Utah Data Privacy Law: Consumer Rights, Requests, and Penalties

The Utah data privacy law, formally the Utah Consumer Privacy Act (UCPA), gives Utah residents the right to see, delete, export, and stop the sale of personal information held by large businesses that meet the law’s thresholds. It took effect on December 31, 2023, and a 2025 amendment adds a right to correct inaccurate data starting July 1, 2026.1Chambers and Partners. Data Protection and Privacy 2026 – USA Utah

What You Can Ask a Business to Do

Utah consumers have four rights today and a fifth arriving in 2026.

The deletion right is narrower than California’s or Colorado’s. It reaches only what you gave the company directly, not what a company inferred about you or bought from a data broker. If your concern is profiling built from your browsing behavior, that gap matters.

Who the Law Protects

The UCPA covers Utah residents acting in a personal or household capacity: shopping online, running a streaming subscription, using a fitness app at home.3Utah Legislature. Utah Code 13-61-101 – Definitions

It does not cover you when you are acting in an employment or commercial context. Hiring records, work performance reviews, and information exchanged in a business-to-business deal fall outside the law. If you use the same device for work and personal life, only your personal-use data triggers protections.3Utah Legislature. Utah Code 13-61-101 – Definitions

Which Businesses Have to Comply

A business is covered only if it meets all three of the following. It must do business in Utah or target products or services at Utah residents. It must have annual revenue of $25 million or more. And it must hit one of two data thresholds in a calendar year:4Utah Legislature. Utah Code 13-61-102 – Applicability

  • Control or process personal data of 100,000 or more Utah consumers, or
  • Derive more than 50 percent of gross revenue from selling personal data and control or process data of at least 25,000 Utah consumers.

All three tests must be met. A Utah startup handling data for 200,000 people but earning under $25 million is not covered. A national company earning $50 million but processing data on only 10,000 Utah consumers is not covered either.4Utah Legislature. Utah Code 13-61-102 – Applicability

Whole categories of organizations are also exempt no matter what data they hold: government entities and their contractors, tribes, public and private higher education institutions, nonprofits, HIPAA-covered entities and their business associates, financial institutions governed by the Gramm-Leach-Bliley Act, and air carriers under federal aviation law. Specific data types are also exempt regardless of who holds them, including protected health information under HIPAA, records covered by the Fair Credit Reporting Act, GLBA-regulated financial data, and FERPA-covered education records.4Utah Legislature. Utah Code 13-61-102 – Applicability

The practical result: much of what you might assume the UCPA covers, especially your bank, your hospital, and your university, is actually governed by other laws entirely.

Sensitive Data Has Its Own Rule

Sensitive data is treated differently. Before a business processes it, the business must give you clear notice and an opportunity to opt out.5Utah Legislature. Utah Code 13-61-302 – Controller Duties

Sensitive data under the UCPA generally includes information about racial or ethnic origin, religious beliefs, sexual orientation, citizenship or immigration status, medical history, genetic or biometric data, and geolocation. For children under 13, the business must follow the federal Children’s Online Privacy Protection Act (COPPA) instead of the standard UCPA opt-out process.5Utah Legislature. Utah Code 13-61-302 – Controller Duties

Here is where Utah diverges from Virginia and Colorado, which require your affirmative consent before a business can process sensitive data. Utah uses an opt-out model. If a company sends you a notice about processing sensitive data and you do nothing, the company can proceed. Silence counts as permission.

How to Make a Request

To use any of these rights, you submit a request through the channels the business makes available. Most companies provide an online form or a dedicated email address in their privacy notice. The business must verify your identity before acting, usually by matching the information you provide against data it already has on file.

Once you are verified, the business has 45 days to respond. If it cannot authenticate you using reasonable efforts, it does not have to fulfill the request. If it denies the request, it must tell you within the same 45-day window and explain why.6Utah Legislature. Utah Code 13-61-203 – Responding to Consumer Requests

What Happens If a Business Ignores You

You cannot sue a business yourself for a UCPA violation. The statute bars any private right of action.7Utah Legislature. Utah Code 13-61-305 – No Private Cause of Action

Enforcement runs through the state. You file a complaint with the Utah Division of Consumer Protection.8Utah Division of Consumer Protection. Utah Consumer Privacy Act The Division investigates and, if it finds merit, refers the case to the Attorney General.

The Attorney General then sends the business a written notice of the violation. The business has 30 days to cure the problem and confirm in writing that it has done so. If it does not cure within that window, the Attorney General can bring a formal action and recover the consumer’s actual damages plus up to $7,500 per violation.9Utah Legislature. Utah Code 13-61-402 – Enforcement by Attorney General

For consumers, that structure means enforcement is slow and there is no guarantee of any payout even when a company clearly violated the law. A first offense is effectively a warning, and the payout, if it comes, goes toward damages and state penalties rather than a private settlement.

What Changes in 2026

The 2025 amendment (HB 418) adds a right to correct inaccurate personal data, effective July 1, 2026.1Chambers and Partners. Data Protection and Privacy 2026 – USA Utah Until then, if a company holds wrong information about you, the UCPA lets you see it and, in some cases, delete it, but not force the company to fix it. After that date, correction joins the list of requests a covered business must process within the same 45-day window.