders, and sometimes jail time (more on that later, because New Jersey does not fool around on this one), and state agencies also sit in a messier spot than most private companies, since they answer to federal baselines, state statutes, and increasingly local rules, all at once, often pointing in slightly different directions.
The five pillars structuring this piece are records management, cybersecurity and risk governance, open records and transparency, privacy regulation, and the newest arrival, AI governance. Treat these as five separate programs run by five separate teams and you end up in trouble fast. A gap in records management doesn't stay contained; it shows up six months later as a blown open records deadline, or a security audit that can't say where sensitive data actually lives.
Records management as the foundational layer every other pillar rests on
Everything else here depends on an agency knowing what records it actually has. Sounds obvious, and it's also the part most agencies get wrong.
Both state and federal law dictate what records must be kept and for how long, and when the two conflict, agencies satisfy whichever requirement is stricter. That's the rule, not a suggestion. California's State Records Management Act, codified in Government Code sections 12270 through 12279, governs executive branch agencies and gets put into practice through State Administrative Manual Chapter 1600. New York spreads the obligation across several statutes at once: the Freedom of Information Law, the Open Meetings Law, the Personal Privacy Protection Law, and Part 188 of 8NYCRR, which spells out what a records management officer does and how disposition procedures work.
None of that matters without an inventory first. Agencies need to know what records they hold, where those records live, how much volume they're dealing with, and how the records get used, before anyone builds a retention schedule. Skip the inventory and jump straight to a schedule, and you're writing a budget without checking your bank balance; the numbers might look fine on paper, but they won't survive contact with reality.
The retention schedule itself formalizes what's called the agency's "normal course of doing business," a legal concept with real teeth. No record gets destroyed without an approved Records Disposition Schedule, and destroying something without that approval is a violation on its own, whether or not the destroyed record ever turns out to matter. Add the statute of limitations problem on top: records that could become relevant to litigation need to be held at minimum for the applicable limitations period, and that period shifts depending on the type of claim. The retention clock isn't one clock; it's several, ticking at different speeds, for different reasons.
Then there's the question of what even counts as a record, which used to be simple and isn't now. In nearly every jurisdiction, anything produced, held, transmitted, or reproduced with or for a government body counts as a record, regardless of its physical form. Wisconsin's guidance says it plainly: content posted to social media on behalf of a government authority is a record subject to public records requests if it relates to government business. That tweet from the state agriculture department about crop insurance deadlines is technically a record, which means agencies using social platforms for public communication need an actual preservation and retrieval policy, not just a content calendar.
Get any of this wrong and the consequences range from fines to civil liability to losing government contracts or licenses, depending on the state.
How open records laws turn internal records management into a public-facing obligation
Every state has its own public records statute, and most arrived after the federal FOIA set the template. But the names alone tell you these laws didn't grow up together: some states call it FOIA, others FOIL, still others Right to Know, Sunshine Law, or Open Records. Different name, different mechanics, often wildly different consequences for getting it wrong.
States diverge on the details that matter most in practice. How much time does an agency get to respond to a request? Which branches of government does the law even cover? What exemptions exist for sensitive categories of records, and what fee structures, with what waivers, apply? Those questions have different answers depending on which state you're standing in, and an agency operating across state lines, or running a federally funded program with public records exposure in multiple states, has to track all of it at once.
The penalty structure is where things get genuinely interesting. Some states cap the fine for a first offense at a fairly modest amount, while others set per-occurrence minimums that stack up fast for an agency with a pattern of noncompliance, turning a paperwork problem into a real budget line. New Jersey's Open Public Records Act stands out because it allows for jail time for repeat offenders, an unusually blunt instrument for what is, on its face, a records administration issue. That's the legislature signaling, about as unsubtly as possible, that obstruction won't get filed away as a clerical error.
Because each state passes its own version of this law, there's no central enforcement body and no unified national standard sitting above all of it. Agencies working across state lines, or under federal program requirements layered on top of state law, navigate a patchwork rather than a single rulebook.
Open records compliance depends entirely on records being findable, retrievable, and correctly classified at the agency level, long before a request lands on anyone's desk, and no legal department can substitute for that groundwork after the fact. That findability has to extend to electronic records too, and response timelines apply just as much to email threads and database entries as they do to a paper file in a cabinet, which means an agency's digital housekeeping is now a matter of legal exposure, not just IT hygiene.
Cybersecurity governance requirements that agencies must implement, not just adopt
Older state security frameworks focused mostly on technical controls: encryption, access controls, network segmentation, the usual toolkit. The newer wave cares more about governance, risk management, and who's accountable when something goes wrong. That's a meaningful shift, because a firewall doesn't fail an audit; a lack of documented accountability does.
The state-by-state landscape varies in structure but rhymes in substance. Arizona's P8000 Information Security Policy Series covers security, privacy, and supply-chain risk across every state agency, with the P8120 policy defining the statewide program each agency has to stand up on its own. California runs its requirements through the SIMM 5300 series. Florida's Cybersecurity Act, under section 282.318, mandates governance, operational, and oversight standards aligned to the NIST Cybersecurity Framework, and the companion Local Government Cybersecurity Act, section 282.3185, extends similar obligations down to counties and municipalities. Virginia sets minimum baseline requirements through SEC530. Pennsylvania does it differently, assigning enterprise-wide IT governance, including policy development itself, to the Office of Administration under Executive Order 2016-06.
None of that replaces the federal layer; it stacks on top of it. Agencies receiving federal funding or running federal programs still have to meet NIST SP 800-53 and FISMA standards regardless of what the state framework says, which means "compliant with state law" and "compliant, period" aren't always the same thing.
Role clarity is where a lot of these frameworks live or die. Data Owners sit at the senior level and are accountable for classification decisions, access authorization, and making sure data use lines up with actual business goals. Data Stewards handle the operational side: metadata, data quality monitoring, enforcing classification day to day. Data Custodians handle the technical implementation side, working with the systems and controls that support data storage and access. Skip defining any one of these roles and you get a security program that looks fine in a slide deck and falls apart the moment an incident response team needs to know who's actually authorized to make a call.
Here's the quiet problem nobody puts in a press release: most states haven't backed these cybersecurity mandates with dedicated budget line items. Writing the policy is one thing; funding it is a separate legislative fight, and plenty of states haven't finished that fight yet, which leaves a structural weak spot no amount of good policy language can patch over. The federal State and Local Cybersecurity Grant Program, created under the 2021 Infrastructure Investment and Jobs Act, closes some of that gap, and it's aimed mostly at local governments, which tend to have the least mature security posture of the bunch. It's a start, but only that.
For agency leaders, the takeaway is plain: a policy framework needs roles that are defined, programs that are funded, and procedures written down well enough to survive an auditor asking uncomfortable questions.
Privacy regulation as a cross-cutting requirement that touches every other pillar
Privacy doesn't show up in state government as one clean statute you can point to. It builds up, piece by piece, from several directions at once. New York's Personal Privacy Protection Law restricts arbitrary collection of personal data, gives citizens the right to access and correct their own records, and regulates how agencies disclose information. Layer federal sector-specific laws on top, HIPAA for health records, FERPA for education records, and you get requirements that apply no matter what state law says, setting a floor agencies can't drop below regardless of how permissive the state framework happens to be.
This is where privacy and records management start intersecting whether anyone planned it or not. Agencies classify records by sensitivity as part of the inventory process, because that classification determines the retention period, who gets access, and whether the record qualifies for an open records exemption. Get the classification wrong and you've either disclosed something you shouldn't have, or withheld something the law says the public is entitled to see. Neither mistake looks good in a headline.
Data minimization runs as a common thread through nearly every privacy framework: don't collect personal data beyond what a defined purpose actually requires. Simple principle, and it carries real downstream consequences for how databases get built and how records schedules get set, since you can't retain data you never should have collected in the first place.
The role overlap deserves a mention too. Data Owners and Data Stewards, the same people responsible for classification and quality under the cybersecurity pillar, carry privacy responsibilities as well; their job descriptions overlap heavily with what a dedicated privacy officer would do at a larger organization. OMB's M-19-23 pushes agencies toward a data governance body chaired by the Chief Data Officer, and that body has to coordinate with privacy and security functions directly, or accountability starts splitting across departments that technically report on the same data but never talk to each other about it.
This is where the whole system gets hard to run off a checklist. Open records law pushes agencies toward disclosure; privacy law pushes the opposite way, toward protection. Agencies make judgment calls at that exact intersection constantly, often under time pressure, and getting it wrong in either direction creates liability. Too much disclosure violates privacy law, and too little violates open records law. What agencies actually need is a documented decision framework for handling requests that touch personal data, so the answer doesn't depend on which staff member happens to be on duty that day.
AI governance requirements taking shape across state legislatures and executive offices
The legislative activity here isn't subtle. In 2025, lawmakers introduced noticeably more bills targeting public sector AI use than in 2024, spanning a wide cross-section of states with genuine bipartisan support, and a share of those bills actually became law. This issue skipped its slow-simmer phase entirely.
State legislatures are mostly circling two concerns. First: how agencies use AI in decisions that directly affect residents, things like benefits eligibility, licensing, law enforcement. Second: the privacy of the administrative data feeding those AI systems in the first place, because a model is only as trustworthy as the data pipeline behind it.
Utah is the example everyone points to, and for good reason. The state created a Center of Excellence in AI back in 2018, years before generative AI became a dinner-table topic. It had an enterprise generative AI policy in place by 2023, and launched a dedicated Office of AI Policy in 2024. That timeline matters more than any single policy document Utah produced, because it shows governance infrastructure for AI takes years of groundwork, well beyond a memo circulated once and considered finished.
Agencies elsewhere now face the same requirements Utah worked through over the better part of a decade, compressed into a much shorter runway. There's the AI system inventory, which is really the records inventory problem wearing a different hat: you can't govern what you haven't counted. There's risk assessment before deploying AI in any high-stakes decision. There are transparency obligations showing up in some frameworks that require agencies to disclose when AI played a role in a decision affecting someone's life. And there's data provenance, meaning agencies need to actually know what data trained or currently feeds a given system, which sounds simple until you try to trace it backward through three vendor contracts and a legacy database nobody's touched since 2015.
NASCIO's numbers tell the bigger story. For the first time, AI rose to the top of state CIO priorities heading into 2026, displacing cybersecurity, which had held that spot for well over a decade. That's not a small shift, and it signals AI governance moved from an emerging concern to an operational mandate that state technology leadership now treats as urgent.
The gap most agencies live in right now: AI governance policies get written faster than the infrastructure needed to support them, roles, audit mechanisms, training programs, procurement controls, can actually get built. Writing the policy is the easy part; standing up the machinery behind it is where the real work sits.
How the five pillars connect in practice and what agencies need to act on first
By now the connections should be visible rather than asserted. A poor records inventory makes open records compliance slower and riskier, because you can't produce what you can't find. Undefined data classification makes cybersecurity controls nearly impossible to apply with precision, since you can't protect data at the right sensitivity level if nobody agreed on what that level is. Privacy obligations determine which records can be disclosed at all, and shape how AI systems get to use agency data in the first place. And AI systems, in turn, generate new records that fall right back under all four of the other pillars.
Governance structure has to exist before any of this policy language becomes real. Defined roles, Data Owners, Data Stewards, a Chief Data Officer, a CISO, need to be in place before consistent implementation is even possible. Oregon's IT Governance Committee model and OMB's CDO-chaired governance body under M-19-23 offer two different structural templates worth studying, not because either is a perfect blueprint, but because both show what accountability looks like when it has an actual name attached to it.
For agencies taking stock of where they stand, the sequencing matters. Start with the records inventory; it surfaces the entire data landscape every other pillar depends on, and skipping it just delays the reckoning. From there, map current retention schedules against digital and social media records, which is where most of the gaps show up these days. Audit who actually holds the Data Owner and Data Steward roles on paper versus who's doing the work in practice, because accountability gaps there undermine everything built on top. Run a policy-to-budget check on cybersecurity specifically, since a framework without funded implementation behind it is a pattern showing up across most states right now. And treat AI governance as a live requirement today, given how fast the legislative trend line is moving.
There's a production problem tucked inside all of this that rarely gets named directly. Agencies have to document, communicate, and update these policies continuously: internal governance documents, training materials, public disclosure notices, legislative reporting, all of it needs to stay accurate and consistent, at a pace that outstrips what a lot of agencies can manage using the same content processes they relied on a decade ago.
Good information governance calls for defined ownership, regular updates, and enough institutional capacity to actually produce the documentation that makes the governance real instead of aspirational, sustained well past the point of a single completed checklist. Miss that, and you've got five pillars holding up a roof that was never actually bolted to any of them.


