Utah
What Is the UCPA? Utah Consumer Privacy Act Explained
Independently fact-checked against primary sources (last audited August 15, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 15, 2026. · 9 primary sources cited on this page. How we verify our legal content

The Utah Consumer Privacy Act (UCPA) is Utah's comprehensive consumer data privacy law, codified at Utah Code Title 13, Chapter 61. The chapter currently runs from Section 13-61-101 through Section 13-61-404, and a new motor vehicle privacy part extends it through Section 13-61-504 on January 1, 2027. Enacted as SB 227 and signed by Governor Spencer Cox on March 24, 2022, it took effect December 31, 2023, and gives Utah residents rights over their personal data while imposing one of the narrowest coverage thresholds of any state privacy law in the country.
As of 2026, the Utah Attorney General holds exclusive authority to enforce the UCPA under Section 13-61-402, with civil penalties up to $7,500 per violation. A 30-day cure period applies before any action, and unlike several other states that let their cure windows expire, Utah's cure period has no sunset date.
Jurisdiction scope: This covers Utah's Consumer Privacy Act (Utah Code Title 13, Chapter 61). It is general legal information, not legal advice.
What the UCPA is: statute, enactment, and effective dates
The Utah Consumer Privacy Act is Utah's first comprehensive consumer data privacy law. It is codified at Utah Code Title 13, Chapter 61, running from Section 13-61-101 (definitions) through Section 13-61-404 (the attorney general report). The legislature passed it as Senate Bill 227 during the 2022 General Session, and Governor Spencer Cox signed it on March 24, 2022.
The statute took effect December 31, 2023, giving covered businesses roughly twenty months to prepare. That made Utah the fourth state, after California, Virginia, and Colorado, to enact a broad consumer privacy law. The chapter is enacted by "Chapter 462, 2022 General Session," the citation that appears at the end of each original section.
Utah's law sits in the Virginia and Colorado lineage rather than the California one. It uses the controller and processor vocabulary of those statutes, and it grants a familiar set of consumer rights. What makes the UCPA stand apart is not its structure but how far it pulls back the lever on coverage and on the duties it imposes. On nearly every contested design choice, Utah chose the most business-friendly path available.
Who the UCPA covers: the $25M AND-gated threshold
The applicability test in Section 13-61-102(1) is the single most important feature of the UCPA, because it is among the narrowest in the United States. The law applies to a controller or processor that meets all of these conditions at once.
First, the entity must conduct business in Utah or produce a product or service targeted to Utah residents. Second, under Section 13-61-102(1)(b), it must have "annual revenue of $25,000,000 or more." Third, under Section 13-61-102(1)(c), it must satisfy one of two data thresholds: during a calendar year it "controls or processes personal data of 100,000 or more consumers," or it "derives over 50% of the entity's gross revenue from the sale of personal data and controls or processes personal data of 25,000 or more consumers." Those subsection letters change on January 1, 2027: the 2026 amendment discussed below renumbers this whole test into Subsection (1)(a), so the revenue floor becomes (1)(a)(ii) and the data-volume thresholds become (1)(a)(iii).
The structure is what matters. The $25 million revenue requirement is joined to the rest by the word "and," not "or." A company must clear the revenue floor and then also hit a data-volume threshold. This is fundamentally different from California, where the thresholds are alternatives.
Under California's CCPA, a for-profit business is covered if it meets any one of three tests: more than $25 million in annual gross revenue, the data of 100,000 or more California consumers or households, or 50% or more of revenue from selling or sharing personal information. A small data broker with $5 million in revenue that handles 200,000 Californians is covered by the CCPA. The same broker is not covered by the UCPA, because it never clears Utah's $25 million floor. By tying the revenue requirement to the data thresholds with an "and," Utah excludes every business below $25 million in revenue, no matter how much data it processes.
The practical upshot: a large share of mid-size companies that fall within California's, Colorado's, or Texas's reach owe no obligations under the UCPA at all. Utah's coverage is among the most limited of any state privacy law as of 2026, though not the single narrowest by every measure. Florida's Digital Bill of Rights applies only to controllers with more than $1 billion in global gross annual revenue that also engage in a narrow set of activities, such as deriving most of their revenue from online advertising, which by itself reaches an even smaller slice of companies on the revenue axis, even though Florida's law is narrow through a different mechanism than Utah's AND-gated revenue-plus-data-volume test.
A change is also coming to the applicability test itself. H.B. 357, enacted as Chapter 193 of the 2026 General Session, takes effect January 1, 2027 and restructures Section 13-61-102(1). On that date the existing controller-and-processor test is renumbered into Subsection (1)(a)(i) through (1)(a)(iii), which is why the (1)(b) and (1)(c) citations above are correct today but will point elsewhere in 2027. A new Subsection (1)(b) is then added for "a motor vehicle manufacturer who" both "manufactures motor vehicles that are sold or leased in the state" and "collects, transmits, or stores personal data through a vehicle data collection system."
That new subsection is a second, independent basis for coverage, and it carries no revenue floor at all. A manufacturer meeting that description is covered whether or not it clears the $25 million threshold that gates the rest of the chapter. It reaches only motor vehicle manufacturers, and H.B. 357 pairs it with a new set of substantive duties in Part 5, described below.

Categorical exemptions under Section 13-61-102(2)
Even among businesses that clear the threshold, Section 13-61-102(2) removes whole categories of organizations and data from the law's reach. These exemptions are entity-based and data-based, and they track the pattern set by other state laws.
On the entity side, the UCPA does not apply to a governmental entity or a third party acting on its behalf, a tribe, an institution of higher education, a nonprofit corporation, a HIPAA covered entity, a HIPAA business associate, or an air carrier. The nonprofit and higher-education exemptions are notable because some newer state laws have narrowed or eliminated them; Utah keeps both as full carve-outs.
On the data side, Section 13-61-102(2) excludes protected health information under HIPAA, patient identifying information under 42 C.F.R. Part 2, human-subjects research data, information governed by the Fair Credit Reporting Act, financial data and institutions governed by the Gramm-Leach-Bliley Act under Section 13-61-102(2)(k), data under the federal Driver's Privacy Protection Act, education records under FERPA, and data under the Farm Credit Act. Employment data and emergency-contact data are also carved out under Section 13-61-102(2)(o), and personal data processed for purely personal or household purposes is excluded under Section 13-61-102(2)(p).
These carve-outs mean that hospitals, banks, credit unions, universities, charities, and state agencies generally operate outside the UCPA even when they hold large volumes of Utah-resident data. A covered entity that processes a patient's protected health information in accordance with HIPAA is exempt as to that data, though it remains bound by HIPAA itself.
The opt-out sensitive-data model: Utah's signature difference
The clearest way Utah departs from every other state is how it treats sensitive data. Under Section 13-61-302(3), a controller "may not process sensitive data collected from a consumer without first presenting the consumer with clear notice and an opportunity to opt out of the processing." For a known child, the controller must process the data in accordance with COPPA.
That is an opt-out model. Every other comprehensive state privacy law, including Virginia, Colorado, Connecticut, and Texas, requires opt-in consent before a controller may process sensitive data. Under those laws, sensitive data cannot be processed unless the consumer first affirmatively agrees. Utah flips the default: a controller may process sensitive data and simply give the consumer notice and a chance to say no.
Sensitive data is defined in Section 13-61-101 and includes personal data revealing racial or ethnic origin, religious beliefs, sexual orientation, citizenship or immigration status, or medical history and health conditions, along with genetic or biometric data processed to identify a specific individual and specific geolocation data accurate within 1,750 feet. Because Utah uses an opt-out gate for all of these categories, businesses face a lighter consent burden in Utah than anywhere else.
This single design choice, more than any other, is why the UCPA is widely described as the most business-friendly comprehensive privacy law in the country.
The lighter compliance load: no assessments, no universal opt-out
Two duties that have become standard elsewhere are simply absent from the UCPA. First, the law contains no data protection assessment requirement. Colorado, Connecticut, Texas, and others require controllers to document risk assessments for high-risk processing such as targeted advertising, data sales, and certain profiling. Utah imposes no such obligation, so a covered Utah controller does not have to prepare or retain these assessments.
Second, the UCPA does not require controllers to honor a universal opt-out mechanism. Texas, Colorado, Montana, Oregon, and California all require covered businesses to recognize browser- or device-level opt-out signals such as Global Privacy Control. Utah's opt-out rights in Section 13-61-201 must be exercised by the consumer through whatever method the controller prescribes under Section 13-61-202; there is no statutory command to detect or honor a global signal.
The consumer-rights set is also trimmer than the national norm. As enacted, Section 13-61-201 grants the right to confirm and access, to delete data the consumer provided, to obtain a portable copy, and to opt out of targeted advertising and the sale of personal data. There is no right to opt out of profiling, and there was no right to correct inaccurate data, a gap that made Utah the only early comprehensive state law without a correction right.

The right to correct under HB 418
That correction gap has closed. HB 418, enacted in the 2025 General Session, amended Section 13-61-201 to add a right to correct. The revised statute, which carries the "Amended by Chapter 468, 2025 General Session" citation, gives a consumer "the right to request that a controller correct inaccuracies in the consumer's personal data, taking into account the nature of the personal data and the purposes of the processing."
The timing has passed. HB 418's amendment to Section 13-61-201 took effect July 1, 2026, and the correction right is now in force. Utah consumers can demand correction of inaccurate data under the UCPA, and businesses are expected to have a correction workflow in place.
The correction right sits alongside the existing rights and is handled through the same 45-day response window in Section 13-61-203. It does not add a profiling opt-out or a universal opt-out duty; the rest of Utah's narrow framework remains intact.
Part 5: in-vehicle privacy controls for model year 2030 vehicles
The same 2026 bill did more than widen the applicability test. H.B. 357 also enacted a new Part 5, Motor Vehicle Data Privacy, at Sections 13-61-501 through 13-61-504. Like the applicability change, it takes effect January 1, 2027.
The core duty sits in Section 13-61-502(1). For a motor vehicle with a model year 2030 or later, a manufacturer must provide in-vehicle privacy controls that allow a consumer to view the categories of personal data the vehicle data collection system collects, view the categories of third parties the manufacturer shares personal data with, opt out of the sale of personal data or processing for targeted advertising, and delete readily accessible data. Section 13-61-501(3) defines readily accessible data narrowly: data the consumer directly inputs into or provides to the vehicle from a connected device through the in-vehicle interface, and that is stored locally on the vehicle.
The controls have to live in the vehicle itself. Under Section 13-61-502(3) they must be accessible through the in-vehicle interface, accessible to any individual operating the vehicle, and clearly labeled and easy to locate. A manufacturer may also offer the same controls through a website or mobile application under Section 13-61-502(5), but it may not require a consumer to use one to exercise these rights. Settings a consumer selects remain in effect until the consumer changes them.
Two limits keep the part narrow. Section 13-61-502(2) excuses a manufacturer from the control requirement for a specific model if it demonstrates that the model is not technologically capable of providing them. And Section 13-61-503 exempts minimum-necessary data collected solely for internal product improvement, along with data a vehicle data collection system collects solely for vehicle safety, vehicle operation, or compliance with federal or state law, from the consent requirements of Section 13-61-302.
One deadline is firm. Under Section 13-61-502(6), a manufacturer that receives a court order requiring deletion, or a request that includes a copy of a legally issued protective order, must delete all personal data within five business days of receiving it. Section 13-61-504 directs the Motor Vehicle Division to publish information about these rights on its website.
UCPA vs. CCPA: the key differences
Utah's law and California's CCPA are frequently compared by companies operating nationally. Our state data privacy law comparison page covers the full multistate picture, but three distinctions between the UCPA and California's CCPA matter most.
Coverage threshold. The CCPA uses three alternative tests joined by "or," so a business is covered if it meets any one. The UCPA joins its $25 million revenue floor to its data thresholds with "and," so a business must clear both. That single conjunction makes Utah's net far smaller. Many companies covered by the CCPA owe nothing under the UCPA.
Sensitive data. California requires businesses to let consumers limit the use of sensitive personal information, and other states require opt-in consent. Utah alone uses an opt-out gate under Section 13-61-302(3): notice plus an opportunity to decline. This is the lightest sensitive-data standard among comprehensive state laws.
Enforcement and remedies. California retains a limited private right of action for certain data breaches, allowing statutory damages between $100 and $750 per consumer per incident. The UCPA has no private right of action of any kind. Under Section 13-61-402(1), the Utah Attorney General has "the exclusive authority to enforce this chapter," and consumers cannot sue covered businesses directly.
Related guides
- Utah Data Privacy Laws (UCPA hub)
- UCPA Consumer Rights: How to Access, Delete, and Opt Out
- UCPA Compliance Checklist for Businesses
- US State Privacy Laws Comparison
- What Is the CCPA? California's Privacy Law Explained
More Utah Laws
Frequently Asked Questions
What is the UCPA?
The UCPA, or Utah Consumer Privacy Act, is Utah's comprehensive consumer data privacy law, codified at Utah Code Title 13, Chapter 61, running from Section 13-61-101 through Section 13-61-404 and extending through Section 13-61-504 when a new motor vehicle privacy part takes effect January 1, 2027. It was enacted as SB 227, signed by Governor Spencer Cox on March 24, 2022, and took effect December 31, 2023. It gives Utah residents rights over their personal data and is widely regarded as the most business-friendly comprehensive state privacy law in the United States.
When did the UCPA take effect?
The UCPA took effect on December 31, 2023, after being signed into law on March 24, 2022. A later amendment, HB 418 from the 2025 General Session, added a right to correct inaccurate data effective July 1, 2026. That correction right is now in force.
Who does the UCPA apply to?
Under Section 13-61-102, the UCPA applies to a controller or processor that does business in Utah or targets Utah residents, has annual revenue of $25,000,000 or more, and either processes data of 100,000 or more Utah consumers a year or derives over 50% of gross revenue from selling personal data while processing data of 25,000 or more consumers. The $25 million revenue requirement is joined by 'and,' which makes Utah's coverage among the narrowest of any state privacy law. A separate basis that carries no revenue floor applies to motor vehicle manufacturers starting January 1, 2027 under Section 13-61-102(1)(b); on that date the controller-and-processor test described above is renumbered into Subsection (1)(a).
Why is Utah's privacy law considered one of the narrowest in the country?
Because Section 13-61-102 links the $25 million revenue floor to the data-volume thresholds with the word 'and' rather than 'or.' A business must clear both. In California and most other states the thresholds are alternatives, so a high-volume data company under $25 million in revenue is still covered. In Utah it is not, so far fewer businesses fall within the UCPA's reach. Florida's Digital Bill of Rights sets an even higher revenue bar, over $1 billion, paired with a narrow activity test, so the two laws are narrow in different ways rather than Utah being the single narrowest by every measure.
What entities are exempt from the UCPA?
Section 13-61-102(2) exempts governmental entities, tribes, institutions of higher education, nonprofit corporations, HIPAA covered entities and business associates, GLBA-covered financial institutions, and air carriers. It also excludes data governed by HIPAA, the Fair Credit Reporting Act, FERPA, the Driver's Privacy Protection Act, and the Farm Credit Act, along with most employment data and purely personal or household processing.
How does the UCPA treat sensitive data differently from other states?
The UCPA uses an opt-out model. Under Section 13-61-302(3), a controller may process sensitive data after presenting the consumer with clear notice and an opportunity to opt out. Every other comprehensive state law requires opt-in consent before processing sensitive data. For a known child, the controller must comply with COPPA. This opt-out standard is Utah's signature difference and the main reason the law is considered the most business-friendly.
Does the UCPA require data protection assessments or universal opt-out signals?
No to both. Unlike Colorado, Connecticut, and Texas, the UCPA does not require controllers to perform or document data protection assessments. And unlike Texas, Colorado, Montana, Oregon, and California, it does not require controllers to honor universal opt-out signals such as Global Privacy Control. These omissions make Utah's compliance load lighter than nearly every other state.
How is the UCPA different from the CCPA?
Three main differences. Coverage: the CCPA's three thresholds are alternatives ('or'), while the UCPA joins its $25 million revenue floor to its data thresholds with 'and,' covering far fewer businesses. Sensitive data: California and other states require opt-in or use limitation, while Utah uses an opt-out gate under Section 13-61-302(3). Remedies: the CCPA has a limited private right of action for data breaches, while the UCPA has none and is enforced exclusively by the Utah Attorney General under Section 13-61-402.
What do Utah's 2027 motor vehicle data privacy rules require?
H.B. 357, Chapter 193 of the 2026 General Session, takes effect January 1, 2027. It adds motor vehicle manufacturers that sell or lease vehicles in Utah and collect, transmit, or store personal data through a vehicle data collection system as a coverage basis under Section 13-61-102(1)(b), with no revenue floor. It also enacts Part 5, Sections 13-61-501 through 13-61-504. Under Section 13-61-502(1), for model year 2030 and later vehicles a manufacturer must provide in-vehicle privacy controls that let a consumer view the categories of data collected, view the categories of third parties it shares data with, opt out of sale and targeted advertising, and delete readily accessible data. Under Section 13-61-502(6) it must delete all personal data within five business days of a court order or a request that includes a legally issued protective order.
Updates
Corrected and expanded the coverage of Utah H.B. 357 (Chapter 193, 2026 General Session), which on January 1, 2027 renumbers the Section 13-61-102 applicability test, adds motor vehicle manufacturers as a coverage basis with no revenue floor, and enacts a new Part 5 requiring in-vehicle privacy controls on model year 2030 and later vehicles.
Softened this page's 'narrowest coverage in the country' claim to 'among the narrowest' and added context on Florida's much higher (but differently structured) revenue threshold, and added a note that Utah Code 13-61-102 gains a separate, no-revenue-floor coverage basis for motor vehicle manufacturers effective January 1, 2027 (Chapter 193, 2026 General Session).
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Corrected the subsection citations for the UCPA's $25 million revenue floor and data-volume thresholds (Section 13-61-102(1)(b) and (1)(c), not (1)(a)(ii)/(1)(a)(iii)).
Updated the HB 418 correction-right coverage (KeyTakeaways, the 'Forthcoming' section, and one FAQ answer) to reflect that the July 1, 2026 effective date has passed and the right is now in force, matching the sibling ucpa-consumer-rights page's linked current statute text.
Governing law re-checked for recent changes
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
Utah Code, Title 13: Commerce and Trade
§ 13-61-201Consumer rights -- Access -- Deletion -- Portability -- Opt out of certain processing.In forcecited in 4 of our articles
(1) A consumer has the right to: (a) confirm whether a controller is processing the consumer's personal data; and (b) access the consumer's personal data. (2) A consumer has the right to delete the consumer's personal data that the consumer provided to the controller. (3) A consumer has the right to obtain a copy of the consumer's personal data, that the consumer previously provided to the controller, in a format that: (a) to the extent technically feasible, is portable; (b) to the extent practicable, is readily usable; and (c) allows the consumer to transmit the data to another controller without impediment, where the processing is carried out by automated means. (4) A consumer has the right to request that a controller correct inaccuracies in the consumer's personal data, taking into account the nature of the personal data and the purposes of the processing of the consumer's personal data. (5) A consumer has the right to opt out of the processing of the consumer's personal data for purposes of: (a) targeted advertising; or (b) the sale of personal data. (6) Nothing in this section requires a person to cause a breach of security system as defined in Section 13-44-102.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at le.utah.gov
Also relied on in: UCPA Compliance Checklist for Businesses (Utah 2026), UCPA Consumer Rights: Access, Delete & Opt Out (Utah), Utah Data Privacy Laws: UCPA Consumer Rights Guide (2026)
§ 13-61-102Applicability.In forcecited in 3 of our articles
(1) This chapter applies to any controller or processor who: (a) (i) conducts business in the state; or (ii) produces a product or service that is targeted to consumers who are residents of the state; (b) has annual revenue of $25,000,000 or more; and (c) satisfies one or more of the following thresholds: (i) during a calendar year, controls or processes personal data of 100,000 or more consumers; or (ii) derives over 50% of the entity's gross revenue from the sale of personal data and controls or processes personal data of 25,000 or more consumers. (2) This chapter does not apply to: (a) a governmental entity or a third party under contract with a governmental entity when the third party is acting on behalf of the governmental entity; (b) a tribe; (c) an institution of higher education; (d) a nonprofit corporation; (e) a covered entity; (f) a business associate; (g) information that meets the definition of: (i) protected health information for purposes of the federal Health Insurance Portability and Accountability Act of 1996, 42 U.S.C. Sec. 1320d et seq., and related regulations; (ii) patient identifying information for purposes of 42 C.F.R.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at le.utah.gov
§ 13-61-302Responsibilities of controllers -- Transparency -- Purpose specification and data minimization -- Consent for secondary use -- Security -- Nondiscrimination -- Nonretaliation -- Nonwaiver of consumer rights.In forcecited in 5 of our articles
(1) (a) A controller shall provide consumers with a reasonably accessible and clear privacy notice that includes: (i) the categories of personal data processed by the controller; (ii) the purposes for which the categories of personal data are processed; (iii) how consumers may exercise a right; (iv) the categories of personal data that the controller shares with third parties, if any; and (v) the categories of third parties, if any, with whom the controller shares personal data. (b) If a controller sells a consumer's personal data to one or more third parties or engages in targeted advertising, the controller shall clearly and conspicuously disclose to the consumer the manner in which the consumer may exercise the right to opt out of the: (i) sale of the consumer's personal data; or (ii) processing for targeted advertising. (2) (a) A controller shall establish, implement, and maintain reasonable administrative, technical, and physical data security practices designed to: (i) protect the confidentiality and integrity of personal data; and (ii) reduce reasonably foreseeable risks of harm to consumers relating to the processing of personal data.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at le.utah.gov
Also relied on in: Utah Biometric Privacy Laws: Collection, Consent & Penalties (2026)
§ 13-61-402Enforcement powers of the attorney general.In forcecited in 3 of our articles
(1) The attorney general has the exclusive authority to enforce this chapter. (2) Upon referral from the division, the attorney general may initiate an enforcement action against a controller or processor for a violation of this chapter. (3) (a) At least 30 days before the day on which the attorney general initiates an enforcement action against a controller or processor, the attorney general shall provide the controller or processor: (i) written notice identifying each provision of this chapter the attorney general alleges the controller or processor has violated or is violating; and (ii) an explanation of the basis for each allegation. (b) The attorney general may not initiate an action if the controller or processor: (i) cures the noticed violation within 30 days after the day on which the controller or processor receives the written notice described in Subsection (3)(a); and (ii) provides the attorney general an express written statement that: (A) the violation has been cured; and (B) no further violation of the cured violation will occur.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at le.utah.gov
§ 13-61-101Definitions.In forcecited in 7 of our articles
As used in this chapter: (1) "Account" means the Consumer Privacy Restricted Account established in Section 13-61-403. (2) "Affiliate" means an entity that: (a) controls, is controlled by, or is under common control with another entity; or (b) shares common branding with another entity. (3) "Aggregated data" means information that relates to a group or category of consumers: (a) from which individual consumer identities have been removed; and (b) that is not linked or reasonably linkable to any consumer. (4) "Air carrier" means the same as that term is defined in 49 U.S.C. Sec. 40102. (5) "Authenticate" means to use reasonable means to determine that a consumer's request to exercise the rights described in Section 13-61-201 is made by the consumer who is entitled to exercise those rights. (6) (a) "Biometric data" means data generated by automatic measurements of an individual's unique biological characteristics.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at le.utah.gov
Also relied on in: Utah Employee Monitoring Laws: Workplace Surveillance and Social Media (2026), Utah Smart Glasses Recording Laws (2026)
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- Utah Code Title 13, Chapter 61: Utah Consumer Privacy Act (Full Text)(le.utah.gov).gov
- Utah Code Section 13-61-101: Definitions(le.utah.gov).gov
- Utah Code Section 13-61-102: Applicability and Exemptions(le.utah.gov).gov
- Utah Code Section 13-61-302: Responsibilities of Controllers (Sensitive Data Opt-Out)(le.utah.gov).gov
- Utah Code Section 13-61-402: Enforcement Powers of the Attorney General(le.utah.gov).gov
- Utah HB 418 (2025): Data Sharing Amendments, Enrolled Bill(le.utah.gov).gov
- Utah Division of Consumer Protection: Utah Consumer Privacy Act (UCPA)(commerce.utah.gov).gov
- Utah Senate Bill 227 (2022): Consumer Privacy Act, Enrolled Bill(le.utah.gov).gov
- Utah H.B. 357 (2026): Amendments to Motor Vehicle Data Privacy, Enrolled Bill (Chapter 193)(le.utah.gov).gov
- Utah H.B. 357 (2026), Enrolled Copy: Amendments to Motor Vehicle Data Privacy (full bill text)(le.utah.gov)
- Utah Code Section 13-61-502: Motor Vehicle Manufacturer Requirements (effective 1/1/2027)(le.utah.gov)
- Utah Code Section 13-61-501: Definitions, Motor Vehicle Data Privacy (effective 1/1/2027)(le.utah.gov)
- Utah Code Section 13-61-503: Exemptions for Motor Vehicle Manufacturers (effective 1/1/2027)(le.utah.gov)