Core statute is in force, regulator identity and enforcement pathway are clearly documented and confirmed via primary regulator homepage and secondary legal-analysis sources.
Traffic-light rationale — GreenCore statute is in force, regulator identity and enforcement pathway are clearly documented and confirmed via primary regulator homepage and secondary legal-analysis sources.
Sub-modules (5)
Regulator And AuthorityGreen
The Division of Consumer Protection administers a consumer-complaint intake and investigation function; the Utah Attorney General holds exclusive enforcement authority over substantiated UCPA violations referred by the Division.
Claims (1):
The UCPA tasks the Division of Consumer Protection with administering a consumer-complaint system and investigating potential violations, with mandatory referral to the Attorney General where substantial evidence of a violation exists; the Attorney General holds exclusive enforcement authority.
Act And InstrumentsGreen
The UCPA (SB 227) was signed 24 March 2022 and took effect 31 December 2023, making Utah the fourth U.S. state with comprehensive consumer-privacy legislation.
Claims (1):
Governor Spencer Cox signed the Utah Consumer Privacy Act (SB 227) into law on 24 March 2022, making Utah the fourth U.S. state to enact comprehensive consumer-privacy legislation, effective 31 December 2023.
Material ScopeGreen
The UCPA applies to controllers/processors conducting business in or targeting Utah residents that meet a $25M+ annual revenue threshold combined with either 100,000+ consumers processed or 25,000+ consumers plus 50%+ revenue from data sales; it carries broad entity- and data-level exemptions (government, higher education, nonprofits, HIPAA/GLBA-covered entities, employment data).
Claims (2):
The UCPA applies to controllers/processors conducting business in Utah or targeting Utah residents with at least $25 million in annual revenue that either control/process personal data of 100,000+ consumers, or derive over 50% of gross revenue from personal-data sales and control/process data of 25,000+ consumers.
The UCPA exempts governmental entities and their contractors, institutions of higher education, nonprofit corporations, HIPAA-covered entities/business associates, and GLBA-regulated financial institutions, and excludes employment-context data and data governed by several named federal statutes.
Territorial ScopeGreen
Applicability is targeting-based (conducting business in Utah or directing products/services to Utah residents) rather than establishment-based, consistent with the Virginia-model comprehensive privacy laws.
Claims (1):
The UCPA applies to any controller or processor that conducts business in Utah or produces a product or service targeted to Utah residents, irrespective of the entity's place of establishment.
Regulator Registration And FilingRed
No evidence was found of a controller registration, licensing, or filing obligation with the Division of Consumer Protection or Attorney General under the UCPA.
Absence provenance: not recorded. Searched: Utah Consumer Privacy Act UCPA effective date enforcement Division of Consumer Protection, Utah Consumer Privacy Act 2024 amendments enforcement actions.
Category narrative66 words
Utah's data-protection landscape is anchored by the Utah Consumer Privacy Act (UCPA, SB 227), a comprehensive but business-friendly consumer-privacy statute enacted 24 March 2022 and effective 31 December 2023, enforced exclusively by the Utah Attorney General with a front-end complaint-triage role for the Division of Consumer Protection. There is no dedicated Utah data-protection authority equivalent to California's CPPA; enforcement authority sits with a generalist consumer-protection apparatus.
Sources and claims (5)
ConfirmedIAPP — The UCPA tasks the Division of Consumer Protection with administering a consumer-complaint system and investigating potential violations, with mandatory referral to the Attorney General where substantial evidence of a violation exists; the Attorney General holds exclusive enforcement authority.observed
ConfirmedDataGuidance — Governor Spencer Cox signed the Utah Consumer Privacy Act (SB 227) into law on 24 March 2022, making Utah the fourth U.S. state to enact comprehensive consumer-privacy legislation, effective 31 December 2023.observed
ConfirmedIAPP — The UCPA applies to controllers/processors conducting business in Utah or targeting Utah residents with at least $25 million in annual revenue that either control/process personal data of 100,000+ consumers, or derive over 50% of gross revenue from personal-data sales and control/process data of 25,000+ consumers.observed
ConfirmedIAPP — The UCPA exempts governmental entities and their contractors, institutions of higher education, nonprofit corporations, HIPAA-covered entities/business associates, and GLBA-regulated financial institutions, and excludes employment-context data and data governed by several named federal statutes.observed
ConfirmedIAPP — The UCPA applies to any controller or processor that conducts business in Utah or produces a product or service targeted to Utah residents, irrespective of the entity's place of establishment.observed
Traffic-light rationale — AmberA functioning notice/opt-out framework exists but lacks opt-in consent for sensitive categories, which is the norm among most peer state laws.
Sub-modules (4)
Lawful BasesAmber
No enumerated Article-6-style lawful-basis list exists; processing is generally permitted subject to notice and opt-out rights rather than an ex-ante lawful-basis test.
Claims (1):
Unlike the EU GDPR's enumerated lawful-basis model, the UCPA does not require a specific legal basis for general processing of personal data, relying instead on notice-and-opt-out rights for targeted advertising, sale, and sensitive-data processing.
Consent ThresholdsAmber
Affirmative (opt-in) consent under the UCPA is required only for processing personal data of consumers known to be under 13, aligned with COPPA; all other processing relies on notice/opt-out.
Claims (1):
Processing personal data of consumers known to be under age 13 requires verifiable parental consent consistent with COPPA; this is the only UCPA-regulated activity requiring affirmative opt-in consent.
Special CategoriesAmber
Sensitive data (a UCPA-defined category) is subject to a notice-and-opt-out standard rather than opt-in consent, a materially lighter-touch approach than Virginia, Colorado or Connecticut. Genetic data receives additional sector-specific protection via Utah's Genetic Testing Privacy Act.
Claims (2):
The UCPA does not require opt-in consent for processing sensitive data; controllers must instead provide clear notice and an opportunity to opt out before processing sensitive data, a lighter standard than Iowa aside, most WPA-model peer states.
Utah's genetic-privacy framework requires notice and a right to opt out for genetic-data processing, treating genetic information as a distinct sensitive category alongside the UCPA's general sensitive-data provisions.
Pseudonymisation And AnonymisationGreen
Consumer opt-out rights under the UCPA do not extend to properly de-identified or pseudonymous data meeting the Act's safe-harbour definition, consistent with the pattern shared by Colorado, Connecticut and Virginia.
Claims (1):
Consistent with Colorado, Connecticut and Virginia, Utah's opt-out rights for sale/targeted-advertising extend to pseudonymous data, unlike Iowa's narrower approach which excludes pseudonymous data from opt-out coverage.
Category narrative45 words
The UCPA does not adopt a GDPR-style enumerated lawful-basis regime; it instead relies on notice-and-opt-out mechanics for targeted advertising, sale, and sensitive-data processing, reserving opt-in consent solely for known under-13 processing (COPPA-aligned). This is materially weaker than Virginia's or Colorado's opt-in model for sensitive data.
Sources and claims (5)
ConfirmedIAPP — Unlike the EU GDPR's enumerated lawful-basis model, the UCPA does not require a specific legal basis for general processing of personal data, relying instead on notice-and-opt-out rights for targeted advertising, sale, and sensitive-data processing.observed
ConfirmedIAPP — Processing personal data of consumers known to be under age 13 requires verifiable parental consent consistent with COPPA; this is the only UCPA-regulated activity requiring affirmative opt-in consent.observed
ConfirmedIAPP — The UCPA does not require opt-in consent for processing sensitive data; controllers must instead provide clear notice and an opportunity to opt out before processing sensitive data, a lighter standard than Iowa aside, most WPA-model peer states.observed
ProbableIAPP — Utah's genetic-privacy framework requires notice and a right to opt out for genetic-data processing, treating genetic information as a distinct sensitive category alongside the UCPA's general sensitive-data provisions.observed
ProbableIAPP — Consistent with Colorado, Connecticut and Virginia, Utah's opt-out rights for sale/targeted-advertising extend to pseudonymous data, unlike Iowa's narrower approach which excludes pseudonymous data from opt-out coverage.observed
Core access/deletion/portability rights are confirmed in force, but the absence of correction and profiling opt-out rights represents a material gap relative to peer state laws.
Traffic-light rationale — AmberCore access/deletion/portability rights are confirmed in force, but the absence of correction and profiling opt-out rights represents a material gap relative to peer state laws.
Sub-modules (5)
Access RightGreen
Consumers have a statutory right of access to their personal data held by a controller.
Claims (1):
The UCPA establishes new consumer rights including the right of access, deletion, and portability, and the right to opt out of targeted advertising or the sale of personal data.
Rectification And ErasureAmber
A right to delete exists, but the UCPA notably omits a right to correct inaccuracies in personal data, unlike California, Virginia and Colorado.
Claims (1):
Notably absent from the UCPA is a right to correct inaccuracies in personal data, distinguishing it from California, Virginia and Colorado's comprehensive privacy laws.
Restriction And ObjectionAmber
Consumers may opt out of targeted advertising and sale of personal data, but the UCPA provides no right to opt out of profiling and does not require recognition of universal opt-out signals such as the Global Privacy Control.
Claims (1):
The UCPA provides consumers the right to opt out of processing for targeted advertising and sale of personal data, but the right to opt out of profiling is absent, and controllers are not required to recognize universal opt-out signals.
Data PortabilityGreen
A statutory data-portability right is included among the UCPA's core consumer rights.
Claims (1):
The UCPA establishes a consumer right to data portability.
Deadlines And Response WindowsGreen
Controllers must act on and respond to consumer requests within 45 days, extendable once by a further 45 days when reasonably necessary, with notice to the consumer and no fee for the initial request.
Claims (1):
Controllers must act on and inform consumers of the outcome of a rights request within 45 days, extendable once for a further 45 days if reasonably necessary, and generally may not charge a fee for the initial request.
Category narrative53 words
The UCPA grants Utah consumers rights of access, deletion, portability, and opt-out of targeted advertising/sale, but notably omits a right to correct inaccurate data, a right to opt out of profiling, and any obligation to honor universal opt-out signals — all present in Virginia/Colorado/California equivalents. Response deadlines (45+45 days) mirror the WPA-model standard.
Sources and claims (5)
ConfirmedDataGuidance — The UCPA establishes new consumer rights including the right of access, deletion, and portability, and the right to opt out of targeted advertising or the sale of personal data.observed
ConfirmedIAPP — Notably absent from the UCPA is a right to correct inaccuracies in personal data, distinguishing it from California, Virginia and Colorado's comprehensive privacy laws.observed
ConfirmedIAPP — The UCPA provides consumers the right to opt out of processing for targeted advertising and sale of personal data, but the right to opt out of profiling is absent, and controllers are not required to recognize universal opt-out signals.observed
ConfirmedDataGuidance — The UCPA establishes a consumer right to data portability.observed
ConfirmedDataGuidance — Controllers must act on and inform consumers of the outcome of a rights request within 45 days, extendable once for a further 45 days if reasonably necessary, and generally may not charge a fee for the initial request.observed
Security and breach-notification duties are confirmed and in force, but accountability tooling (DPIA, DPO, ROPA) that is standard among peer comprehensive privacy laws is absent from the UCPA.
Primary frameworkUtah Consumer Privacy Act (UCPA); Utah Protection of Personal Information Act; Utah Technology Governance Act
Traffic-light rationale — AmberSecurity and breach-notification duties are confirmed and in force, but accountability tooling (DPIA, DPO, ROPA) that is standard among peer comprehensive privacy laws is absent from the UCPA.
Sub-modules (7)
Accountability And DpiaAmber
The UCPA does not expressly provide for data protection or privacy impact assessment requirements, unlike Colorado, Connecticut and Virginia.
Claims (1):
The UCPA does not expressly provide for data protection or privacy impact assessment requirements.
Dpo RequirementsRed
No statutory requirement for controllers to appoint a data protection officer was identified in the UCPA text or secondary analysis reviewed.
Absence provenance: not recorded. Searched: Utah Consumer Privacy Act UCPA effective date enforcement Division of Consumer Protection, Utah Consumer Privacy Act sensitive data consent opt-in requirement definition.
Ropa RequirementsRed
No statutory records-of-processing (ROPA) obligation was identified for UCPA-covered controllers.
Absence provenance: not recorded. Searched: Utah Consumer Privacy Act UCPA effective date enforcement Division of Consumer Protection.
Joint Controller ArrangementsRed
No UCPA-specific joint-controller or processor-contract provisions were independently verified in this research pass beyond the general WPA-model pattern common to peer states.
Absence provenance: not recorded. Searched: Utah Consumer Privacy Act right to access delete opt out targeted advertising sale profiling.
Security MeasuresGreen
Controllers must establish, implement and maintain reasonable administrative, technical and physical data-security practices to protect personal data, mirroring the CCPA/VCDPA/CPA security standard.
Claims (1):
As with the CCPA, VCDPA and CPA, UCPA controllers must establish, implement, and maintain reasonable administrative, technical, and physical data security practices to protect the confidentiality of personal data.
Breach NotificationGreen
Breach notification is governed by Utah's Protection of Personal Information Act (separate from the UCPA), recently amended alongside the Utah Technology Governance Act; a 2019 amendment (SB 193) increased civil penalties for large breaches and set differentiated statutes of limitation.
Claims (2):
Utah lawmakers updated the Utah Protection of Personal Information Act and the Utah Technology Governance Act with amendments including data-breach notification requirements intended to coordinate state, local and federal cybersecurity efforts.
A 2019 amendment (SB 193) to Utah's breach-notification law permits civil penalties greater than $100,000 for breaches affecting 10,000 or more consumers and establishes five-year (civil) and ten-year (administrative) statutes of limitation for violations.
Retention And DisposalRed
No explicit UCPA-mandated data-retention limit or disposal obligation was identified in sources reviewed.
Absence provenance: not recorded. Searched: Utah Consumer Privacy Act UCPA effective date enforcement Division of Consumer Protection.
Category narrative56 words
The UCPA imposes a general security-practices obligation but expressly omits DPIA/privacy-impact-assessment, DPO-appointment, and ROPA requirements that are standard in Colorado, Connecticut and Virginia. Breach notification is governed by a separate statute (the Utah Protection of Personal Information Act), recently amended alongside the Utah Technology Governance Act, with civil-penalty and limitations provisions dating to a 2019 amendment.
Sources and claims (4)
ConfirmedDataGuidance — The UCPA does not expressly provide for data protection or privacy impact assessment requirements.observed
ConfirmedIAPP — As with the CCPA, VCDPA and CPA, UCPA controllers must establish, implement, and maintain reasonable administrative, technical, and physical data security practices to protect the confidentiality of personal data.observed
ProbableIAPP — Utah lawmakers updated the Utah Protection of Personal Information Act and the Utah Technology Governance Act with amendments including data-breach notification requirements intended to coordinate state, local and federal cybersecurity efforts.observed
ConfirmedDataGuidance — A 2019 amendment (SB 193) to Utah's breach-notification law permits civil penalties greater than $100,000 for breaches affecting 10,000 or more consumers and establishes five-year (civil) and ten-year (administrative) statutes of limitation for violations.observed
No comprehensive cross-border transfer regime exists at the Utah state level; this is a legitimate 'no regime' finding rather than a research gap.
Traffic-light rationale — RedNo comprehensive cross-border transfer regime exists at the Utah state level; this is a legitimate 'no regime' finding rather than a research gap.
Sub-modules (6)
Transfer MechanismsRed
State comprehensive consumer-privacy statutes such as the UCPA impose obligations centered on notices, minimization, sensitive-data handling and opt-out rights; they do not include cross-border transfer mechanisms analogous to GDPR Art. 44-49.
Claims (1):
State comprehensive consumer-privacy statutes generally impose obligations that revolve around privacy notices, data minimization and purpose limitation, sensitive personal information, data protection assessments, and universal opt-out mechanisms, rather than cross-border transfer regulation.
Adequacy ReceivedRed
Not applicable — Utah has no adequacy-recognition framework for inbound data flows.
Absence provenance: not recorded. Searched: Utah Consumer Privacy Act UCPA effective date enforcement Division of Consumer Protection.
Adequacy GrantedRed
Not applicable — Utah has no authority or mechanism to grant adequacy determinations to other regimes.
Absence provenance: not recorded. Searched: Utah Consumer Privacy Act UCPA effective date enforcement Division of Consumer Protection.
Sccs And BcrsRed
No SCC or BCR framework exists under the UCPA or Utah law generally.
Absence provenance: not recorded. Searched: Utah Consumer Privacy Act UCPA effective date enforcement Division of Consumer Protection.
Transfer Impact AssessmentRed
No transfer-impact-assessment obligation exists under the UCPA.
Absence provenance: not recorded. Searched: Utah Consumer Privacy Act UCPA effective date enforcement Division of Consumer Protection.
Data LocalisationRed
No data-localisation mandate exists under Utah law for personal data covered by the UCPA.
Absence provenance: not recorded. Searched: Utah Consumer Privacy Act UCPA effective date enforcement Division of Consumer Protection.
Category narrative44 words
As a U.S. state consumer-privacy statute, the UCPA contains no GDPR-style cross-border transfer regime: no adequacy mechanism (received or granted), no SCC/BCR framework, no transfer-impact-assessment requirement, and no data-localisation mandate. This module is structurally inapplicable to Utah's legal framework rather than a compliance gap.
Sources and claims (1)
ProbableIAPP — State comprehensive consumer-privacy statutes generally impose obligations that revolve around privacy notices, data minimization and purpose limitation, sensitive personal information, data protection assessments, and universal opt-out mechanisms, rather than cross-border transfer regulation.observed
Traffic-light rationale — GreenSectoral carve-outs are clearly and consistently documented across primary and secondary sources for the major federal overlays.
Sub-modules (7)
Financial Sector OverlayGreen
Financial institutions and data governed by Title V of the Gramm-Leach-Bliley Act are exempt from the UCPA, leaving GLBA as the operative privacy regime for Utah financial-sector personal data.
Claims (1):
The UCPA exempts financial institutions and data subject to Title V of the Gramm-Leach-Bliley Act of 1999 from its scope.
Health Sector OverlayGreen
HIPAA-covered entities/business associates and protected health information are excluded from UCPA scope, leaving HIPAA/HITECH as the operative regime for Utah health-sector data.
Claims (1):
The UCPA exempts HIPAA-covered entities and business associates, and excludes protected health information and related health-context data from its scope.
Telecoms And EprivacyAmber
Utah has no dedicated ePrivacy-style prior-consent regime for cookies/electronic communications; tracking-based advertising is instead governed through the UCPA's general opt-out-for-sale/targeted-advertising mechanism.
Claims (1):
Where a controller sells personal data to third parties or engages in targeted advertising, the UCPA requires clear and conspicuous disclosure of the means for consumers to opt out, functioning as Utah's principal mechanism for regulating tracking-based advertising in lieu of a dedicated ePrivacy-style consent regime.
Employment DataGreen
Personal data processed or maintained in the employment context, including job-applicant data, is excluded from UCPA coverage.
Claims (1):
Data processed or maintained in the course of employment, including job applicant data, is exempt from UCPA coverage.
Credit And ScoringGreen
Information subject to the federal Fair Credit Reporting Act is excluded from UCPA scope, leaving FCRA as the operative regime for Utah credit-reporting data.
Claims (1):
The UCPA excludes information subject to the federal Fair Credit Reporting Act from its material scope.
EducationGreen
Institutions of higher education are entity-exempt and FERPA-governed data is excluded from UCPA scope.
Claims (1):
The UCPA exempts institutions of higher education and excludes data subject to the federal Family Educational Rights and Privacy Act (FERPA) from its scope.
InsuranceGreen
Utah's Genetic Testing Privacy Act separately restricts insurers from requesting, requiring, or using genetic test results of asymptomatic individuals or blood relatives for underwriting, subject to enumerated exceptions.
Claims (1):
Utah's Genetic Testing Privacy Act restricts insurers from requesting, requiring, or otherwise considering genetic test results of an asymptomatic individual or blood relative for underwriting purposes, subject to enumerated exceptions.
Category narrative56 words
The UCPA's material scope carves out the principal U.S. federal sectoral regimes — GLBA for financial data, HIPAA/HITECH for health data, FCRA for credit-reporting data, and FERPA for education records — leaving those federal statutes as the operative regime in their respective sectors. A separate Genetic Testing Privacy Act restricts insurer use of genetic test results.
Sources and claims (7)
ConfirmedDataGuidance — The UCPA exempts financial institutions and data subject to Title V of the Gramm-Leach-Bliley Act of 1999 from its scope.observed
ConfirmedDataGuidance — The UCPA exempts HIPAA-covered entities and business associates, and excludes protected health information and related health-context data from its scope.observed
ConfirmedIAPP — Data processed or maintained in the course of employment, including job applicant data, is exempt from UCPA coverage.observed
ConfirmedIAPP — The UCPA excludes information subject to the federal Fair Credit Reporting Act from its material scope.observed
ConfirmedIAPP — The UCPA exempts institutions of higher education and excludes data subject to the federal Family Educational Rights and Privacy Act (FERPA) from its scope.observed
ProbableState of Utah / hosted via DataGuidance — Utah's Genetic Testing Privacy Act restricts insurers from requesting, requiring, or otherwise considering genetic test results of an asymptomatic individual or blood relative for underwriting purposes, subject to enumerated exceptions.observed
ProbableDataGuidance — Where a controller sells personal data to third parties or engages in targeted advertising, the UCPA requires clear and conspicuous disclosure of the means for consumers to opt out, functioning as Utah's principal mechanism for regulating tracking-based advertising in lieu of a dedicated ePrivacy-style consent regime.observed
Traffic-light rationale — AmberA functioning opt-out mechanism exists but is narrower than peer-state frameworks on signal recognition, dark patterns, and sale definition breadth.
Sub-modules (6)
Cookies And TrackersAmber
Cookie/tracker-based data sales or targeted advertising trigger a disclosure-and-opt-out obligation rather than a prior-consent requirement.
Claims (1):
Where a controller sells personal data to third parties or engages in targeted advertising, the UCPA requires clear and conspicuous disclosure of the means for consumers to opt out, functioning as Utah's principal mechanism for regulating tracking-based advertising in lieu of a dedicated ePrivacy-style consent regime.
Dark PatternsRed
No UCPA prohibition on dark patterns in obtaining consent or facilitating opt-outs was identified, unlike California and Colorado.
Absence provenance: not recorded. Searched: Utah Consumer Privacy Act right to access delete opt out targeted advertising sale profiling.
Opt Out SignalsAmber
Unlike the Colorado Privacy Act, the UCPA does not require controllers to recognize universal opt-out signals such as the Global Privacy Control.
Claims (1):
Unlike the Colorado Privacy Act, controllers subject to the UCPA are not required to recognize universal opt-out signals as a method for consumers to exercise their opt-out rights.
Clean Rooms And DcrRed
No UCPA provisions addressing data clean rooms or data-collaboration arrangements were identified.
Absence provenance: not recorded. Searched: Utah Consumer Privacy Act right to access delete opt out targeted advertising sale profiling.
Cross Context AdvertisingAmber
The UCPA defines 'sale' narrowly as an exchange of personal data for monetary consideration only, excluding non-monetary exchanges that would qualify as a 'sale' or 'share' under California's broader CCPA/CPRA framework.
Claims (1):
The UCPA contains a VCDPA-like definition of 'sale' limited to exchanges of personal data for monetary consideration, narrower than the CCPA/CPA definitions covering monetary or other valuable consideration.
Direct MarketingAmber
The UCPA's targeted-advertising opt-out right functions as Utah's principal direct-marketing control mechanism, absent a dedicated telemarketing/e-marketing consent statute within the Act itself.
Claims (1):
Consumers have the right to opt out of processing of personal data for targeted-advertising purposes under the UCPA, serving as Utah's principal statutory lever over direct-marketing-adjacent data use.
Category narrative43 words
The UCPA's adtech/commercial-privacy toolkit is limited to a notice-and-opt-out right for sale and targeted advertising, using a narrow monetary-only definition of 'sale.' The Act does not mandate recognition of universal opt-out signals (unlike Colorado), contains no dark-patterns prohibition, and has no clean-room/data-collaboration-room provisions.
Sources and claims (3)
ConfirmedIAPP — Unlike the Colorado Privacy Act, controllers subject to the UCPA are not required to recognize universal opt-out signals as a method for consumers to exercise their opt-out rights.observed
ConfirmedIAPP — The UCPA contains a VCDPA-like definition of 'sale' limited to exchanges of personal data for monetary consideration, narrower than the CCPA/CPA definitions covering monetary or other valuable consideration.observed
ProbableIAPP — Consumers have the right to opt out of processing of personal data for targeted-advertising purposes under the UCPA, serving as Utah's principal statutory lever over direct-marketing-adjacent data use.observed
Traffic-light rationale — AmberAI-specific legislation exists and is in force, but ADM transparency, profiling opt-out, and dedicated biometric protections are largely absent.
Sub-modules (6)
Profiling RestrictionsAmber
Unlike Virginia and Colorado, the UCPA does not provide consumers a right to opt out of profiling.
Claims (1):
Unlike the VCDPA and CPA, the right to opt out of profiling is absent from the UCPA.
Automated Decision Making TransparencyRed
No ADM-transparency or explanation-right provision analogous to GDPR Art. 22 was identified under the UCPA.
Absence provenance: not recorded. Searched: Utah AI Policy Act 2024 automated decision biometric law social media minors.
Ai Risk AssessmentsAmber
Utah's Artificial Intelligence Policy Act (2024) clarifies that existing consumer-protection and privacy laws apply to generative-AI uses, targeting the most harmful applications rather than mandating formal AI risk assessments as Colorado's risk-based model does.
Claims (1):
Utah's Artificial Intelligence Policy Act (2024) takes a simpler approach than risk-based AI statutes by clarifying that existing consumer-protection laws apply to generative AI, focused on defining and prohibiting the most harmful uses of AI rather than mandating formal risk assessments.
Biometric RegimeAmber
Biometric identifiers are likely captured within the UCPA's general 'sensitive data' category (subject to notice-and-opt-out) rather than governed by a dedicated biometric-specific statute analogous to Illinois' BIPA.
Claims (1):
Biometric data is understood to fall within the UCPA's general 'sensitive data' category, subject to the Act's notice-and-opt-out (rather than opt-in consent) regime, in the absence of a dedicated Utah biometric-specific statute analogous to Illinois' BIPA.
Genetic DataGreen
Utah's Genetic Testing Privacy Act restricts genetic testing, disclosure, and insurer use of genetic information, operating alongside the UCPA's sensitive-data notice-and-opt-out provisions for genetic data collected by commercial controllers.
Claims (1):
Utah's Genetic Testing Privacy Act (Utah Code Title 26, Chapter 45) restricts insurer requests for, or consideration of, genetic test results of asymptomatic individuals or their blood relatives.
State Surveillance CarveoutsAmber
The UCPA does not apply to government entities or contracted third parties acting on a government entity's behalf, functioning as a blanket exemption for state/local government data processing including surveillance-adjacent activity.
Claims (1):
The UCPA does not apply to government entities or third parties under contract with a government entity acting on that entity's behalf, providing a blanket carve-out from the state's consumer-privacy framework for government-related processing.
Category narrative81 words
The UCPA provides no right to opt out of profiling and no ADM-transparency/explanation right analogous to GDPR Art. 22. Utah's separate Artificial Intelligence Policy Act (2024) clarifies that existing consumer-protection and privacy law applies to generative-AI use cases, adopting a narrower approach than risk-based statutes like Colorado's. There is no dedicated Utah biometric-specific statute (unlike Illinois' BIPA); biometric identifiers are addressed only as part of the UCPA's general sensitive-data category. Genetic data is separately regulated under the Genetic Testing Privacy Act.
Sources and claims (5)
ConfirmedIAPP — Unlike the VCDPA and CPA, the right to opt out of profiling is absent from the UCPA.observed
ConfirmedIAPP — Utah's Artificial Intelligence Policy Act (2024) takes a simpler approach than risk-based AI statutes by clarifying that existing consumer-protection laws apply to generative AI, focused on defining and prohibiting the most harmful uses of AI rather than mandating formal risk assessments.observed
ProbableIAPP — Biometric data is understood to fall within the UCPA's general 'sensitive data' category, subject to the Act's notice-and-opt-out (rather than opt-in consent) regime, in the absence of a dedicated Utah biometric-specific statute analogous to Illinois' BIPA.observed
ConfirmedState of Utah / hosted via DataGuidance — Utah's Genetic Testing Privacy Act (Utah Code Title 26, Chapter 45) restricts insurer requests for, or consideration of, genetic test results of asymptomatic individuals or their blood relatives.observed
ConfirmedIAPP — The UCPA does not apply to government entities or third parties under contract with a government entity acting on that entity's behalf, providing a blanket carve-out from the state's consumer-privacy framework for government-related processing.observed
COPPA-aligned parental-consent baseline is solid, but the flagship minors' social-media protection is under active, unresolved federal litigation, materially weakening current enforceability.
Primary frameworkUtah Consumer Privacy Act (UCPA); Utah Minor Protection in Social Media Act (SB 194/HB 464)
Traffic-light rationale — AmberCOPPA-aligned parental-consent baseline is solid, but the flagship minors' social-media protection is under active, unresolved federal litigation, materially weakening current enforceability.
Sub-modules (5)
Age VerificationAmber
Utah's Minor Protection in Social Media Act (successor to the Social Media Regulation Act) addresses minors' access to algorithmically curated social media, but is under a federal injunction as of the last confirmed status (September 2024); current appellate/litigation status as of August 2026 was not independently reconfirmed in this pass.
Claims (1):
Utah repealed the Social Media Regulation Act in the face of technology-industry lawsuits and replaced it with the Minor Protection in Social Media Act (SB 194/HB 464), addressing algorithmic harms to minors; a federal district court partially enjoined the successor act's provisions in early September 2024 on First Amendment grounds.
Parental ConsentGreen
Controllers processing personal data of consumers known to be under 13 must obtain verifiable parental consent consistent with COPPA.
Claims (1):
Controllers processing the personal data of consumers known to be under the age of 13 are required to obtain verifiable parental consent and process such data in accordance with COPPA.
Minor Profiling BansAmber
Utah's social-media legislation created a private right of action for minors whose mental health has been harmed by an algorithmically driven social-media feature — a notable exception to Utah's general no-private-right-of-action posture, though enforceability is complicated by the pending federal injunction against the successor Act.
Claims (1):
Utah's replacement social-media law allows for a private right of action for minors whose mental health has been harmed by a social-media algorithm, one of the few private-right-of-action mechanisms in Utah's broader privacy/consumer-protection framework.
Education SettingsAmber
FERPA-governed education records and higher-education-institution data are excluded from UCPA scope; Utah has no additional UCPA-specific K-12/higher-education data-privacy overlay identified in this research pass.
Claims (1):
The UCPA excludes data subject to FERPA and exempts institutions of higher education, leaving federal education-privacy law as the operative regime for education-sector data not otherwise covered by Utah-specific minors' legislation.
Dependent AdultsRed
No Utah-specific statutory protection for dependent/vulnerable adults' personal data (elderly, mentally incapacitated) was identified within the UCPA or related state privacy statutes reviewed.
Absence provenance: not recorded. Searched: Utah Consumer Privacy Act right to access delete opt out targeted advertising sale profiling, Utah Consumer Privacy Act UCPA effective date enforcement Division of Consumer Protection.
Category narrative75 words
The UCPA aligns its under-13 parental-consent threshold with COPPA. Utah's more consequential minors' protections sit outside the UCPA in the Minor Protection in Social Media Act (SB 194/HB 464), which replaced the original Social Media Regulation Act but was preliminarily enjoined by a federal court in September 2024 on First Amendment grounds; that law also created a private right of action for minors harmed by addictive social-media algorithms. No Utah-specific dependent-adults data-protection provision was identified.
Sources and claims (4)
ConfirmedIAPP — Controllers processing the personal data of consumers known to be under the age of 13 are required to obtain verifiable parental consent and process such data in accordance with COPPA.observed
ConfirmedIAPP — Utah repealed the Social Media Regulation Act in the face of technology-industry lawsuits and replaced it with the Minor Protection in Social Media Act (SB 194/HB 464), addressing algorithmic harms to minors; a federal district court partially enjoined the successor act's provisions in early September 2024 on First Amendment grounds.observed
ProbableIAPP — Utah's replacement social-media law allows for a private right of action for minors whose mental health has been harmed by a social-media algorithm, one of the few private-right-of-action mechanisms in Utah's broader privacy/consumer-protection framework.observed
ProbableIAPP — The UCPA excludes data subject to FERPA and exempts institutions of higher education, leaving federal education-privacy law as the operative regime for education-sector data not otherwise covered by Utah-specific minors' legislation.observed
Enforcement powers and penalty ceilings are clearly defined and in force, but observable enforcement activity specific to Utah is low/opaque, and structural redress avenues for consumers (private right of action, collective redress) are largely foreclosed.
Traffic-light rationale — AmberEnforcement powers and penalty ceilings are clearly defined and in force, but observable enforcement activity specific to Utah is low/opaque, and structural redress avenues for consumers (private right of action, collective redress) are largely foreclosed.
Sub-modules (6)
Regulator Powers And PenaltiesGreen
The Attorney General has exclusive authority to enforce the UCPA, must give 30 days' written notice of alleged violations, and may seek injunctive relief and civil penalties of up to $7,500 per violation plus actual damages if a controller fails to cure.
Claims (1):
The Utah Attorney General must provide 30 days' written notice of alleged UCPA violations before initiating enforcement, and may seek an injunction and civil penalties of up to $7,500 per violation if the controller/processor fails to cure.
Enforcement Activity IndexAmber
Public enforcement activity specific to the UCPA was not identified in sources reviewed; broader 2024 multi-state tracking found only two final public state-comprehensive-privacy enforcement actions nationally, both by California, with most other states (implicitly including Utah) remaining in non-public cure-period activity.
Claims (1):
As of 2024, most U.S. state comprehensive privacy laws remained in non-public 'right to cure' enforcement phases, with only two final public state-comprehensive-privacy enforcement actions recorded that year, both brought by California's Attorney General.
Regulator Funding And CapacityRed
No data on the Division of Consumer Protection's budget or headcount specific to UCPA enforcement capacity was identified in this research pass.
Absence provenance: not recorded. Searched: Utah Attorney General UCPA enforcement action 2025 2026 fine.
Collective Redress And Class ActionsAmber
The UCPA does not allow a consumer to use a violation of the Act to support a claim under other Utah laws, foreclosing indirect class-action leverage via the UCPA itself.
Claims (1):
The UCPA does not allow a consumer to use a violation of the Act to support a claim under other Utah laws, limiting indirect collective-redress pathways.
Private Right Of ActionAmber
The UCPA does not provide consumers with a private right of action; enforcement runs exclusively through the Attorney General. (A narrow, statute-specific private right of action exists outside the UCPA under Utah's minors'/social-media legislation — see children_and_vulnerable_groups.)
Claims (1):
The UCPA does not provide consumers with a private right of action; the Utah Attorney General has exclusive authority to enforce its provisions.
Recent Developments 180DRed
No Utah-specific UCPA legislative amendment, enforcement action, or judicial ruling within the last 180 days (February-August 2026) was identified in the sources reviewed for this run.
Absence provenance: not recorded. Searched: Utah Attorney General UCPA enforcement action 2025 2026 fine, Utah Minor Protection Social Media Act injunction 2026 appeal status.
Category narrative91 words
The Utah Attorney General holds exclusive UCPA enforcement authority, subject to a mandatory 30-day cure period, with penalties capped at $7,500 per violation plus actual damages and available injunctive relief. There is no private right of action under the UCPA and no mechanism to bootstrap UCPA violations into other Utah-law claims. As of the most recent multi-state review available, Utah had not yet generated a final public UCPA enforcement action; most state comprehensive-privacy enforcement in 2024 remained in non-public cure-period stages, with only California generating final public enforcement actions that year.
Sources and claims (4)
ConfirmedDataGuidance — The Utah Attorney General must provide 30 days' written notice of alleged UCPA violations before initiating enforcement, and may seek an injunction and civil penalties of up to $7,500 per violation if the controller/processor fails to cure.observed
ProbableIAPP — As of 2024, most U.S. state comprehensive privacy laws remained in non-public 'right to cure' enforcement phases, with only two final public state-comprehensive-privacy enforcement actions recorded that year, both brought by California's Attorney General.observed
ConfirmedIAPP — The UCPA does not allow a consumer to use a violation of the Act to support a claim under other Utah laws, limiting indirect collective-redress pathways.observed
ConfirmedDataGuidance — The UCPA does not provide consumers with a private right of action; the Utah Attorney General has exclusive authority to enforce its provisions.observed
No categories match.
Filters combine as OR inside a group and AND across
groups.
Editorial metadata
Provenance only. Nothing below gates publication or affects the render.
Editorial metadata for United States – Utah
Field
Value
trust.lawyer_review.status
never_reviewed
trust.lawyer_review.reviewer
not recorded
trust.content_source
ai_generated
Provenance and declared absence
Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.
Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.
Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.
Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.
Suppressed by doctrine: derived risk score; derived_scores = {}.
Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-06. A year-precision row is never promoted into a tighter band.
Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 43 claim(s), 46 source(s) in the cumulative register.
GDPR article map
Cross-reference: which category/sub-module covers each UK GDPR article (38 mapped).
regulator_and_framework, data_subject_rights, sectoral_watch and enforcement_and_redress modules are well-supported by convergent T2 legal-analysis sources (IAPP, DataGuidance) plus one T1 regulator homepage and one T1 statute-text PDF (Genetic Testing Privacy Act). lawful_processing_and_special_data, controller_processor_duties, adtech_and_commercial_privacy, algorithmic_biometric_and_surveillance_governance and children_and_vulnerable_groups rely primarily on T2 secondary analysis with several sub-modules resolved as legitimate absences (no DPIA/DPO/ROPA, no dark-patterns rule, no dedicated biometric statute) rather than research gaps. cross_border_and_adequacy is a structural 'no regime' finding at the module level, consistent with US state consumer-privacy law generally lacking GDPR-style transfer mechanics. No direct fetch of the full Utah Code Title 13 Chapter 61 statutory text or the Utah AG/Division UCPA effectiveness report (due 1 July 2025) was performed in this pass; findings rely on convergent secondary legal-analysis sources plus targeted primary-source anchors (Division homepage, Genetic Testing Privacy Act text).
Unresolved questions (6):
Confirm current (August 2026) appellate/litigation status of the federal injunction against Utah's Minor Protection in Social Media Act (SB194/HB464).
Confirm exact effective date and current in-force text of the Utah Artificial Intelligence Policy Act following any 2025 amendments extending or altering its sunset/repeal provisions.
Obtain Utah Division of Consumer Protection budget/headcount data specific to UCPA enforcement capacity.
Confirm whether Utah has enacted a dedicated biometric-information-privacy statute since this research pass, given the UCPA's general sensitive-data treatment of biometric identifiers.
Verify whether the UCPA-mandated Attorney General/Division effectiveness report (due 1 July 2025) has been published, and whether it recommends amendments (e.g., DPIA, private right of action, universal opt-out signal recognition).
Confirm whether any UCPA-specific Attorney General enforcement action (settlement, fine, or injunction) has been publicly announced to date.