close
close
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Utah Privacy Law

UT

Utah (UCPA)

Last updated

UCPA Enacted, in effect

Who this affects: This page tracks Utah’s UCPA, which governs controllers and processors.

Who it applies to: Entities that do business in Utah or target its residents, and meet: 100,000+ consumers and $25,000,000+ annual revenue, or 25,000+ consumers and $25,000,000+ annual revenue and more than 50% of gross revenue from selling data.

Content on this page is not legal advice This page aggregates publicly cited regulatory facts for informational purposes only. It is not legal advice, and DataGrail is not responsible for decisions made in reliance on it. Consult qualified counsel for your specific compliance obligations.
Dec 31, 2023
Effective ↗
Attorney General
Enforced by ↗
$7,500
Maximum penalty per violation ↗
None
Private right of action ↗

The law, in plain English

Must · Can’t · Should

UCPA, distilled to what actually changes your week. Read one column to know your floor, your hard limits, and the further obligations and good practices worth planning for.

Must

  • Act on access, deletion, portability, correction and opt-out requests and tell the consumer what you did within 45 days. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. UT-13-61-203 “Within 45 days after the day on which a controller receives a request to exercise a right, the controller shall: (i) take action on the consumer's request; and (ii) inform the consumer of any action taken on the consumer's request.” Read the statute UT-13-61-203 “a controller shall comply with a consumer's request under Section 13-61-202 to exercise a right” Read the statute UT-13-61-201 “access the consumer's personal data” Read the statute UT-13-61-201 “A consumer has the right to delete the consumer's personal data that the consumer provided to the controller.” Read the statute UT-13-61-201 “A consumer has the right to obtain a copy of the consumer's personal data, that the consumer previously provided to the controller” Read the statute UT-13-61-201 “A consumer has the right to request that a controller correct inaccuracies in the consumer's personal data” Read the statute UT-13-61-201 “A consumer has the right to opt out of the processing of the consumer's personal data for purposes of: (a)targeted advertising; or (b)the sale of personal data.” Read the statute
  • Before a processor processes data, sign a contract setting instructions, purpose, data type, duration, rights and obligations. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. UT-13-61-301 “Before a processor performs processing on behalf of a controller, the processor and controller shall enter into a contract that: (a) clearly sets forth instructions for processing personal data, the nature and purpose of the processing, the type of data subject to processing, the duration of the processing, and the parties' rights and obligations” Read the statute
  • Provide a clear, accessible privacy notice and conspicuously disclose how to opt out of sale and targeted advertising. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. UT-13-61-302 “A controller shall provide consumers with a reasonably accessible and clear privacy notice” Read the statute UT-13-61-302 “the controller shall clearly and conspicuously disclose to the consumer the manner in which the consumer may exercise the right to opt out” Read the statute UT-13-61-201 “A consumer has the right to opt out of the processing of the consumer's personal data for purposes of: (a)targeted advertising; or (b)the sale of personal data.” Read the statute

Can't

  • Process sensitive data without first giving clear notice and a chance to opt out, or a known child's data outside COPPA. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. UT-13-61-302 “a controller may not process sensitive data collected from a consumer without: (a) first presenting the consumer with clear notice and an opportunity to opt out of the processing; or (b) in the case of the processing of personal data concerning a known child, processing the data in accordance with the federal Children's Online Privacy Protection Act, 15 U.S.C. Sec. 6501 et seq., and the act's implementing regulations and exemptions” Read the statute
  • Deny service or offer a different price or quality for exercising a right, except targeted-ad opt-out or loyalty offers. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. UT-13-61-302 “A controller may not discriminate against a consumer for exercising a right by: (i) denying a good or service to the consumer; (ii) charging the consumer a different price or rate for a good or service; or (iii) providing the consumer a different level of quality of a good or service. (b) This Subsection (4) does not prohibit a controller from offering a different price, rate, level, quality, or selection of a good or service to a consumer, including offering a good or service for no fee or at a discount, if: (i) the consumer has opted out of targeted advertising; or (ii) the offer is related to the consumer's voluntary participation in a bona fide loyalty, rewards, premium features, discounts, or club card program” Read the statute
  • Charge for a consumer's first request in a 12-month period, except in cases such as excessive or manifestly unfounded requests. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. UT-13-61-203 “A controller may not charge a fee for information in response to a request, unless the request is the consumer's second or subsequent request during the same 12-month period. (b) (i) Notwithstanding Subsection (4)(a), a controller may charge a reasonable fee to cover the administrative costs of complying with a request or refuse to act on a request, if: (A) the request is excessive, repetitive, technically infeasible, or manifestly unfounded; (B) the controller reasonably believes the primary purpose in submitting the request was something other than exercising a right; or (C) the request, individually or as part of an organized effort, harasses, disrupts, or imposes undue burden on the resources of the controller's business.” Read the statute

Should

  • Track the initial 45-day clock so any single 45-day extension notice, with length and reasons, goes out before it expires. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. UT-13-61-203 “The controller may extend once the initial 45-day period by an additional 45 days if reasonably necessary due to the complexity of the request or the volume of the requests received by the controller. (c) If a controller extends the initial 45-day period, before the initial 45-day period expires, the controller shall: (i) inform the consumer of the extension, including the length of the extension; and (ii) provide the reasons the extension is reasonably necessary as described in Subsection (2)(b)” Read the statute
  • Scale administrative, technical and physical security to your data's volume and nature and your business size, scope and type. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. UT-13-61-302 “A controller shall establish, implement, and maintain reasonable administrative, technical, and physical data security practices” Read the statute UT-13-61-302 “Considering the controller's business size, scope, and type, a controller shall use data security practices that are appropriate for the volume and nature of the personal data at issue” Read the statute

These are the highlights we judge most important, not everything UCPA requires. The comprehensive law section below covers the full detail, fact by fact, with the statutory text behind every one.

The comprehensive law

Utah Consumer Privacy Act

UCPA (SB 227) is Utah’s comprehensive privacy law. Every fact was extracted from the primary statute by the DataGrail regulation engine and is grounded to the cited source. Scan the facts; the exact statutory text sits one click away on each source link.

Status
Enacted, in effect
Archived excerpt — the text we read …-61-305) Download Options PDF | RTF | XML Next Section (13-61-402) >> IndexUtah Code Title 13Commerce and Trade Chapter 61Utah Consumer Privacy Act Part 4Enforcement Section 401Investigative powers of division. (Effective 12/31/2023) Effective 12/31/2023 13-61-401. Investigative powers of division. (1) The division shall establish and administer a system to receive consumer complaints regarding a controller's or processor's alleged violation of … Archived from source — captured 2026-07-21 · snapshot 57c8e4b4 Verify at the source

Corroborated by Privacy-law tracker

Effective
December 31, 2023
Archived excerpt — the text we read …-61-305) Download Options PDF | RTF | XML Next Section (13-61-402) >> IndexUtah Code Title 13Commerce and Trade Chapter 61Utah Consumer Privacy Act Part 4Enforcement Section 401Investigative powers of division. (Effective 12/31/2023) Effective 12/31/2023 13-61-401. Investigative powers of division. (1) The division shall establish and administer a system to receive consumer complaints regarding a controller's or processor's alleged violation of … Archived from source — captured 2026-07-21 · snapshot 57c8e4b4 Verify at the source

Corroborated by Privacy-law tracker

Signed
March 24, 2022
“24 Mar 2022, Governor Signed” View the source
Enforced by
Attorney General
Attorney General (with referral from the Division of Consumer Protection) Archived excerpt — the text we read 13-61-402. Enforcement powers of the attorney general. (1) The attorney general has the exclusive authority to enforce this chapter. (2) Upon referral from the division, the attorney general may initiate an enforcement action against a controller or processor for a violation of this chapter. (3) (a) At least 30 days before the day on which the att… Archived from source — captured 2026-07-21 · snapshot c36f065a Verify at the source
Maximum penalty per violation
$7,500
The attorney general may also recover actual damages for consumers. “for each violation described in Subsection (3)(c), an amount not to exceed $7,500” View the statute
Right to cure
30 days
Archived excerpt — the text we read …eral alleges the controller or processor has violated or is violating; and (ii) an explanation of the basis for each allegation. (b) The attorney general may not initiate an action if the controller or processor: (i) cures the noticed violation within 30 days after the day on which the controller or processor receives the written notice described in Subsection (3)(a); and (ii) provides the attorney general an express written statement that: (A) the violation has been cured; and (B) no further violation of the cured violation will occur. (c) The attorney general may initiate an a… Archived from source — captured 2026-07-21 · snapshot c36f065a Verify at the source
Private right of action
No private right of action.
Archived excerpt — the text we read 13-61-305. No private cause of action. A violation of this chapter does not provide a basis for, nor is a violation of this chapter subject to, a private right of action under this chapter or any other law. Enacted by Chapter 462, 2022 General Session << Previous Section (13-61-304) Download Options PDF | RTF | XML Next Section (13-61-401) >> Archived from source — captured 2026-07-21 · snapshot fad481af Verify at the source

Corroborated by Privacy-law tracker

Universal opt-out signal
Not required

Corroborated by Privacy-law tracker

Who it applies to

Entities that do business in Utah or target its residents, and meet: 100,000+ consumers and $25,000,000+ annual revenue, or 25,000+ consumers and $25,000,000+ annual revenue and more than 50% of gross revenue from selling data

What the law gives consumers

  • Right to access Archived excerpt — the text we read 13-61-201. Consumer rights -- Access -- Deletion -- Portability -- Opt out of certain processing. (1)A consumer has the right to: (a)confirm whether a controller is processing the consumer's personal data; and (b)access the consumer's personal data. (2)A consumer has the right to delete the consumer's personal data that the consumer provided to the controller. (3)A consumer has the right to obtain a copy of the consumer's personal data, that the consumer previou… Archived from source — captured 2026-07-21 · snapshot 68a8d25c Verify at the source
  • Right to delete (limited) Only personal data the consumer provided to the controller (not data obtained about the consumer). Archived excerpt — the text we read …-- Deletion -- Portability -- Opt out of certain processing. (1)A consumer has the right to: (a)confirm whether a controller is processing the consumer's personal data; and (b)access the consumer's personal data. (2)A consumer has the right to delete the consumer's personal data that the consumer provided to the controller. (3)A consumer has the right to obtain a copy of the consumer's personal data, that the consumer previously provided to the controller, in a format that: (a)to the extent technically feasible, is portable; (b)to the e… Archived from source — captured 2026-07-21 · snapshot 68a8d25c Verify at the source
  • Right to data portability Archived excerpt — the text we read …a controller is processing the consumer's personal data; and (b)access the consumer's personal data. (2)A consumer has the right to delete the consumer's personal data that the consumer provided to the controller. (3)A consumer has the right to obtain a copy of the consumer's personal data, that the consumer previously provided to the controller, in a format that: (a)to the extent technically feasible, is portable; (b)to the extent practicable, is readily usable; and (c)allows the consumer to transmit the data to another controller without impediment, where … Archived from source — captured 2026-07-21 · snapshot 68a8d25c Verify at the source
  • Right to correct Archived excerpt — the text we read …ible, is portable; (b)to the extent practicable, is readily usable; and (c)allows the consumer to transmit the data to another controller without impediment, where the processing is carried out by automated means. (4)A consumer has the right to request that a controller correct inaccuracies in the consumer's personal data, taking into account the nature of the personal data and the purposes of the processing of the consumer's personal data. (5)A consumer has the right to opt out of the processing of the consumer's personal data for purp… Archived from source — captured 2026-07-21 · snapshot 68a8d25c Verify at the source
  • Right to opt out of sale Archived excerpt — the text we read …as the right to request that a controller correct inaccuracies in the consumer's personal data, taking into account the nature of the personal data and the purposes of the processing of the consumer's personal data. (5)A consumer has the right to opt out of the processing of the consumer's personal data for purposes of: (a)targeted advertising; or (b)the sale of personal data. (6)Nothing in this section requires a person to cause a breach of security system as defined in Section 13-44-102. Amended by Chapter 468, 2025 General Session << Previous Section (13-61-103) Download Options PDF |… Archived from source — captured 2026-07-21 · snapshot 68a8d25c Verify at the source
  • Right to opt out of targeted advertising Archived excerpt — the text we read …as the right to request that a controller correct inaccuracies in the consumer's personal data, taking into account the nature of the personal data and the purposes of the processing of the consumer's personal data. (5)A consumer has the right to opt out of the processing of the consumer's personal data for purposes of: (a)targeted advertising; or (b)the sale of personal data. (6)Nothing in this section requires a person to cause a breach of security system as defined in Section 13-44-102. Amended by Chapter 468, 2025 General Session << Previous Section (13-61-103) Download Options PDF |… Archived from source — captured 2026-07-21 · snapshot 68a8d25c Verify at the source
  • Sensitive data: notice and opt-out Archived excerpt — the text we read …ontroller's business size, scope, and type, a controller shall use data security practices that are appropriate for the volume and nature of the personal data at issue. (3) Except as otherwise provided in this chapter, a controller may not process sensitive data collected from a consumer without: (a) first presenting the consumer with clear notice and an opportunity to opt out of the processing; or (b) in the case of the processing of personal data concerning a known child, processing the data in accordance with the federal Children's Online Privacy Protection Act, 15 U.S.C. Sec. 6501 et seq., and the act's i… Archived from source — captured 2026-07-21 · snapshot ec992c50 Verify at the source
  • Right against discrimination Archived excerpt — the text we read …l data concerning a known child, processing the data in accordance with the federal Children's Online Privacy Protection Act, 15 U.S.C. Sec. 6501 et seq., and the act's implementing regulations and exemptions. (4) (a) A controller may not discriminate against a consumer for exercising a right by: (i) denying a good or service to the consumer; (ii) charging the consumer a different price or rate for a good or service; or (iii) providing the consumer a different level of quality of a good or service. (b) This… Archived from source — captured 2026-07-21 · snapshot ec992c50 Verify at the source
  • Not granted: Private right of action Archived excerpt — the text we read 13-61-305. No private cause of action. A violation of this chapter does not provide a basis for, nor is a violation of this chapter subject to, a private right of action under this chapter or any other law. Enacted by Chapter 462, 2022 General Session << Previous Section (13-61-304) Download Options PDF | RTF | XML Next Section (13-61-401) >> Archived from source — captured 2026-07-21 · snapshot fad481af Verify at the source

Who the law governs

  • Controllers Archived excerpt — the text we read … any manner over the election of a majority of the directors or of the individuals exercising similar functions; or (c)the power to exercise controlling influence of the management of an entity. (12)"Controller" means a person doing business in the state who determines the purposes for which and the means by which personal data are processed, regardless of whether the person makes the determination alone or with others. (13)"Covered entity" means the same as that term is defined in 45 C.F.R. Sec. 160.103. (14) (a)"Deidentified data" means data that: (i)cannot reasonably be linked to an identified individual or an identifiable indi… Archived from source — captured 2026-07-21 · snapshot 31cfab68 Verify at the source
  • Processors Archived excerpt — the text we read …nformation. (25)"Process" means an operation or set of operations performed on personal data, including collection, use, storage, disclosure, analysis, deletion, or modification of personal data. (26)"Processor" means a person who processes personal data on behalf of a controller. (27)"Protected health information" means the same as that term is defined in 45 C.F.R. Sec. 160.103. (28)"Pseudonymous data" means personal data that cannot be attributed to a specific individual without the use of a… Archived from source — captured 2026-07-21 · snapshot 31cfab68 Verify at the source

Exemptions

  • Governmental entity or contracted third party Archived excerpt — the text we read …0,000 or more consumers; or (ii)derives over 50% of the entity's gross revenue from the sale of personal data and controls or processes personal data of 25,000 or more consumers. (2)This chapter does not apply to: (a)a governmental entity or a third party under contract with a governmental entity when the third party is acting on behalf of the governmental entity; (b)a tribe; (c)an institution of higher education; (d)a nonprofit corporation; (e)a covered entity; (f)a business associate; (g)information that meets the definition of: (i)protected health information for purpo… Archived from source — captured 2026-07-21 · snapshot c28c2316 Verify at the source
  • Tribe Archived excerpt — the text we read …25,000 or more consumers. (2)This chapter does not apply to: (a)a governmental entity or a third party under contract with a governmental entity when the third party is acting on behalf of the governmental entity; (b)a tribe; (c)an institution of higher education; (d)a nonprofit corporation; (e)a covered entity; (f)a business associate; (g)information that meets the definition of: (i)protected health information for purposes of the fe… Archived from source — captured 2026-07-21 · snapshot c28c2316 Verify at the source
  • Institution of higher education Archived excerpt — the text we read …e consumers. (2)This chapter does not apply to: (a)a governmental entity or a third party under contract with a governmental entity when the third party is acting on behalf of the governmental entity; (b)a tribe; (c)an institution of higher education; (d)a nonprofit corporation; (e)a covered entity; (f)a business associate; (g)information that meets the definition of: (i)protected health information for purposes of the federal Health Insurance Portability and A… Archived from source — captured 2026-07-21 · snapshot c28c2316 Verify at the source
  • Nonprofit corporation Archived excerpt — the text we read …pply to: (a)a governmental entity or a third party under contract with a governmental entity when the third party is acting on behalf of the governmental entity; (b)a tribe; (c)an institution of higher education; (d)a nonprofit corporation; (e)a covered entity; (f)a business associate; (g)information that meets the definition of: (i)protected health information for purposes of the federal Health Insurance Portability and Accountability Act of 1996, 42… Archived from source — captured 2026-07-21 · snapshot c28c2316 Verify at the source
  • HIPAA covered entities (entity-level) Entity-level Archived excerpt — the text we read …ntity or a third party under contract with a governmental entity when the third party is acting on behalf of the governmental entity; (b)a tribe; (c)an institution of higher education; (d)a nonprofit corporation; (e)a covered entity; (f)a business associate; (g)information that meets the definition of: (i)protected health information for purposes of the federal Health Insurance Portability and Accountability Act of 1996, 42 U.S.C. Sec. 1320d et … Archived from source — captured 2026-07-21 · snapshot c28c2316 Verify at the source
  • HIPAA business associates (entity-level) Entity-level Archived excerpt — the text we read … under contract with a governmental entity when the third party is acting on behalf of the governmental entity; (b)a tribe; (c)an institution of higher education; (d)a nonprofit corporation; (e)a covered entity; (f)a business associate; (g)information that meets the definition of: (i)protected health information for purposes of the federal Health Insurance Portability and Accountability Act of 1996, 42 U.S.C. Sec. 1320d et seq., and related regulati… Archived from source — captured 2026-07-21 · snapshot c28c2316 Verify at the source
  • HIPAA protected health information Archived excerpt — the text we read …g on behalf of the governmental entity; (b)a tribe; (c)an institution of higher education; (d)a nonprofit corporation; (e)a covered entity; (f)a business associate; (g)information that meets the definition of: (i)protected health information for purposes of the federal Health Insurance Portability and Accountability Act of 1996, 42 U.S.C. Sec. 1320d et seq., and related regulations; (ii)patient identifying information for purposes of 42 C.F.R. Part 2; (iii)identifiable private information for purposes of the Federal Policy for the Protection of Human Subjects, 45 C.F.R. Part 46; (iv)identifiabl… Archived from source — captured 2026-07-21 · snapshot c28c2316 Verify at the source
  • 42 CFR Part 2 patient identifying information Archived excerpt — the text we read …rmation that meets the definition of: (i)protected health information for purposes of the federal Health Insurance Portability and Accountability Act of 1996, 42 U.S.C. Sec. 1320d et seq., and related regulations; (ii)patient identifying information for purposes of 42 C.F.R. Part 2; (iii)identifiable private information for purposes of the Federal Policy for the Protection of Human Subjects, 45 C.F.R. Part 46; (iv)identifiable private information or personal data collected as part of human subje… Archived from source — captured 2026-07-21 · snapshot c28c2316 Verify at the source
  • Human subjects research identifiable private information Archived excerpt — the text we read …or purposes of the federal Health Insurance Portability and Accountability Act of 1996, 42 U.S.C. Sec. 1320d et seq., and related regulations; (ii)patient identifying information for purposes of 42 C.F.R. Part 2; (iii)identifiable private information for purposes of the Federal Policy for the Protection of Human Subjects, 45 C.F.R. Part 46; (iv)identifiable private information or personal data collected as part of human subjects research pursuant to or under the same standards as: (A)the good clinical practice guidelines issued by the International Coun… Archived from source — captured 2026-07-21 · snapshot c28c2316 Verify at the source
  • Human subjects research data Human subjects research data under ICH good clinical practice guidelines or 21 C.F.R. Parts 50 and 56. Archived excerpt — the text we read …regulations; (ii)patient identifying information for purposes of 42 C.F.R. Part 2; (iii)identifiable private information for purposes of the Federal Policy for the Protection of Human Subjects, 45 C.F.R. Part 46; (iv)identifiable private information or personal data collected as part of human subjects research pursuant to or under the same standards as: (A)the good clinical practice guidelines issued by the International Council for Harmonisation; or (B)the Protection of Human Subjects under 21 C.F.R. Part 50 and Institutional Review Boards under 21 C.F.R. Part 56; (v)personal data used or shared in research conducted in accordance with one or more of the requirements described in Subsection (2)(g)(iv); (vi)information and documents created specifically for, and collected and m… Archived from source — captured 2026-07-21 · snapshot c28c2316 Verify at the source
  • Research data used or shared under those standards Archived excerpt — the text we read …A)the good clinical practice guidelines issued by the International Council for Harmonisation; or (B)the Protection of Human Subjects under 21 C.F.R. Part 50 and Institutional Review Boards under 21 C.F.R. Part 56; (v)personal data used or shared in research conducted in accordance with one or more of the requirements described in Subsection (2)(g)(iv); (vi)information and documents created specifically for, and collected and maintained by, a committee but not a board or council listed in Section 26B-1-204; (vii)information and documents created for purposes of the … Archived from source — captured 2026-07-21 · snapshot c28c2316 Verify at the source
  • Committee-created health documents Archived excerpt — the text we read … C.F.R. Part 50 and Institutional Review Boards under 21 C.F.R. Part 56; (v)personal data used or shared in research conducted in accordance with one or more of the requirements described in Subsection (2)(g)(iv); (vi)information and documents created specifically for, and collected and maintained by, a committee but not a board or council listed in Section 26B-1-204; (vii)information and documents created for purposes of the federal Health Care Quality Improvement Act of 1986, 42 U.S.C. Sec. 11101 et seq., and related regulations; (viii)patient safety work product for purposes of… Archived from source — captured 2026-07-21 · snapshot c28c2316 Verify at the source
  • Health Care Quality Improvement Act information Archived excerpt — the text we read …of the requirements described in Subsection (2)(g)(iv); (vi)information and documents created specifically for, and collected and maintained by, a committee but not a board or council listed in Section 26B-1-204; (vii)information and documents created for purposes of the federal Health Care Quality Improvement Act of 1986, 42 U.S.C. Sec. 11101 et seq., and related regulations; (viii)patient safety work product for purposes of 42 C.F.R. Part 3; or (ix)information that is: (A)deidentified in accordance with the requirements for deidentification set forth in 45 C.F.R. Part 164; and (B)deriv… Archived from source — captured 2026-07-21 · snapshot c28c2316 Verify at the source
  • Patient safety work product Archived excerpt — the text we read …oard or council listed in Section 26B-1-204; (vii)information and documents created for purposes of the federal Health Care Quality Improvement Act of 1986, 42 U.S.C. Sec. 11101 et seq., and related regulations; (viii)patient safety work product for purposes of 42 C.F.R. Part 3; or (ix)information that is: (A)deidentified in accordance with the requirements for deidentification set forth in 45 C.F.R. Part 164; and (B)derived from any of the health care-related information listed in this Sub… Archived from source — captured 2026-07-21 · snapshot c28c2316 Verify at the source
  • Deidentified health-related information Archived excerpt — the text we read …es of the federal Health Care Quality Improvement Act of 1986, 42 U.S.C. Sec. 11101 et seq., and related regulations; (viii)patient safety work product for purposes of 42 C.F.R. Part 3; or (ix)information that is: (A)deidentified in accordance with the requirements for deidentification set forth in 45 C.F.R. Part 164; and (B)derived from any of the health care-related information listed in this Subsection (2)(g); (h)information originating from, and intermingled to be indistinguishable with, information under Subsection (2)(g) that is maintained by: (i)a health care facility or health care provider; or (ii)a program or a qua… Archived from source — captured 2026-07-21 · snapshot c28c2316 Verify at the source
  • Intermingled indistinguishable health information Archived excerpt — the text we read …n that is: (A)deidentified in accordance with the requirements for deidentification set forth in 45 C.F.R. Part 164; and (B)derived from any of the health care-related information listed in this Subsection (2)(g); (h)information originating from, and intermingled to be indistinguishable with, information under Subsection (2)(g) that is maintained by: (i)a health care facility or health care provider; or (ii)a program or a qualified service organization as defined in 42 C.F.R. Sec. 2.11; (i)information used only for public health activities and purposes as described in 45 C.F.R. Sec. 164.512; (j) (i)an activity by: (A)a consumer reporting agency, as defined in 15 U.S.C. Sec. 1681a; (B)a furnisher … Archived from source — captured 2026-07-21 · snapshot c28c2316 Verify at the source
  • Public health activities information Archived excerpt — the text we read …guishable with, information under Subsection (2)(g) that is maintained by: (i)a health care facility or health care provider; or (ii)a program or a qualified service organization as defined in 42 C.F.R. Sec. 2.11; (i)information used only for public health activities and purposes as described in 45 C.F.R. Sec. 164.512; (j) (i)an activity by: (A)a consumer reporting agency, as defined in 15 U.S.C. Sec. 1681a; (B)a furnisher of information, as set forth in 15 U.S.C. Sec. 1681s-2, who provides information for use in a consumer repor… Archived from source — captured 2026-07-21 · snapshot c28c2316 Verify at the source
  • FCRA-regulated consumer reporting activity bearing on creditworthiness, and others FCRA-regulated consumer reporting activity bearing on creditworthiness, character, reputation or mode of living. Consumer reporting agencies, furnishers, users. Archived excerpt — the text we read …are provider; or (ii)a program or a qualified service organization as defined in 42 C.F.R. Sec. 2.11; (i)information used only for public health activities and purposes as described in 45 C.F.R. Sec. 164.512; (j) (i)an activity by: (A)a consumer reporting agency, as defined in 15 U.S.C. Sec. 1681a; (B)a furnisher of information, as set forth in 15 U.S.C. Sec. 1681s-2, who provides information for use in a consumer report, as defined in 15 U.S.C. Sec. 1681a; or (C)a user of a consumer report, as set forth in 15 U.S.C. Sec. 1681b; (ii)subject to regulation under the federal Fair Credit Reporting Act, 15 U.S.C. Sec. 1681 et seq.; and (iii)involving the collection, maintenance, disclosure, sale, communication, or use of any personal data bearing on a consumer's: (A)credit worthiness; (B)credit standing; (C)credit capacity; (D)character; (E)general reputation; (F)personal characteristics; or (G)mode of living; (k)a financial institution or an affiliate of a financial institution governed by, or personal data collected, processed, sold, or disclosed in accordance with, Title V of the Gramm-Leach-Bliley Act, 15 U.S.C. Sec. 68… Archived from source — captured 2026-07-21 · snapshot c28c2316 Verify at the source
  • GLBA: financial institutions, their affiliates, and data subject to Title V Entity- and data-level Archived excerpt — the text we read …tion, or use of any personal data bearing on a consumer's: (A)credit worthiness; (B)credit standing; (C)credit capacity; (D)character; (E)general reputation; (F)personal characteristics; or (G)mode of living; (k)a financial institution or an affiliate of a financial institution governed by, or personal data collected, processed, sold, or disclosed in accordance with, Title V of the Gramm-Leach-Bliley Act, 15 U.S.C. Sec. 6801 et seq., and related regulations; (l)personal data collected, processed, sold, or disclosed in accordance with the federal Driver's Privacy Protection Act of 1994, 18 U.S.C. Sec. 2721 et seq.; (m)personal data regulated by the federal Family Educatio… Archived from source — captured 2026-07-21 · snapshot c28c2316 Verify at the source
  • Driver's Privacy Protection Act data Archived excerpt — the text we read …iate of a financial institution governed by, or personal data collected, processed, sold, or disclosed in accordance with, Title V of the Gramm-Leach-Bliley Act, 15 U.S.C. Sec. 6801 et seq., and related regulations; (l)personal data collected, processed, sold, or disclosed in accordance with the federal Driver's Privacy Protection Act of 1994, 18 U.S.C. Sec. 2721 et seq.; (m)personal data regulated by the federal Family Education Rights and Privacy Act, 20 U.S.C. Sec. 1232g, and related regulations; (n)personal data collected, processed, sold, or disclosed in accordance with the feder… Archived from source — captured 2026-07-21 · snapshot c28c2316 Verify at the source
  • FERPA-regulated education data Archived excerpt — the text we read …, 15 U.S.C. Sec. 6801 et seq., and related regulations; (l)personal data collected, processed, sold, or disclosed in accordance with the federal Driver's Privacy Protection Act of 1994, 18 U.S.C. Sec. 2721 et seq.; (m)personal data regulated by the federal Family Education Rights and Privacy Act, 20 U.S.C. Sec. 1232g, and related regulations; (n)personal data collected, processed, sold, or disclosed in accordance with the federal Farm Credit Act of 1971, 12 U.S.C. Sec. 2001 et seq.; (o)data that are processed or maintained: (i)in the course of an individ… Archived from source — captured 2026-07-21 · snapshot c28c2316 Verify at the source
  • Farm Credit Act data Archived excerpt — the text we read …th the federal Driver's Privacy Protection Act of 1994, 18 U.S.C. Sec. 2721 et seq.; (m)personal data regulated by the federal Family Education Rights and Privacy Act, 20 U.S.C. Sec. 1232g, and related regulations; (n)personal data collected, processed, sold, or disclosed in accordance with the federal Farm Credit Act of 1971, 12 U.S.C. Sec. 2001 et seq.; (o)data that are processed or maintained: (i)in the course of an individual applying to, being employed by, or acting as an agent or independent contractor of a controller, processor, or third party, to the extent th… Archived from source — captured 2026-07-21 · snapshot c28c2316 Verify at the source
  • Employment-related data Archived excerpt — the text we read …2g, and related regulations; (n)personal data collected, processed, sold, or disclosed in accordance with the federal Farm Credit Act of 1971, 12 U.S.C. Sec. 2001 et seq.; (o)data that are processed or maintained: (i)in the course of an individual applying to, being employed by, or acting as an agent or independent contractor of a controller, processor, or third party, to the extent the collection and use of the data are related to the individual's role; (ii)as the emergency contact information of an individual described in Subsection (2)(o)(i) and used for emergency contact purposes; or (iii)to administer benefits for another individual relating to an individual des… Archived from source — captured 2026-07-21 · snapshot c28c2316 Verify at the source
  • Emergency contact information Archived excerpt — the text we read …ual applying to, being employed by, or acting as an agent or independent contractor of a controller, processor, or third party, to the extent the collection and use of the data are related to the individual's role; (ii)as the emergency contact information of an individual described in Subsection (2)(o)(i) and used for emergency contact purposes; or (iii)to administer benefits for another individual relating to an individual described in Subsection (2)(o)(i) and used for the purpose of administering the benefits; (p)an individual's processing of personal data… Archived from source — captured 2026-07-21 · snapshot c28c2316 Verify at the source
  • Benefits administration data Archived excerpt — the text we read …ent the collection and use of the data are related to the individual's role; (ii)as the emergency contact information of an individual described in Subsection (2)(o)(i) and used for emergency contact purposes; or (iii)to administer benefits for another individual relating to an individual described in Subsection (2)(o)(i) and used for the purpose of administering the benefits; (p)an individual's processing of personal data for purely personal or household purposes; or (q)an air carrier. (3)A controller is in compliance with any obligation to obtain parental consent under this chapter if t… Archived from source — captured 2026-07-21 · snapshot c28c2316 Verify at the source
  • Purely personal or household purposes Archived excerpt — the text we read …(i) and used for emergency contact purposes; or (iii)to administer benefits for another individual relating to an individual described in Subsection (2)(o)(i) and used for the purpose of administering the benefits; (p)an individual's processing of personal data for purely personal or household purposes; or (q)an air carrier. (3)A controller is in compliance with any obligation to obtain parental consent under this chapter if the controller complies with the verifiable parental consent mechanisms under the Children's… Archived from source — captured 2026-07-21 · snapshot c28c2316 Verify at the source
  • Air carrier Archived excerpt — the text we read …idual relating to an individual described in Subsection (2)(o)(i) and used for the purpose of administering the benefits; (p)an individual's processing of personal data for purely personal or household purposes; or (q)an air carrier. (3)A controller is in compliance with any obligation to obtain parental consent under this chapter if the controller complies with the verifiable parental consent mechanisms under the Children's Online Privacy Protect… Archived from source — captured 2026-07-21 · snapshot c28c2316 Verify at the source
  • Evidentiary privilege (compliance would violate a Utah evidentiary privilege) Archived excerpt — the text we read …child or the performance of a contract to which the consumer or a parent or legal guardian of a child is a party; or (n) retain a consumer's email address to comply with the consumer's request to exercise a right. (2) This chapter does not apply if a controller's or processor's compliance with this chapter: (a) violates an evidentiary privilege under Utah law; (b) as part of a privileged communication, prevents a controller or processor from providing personal data concerning a consumer to a person covered by an evidentiary privilege under Utah law; or (c) adversely affect… Archived from source — captured 2026-07-21 · snapshot ec9b7f94 Verify at the source
  • Trade secrets (no obligation to disclose) Archived excerpt — the text we read …lation of this chapter. (4) If a controller processes personal data under an exemption described in Subsection (1), the controller bears the burden of demonstrating that the processing qualifies for the exemption. (5) Nothing in this chapter requires a controller, processor, third party, or consumer to disclose a trade secret. Enacted by Chapter 462, 2022 General Session << Previous Section (13-61-303) Download Options PDF | RTF | XML Next Section (13-61-305) >> Archived from source — captured 2026-07-21 · snapshot ec9b7f94 Verify at the source
  • Privileged communications to a person covered by an evidentiary privilege Archived excerpt — the text we read …ress to comply with the consumer's request to exercise a right. (2) This chapter does not apply if a controller's or processor's compliance with this chapter: (a) violates an evidentiary privilege under Utah law; (b) as part of a privileged communication, prevents a controller or processor from providing personal data concerning a consumer to a person covered by an evidentiary privilege under Utah law; or (c) adversely affects the privacy or other rights of any person. (3) A controller or processor is not in violation of this chapter if: (a) the controller or processor discloses personal data to a third party contr… Archived from source — captured 2026-07-21 · snapshot ec9b7f94 Verify at the source
  • Compliance that would adversely affect the privacy or other rights of any person Archived excerpt — the text we read …e under Utah law; (b) as part of a privileged communication, prevents a controller or processor from providing personal data concerning a consumer to a person covered by an evidentiary privilege under Utah law; or (c) adversely affects the privacy or other rights of any person. (3) A controller or processor is not in violation of this chapter if: (a) the controller or processor discloses personal data to a third party controller or processor in compliance with this chapter; (b) the third p… Archived from source — captured 2026-07-21 · snapshot ec9b7f94 Verify at the source

Published Sep 29, 2026 from the DataGrail regulation engine; each fact links to its primary source.

Timeline

UCPA milestones

This state currently has one dated milestone on the books.

Enforcement December 31, 2023

UCPA took effect

Enforcement began — obligations have been live since this date.

Source: primary citation

Published Sep 29, 2026 from the DataGrail regulation engine; each fact links to its primary source. Reference only, not legal advice.

When staying on top of the law isn't enough, DataGrail automates the work.
DSR automation and regulatory tracking — handled by the platform behind this reference.
How DataGrail helps
Back to the Regulations Hub Reference only — not legal advice. Published Sep 29, 2026