Utah wrote the state privacy law for people who did not want one: dual applicability gates that exempt most companies, opt-out (not consent) even for sensitive data, no assessments, no signals, and a cure period welded to the front of every enforcement action. Its significance is mostly comparative, it defines the floor of the American framework, and Iowa and a few later states built on its chassis. If your program satisfies Virginia, Utah is already done.
| Law | UCPA, Utah Code 13-61-101 et seq. |
|---|---|
| Effective | December 31, 2023 |
| Applies if | $25M+ revenue AND volume threshold (conjunctive) |
| Max penalty | $7,500 per violation, after mandatory 30-day cure |
| Regulator | Utah AG |
| Statute | Utah Code 13-61 |
What still has to be true in Utah
The notice must be accurate. Utah’s privacy-notice duty (categories, purposes, third-party sharing, rights mechanics) is enforceable on its own, and inaccurate notices are also FTC Act and state UDAP exposure. The recurring failure is unlisted ad-tech sharing, visible to anyone who reads the network tab.
Opt-outs must work. Targeted advertising and sale opt-outs need functioning intake and suppression even without GPC recognition. Since Colorado, Texas, and Connecticut mandate signal handling anyway, most controllers run one national GPC pipeline that over-complies here.
Security is unwaived. Reasonable administrative, technical, and physical safeguards, and Utah’s separate breach-notification statute (Utah Code 13-44) still applies with AG notice duties for larger incidents.
Watch the deltas, not the law. Utah rarely amends, but its exemptions do not travel: the same data flows may need consent in Colorado, assessments in Connecticut, and honoring GPC in Texas. The state comparison and multi-state strategy guide map where Utah’s floor diverges from everyone else’s requirements.
Verify the two things Utah does demand, honest notices and working opt-outs, against your site’s actual behavior with a free scan.