🔒 Data Protection Regulatory Intelligence
GDPRI · dataprotection.gi
US-UT · run data-protection-2026-08-06 v13-gdpri-1.0.0
content: ai_generated 20 sources retrieved model claude-sonnet-5 ·

United States – Utah

US-UT schema gdpri-v2 trajectory: not recordedhybrid regimeoverlaps: FIM, WPM, AIC

Last updated · 10 categories · 43 claims · 20 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
43Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

No content recorded at this JID path.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Core statute is in force, regulator identity and enforcement pathway are clearly documented and confirmed via primary regulator homepage and secondary legal-analysis sources.

Primary frameworkUtah Consumer Privacy Act (UCPA), Utah Code Title 13, Chapter 61
Traffic-light rationale — GreenCore statute is in force, regulator identity and enforcement pathway are clearly documented and confirmed via primary regulator homepage and secondary legal-analysis sources.

Sub-modules (5)

Regulator And AuthorityGreen

The Division of Consumer Protection administers a consumer-complaint intake and investigation function; the Utah Attorney General holds exclusive enforcement authority over substantiated UCPA violations referred by the Division.

Claims (1):

  • The UCPA tasks the Division of Consumer Protection with administering a consumer-complaint system and investigating potential violations, with mandatory referral to the Attorney General where substantial evidence of a violation exists; the Attorney General holds exclusive enforcement authority.

Act And InstrumentsGreen

The UCPA (SB 227) was signed 24 March 2022 and took effect 31 December 2023, making Utah the fourth U.S. state with comprehensive consumer-privacy legislation.

Claims (1):

  • Governor Spencer Cox signed the Utah Consumer Privacy Act (SB 227) into law on 24 March 2022, making Utah the fourth U.S. state to enact comprehensive consumer-privacy legislation, effective 31 December 2023.

Material ScopeGreen

The UCPA applies to controllers/processors conducting business in or targeting Utah residents that meet a $25M+ annual revenue threshold combined with either 100,000+ consumers processed or 25,000+ consumers plus 50%+ revenue from data sales; it carries broad entity- and data-level exemptions (government, higher education, nonprofits, HIPAA/GLBA-covered entities, employment data).

Claims (2):

  • The UCPA applies to controllers/processors conducting business in Utah or targeting Utah residents with at least $25 million in annual revenue that either control/process personal data of 100,000+ consumers, or derive over 50% of gross revenue from personal-data sales and control/process data of 25,000+ consumers.
  • The UCPA exempts governmental entities and their contractors, institutions of higher education, nonprofit corporations, HIPAA-covered entities/business associates, and GLBA-regulated financial institutions, and excludes employment-context data and data governed by several named federal statutes.

Territorial ScopeGreen

Applicability is targeting-based (conducting business in Utah or directing products/services to Utah residents) rather than establishment-based, consistent with the Virginia-model comprehensive privacy laws.

Claims (1):

  • The UCPA applies to any controller or processor that conducts business in Utah or produces a product or service targeted to Utah residents, irrespective of the entity's place of establishment.

Regulator Registration And FilingRed

No evidence was found of a controller registration, licensing, or filing obligation with the Division of Consumer Protection or Attorney General under the UCPA.

Absence provenance: not recorded. Searched: Utah Consumer Privacy Act UCPA effective date enforcement Division of Consumer Protection, Utah Consumer Privacy Act 2024 amendments enforcement actions.

Category narrative66 words

Utah's data-protection landscape is anchored by the Utah Consumer Privacy Act (UCPA, SB 227), a comprehensive but business-friendly consumer-privacy statute enacted 24 March 2022 and effective 31 December 2023, enforced exclusively by the Utah Attorney General with a front-end complaint-triage role for the Division of Consumer Protection. There is no dedicated Utah data-protection authority equivalent to California's CPPA; enforcement authority sits with a generalist consumer-protection apparatus.

Sources and claims (5)
  1. ConfirmedIAPPThe UCPA tasks the Division of Consumer Protection with administering a consumer-complaint system and investigating potential violations, with mandatory referral to the Attorney General where substantial evidence of a violation exists; the Attorney General holds exclusive enforcement authority.observed
  2. ConfirmedDataGuidanceGovernor Spencer Cox signed the Utah Consumer Privacy Act (SB 227) into law on 24 March 2022, making Utah the fourth U.S. state to enact comprehensive consumer-privacy legislation, effective 31 December 2023.observed
  3. ConfirmedIAPPThe UCPA applies to controllers/processors conducting business in Utah or targeting Utah residents with at least $25 million in annual revenue that either control/process personal data of 100,000+ consumers, or derive over 50% of gross revenue from personal-data sales and control/process data of 25,000+ consumers.observed
  4. ConfirmedIAPPThe UCPA exempts governmental entities and their contractors, institutions of higher education, nonprofit corporations, HIPAA-covered entities/business associates, and GLBA-regulated financial institutions, and excludes employment-context data and data governed by several named federal statutes.observed
  5. ConfirmedIAPPThe UCPA applies to any controller or processor that conducts business in Utah or produces a product or service targeted to Utah residents, irrespective of the entity's place of establishment.observed

#

A functioning notice/opt-out framework exists but lacks opt-in consent for sensitive categories, which is the norm among most peer state laws.

Primary frameworkUtah Consumer Privacy Act (UCPA); Utah Genetic Testing Privacy Act (Utah Code Title 26, Ch. 45)
Traffic-light rationale — AmberA functioning notice/opt-out framework exists but lacks opt-in consent for sensitive categories, which is the norm among most peer state laws.

Sub-modules (4)

Lawful BasesAmber

No enumerated Article-6-style lawful-basis list exists; processing is generally permitted subject to notice and opt-out rights rather than an ex-ante lawful-basis test.

Claims (1):

  • Unlike the EU GDPR's enumerated lawful-basis model, the UCPA does not require a specific legal basis for general processing of personal data, relying instead on notice-and-opt-out rights for targeted advertising, sale, and sensitive-data processing.

Special CategoriesAmber

Sensitive data (a UCPA-defined category) is subject to a notice-and-opt-out standard rather than opt-in consent, a materially lighter-touch approach than Virginia, Colorado or Connecticut. Genetic data receives additional sector-specific protection via Utah's Genetic Testing Privacy Act.

Claims (2):

  • The UCPA does not require opt-in consent for processing sensitive data; controllers must instead provide clear notice and an opportunity to opt out before processing sensitive data, a lighter standard than Iowa aside, most WPA-model peer states.
  • Utah's genetic-privacy framework requires notice and a right to opt out for genetic-data processing, treating genetic information as a distinct sensitive category alongside the UCPA's general sensitive-data provisions.

Pseudonymisation And AnonymisationGreen

Consumer opt-out rights under the UCPA do not extend to properly de-identified or pseudonymous data meeting the Act's safe-harbour definition, consistent with the pattern shared by Colorado, Connecticut and Virginia.

Claims (1):

  • Consistent with Colorado, Connecticut and Virginia, Utah's opt-out rights for sale/targeted-advertising extend to pseudonymous data, unlike Iowa's narrower approach which excludes pseudonymous data from opt-out coverage.
Category narrative45 words

The UCPA does not adopt a GDPR-style enumerated lawful-basis regime; it instead relies on notice-and-opt-out mechanics for targeted advertising, sale, and sensitive-data processing, reserving opt-in consent solely for known under-13 processing (COPPA-aligned). This is materially weaker than Virginia's or Colorado's opt-in model for sensitive data.

Sources and claims (5)
  1. ConfirmedIAPPUnlike the EU GDPR's enumerated lawful-basis model, the UCPA does not require a specific legal basis for general processing of personal data, relying instead on notice-and-opt-out rights for targeted advertising, sale, and sensitive-data processing.observed
  2. ConfirmedIAPPProcessing personal data of consumers known to be under age 13 requires verifiable parental consent consistent with COPPA; this is the only UCPA-regulated activity requiring affirmative opt-in consent.observed
  3. ConfirmedIAPPThe UCPA does not require opt-in consent for processing sensitive data; controllers must instead provide clear notice and an opportunity to opt out before processing sensitive data, a lighter standard than Iowa aside, most WPA-model peer states.observed
  4. ProbableIAPPUtah's genetic-privacy framework requires notice and a right to opt out for genetic-data processing, treating genetic information as a distinct sensitive category alongside the UCPA's general sensitive-data provisions.observed
  5. ProbableIAPPConsistent with Colorado, Connecticut and Virginia, Utah's opt-out rights for sale/targeted-advertising extend to pseudonymous data, unlike Iowa's narrower approach which excludes pseudonymous data from opt-out coverage.observed

#

Core access/deletion/portability rights are confirmed in force, but the absence of correction and profiling opt-out rights represents a material gap relative to peer state laws.

Primary frameworkUtah Consumer Privacy Act (UCPA)
Traffic-light rationale — AmberCore access/deletion/portability rights are confirmed in force, but the absence of correction and profiling opt-out rights represents a material gap relative to peer state laws.

Sub-modules (5)

Access RightGreen

Consumers have a statutory right of access to their personal data held by a controller.

Claims (1):

  • The UCPA establishes new consumer rights including the right of access, deletion, and portability, and the right to opt out of targeted advertising or the sale of personal data.

Rectification And ErasureAmber

A right to delete exists, but the UCPA notably omits a right to correct inaccuracies in personal data, unlike California, Virginia and Colorado.

Claims (1):

  • Notably absent from the UCPA is a right to correct inaccuracies in personal data, distinguishing it from California, Virginia and Colorado's comprehensive privacy laws.

Restriction And ObjectionAmber

Consumers may opt out of targeted advertising and sale of personal data, but the UCPA provides no right to opt out of profiling and does not require recognition of universal opt-out signals such as the Global Privacy Control.

Claims (1):

  • The UCPA provides consumers the right to opt out of processing for targeted advertising and sale of personal data, but the right to opt out of profiling is absent, and controllers are not required to recognize universal opt-out signals.

Data PortabilityGreen

A statutory data-portability right is included among the UCPA's core consumer rights.

Claims (1):

  • The UCPA establishes a consumer right to data portability.

Deadlines And Response WindowsGreen

Controllers must act on and respond to consumer requests within 45 days, extendable once by a further 45 days when reasonably necessary, with notice to the consumer and no fee for the initial request.

Claims (1):

  • Controllers must act on and inform consumers of the outcome of a rights request within 45 days, extendable once for a further 45 days if reasonably necessary, and generally may not charge a fee for the initial request.
Category narrative53 words

The UCPA grants Utah consumers rights of access, deletion, portability, and opt-out of targeted advertising/sale, but notably omits a right to correct inaccurate data, a right to opt out of profiling, and any obligation to honor universal opt-out signals — all present in Virginia/Colorado/California equivalents. Response deadlines (45+45 days) mirror the WPA-model standard.

Sources and claims (5)
  1. ConfirmedDataGuidanceThe UCPA establishes new consumer rights including the right of access, deletion, and portability, and the right to opt out of targeted advertising or the sale of personal data.observed
  2. ConfirmedIAPPNotably absent from the UCPA is a right to correct inaccuracies in personal data, distinguishing it from California, Virginia and Colorado's comprehensive privacy laws.observed
  3. ConfirmedIAPPThe UCPA provides consumers the right to opt out of processing for targeted advertising and sale of personal data, but the right to opt out of profiling is absent, and controllers are not required to recognize universal opt-out signals.observed
  4. ConfirmedDataGuidanceThe UCPA establishes a consumer right to data portability.observed
  5. ConfirmedDataGuidanceControllers must act on and inform consumers of the outcome of a rights request within 45 days, extendable once for a further 45 days if reasonably necessary, and generally may not charge a fee for the initial request.observed

#

Security and breach-notification duties are confirmed and in force, but accountability tooling (DPIA, DPO, ROPA) that is standard among peer comprehensive privacy laws is absent from the UCPA.

Primary frameworkUtah Consumer Privacy Act (UCPA); Utah Protection of Personal Information Act; Utah Technology Governance Act
Traffic-light rationale — AmberSecurity and breach-notification duties are confirmed and in force, but accountability tooling (DPIA, DPO, ROPA) that is standard among peer comprehensive privacy laws is absent from the UCPA.

Sub-modules (7)

Accountability And DpiaAmber

The UCPA does not expressly provide for data protection or privacy impact assessment requirements, unlike Colorado, Connecticut and Virginia.

Claims (1):

  • The UCPA does not expressly provide for data protection or privacy impact assessment requirements.

Dpo RequirementsRed

No statutory requirement for controllers to appoint a data protection officer was identified in the UCPA text or secondary analysis reviewed.

Absence provenance: not recorded. Searched: Utah Consumer Privacy Act UCPA effective date enforcement Division of Consumer Protection, Utah Consumer Privacy Act sensitive data consent opt-in requirement definition.

Ropa RequirementsRed

No statutory records-of-processing (ROPA) obligation was identified for UCPA-covered controllers.

Absence provenance: not recorded. Searched: Utah Consumer Privacy Act UCPA effective date enforcement Division of Consumer Protection.

Joint Controller ArrangementsRed

No UCPA-specific joint-controller or processor-contract provisions were independently verified in this research pass beyond the general WPA-model pattern common to peer states.

Absence provenance: not recorded. Searched: Utah Consumer Privacy Act right to access delete opt out targeted advertising sale profiling.

Security MeasuresGreen

Controllers must establish, implement and maintain reasonable administrative, technical and physical data-security practices to protect personal data, mirroring the CCPA/VCDPA/CPA security standard.

Claims (1):

  • As with the CCPA, VCDPA and CPA, UCPA controllers must establish, implement, and maintain reasonable administrative, technical, and physical data security practices to protect the confidentiality of personal data.

Breach NotificationGreen

Breach notification is governed by Utah's Protection of Personal Information Act (separate from the UCPA), recently amended alongside the Utah Technology Governance Act; a 2019 amendment (SB 193) increased civil penalties for large breaches and set differentiated statutes of limitation.

Claims (2):

  • Utah lawmakers updated the Utah Protection of Personal Information Act and the Utah Technology Governance Act with amendments including data-breach notification requirements intended to coordinate state, local and federal cybersecurity efforts.
  • A 2019 amendment (SB 193) to Utah's breach-notification law permits civil penalties greater than $100,000 for breaches affecting 10,000 or more consumers and establishes five-year (civil) and ten-year (administrative) statutes of limitation for violations.

Retention And DisposalRed

No explicit UCPA-mandated data-retention limit or disposal obligation was identified in sources reviewed.

Absence provenance: not recorded. Searched: Utah Consumer Privacy Act UCPA effective date enforcement Division of Consumer Protection.

Category narrative56 words

The UCPA imposes a general security-practices obligation but expressly omits DPIA/privacy-impact-assessment, DPO-appointment, and ROPA requirements that are standard in Colorado, Connecticut and Virginia. Breach notification is governed by a separate statute (the Utah Protection of Personal Information Act), recently amended alongside the Utah Technology Governance Act, with civil-penalty and limitations provisions dating to a 2019 amendment.

Sources and claims (4)
  1. ConfirmedDataGuidanceThe UCPA does not expressly provide for data protection or privacy impact assessment requirements.observed
  2. ConfirmedIAPPAs with the CCPA, VCDPA and CPA, UCPA controllers must establish, implement, and maintain reasonable administrative, technical, and physical data security practices to protect the confidentiality of personal data.observed
  3. ProbableIAPPUtah lawmakers updated the Utah Protection of Personal Information Act and the Utah Technology Governance Act with amendments including data-breach notification requirements intended to coordinate state, local and federal cybersecurity efforts.observed
  4. ConfirmedDataGuidanceA 2019 amendment (SB 193) to Utah's breach-notification law permits civil penalties greater than $100,000 for breaches affecting 10,000 or more consumers and establishes five-year (civil) and ten-year (administrative) statutes of limitation for violations.observed

#

No comprehensive cross-border transfer regime exists at the Utah state level; this is a legitimate 'no regime' finding rather than a research gap.

Traffic-light rationale — RedNo comprehensive cross-border transfer regime exists at the Utah state level; this is a legitimate 'no regime' finding rather than a research gap.

Sub-modules (6)

Transfer MechanismsRed

State comprehensive consumer-privacy statutes such as the UCPA impose obligations centered on notices, minimization, sensitive-data handling and opt-out rights; they do not include cross-border transfer mechanisms analogous to GDPR Art. 44-49.

Claims (1):

  • State comprehensive consumer-privacy statutes generally impose obligations that revolve around privacy notices, data minimization and purpose limitation, sensitive personal information, data protection assessments, and universal opt-out mechanisms, rather than cross-border transfer regulation.

Adequacy ReceivedRed

Not applicable — Utah has no adequacy-recognition framework for inbound data flows.

Absence provenance: not recorded. Searched: Utah Consumer Privacy Act UCPA effective date enforcement Division of Consumer Protection.

Adequacy GrantedRed

Not applicable — Utah has no authority or mechanism to grant adequacy determinations to other regimes.

Absence provenance: not recorded. Searched: Utah Consumer Privacy Act UCPA effective date enforcement Division of Consumer Protection.

Sccs And BcrsRed

No SCC or BCR framework exists under the UCPA or Utah law generally.

Absence provenance: not recorded. Searched: Utah Consumer Privacy Act UCPA effective date enforcement Division of Consumer Protection.

Transfer Impact AssessmentRed

No transfer-impact-assessment obligation exists under the UCPA.

Absence provenance: not recorded. Searched: Utah Consumer Privacy Act UCPA effective date enforcement Division of Consumer Protection.

Data LocalisationRed

No data-localisation mandate exists under Utah law for personal data covered by the UCPA.

Absence provenance: not recorded. Searched: Utah Consumer Privacy Act UCPA effective date enforcement Division of Consumer Protection.

Category narrative44 words

As a U.S. state consumer-privacy statute, the UCPA contains no GDPR-style cross-border transfer regime: no adequacy mechanism (received or granted), no SCC/BCR framework, no transfer-impact-assessment requirement, and no data-localisation mandate. This module is structurally inapplicable to Utah's legal framework rather than a compliance gap.

Sources and claims (1)
  1. ProbableIAPPState comprehensive consumer-privacy statutes generally impose obligations that revolve around privacy notices, data minimization and purpose limitation, sensitive personal information, data protection assessments, and universal opt-out mechanisms, rather than cross-border transfer regulation.observed

#

Sectoral carve-outs are clearly and consistently documented across primary and secondary sources for the major federal overlays.

Primary frameworkUtah Consumer Privacy Act (UCPA); Utah Genetic Testing Privacy Act
Traffic-light rationale — GreenSectoral carve-outs are clearly and consistently documented across primary and secondary sources for the major federal overlays.

Sub-modules (7)

Financial Sector OverlayGreen

Financial institutions and data governed by Title V of the Gramm-Leach-Bliley Act are exempt from the UCPA, leaving GLBA as the operative privacy regime for Utah financial-sector personal data.

Claims (1):

  • The UCPA exempts financial institutions and data subject to Title V of the Gramm-Leach-Bliley Act of 1999 from its scope.

Health Sector OverlayGreen

HIPAA-covered entities/business associates and protected health information are excluded from UCPA scope, leaving HIPAA/HITECH as the operative regime for Utah health-sector data.

Claims (1):

  • The UCPA exempts HIPAA-covered entities and business associates, and excludes protected health information and related health-context data from its scope.

Telecoms And EprivacyAmber

Utah has no dedicated ePrivacy-style prior-consent regime for cookies/electronic communications; tracking-based advertising is instead governed through the UCPA's general opt-out-for-sale/targeted-advertising mechanism.

Claims (1):

  • Where a controller sells personal data to third parties or engages in targeted advertising, the UCPA requires clear and conspicuous disclosure of the means for consumers to opt out, functioning as Utah's principal mechanism for regulating tracking-based advertising in lieu of a dedicated ePrivacy-style consent regime.

Employment DataGreen

Personal data processed or maintained in the employment context, including job-applicant data, is excluded from UCPA coverage.

Claims (1):

  • Data processed or maintained in the course of employment, including job applicant data, is exempt from UCPA coverage.

Credit And ScoringGreen

Information subject to the federal Fair Credit Reporting Act is excluded from UCPA scope, leaving FCRA as the operative regime for Utah credit-reporting data.

Claims (1):

  • The UCPA excludes information subject to the federal Fair Credit Reporting Act from its material scope.

EducationGreen

Institutions of higher education are entity-exempt and FERPA-governed data is excluded from UCPA scope.

Claims (1):

  • The UCPA exempts institutions of higher education and excludes data subject to the federal Family Educational Rights and Privacy Act (FERPA) from its scope.

InsuranceGreen

Utah's Genetic Testing Privacy Act separately restricts insurers from requesting, requiring, or using genetic test results of asymptomatic individuals or blood relatives for underwriting, subject to enumerated exceptions.

Claims (1):

  • Utah's Genetic Testing Privacy Act restricts insurers from requesting, requiring, or otherwise considering genetic test results of an asymptomatic individual or blood relative for underwriting purposes, subject to enumerated exceptions.
Category narrative56 words

The UCPA's material scope carves out the principal U.S. federal sectoral regimes — GLBA for financial data, HIPAA/HITECH for health data, FCRA for credit-reporting data, and FERPA for education records — leaving those federal statutes as the operative regime in their respective sectors. A separate Genetic Testing Privacy Act restricts insurer use of genetic test results.

Sources and claims (7)
  1. ConfirmedDataGuidanceThe UCPA exempts financial institutions and data subject to Title V of the Gramm-Leach-Bliley Act of 1999 from its scope.observed
  2. ConfirmedDataGuidanceThe UCPA exempts HIPAA-covered entities and business associates, and excludes protected health information and related health-context data from its scope.observed
  3. ConfirmedIAPPData processed or maintained in the course of employment, including job applicant data, is exempt from UCPA coverage.observed
  4. ConfirmedIAPPThe UCPA excludes information subject to the federal Fair Credit Reporting Act from its material scope.observed
  5. ConfirmedIAPPThe UCPA exempts institutions of higher education and excludes data subject to the federal Family Educational Rights and Privacy Act (FERPA) from its scope.observed
  6. ProbableState of Utah / hosted via DataGuidanceUtah's Genetic Testing Privacy Act restricts insurers from requesting, requiring, or otherwise considering genetic test results of an asymptomatic individual or blood relative for underwriting purposes, subject to enumerated exceptions.observed
  7. ProbableDataGuidanceWhere a controller sells personal data to third parties or engages in targeted advertising, the UCPA requires clear and conspicuous disclosure of the means for consumers to opt out, functioning as Utah's principal mechanism for regulating tracking-based advertising in lieu of a dedicated ePrivacy-style consent regime.observed

#

A functioning opt-out mechanism exists but is narrower than peer-state frameworks on signal recognition, dark patterns, and sale definition breadth.

Primary frameworkUtah Consumer Privacy Act (UCPA)
Traffic-light rationale — AmberA functioning opt-out mechanism exists but is narrower than peer-state frameworks on signal recognition, dark patterns, and sale definition breadth.

Sub-modules (6)

Cookies And TrackersAmber

Cookie/tracker-based data sales or targeted advertising trigger a disclosure-and-opt-out obligation rather than a prior-consent requirement.

Claims (1):

  • Where a controller sells personal data to third parties or engages in targeted advertising, the UCPA requires clear and conspicuous disclosure of the means for consumers to opt out, functioning as Utah's principal mechanism for regulating tracking-based advertising in lieu of a dedicated ePrivacy-style consent regime.

Dark PatternsRed

No UCPA prohibition on dark patterns in obtaining consent or facilitating opt-outs was identified, unlike California and Colorado.

Absence provenance: not recorded. Searched: Utah Consumer Privacy Act right to access delete opt out targeted advertising sale profiling.

Opt Out SignalsAmber

Unlike the Colorado Privacy Act, the UCPA does not require controllers to recognize universal opt-out signals such as the Global Privacy Control.

Claims (1):

  • Unlike the Colorado Privacy Act, controllers subject to the UCPA are not required to recognize universal opt-out signals as a method for consumers to exercise their opt-out rights.

Clean Rooms And DcrRed

No UCPA provisions addressing data clean rooms or data-collaboration arrangements were identified.

Absence provenance: not recorded. Searched: Utah Consumer Privacy Act right to access delete opt out targeted advertising sale profiling.

Cross Context AdvertisingAmber

The UCPA defines 'sale' narrowly as an exchange of personal data for monetary consideration only, excluding non-monetary exchanges that would qualify as a 'sale' or 'share' under California's broader CCPA/CPRA framework.

Claims (1):

  • The UCPA contains a VCDPA-like definition of 'sale' limited to exchanges of personal data for monetary consideration, narrower than the CCPA/CPA definitions covering monetary or other valuable consideration.

Direct MarketingAmber

The UCPA's targeted-advertising opt-out right functions as Utah's principal direct-marketing control mechanism, absent a dedicated telemarketing/e-marketing consent statute within the Act itself.

Claims (1):

  • Consumers have the right to opt out of processing of personal data for targeted-advertising purposes under the UCPA, serving as Utah's principal statutory lever over direct-marketing-adjacent data use.
Category narrative43 words

The UCPA's adtech/commercial-privacy toolkit is limited to a notice-and-opt-out right for sale and targeted advertising, using a narrow monetary-only definition of 'sale.' The Act does not mandate recognition of universal opt-out signals (unlike Colorado), contains no dark-patterns prohibition, and has no clean-room/data-collaboration-room provisions.

Sources and claims (3)
  1. ConfirmedIAPPUnlike the Colorado Privacy Act, controllers subject to the UCPA are not required to recognize universal opt-out signals as a method for consumers to exercise their opt-out rights.observed
  2. ConfirmedIAPPThe UCPA contains a VCDPA-like definition of 'sale' limited to exchanges of personal data for monetary consideration, narrower than the CCPA/CPA definitions covering monetary or other valuable consideration.observed
  3. ProbableIAPPConsumers have the right to opt out of processing of personal data for targeted-advertising purposes under the UCPA, serving as Utah's principal statutory lever over direct-marketing-adjacent data use.observed

#

AI-specific legislation exists and is in force, but ADM transparency, profiling opt-out, and dedicated biometric protections are largely absent.

Primary frameworkUtah Artificial Intelligence Policy Act (2024); Utah Consumer Privacy Act (UCPA); Utah Genetic Testing Privacy Act
Traffic-light rationale — AmberAI-specific legislation exists and is in force, but ADM transparency, profiling opt-out, and dedicated biometric protections are largely absent.

Sub-modules (6)

Profiling RestrictionsAmber

Unlike Virginia and Colorado, the UCPA does not provide consumers a right to opt out of profiling.

Claims (1):

  • Unlike the VCDPA and CPA, the right to opt out of profiling is absent from the UCPA.

Automated Decision Making TransparencyRed

No ADM-transparency or explanation-right provision analogous to GDPR Art. 22 was identified under the UCPA.

Absence provenance: not recorded. Searched: Utah AI Policy Act 2024 automated decision biometric law social media minors.

Ai Risk AssessmentsAmber

Utah's Artificial Intelligence Policy Act (2024) clarifies that existing consumer-protection and privacy laws apply to generative-AI uses, targeting the most harmful applications rather than mandating formal AI risk assessments as Colorado's risk-based model does.

Claims (1):

  • Utah's Artificial Intelligence Policy Act (2024) takes a simpler approach than risk-based AI statutes by clarifying that existing consumer-protection laws apply to generative AI, focused on defining and prohibiting the most harmful uses of AI rather than mandating formal risk assessments.

Biometric RegimeAmber

Biometric identifiers are likely captured within the UCPA's general 'sensitive data' category (subject to notice-and-opt-out) rather than governed by a dedicated biometric-specific statute analogous to Illinois' BIPA.

Claims (1):

  • Biometric data is understood to fall within the UCPA's general 'sensitive data' category, subject to the Act's notice-and-opt-out (rather than opt-in consent) regime, in the absence of a dedicated Utah biometric-specific statute analogous to Illinois' BIPA.

Genetic DataGreen

Utah's Genetic Testing Privacy Act restricts genetic testing, disclosure, and insurer use of genetic information, operating alongside the UCPA's sensitive-data notice-and-opt-out provisions for genetic data collected by commercial controllers.

Claims (1):

  • Utah's Genetic Testing Privacy Act (Utah Code Title 26, Chapter 45) restricts insurer requests for, or consideration of, genetic test results of asymptomatic individuals or their blood relatives.

State Surveillance CarveoutsAmber

The UCPA does not apply to government entities or contracted third parties acting on a government entity's behalf, functioning as a blanket exemption for state/local government data processing including surveillance-adjacent activity.

Claims (1):

  • The UCPA does not apply to government entities or third parties under contract with a government entity acting on that entity's behalf, providing a blanket carve-out from the state's consumer-privacy framework for government-related processing.
Category narrative81 words

The UCPA provides no right to opt out of profiling and no ADM-transparency/explanation right analogous to GDPR Art. 22. Utah's separate Artificial Intelligence Policy Act (2024) clarifies that existing consumer-protection and privacy law applies to generative-AI use cases, adopting a narrower approach than risk-based statutes like Colorado's. There is no dedicated Utah biometric-specific statute (unlike Illinois' BIPA); biometric identifiers are addressed only as part of the UCPA's general sensitive-data category. Genetic data is separately regulated under the Genetic Testing Privacy Act.

Sources and claims (5)
  1. ConfirmedIAPPUnlike the VCDPA and CPA, the right to opt out of profiling is absent from the UCPA.observed
  2. ConfirmedIAPPUtah's Artificial Intelligence Policy Act (2024) takes a simpler approach than risk-based AI statutes by clarifying that existing consumer-protection laws apply to generative AI, focused on defining and prohibiting the most harmful uses of AI rather than mandating formal risk assessments.observed
  3. ProbableIAPPBiometric data is understood to fall within the UCPA's general 'sensitive data' category, subject to the Act's notice-and-opt-out (rather than opt-in consent) regime, in the absence of a dedicated Utah biometric-specific statute analogous to Illinois' BIPA.observed
  4. ConfirmedState of Utah / hosted via DataGuidanceUtah's Genetic Testing Privacy Act (Utah Code Title 26, Chapter 45) restricts insurer requests for, or consideration of, genetic test results of asymptomatic individuals or their blood relatives.observed
  5. ConfirmedIAPPThe UCPA does not apply to government entities or third parties under contract with a government entity acting on that entity's behalf, providing a blanket carve-out from the state's consumer-privacy framework for government-related processing.observed

#

COPPA-aligned parental-consent baseline is solid, but the flagship minors' social-media protection is under active, unresolved federal litigation, materially weakening current enforceability.

Primary frameworkUtah Consumer Privacy Act (UCPA); Utah Minor Protection in Social Media Act (SB 194/HB 464)
Traffic-light rationale — AmberCOPPA-aligned parental-consent baseline is solid, but the flagship minors' social-media protection is under active, unresolved federal litigation, materially weakening current enforceability.

Sub-modules (5)

Age VerificationAmber

Utah's Minor Protection in Social Media Act (successor to the Social Media Regulation Act) addresses minors' access to algorithmically curated social media, but is under a federal injunction as of the last confirmed status (September 2024); current appellate/litigation status as of August 2026 was not independently reconfirmed in this pass.

Claims (1):

  • Utah repealed the Social Media Regulation Act in the face of technology-industry lawsuits and replaced it with the Minor Protection in Social Media Act (SB 194/HB 464), addressing algorithmic harms to minors; a federal district court partially enjoined the successor act's provisions in early September 2024 on First Amendment grounds.

Minor Profiling BansAmber

Utah's social-media legislation created a private right of action for minors whose mental health has been harmed by an algorithmically driven social-media feature — a notable exception to Utah's general no-private-right-of-action posture, though enforceability is complicated by the pending federal injunction against the successor Act.

Claims (1):

  • Utah's replacement social-media law allows for a private right of action for minors whose mental health has been harmed by a social-media algorithm, one of the few private-right-of-action mechanisms in Utah's broader privacy/consumer-protection framework.

Education SettingsAmber

FERPA-governed education records and higher-education-institution data are excluded from UCPA scope; Utah has no additional UCPA-specific K-12/higher-education data-privacy overlay identified in this research pass.

Claims (1):

  • The UCPA excludes data subject to FERPA and exempts institutions of higher education, leaving federal education-privacy law as the operative regime for education-sector data not otherwise covered by Utah-specific minors' legislation.

Dependent AdultsRed

No Utah-specific statutory protection for dependent/vulnerable adults' personal data (elderly, mentally incapacitated) was identified within the UCPA or related state privacy statutes reviewed.

Absence provenance: not recorded. Searched: Utah Consumer Privacy Act right to access delete opt out targeted advertising sale profiling, Utah Consumer Privacy Act UCPA effective date enforcement Division of Consumer Protection.

Category narrative75 words

The UCPA aligns its under-13 parental-consent threshold with COPPA. Utah's more consequential minors' protections sit outside the UCPA in the Minor Protection in Social Media Act (SB 194/HB 464), which replaced the original Social Media Regulation Act but was preliminarily enjoined by a federal court in September 2024 on First Amendment grounds; that law also created a private right of action for minors harmed by addictive social-media algorithms. No Utah-specific dependent-adults data-protection provision was identified.

Sources and claims (4)
  1. ConfirmedIAPPControllers processing the personal data of consumers known to be under the age of 13 are required to obtain verifiable parental consent and process such data in accordance with COPPA.observed
  2. ConfirmedIAPPUtah repealed the Social Media Regulation Act in the face of technology-industry lawsuits and replaced it with the Minor Protection in Social Media Act (SB 194/HB 464), addressing algorithmic harms to minors; a federal district court partially enjoined the successor act's provisions in early September 2024 on First Amendment grounds.observed
  3. ProbableIAPPUtah's replacement social-media law allows for a private right of action for minors whose mental health has been harmed by a social-media algorithm, one of the few private-right-of-action mechanisms in Utah's broader privacy/consumer-protection framework.observed
  4. ProbableIAPPThe UCPA excludes data subject to FERPA and exempts institutions of higher education, leaving federal education-privacy law as the operative regime for education-sector data not otherwise covered by Utah-specific minors' legislation.observed

#

Enforcement powers and penalty ceilings are clearly defined and in force, but observable enforcement activity specific to Utah is low/opaque, and structural redress avenues for consumers (private right of action, collective redress) are largely foreclosed.

Primary frameworkUtah Consumer Privacy Act (UCPA)
Traffic-light rationale — AmberEnforcement powers and penalty ceilings are clearly defined and in force, but observable enforcement activity specific to Utah is low/opaque, and structural redress avenues for consumers (private right of action, collective redress) are largely foreclosed.

Sub-modules (6)

Regulator Powers And PenaltiesGreen

The Attorney General has exclusive authority to enforce the UCPA, must give 30 days' written notice of alleged violations, and may seek injunctive relief and civil penalties of up to $7,500 per violation plus actual damages if a controller fails to cure.

Claims (1):

  • The Utah Attorney General must provide 30 days' written notice of alleged UCPA violations before initiating enforcement, and may seek an injunction and civil penalties of up to $7,500 per violation if the controller/processor fails to cure.

Enforcement Activity IndexAmber

Public enforcement activity specific to the UCPA was not identified in sources reviewed; broader 2024 multi-state tracking found only two final public state-comprehensive-privacy enforcement actions nationally, both by California, with most other states (implicitly including Utah) remaining in non-public cure-period activity.

Claims (1):

  • As of 2024, most U.S. state comprehensive privacy laws remained in non-public 'right to cure' enforcement phases, with only two final public state-comprehensive-privacy enforcement actions recorded that year, both brought by California's Attorney General.

Regulator Funding And CapacityRed

No data on the Division of Consumer Protection's budget or headcount specific to UCPA enforcement capacity was identified in this research pass.

Absence provenance: not recorded. Searched: Utah Attorney General UCPA enforcement action 2025 2026 fine.

Collective Redress And Class ActionsAmber

The UCPA does not allow a consumer to use a violation of the Act to support a claim under other Utah laws, foreclosing indirect class-action leverage via the UCPA itself.

Claims (1):

  • The UCPA does not allow a consumer to use a violation of the Act to support a claim under other Utah laws, limiting indirect collective-redress pathways.

Private Right Of ActionAmber

The UCPA does not provide consumers with a private right of action; enforcement runs exclusively through the Attorney General. (A narrow, statute-specific private right of action exists outside the UCPA under Utah's minors'/social-media legislation — see children_and_vulnerable_groups.)

Claims (1):

  • The UCPA does not provide consumers with a private right of action; the Utah Attorney General has exclusive authority to enforce its provisions.

Recent Developments 180DRed

No Utah-specific UCPA legislative amendment, enforcement action, or judicial ruling within the last 180 days (February-August 2026) was identified in the sources reviewed for this run.

Absence provenance: not recorded. Searched: Utah Attorney General UCPA enforcement action 2025 2026 fine, Utah Minor Protection Social Media Act injunction 2026 appeal status.

Category narrative91 words

The Utah Attorney General holds exclusive UCPA enforcement authority, subject to a mandatory 30-day cure period, with penalties capped at $7,500 per violation plus actual damages and available injunctive relief. There is no private right of action under the UCPA and no mechanism to bootstrap UCPA violations into other Utah-law claims. As of the most recent multi-state review available, Utah had not yet generated a final public UCPA enforcement action; most state comprehensive-privacy enforcement in 2024 remained in non-public cure-period stages, with only California generating final public enforcement actions that year.

Sources and claims (4)
  1. ConfirmedDataGuidanceThe Utah Attorney General must provide 30 days' written notice of alleged UCPA violations before initiating enforcement, and may seek an injunction and civil penalties of up to $7,500 per violation if the controller/processor fails to cure.observed
  2. ProbableIAPPAs of 2024, most U.S. state comprehensive privacy laws remained in non-public 'right to cure' enforcement phases, with only two final public state-comprehensive-privacy enforcement actions recorded that year, both brought by California's Attorney General.observed
  3. ConfirmedIAPPThe UCPA does not allow a consumer to use a violation of the Act to support a claim under other Utah laws, limiting indirect collective-redress pathways.observed
  4. ConfirmedDataGuidanceThe UCPA does not provide consumers with a private right of action; the Utah Attorney General has exclusive authority to enforce its provisions.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for United States – Utah
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewernot recorded
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-06. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 43 claim(s), 46 source(s) in the cumulative register.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (38 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsaccess right
Art. 14Data Subject Rightsaccess right
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsrestriction and objection
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy received
Art. 46Cross-Border & Adequacysccs and bcrs
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 48Cross-Border & Adequacytransfer mechanisms
Art. 49Cross-Border & Adequacytransfer mechanisms
Art. 77Enforcement & Redressregulator powers and penalties
Art. 78Enforcement & Redressprivate right of action
Art. 79Enforcement & Redressprivate right of action
Art. 80Enforcement & Redresscollective redress and class actions
Art. 81Enforcement & Redresscollective redress and class actions
Art. 82Enforcement & Redressprivate right of action
Art. 83Enforcement & Redressregulator powers and penalties
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

regulator_and_framework, data_subject_rights, sectoral_watch and enforcement_and_redress modules are well-supported by convergent T2 legal-analysis sources (IAPP, DataGuidance) plus one T1 regulator homepage and one T1 statute-text PDF (Genetic Testing Privacy Act). lawful_processing_and_special_data, controller_processor_duties, adtech_and_commercial_privacy, algorithmic_biometric_and_surveillance_governance and children_and_vulnerable_groups rely primarily on T2 secondary analysis with several sub-modules resolved as legitimate absences (no DPIA/DPO/ROPA, no dark-patterns rule, no dedicated biometric statute) rather than research gaps. cross_border_and_adequacy is a structural 'no regime' finding at the module level, consistent with US state consumer-privacy law generally lacking GDPR-style transfer mechanics. No direct fetch of the full Utah Code Title 13 Chapter 61 statutory text or the Utah AG/Division UCPA effectiveness report (due 1 July 2025) was performed in this pass; findings rely on convergent secondary legal-analysis sources plus targeted primary-source anchors (Division homepage, Genetic Testing Privacy Act text).

Unresolved questions (6):

  • Confirm current (August 2026) appellate/litigation status of the federal injunction against Utah's Minor Protection in Social Media Act (SB194/HB464).
  • Confirm exact effective date and current in-force text of the Utah Artificial Intelligence Policy Act following any 2025 amendments extending or altering its sunset/repeal provisions.
  • Obtain Utah Division of Consumer Protection budget/headcount data specific to UCPA enforcement capacity.
  • Confirm whether Utah has enacted a dedicated biometric-information-privacy statute since this research pass, given the UCPA's general sensitive-data treatment of biometric identifiers.
  • Verify whether the UCPA-mandated Attorney General/Division effectiveness report (due 1 July 2025) has been published, and whether it recommends amendments (e.g., DPIA, private right of action, universal opt-out signal recognition).
  • Confirm whether any UCPA-specific Attorney General enforcement action (settlement, fine, or injunction) has been publicly announced to date.

Escalate to primary-source review: yes