Home
Utah UCPA and Cookies: All you need to know

Utah UCPA and Cookies: All you need to know

1 year ago
João Bruno Soares
16 minutes

Utah is the most business-friendly state in the US privacy landscape.

The Utah Consumer Privacy Act (UCPA), Utah Code § 13-61-101 et seq., took effect on December 31, 2023. It is the leanest state privacy law among those approved so far in the US, with fewer obligations for businesses and stronger protection for the traditional business model.

But "lean" does not mean ignorable. The US$ 25 million revenue threshold creates a well-defined scope, and the Utah Attorney General has exclusive enforcement authority.

What is the UCPA?

The Utah Consumer Privacy Act is Utah's state personal data protection law. It grants basic rights to state residents and creates obligations for businesses that process their data.

Enforcement follows a two-stage model: the Division of Consumer Protection receives and investigates consumer complaints. If it finds substantial evidence of a violation, it refers to the Utah Attorney General, who has exclusive authority to initiate enforcement actions.

There is no private right of action.

When did the UCPA take effect?

On December 31, 2023.

Who must comply with the UCPA?

Under Utah Code § 13-61-102(1), the law applies to controllers or processors that:

Conduct business in Utah or produce products or services targeted to state residents;

Have annual revenue of US$ 25,000,000 or more; and

Meet at least one of the following thresholds:

Control or process personal data of 100,000 or more consumers during a calendar year; or

Derive more than 50% of gross revenue from the sale of personal data and control or process personal data of 25,000 or more consumers.

The key differentiator from other laws: the UCPA requires the business to satisfy the US$ 25 million revenue requirement AND at least one of the volume thresholds. Other state laws use one or the other. Here both are needed. This significantly reduces the number of businesses in scope.

Understanding the distinction between controller and processor is fundamental to defining responsibilities in the processing chain.

UCPA Exemptions

Under Utah Code § 13-61-102(2), the following are exempt:

Government entities and third parties contracted on their behalf.

Native American tribes.

Institutions of higher education.

Nonprofit corporations.

HIPAA covered entities and business associates.

HIPAA-protected health information and related health data in specific situations.

Regulated clinical research data.

Consumer credit data regulated by the Fair Credit Reporting Act.

Financial institutions and data regulated by the Gramm-Leach-Bliley Act.

Data regulated by the Driver's Privacy Protection Act.

Data regulated by FERPA.

Data regulated by the Farm Credit Act.

Employee, job applicant, and independent contractor data in an employment context.

Data processed for purely personal or household purposes.

Air carriers.

What is personal data under the UCPA?

Under Utah Code § 13-61-101(24), personal data is any information linked or reasonably linkable to an identified individual or an identifiable individual.

Not personal data: de-identified data, aggregated data, and publicly available information.

The UCPA also defines pseudonymous data (§ 13-61-101(28)) as personal data that cannot be attributed to a specific individual without additional information kept separately and under appropriate technical and organizational measures. Pseudonymous data has limited protection under the UCPA.

What is sensitive data under the UCPA?

Under Utah Code § 13-61-101(32), sensitive data includes:

Personal data revealing racial or ethnic origin, religious beliefs, sexual orientation, citizenship or immigration status, or information about medical history, physical or mental health condition, or medical treatment or diagnosis.

Processing of genetic personal data or biometric data, where the processing is for the purpose of identifying a specific individual.

Specific geolocation data.

Note on the UCPA's sensitive data model: unlike the CPRA and several other state laws, the UCPA does not require consent to process sensitive data. It only requires the business to present a clear notice and offer an opt-out opportunity before processing. This is one of the aspects that makes the UCPA more business-friendly than other state laws.

For data of known children (under 13), businesses must comply with COPPA requirements (§ 13-61-102(3)).

What is specific geolocation data under the UCPA?

Under Utah Code § 13-61-101(33), specific geolocation data means information derived from technology, including GPS coordinates, that directly identifies an individual's specific location with a precision of 1,750 feet or less.

What are consumer rights under the UCPA?

Under Utah Code § 13-61-201, Utah residents have four rights:

Right to confirm and access: confirm whether the controller is processing personal data and access that data (§ 13-61-201(1)).

Right to deletion: request deletion of personal data the consumer provided to the controller. Note: the UCPA limits the deletion right to data the consumer provided. Data the controller obtained from other sources does not need to be deleted under the UCPA (§ 13-61-201(2)).

Right to portability: obtain a copy of the data in a portable format where technically feasible, for transmission to another controller without impediment (§ 13-61-201(3)).

Right to opt-out: refuse processing of personal data for targeted advertising or sale of personal data (§ 13-61-201(4)).

What the UCPA does not include compared to other laws

No right to correct inaccurate data. The UCPA does not guarantee this right, unlike the CPRA, OCPA, VCDPA, and CTDPA.

No right to opt-out of profiling. The UCPA covers only targeted advertising and data sales.

No formal structured appeal process. The law does not define an appeal process for controller denials.

Response deadlines for requests

Under Utah Code § 13-61-203:

45 days to respond from receipt of the request.

Extension of +45 days when reasonably necessary due to complexity or volume, with notification within the initial period.

Free for the first request from each consumer per 12-month period (§ 13-61-203(4)(a)).

From the second request in the same 12-month period, the business may charge a reasonable fee or refuse if the request is excessive, repetitive, technically infeasible, manifestly unfounded, or if the controller reasonably believes the primary purpose is not exercising a right.

Sensitive data: opt-out, not consent

This is one of the most important points of the UCPA for businesses already compliant with other laws.

Under Utah Code § 13-61-302(3), the controller may not process sensitive data collected from a consumer without first:

Presenting the consumer with a clear notice; and

Offering the consumer the opportunity to opt out of the processing.

This opt-out model for sensitive data is substantially less restrictive than the opt-in (prior consent) model required by the CPRA, OCPA, CTDPA, and VCDPA. Businesses already compliant with the more restrictive laws will automatically be compliant with the UCPA on this point.

Controller obligations under the UCPA

Under Utah Code § 13-61-302, the controller must:

Privacy notice: provide a reasonably accessible and clear privacy notice including: categories of personal data processed, purposes of processing, how consumers can exercise their rights, categories of data shared with third parties (if any), and categories of third parties with whom data is shared.

Data security: establish, implement, and maintain reasonable administrative, technical, and physical data security practices proportionate to the volume and nature of the data.

Disclosure of sale and targeted advertising: if the business sells data or uses data for targeted advertising, it must clearly and conspicuously inform the consumer and provide an opt-out mechanism.

Non-discrimination: may not discriminate against consumers who exercise their rights.

Processor contracts: before engaging processors, the controller must enter into contracts with specific requirements including processing instructions, confidentiality obligations, and subcontractor requirements.

Cookies and the UCPA

Cookies that collect personal data or allow user identification fall within the UCPA's scope.

The site must display a clear cookie notice, provide an opt-out mechanism for targeted advertising and data sales, and describe in the privacy notice how consumers can exercise their rights.

Correct tag categorization is what makes it possible to identify which cookies constitute targeted advertising or data sales.

The UCPA defines targeted advertising in § 13-61-101(34) as ads selected based on data obtained from the consumer's activities over time and across non-affiliated websites or applications. Ads based on activities within the controller's own site do not qualify.

The UCPA does not require honoring the GPC. Unlike the CPRA (California) and CTDPA (Connecticut), the UCPA does not mention the obligation to honor universal opt-out signals such as the Global Privacy Control. However, implementing the GPC is a best practice that covers requirements in other jurisdictions.

Enforcement and penalties

Under Utah Code § 13-61-402, the Utah Attorney General has exclusive enforcement authority.

The process follows two stages:

Stage 1: the consumer files a complaint with the Division of Consumer Protection. The Division investigates and, if it finds substantial evidence of a violation, refers to the Attorney General.

Stage 2: the AG notifies the controller in writing, identifying violations and providing 30 guaranteed days to cure.

If the controller cures the violation within 30 days and provides a written statement that the violation has been cured and will not recur, no action is initiated.

If the violation continues or the controller breaches the provided statement, the AG may initiate action and recover:

Actual damages to the consumer.

Up to US$ 7,500 per violation.

The 30-day cure period is guaranteed permanently by the UCPA, unlike other laws such as the OCPA and CPRA that have eliminated the cure period. This makes UCPA enforcement more predictable for businesses.

How AdOpt helps with the UCPA

AdOpt records every consent and opt-out interaction, blocks trackers before acceptance, and generates the auditable log needed in an Attorney General investigation.

The automatic scan identifies all active trackers on the site, feeding the data inventory required for the privacy notice. And when the law changes, the platform updates automatically.

Over 60,000 websites already run with AdOpt.

Privacy is not a banner. It is a position.

Ready to bring your website into compliance with the Utah UCPA? Talk to our team.

Comparing UCPA with other privacy laws

LawStateThresholdSensitive DataRight to CorrectCure PeriodEffective Date
UCPAUtahUS$ 25M + 100K or 25K + 50%Opt-out (prior notice)Not provided30 days guaranteedDec 2023
OCPAOregon100K (excl. payments) or 25K + 25%Opt-in (consent)ProvidedEliminated (Jan 2026)Jul 2024
CTDPAConnecticut100K (excl. payments) or 25K + 25%Opt-in (consent)ProvidedDiscretionaryJul 2023
VCDPAVirginia100K or 25K + 50%Opt-in (consent)Provided30 days guaranteedJan 2023
CPRACaliforniaUS$ 25M or 100K or 50%Opt-in + SPI limitationProvidedEliminatedJan 2023

The UCPA in practice: the three documents

Compliance with the UCPA rests on three documents that have to agree with each other: the cookies policy, which declares every tracker and its purpose; the privacy policy, which explains what you do with the data; and the privacy portal, where the consumer exercises their rights and you keep the record of it.

FAQ: Utah UCPA

1. What makes the UCPA different from other US state privacy laws?
The UCPA is the most business-friendly state privacy law among those approved in the US so far. Key differences: requires both US$ 25M revenue AND at least one volume threshold (dual requirement), while other laws use one or the other; uses opt-out for sensitive data, while most other laws require opt-in (consent); no right to correct data; no right to opt-out of profiling; and maintains a guaranteed 30-day cure period permanently, while other laws are eliminating that period.

2. Why does the UCPA use opt-out for sensitive data instead of opt-in?
The UCPA reflects the Utah legislature's philosophy of creating a law that protects consumers without creating excessive barriers for businesses. The opt-out model for sensitive data (Utah Code § 13-61-302(3)) requires the business to inform the consumer and give them the opportunity to refuse, but does not require active prior consent. This is significantly less restrictive than the consent standard required by the CPRA, OCPA, and other laws.

3. Does the UCPA have a right to correct inaccurate data?
No. This is one of the most notable absent rights in the UCPA. The law only guarantees four rights: confirm/access, deletion (limited to data provided by the consumer), portability, and opt-out from targeted advertising and data sales. Correction of inaccurate data is not among them, distinguishing the UCPA from the VCDPA, OCPA, CTDPA, and CPRA.

4. What does the limited deletion right in the UCPA mean?
The UCPA's deletion right (§ 13-61-201(2)) applies only to personal data the consumer provided to the controller. Data the controller obtained from other sources, such as data brokers, third-party lists, or inferences created from other data, do not need to be deleted under the UCPA. This is a significant difference from the OCPA and CTDPA, which require deletion of data from any source.

5. What is the penalty for UCPA non-compliance?
The Attorney General can recover actual consumer damages and up to US$ 7,500 per violation. Before initiating any action, the AG is required to notify the controller and grant 30 days to cure (§ 13-61-402(3)). This 30-day period is guaranteed permanently by the UCPA. If the controller cures the violation and provides a written statement, no action is initiated. There is no private right of action for consumers (§ 13-61-305).

Ready to bring your website into compliance with the Utah UCPA? Talk to our team.

Tags

CMP
Cookies
Privacy Policy
ucpa

Related posts

5 Common Cookie Consent Mistakes Hurting Your Compliance

Discover the 5 common **cookie consent mistakes** that risk your **compliance** and learn how to avoid heavy **fines**. Simplify your **data privacy** strategy using a reliable **[Cookie notice/banner](https://goadopt.io/en/blog/why-the-cookie-banner/)**.

AdOpt post

Connecticut CTDPA: Cookies Policy

What the Connecticut CTDPA requires from your Cookies Policy: opt-out link, opt-out preference signal from January 2025, 15-day consent revocation, teen protections, and targeted advertising definition.

AdOpt post

Axeptio Strengthens its International Expansion with the Acquisition of AdOpt

Axeptio acquires Brazil's AdOpt, expanding global reach in consent management and LGPD compliance.

AdOpt post

7 Steps to GDPR-Compliant Cookie Banners in 2025

Learn the essential steps for creating GDPR-compliant cookie banners in 2025, ensuring user consent and privacy protection.

AdOpt post

5 Signs Your Website Needs an Cookie Consent Strategy

How does your website handle LGPD? What strategies does it use to comply with the General Data Protection Law? Have you thought about using a cookie notice but don't know if your site has cookies or if it's enough? If you can't answer these questions, be cautious! Your page may be exposed to fines and other sanctions.

AdOpt post

How long can we ignore LGPD?

LGPD is in effect. Despite that, there are still many companies ignoring it, but is that possible? How long can we ignore LGPD?

AdOpt post

California CCPA: DSAR Privacy Portal

How to handle DSARs under the California CCPA/CPRA: 7 consumer rights, 45-day deadline, toll-free number required, 12-month lookback, private right of action for breaches, and CPPA enforcement.

AdOpt post

LGPD: An Opportunity for Digital Marketing Agencies!

Have you ever thought that your marketing agency could find a great business opportunity in LGPD? Well, unlike what many think, it brings changes that can accelerate the demand for the services of these companies.

AdOpt post

New Hampshire NHDPA: Privacy Policy

Learn what your Privacy Policy must contain under the NHDPA. We break down the 8 mandatory elements and how to comply with New Hampshire's data privacy law.

AdOpt post

Colorado CPA and Cookies: All You Need to Know

The Colorado Consumer Privacy Act went into effect July 1, 2023 (CPA). CPA is a vital piece of legislation designed to protect the privacy of residents in Colorado. Understanding its requirements is essential for any business operating in the state. This act is all about giving control back to the consumers regarding their personal data. But what does this mean for you and your business, especially when it comes to managing cookies on your website?

AdOpt post

The Impact of Cookie Banners on Your E-commerce - LGPD

Having a cookie banner on your brand's website has become indispensable for many. However, for e-commerce websites, it has practically become an obligation to have one. This is because this type of website has a technological composition in which cookies are a structural part. Login flow, items in the shopping cart, recommendation showcases, remarketing... Most of them rely on cookies.

AdOpt post

California CPRA and Cookies: All you need to know

California CPRA explained: CCPA vs CPRA timeline and key differences, sensitive personal information, sharing of data, CPPA enforcement, GPC requirement, and tripled penalties for minors.

AdOpt post

MTCDPA Montana and Cookies: All you need to know

Find out if the MTCDPA applies to your site, key compliance deadlines, and new rules for cookies and consent in Montana

AdOpt post

IOWA ICDPA: DSAR and Privacy Portal

Iowa ICDPA DSAR guide: 90-day response deadline, 45-day extension, 60-day appeal process, limited deletion scope, opt-out from data sales, targeted advertising disclosure requirement, and 90-day cure period.

AdOpt post

Utah UCPA: DSAR and Privacy Portal

Utah UCPA DSAR guide: four consumer rights, limited deletion scope, no right to correct, no formal appeal process, no opt-out of profiling, 45-day deadline, and the guaranteed 30-day cure period.

AdOpt post

Montana MTCDPA: Privacy Policy

Learn what your MTCDPA Privacy Policy must include after Montana's SB 297 amendments from the conspicuous "privacy" hyperlink and last-updated date requirements to sale disclosures, minor protections, and how to keep your notice operationally aligned with your stack.

AdOpt post

Texas TDPSA and Cookies: All You Need to Know

Your website have users accessing from Texas? So be ready… the Texas Data Privacy and Security Act is here to shake things up. Don't worry; we've got your back. This guide will walk you through everything you need to know to ensure your website complies with the new regulations.

AdOpt post

What is a privacy policy?

A privacy policy is a document that outlines how an organization collects, uses, discloses, and manages a customer's data. It's essential for building trust with users and complying with legal requirements. However, if you're not familiar with it, don't worry as we're here to help you.

AdOpt post

How does a cookie banner operate?

Here is a step-by-step explanation of how consent registration works in AdOpt.

AdOpt post

Texas TDPSA: Privacy Policy

The Texas Data Privacy and Security Act (TDPSA) introduces sweeping changes to how businesses collect, use, and disclose personal data—and your privacy policy is now a frontline compliance tool. This article is a comprehensive guide for any company serving Texas residents, explaining how to align your privacy practices with the new legal standards.

AdOpt post

New Hampshire NHDPA: DSAR Privacy Portal

What is a DSAR under NHDPA? Complete guide to consumer rights, response deadlines, and building a compliant Privacy Portal for your site.

AdOpt post

Tenesse TIPA: Cookies Policy

Learn how to build a defensible TIPA Cookies Policy for Tennessee compliance covering consent architecture, opt-out requirements, the NIST affirmative defense, and how your cookie banner, privacy notice, and vendor management must work together under the Tennessee Information Protection Act.

AdOpt post

Florida FDBR and Cookies: All You Need to Know

Everything you need to know about the Florida Digital Bill of Rights (FDBR): who must comply, the $1 billion threshold, 7 consumer rights, FIPA vs FDBR explained, penalties, and cookies.

AdOpt post

Colorado CPA: Cookies Policy

What the Colorado CPA requires from your Cookies Policy: mandatory Universal Opt-Out Mechanism from July 2024, targeted advertising definition, dark pattern rules, and the 24-month consent refresh.

AdOpt post

Oregon OCPA and Cookies: All You Need to Know

Everything about the Oregon OCPA: who must comply, the payment transaction exclusion, 25% revenue threshold, derived data in scope, GPC requirement from January 2026, and elimination of the cure period.

AdOpt post

LGPD and Cookies all do you need to know?

In this article, you will have a great introduction to the topic, as well as various other variations that revolve around the subject: Cookies and LGPD.

AdOpt post

California CPRA: Privacy Policy

What the California CPRA requires from your Privacy Policy: SPI category, two mandatory links, data retention periods, sharing disclosure, right to correct, GPC, and minor protections.

AdOpt post

Florida FDBR: Cookies Policy

What the Florida FDBR requires from your Cookies Policy: targeted advertising across affiliated sites, opt-out for sensitive data and voice recognition, dark patterns, and tripled penalties.

AdOpt post

Google Consent Mode: Beginner to Advanced Guide.

Google Consent Mode (GCM) is nothing more than a way for you to integrate the consent you collect from your visitors into Google technologies. In this way, upon receiving this consent information, collection can only occur with authorization, thus complying with the legislation and having direct evidence of compliance as defense for both you and Google.

AdOpt post

Tenesse TIPA: DSAR Privacy Portal

Learn how to build a TIPA-compliant Privacy Portal for Tennessee. Understand DSAR deadlines, consumer rights, opt-out mechanisms, and the affirmative defense that sets TIPA apart from every other US state privacy law.

AdOpt post

Florida FDBR: Privacy Policy

What the Florida FDBR requires from your Privacy Policy: annual updates, 6 mandatory content categories, specific notices for sensitive and biometric data sales, and the 7 consumer rights.

AdOpt post

California CCPA: Privacy Policy

What the California CCPA/CPRA requires from your Privacy Policy: 12-month lookback, annual updates, Do Not Sell link, sensitive PI disclosures, toll-free number, and the 7 consumer rights.

AdOpt post

Connecticut CTDPA: Privacy Policy

What the Connecticut CTDPA requires from your Privacy Policy: active email contact, opt-out link, 15-day consent revocation, opt-out preference signal from January 2025, and teen protections.

AdOpt post

Colorado CPA: Privacy Policy

What the Colorado CPA requires from your Privacy Policy: 5 mandatory elements, purpose specification duty, secondary use prohibition, 24-month consent refresh, and Universal Opt-Out Mechanism disclosure.

AdOpt post

Oregon OCPA: Cookies Policy

What the Oregon OCPA requires from your Cookies Policy: opt-out link, GPC from January 2026, opt-out without authentication, derived data in scope, teen protections, and the elimination of the cure period.

AdOpt post

California CPRA: DSAR and Privacy Portal

California CPRA DSAR guide: new rights to correct and limit SPI, opt-out without multiple steps, GPC as valid opt-out, 12-month minor rule, private right of action, and CPPA enforcement.

AdOpt post

What is a CMP (Consent Management Platform)?

A CMP is a tool/platform used to manage the consent of up to millions of users so that a company can use the data of these users for its previously stated purposes.

AdOpt post

Cookies and the TDPSA

If your website uses cookies and serves users in Texas, the Texas Data Privacy and Security Act (TDPSA) applies to you. This article breaks down exactly how cookies are treated under the law—and what your business must do to remain compliant and build user trust.

AdOpt post

Virginia VCDPA: DSAR Privacy Portal

How to handle DSARs under the Virginia VCDPA: consumer rights, 45-day response deadlines, the appeal process, free requests twice per year, and how to build a compliant Privacy Portal.

AdOpt post

GDPR Legal Basis: An Introduction

In this article, we'll explore the GDPR foundations and provide practical insights from the basics to more advanced concepts of its legal basis.

AdOpt post

Florida FDBR: DSAR Privacy Portal

How to handle DSARs under the Florida FDBR: 7 consumer rights, two required submission channels, 45-day deadline with only 15-day extension, tripled penalties for children, and compliance guide.

AdOpt post

IOWA ICDPA: Cookies Policy

What the Iowa ICDPA requires from your Cookies Policy: opt-out for data sales and targeted advertising, opt-out model for sensitive data, no GPC requirement, no specific link text required, and the 90-day cure period.

AdOpt post

Best practices in tag categorization

It's time to talk about one of the most impactful tasks, both for the company and for the visitors of your websites: tag categorization. But why is it so impactful? What is the relevance of this configuration and how can it affect us? It is precisely because of these common questions we receive from our clients that we have written this article on best practices in tag categorization.

AdOpt post

Montana MTCDPA: DSAR Policy

Rights, Policy and how to understand about the DSAR Montana MTCDPA

AdOpt post

What is the difference between cookies, local storage, and session storage?

Despite cookies being more well-known, what is the main difference between cookies and session storage and local storage? Why choose one over the other? This article will help you with these doubts!

AdOpt logoAdOpt logo

Address: 7345 W Sand Lake Road, Ste 210 Office 5898 Orlando, FL 32819

15 Rue du Général Campredon, 34000 Montpellier, France

207 Rue de Bercy, 75012 Paris, France

EIN: 86-3965064

Phone: +1 (407) 768-3792

AdOpt

Resources

Product

Certifications

Google CMP PartnerIAB Europe TCF Registered Vendor

© GO ADOPT, LLC since 2020 - Made by people who love🍪