Utah Consumer Privacy Act (UCPA)
· About Utah Consumer Privacy Act (UCPA)
Key Takeaways
- The Utah Consumer Privacy Act (UCPA) applies to certain controllers and processors that do business in Utah or target Utah residents, and it gives Utah consumers rights to access, delete, and opt out of targeted advertising, sale, and certain profiling. The Utah Legislature’s current code also reflects a 2026 amendment adding a right to correct inaccuracies, effective 1 July 2026.[8][14]
- The UCPA is enforced through the Utah Division of Consumer Protection and the Utah Attorney General, with a mandatory notice-and-cure structure that has governed enforcement since the law took effect on 31 December 2023.[13][15]
- A controller that meets the statutory thresholds must respond to consumer requests within 45 days, provide a privacy notice, conduct data protection assessments for certain processing, and flow down processor obligations through contract terms.[13][15]
- The original UCPA imposed a comparatively narrow private- and public-enforcement model, but the state’s 2025 review reported limited enforcement activity and described the required referral process before litigation.[15]
- A 2026 motor-vehicle privacy amendment was enacted separately from the core consumer privacy law and is reflected in Utah Code materials with a 1 January 2027 effective date for the new motor vehicle data privacy part.[2][12]
What It Is
The UCPA is Utah’s comprehensive consumer privacy law, codified in Utah Code Title 13, Chapter 61, that regulates how covered businesses collect, use, share, and disclose personal data of Utah consumers.[12][13] It is administered at the state level by the Division of Consumer Protection, with enforcement authority ultimately vested in the Attorney General.[13][15]
The law was enacted in 2022, became effective on 31 December 2023, and its statutory applicability provisions took effect on 31 December 2023 as well.[14][13] Utah’s code now also shows a 2026 amendment to the definitions section with an effective date of 5 May 2026 and a superseding date of 1 January 2027, reflecting later legislative changes, including the 2026 motor vehicle privacy package.[8][12]
A notable 2025 amendment added the consumer right to correct inaccurate personal data, with an effective date of 1 July 2026.[1][8] This is a meaningful post-enactment expansion because the original UCPA did not include correction as a consumer right.
Who Must Comply
The UCPA applies to a controller that conducts business in Utah or produces a product or service targeted to Utah residents, and that either has annual revenue of at least $25 million or satisfies one of the statutory data-volume thresholds.[14][13] The thresholds focus on the amount of Utah consumer data processed, including numbers of consumers and percentages of revenue tied to data sales or processing.
The law has exterritorial effect in practice because it reaches covered businesses outside Utah if they target Utah residents and meet the thresholds.[14] It is not limited to Utah-incorporated companies.
The UCPA exempts certain entities and data types, including data governed by other sectoral regimes and certain public and employment contexts as defined in the statute.[14][13] The statute also excludes government entities and applies more narrowly than the most expansive state privacy laws.
Processors are not directly subject to the full consumer-rights framework in the same way controllers are, but they must act under contract and follow controller instructions, including security and confidentiality requirements.[13]
Core Requirements
- Provide a compliant privacy notice. Covered controllers must disclose the categories of personal data processed, the purpose of processing, how consumers can exercise rights, the categories of data shared, and whether the business sells data or engages in targeted advertising.[13]
- Honor consumer rights requests. Controllers must provide access, deletion, and opt-out rights, and as of the 2026 amendment, correction rights for inaccurate personal data; requests must be answered within 45 days, subject to a possible extension.[1][13]
- Publish and honor an opt-out mechanism. Controllers must allow consumers to opt out of targeted advertising, sale of personal data, and certain profiling decisions with legal or similarly significant effects.[13]
- Limit processing to disclosed purposes. Controllers must avoid processing personal data for purposes that are neither reasonably necessary to, nor compatible with, the purposes disclosed in the privacy notice without obtaining consent or another valid legal basis under the statute.[13]
- Conduct data protection assessments for high-risk processing. Controllers must assess processing that presents a heightened risk, including targeted advertising, sale of personal data, certain profiling, and processing sensitive data.[13]
- Use written contracts with processors. Controller-processor contracts must include confidentiality, deletion or return, audit/support, and security obligations, and the processor may act only on documented instructions.[13]
- Implement reasonable security. The UCPA requires businesses to maintain reasonable administrative, technical, and physical safeguards appropriate to the volume and nature of the personal data they control.[13]
Deadlines and Penalties
| milestone | date | what applies | |---|---:|---| | UCPA effective date | 31 December 2023 | Core consumer privacy obligations and enforcement framework begin to apply.[14] | | Right to correct becomes effective | 1 July 2026 | Consumers gain the statutory right to correct inaccurate personal data.[1][8] | | Motor vehicle privacy amendments effective | 1 January 2027 | New motor-vehicle data privacy provisions take effect.[2][12] |
The UCPA is enforced by the Utah Attorney General after referral through the Division of Consumer Protection, and the statute includes a 30-day cure period before an enforcement action may proceed.[15] The cure window is central to the law’s practical penalty model.
Maximum civil penalties are generally governed by Utah’s consumer protection enforcement provisions and can reach $7,500 per violation under the state’s enforcement framework, with injunctive relief and other equitable remedies also available.[15] The 2025 legislative review also described the state’s process as requiring a Division investigation and a subsequent Attorney General cure notice before litigation.[15]
How to Comply
- Map data and define roles. Identify whether the organization is a controller, processor, or both, and document Utah consumer data flows, sharing partners, retention, and purposes.
- Build a rights-request workflow. Create intake, identity-verification, legal-review, and fulfillment procedures for access, deletion, correction, and opt-out requests, with a documented 45-day SLA.
- Update notices and preference tooling. Publish a UCPA-specific privacy notice and implement an opt-out mechanism for sale, targeted advertising, and covered profiling.
- Run and document risk assessments. Use a formal assessment method aligned with NIST CSF 2.0 for governance and risk management, and map high-risk processing to documented criteria and approvals.
- Harden security controls. Implement a security program consistent with ISO 27001 controls for access management, logging, incident response, vendor oversight, encryption, and asset inventory.
- Operationalize AI and automated decisioning governance. Where profiling or AI-supported decisions are in scope, align lifecycle controls with ISO 42001 for policy, accountability, human oversight, testing, and review.
- Contract and monitor vendors. Refresh processor agreements, due-diligence questionnaires, and audit rights to ensure processors only act on documented instructions and maintain equivalent safeguards.
- Test cure-ready compliance. Maintain evidence packs for notices, assessments, training, request logs, and security controls so the business can respond quickly if the Attorney General issues a cure notice.
Related Regulations
The California Consumer Privacy Act/CPRA is the closest peer law and is broader in several areas, especially in rulemaking detail and consumer-rights infrastructure, so multistate programs often use it as the highest common denominator.
The Colorado Privacy Act overlaps heavily on rights, assessment obligations, and opt-outs, but its enforcement and rule structure differ, so one control set may not satisfy both states without state-specific tuning.
The Virginia Consumer Data Protection Act is similar in scope and controller/processor architecture, but Utah’s framework is generally narrower and historically less prescriptive on certain operational details.
The Federal Trade Commission Act can overlap where privacy practices are unfair or deceptive, meaning a company can face federal enforcement even when it is technically compliant with state privacy law.
The Children’s Online Privacy Protection Act may conflict or overlap for child-directed services because COPPA governs children under 13 and imposes separate notice, consent, and retention rules.
FAQ
Does the UCPA apply to companies outside Utah?
Yes, if the company conducts business in Utah or targets Utah residents and meets the statutory thresholds.[14] Physical presence in Utah is not required. The law is designed to reach out-of-state businesses that serve Utah consumers.
Does the UCPA now include a right to correct personal data?
Yes. Utah’s 2025 amendment added a consumer right to correct inaccurate personal data, and the change became effective on 1 July 2026.[1][8] Controllers should update request workflows, verification standards, and recordkeeping to reflect that right.
Does the UCPA require a Data Protection Impact Assessment?
Yes, for certain higher-risk activities such as targeted advertising, sale of personal data, sensitive-data processing, and specific profiling uses.[13] The assessment should document the benefits, risks, safeguards, and whether the processing is reasonably necessary and proportionate.
Does the UCPA have a private right of action?
No private right of action is provided in the statute’s consumer privacy framework; enforcement runs through state authorities.[15] That means litigation exposure under the UCPA is primarily public enforcement, although other laws may still create private claims.
Does a business need a privacy notice even if it does not sell data?
Yes. The notice requirement applies broadly to covered controllers, not only to businesses that sell data.[13] The notice must still explain categories processed, purposes, rights, and how consumers can submit requests.
Did the 2026 motor-vehicle privacy amendment change the main UCPA deadlines?
No, it is a separate set of vehicle-specific amendments that are reflected in Utah code with a 1 January 2027 effective date for that part.[2][12] The core UCPA deadlines, including the 2026 correction right, remain distinct from that vehicle package.
Sources
- Utah Code Title 13, Chapter 61 (Utah Consumer Privacy Act)
- Utah Code § 13-61-101 Definitions
- Utah Code § 13-61-102 Applicability
- Utah Division of Consumer Protection: UCPA consumer notice
- Utah Legislature: 2025/2026 bill materials on HB 418 and related UCPA amendments
- Utah Legislature: 2026 enrolled HB 357 motor vehicle privacy amendment
- Utah Legislature interim report evaluating the UCPA
- Privacy Rights Clearinghouse overview of the Utah Consumer Privacy Act
Put it into practice
- Generate the policy: Utah UCPA policy generator (generatepolicy.com)
- Buy the policy pack: State Privacy Law Checklist (cyberpolicy.shop)
- Build it yourself: 2026 US Privacy Program Workbook (ciso.diy)