The Utah Consumer Privacy Act (UCPA, Utah Code § 13-61-101) is the most straightforward state privacy law in its Privacy Policy requirements.
This page covers one piece of the picture. For the full scope of the UCPA — who must comply, the thresholds, the consumer rights and the penalties — start with our complete guide to the UCPA and cookies.
No actively monitored contact channel like the OCPA requires. No mandatory retention periods like the CPRA. No detailed description of how each third party may process data like the OCPA requires. Five categories of information that must be in the document, and that is it.
But simple does not mean trivial. The law still requires real transparency about what is happening with Utah consumers' data.
This article focuses exclusively on what the UCPA requires from the Privacy Policy, based on the official text of the law.
The law uses the term "privacy notice." In practice, it is the Privacy Policy most sites already have.
Utah Code § 13-61-302(1)(a) requires the controller to provide consumers with a privacy notice that is "reasonably accessible and clear."
The notice must list the categories of personal data the controller processes (§ 13-61-302(1)(a)(i)).
Personal data under the UCPA is any information linked or reasonably linkable to an identified or identifiable individual. This includes identifiers such as name, email, IP address, browsing history, location data, and any data that allows tracking a person.
De-identified data, aggregated data, and publicly available information are excluded.
The notice must explain the purposes for which each category of data is processed (§ 13-61-302(1)(a)(ii)).
The UCPA does not explicitly list that purposes must be as specific as required by other laws like the VCDPA, but the requirement that the notice be "reasonably accessible and clear" implies that "improve services" is not sufficient. "Behavioral data to identify usability improvement opportunities" is the correct level.
The notice must describe how consumers can exercise the rights guaranteed by the UCPA (§ 13-61-302(1)(a)(iii)).
The four rights under the UCPA are:
Confirm and access: know whether the controller processes data and access that data.
Deletion: request deletion of data the consumer provided to the controller.
Portability: obtain a copy of the data in a portable format for transmission to another controller.
Opt-out: refuse processing for targeted advertising or data sales.
For each right, the notice must describe the request submission channel and the 45-day response deadline.
What the UCPA does not require to be described: a formal appeal process (the law has no such structured mechanism), a right to correct (the UCPA does not provide this right), and a right to opt-out of profiling (not covered by the law).
If the business shares data with third parties, the notice must list which categories of data are shared (§ 13-61-302(1)(a)(iv)).
This covers analytics tools, advertising platforms, CRMs, payment processors, and any external service that receives user data.
The UCPA uses the concept of "sale" of data, defined in § 13-61-101(31) as the exchange of personal data for monetary consideration to third parties. Sharing without monetary consideration does not constitute "sale" under the UCPA, unlike the CPRA which includes the concept of "sharing" for behavioral advertising even without payment.
Beyond the categories of data, the notice must identify the categories of third parties with whom data is shared (§ 13-61-302(1)(a)(v)).
Categories such as "audience analytics platforms," "marketing automation tools," and "payment processors" are valid examples.
The UCPA does not require the level of detail the OCPA demands (entity type and how each third party may process data). Identifiable categories are sufficient.
If the business sells data or uses data for targeted advertising, Utah Code § 13-61-302(1)(b) requires clear and conspicuous disclosure, along with the opt-out method.
Targeted advertising, per § 13-61-101(34), consists of ads selected based on data obtained from the consumer's activities over time and across non-affiliated websites or online applications. Ads based on activities within the controller's own site do not qualify.
If the site uses a Meta Pixel, Google Ads, or any pixel that sends data to external advertising networks, the business is operating targeted advertising and must disclose this explicitly.
This is the point that most differentiates the UCPA from other state laws. Utah Code § 13-61-302(3) requires that, before processing sensitive data, the controller:
Present the consumer with a clear notice; and
Offer the consumer the opportunity to opt out.
Prior consent is not required. The business may process sensitive data, provided it informs the consumer and gives them the option to refuse before starting.
Sensitive data under the UCPA includes: health and medical data, genetic and biometric data for identification, specific geolocation data, racial or ethnic origin, religious beliefs, sexual orientation, and citizenship or immigration status.
For data of known children (under 13), the business must comply with COPPA (§ 13-61-102(3)), which in practice requires verifiable parental consent.
The Privacy Policy must:
Identify whether the business processes sensitive data.
Describe how the sensitive data notice is presented to the consumer.
Explain how the consumer can exercise the opt-out from sensitive data processing.
For businesses that already have Privacy Policies written for other state laws, it is worth noting what the UCPA does not require:
No mandatory retention periods. The CPRA requires specifying how long each data category is retained. The UCPA has no such requirement.
No actively monitored contact channel. The OCPA requires an actively monitored email or online mechanism. The UCPA only requires the notice to describe how consumers can exercise their rights.
No detail about third parties. The OCPA requires describing how each third party may process data. The UCPA only requires categories.
No right to correct to describe. Since the UCPA does not provide this right, the policy does not need to describe it.
No formal appeal process. The UCPA has no structured appeal mechanism like the OCPA and CTDPA.
This makes the UCPA Privacy Policy the simplest to structure among current US state privacy laws.
Utah Code § 13-61-302(2) requires the controller to establish, implement, and maintain reasonable administrative, technical, and physical data security practices, proportionate to the size, scope, type, and volume of data processed.
The Privacy Policy should mention that the business implements appropriate security measures to protect consumers' personal data, even without needing to detail each specific measure.
Utah Code § 13-61-302(4) expressly prohibits the business from discriminating against consumers who exercise their rights. This includes denying goods or services, charging different prices, or offering different quality.
The exception is voluntary loyalty programs and situations where the consumer opted out of targeted advertising and the business adjusted the price accordingly, provided the price difference is reasonably related to the value the data provides the business.
The Privacy Policy must mention this non-discrimination policy.
Before initiating any action, the Utah Attorney General is required to notify the controller and grant 30 days to cure (§ 13-61-402(3)). This deadline is guaranteed permanently by the UCPA, unlike other laws that have eliminated it.
An outdated or incomplete Privacy Policy is one of the easiest violations to identify. Correcting it within 30 days after a notification is achievable with the right processes. But structuring the policy correctly from the start is always more efficient.
AdOpt ensures that what is written in the Policy has real correspondence with what actually happens on the site.
The automatic scan identifies all active technologies, feeding the list of data categories and third parties that must appear in the document. The consent management platform ensures the opt-out mechanism works as described.
Every interaction is logged. If the Attorney General requests evidence, the record is available.
Over 60,000 websites already run with AdOpt.
Privacy is not a banner. It is a position.
Want to build a Privacy Policy for your site that complies with the UCPA? Talk to our team.
Visible and accessible link on all pages of the site.
Categories of personal data processed, with sufficient description for the consumer to understand (§ 13-61-302(1)(a)(i)).
Purposes of processing for each category (§ 13-61-302(1)(a)(ii)).
How to exercise the 4 rights guaranteed by the UCPA: confirm/access, deletion, portability, opt-out, with channel and 45-day deadline (§ 13-61-302(1)(a)(iii)).
Categories of personal data shared with third parties, if any (§ 13-61-302(1)(a)(iv)).
Categories of third parties with whom data is shared (§ 13-61-302(1)(a)(v)).
Disclosure of targeted advertising or data sale with accessible opt-out (§ 13-61-302(1)(b)).
Sensitive data treatment: clear notice and opt-out opportunity before processing (§ 13-61-302(3)).
Children's data treatment: COPPA compliance for children under 13 (§ 13-61-102(3)).
Non-discrimination policy for consumers exercising rights (§ 13-61-302(4)).
Free service for the first request per 12-month period (§ 13-61-203(4)(a)).
1. Does the UCPA Privacy Policy need to specify data retention periods?
No. The UCPA does not require the Privacy Policy to specify how long each data category is retained. This distinguishes the UCPA from the CPRA, which requires this information explicitly. The UCPA only requires the policy to describe the categories of data processed and the purposes, without detailing retention periods.
2. Do I need to describe the right to correct in the UCPA Privacy Policy?
No. The UCPA does not guarantee the right to correct inaccurate data, unlike the CPRA, OCPA, VCDPA, and CTDPA. The policy only needs to describe the four rights the law actually guarantees: confirm/access, deletion (limited to data provided by the consumer), portability, and opt-out from targeted advertising and data sales.
3. How does the UCPA treat sensitive data differently from other state laws?
Utah Code § 13-61-302(3) requires only a clear notice and an opt-out opportunity before processing sensitive data. Laws like the CPRA, OCPA, VCDPA, and CTDPA require active prior consent (opt-in) for sensitive data. This difference is fundamental: under the UCPA, the business can process sensitive data unless the consumer actively refuses. Under the other laws, the business can only process with the consumer's active consent.
4. Does the UCPA Privacy Policy need to describe an appeal process?
No. The UCPA does not define a formal appeal process for when the controller denies a consumer request. Unlike the OCPA (45 days for appeal), CTDPA (60 days), and VCDPA (60 days), the UCPA has no such structured mechanism. The Policy only needs to describe the four rights and the request submission channel.
5. What happens if the Privacy Policy is incomplete when the Attorney General investigates?
The AG sends notification identifying violations and gives 30 days to cure (§ 13-61-402(3)). This 30-day period is guaranteed permanently by the UCPA. If the business corrects the Policy and provides a written statement that the violation has been cured and will not recur, no formal action is initiated. If not corrected or if the statement is breached, the AG may seek penalties of up to US$ 7,500 per violation. An outdated Policy is one of the easiest violations to identify and to correct.
Ready to build a Privacy Policy for your site that complies with the UCPA? Talk to our team.
Discover the 5 common **cookie consent mistakes** that risk your **compliance** and learn how to avoid heavy **fines**. Simplify your **data privacy** strategy using a reliable **[Cookie notice/banner](https://goadopt.io/en/blog/why-the-cookie-banner/)**.
What the Connecticut CTDPA requires from your Cookies Policy: opt-out link, opt-out preference signal from January 2025, 15-day consent revocation, teen protections, and targeted advertising definition.
Learn the essential steps for creating GDPR-compliant cookie banners in 2025, ensuring user consent and privacy protection.
How does your website handle LGPD? What strategies does it use to comply with the General Data Protection Law? Have you thought about using a cookie notice but don't know if your site has cookies or if it's enough? If you can't answer these questions, be cautious! Your page may be exposed to fines and other sanctions.
LGPD is in effect. Despite that, there are still many companies ignoring it, but is that possible? How long can we ignore LGPD?
How to handle DSARs under the California CCPA/CPRA: 7 consumer rights, 45-day deadline, toll-free number required, 12-month lookback, private right of action for breaches, and CPPA enforcement.
Have you ever thought that your marketing agency could find a great business opportunity in LGPD? Well, unlike what many think, it brings changes that can accelerate the demand for the services of these companies.
Learn what your Privacy Policy must contain under the NHDPA. We break down the 8 mandatory elements and how to comply with New Hampshire's data privacy law.
Having a cookie banner on your brand's website has become indispensable for many. However, for e-commerce websites, it has practically become an obligation to have one. This is because this type of website has a technological composition in which cookies are a structural part. Login flow, items in the shopping cart, recommendation showcases, remarketing... Most of them rely on cookies.
California CPRA explained: CCPA vs CPRA timeline and key differences, sensitive personal information, sharing of data, CPPA enforcement, GPC requirement, and tripled penalties for minors.
Find out if the MTCDPA applies to your site, key compliance deadlines, and new rules for cookies and consent in Montana
Iowa ICDPA DSAR guide: 90-day response deadline, 45-day extension, 60-day appeal process, limited deletion scope, opt-out from data sales, targeted advertising disclosure requirement, and 90-day cure period.
Utah UCPA DSAR guide: four consumer rights, limited deletion scope, no right to correct, no formal appeal process, no opt-out of profiling, 45-day deadline, and the guaranteed 30-day cure period.
Learn what your MTCDPA Privacy Policy must include after Montana's SB 297 amendments from the conspicuous "privacy" hyperlink and last-updated date requirements to sale disclosures, minor protections, and how to keep your notice operationally aligned with your stack.
A privacy policy is a document that outlines how an organization collects, uses, discloses, and manages a customer's data. It's essential for building trust with users and complying with legal requirements. However, if you're not familiar with it, don't worry as we're here to help you.
Here is a step-by-step explanation of how consent registration works in AdOpt.
The Texas Data Privacy and Security Act (TDPSA) introduces sweeping changes to how businesses collect, use, and disclose personal data—and your privacy policy is now a frontline compliance tool. This article is a comprehensive guide for any company serving Texas residents, explaining how to align your privacy practices with the new legal standards.
What is a DSAR under NHDPA? Complete guide to consumer rights, response deadlines, and building a compliant Privacy Portal for your site.
Learn how to build a defensible TIPA Cookies Policy for Tennessee compliance covering consent architecture, opt-out requirements, the NIST affirmative defense, and how your cookie banner, privacy notice, and vendor management must work together under the Tennessee Information Protection Act.
The Connecticut Data Privacy Act (CTDPA) is a state regulation designed to protect the privacy of Connecticut residents. It also regards cookies, so in this article we will help you understand all about this new privacy regulation.
Everything you need to know about the Florida Digital Bill of Rights (FDBR): who must comply, the $1 billion threshold, 7 consumer rights, FIPA vs FDBR explained, penalties, and cookies.
What the Colorado CPA requires from your Cookies Policy: mandatory Universal Opt-Out Mechanism from July 2024, targeted advertising definition, dark pattern rules, and the 24-month consent refresh.
Everything about the Oregon OCPA: who must comply, the payment transaction exclusion, 25% revenue threshold, derived data in scope, GPC requirement from January 2026, and elimination of the cure period.
In this article, you will have a great introduction to the topic, as well as various other variations that revolve around the subject: Cookies and LGPD.
What the California CPRA requires from your Privacy Policy: SPI category, two mandatory links, data retention periods, sharing disclosure, right to correct, GPC, and minor protections.
What the Florida FDBR requires from your Cookies Policy: targeted advertising across affiliated sites, opt-out for sensitive data and voice recognition, dark patterns, and tripled penalties.
Google Consent Mode (GCM) is nothing more than a way for you to integrate the consent you collect from your visitors into Google technologies. In this way, upon receiving this consent information, collection can only occur with authorization, thus complying with the legislation and having direct evidence of compliance as defense for both you and Google.
Learn how to build a TIPA-compliant Privacy Portal for Tennessee. Understand DSAR deadlines, consumer rights, opt-out mechanisms, and the affirmative defense that sets TIPA apart from every other US state privacy law.
The Colorado Consumer Privacy Act went into effect July 1, 2023 (CPA). CPA is a vital piece of legislation designed to protect the privacy of residents in Colorado. Understanding its requirements is essential for any business operating in the state. This act is all about giving control back to the consumers regarding their personal data. But what does this mean for you and your business, especially when it comes to managing cookies on your website?
What the Florida FDBR requires from your Privacy Policy: annual updates, 6 mandatory content categories, specific notices for sensitive and biometric data sales, and the 7 consumer rights.
What the California CCPA/CPRA requires from your Privacy Policy: 12-month lookback, annual updates, Do Not Sell link, sensitive PI disclosures, toll-free number, and the 7 consumer rights.
What the Connecticut CTDPA requires from your Privacy Policy: active email contact, opt-out link, 15-day consent revocation, opt-out preference signal from January 2025, and teen protections.
What the Colorado CPA requires from your Privacy Policy: 5 mandatory elements, purpose specification duty, secondary use prohibition, 24-month consent refresh, and Universal Opt-Out Mechanism disclosure.
Utah UCPA explained: the most business-friendly US state privacy law, dual threshold requirement, opt-out for sensitive data, no right to correct, guaranteed 30-day cure period, and key differences from other state laws.
What the Oregon OCPA requires from your Cookies Policy: opt-out link, GPC from January 2026, opt-out without authentication, derived data in scope, teen protections, and the elimination of the cure period.
California CPRA DSAR guide: new rights to correct and limit SPI, opt-out without multiple steps, GPC as valid opt-out, 12-month minor rule, private right of action, and CPPA enforcement.
Your website have users accessing from Texas? So be ready… the Texas Data Privacy and Security Act is here to shake things up. Don't worry; we've got your back. This guide will walk you through everything you need to know to ensure your website complies with the new regulations.
How to handle DSARs under the Virginia VCDPA: consumer rights, 45-day response deadlines, the appeal process, free requests twice per year, and how to build a compliant Privacy Portal.
In this article, we'll explore the GDPR foundations and provide practical insights from the basics to more advanced concepts of its legal basis.
How to handle DSARs under the Florida FDBR: 7 consumer rights, two required submission channels, 45-day deadline with only 15-day extension, tripled penalties for children, and compliance guide.
What the Iowa ICDPA requires from your Cookies Policy: opt-out for data sales and targeted advertising, opt-out model for sensitive data, no GPC requirement, no specific link text required, and the 90-day cure period.
It's time to talk about one of the most impactful tasks, both for the company and for the visitors of your websites: tag categorization. But why is it so impactful? What is the relevance of this configuration and how can it affect us? It is precisely because of these common questions we receive from our clients that we have written this article on best practices in tag categorization.
Rights, Policy and how to understand about the DSAR Montana MTCDPA
Despite cookies being more well-known, what is the main difference between cookies and session storage and local storage? Why choose one over the other? This article will help you with these doubts!
What the California CPRA requires from your Cookies Policy: the sharing concept, GPC as valid opt-out, Do Not Sell or Share link, SPI geolocation, minor protections, and retention periods.
09 Jun 2026
Address: 7345 W Sand Lake Road, Ste 210 Office 5898 Orlando, FL 32819
15 Rue du Général Campredon, 34000 Montpellier, France
207 Rue de Bercy, 75012 Paris, France
EIN: 86-3965064
Phone: +1 (407) 768-3792
AdOpt
Resources
Product
Certifications