Utah is the most business-friendly state in the US privacy landscape.
The Utah Consumer Privacy Act (UCPA), Utah Code § 13-61-101 et seq., took effect on December 31, 2023. It is the leanest state privacy law among those approved so far in the US, with fewer obligations for businesses and stronger protection for the traditional business model.
But "lean" does not mean ignorable. The US$ 25 million revenue threshold creates a well-defined scope, and the Utah Attorney General has exclusive enforcement authority.
The Utah Consumer Privacy Act is Utah's state personal data protection law. It grants basic rights to state residents and creates obligations for businesses that process their data.
Enforcement follows a two-stage model: the Division of Consumer Protection receives and investigates consumer complaints. If it finds substantial evidence of a violation, it refers to the Utah Attorney General, who has exclusive authority to initiate enforcement actions.
There is no private right of action.
On December 31, 2023.
Under Utah Code § 13-61-102(1), the law applies to controllers or processors that:
Conduct business in Utah or produce products or services targeted to state residents;
Have annual revenue of US$ 25,000,000 or more; and
Meet at least one of the following thresholds:
Control or process personal data of 100,000 or more consumers during a calendar year; or
Derive more than 50% of gross revenue from the sale of personal data and control or process personal data of 25,000 or more consumers.
The key differentiator from other laws: the UCPA requires the business to satisfy the US$ 25 million revenue requirement AND at least one of the volume thresholds. Other state laws use one or the other. Here both are needed. This significantly reduces the number of businesses in scope.
Understanding the distinction between controller and processor is fundamental to defining responsibilities in the processing chain.
Under Utah Code § 13-61-102(2), the following are exempt:
Government entities and third parties contracted on their behalf.
Native American tribes.
Institutions of higher education.
Nonprofit corporations.
HIPAA covered entities and business associates.
HIPAA-protected health information and related health data in specific situations.
Regulated clinical research data.
Consumer credit data regulated by the Fair Credit Reporting Act.
Financial institutions and data regulated by the Gramm-Leach-Bliley Act.
Data regulated by the Driver's Privacy Protection Act.
Data regulated by FERPA.
Data regulated by the Farm Credit Act.
Employee, job applicant, and independent contractor data in an employment context.
Data processed for purely personal or household purposes.
Air carriers.
Under Utah Code § 13-61-101(24), personal data is any information linked or reasonably linkable to an identified individual or an identifiable individual.
Not personal data: de-identified data, aggregated data, and publicly available information.
The UCPA also defines pseudonymous data (§ 13-61-101(28)) as personal data that cannot be attributed to a specific individual without additional information kept separately and under appropriate technical and organizational measures. Pseudonymous data has limited protection under the UCPA.
Under Utah Code § 13-61-101(32), sensitive data includes:
Personal data revealing racial or ethnic origin, religious beliefs, sexual orientation, citizenship or immigration status, or information about medical history, physical or mental health condition, or medical treatment or diagnosis.
Processing of genetic personal data or biometric data, where the processing is for the purpose of identifying a specific individual.
Specific geolocation data.
Note on the UCPA's sensitive data model: unlike the CPRA and several other state laws, the UCPA does not require consent to process sensitive data. It only requires the business to present a clear notice and offer an opt-out opportunity before processing. This is one of the aspects that makes the UCPA more business-friendly than other state laws.
For data of known children (under 13), businesses must comply with COPPA requirements (§ 13-61-102(3)).
Under Utah Code § 13-61-101(33), specific geolocation data means information derived from technology, including GPS coordinates, that directly identifies an individual's specific location with a precision of 1,750 feet or less.
Under Utah Code § 13-61-201, Utah residents have four rights:
Right to confirm and access: confirm whether the controller is processing personal data and access that data (§ 13-61-201(1)).
Right to deletion: request deletion of personal data the consumer provided to the controller. Note: the UCPA limits the deletion right to data the consumer provided. Data the controller obtained from other sources does not need to be deleted under the UCPA (§ 13-61-201(2)).
Right to portability: obtain a copy of the data in a portable format where technically feasible, for transmission to another controller without impediment (§ 13-61-201(3)).
Right to opt-out: refuse processing of personal data for targeted advertising or sale of personal data (§ 13-61-201(4)).
No right to correct inaccurate data. The UCPA does not guarantee this right, unlike the CPRA, OCPA, VCDPA, and CTDPA.
No right to opt-out of profiling. The UCPA covers only targeted advertising and data sales.
No formal structured appeal process. The law does not define an appeal process for controller denials.
Under Utah Code § 13-61-203:
45 days to respond from receipt of the request.
Extension of +45 days when reasonably necessary due to complexity or volume, with notification within the initial period.
Free for the first request from each consumer per 12-month period (§ 13-61-203(4)(a)).
From the second request in the same 12-month period, the business may charge a reasonable fee or refuse if the request is excessive, repetitive, technically infeasible, manifestly unfounded, or if the controller reasonably believes the primary purpose is not exercising a right.
This is one of the most important points of the UCPA for businesses already compliant with other laws.
Under Utah Code § 13-61-302(3), the controller may not process sensitive data collected from a consumer without first:
Presenting the consumer with a clear notice; and
Offering the consumer the opportunity to opt out of the processing.
This opt-out model for sensitive data is substantially less restrictive than the opt-in (prior consent) model required by the CPRA, OCPA, CTDPA, and VCDPA. Businesses already compliant with the more restrictive laws will automatically be compliant with the UCPA on this point.
Under Utah Code § 13-61-302, the controller must:
Privacy notice: provide a reasonably accessible and clear privacy notice including: categories of personal data processed, purposes of processing, how consumers can exercise their rights, categories of data shared with third parties (if any), and categories of third parties with whom data is shared.
Data security: establish, implement, and maintain reasonable administrative, technical, and physical data security practices proportionate to the volume and nature of the data.
Disclosure of sale and targeted advertising: if the business sells data or uses data for targeted advertising, it must clearly and conspicuously inform the consumer and provide an opt-out mechanism.
Non-discrimination: may not discriminate against consumers who exercise their rights.
Processor contracts: before engaging processors, the controller must enter into contracts with specific requirements including processing instructions, confidentiality obligations, and subcontractor requirements.
Cookies that collect personal data or allow user identification fall within the UCPA's scope.
The site must display a clear cookie notice, provide an opt-out mechanism for targeted advertising and data sales, and describe in the privacy notice how consumers can exercise their rights.
Correct tag categorization is what makes it possible to identify which cookies constitute targeted advertising or data sales.
The UCPA defines targeted advertising in § 13-61-101(34) as ads selected based on data obtained from the consumer's activities over time and across non-affiliated websites or applications. Ads based on activities within the controller's own site do not qualify.
The UCPA does not require honoring the GPC. Unlike the CPRA (California) and CTDPA (Connecticut), the UCPA does not mention the obligation to honor universal opt-out signals such as the Global Privacy Control. However, implementing the GPC is a best practice that covers requirements in other jurisdictions.
Under Utah Code § 13-61-402, the Utah Attorney General has exclusive enforcement authority.
The process follows two stages:
Stage 1: the consumer files a complaint with the Division of Consumer Protection. The Division investigates and, if it finds substantial evidence of a violation, refers to the Attorney General.
Stage 2: the AG notifies the controller in writing, identifying violations and providing 30 guaranteed days to cure.
If the controller cures the violation within 30 days and provides a written statement that the violation has been cured and will not recur, no action is initiated.
If the violation continues or the controller breaches the provided statement, the AG may initiate action and recover:
Actual damages to the consumer.
Up to US$ 7,500 per violation.
The 30-day cure period is guaranteed permanently by the UCPA, unlike other laws such as the OCPA and CPRA that have eliminated the cure period. This makes UCPA enforcement more predictable for businesses.
AdOpt records every consent and opt-out interaction, blocks trackers before acceptance, and generates the auditable log needed in an Attorney General investigation.
The automatic scan identifies all active trackers on the site, feeding the data inventory required for the privacy notice. And when the law changes, the platform updates automatically.
Over 60,000 websites already run with AdOpt.
Privacy is not a banner. It is a position.
Ready to bring your website into compliance with the Utah UCPA? Talk to our team.
| Law | State | Threshold | Sensitive Data | Right to Correct | Cure Period | Effective Date |
|---|---|---|---|---|---|---|
| UCPA | Utah | US$ 25M + 100K or 25K + 50% | Opt-out (prior notice) | Not provided | 30 days guaranteed | Dec 2023 |
| OCPA | Oregon | 100K (excl. payments) or 25K + 25% | Opt-in (consent) | Provided | Eliminated (Jan 2026) | Jul 2024 |
| CTDPA | Connecticut | 100K (excl. payments) or 25K + 25% | Opt-in (consent) | Provided | Discretionary | Jul 2023 |
| VCDPA | Virginia | 100K or 25K + 50% | Opt-in (consent) | Provided | 30 days guaranteed | Jan 2023 |
| CPRA | California | US$ 25M or 100K or 50% | Opt-in + SPI limitation | Provided | Eliminated | Jan 2023 |
Compliance with the UCPA rests on three documents that have to agree with each other: the cookies policy, which declares every tracker and its purpose; the privacy policy, which explains what you do with the data; and the privacy portal, where the consumer exercises their rights and you keep the record of it.
1. What makes the UCPA different from other US state privacy laws?
The UCPA is the most business-friendly state privacy law among those approved in the US so far. Key differences: requires both US$ 25M revenue AND at least one volume threshold (dual requirement), while other laws use one or the other; uses opt-out for sensitive data, while most other laws require opt-in (consent); no right to correct data; no right to opt-out of profiling; and maintains a guaranteed 30-day cure period permanently, while other laws are eliminating that period.
2. Why does the UCPA use opt-out for sensitive data instead of opt-in?
The UCPA reflects the Utah legislature's philosophy of creating a law that protects consumers without creating excessive barriers for businesses. The opt-out model for sensitive data (Utah Code § 13-61-302(3)) requires the business to inform the consumer and give them the opportunity to refuse, but does not require active prior consent. This is significantly less restrictive than the consent standard required by the CPRA, OCPA, and other laws.
3. Does the UCPA have a right to correct inaccurate data?
No. This is one of the most notable absent rights in the UCPA. The law only guarantees four rights: confirm/access, deletion (limited to data provided by the consumer), portability, and opt-out from targeted advertising and data sales. Correction of inaccurate data is not among them, distinguishing the UCPA from the VCDPA, OCPA, CTDPA, and CPRA.
4. What does the limited deletion right in the UCPA mean?
The UCPA's deletion right (§ 13-61-201(2)) applies only to personal data the consumer provided to the controller. Data the controller obtained from other sources, such as data brokers, third-party lists, or inferences created from other data, do not need to be deleted under the UCPA. This is a significant difference from the OCPA and CTDPA, which require deletion of data from any source.
5. What is the penalty for UCPA non-compliance?
The Attorney General can recover actual consumer damages and up to US$ 7,500 per violation. Before initiating any action, the AG is required to notify the controller and grant 30 days to cure (§ 13-61-402(3)). This 30-day period is guaranteed permanently by the UCPA. If the controller cures the violation and provides a written statement, no action is initiated. There is no private right of action for consumers (§ 13-61-305).
Ready to bring your website into compliance with the Utah UCPA? Talk to our team.
Discover the 5 common **cookie consent mistakes** that risk your **compliance** and learn how to avoid heavy **fines**. Simplify your **data privacy** strategy using a reliable **[Cookie notice/banner](https://goadopt.io/en/blog/why-the-cookie-banner/)**.
What the Connecticut CTDPA requires from your Cookies Policy: opt-out link, opt-out preference signal from January 2025, 15-day consent revocation, teen protections, and targeted advertising definition.
Axeptio acquires Brazil's AdOpt, expanding global reach in consent management and LGPD compliance.
Learn the essential steps for creating GDPR-compliant cookie banners in 2025, ensuring user consent and privacy protection.
How does your website handle LGPD? What strategies does it use to comply with the General Data Protection Law? Have you thought about using a cookie notice but don't know if your site has cookies or if it's enough? If you can't answer these questions, be cautious! Your page may be exposed to fines and other sanctions.
LGPD is in effect. Despite that, there are still many companies ignoring it, but is that possible? How long can we ignore LGPD?
How to handle DSARs under the California CCPA/CPRA: 7 consumer rights, 45-day deadline, toll-free number required, 12-month lookback, private right of action for breaches, and CPPA enforcement.
Have you ever thought that your marketing agency could find a great business opportunity in LGPD? Well, unlike what many think, it brings changes that can accelerate the demand for the services of these companies.
Learn what your Privacy Policy must contain under the NHDPA. We break down the 8 mandatory elements and how to comply with New Hampshire's data privacy law.
The Colorado Consumer Privacy Act went into effect July 1, 2023 (CPA). CPA is a vital piece of legislation designed to protect the privacy of residents in Colorado. Understanding its requirements is essential for any business operating in the state. This act is all about giving control back to the consumers regarding their personal data. But what does this mean for you and your business, especially when it comes to managing cookies on your website?
Having a cookie banner on your brand's website has become indispensable for many. However, for e-commerce websites, it has practically become an obligation to have one. This is because this type of website has a technological composition in which cookies are a structural part. Login flow, items in the shopping cart, recommendation showcases, remarketing... Most of them rely on cookies.
California CPRA explained: CCPA vs CPRA timeline and key differences, sensitive personal information, sharing of data, CPPA enforcement, GPC requirement, and tripled penalties for minors.
Find out if the MTCDPA applies to your site, key compliance deadlines, and new rules for cookies and consent in Montana
Iowa ICDPA DSAR guide: 90-day response deadline, 45-day extension, 60-day appeal process, limited deletion scope, opt-out from data sales, targeted advertising disclosure requirement, and 90-day cure period.
Utah UCPA DSAR guide: four consumer rights, limited deletion scope, no right to correct, no formal appeal process, no opt-out of profiling, 45-day deadline, and the guaranteed 30-day cure period.
Learn what your MTCDPA Privacy Policy must include after Montana's SB 297 amendments from the conspicuous "privacy" hyperlink and last-updated date requirements to sale disclosures, minor protections, and how to keep your notice operationally aligned with your stack.
Your website have users accessing from Texas? So be ready… the Texas Data Privacy and Security Act is here to shake things up. Don't worry; we've got your back. This guide will walk you through everything you need to know to ensure your website complies with the new regulations.
A privacy policy is a document that outlines how an organization collects, uses, discloses, and manages a customer's data. It's essential for building trust with users and complying with legal requirements. However, if you're not familiar with it, don't worry as we're here to help you.
Here is a step-by-step explanation of how consent registration works in AdOpt.
The Texas Data Privacy and Security Act (TDPSA) introduces sweeping changes to how businesses collect, use, and disclose personal data—and your privacy policy is now a frontline compliance tool. This article is a comprehensive guide for any company serving Texas residents, explaining how to align your privacy practices with the new legal standards.
What is a DSAR under NHDPA? Complete guide to consumer rights, response deadlines, and building a compliant Privacy Portal for your site.
Learn how to build a defensible TIPA Cookies Policy for Tennessee compliance covering consent architecture, opt-out requirements, the NIST affirmative defense, and how your cookie banner, privacy notice, and vendor management must work together under the Tennessee Information Protection Act.
Everything you need to know about the Florida Digital Bill of Rights (FDBR): who must comply, the $1 billion threshold, 7 consumer rights, FIPA vs FDBR explained, penalties, and cookies.
What the Colorado CPA requires from your Cookies Policy: mandatory Universal Opt-Out Mechanism from July 2024, targeted advertising definition, dark pattern rules, and the 24-month consent refresh.
Everything about the Oregon OCPA: who must comply, the payment transaction exclusion, 25% revenue threshold, derived data in scope, GPC requirement from January 2026, and elimination of the cure period.
In this article, you will have a great introduction to the topic, as well as various other variations that revolve around the subject: Cookies and LGPD.
What the California CPRA requires from your Privacy Policy: SPI category, two mandatory links, data retention periods, sharing disclosure, right to correct, GPC, and minor protections.
What the Florida FDBR requires from your Cookies Policy: targeted advertising across affiliated sites, opt-out for sensitive data and voice recognition, dark patterns, and tripled penalties.
Google Consent Mode (GCM) is nothing more than a way for you to integrate the consent you collect from your visitors into Google technologies. In this way, upon receiving this consent information, collection can only occur with authorization, thus complying with the legislation and having direct evidence of compliance as defense for both you and Google.
Learn how to build a TIPA-compliant Privacy Portal for Tennessee. Understand DSAR deadlines, consumer rights, opt-out mechanisms, and the affirmative defense that sets TIPA apart from every other US state privacy law.
What the Florida FDBR requires from your Privacy Policy: annual updates, 6 mandatory content categories, specific notices for sensitive and biometric data sales, and the 7 consumer rights.
What the California CCPA/CPRA requires from your Privacy Policy: 12-month lookback, annual updates, Do Not Sell link, sensitive PI disclosures, toll-free number, and the 7 consumer rights.
What the Connecticut CTDPA requires from your Privacy Policy: active email contact, opt-out link, 15-day consent revocation, opt-out preference signal from January 2025, and teen protections.
What the Colorado CPA requires from your Privacy Policy: 5 mandatory elements, purpose specification duty, secondary use prohibition, 24-month consent refresh, and Universal Opt-Out Mechanism disclosure.
What the Oregon OCPA requires from your Cookies Policy: opt-out link, GPC from January 2026, opt-out without authentication, derived data in scope, teen protections, and the elimination of the cure period.
California CPRA DSAR guide: new rights to correct and limit SPI, opt-out without multiple steps, GPC as valid opt-out, 12-month minor rule, private right of action, and CPPA enforcement.
A CMP is a tool/platform used to manage the consent of up to millions of users so that a company can use the data of these users for its previously stated purposes.
If your website uses cookies and serves users in Texas, the Texas Data Privacy and Security Act (TDPSA) applies to you. This article breaks down exactly how cookies are treated under the law—and what your business must do to remain compliant and build user trust.
How to handle DSARs under the Virginia VCDPA: consumer rights, 45-day response deadlines, the appeal process, free requests twice per year, and how to build a compliant Privacy Portal.
In this article, we'll explore the GDPR foundations and provide practical insights from the basics to more advanced concepts of its legal basis.
How to handle DSARs under the Florida FDBR: 7 consumer rights, two required submission channels, 45-day deadline with only 15-day extension, tripled penalties for children, and compliance guide.
What the Iowa ICDPA requires from your Cookies Policy: opt-out for data sales and targeted advertising, opt-out model for sensitive data, no GPC requirement, no specific link text required, and the 90-day cure period.
It's time to talk about one of the most impactful tasks, both for the company and for the visitors of your websites: tag categorization. But why is it so impactful? What is the relevance of this configuration and how can it affect us? It is precisely because of these common questions we receive from our clients that we have written this article on best practices in tag categorization.
Rights, Policy and how to understand about the DSAR Montana MTCDPA
Despite cookies being more well-known, what is the main difference between cookies and session storage and local storage? Why choose one over the other? This article will help you with these doubts!
30 Jun 2025
Address: 7345 W Sand Lake Road, Ste 210 Office 5898 Orlando, FL 32819
15 Rue du Général Campredon, 34000 Montpellier, France
207 Rue de Bercy, 75012 Paris, France
EIN: 86-3965064
Phone: +1 (407) 768-3792
AdOpt
Resources
Product
Certifications