Utah
Utah Data Breach Notification Laws: Reporting Rules & Timelines (2026)

Utah's Protection of Personal Information Act requires businesses to notify affected residents of a data breach in the most expedient time possible and without unreasonable delay. Under Utah Code 13-44-202, there is no fixed-day deadline; the timeline accounts for investigation scope and law enforcement needs.
Utah's data breach notification law is codified as the Protection of Personal Information Act, Utah Code 13-44-101 et seq., and has been in effect since 2006. The law received a significant update in 2024 through Senate Bill 98, effective May 1, 2024, which added new requirements for notifying the Attorney General and the Utah Cyber Center.
Utah's approach to breach notification is distinctive in several ways. The law requires entities to investigate first and notify only if identity theft or fraud is reasonably likely. The timeline uses a "without unreasonable delay" standard rather than a fixed-day deadline. And the penalty structure caps damages at modest levels compared to many other states.
This guide covers the full scope of Utah's breach notification requirements, including how they connect to the broader Utah data privacy laws framework, which also includes the Utah Consumer Privacy Act (UCPA).
Who Must Comply
Utah's law applies to any person who owns or licenses computerized data that includes personal information concerning a Utah resident. The term "person" includes businesses, corporations, partnerships, and other entities. Businesses located outside Utah are subject to the law if they hold data belonging to Utah residents.
Third-Party Data Holders
When a third party maintains data on behalf of another entity, the third party must notify the data owner or licensee of the breach. The data owner then bears the responsibility for investigating and notifying affected residents.
Own Security Policy Exception
An entity that maintains its own notification procedures as part of an information security policy is deemed in compliance with the notification requirements, as long as those procedures are consistent with the timing requirements of the statute.
The Investigation Requirement
Utah stands out from many states by requiring entities to conduct a good faith investigation before triggering notification obligations.
Under Section 13-44-202, when an entity becomes aware of a breach of system security, it must conduct a good faith, reasonable, and prompt investigation to determine the likelihood that personal information has been or will be misused for identity theft or fraud.
Notification is required only if the investigation reveals that misuse of personal information for identity theft or fraud has occurred or is reasonably likely. This risk-based approach means not every breach automatically requires notification. If an entity determines through its investigation that misuse is unlikely, it may not be required to notify.
What Constitutes a Breach
Under Section 13-44-102, a "breach of system security" means an unauthorized acquisition of computerized data maintained by a person that compromises the security, confidentiality, or integrity of personal information.
The definition focuses on acquisition, not just access. Unauthorized access without actual acquisition of the data may not trigger the investigation obligation.
Encryption Safe Harbor
If personal information was encrypted or protected by another method that renders the data unreadable or unusable, the breach notification requirements do not apply. Utah does not specify a particular encryption standard (unlike some states that require FIPS 140-2 or 128-bit encryption).
Personal Information That Triggers the Law
Under Section 13-44-102, personal information means a person's first name or first initial and last name, combined with any one or more of the following data elements, when either the name or data element is unencrypted or not protected by another method that renders the data unreadable or unusable:
- Social Security number
- Financial account number, or credit or debit card number, combined with any required security code, access code, or password that would permit access to the account
- Driver's license number or state identification card number
What Utah's Law Does Not Cover
Utah's definition is relatively narrow. It does not include:
- Medical or health information
- Health insurance identification numbers
- Biometric data
- Email credentials (usernames with passwords)
- Passport numbers
- Taxpayer identification numbers (other than SSNs)
Personal information does not include information contained in federal, state, or local government records or in widely distributed media that are lawfully made available to the general public.
Notification Timeline

Utah requires notification in the most expedient time possible without unreasonable delay, considering:
- Legitimate investigative needs of law enforcement
- The time needed to determine the scope of the breach
- The time needed to restore the reasonable integrity of the system
There is no fixed-day deadline. This gives entities some flexibility but also means compliance depends on what is "reasonable" under the circumstances.
Law Enforcement Delay
Notification may be delayed if a law enforcement agency determines that notification will impede a criminal investigation. Notification must proceed once law enforcement indicates it will no longer compromise the investigation.
Who Must Be Notified
Affected Individuals
Every Utah resident whose personal information was, or is reasonably believed to have been, misused or reasonably likely to be misused for identity theft or fraud must receive notification.
Attorney General and Utah Cyber Center (500+ Threshold)

Under the 2024 amendments added by SB 98, when a breach affects 500 or more Utah residents, the entity must also notify:
The notification must include: the date the breach occurred, the date it was discovered, the total number of people affected (including the number of Utah residents), the type of personal information involved, and a short description of the breach.
Documents submitted to the AG or Cyber Center may be classified as protected records under certain circumstances, providing confidentiality protections during the investigation.
Consumer Reporting Agencies (1,000+ Threshold)
When the investigation reveals that misuse of personal information relating to 1,000 or more Utah residents has occurred or is reasonably likely to occur, the entity must also notify each consumer reporting agency that compiles and maintains files on consumers on a nationwide basis, as defined in 15 U.S.C. Section 1681a.
Methods of Notification
Utah permits several notification methods:
- Written notice sent by first-class mail
- Electronic notice, if the entity's primary method of communication with the resident is electronic
- Telephone notice, including through the use of automatic dialing technology
Substitute Notice
Utah also provides for notice by publishing in a newspaper of general circulation. This is available when other methods of notification are impractical.
Penalties and Enforcement

Civil Penalties
Under Section 13-44-301, a person who violates the statute is subject to:
- Up to $2,500 per consumer for a violation or series of violations concerning a specific consumer
- Up to $100,000 in the aggregate for related violations concerning more than one consumer
The $100,000 cap can be exceeded if the violations concern 10,000 or more consumers who are Utah residents and 10,000 or more consumers who are residents of other states, or if the person agrees to settle for a greater amount.
Attorney General Enforcement
Only the Attorney General can enforce the statute. The AG may seek:
- Civil penalties as outlined above
- Injunctive relief to prevent future violations
- Attorney's fees and costs
No Private Right of Action
Utah's breach notification law does not create a private right of action. Individuals cannot sue under this statute. They may pursue claims under other legal theories such as negligence, but not under the Protection of Personal Information Act itself.
Connection to the Utah Consumer Privacy Act
The Utah Consumer Privacy Act (UCPA), effective December 31, 2023, is a separate comprehensive privacy law that governs how businesses collect and use personal data. UCPA does not replace or modify the breach notification requirements of Chapter 44. The two laws operate independently:
- Chapter 44 governs what happens when personal information is compromised in a breach
- UCPA governs the collection, use, and sharing of personal data in the ordinary course of business
Businesses that handle Utah consumer data should ensure compliance with both statutes.
This article provides general legal information about Utah data privacy laws and breach notification requirements. It is not legal advice, and it does not create an attorney-client relationship. Data breach response involves time-sensitive obligations. Consult a qualified attorney licensed in Utah for guidance specific to your situation.
More Utah Laws
Frequently Asked Questions
How quickly must a business notify Utah residents after a data breach?
Utah requires notification in the most expedient time possible without unreasonable delay. There is no fixed-day deadline like the 30, 45, or 60 days many other states impose. The timeline must account for legitimate law enforcement needs, the time to determine the breach scope, and the time to restore system integrity.
Does Utah require Attorney General notification for data breaches?
Yes, as of May 2024. Senate Bill 98 added a requirement to notify the Attorney General and the Utah Cyber Center when a breach affects 500 or more Utah residents. The notification must include the breach date, discovery date, total affected individuals, type of personal information, and a description of the breach.
What are the penalties for failing to notify about a data breach in Utah?
Civil penalties are capped at $2,500 per consumer and $100,000 in the aggregate for related violations. The aggregate cap can be exceeded in cases involving 10,000 or more consumers in both Utah and other states, or if the parties agree to a higher settlement. Only the Attorney General can enforce the law.
Must businesses investigate before sending breach notification in Utah?
Yes. Utah requires entities to conduct a good faith, reasonable, and prompt investigation upon becoming aware of a breach. Notification is required only if the investigation reveals that personal information has been or is reasonably likely to be misused for identity theft or fraud. This risk-based approach distinguishes Utah from states that require notification for any unauthorized acquisition.
Does Utah's breach notification law cover medical or health information?
No. Utah's personal information definition only covers SSNs, financial account numbers with security codes, and driver's license or state ID numbers. Medical information, health insurance data, biometric data, and email credentials are not covered under the breach notification statute.
Affected by a data breach or biometric privacy violation?
If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.
Updates
Governing law re-checked for recent changes
Corrected a claim that Utah's breach notification law does not require notifying consumer reporting agencies; Section 13-44-202(1)(d) requires it once a breach affects 1,000 or more Utah residents.
Governing law re-checked for recent changes
The Law Behind This Article
This article rests on 3 statutory provisions held in our own legal record, each retrieved from the official source. Tap a section to read the operative text.
Utah Code, Title 13: Commerce and Trade
§ 13-44-102Definitions.In forcecited in 2 of our articles
As used in this chapter: (1) (a) "Breach of system security" means an unauthorized acquisition of computerized data maintained by a person that compromises the security, confidentiality, or integrity of personal information. (b) "Breach of system security" does not include the acquisition of personal information by an employee or agent of the person possessing unencrypted computerized data unless the personal information is used for an unlawful purpose or disclosed in an unauthorized manner. (2) "Consumer" means a natural person. (3) "Financial institution" means the same as that term is defined in 15 U.S.C. Sec. 6809.
Official text (excerpt) · as of 2026-07-29 · Read the full section at le.utah.gov
Also relied on in: Utah Data Privacy Laws: UCPA Consumer Rights Guide (2026)
§ 13-44-202Personal information -- Disclosure of system security breach.In forcecited in 2 of our articles
(1) (a) A person who owns or licenses computerized data that includes personal information concerning a Utah resident shall, when the person becomes aware of a breach of system security, conduct in good faith a reasonable and prompt investigation to determine the likelihood that personal information has been or will be misused for identity theft or fraud purposes. (b) If an investigation under Subsection (1)(a) reveals that the misuse of personal information for identity theft or fraud purposes has occurred, or is reasonably likely to occur, the person shall provide notification to each affected Utah resident. (c) If an investigation under Subsection (1)(a) reveals that the misuse of personal information relating to 500 or more Utah residents, for identity theft or fraud purposes, has occurred or is reasonably likely to occur, the person shall, in addition to the notification required in Subsection (1)(b), provide notification to: (i) the Office of the Attorney General; and (ii) the Utah Cyber Center created in Section 63A-16-1102.
Official text (excerpt) · as of 2026-07-29 · Read the full section at le.utah.gov
§ 13-44-301Enforcement -- Confidentiality agreement -- Penalties.In forcecited in 2 of our articles
(1) The attorney general may enforce this chapter's provisions. (2) (a) Nothing in this chapter creates a private right of action. (b) Nothing in this chapter affects any private right of action existing under other law, including contract or tort. (3) A person who violates this chapter's provisions is subject to a civil penalty of: (a) no greater than $2,500 for a violation or series of violations concerning a specific consumer; and (b) no greater than $100,000 in the aggregate for related violations concerning more than one consumer, unless: (i) the violations concern: (A) 10,000 or more consumers who are residents of the state; and (B) 10,000 or more consumers who are residents of other states; or (ii) the person agrees to settle for a greater amount. (4) (a) In addition to the penalties provided in Subsection (3), the attorney general may seek, in an action brought under this chapter: (i) injunctive relief to prevent future violations of this chapter; and (ii) attorney fees and costs.
Official text (excerpt) · as of 2026-07-29 · Read the full section at le.utah.gov
Search our full record of US law — 1.79 million sections, every state + federal →
Sources and References
- Utah Code 13-44-202 - Disclosure of System Security Breach(le.utah.gov).gov
- Utah Code 13-44-301 - Enforcement(le.utah.gov).gov
- Senate Bill 98 (2024) - Online Data Security and Privacy Amendments(le.utah.gov).gov
- Utah Cyber Center - Report a Breach(cybercenter.utah.gov).gov
- Utah Code 13-44-102 - Definitions(law.justia.com)