THE WIRE · UPDATED 4:36 PM MDT No story is too small.
Official SourceSalt Lake City

Utah voters ask why private information can’t be removed from Salesforce

Official source This story comes from an official government or institutional source.
A close-up of official government documents with redactions on a dark wooden desk in Salt Lake City, symbolizing data privacy and information control issues within state systems.
Photo via AI illustration
SALT LAKE CITY, Utah — This week, registration information for more than 1 million Utah voters became public unless those voters were approved for at-risk status. The designation is meant to help protect voters who may face safety concerns if their personal information is

Key takeaways

  • Voters seeking at-risk status submitted names, birth dates, addresses, and reasons for privacy concerns via email to the Lt. Gov's Office.
  • The submission process did not notify voters that their emailed forms would be processed through Salesforce.
  • The Utah Lt. Gov's Office uses Salesforce to manage constituent communications and states that security safeguards are in place.
  • There is currently no provided method for voters to request the removal of their data from the Salesforce system once submitted.
  • A state retention policy mandates that correspondence is kept for five years after a governor's term ends before moving to permanent archives.
  • Cybersecurity experts noted that using such systems for sensitive data requires strict access controls, encryption, and disabled exports to prevent identity theft.

SALT LAKE CITY, Utah — This week, registration information for more than 1 million Utah voters became public unless those voters were approved for at-risk status.

The designation is meant to help protect voters who may face safety concerns if their personal information is released publicly. But the KSL Investigators found thousands of voters who submitted at-risk forms to protect their information now have a new concern: They did not realize their information could be routed through a third-party system, and they may not be able to get it removed.

The at-risk form asked voters to provide personal information, including their name, date of birth, address, contact information and the reason they believe they qualify for additional privacy protections.

Email was listed as one way to submit the form to the Utah Lt. Gov's Office. But the form did not say voters who emailed it could have their information held in Salesforce, a third-party, cloud-based customer relationship management system.

The at-risk designation form listed an email address for the Utah Lt. Gov's Office as one way to submit the request. The form did not include a notice that emailed forms could be routed through Salesforce, a third-party system used to manage communication. (Jack Grimm, KSL)

KSL Investigators asked the Lt. Gov's Office whether voters could remove their information after submitting it. In response, the office shared a retention policy for constituent correspondence.

That policy states records are kept for five years after the governor leaves office and are then moved to permanent archives.

A voter trying to stay private

Ever since someone shared her home address online several years ago, Zoe said she has gone above and beyond to protect her privacy, including only sharing her first name with KSL Investigates.

“There’s a lot of hateful folks out there,” she said.

Zoe told KSL Investigates she has gone above and beyond to protect her privacy after her home address was shared online. (Jack Grimm, KSL)

So when Zoe learned her voter information could become public, she quickly filled out the at-risk application.

“Home is sanctuary,” she said.

She included her home address, contact information and the personal reason she believes she is at risk. Then she emailed the form to the Lt. Gov's Office, using an option listed on the form.

About a week later, Zoe said she received an automatic reply.

“I noticed that the sending address was from a company called Salesforce,” she said.

That is when she contacted the KSL Investigators.

Concern over where the information went

Salesforce is often used to track interactions, manage communication and automate workflows. Zoe said she did not realize when she submitted sensitive information it could become part of that system. She now worries about what could be done with her information while it is being held online.

“It wouldn’t be hard for someone to compile a list of at-risk voters who requested this designation,” Zoe said.

At last check, more than 5,400 voters submitted their information through this system.

“That’s kind of frightening,” Zoe said.

What the state says

The Lt. Gov's Office told KSL Investigators it uses Salesforce “to ensure a timely response whenever a constituent sends feedback to the lieutenant governor’s office via email.”

The office said it is “confident in the security” of its constituent services.

In April, the Lt. Gov's Office told KSL the letters voters received instructed them to send forms to their county clerk, and that the office generally forwarded forms it received to the appropriate clerks within a couple of business days.

The office also said it passed forms along as-is, and did not track how many were received by email versus how many were forwarded to counties.

When KSL asked whether voters could now remove their information, the office did not provide a removal process. Instead, it pointed to the retention policy for constituent correspondence.

Cybersecurity experts weigh in

The KSL Investigators consulted two cybersecurity experts regarding Zoe’s concerns, meeting with Kathryn Linford, CEO of Insight IT, and Earl Foote, founder of Nexus IT Consultants.

Neither expert recommended using a system like Salesforce for these submissions unless access was limited and logged, exports were disabled and data was encrypted at all times.

The Lt. Gov's Office said those safeguards are in place.

Foote said those protections matter because of the type of information included on the forms.

“All of those things are things that would be hackers can use for identity theft,” Foote said.

Salesforce would not comment on individual customers, but said security and privacy are top priorities. The company also said it does not acquire ownership rights in customer data or sell it to third parties.

Who qualifies for at-risk status

The at-risk designation is available to certain groups of Utah voters, including victims of domestic violence, people with protection orders, law enforcement officers, members of the armed forces and public figures. People who live with someone who qualifies may also request at-risk status.

For Zoe, the issue comes down to what voters knew before they hit send. She said people who were trying to keep their information private should have been told where that information could go, how long it could be kept and whether it could ever be removed.

“We just need transparency so that we can be assured that we are safe,” Zoe said.

Have you experienced something you think just isn’t right? The KSL Investigators want to help. Submit your tip at investigates@ksl.com or 385-707-6153 so we can get working for you.

This story was adapted from a TV broadcast script using artificial intelligence. Every story, including those adapted with AI, is reviewed by a human editor before publication to ensure that KSL's editorial standards are upheld.

Article details

CategoryOfficial Source
CitySalt Lake City
ToneNeutral