Dev Mode. Emulators used.

Select Committee on Federal Administration & Policy Changes 9/10/2026

Publish Date: 9/16/2026
Description:

Agenda: Call to Order; Approval of the Agenda; Public Comment; Welcoming City Data and Privacy Protections - Resolution 32194; Adjournment.

SPEAKER_99

[2s]

Music Plays

SPEAKER_08

[21s]

Good afternoon.

The Select Committee on Federal Administration and Policy Changes Committee meeting will come to order.

It is 2.04 p.m.

Thursday, September 10th.

I'm Alexis Mercedes Rink, Chair of the Committee.

Will the Committee Clerk please call the roll and let the record reflect that Council President Hollingsworth, Council Member Juarez, Council Member Rivera, and Council Member Strauss are excused.

SPEAKER_02

[1s]

Council Member Foster?

SPEAKER_08

[0s]

Here.

SPEAKER_02

[1s]

Vice Chair Kettle?

SPEAKER_03

[0s]

Here.

SPEAKER_02

[1s]

Council Member Lynn?

SPEAKER_04

[0s]

Here.

SPEAKER_02

[1s]

Council member Saka?

SPEAKER_08

[0s]

Here.

SPEAKER_02

[0s]

Chair Rink?

SPEAKER_07

[0s]

Here.

SPEAKER_02

[3s]

Chair, there are five members present and four excused.

SPEAKER_08

[1m31s]

Thank you, clerk.

And we will now move on to approval of today's agenda.

I move to if there is no objection, the agenda is adopted.

Hearing no objection, the agenda is adopted.

Good afternoon, everyone, and welcome to the third Select Committee on Federal Administration and Policy Changes of 2026. We have only one item on today's agenda, a briefing and discussion from the mayor's office, Seattle IT, and the Department of Finance and Administrative Services, also known as FAS.

The executive branch will brief us today on their report from the Welcoming City Data and Privacy Protections Resolution sponsored by Councilmember Foster and voted out of this committee during our March 5th meeting earlier this year.

As a reminder, this resolution was drafted and written at the beginning of this year when our federal regime was in the middle of Operation Metro Search.

We as a council took swift action through our committees, updating ordinances, creating resolutions and working with the mayor's office to protect our immigrant and refugee neighbors.

We know that this fear and the chilling effect was not just limited to the first part of 2026, as we know that Seattle and King County have seen a major uptick in ICE enforcement throughout the summer.

So I want our immigrant and refugee community to know that you are welcome here, that you matter, and we'll continue to stand by you and fight for you.

And with that, we will now open the hybrid public comment period.

Public comments should relate to items on today's agenda within the purview of this committee.

Clerk, how many speakers are signed up for today?

SPEAKER_02

[4s]

Currently, we have zero in-person speakers and one remote speaker.

SPEAKER_08

[9s]

Thank you.

Each speaker will be given two minutes and we will go to our one remote speaker.

Could the clerk please read the public comment instructions?

SPEAKER_02

[38s]

The public comment period is up to 60 minutes.

Speakers will be called in the order in which they are registered.

Speakers will hear a chime when 10 seconds are left of their time.

Speakers mics will be muted if they do not end their comments within the allotted time to allow us to call on the next speaker.

The public comment period is now open and we will begin with the first speaker on the list.

So the first speaker is Hannah Ziff, please press star six.

SPEAKER_04

[1s]

Hi, can you hear me?

SPEAKER_02

[2s]

Yes, you feel free to start.

SPEAKER_04

[58s]

Thank you so much.

I think one of the top issues that the public is focusing on right now is if our privacy will be breached by powerful interests that are based in foreign countries.

So I promote that Seattle's taking steps to protect our privacy.

I also thought it was really interesting that the Fire Department with AMR and their contracts has fines in place in case there are privacy breaches.

It's not only a good way to protect our interests, but it can also generate revenue for the city, and it can also take us more free and at liberty to take risks on these contracts.

If we're protecting our privacy from the get-go, then we wouldn't have to worry about that as much.

Thank you so much for protecting the public interest.

SPEAKER_08

[1m08s]

Thank you, Hannah.

That was our final registered speaker.

And with that, we will now close the public comment period and move on to our items of business.

Now, before we officially move into our first item business regarding Councilmember Foster's data privacy resolution passed earlier this year, I wanted to take a moment to note the number of actions that the city has taken in response.

to actions like we saw in Operation Metro Surge.

Now, while the city of Seattle does not directly control federal immigration policy, what we can do is control our data, our policies, and what we do with our resources.

So I want to thank our city leadership, the mayor, this council, and particularly Councilmember Foster for this resolution, as this resolution requested a review of our city's collection and sharing practices to limit data exposure to the federal government, and that departments incorporate privacy standards into future contracting requirements, and this resulted in a report and presentation now coming before us today.

And with that, I would like to invite Councilmember Foster as the sponsor of this resolution and the report that it's responding to to speak to this.

SPEAKER_00

[3m01s]

Thank you so much, Chair Rink.

I appreciate that and appreciate your leadership.

I will start with saying when I brought this resolution forward earlier this year, it was because we really were seeing the challenge that Seattle residents faced between concern around ICE enforcement and need to make sure that we have access to our city services and also a need and a desire that I know we all share both on City Council in the city departments and in the mayor's office to protect people's privacy.

I wanna express my gratitude to the, I'm looking at the department staff, I wanna express my gratitude to the department staff and FAS and IT for this report, but also to the staff around the city because we wanted to make sure that whether you are in human services or parks or any department in the city that we have the strongest protections for residents and that we're clear that people should be accessing city services and receiving benefits.

So I just want to first start with that gratitude as well as gratitude for the leadership from the mayor's office.

We put forward this resolution and I guess maybe it was a little bit before.

On the same timeline there was also work from the mayor's office with an executive order and I think it's an example of where this council and the departments and the mayor and us as a city are just really united in our desire to make sure that we are protecting our residents and keeping that the priority.

So I will start with that.

And to say this was about, you know, looking beyond our policies on paper and making sure that our compliance is up to date with what our stated values are.

That's why this resolution was so important in terms of looking at data sharing practices, contractor protections, and greater transparency around any potential, excuse me, any potential federal requests.

And Councilman Barink, as you already noted, and as we had a conversation in committee yesterday, that urgency continues.

Our immigrant neighbors continue to be targeted.

We know that data that we have available shows that there were about 700 ICE arrests per month across Washington in June and July, with more than 470 arrests in Seattle, detainments in Seattle, between January and July.

And the majority of these involve people who don't have a criminal record.

And these are, as we talked about yesterday, these are our neighbors, these are our friends, these are our family members, small business owners, this is our community.

And I think it's right for us as council to ensure, as I've said many times before, that we're using every tool at our disposal to protect our neighbors and to make our neighbors feel protected and that they can access services.

So from my vantage point, the work around contracting is particularly important and the resolution intentionally asked us to look at contractors and third party vendors as well as our city practices and I know we'll talk about that in a little bit today with some of the areas that were identified for possible future work.

But just will say, I know this has been a hard time.

It continues to be a really, really hard time.

And we owe it to our residents to do everything we can.

And I think this is an example of us continuing to do that work.

So thank you and thank you, Chair.

SPEAKER_08

[8s]

Thank you, Councilmember Foster.

And with that, we will officially move into our first and only item of business for today.

Will the clerk please read item one to the record?

SPEAKER_02

[8s]

Agenda item one, welcoming city data and privacy protections, resolution 32194 for briefing and discussion.

SPEAKER_08

[43s]

Wonderful.

At this point, I will invite our presenters to come on up to the table and get settled in and colleagues will be at ease just until they get settled in.

Thank you all so much for being here today.

When you're ready, if you can take a moment to introduce yourselves for the record before beginning your presentation, that would be great.

Thank you.

SPEAKER_07

[18s]

Thank you.

Good afternoon, council members.

Rain, council members Zaka and Foster and Kettle.

My name is Christina Pham.

I am with the mayor's office and my role is the executive operations manager to oversee Seattle IT.

And my co-presenters today are...

Hello.

Can you hear me?

SPEAKER_06

[7s]

Okay.

Hi, I'm Sarah Carrier.

I am the manager of the city's privacy program within Seattle IT.

SPEAKER_05

[8s]

Good afternoon.

I'm Selena Chambliss.

I'm a senior policy advisor in our finance and administrative services purchasing and contracting division.

SPEAKER_07

[3m21s]

Thank you again for having us here today.

So while adopting the resolution T2194, we understand that you request the resolution to review of the current and future contractor policy, purchasing and procurement requirements, and to ensure that policy alignment with the Seattle Privacy's principle.

We have been working closely together in partnership across the departments and collectively across the city.

In addition to that above work, the mayor's issued a directive order in January 26th and that is by March 1st of 2026 all departments to complete an inventory of our data collection management and sharing practices to limit the inadvertent disclosure of information to federal immigration's enforcement authority and The goal of that is to ensure that we are putting together departments are putting to submit a proposed plan to implement additional actions to reduce data exposure Limiting the data collections deleting data that has met its legal retention requirements and reviewing data sharing agreement and vendor contracts and also reviewing updating permissions and access control to data stores and All city departments have conducted and complete that review as of March 1st of 2026. In addition, we have been working closely with OIRA, Department of Immigration Affairs 2, making sure that they are staying in touch with community, engaging in response to this topic.

In addition, they have training that is available in Cornerstone to help city departments understand about the immigration enforcement compliance and readiness.

So all of that work has been done leading up to this point.

I do want to take a little bit of time to kind of share the overview of the Seattle IT and the FAS partnership in this space before we go into the PowerPoint presentation.

Seattle Information Technology is responsible for stewardship of the city privacy principles, while the Department of Finance and Administrative Services is responsible for the City of Seattle contractor policy, a citywide consulting contract policy that guides each department.

Working together, the two departments incorporate data use, ownership, privacy, and security, and sharing the requirements and standard of our template language for city contracts.

Seattle IT would review the IT procurements that submit through its technology review process and advise department on compliance with applicable data privacy and protections law and obligations.

Departments remain responsible for their own procurement processes and would follow FAS best practices to stay within compliance.

Seattle IT current privacy and compliance oversight framework would utilize the targeted reviews of contractor compliance and data sharing agreements as needed in lieu of a recurring audit cycle.

In addition, Seattle IT has identified two areas for further policies development formalizing vendor ethics and decision-making standards and addressing supply chain risk where data may be exposed across multiple tiers of vendor and subcontractors over a product's lifecycle.

We are now going to share with you the details of this work through the PowerPoint presentation and I will hand it over to Sarah to kick us off.

SPEAKER_06

[4m58s]

Great, thank you.

I'm just gonna jump right in.

So we're gonna be presenting and discussing today.

Thank you, Christina, for that intro.

We've kind of laid out this presentation and discussion in a way that is hopefully structurally aligned with the resolution response report that Christina was mentioning and addressing topics in the following areas.

So, First, we'll briefly discuss a review of the existing contractor policies and practices and how we approach that through directive support, both on the IT side and as well as the FAS side.

We'll then kind of dive into how we approach on the Seattle IT side verifying compliance with applicable privacy and data protection laws, and then get into some of the additional recommendations to identify how we could close any potential gaps around vulnerabilities that may present themselves around federal government, use of city data for federal enforcement actions.

And finally, I'll hand it over to FAS to talk about the future contracting standards and then questions at the end.

Okay, so first, there are kind of three primary approaches that within Seattle IT we take to ensure we're supporting the terms kind of outlined around ensuring we're in alignment with the city's privacy principles.

The first approach is we need to ensure that our standard contracting terms address issues around privacy, security, and, you know, compliance as well.

So this includes things like data ownership, data use and sharing limitations, data access and security protocols, as well as requirements around potential incident or data breaches.

So one of the actions that we've taken is we ensured that in partnership with FAS that those terms exist in our existing contracts, not only in contracts but also as well as data sharing agreements that may be executed by departments as they enter into agreements with external agencies to the city.

Secondarily, we also developed an internal resource page to help support departments in executing and realizing the provisions outlaid within the directive around providing them resources to trainings that can help support them in how do I change permissions and access controls within standard data stores like SharePoint or OneDrive.

additional training links around data privacy, also providing them a one-stop shop for finding templates, such as the contract language or data sharing agreement templates that have those standard privacy and security provisions, and also resources that support them in making sure that we are being compliant and moving in alignment with our retention and destruction requirements around city records and city data.

so making sure that we have links to the city clerk's office and the retention schedules as a resource for departments to use.

Finally, we ended up partnering with departments on essentially consultation and one-on-one directive support, which is something we actually do in practice.

Many of these things are actually also have been in place for a long time, for many, many years.

but we engaged in consultations with departments on a one-on-one basis to help provide them privacy best practices and how they can apply those practices into their department lines of business or the services that they offer our residents.

So that looked like also things like reviewing existing contracts, specific contracts or data sharing agreements that they had.

And if there were any legal questions around the terms of the agreement, we would direct them to go engage with the city attorney's office as subject matter experts on the legal terms.

But we were there to ensure that all of those privacy and security provisions were in place and buttoned up.

Similarly, if there were questions around, can I get rid of this data?

Can I destroy it?

We first directed folks to go have a conversation with the city clerk's office, the city records management program, to ensure that the appropriate retention schedules were met prior to doing that kind of destruction.

And with that, I will hand it over to FAS.

SPEAKER_05

[1m15s]

Thanks, Sarah.

So on this slide, I will take a moment to highlight the work that FAS has done to support the resolution and the directive and strengthen our privacy protections.

This is work that we've done this year.

One of the things FAS has done is completed a review of all purchasing and contracting policies, procedures, and templates to ensure data and privacy protections are consistently embedded.

FAS does maintain all contracting templates for the city across the city.

We also created a new internal policy that requires FAS to maintain boilerplate language for city contracts that outlines appropriate procedures for responding to information or access requests from federal immigration authorities.

We also made a clear intention to post that public guidance for city contractors on these updates to ensure transparency and consistent practice.

and we commit to continually reviewing contractor policies and practices to make sure they align with the city's privacy principles.

SPEAKER_06

[6m03s]

Okay, yeah, so in terms of how we think about approaching aspects of verifying compliance with applicable privacy and data protection laws, both for ourselves and for our contractors or vendors that we work with at the city, we kind of take a...

a kind of three-tiered approach, which is primarily a risk-based approach, which is a mechanism by which we evaluate technology solutions that we want to procure or use, or projects, right?

And so as part of that procurement pipeline, we have a series of steps that help us along the way in identifying what those kind of compliance requirements would be in alignment with our privacy and security standards that we have at the city.

So first, I can speak to the privacy bit pretty well.

What we do in the privacy space is ensure we have a very clear understanding through our assessment process.

As each technology as requested comes through, it gets a privacy assessment, wherein we look into what are the compliance or regulatory frameworks that apply to this data or the use of this technology?

What are the requirements, if there are regulatory frameworks that apply, around how we protect that data?

who can have access to it.

So we work to develop through this review an established mechanism for understanding at a very high level of detail what are the data processing and sharing requirements that are involved in the use of this technology or project, and also making sure that we are in alignment with each of the six of our city's established privacy principles and the way that we're going to implement and use the technology and the associated data.

So that's on the privacy side.

As part of this procurement process and reviews, there's also a security review.

And the security review helps to ensure that cybersecurity standards are met and in alignment with the requirements set forth in the city's IT security policy.

There is an evaluation of the vendor's cybersecurity posture, which is determined through the process of gathering vendor security documentation, such as data flow diagrams, understanding access control mechanisms, and a verification of audits against external global industry standards as part of that security review process.

And then finally, it goes into contracting and procurement, which we just heard and have talked about, where the standard terms and conditions apply around data privacy, security, ownership, use and sharing limitations, and the like in the city's standard contract terms.

OK.

Now we're going to talk about how we think about some recommendations around, are there any potential vulnerabilities for the data to be used for federal immigration enforcement purposes?

And what are some thoughts about potential recommendations to address any of those potentially identified vulnerabilities?

So something to consider is around establishing some vendor ethics and decision-making standards for the city.

So what this looks like is considering evaluating and defining requirements that really help the city departments support doing business with vendors whose practices align with city values, right?

We know we have a privacy program and privacy principles, but the city has many espoused values.

And so working to define what those thresholds are can help not only with vendor selection, but also drive consistency around decision-making that impacts residents that we serve and the data that they really entrust us with on a daily basis.

Additionally, another thought and consideration, and bear with me because this might get a little IT-y, but putting some thought into how we can collaborate to address supply chain risk.

So when we think about supply chain, we kind of think about all of the components that are present from development, design, build, delivery of a product or service all the way through all the way through until we would use it at the city end, right?

And so if something goes wrong at any point in that linked chain, there's potential there to have exposure around some data protection issues that we may not be expecting or anticipating that could lead to something like unauthorized access, right?

And so I think there's a lot of ways to think about approaching this.

It could look like additional contract requirements, additional vendor requirements for documentation around all of the components that are kind of in their supply chain for the thing that we're trying to purchase or acquire or use so that we have a more robust understanding of the bigger picture of where things could potentially go wrong so that we can preemptively try to address those issues.

That's what I would say in terms of thoughts around recommendations for addressing some potential vulnerabilities.

And I will pass it off to FAS to discuss future contracting.

SPEAKER_05

[57s]

Yeah, so turning to future contracting standards, as mentioned a couple times already, FAS plays a central role in updating city purchasing and contracting policies, so they stay compliant with local, state, and federal laws.

This authority comes from SMC 2060, which just outlines our responsibilities in this space.

We have regular meetings and communications with city departments about updates to policies and procedures.

Recommendation, FAS should continue partnering closely with Seattle IT to ensure contracting policies and procedures remain aligned with data and privacy protections, particularly as technology and regulatory landscapes evolve.

If and when they change, we will update city departments and will also continue to keep vendors updated of major changes as well.

Thank you so much.

I think that is it.

SPEAKER_08

[6s]

Wonderful.

Thank you all so much for the presentation.

I'm going to turn it first over to sponsor of the bill, Councilmember Foster.

SPEAKER_00

[1m09s]

Thank you so much, Councilmember Rank.

I appreciate that.

And I am having a little computer moment here.

Bear with me.

Okay, there we go.

Thank you.

So that was really helpful.

I appreciate that.

And I'll just say again, I appreciate all the hard work that you all do in the departments and the unity that we have as a city around these goals.

I wanted to first ask, and I think you touched on this a little bit in the presentation where you sort of talked about work that had been done to just ensure that there's alignment between the records retention and then what is already being collected through the departments.

But just to drill down on that a little bit more, I'm wondering if there's any examples of information that we've identified that we either no longer need to collect, can reduce our collection on, or just lessen any of those barriers for data collection that you've identified through this process.

SPEAKER_06

[1m17s]

Yeah, so I'm not going to be able to think of any off the top, but those department consultations that we execute on a regular basis where we're helping departments kind of right-size their services, service offerings, business process, practices, et cetera, to make sure they're in alignment with what those principles are and the data minimization principle is what you're speaking to right now.

So that's something that we discuss with them once we understand what the business process is through that consultation process, right?

So kind of our first primary question as part of that consultation or review is, what is the bare minimum data required in order to provide the service you're trying to provide, right?

That we need to collect in order to deliver, right?

And so we kind of start foundationally there and then say, okay, well, if we don't need these other data, they might be a nice to have, but maybe that's not the moment that we collect it, right?

Because there's a certain level of risk there.

So that's kind of what I was speaking to when we talk about thinking through a risk-based approach, right?

So it's in partnership with departments, but if you're asking me specifically, I don't have one exact example off the top, but it's something that we do regularly through the consultation process.

SPEAKER_00

[1m54s]

That's helpful, thank you.

Did anybody else want to speak to that from FAS?

No, okay.

Okay, I think that's helpful and I'm happy to follow up.

I just, I think this is, and I appreciate you giving me two words to describe my longer description.

So the data minimization approach I think feels really important because we know that we should only collect what we need and that sometimes as those needs change over time, maybe there are relics of information that we're collecting because we previously needed it.

And I think for me that was one of the things that was at the core of this is to ensure that we don't collect information that we don't have to collect because then we do have to maintain it and align with all of our public records standards.

So making sure we've got it up correct up front feels really important to me.

So I'm happy to follow up to learn more about the examples where those consultations led to that.

so that it can just inform our ongoing thinking and ongoing partnership.

So thank you for that.

I want to turn now to a little bit around the recommendations.

And so I want to say this was maybe slide Six.

Yeah, so this was really helpful to hear the potential areas for future work.

And so I'm curious, and as I was reading through the report and even looking at the funnels that you provided in the slide deck, which I think are really helpful frameworks, I'm curious when we look at these two opportunities, whether you see those as I would call them maybe little P or big P policy opportunities, given that you said there's a number of things that this could look like, potentially additional contractor requirements, vendor requirements or other pieces, and also understanding that FAS and IT holds a lot inside the department.

So I'm looking to understand a little bit more around the potential levers for these two areas of of additional future work.

SPEAKER_06

[1m56s]

I guess this is my slide, so I'll give it a go.

So I certainly think on the supply chain conversation, that is something that is typically primarily driven from a security standpoint, right?

Because it's addressing vulnerabilities in a chain of software development lifecycle and delivery.

and so I definitely think that none of these things happen in isolation, right?

And so whether you're talking about that or the vendor ethics conversation, I think there's room for partnership and collaboration on what the best approach is.

I would also lean heavily on our cybersecurity folks within the IT department and other OT security folks in the other departments as well who have expertise in kind of supply chain for the systems that they do from an operational technology perspective to say what could this look like to try to address this risk to make sure that we're kind of buttoned up from a security perspective and minimizing the likelihood to the extent that we can to to kind of combat any potential opportunities for unintentional data exposure in that way.

When it comes to the vendor ethics and decision-making standards, I think it could be open.

Again, definitely not something that happens in isolation, but the best results always happen in partnership and collaboration.

So I think that it's certainly, you know, the executive side departments would have a stake in the game too, our partners at FAS specifically or especially.

But I think there's room and open to interpretation about how to approach that, to be honest with you.

I think there are multiple avenues to explore.

SPEAKER_07

[6s]

CTO Acting Smith is on the call and she has some additional information that she can share.

SPEAKER_01

[1m48s]

Hello, thank you for the opportunity to add to what Sarah said.

So basically, in terms of policy, whether it's small P or large P, for vendor ethics and decision-making standards, I think that we would first need to partner with FAS to ensure that our major vendors are collaborating with us to understand our approach.

I do think that that probably has the greatest opportunity for some additional policy or directives as a citywide proposal for the supply chain risk.

This is really something that we have a set of standards that we continue to develop around what supply chain should look like.

And again, in partnership with FAS.

So our standards for supply chain look a little bit different from their standards because they are dealing with more material goods and we're dealing more with software.

But it's easy to understand that supply chain risk when you think about laptops, right?

What are they putting on the laptop before they ship it to the City of Seattle?

How do we ensure that there is no risk or any vulnerabilities introduced into that supply chain from a security perspective, how you extrapolate that into the data concerns to protect our populations, particularly when we're talking about federal enforcement of immigration.

That's where we would look at our software and we would partner with FIS to understand any information or data they were collecting through their supply chains, that would probably be more of an internal departmental policy or set of standards.

So those would be kind of small p, large p that I would suggest.

SPEAKER_00

[54s]

Thank you so much.

That's incredibly helpful, and it gives us a good opportunity, I think, for areas for follow-up.

And I think my overall sort of takeaway from this, from the report in your presentation today, is I was really excited to hear about the department consultations and that work, I look forward to having more conversations to learn about what that unearthed and what we're doing well and what we want to continue to do.

And I also think I see and share the potential future work around the supply chain and also the vendor work.

Because knowing that, again, as I opened, part of my intent with this resolution was making sure that our city practices are really strong.

and that one of our city practices being how we engage with our vendors is also strong.

So I appreciate the identification of that area for future work and I look forward to continuing to collaborate with you all on that.

Thank you.

Thank you, Chair.

SPEAKER_08

[17s]

Thank you, Councilmember Foster.

And thank you again for your leadership on bringing forward this resolution and getting us this good information and huge gratitude again to the team here presenting on this information.

Thank you to each of your teams for preparing this report.

Colleagues, do you have any additional questions on today's presentation?

Vice Chair Kettle.

SPEAKER_03

[4m16s]

Thank you, Chair.

I also want to thank, well, first, thank you everyone who's coming, including Ms. Smith, who's coming virtually.

I think it's important, and I'm noting the parallels.

It's great to have FAS here, and then also the IT side for those parallels, but also Council Member Foster for her work here in this area.

As you know, we passed, I believe, if I got it right, seven bills related to federal law enforcement at the beginning of the year.

Some came out of this committee, some came out of my Public Safety Committee meeting and I think it's important as we go through these slides and to have particularly these two departments represented because it really parallels similar work that we've been doing in the Public Safety Committee.

and that is, you know, in terms of those issues like with technology and so forth, one of the big main areas was contract language and the like.

So I really appreciate FAS and that piece.

I guess IT also would have elements of that as well and then bringing it all together.

obviously for the mayor's team because it's the little things that matter.

And that's why, again, with the various bills that we passed, of which I know I recognize some don't agree with those bills being passed, but they were all passed.

But it's the same mindset.

We were looking to protect the privacy and the civil liberties piece and find that balance with the public safety side of things.

And so I see this parallel effort here, which I think is really important.

And then on the IT side, this is really important in terms of system, the parameters of the system, the protocols, the characteristics, because it's the little things that make a difference in terms of where the information flows and who has access to it.

And again, with the public safety bills that we did with the tech program, we put those in place for those same reasons.

Again, to find that balance between public safety on one side and privacy and civil liberties here.

And so, addressing risk and the like.

By the way, thank you on behalf of Council Member Juarez for putting slide numbers on your slides.

She's not here today, but I'm bringing her out in terms of her noting of the slides.

Like on slide five, you know, highlighting on the IT side these pieces that need to be done is really important.

And so I just want to thank everyone for doing this.

And I just wanted to note that there's almost a standardization in terms of what we need to do as a city, big picture-wise, in terms of leadership and in our role and, you know, as a council to, you know, oversee this and have the oversight.

And might I add, too, thank you for coming, and thank you, Chair, for this subject, because it kind of parallels what we did this week in the Public Safety Committee with Fire Department as it relates to 911, the call center, the nurses' line, the use of AI with 911, because we do have a duty and a responsibility to kind of have the opportunity for this as presented, so then the public knows about it, you know, and it's not a surprise.

It may be a surprise to some, that we do our job to highlight these pieces.

And I think it's important to show the public through Councilmember Foster's work and all my colleagues, Councilmember Saki here too, is to, and I may not forget Councilmember Lynn, who's also checking in remotely, that we have this all being worked and then having the public have the ability.

So thank you for coming and just highlighting because it parallels from a specific topic like what we did this week with the fire department and the 9-1-1, the FACT, the Fire Alarm Center and the Nurses Line and then also the AI piece.

Again, Chair, thank you because, again, from a public awareness perspective, I think it's important to walk through this.

And it also gives me an opportunity to show parallels with the work that we've done in Public Safety Committee, too.

I won't lie.

I did want to take the opportunity to show that.

Thank you.

SPEAKER_08

[1m26s]

MS. Thank you, Vice Chair Kettle.

I appreciate those remarks and good to highlight just to the parallels here and what's going on.

I really appreciate that.

And thank you again.

Colleagues, any additional questions?

Maybe while folks are considering, I'll jump in with just one point here because I really appreciate Councilmember Foster kind of taking us to the the point of where do we go from here and what does the future work look like?

I really appreciate that point.

I wanted to get to that as well.

I wanted to dive into just one point on the executive response and maybe just draw us into a real-world example of what this might look like.

There was a note in the executive response and I'm just going to read a quote from it where it states that departments were also directed to submit a proposed plan to implement additional actions to reduce data exposure, such as limiting data collection, deleting data to meet its legal retention, and reviewing data sharing agreements and vendor contracts, and reviewing and updating permissions and access controls to data stores.

So to translate that into a real-world example, if we look at the Department of Neighborhoods, and they were holding a community event with a sign-in sheet.

Would the sign-in sheet look different as a part of limiting data collection per the proposed plan and do departments get discretion on reducing data exposure or are we really working towards that standardization and to what extent?

SPEAKER_07

[1m42s]

I'll take on, I'll try to answer that.

Thank you, Council Member Rink.

In reality practice, if that is a scenario, the intentions for department to follow the protocol that the executive office put together in the early of this year, we would capture information as a general public in terms of the bulk of who is coming to the event.

but not necessarily in the details of who they are.

In addition to that, we stand by the process, the protocol that we put in place very clear where earlier this year with the directive order that went out, we work with city attorney office in addition with Seattle IT to put together an email where we appoint and the information for the actual event that department would be hosting.

And these are the things that they should do and don't do.

We also ask that, you know, I'm looking at my note here.

We're also asking them that reaching out to privacy and engagement team, if they aren't sure, like talk to us before they're actually asking for selecting the information for their event.

If they're unsure, talk to us and we will route that through our general counsel into city attorney office and working with privacy team in IT to make sure that they have what is equipped for that event.

But again, we are not collecting specific details of our resident, our community.

We're looking for more of a general interest of topic.

You're coming for this purpose.

And so that's how we have been directed departments to do.

Thank you for unpacking that, Christina.

SPEAKER_08

[2s]

Any additional comment to that point?

SPEAKER_06

[53s]

Yeah, no, I mean, I think that's exactly spot on, right?

And this is really where the privacy assessment and evaluation in partnership with departments comes from, which is that outreach that Christina mentioned to say, hey, like, if you have any questions, please come.

We can help identify ways to minimize the data, what the appropriate retention schedule is.

If we don't know it, we're gonna direct you to the city records management program who has the schedules.

and then talk about once we meet those, how can we go about deleting the data that we don't need to retain any longer?

And so it's all kind of part of that process.

And so the privacy principles and meeting those requirements are broad in general and so open to adaptation because the department needs and the services we provide vary vastly, right?

So we have to have some level of standardization, but also the flexibility to work directly with departments for their unique cases, right?

SPEAKER_07

[44s]

I would also add one more actual reality of activity that the mayor's office, the executive team is doing is that we are working in partnership with RRA and hosting the regular meeting that is called Stand Together.

And that is what department has that have external public facing to ensure that they are engaged and stay connected, up to date information and support for one another when it comes to our immigrant community, specifically for that area.

So again, just working with the external public-facing departments to have a way connect back to the executive office and making sure that they know there is a process and protocol and working with us collaboratively.

SPEAKER_08

[19s]

Thank you all.

That's that's really helpful to understand.

I just appreciate that response.

And again, huge appreciation to all for the work on this.

And it sounds like we have some upcoming work as well.

Wonderful.

With that, colleagues, I'm not seeing any additional hands, so I do want to toss it back to the bill sponsor, Councilmember Foster, for last word.

SPEAKER_00

[1m53s]

Thank you so much, Chair.

I appreciate that.

And what I want to say, I think, as we close out is I was sort of thinking about where we see the opportunities to continue working together.

And I think that's important because, and you all have spoken to this already, the landscape around data and privacy is consistently changing.

It feels like we are just in the midst of so much rapid change in that space.

and that part of our role at the city is to make sure that we are keeping pace with that change and that our internal policies and procedures are keeping pace with that.

And so I look forward to partnership on that, and that feels sort of like the bigger picture, you know, you sort of the supply chain component.

But I also think in terms of the questions from Council Member Rink, I think those identify another area of work, right, which is that sort of internal, and I know that this is work that you all are doing day in and day out, to continue to make sure that this, our policies, our practices, our procedures are fully embedded within the city and fully executed to their intent, whether that's from the department director, the division director, or our staff who are the public face of the city who everyone is interacting with on a day-to-day basis.

and so I look forward to continuing to work together on that because I think that's where, those places are really where the impact of this policy is gonna be felt the most by our residents and I think I heard that in your presentation and I also see the opportunities to continue to continue innovating and evolving as the world continues to evolve pretty rapidly in these areas.

I don't want to call this a first step because you guys have obviously been at this for too long to call this a first step, but I think this is a great opportunity for us to continue to work together on the issues identified in this report, so thank you.

SPEAKER_07

[19s]

Well said, Councilmember Foster.

We'll make sure that CTO Smith will also follow up with you on just the recommendations around, you know, how we can minimize the risks and vulnerabilities.

But we also want to take the time to thank you for your time and your partnership.

And again, we do an agreement that we would look forward to working in partnership with you.

Thank you.

Thank you all again.

SPEAKER_06

[10s]

Final word.

Thank you for having us, and thank you for the work.

Just really appreciate the attention.

It's really important, so thank you.

SPEAKER_05

[15s]

Yeah, I would just add again, also thank you for your advocacy in this area.

It's very important to FAS to protect the data of not just the city, but also of our contractors, our subcontractors, and their employees, so thank you very much.

SPEAKER_08

[28s]

Thank you all again.

And with that, I'm going to close out this agenda item and thank our presenters again.

Please take care and we'll be in touch.

Thank you.

And colleagues, we have reached the end of today's agenda.

The next Select Committee on Federal Administration and Policy Changes is scheduled for December 10th, 2026. Is there any business to come before the committee for good of the order?

Hearing and seeing none, we are adjourned.

It is 2.53 p.m.

Thank you all.