Utah
UCPA Compliance Checklist for Businesses (Utah 2026)
Independently fact-checked against primary sources (last audited August 15, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 15, 2026. · 11 primary sources cited on this page. How we verify our legal content

Complying with the Utah Consumer Privacy Act (UCPA) starts with one question: does the law even apply to you? Under Section 13-61-102, a business is covered only if it has annual revenue of $25,000,000 or more AND meets a data-volume threshold, which makes Utah's reach among the narrowest of any state. Businesses that clear the bar must post a privacy notice, offer opt-outs for sale and targeted advertising, provide an opt-out for sensitive data, honor consumer requests within 45 days, and sign processor contracts.
As of 2026, Utah's compliance load is lighter than most states: there are no data protection assessments and no obligation to honor universal opt-out signals. The Utah Attorney General enforces the law under Section 13-61-402, with a permanent 30-day cure period and penalties up to $7,500 per violation.
Jurisdiction scope: This covers Utah's Consumer Privacy Act (Utah Code Title 13, Chapter 61). It is general legal information, not legal advice.
Step 1: Determine whether the UCPA applies to you
The first compliance task is the threshold analysis, because most businesses are not covered. Section 13-61-102(1) applies the UCPA to a controller or processor that conducts business in Utah or targets Utah residents, has "annual revenue of $25,000,000 or more," and satisfies one of two data thresholds: processing personal data of 100,000 or more consumers in a calendar year, or deriving over 50% of gross revenue from the sale of personal data while processing data of 25,000 or more consumers.
The critical structural point is that the revenue requirement is connected to the rest with "and." A business must clear the $25 million floor before any data threshold even matters. If your annual revenue is below $25 million, the UCPA generally does not apply to you, regardless of how many Utah residents' records you hold. That is what makes Utah's coverage among the narrowest in the country, though not the single narrowest by every measure: Florida's Digital Bill of Rights applies only above $1 billion in global revenue paired with a narrow activity test, which reaches an even smaller slice of companies on the revenue axis alone.
One exception to the $25 million floor takes effect January 1, 2027. Section 13-61-102(1)(b), added by Chapter 193 of the 2026 General Session (H.B. 357), brings motor vehicle manufacturers that sell or lease vehicles in Utah and collect, transmit, or store personal data through a vehicle data collection system into the UCPA regardless of revenue. If you manufacture vehicles sold or leased in Utah, do not rely on the revenue floor alone; confirm whether this separate basis covers you starting in 2027.
Run the analysis precisely. Confirm whether you do business in Utah or target Utah residents. Confirm your annual revenue figure. Then test the two data prongs. Many companies that are covered by California, Colorado, or Texas law will find they fall outside the UCPA entirely, which can meaningfully shrink the scope of a multistate privacy program.
Step 2: Confirm you are not categorically exempt
Even above the threshold, Section 13-61-102(2) removes entire categories of organizations and data. Check whether you fit a carve-out before building anything.
Exempt entities include governmental entities and their contractors, tribes, institutions of higher education, nonprofit corporations, HIPAA covered entities, HIPAA business associates, and air carriers. Exempt data includes protected health information under HIPAA, information governed by the Fair Credit Reporting Act, data under the federal Driver's Privacy Protection Act, education records under FERPA, financial data and institutions governed by the Gramm-Leach-Bliley Act under Section 13-61-102(2)(k), and data under the Farm Credit Act.
Employment and emergency-contact data are also excluded under Section 13-61-102(2)(o). If you are partially exempt, for example a company with both a HIPAA-regulated division and a consumer division, apply the UCPA only to the non-exempt data. The statute does not grant a whole-organization pass based on partial overlap, so map your data flows to see which datasets remain in scope.
Step 3: Publish a compliant privacy notice
If you are covered, the privacy notice is the foundational obligation. Section 13-61-302(1)(a) requires a controller to provide consumers with "a reasonably accessible and clear privacy notice" that includes five elements: the categories of personal data processed, the purposes for which those categories are processed, how consumers may exercise a right, the categories of personal data shared with third parties, and the categories of third parties with whom data is shared.
Write the notice in plain language and place it where consumers can find it, typically linked from every page of a website. Keep it current as your data practices change. Because Utah does not require a separate sensitive-data sale notice with mandated statutory wording the way Texas does, the privacy notice and the opt-out disclosures do most of the transparency work under the UCPA.
Make sure the notice explains, in concrete terms, the method a consumer uses to submit a rights request. Section 13-61-202 lets the controller prescribe that method, but the privacy notice is where consumers learn what it is.

Step 4: Build opt-out mechanisms for sale and targeted advertising
If you sell personal data or engage in targeted advertising, you owe consumers a clear way out. Section 13-61-302(1)(b) requires that a controller "clearly and conspicuously disclose to the consumer the manner in which the consumer may exercise the right to opt out" of the sale of personal data or processing for targeted advertising.
In practice this means a visible opt-out link or control, plus a back-end process to actually stop selling that consumer's data or stop targeting ads to them once they opt out. The opt-out right comes from Section 13-61-201(5).
One thing you do not have to build: a universal opt-out signal mechanism. Texas, Colorado, Montana, Oregon, and California require controllers to detect and honor browser- or device-level signals such as Global Privacy Control. The UCPA contains no such requirement. A consumer must use the opt-out method you prescribe; you are not obligated to recognize a global signal. This is one of the places where Utah compliance is genuinely lighter.
Step 5: Set up the sensitive-data opt-out
Utah's sensitive-data rule is the part of the checklist that differs most from other states, so handle it carefully. Section 13-61-302(3) says a controller "may not process sensitive data collected from a consumer without first presenting the consumer with clear notice and an opportunity to opt out of the processing." For a known child, the controller must process the data in accordance with COPPA.
This is an opt-out mechanism, not opt-in consent. You may process sensitive data, but only after you have given clear notice and a real chance to decline. Build a notice-and-opt-out flow that fires before sensitive data is processed, and make the opt-out easy to use. Sensitive data, defined in Section 13-61-101, includes data revealing racial or ethnic origin, religious beliefs, sexual orientation, citizenship or immigration status, and health conditions, plus genetic or biometric data used to identify a person and specific geolocation data accurate within 1,750 feet.
If you previously built opt-in consent flows for Virginia, Colorado, Connecticut, or Texas, you do not need to replicate them for Utah. But do not skip the Utah-specific notice and opt-out, because that is what the statute requires.

Step 6: Wire up consumer-request handling within 45 days
You need an intake and response process for consumer rights requests. Section 13-61-203 requires a controller, within 45 days of receiving a request, to take action and inform the consumer of the action taken. You may extend once by an additional 45 days, up to 90 days total, when reasonably necessary due to complexity or volume, provided you notify the consumer of the extension within the first 45 days.
Build authentication into the flow. Before honoring an access or deletion request, you may verify that the requester is the consumer entitled to make it; if you cannot authenticate using commercially reasonable efforts, you are not required to comply. The first request in any 12-month period must be free under Section 13-61-203(4); you may charge for a second or later request in the same period or decline requests that are excessive, repetitive, technically infeasible, or manifestly unfounded.
Handle the right to correct. HB 418 (2025) amended Section 13-61-201 to add a correction right effective July 1, 2026, and that date has now passed, so the right is in force. Under Section 13-61-201(4), a consumer can request that a controller correct inaccuracies in the consumer's personal data, and covered businesses should process those requests through the same 45-day process described above.
Step 7: Put processor contracts in place
If you use vendors to process personal data, you need contracts that meet the statute. Section 13-61-301(2) requires that, before a processor performs processing on behalf of a controller, the two enter a contract that sets forth instructions for processing, the nature and purpose of the processing, the type of data, the duration, and the parties' rights and obligations.
The contract must also require the processor to ensure each person processing the data is subject to a duty of confidentiality, and to engage any subcontractor under a written contract imposing the same obligations on the subcontractor. Section 13-61-301(1) separately requires the processor to follow the controller's instructions and assist the controller with security and breach-notification obligations.
Review your existing vendor agreements and add UCPA-compliant data processing terms where they are missing. The same data processing addendum you use for other state laws will generally satisfy Utah, since Utah's processor terms track the common multistate pattern.
Step 8: Understand enforcement, the cure period, and penalties
Finally, know how the law is enforced, because it changes your risk calculus. The Division of Consumer Protection takes consumer complaints and investigates under Section 13-61-401; if the director finds reasonable cause that substantial evidence of a violation exists, the director refers the matter to the attorney general. Under Section 13-61-402(1), the Utah Attorney General has "the exclusive authority to enforce this chapter."
Before filing an action, the attorney general must give at least 30 days' written notice identifying each provision allegedly violated. Under Section 13-61-402(3)(b), no action proceeds if the controller or processor cures the noticed violation within 30 days and provides a written statement that the violation has been cured and will not recur. This cure period is permanent. Unlike Colorado and Connecticut, whose cure windows expired, Utah built no sunset into Section 13-61-402, so the cure opportunity remains available indefinitely as of 2026.
If a violation is not cured, the attorney general may recover actual damages to the consumer plus up to $7,500 for each violation under Section 13-61-402(3)(d). Money recovered goes into the Consumer Privacy Account established in Section 13-61-403. There is no private right of action, so the attorney general is the only party that can bring an enforcement claim.
Related guides
- Utah Data Privacy Laws (UCPA hub)
- What Is the UCPA? Utah Consumer Privacy Act Explained
- UCPA Consumer Rights: How to Access, Delete, and Opt Out
- US State Privacy Laws Comparison
- What Is the CCPA? California's Privacy Law Explained
More Utah Laws
Frequently Asked Questions
How do I know if my business has to comply with the UCPA?
Run the Section 13-61-102 test. The UCPA covers you only if you do business in Utah or target Utah residents, have annual revenue of $25,000,000 or more, AND either process data of 100,000+ Utah consumers a year or make over 50% of gross revenue from selling data while processing 25,000+ consumers' data. Because the revenue floor is joined by 'and,' a business under $25 million generally sits outside the law no matter how much data it holds, with one exception: motor vehicle manufacturers become covered under a separate, no-revenue-floor basis starting January 1, 2027 (Section 13-61-102(1)(b)).
What does a UCPA-compliant privacy notice need to include?
Under Section 13-61-302(1)(a), the notice must include the categories of personal data processed, the purposes for processing them, how consumers may exercise a right, the categories of data shared with third parties, and the categories of those third parties. If you sell data or run targeted advertising, Section 13-61-302(1)(b) also requires a clear and conspicuous disclosure of how to opt out.
Does the UCPA require opt-in consent for sensitive data?
No. Utah is the national outlier here. Under Section 13-61-302(3), a controller may process sensitive data after presenting the consumer with clear notice and an opportunity to opt out. Every other comprehensive state law requires opt-in consent. For a known child, you must instead comply with COPPA. Build a notice-and-opt-out flow that runs before sensitive data is processed.
Does the UCPA require data protection assessments?
No. Unlike Colorado, Connecticut, and Texas, the UCPA does not require controllers to perform or document data protection assessments for high-risk processing. This is one of the reasons Utah's compliance burden is lighter than most states. You should still maintain reasonable security practices under Section 13-61-302(2), but no formal assessment documentation is mandated.
Do I have to honor Global Privacy Control or other universal opt-out signals?
No. The UCPA does not require controllers to detect or honor universal opt-out signals such as Global Privacy Control. Texas, Colorado, Montana, Oregon, and California impose that duty, but Utah does not. A Utah consumer must use the opt-out method you prescribe under Section 13-61-202; you are not obligated to recognize a browser- or device-level signal.
How long do I have to respond to a consumer request under the UCPA?
Section 13-61-203 gives you 45 days from receipt to act on a request and inform the consumer. You may extend once by another 45 days (90 days total) when reasonably necessary due to complexity or volume, if you notify the consumer of the extension within the first 45 days. The first request in any 12-month period must be free.
What is the penalty for violating the UCPA?
Under Section 13-61-402(3)(d), the attorney general may recover actual damages to the consumer plus up to $7,500 for each violation. Before suing, the attorney general must give at least 30 days' written notice, and no action proceeds if you cure the violation within 30 days and provide written confirmation. That cure period is permanent, with no sunset date, and there is no private right of action.
Is the UCPA's cure period permanent?
Yes. The 30-day cure opportunity in Section 13-61-402(3) has no expiration date. This differs from states like Colorado and Connecticut, whose cure periods sunset. As of 2026, a Utah business that fixes a noticed violation within 30 days and provides the required written statement avoids enforcement for that violation indefinitely.
Updates
Softened this page's 'narrowest coverage in the country' claim to 'among the narrowest' and added context on Florida's much higher (but differently structured) revenue threshold, and qualified Step 1's revenue-floor rule with the January 1, 2027 exception for motor vehicle manufacturers, who become covered under Utah Code 13-61-102(1)(b) (Chapter 193, 2026 General Session) regardless of revenue.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Corrected an outdated statement that Utah's new right to correct personal-data inaccuracies (added by HB 418, effective July 1, 2026) was 'not yet in force' -- that effective date has passed, and the right is now active under Section 13-61-201(4).
Corrected a miscited UCPA subsection: the opt-out-of-sale/targeted-advertising right is Section 13-61-201(5), not (4), which is the right to correct.
Governing law re-checked for recent changes
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
Utah Code, Title 13: Commerce and Trade
§ 13-61-302Responsibilities of controllers -- Transparency -- Purpose specification and data minimization -- Consent for secondary use -- Security -- Nondiscrimination -- Nonretaliation -- Nonwaiver of consumer rights.In forcecited in 5 of our articles
(1) (a) A controller shall provide consumers with a reasonably accessible and clear privacy notice that includes: (i) the categories of personal data processed by the controller; (ii) the purposes for which the categories of personal data are processed; (iii) how consumers may exercise a right; (iv) the categories of personal data that the controller shares with third parties, if any; and (v) the categories of third parties, if any, with whom the controller shares personal data. (b) If a controller sells a consumer's personal data to one or more third parties or engages in targeted advertising, the controller shall clearly and conspicuously disclose to the consumer the manner in which the consumer may exercise the right to opt out of the: (i) sale of the consumer's personal data; or (ii) processing for targeted advertising. (2) (a) A controller shall establish, implement, and maintain reasonable administrative, technical, and physical data security practices designed to: (i) protect the confidentiality and integrity of personal data; and (ii) reduce reasonably foreseeable risks of harm to consumers relating to the processing of personal data.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at le.utah.gov
Also relied on in: Utah Data Privacy Laws: UCPA Consumer Rights Guide (2026), Utah Biometric Privacy Laws: Collection, Consent & Penalties (2026), UCPA Consumer Rights: Access, Delete & Opt Out (Utah)
§ 13-61-102Applicability.In forcecited in 3 of our articles
(1) This chapter applies to any controller or processor who: (a) (i) conducts business in the state; or (ii) produces a product or service that is targeted to consumers who are residents of the state; (b) has annual revenue of $25,000,000 or more; and (c) satisfies one or more of the following thresholds: (i) during a calendar year, controls or processes personal data of 100,000 or more consumers; or (ii) derives over 50% of the entity's gross revenue from the sale of personal data and controls or processes personal data of 25,000 or more consumers. (2) This chapter does not apply to: (a) a governmental entity or a third party under contract with a governmental entity when the third party is acting on behalf of the governmental entity; (b) a tribe; (c) an institution of higher education; (d) a nonprofit corporation; (e) a covered entity; (f) a business associate; (g) information that meets the definition of: (i) protected health information for purposes of the federal Health Insurance Portability and Accountability Act of 1996, 42 U.S.C. Sec. 1320d et seq., and related regulations; (ii) patient identifying information for purposes of 42 C.F.R.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at le.utah.gov
Also relied on in: What Is the UCPA? Utah Consumer Privacy Act Explained
§ 13-61-203Controller's response to requests.In forcecited in 2 of our articles
(1) Subject to the other provisions of this chapter, a controller shall comply with a consumer's request under Section 13-61-202 to exercise a right. (2) (a) Within 45 days after the day on which a controller receives a request to exercise a right, the controller shall: (i) take action on the consumer's request; and (ii) inform the consumer of any action taken on the consumer's request. (b) The controller may extend once the initial 45-day period by an additional 45 days if reasonably necessary due to the complexity of the request or the volume of the requests received by the controller. (c) If a controller extends the initial 45-day period, before the initial 45-day period expires, the controller shall: (i) inform the consumer of the extension, including the length of the extension; and (ii) provide the reasons the extension is reasonably necessary as described in Subsection (2)(b). (d) The 45-day period does not apply if the controller reasonably suspects the consumer's request is fraudulent and the controller is not able to authenticate the request before the 45-day period expires.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at le.utah.gov
§ 13-61-301Responsibility according to role.In force
(1) A processor shall: (a) adhere to the controller's instructions; and (b) taking into account the nature of the processing and information available to the processor, by appropriate technical and organizational measures, insofar as reasonably practicable, assist the controller in meeting the controller's obligations, including obligations related to the security of processing personal data and notification of a breach of security system described in Section 13-44-202. (2) Before a processor performs processing on behalf of a controller, the processor and controller shall enter into a contract that: (a) clearly sets forth instructions for processing personal data, the nature and purpose of the processing, the type of data subject to processing, the duration of the processing, and the parties' rights and obligations; (b) requires the processor to ensure each person processing personal data is subject to a duty of confidentiality with respect to the personal data; and (c) requires the processor to engage any subcontractor pursuant to a written contract that requires the subcontractor to meet the same obligations as the processor with respect to the personal data.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at le.utah.gov
§ 13-61-402Enforcement powers of the attorney general.In forcecited in 3 of our articles
(1) The attorney general has the exclusive authority to enforce this chapter. (2) Upon referral from the division, the attorney general may initiate an enforcement action against a controller or processor for a violation of this chapter. (3) (a) At least 30 days before the day on which the attorney general initiates an enforcement action against a controller or processor, the attorney general shall provide the controller or processor: (i) written notice identifying each provision of this chapter the attorney general alleges the controller or processor has violated or is violating; and (ii) an explanation of the basis for each allegation. (b) The attorney general may not initiate an action if the controller or processor: (i) cures the noticed violation within 30 days after the day on which the controller or processor receives the written notice described in Subsection (3)(a); and (ii) provides the attorney general an express written statement that: (A) the violation has been cured; and (B) no further violation of the cured violation will occur.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at le.utah.gov
§ 13-61-401Investigative powers of division.In forcecited in 2 of our articles
(1) The division shall establish and administer a system to receive consumer complaints regarding a controller's or processor's alleged violation of this chapter. (2) (a) The division may investigate a consumer complaint to determine whether the controller or processor violated or is violating this chapter. (b) If the director has reasonable cause to believe that substantial evidence exists that a person identified in a consumer complaint is in violation of this chapter, the director shall refer the matter to the attorney general. (c) Upon request, the division shall provide consultation and assistance to the attorney general in enforcing this chapter.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at le.utah.gov
§ 13-61-201Consumer rights -- Access -- Deletion -- Portability -- Opt out of certain processing.In forcecited in 6 of our articles
(1) A consumer has the right to: (a) confirm whether a controller is processing the consumer's personal data; and (b) access the consumer's personal data. (2) A consumer has the right to delete the consumer's personal data that the consumer provided to the controller. (3) A consumer has the right to obtain a copy of the consumer's personal data, that the consumer previously provided to the controller, in a format that: (a) to the extent technically feasible, is portable; (b) to the extent practicable, is readily usable; and (c) allows the consumer to transmit the data to another controller without impediment, where the processing is carried out by automated means. (4) A consumer has the right to request that a controller correct inaccuracies in the consumer's personal data, taking into account the nature of the personal data and the purposes of the processing of the consumer's personal data. (5) A consumer has the right to opt out of the processing of the consumer's personal data for purposes of: (a) targeted advertising; or (b) the sale of personal data. (6) Nothing in this section requires a person to cause a breach of security system as defined in Section 13-44-102.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at le.utah.gov
Also relied on in: How to Request Your Personal Data: US Privacy Rights by State
Explore the law
This article also draws on these acts and chapters (opening at their first section): Utah Code, Title 13: Commerce and Trade § 13-61-101 (Definitions.)
Related law for further reading — not part of this article’s citations.
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- Utah Code Title 13, Chapter 61: Utah Consumer Privacy Act (Full Text)(le.utah.gov).gov
- Utah Code Section 13-61-102: Applicability and Exemptions(le.utah.gov).gov
- Utah Code Section 13-61-201: Consumer Rights(le.utah.gov).gov
- Utah Code Section 13-61-203: Controller's Response to Requests (45-Day Window)(le.utah.gov).gov
- Utah Code Section 13-61-301: Responsibility According to Role (Processor Contracts)(le.utah.gov).gov
- Utah Code Section 13-61-302: Responsibilities of Controllers (Privacy Notice, Sensitive Data Opt-Out)(le.utah.gov).gov
- Utah Code Section 13-61-401: Investigative Powers of the Division of Consumer Protection(le.utah.gov).gov
- Utah Code Section 13-61-402: Enforcement Powers of the Attorney General (30-Day Cure, $7,500 Penalty)(le.utah.gov).gov
- Utah HB 418 (2025): Data Sharing Amendments, Enrolled Bill(le.utah.gov).gov
- Utah Division of Consumer Protection: Utah Consumer Privacy Act (UCPA)(commerce.utah.gov).gov
- Utah H.B. 357 (2026): Amendments to Motor Vehicle Data Privacy, Enrolled Bill (Chapter 193)(le.utah.gov).gov