{"id":374,"date":"2024-09-17T14:16:00","date_gmt":"2024-09-17T12:16:00","guid":{"rendered":"https:\/\/stage.usercentrics.com\/?post_type=knowledge&#038;p=28416"},"modified":"2025-06-26T12:13:02","modified_gmt":"2025-06-26T10:13:02","slug":"utah-consumer-privacy-act-ucpa","status":"publish","type":"knowledge","link":"https:\/\/usercentrics.com\/us\/knowledge-hub\/utah-consumer-privacy-act-ucpa\/","title":{"rendered":"Utah Consumer Privacy Act (UCPA): an overview"},"content":{"rendered":"\n<p>The Utah Consumer Privacy Act (UCPA) came into effect on December 31, 2023, and is one of the increasing number of statewide laws in the US that aim to protect the rights of consumers whose data is processed by businesses.<\/p>\n\n\n\n<p>When it was passed, the UCPA was the fourth piece of legislation of its kind in the US. Lawmakers were able to draw on earlier regulations, like the <a href=\"https:\/\/usercentrics.com\/knowledge-hub\/colorado-privacy-act\/\">Colorado Privacy Act (CPA)<\/a> and the <a href=\"https:\/\/usercentrics.com\/knowledge-hub\/virginia-consumer-data-protection-act-vcdpa\/\">Virginia Consumer Data Protection Act (VCDPA)<\/a>, which were both based on the first and most stringent US privacy law: the <a href=\"https:\/\/usercentrics.com\/knowledge-hub\/california-consumer-privacy-act\/\">California Consumer Protection Act (CCPA)<\/a>.<\/p>\n\n\n\n<p>With this foundation, the UCPA strikes a finer balance between consumer rights and business responsibilities. Overall, the narrower scope of its definitions and compliance requirements means that it can be seen as \u201clighter\u201d and more business-friendly than the majority of other <a href=\"https:\/\/usercentrics.com\/knowledge-hub\/us-data-privacy-laws-by-state\/\">state-level data privacy laws<\/a> in place.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-what-is-the-utah-consumer-privacy-act\">What is the Utah Consumer Privacy Act?<\/h2>\n\n\n\n<p>The UCPA gives consumers in Utah a degree of control over how businesses are able to collect and use their data. Under the UCPA, individuals have the right to know if a business is processing their personal data, to access and have that data deleted, and to opt out from their data being sold.<\/p>\n\n\n\n<p>Unlike other similar data privacy laws, the UCPA doesn\u2019t place limits on the data that businesses can gather and what they can do with it. The responsibility for minimizing the collection and processing of data rests with the consumer.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-upca-summary\">UPCA summary<\/h3>\n\n\n\n<p>The <a href=\"https:\/\/le.utah.gov\/~2022\/bills\/static\/SB0227.html\">UCPA<\/a> protects the privacy rights of Utah residents and establishes data privacy responsibilities for companies that operate in the state and process the data of the nearly 4 million individuals who live there.<\/p>\n\n\n\n<p>It requires businesses that collect data to protect the confidentiality and integrity of that data to reduce the risk of harm associated with processing it. Organizations must also provide consumers with clear and accessible privacy notices and inform them about how they can opt out of the sale of their data.<\/p>\n\n\n\n<p>Like other US state laws, the UCPA uses an opt-out model for user consent, rather than the opt-in model in place for regulations such as the <a href=\"https:\/\/usercentrics.com\/gdpr\/\">General Data Protection Regulation (GDPR)<\/a>.&nbsp;<\/p>\n\n\n\n<p>This means that consumers\u2019 personal data can be collected, sold, or used for targeted advertising without first obtaining their explicit and informed consent. The only exception here relates to children\u2019s data. In that case, consent must be obtained from a parent or legal guardian.&nbsp;<\/p>\n\n\n\n<p>Unlike most US data privacy laws, the UCPA does not require prior consent for the processing of data categorized as sensitive. Companies just need to notify consumers about collection and use and provide an opt-out option.<\/p>\n\n\n\n<p>The sale of data is one of the key focuses for the UCPA. The Act defines any \u201cexchange of personal data for monetary consideration by a controller to a third party\u201d as a sale.&nbsp;<\/p>\n\n\n\n<p>This definition doesn\u2019t include non-monetary exchanges, which means that it doesn\u2019t apply to data sharing among businesses, differentiating it from the CCPA and California Privacy Rights Act (CPRA).<\/p>\n\n\n\n<p>However, consumers do have the right \u2014 and must be provided with the option \u2014 to opt out of the sale of their data or its use for targeted advertising. If a consumer exercises this right, their data can no longer be used.&nbsp;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-updates-to-the-ucpa\">Updates to the UCPA<\/h3>\n\n\n\n<p>On March 13, 2024, Utah became the first state to enact an AI-focused consumer protection law. The <a href=\"https:\/\/le.utah.gov\/~2024\/bills\/static\/SB0149.html\">Utah Artificial Intelligence Policy Act (UAIP)<\/a>, which came into effect on May 1, 2024, modifies the UCPA and places certain duties on businesses using generative AI in the course of their business.&nbsp;<\/p>\n\n\n\n<p>The act focuses mainly on businesses operating in regulated industries, i.e. those where a person requires a license or state certificate to work. These businesses must disclose to customers that they are interacting with generative AI or materials that are created by generative AI.&nbsp;<\/p>\n\n\n\n<p>It also requires businesses in non-regulated sectors to disclose the use of this technology if asked or prompted by a customer. However, it\u2019s not clear what mechanisms an organization must put in place to field these requests or how the disclosure should take place.<\/p>\n\n\n\n<p>The UAIP has also created an Office of Artificial Intelligence Policy that is tasked with setting up an Artificial Intelligence Learning Laboratory Program. The goal is that this AI Lab will support AI-related regulation and development within the state.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-definitions-under-the-utah-consumer-privacy-act\">Definitions under the Utah Consumer Privacy Act<\/h2>\n\n\n\n<p>The UCPA applies to controllers or processors of consumer data. It defines these terms as follows.&nbsp;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-controller-under-ucpa\">Controller under UCPA<\/h3>\n\n\n\n<p>Controller means<strong> <\/strong><em>\u201ca person doing business in the state who determines the purposes for which and the means by which personal data are processed, regardless of whether the person makes the determination alone or with others.\u201d <\/em>(Section 101.12 UCPA)<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-processor-under-ucpa\">Processor under UCPA<\/h3>\n\n\n\n<p>Processor means<strong> <\/strong><em>\u201ca person who processes personal data on behalf of a controller.\u201d <\/em>In relation to controllers and processors, \u201cperson\u201d includes natural persons or commercial or noncommercial entities, including third parties, that process data and meet the applicability criteria. (Section 101.26 UCPA)<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-consumer-under-ucpa\">Consumer under UCPA<\/h3>\n\n\n\n<p>Consumer means <em>\u201can individual who is a resident of the state acting in an individual or household context\u201d <\/em>who is not <em>\u201cacting in an employment or commercial context.\u201d <\/em>(Section 101.10 UCPA)<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-personal-data-under-ucpa\">Personal data under UCPA<\/h3>\n\n\n\n<p>\u201cPersonal data\u201d refers to<em> \u201cinformation that is linked or reasonably linkable to an identified individual or an identifiable individual.\u201d <\/em>(Section 101.24 UCPA)<\/p>\n\n\n\n<p>There are specific forms of personal data that can make an individual directly identifiable (e.g. a name or email address), while others may not qualify on their own (e.g. an IP address). However, it\u2019s important to note that non-identifying data may become identifying when it\u2019s aggregated with other kinds of personal data.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-exclusions-to-the-definition-of-personal-data\">Exclusions to the definition of personal data<\/h4>\n\n\n\n<p>The UPCA sets out a number of exclusions in relation to personal data. This includes information that:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>is publicly available&nbsp;<\/li>\n\n\n\n<li>has been deidentified or anonymized<\/li>\n\n\n\n<li>relates to groups of consumers and has been aggregated to the extent that individuals cannot be identified<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-sensitive-data-under-ucpa\">Sensitive data under UCPA<\/h3>\n\n\n\n<p>Unlike some other data privacy laws, the UCPA does not require businesses to obtain consent for processing sensitive personal data.&nbsp;<\/p>\n\n\n\n<p>However, controllers do have to clearly notify consumers and provide the opportunity for them to opt out of having their sensitive personal data processed before such data is collected and processed. Like non-sensitive data, consumers can also opt out of processing for sensitive data later, at which point processing must cease.<\/p>\n\n\n\n<p>The Act (Section 101.32 UCPA) defines \u201csensitive data\u201d as personal data that includes or reveals:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>racial or ethnic origin (unless processed by a video communication service or by a licensed healthcare provider)<\/li>\n\n\n\n<li>religious beliefs<\/li>\n\n\n\n<li>sexual orientation<\/li>\n\n\n\n<li>citizenship or immigration status<\/li>\n\n\n\n<li>medical history, mental or physical health condition, or medical treatment or diagnosis by a healthcare professional<\/li>\n\n\n\n<li>genetic or biometric data (if the processing is for the purpose of identifying a specific individual)<\/li>\n\n\n\n<li>geolocation data (if the processing is for the purpose of identifying a specific individual)<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-who-must-comply-with-the-utah-consumer-privacy-act\">Who must comply with the Utah Consumer Privacy Act?<\/h2>\n\n\n\n<p>Similar to other data privacy laws, the UCPA has provisions that provide rights to consumers and place obligations on businesses, provided that they meet certain criteria.&nbsp;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-ucpa-applies-to-businesses-that-nbsp\">UCPA applies to businesses that:&nbsp;<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Operate in Utah, <\/strong>either by conducting business there or by offering a product or service to consumers who reside in the state.<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Meet the annual earnings and data processing thresholds<\/strong>, meaning they report revenue of USD 25 million and either<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>control or process the data of 100,000 consumers<\/li>\n<\/ul>\n\n\n\n<p>or<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>derive more than 50 percent of gross revenue from the sale or control of personal data of 25,000 or more consumers<\/li>\n<\/ul>\n\n\n\n<p>The UCPA differs from some of the other data privacy laws as entities have to meet multiple criteria for it to apply. This narrows its scope. For example, the revenue threshold will exclude smaller SMEs from qualifying. Many of the more recently passed US state-level privacy laws do not include a revenue-centric threshold, though Utah is one of the earlier ones that does.<\/p>\n\n\n\n<p><strong>Unsure if the UCPA applies to your business? Use our <\/strong><a href=\"https:\/\/usercentrics.com\/resources\/ucpa-checklist\/\"><strong>UCPA checklist<\/strong><\/a><strong> to understand if the Act applies to your business, and what you need to do to be compliant.<\/strong><\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-exemptions-to-utah-consumer-privacy-act-compliance\">Exemptions to Utah Consumer Privacy Act compliance<\/h3>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-organizational-exemptions\">Organizational exemptions<\/h4>\n\n\n\n<p>In addition to organizations that fall below the revenue or processing volume thresholds, the UCPA exempts a number of other entities, including:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>institutions of higher education<\/li>\n\n\n\n<li>nonprofit organizations<\/li>\n\n\n\n<li>government organizations and contractors<\/li>\n\n\n\n<li>Indigenous groups<\/li>\n\n\n\n<li>air carriers<\/li>\n\n\n\n<li>organizations covered by the Health Insurance Portability and Accountability Act (HIPAA)<\/li>\n\n\n\n<li>financial institutions governed by the Gramm-Leach-Bliley Act (GLBA)<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-data-exemptions\">Data exemptions<\/h4>\n\n\n\n<p>The UCPA does not apply to information that\u2019s already subject to the following regulations:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Driver\u2019s Privacy Protection Act (DPPA)<\/li>\n\n\n\n<li>Fair Credit Reporting Act (FCRA)<\/li>\n\n\n\n<li>Family Educational Rights and Privacy Act (FERPA)<\/li>\n\n\n\n<li>Farm Credit Act (FCA)<\/li>\n\n\n\n<li>Gramm-Leach-Bliley Act (GLBA)<\/li>\n\n\n\n<li>Health Insurance Portability and Accountability Act (HIPAA)<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-employment-exemptions\">Employment exemptions<\/h4>\n\n\n\n<p>Data processed or maintained during the course of an individual\u2019s employment is exempt from the UCPA.&nbsp;<\/p>\n\n\n\n<p>This covers instances when an individual is applying for a job, as well as when they are \u201cacting as an employee, agent, or independent contractor of a controller, processor, or third party,\u201d provided that the data is \u201ccollected and used within the context of that role\u201d (Section 102.2(o)(i) UCPA).&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-consumer-rights-under-the-utah-consumer-privacy-act\">Consumer rights under the Utah Consumer Privacy Act<\/h2>\n\n\n\n<p>Consumers have four primary rights under the UCPA: access, deletion, portability, and opting out.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Right to access, <\/strong>including confirming whether a controller is processing their data, and the ability to request and receive that data<\/li>\n\n\n\n<li><strong>Right to deletion of personal data,<\/strong> if the data subject directly provided the data to the controller<\/li>\n\n\n\n<li><strong>Right to portability, <\/strong>obtaining a copy of their personal data from the controller, in a format that is:\n<ul class=\"wp-block-list\">\n<li>portable to a technically reasonable extent<\/li>\n\n\n\n<li>readily usable to a practical extent<\/li>\n\n\n\n<li>enables the consumer to transmit the data to another controller reasonably easily, where the processing is carried out by automated means<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>Right to opt out of certain processing,<\/strong> specifically for the sale of the personal data or the purposes of targeted advertising<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-key-differences-with-other-privacy-laws\">Key differences with other privacy laws<\/h3>\n\n\n\n<p>While these rights are similar to those given to consumers under other data privacy laws, both within the US and globally, UCPA does not create other common rights, such as the right to appeal and the right to correct (to request and have omissions or inaccuracies rectified).<\/p>\n\n\n\n<p>In addition to these exclusions, the UCPA does not provide for a private right of action (the ability for an individual consumer to sue a controller for noncompliance or a data breach). To date California is the only state that allows for this. Consumers also cannot use a violation of the UCPA to support a claim under other Utah laws.<\/p>\n\n\n\n<p>What\u2019s more, controllers under the Utah privacy law aren\u2019t required to recognize \u201cuniversal opt-out signals\u201d as a method for consumers to opt out of data processing. This excludes <a href=\"https:\/\/usercentrics.com\/knowledge-hub\/global-privacy-control\/\">global privacy control (GPC)<\/a> measures, where users can set their consent choices once and have them respected across all other sites and properties on which they are active, instead of having to specify their choice at every online property they visit.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-what-are-controllers-obliged-to-do-under-the-utah-consumer-privacy-act\">What are controllers obliged to do under the Utah Consumer Privacy Act?<\/h2>\n\n\n\n<p>Under the UCPA, data controllers must outline exactly how consumers can submit a request and exercise their rights related to their data. They must also respond to any requests within 45 days.&nbsp;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-transparency-under-the-ucpa\">Transparency under the UCPA<\/h3>\n\n\n\n<p>Controllers must provide consumers with a privacy notice or policy that is \u201creasonably accessible and clear.\u201d This notice would typically appear on a business\u2019s website and must include:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>categories of personal data processed by the controller<\/li>\n\n\n\n<li>categories of personal data the controller shares with third parties<\/li>\n\n\n\n<li>categories of third parties with whom the controller shares personal data<\/li>\n\n\n\n<li>a clear explanation of how consumers can exercise their rights, including the right to opt out<\/li>\n\n\n\n<li>\u201cclear and conspicuous\u201d disclosure if personal data is sold to a third party or used for targeted advertising<\/li>\n<\/ul>\n\n\n\n<p>A consent management platform (CMP) can make this easier for you. With the right tool, you can stay compliant by generating an accurate, comprehensive, and up to date privacy policy and notify consumers about any data collection that\u2019s taking place.&nbsp;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-consumer-requests-under-the-ucpa\">Consumer requests under the UCPA<\/h3>\n\n\n\n<p>&nbsp;Consumer requests must be fulfilled free of charge to the consumer, unless the request is:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>the second or subsequent request within the same 12-month period<\/li>\n\n\n\n<li>\u201cexcessive, repetitive, technically infeasible, or manifestly unfounded\u201d (Section 203.4.(b)(i)(A) UCPA)<\/li>\n\n\n\n<li>reasonably believed by the controller to have the primary purpose of \u201csomething other than exercising a right\u201d (Section 203.4.(b)(i)(B) UCPA)<\/li>\n\n\n\n<li>intended to harass, disrupt, or impose undue burden on the resources of the controller\u2019s business<\/li>\n<\/ul>\n\n\n\n<p>Controllers must take action and notify the consumer of their actions within 45 days of receiving a request. If the controller cannot or will not respond to or fulfill the consumer\u2019s request, e.g. if the consumer\u2019s identity cannot be reasonably verified, they must communicate this during that same 45-day period.<\/p>\n\n\n\n<p>However, there are exceptions. The response period can be extended by another 45 days if reasonably necessary, for example, if the request is very complex or the controller is dealing with a high number of requests.&nbsp;<\/p>\n\n\n\n<p>Where there is an extension, the consumer must be informed within the initial 45 days. The notification must include reasons for and the length of the delay.<\/p>\n\n\n\n<p>Unlike some other laws, the UCPA does not have an appeal process for consumers whose requests are denied.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-data-security-under-the-ucpa\">Data security under the UCPA<\/h3>\n\n\n\n<p>Controllers must \u201cestablish, implement, and maintain reasonable administrative, technical, and physical data security practices\u201d that have been \u201cdesigned to protect the confidentiality and integrity of personal data.\u201d (Section 302.2(a) UCPA)&nbsp;<\/p>\n\n\n\n<p>This applies both to the controller and any third party services they use.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-third-party-data-processing-under-the-ucpa\">Third-party data processing under the UCPA<\/h3>\n\n\n\n<p>Controller organizations may use third parties to process data on their behalf, so long as there is a contract in place.&nbsp;<\/p>\n\n\n\n<p>The contract must include data processing instructions, as well as some of the same information that must be outlined in the consumer notification, including:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>the nature and purpose of the processing<\/li>\n\n\n\n<li>the type of data to be processed<\/li>\n\n\n\n<li>the duration of processing<\/li>\n\n\n\n<li>all parties\u2019 rights and obligations, including a duty of confidentiality<\/li>\n\n\n\n<li>a provision that requires the processor to have a written contract with any subcontractor engaged to process personal data that mirrors the obligations on the processor<\/li>\n<\/ul>\n\n\n\n<p>Under the UCPA, controllers don\u2019t have to evaluate the risks of their data processing activities via data protection assessments. What\u2019s more, a contract between a controller and processor does not need to stipulate that the processor must comply with any reasonable <a href=\"https:\/\/usercentrics.com\/data-privacy-audit\/\">data privacy audits<\/a> set in motion by the data controller.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-processing-of-children-s-personal-data-under-the-ucpa\">Processing of children\u2019s personal data under the UCPA<\/h3>\n\n\n\n<p>The processing of children\u2019s data is the only activity under the UCPA that requires explicit consent. Under the Act, a child is defined as an individual known to be under the age of 13.&nbsp;<\/p>\n\n\n\n<p>Controllers must obtain verifiable parental or guardian\u2019s consent prior to processing and process the data in accordance with the <a href=\"\/knowledge-hub\/childrens-online-privacy-protection-act-coppa\/\">Children\u2019s Online Privacy Protection Act (COPPA)<\/a>.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-nondiscrimination-under-the-ucpa\">Nondiscrimination under the UCPA<\/h3>\n\n\n\n<p>Controllers may not discriminate against any consumer who exercises their privacy rights. Examples of potential discrimination include:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>denying goods or services<\/li>\n\n\n\n<li>charging a different price or rate for goods or services<\/li>\n\n\n\n<li>providing a different level of quality for goods or services<\/li>\n<\/ul>\n\n\n\n<p>However, a controller is allowed to offer \u201ca different price, rate, level, quality, or selection of a good or service to a consumer\u201d (Section 302.4(b) UCPA) if that customer has opted out of targeted advertising, or if the offer relates to the consumer voluntarily participating in the controller\u2019s loyalty program.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-enforcement-of-the-utah-consumer-privacy-act\">Enforcement of the Utah Consumer Privacy Act<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-enforcement-authority\">Enforcement authority<\/h3>\n\n\n\n<p>The Utah attorney general has full enforcement authority of UCPA. However, the Division of Consumer Protection is responsible for administering consumer complaints and has the authority to investigate alleged violations.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-investigations-and-cure-period\">Investigations and cure period<\/h3>\n\n\n\n<p>Where authorities find reasonable cause or evidence of a violation, it\u2019s referred to the Attorney General. If the Attorney General pursues the investigation, their office must provide the data controller or data processor with a written notice about the violation.<\/p>\n\n\n\n<p>The UCPA provides the offending party with a 30-day \u201ccure\u201d period. This is a grace period during which the controller is given the opportunity to rectify any violation and provide a statement to the Attorney General about what has been done to resolve the violation and ensure it won\u2019t be repeated. Unlike many US data privacy laws, the UCPA\u2019s cure period does not sunset.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-damages-and-fines\">Damages and fines<\/h3>\n\n\n\n<p>In cases where punitive action is required, for example, if the controller or processor fails to resolve, or repeats the violation after providing a written statement to the contrary, the Attorney General can initiate an enforcement action. This includes damages and fines up to USD 7,500 per violation.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-consent-management-and-the-utah-consumer-privacy-act-nbsp\">Consent management and the Utah Consumer Privacy Act&nbsp;<\/h2>\n\n\n\n<p>The UCPA uses an opt-out model to regulate data collection and processing in the state of Utah. As a data controller in Utah, you\u2019re not required to obtain data subjects\u2019 consent before collecting personal data, unless that data belongs to a child.<\/p>\n\n\n\n<p>However, you are required to give consumers a clear notification that their data is being collected, inform them about their rights, and provide them with the means to opt out, either before or at the point of collection and processing.<\/p>\n\n\n\n<p>To achieve and maintain compliance, use a CMP. A robust CMP can automate the process of notifying customers about data processing, tailoring consent messages, and managing their opt-out choices. This makes it easier to achieve and maintain compliance with the UCPA and other US privacy laws like the CCPA\/CPRA and VCDPA.<\/p>\n\n\n\n<p>A robust CMP helps your business obtain consent in a transparent manner, enabling you to collect valuable data while building trust with your customers.<\/p>\n\n\n<div id=\"uc-cta_69e9dcf52f87a\" class=\"uc-cta uc-cta--button uc-cta--primary uc-ctx--blue\">\n    <div class=\"uc-cta__inner container\">\n        <div class=\"uc-cta__content\">\n                                        <div class=\"uc-cta__heading no-default-margin\">Achieve compliance with a comprehensive consent management solution<\/div>\n                                        <div class=\"uc-cta__description\">\n                    <p>Usercentrics CMP helps you tailor consent messages, manage user opt-out choices, and stay compliant with relevant privacy laws.<\/p>\n                <\/div>\n                                                                    <\/div>\n                            <div class=\"uc-cta__section\">\n                                        <a id=\"6bbc575c-fc2b-4181-a1b3-1dff3d15d9d5\" class=\"uc-button uc-button-size-m uc-button-contained  no-default-link-decoration\" href=\"\/website-consent-management\/\" target=\"\"><span>Learn more<\/span><\/a>                                    <\/div>\n            <\/div>\n<\/div>\n    <script type=\"module\">\n        new Uc_Cta(document.getElementById(\"uc-cta_69e9dcf52f87a\"));\n    <\/script>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-navigating-ucpa-compliance\">Navigating UCPA compliance<\/h2>\n\n\n\n<p>While the requirements for UCPA compliance are less demanding than similar laws\u2019, the potential fines and damage to brand reputation that can result from noncompliance mean that businesses must still be diligent.<\/p>\n\n\n\n<p>Usercentrics can help you adhere to regulatory requirements of laws like the UCPA with its all-in-one CMP that enables you to produce content for privacy notices in just a few clicks. What\u2019s more, our platform simplifies consumer consent management and helps you personalize the consent experience for your users.<\/p>\n\n\n\n<p>If you have questions or interest in implementing our CMP to help you achieve compliance with privacy laws in the US and around the world, <a href=\"https:\/\/usercentrics.com\/book-a-consultation\/\">talk to one of our experts<\/a>.<\/p>\n\n\n\n<p><em>Usercentrics does not provide legal advice, and information is provided for educational purposes only. We always recommend engaging qualified legal counsel or privacy specialists regarding data privacy and protection issues and operations.<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The UCPA provides rights to consumers and places responsibilities on businesses to protect consumer data and use it compliantly. We explore its key provisions and what they mean for both consumers and companies.<\/p>\n","protected":false},"featured_media":7525,"template":"","meta":{"_acf_changed":false,"editor_notices":[],"footnotes":""},"tags":[],"magazine_issue":[],"magazine_tag":[],"resource_tag":[14,13],"class_list":["post-374","knowledge","type-knowledge","status-publish","has-post-thumbnail","hentry","resource_tag-privacy","resource_tag-regulations"],"acf":[],"yoast_head":"<title>Utah Consumer Privacy Act (UCPA): A-Z Breakdown<\/title>\n<meta name=\"description\" content=\"We explain the Utah Consumer Privacy Act (UCPA) and what the Utah privacy law means for consumers, companies, and personal data.\" \/>\n<meta name=\"robots\" content=\"noindex, follow\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Utah Consumer Privacy Act (UCPA): A-Z Breakdown\" \/>\n<meta property=\"og:description\" content=\"We explain the Utah Consumer Privacy Act (UCPA) and what the Utah privacy law means for consumers, companies, and personal data.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/usercentrics.com\/us\/knowledge-hub\/utah-consumer-privacy-act-ucpa\/\" \/>\n<meta property=\"og:site_name\" content=\"Usercentrics - US\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/usercentrics\" \/>\n<meta property=\"article:modified_time\" content=\"2025-06-26T10:13:02+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/usercentrics.com\/us\/wp-content\/uploads\/sites\/7\/2024\/09\/uc_some_1200x630_ucpa_091824_1.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"630\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:title\" content=\"The Utah Consumer Privacy Act | Overview of UCPA\" \/>\n<meta name=\"twitter:description\" content=\"We explain the Utah Consumer Privacy Act (UCPA) and what the Utah privacy law means for consumers and companies.\" \/>\n<meta name=\"twitter:image\" content=\"https:\/\/usercentrics.com\/wp-content\/uploads\/2022\/12\/Utah-privacy-policy-blue-1.jpg\" \/>\n<meta name=\"twitter:site\" content=\"@usercentrics\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"14 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/usercentrics.com\\\/us\\\/knowledge-hub\\\/utah-consumer-privacy-act-ucpa\\\/\",\"url\":\"https:\\\/\\\/usercentrics.com\\\/us\\\/knowledge-hub\\\/utah-consumer-privacy-act-ucpa\\\/\",\"name\":\"Utah Consumer Privacy Act (UCPA): A-Z Breakdown\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/usercentrics.com\\\/us\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/usercentrics.com\\\/us\\\/knowledge-hub\\\/utah-consumer-privacy-act-ucpa\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/usercentrics.com\\\/us\\\/knowledge-hub\\\/utah-consumer-privacy-act-ucpa\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/usercentrics.com\\\/us\\\/wp-content\\\/uploads\\\/sites\\\/7\\\/2024\\\/09\\\/uc_blog_1000x1000_ucpa_a.jpg\",\"datePublished\":\"2024-09-17T12:16:00+00:00\",\"dateModified\":\"2025-06-26T10:13:02+00:00\",\"description\":\"We explain the Utah Consumer Privacy Act (UCPA) and what the Utah privacy law means for consumers, companies, and personal data.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/usercentrics.com\\\/us\\\/knowledge-hub\\\/utah-consumer-privacy-act-ucpa\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":\"https:\\\/\\\/usercentrics.com\\\/us\\\/knowledge-hub\\\/utah-consumer-privacy-act-ucpa\\\/\"}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/usercentrics.com\\\/us\\\/knowledge-hub\\\/utah-consumer-privacy-act-ucpa\\\/#primaryimage\",\"url\":\"https:\\\/\\\/usercentrics.com\\\/us\\\/wp-content\\\/uploads\\\/sites\\\/7\\\/2024\\\/09\\\/uc_blog_1000x1000_ucpa_a.jpg\",\"contentUrl\":\"https:\\\/\\\/usercentrics.com\\\/us\\\/wp-content\\\/uploads\\\/sites\\\/7\\\/2024\\\/09\\\/uc_blog_1000x1000_ucpa_a.jpg\",\"width\":1000,\"height\":1000,\"caption\":\"Utah Consumer Privacy Act\",\"copyrightNotice\":\"\u00a9 Copyright 2026 Usercentrics GmbH\",\"creator\":{\"@type\":\"Organization\",\"name\":\"Usercentrics GmbH\"},\"creditText\":\"Image: Usercentrics GmbH\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/usercentrics.com\\\/us\\\/knowledge-hub\\\/utah-consumer-privacy-act-ucpa\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Resources\",\"item\":\"https:\\\/\\\/usercentrics.com\\\/us\\\/resources\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Blog\",\"item\":\"https:\\\/\\\/usercentrics.com\\\/us\\\/knowledge-hub\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Utah Consumer Privacy Act (UCPA): an overview\",\"item\":\"https:\\\/\\\/usercentrics.com\\\/us\\\/knowledge-hub\\\/utah-consumer-privacy-act-ucpa\\\/\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/usercentrics.com\\\/us\\\/#website\",\"url\":\"https:\\\/\\\/usercentrics.com\\\/us\\\/\",\"name\":\"Usercentrics - US\",\"description\":\"Consent Management Platform (CMP) Usercentrics\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/usercentrics.com\\\/us\\\/?s={search_term_string}\"}}],\"inLanguage\":\"en-US\"}]}<\/script>","yoast_head_json":{"title":"Utah Consumer Privacy Act (UCPA): A-Z Breakdown","description":"We explain the Utah Consumer Privacy Act (UCPA) and what the Utah privacy law means for consumers, companies, and personal data.","robots":{"index":"noindex","follow":"follow"},"og_locale":"en_US","og_type":"article","og_title":"Utah Consumer Privacy Act (UCPA): A-Z Breakdown","og_description":"We explain the Utah Consumer Privacy Act (UCPA) and what the Utah privacy law means for consumers, companies, and personal data.","og_url":"https:\/\/usercentrics.com\/us\/knowledge-hub\/utah-consumer-privacy-act-ucpa\/","og_site_name":"Usercentrics - US","article_publisher":"https:\/\/www.facebook.com\/usercentrics","article_modified_time":"2025-06-26T10:13:02+00:00","og_image":[{"width":1200,"height":630,"url":"https:\/\/usercentrics.com\/us\/wp-content\/uploads\/sites\/7\/2024\/09\/uc_some_1200x630_ucpa_091824_1.jpg","type":"image\/jpeg"}],"twitter_card":"summary_large_image","twitter_title":"The Utah Consumer Privacy Act | Overview of UCPA","twitter_description":"We explain the Utah Consumer Privacy Act (UCPA) and what the Utah privacy law means for consumers and companies.","twitter_image":"https:\/\/usercentrics.com\/wp-content\/uploads\/2022\/12\/Utah-privacy-policy-blue-1.jpg","twitter_site":"@usercentrics","twitter_misc":{"Est. reading time":"14 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/usercentrics.com\/us\/knowledge-hub\/utah-consumer-privacy-act-ucpa\/","url":"https:\/\/usercentrics.com\/us\/knowledge-hub\/utah-consumer-privacy-act-ucpa\/","name":"Utah Consumer Privacy Act (UCPA): A-Z Breakdown","isPartOf":{"@id":"https:\/\/usercentrics.com\/us\/#website"},"primaryImageOfPage":{"@id":"https:\/\/usercentrics.com\/us\/knowledge-hub\/utah-consumer-privacy-act-ucpa\/#primaryimage"},"image":{"@id":"https:\/\/usercentrics.com\/us\/knowledge-hub\/utah-consumer-privacy-act-ucpa\/#primaryimage"},"thumbnailUrl":"https:\/\/usercentrics.com\/us\/wp-content\/uploads\/sites\/7\/2024\/09\/uc_blog_1000x1000_ucpa_a.jpg","datePublished":"2024-09-17T12:16:00+00:00","dateModified":"2025-06-26T10:13:02+00:00","description":"We explain the Utah Consumer Privacy Act (UCPA) and what the Utah privacy law means for consumers, companies, and personal data.","breadcrumb":{"@id":"https:\/\/usercentrics.com\/us\/knowledge-hub\/utah-consumer-privacy-act-ucpa\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":"https:\/\/usercentrics.com\/us\/knowledge-hub\/utah-consumer-privacy-act-ucpa\/"}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/usercentrics.com\/us\/knowledge-hub\/utah-consumer-privacy-act-ucpa\/#primaryimage","url":"https:\/\/usercentrics.com\/us\/wp-content\/uploads\/sites\/7\/2024\/09\/uc_blog_1000x1000_ucpa_a.jpg","contentUrl":"https:\/\/usercentrics.com\/us\/wp-content\/uploads\/sites\/7\/2024\/09\/uc_blog_1000x1000_ucpa_a.jpg","width":1000,"height":1000,"caption":"Utah Consumer Privacy Act","copyrightNotice":"\u00a9 Copyright 2026 Usercentrics GmbH","creator":{"@type":"Organization","name":"Usercentrics GmbH"},"creditText":"Image: Usercentrics GmbH"},{"@type":"BreadcrumbList","@id":"https:\/\/usercentrics.com\/us\/knowledge-hub\/utah-consumer-privacy-act-ucpa\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Resources","item":"https:\/\/usercentrics.com\/us\/resources\/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https:\/\/usercentrics.com\/us\/knowledge-hub\/"},{"@type":"ListItem","position":3,"name":"Utah Consumer Privacy Act (UCPA): an overview","item":"https:\/\/usercentrics.com\/us\/knowledge-hub\/utah-consumer-privacy-act-ucpa\/"}]},{"@type":"WebSite","@id":"https:\/\/usercentrics.com\/us\/#website","url":"https:\/\/usercentrics.com\/us\/","name":"Usercentrics - US","description":"Consent Management Platform (CMP) Usercentrics","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/usercentrics.com\/us\/?s={search_term_string}"}}],"inLanguage":"en-US"}]}},"_links":{"self":[{"href":"https:\/\/usercentrics.com\/us\/wp-json\/wp\/v2\/knowledge\/374","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/usercentrics.com\/us\/wp-json\/wp\/v2\/knowledge"}],"about":[{"href":"https:\/\/usercentrics.com\/us\/wp-json\/wp\/v2\/types\/knowledge"}],"version-history":[{"count":0,"href":"https:\/\/usercentrics.com\/us\/wp-json\/wp\/v2\/knowledge\/374\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/usercentrics.com\/us\/wp-json\/wp\/v2\/media\/7525"}],"wp:attachment":[{"href":"https:\/\/usercentrics.com\/us\/wp-json\/wp\/v2\/media?parent=374"}],"wp:term":[{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/usercentrics.com\/us\/wp-json\/wp\/v2\/tags?post=374"},{"taxonomy":"magazine_issue","embeddable":true,"href":"https:\/\/usercentrics.com\/us\/wp-json\/wp\/v2\/magazine_issue?post=374"},{"taxonomy":"magazine_tag","embeddable":true,"href":"https:\/\/usercentrics.com\/us\/wp-json\/wp\/v2\/magazine_tag?post=374"},{"taxonomy":"resource_tag","embeddable":true,"href":"https:\/\/usercentrics.com\/us\/wp-json\/wp\/v2\/resource_tag?post=374"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}