Skip to content

Utah Consumer Privacy Act (UCPA): What Applies, What Doesn't (2026)

Mate Prgin 8/23/26, 7:16 PM
utah consumer privacy act

Table of Contents

The Utah Consumer Privacy Act (UCPA) is Utah's comprehensive consumer privacy law, in force since December 31, 2023. It gives Utah residents rights over their personal data and sets the rules businesses must follow to collect and share it.

It applies only to businesses with $25 million or more in annual revenue that also process personal data from 100,000 or more Utah consumers. That second bar drops to 25,000 consumers for companies earning over half their revenue from selling data. Both conditions must be true, so most mid-market companies fall outside the law entirely.

For covered businesses: sensitive data needs notice and an opt-out, not opt-in consent, and there is no Global Privacy Control requirement. Penalties run to actual damages plus $7,500 per violation, and a permanent 30-day cure period means you always get a chance to fix problems first.

A right to correct inaccuracies took effect July 1, 2026.

Utah wrote the gentlest comprehensive privacy law in the country's current set, and its lightness is deliberate: it gives residents a baseline set of data rights without pushing heavy compliance work onto business. The UCPA (in force since December 31, 2023) borrowed Virginia's structure, then removed most of the teeth: no assessments, no signal mandates, a consent model that asks less of businesses, and a cure period that never expires.

For most companies the real issue isn't how to comply with Utah. It's whether Utah reaches you at all, and if it does, whether your existing multi-state controls already cover it. This guide answers both, and a third: if Utah is your easiest state, your real obligations are probably coming from Colorado and Connecticut.

What is the UCPA?

The UCPA is Utah's state privacy law, passed as SB 227 in March 2022 and effective December 31, 2023. It made Utah the fourth state with such a law. The statute lives at Utah Code § 13-61-101 and following; the legislature hosts the official text, and the Division of Consumer Protection is the regulator's reference for the UCPA.

Utah has no separate consumer health data law, even though people often assume it does. Health data in Utah falls under the UCPA's sensitive-data rules and, where it applies, HIPAA. (Washington's My Health My Data Act is the different, much stricter animal.)

 

Does the UCPA apply to your business?

The UCPA applies to you only if you meet two thresholds at the same time: a revenue threshold and a data threshold (Utah Code § 13-61-102). Both must be true:

Revenue: $25 million or more in annual revenue. Below that, you are out. Not "mostly out": out.

Data footprint: personal data of 100,000+ Utah consumers in a calendar year, or 25,000+ consumers if you derive over half your gross revenue from selling personal data.

The count means people, not pageviews: Utah residents in a personal or household context (employees and B2B contacts are out) whose data you processed in the preceding year. A good-faith estimate is fine. The same person often shows up in more than one of your systems, so nobody expects a perfect count.

Worked example: a SaaS company with $30 million in revenue and 40,000 Utah end users clears the revenue threshold but not the data threshold, so the UCPA doesn't apply. Its neighbor with $30 million in revenue and 150,000 Utah consumers is covered.

A $10 million company is out regardless of data footprint. Out-of-state and non-US companies play by the same thresholds if they target Utah residents.

If you're exempt: you owe Utah nothing under the UCPA. Keep the minimal hygiene anyway: a truthful privacy notice (the FTC enforces broken promises everywhere), and a check of which other states reach you, since their thresholds are far lower.

utah-ucpa-double-gate@3x

Who's exempt regardless of size

Nonprofits, higher education institutions, government entities, air carriers, GLBA-regulated financial institutions, and tribes.

The HIPAA exemption

Utah's HIPAA exemption is entity-level: HIPAA covered entities and business associates are exempt as whole organizations. That is the broadest version of the health exemption among the states we cover. Colorado exempts only the health data itself, and Connecticut does both, so a healthcare organization's obligations change meaningfully at each state line.

 

What Utah lets you skip, and what it still requires

Utah deliberately leaves out several obligations that other states impose, so parts of your multi-state setup are optional here.

You can skip (for Utah alone):

  • GPC and universal opt-out signals. Utah doesn't require honoring them.
  • Opt-in consent for sensitive data. Utah asks for clear notice and a chance to opt out before processing. Consent means asking permission first; notice-and-opt-out means telling people and letting them object. Utah chose the second.
  • Data protection assessments. Not required.
  • Cure-period anxiety. Utah's 30-day cure window is permanent. You always get notified and get 30 days to fix the problem before penalties can attach.

You can't skip:

  • A privacy notice that says what you collect, why, and who gets it.
  • An opt-out for sale and targeted advertising, findable and functional.
  • Sensitive-data notice before processing those categories.
  • Reasonable security and contracts with your processors.
  • Rights requests: access, deletion, portability, opt-outs, and, since July 1, 2026, correction, answered within 45 days.
  • Reality beyond Utah. If you sell into Colorado, Connecticut, California, or the other 17 states with laws, their stricter rules apply to those visitors regardless of how relaxed Utah is.

Utah also defines "sale" narrowly: an exchange of personal data for money, not the broader "money or other valuable consideration" that California, Colorado, and Virginia use. Data you share for non-monetary value may not count as a sale here, which narrows both the 25,000-consumer threshold trigger and what your opt-out has to cover.

 

utah-ucpa-skip-vs-cant@3x

What counts as sensitive data

Utah's sensitive-data categories are personal data that reveal:

  • Racial or ethnic origin
  • Religious beliefs
  • Sexual orientation
  • Citizenship or immigration status
  • Medical history, or a mental or physical health condition
  • Genetic or biometric data processed to identify a specific individual
  • Specific geolocation

For the categories above, Utah asks for notice and a chance to opt out before processing, not opt-in consent. Data from a known child under 13 is the exception: it is also sensitive, but you handle it under COPPA, which requires verifiable parental consent.

Enzuzo gives you one consent setup for all U.S. state privacy laws → Book a demo to see how it works

Penalties and enforcement: a two-step process

Utah enforces the UCPA through a two-step process that no other state copies exactly. Consumer complaints go first to the Division of Consumer Protection, which investigates. If the Division finds substantial evidence of a violation, it refers the case to the attorney general. Only the attorney general can take enforcement action, and consumers cannot sue on their own.

When enforcement lands, the AG can recover actual damages plus up to $7,500 per violation, counted per consumer, per incident. That number only becomes real if you were notified and failed to cure within 30 days.

That permanent cure period makes Utah, in practice, the most forgiving of the current state privacy laws: a penalty lands only on a business that was told about a problem and didn't fix it. In Colorado and Connecticut, the cure windows have closed, so a first violation can cost you straight away.

What changed in the UCPA in 2026?

One thing changed: consumers gained the right to correct inaccurate personal data, effective July 1, 2026 (HB 418).

Utah UCPA compliance timeline
Date What changed What you must do
Dec 31, 2023 UCPA in force Baseline: notice, opt-outs, security, contracts, DSARs
Jul 1, 2026 Right to correct inaccuracies (HB 418) Handle correction requests in your DSAR intake

Utah launched without a correction right, the only one of the early state laws to skip it. If your rights-request workflow was built to Utah's original spec, it now has a missing request type.

The legislature also runs a formal review of the UCPA (its 2025 evaluation report is public), so expect this table to grow.

Consumer rights under the UCPA

Utah consumers have these rights:

  • Confirm and access the personal data you hold on them.
  • Delete data they provided.
  • Portability: take a copy in a usable format.
  • Opt out of sale and targeted advertising.
  • Opt out of sensitive-data processing, after notice.
  • Correct inaccuracies, since July 2026.

Compared with other states, Utah has no profiling opt-out, no appeal requirement, and no right to a third-party recipient list.

Businesses have 45 days to respond to any consumer request, with the possibility of a 45-day extension when it is genuinely complex. The requestor must be kept informed. Requests that are excessive, repetitive, or manifestly unfounded can be refused or subject to a small fee, but the burden of proof lies on the business if this option is exercised.

ucpa-rights-clean@3x

Are you a controller or a processor under the UCPA?

Most businesses reading this are controllers: if you run the website and decide what personal data to collect and why, that is you, and the UCPA's duties fall on you.

A processor is different. It only handles data on a controller's instructions, a vendor acting on your behalf, so it carries lighter obligations. If you use processors, you have to bind each one with a contract that limits what it can do with your data.

What the UCPA requires from your website

For covered businesses, the website checklist is short:

  • A compliant privacy notice.
  • A visible opt-out for sale and targeted advertising.
  • Notice before sensitive-data processing.
  • Consent records that prove your setup did what your notice claims.
  • A DSAR intake that now handles corrections.

No GPC listener required, and no assessment paperwork behind the banner.

utah-ucpa-vs-california@3x

If you sell beyond Utah

Almost nobody needs consent software for Utah alone. Utah is the easy chapter of a multi-state book.

One visitor who triggers nothing under Utah can still trigger a GPC opt-out under Colorado and an opt-in consent step under Connecticut, because those laws reach far smaller companies. Connecticut now applies to anyone that sells data, at any volume, and Colorado's rules for biometric data and minors apply no matter your size.

The practical answer is a single, location-aware consent setup: meet the strictest rule that reaches a given visitor, ease off where a state genuinely allows it (Utah most of all), and let the tool decide which rules fire where.

How Enzuzo handles this: Enzuzo's consent management platform applies each state's rules by visitor location, honours GPC where it's required, runs opt-in or opt-out consent per region, and keeps the records from one configuration. Teams typically go live in one to three days.

UCPA vs CCPA

UCPA vs CCPA at a glance
Point Utah (UCPA) California (CCPA/CPRA)
Revenue gate $25M+ required, AND data thresholds $25M+ is one of three alternative triggers
Sensitive data Notice + opt-out Right to limit use
GPC Not required Mandatory
Cure period 30 days, permanent None
Private lawsuits No Breaches only
Assessments Not required Required (rulemaking)

For the full U.S. 20-state comparison, read our state law tracker.

FAQs

Who must comply with the Utah Consumer Privacy Act?

Businesses that have $25 million or more in annual revenue AND process personal data from 100,000 or more Utah consumers. The data bar drops to 25,000 consumers when over half of revenue comes from data sales. Both conditions are required, so companies under $25 million are exempt regardless of data volume. Nonprofits, higher ed, government, and HIPAA-covered entities are exempt, too.

Is there a HIPAA exemption in the UCPA?

Yes, and it's entity-level: HIPAA covered entities and business associates are exempt as whole organizations, not just for their health data. That's broader than Colorado's data-only exemption. A covered entity's website and marketing data are outside the UCPA entirely.

What are the penalties under the UCPA, and is there a cure period?

Actual damages plus up to $7,500 per violation, enforced by the attorney general after the Division of Consumer Protection investigates and refers the case. Utah's 30-day cure period never expires, so penalties realistically attach only when a business is notified of a violation and fails to fix it within 30 days.

Does Utah require opt-in consent for sensitive data?

No, Utah does not require opt-in consent for sensitive data. It asks for clear notice and a chance to opt out before processing, lighter than the opt-in consent most states demand. Health, biometric, and precise-location data still trigger the notice duty, and minors' data has its own consent rules.

Does Utah require honoring Global Privacy Control?

No, Utah does not require honoring Global Privacy Control. It has no universal opt-out signal mandate. But twelve other states do, so if you sell beyond Utah, your consent setup likely needs GPC support anyway, applied to visitors from the states that mandate it.

When did the UCPA take effect, and what changed in 2026?

The UCPA took effect December 31, 2023. Its biggest change since: a right to correct inaccurate personal data, added by HB 418 and effective July 1, 2026. Covered businesses' rights-request workflows now need to accept and act on correction requests within the standard 45-day window.

Enzuzo gives you one consent setup for all U.S. state privacy laws → Book a demo to see how it works
Mate Prgin

Mate Prgin

Mate is the CEO & Founder of Enzuzo. He has an executive MBA from Ivey Business School and is a subject matter expert in data privacy and compliance.