Unpacking the Utah Consumer Privacy Act: What Businesses Need to Know for 2025
The Utah Consumer Privacy Act (UCPA), signed into law in March 2022 and taking effect December 31, 2023, is the latest U.S. state privacy legislation to set new rules for how businesses handle personal data. The law provides Utah residents with a range of individual rights and imposes obligations on companies to be more transparent about data practices and safeguard customer information.
As a cyber security expert with over a decade of experience advising companies on data protection, I‘ve seen the profound impact that the EU‘s General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA) have had in transforming privacy into a business imperative. The UCPA, while more limited in scope than those laws, represents another significant milestone in the shift toward data being treated as a precious asset, one that companies have a responsibility to handle ethically and protect diligently.
In this article, I‘ll provide an in-depth look at the key components of the UCPA, how it compares to other state privacy laws, and what businesses need to do to prepare for enforcement in 2024. I‘ll also share insights on the law‘s implications for the broader U.S. privacy landscape and the growing consumer demand for data protection.
Who Does the UCPA Apply To?
The UCPA covers a narrower set of businesses than some other state laws. It applies to companies that:
- Conduct business in Utah or produce products or services targeted to Utah residents, and
- Have annual revenue of $25 million or more and either:
- Control or process personal data of 100,000 or more Utah consumers per year, or
- Derive over 50% of gross revenue from the "sale" of personal data and control or process data of 25,000 or more consumers
Notably, this revenue threshold is higher than laws like the CCPA, which covers businesses with $25 million in revenue regardless of data processing volumes. The UCPA also differs in only covering data collected from consumers in a personal or household context, exempting employee and B2B data.
The law carves out a range of other exemptions, including for:
- Government entities and contractors
- Tribes
- Non-profits
- Higher education institutions
- HIPAA covered entities and business associates
- Data governed by other sectoral federal laws like GLBA, FCRA, FERPA
Consumer Rights Under the UCPA
Utah consumers gain four core rights over their personal data under the law:
-
Right of access: Consumers can confirm whether a business is processing their personal data and obtain access to that data.
-
Right to delete: Consumers can request deletion of personal data they provided to the business.
-
Right to data portability: Consumers can obtain a copy of the personal data they previously provided to the business in a portable and readily usable format.
-
Right to opt-out: Consumers can opt out of the processing of their data for targeted advertising or "sale." The UCPA defines "sale" broadly as the exchange of personal data for monetary consideration by the business to a third party.
These rights largely align with those provided under the CCPA and Virginia‘s Consumer Data Protection Act (VCDPA). One notable difference is the UCPA‘s more expansive definition of "sale," which is likely to capture various types of ad tech data sharing practices that may fall outside the scope of other laws. The UCPA also defines "processing" broadly to include any operation performed on data, including collection, use, storage, disclosure, analysis, deletion, or modification.
Businesses must provide clear notice to consumers of these rights and establish means for them to submit requests. The UCPA gives companies 45 days to respond to a consumer request, with the option for a 45-day extension. Unlike laws like the CCPA, the UCPA allows businesses to charge a reasonable fee for additional requests within a 12-month period.
Privacy Notice & Security Requirements
The UCPA requires businesses to provide consumers with a "reasonably accessible and clear" privacy notice that includes:
- The categories of personal data processed
- The purposes for which the data is processed
- How consumers can exercise their rights
- The categories of third parties the business shares data with
- Instructions on how to opt-out of targeted advertising or sale of personal data, if applicable
Businesses must also implement "reasonable administrative, technical, and physical data security practices" to protect the confidentiality and integrity of personal data. The law states that these measures should be "appropriate to the volume and nature of the personal data at issue."
While this requirement for "reasonable" security is similar to language in the CCPA, it‘s notable that the UCPA does not go as far as the prescriptive security mandates in the CCPA regulations, which lay out specific practices like data inventories, access controls, and incident response plans. This aligns with the overall perception of the UCPA as a more business-friendly law.
UCPA Enforcement & Penalties
The Utah Attorney General has exclusive authority to enforce the UCPA. The law does not provide a private right of action for consumers to sue businesses directly over alleged violations.
If the AG has reasonable cause to believe a business is violating the law, it must first provide written notice identifying the specific provisions being violated. The business then has 30 days to cure the violation and provide the AG an express written statement that the issues have been resolved.
If the business continues to violate the law after the 30-day cure period, the AG may bring an enforcement action seeking actual damages to the consumer and civil penalties of up to $7,500 per violation. By contrast, the CCPA provides for statutory damages between $100-$750 per consumer per incident, which can quickly add up to massive fines in the case of a data breach or other large-scale violation.
Preparing for UCPA Compliance
With the UCPA‘s effective date fast approaching, businesses should take proactive steps to assess their readiness and implement necessary changes. Key priorities include:
-
Data mapping: Inventory the personal data collected from Utah consumers, document data flows and sharing with third parties, and identify data subject to UCPA rights.
-
Privacy policy updates: Review and update online privacy notices to meet UCPA requirements for content and accessibility.
-
Individual rights processes: Establish mechanisms for receiving, authenticating and responding to consumer rights requests in line with UCPA timeframes. This may require updates to internal policies, procedures and training.
-
Data security assessment: Evaluate current administrative, technical and physical safeguards and assess alignment with UCPA "reasonable" security mandate and industry standards. Identify and remediate any gaps.
-
Vendor management: Review contracts with service providers and third parties that receive personal data to ensure UCPA compliance. Update contracts as needed to include required terms for data use, protection and deletion.
By taking these steps, businesses can lay the groundwork for UCPA compliance and demonstrate a commitment to responsible data practices.
The Growing U.S. Privacy Patchwork
The UCPA continues the trend of U.S. states stepping in to regulate privacy in the absence of federal legislation. It joins a growing patchwork of comprehensive state privacy laws, including:
- The California Privacy Rights Act (CPRA), which amends and expands the CCPA and takes effect January 1, 2023
- The Virginia Consumer Data Protection Act (VCDPA), effective January 1, 2023
- The Colorado Privacy Act (CPA), effective July 1, 2023
- The Connecticut Data Privacy Act (CTDPA), effective July 1, 2023
While these laws share many core principles and provisions, they differ in key areas like applicability thresholds, consumer rights, and enforcement mechanisms. This creates complex compliance challenges for businesses operating across state lines.
And more laws are likely on the way. In 2022 alone, at least 29 states and the District of Columbia considered consumer privacy legislation, according to the International Association of Privacy Professionals (IAPP). Several states have already introduced bills in their 2023 legislative sessions to date.
The IAPP also reports that state legislatures proposed more than 50 000 privacy bills in the decade from 2010-2019, a significant uptick from previous years. And a 2022 survey by Pew Research Center found that 79% of U.S. adults are concerned about how companies use their data, with 64% supporting more government regulation of business data practices.
All of this points to growing momentum behind state privacy legislation in the years ahead. And that will make flexible, scalable privacy compliance programs all the more critical for businesses.
Implications for Business
The UCPA‘s passage underscores the growing importance of privacy as a business priority, on par with data security and other mission-critical functions. Mishandling customer data not only risks financial and reputational harm, but also invites ever-increasing regulatory scrutiny and enforcement.
Businesses should approach UCPA compliance not as a check-the-box exercise, but as an opportunity to deepen customer trust, differentiate on privacy, and build more ethical and sustainable data practices. Those that do will be well-positioned to navigate the evolving U.S. privacy landscape in 2024 and beyond.
At the same time, the growing state privacy patchwork has intensified calls for a comprehensive federal law to simplify compliance and provide consistent protections for all Americans. While progress has stalled in recent years due to disagreements over key issues like preemption and private right of action, there are signs that the window may be opening for a deal.
In the meantime, businesses should continue to monitor state law developments, assess their compliance obligations, and invest in the people, processes and technology needed to operationalize privacy at scale. By staying agile and adapting to the shifting regulatory landscape, companies can turn privacy into a competitive advantage and a core component of their brand identity in the digital age.