Not publishable as-is. 3 of 7 publication_gate checks fail. The renderer displays the gate rather than suppressing it. Legal review and sub-brief approval are informational and are not part of this test.
Based mainly on secondary sources. Only 2 of the sources retrieved for this jurisdiction are official or direct reporting of official material (tier 1 or 2), against the 3 we look for. No finding on this page is shown with confidence above “Uncertain” until stronger sources are retrieved.
Utah, USA
US-UTschema gdpri-v2trajectory: not yet assessedhybrid regimeoverlaps: FIM, WPM, AIC
Last updated update date not yet available · 10 categories · 43
claims · 26 sources in the cumulative register
10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
43Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix(sums to 10 rendered categories; click to filter)
Jurisdiction brief
No content recorded at this JID path.
10 of 10 categories
Signal
Density
Selections OR within a group, AND across groups. Press / to search.
Core statute is in force, regulator identity and enforcement pathway are clearly documented and confirmed via primary regulator homepage and secondary legal-analysis sources.
Traffic-light rationale — GreenCore statute is in force, regulator identity and enforcement pathway are clearly documented and confirmed via primary regulator homepage and secondary legal-analysis sources.
Sub-modules (5)
Regulator And AuthorityGreen
The Division of Consumer Protection administers a consumer-complaint intake and investigation function; the Utah Attorney General holds exclusive enforcement authority over substantiated UCPA violations referred by the Division.
Claims (1):
The UCPA tasks the Division of Consumer Protection with administering a consumer-complaint system and investigating potential violations, with mandatory referral to the Attorney General where substantial evidence of a violation exists; the Attorney General holds exclusive enforcement authority.
Act And InstrumentsGreen
The UCPA (SB 227) was signed 24 March 2022 and took effect 31 December 2023, making Utah the fourth U.S. state with comprehensive consumer-privacy legislation.
Claims (1):
Governor Spencer Cox signed the Utah Consumer Privacy Act (SB 227) into law on 24 March 2022, making Utah the fourth U.S. state to enact comprehensive consumer-privacy legislation, effective 31 December 2023.
Material ScopeGreen
The UCPA applies to controllers/processors conducting business in or targeting Utah residents that meet a $25M+ annual revenue threshold combined with either 100,000+ consumers processed or 25,000+ consumers plus 50%+ revenue from data sales; it carries broad entity- and data-level exemptions (government, higher education, nonprofits, HIPAA/GLBA-covered entities, employment data).
Claims (2):
The UCPA applies to controllers/processors conducting business in Utah or targeting Utah residents with at least $25 million in annual revenue that either control/process personal data of 100,000+ consumers, or derive over 50% of gross revenue from personal-data sales and control/process data of 25,000+ consumers.
The UCPA exempts governmental entities and their contractors, institutions of higher education, nonprofit corporations, HIPAA-covered entities/business associates, and GLBA-regulated financial institutions, and excludes employment-context data and data governed by several named federal statutes.
Territorial ScopeGreen
Applicability is targeting-based (conducting business in Utah or directing products/services to Utah residents) rather than establishment-based, consistent with the Virginia-model comprehensive privacy laws.
Claims (1):
The UCPA applies to any controller or processor that conducts business in Utah or produces a product or service targeted to Utah residents, irrespective of the entity's place of establishment.
Regulator Registration And FilingRed
No evidence was found of a controller registration, licensing, or filing obligation with the Division of Consumer Protection or Attorney General under the UCPA.
Utah's data-protection landscape is anchored by the Utah Consumer Privacy Act (UCPA, SB 227), a comprehensive but business-friendly consumer-privacy statute enacted 24 March 2022 and effective 31 December 2023, enforced exclusively by the Utah Attorney General with a front-end complaint-triage role for the Division of Consumer Protection. There is no dedicated Utah data-protection authority equivalent to California's CPPA; enforcement authority sits with a generalist consumer-protection apparatus.
Sources and claims (5)
UncertainIAPP — The UCPA tasks the Division of Consumer Protection with administering a consumer-complaint system and investigating potential violations, with mandatory referral to the Attorney General where substantial evidence of a violation exists; the Attorney General holds exclusive enforcement authority.observed
UncertainDataGuidance — Governor Spencer Cox signed the Utah Consumer Privacy Act (SB 227) into law on 24 March 2022, making Utah the fourth U.S. state to enact comprehensive consumer-privacy legislation, effective 31 December 2023.observed
UncertainIAPP — The UCPA applies to controllers/processors conducting business in Utah or targeting Utah residents with at least $25 million in annual revenue that either control/process personal data of 100,000+ consumers, or derive over 50% of gross revenue from personal-data sales and control/process data of 25,000+ consumers.observed
UncertainIAPP — The UCPA exempts governmental entities and their contractors, institutions of higher education, nonprofit corporations, HIPAA-covered entities/business associates, and GLBA-regulated financial institutions, and excludes employment-context data and data governed by several named federal statutes.observed
UncertainIAPP — The UCPA applies to any controller or processor that conducts business in Utah or produces a product or service targeted to Utah residents, irrespective of the entity's place of establishment.observed
Traffic-light rationale — AmberA functioning notice/opt-out framework exists but lacks opt-in consent for sensitive categories, which is the norm among most peer state laws.
Sub-modules (4)
Lawful BasesAmber
No enumerated Article-6-style lawful-basis list exists; processing is generally permitted subject to notice and opt-out rights rather than an ex-ante lawful-basis test.
Claims (1):
Unlike the EU GDPR's enumerated lawful-basis model, the UCPA does not require a specific legal basis for general processing of personal data, relying instead on notice-and-opt-out rights for targeted advertising, sale, and sensitive-data processing.
Consent ThresholdsAmber
Affirmative (opt-in) consent under the UCPA is required only for processing personal data of consumers known to be under 13, aligned with COPPA; all other processing relies on notice/opt-out.
Claims (1):
Processing personal data of consumers known to be under age 13 requires verifiable parental consent consistent with COPPA; this is the only UCPA-regulated activity requiring affirmative opt-in consent.
Special CategoriesAmber
Sensitive data (a UCPA-defined category) is subject to a notice-and-opt-out standard rather than opt-in consent, a materially lighter-touch approach than Virginia, Colorado or Connecticut. Genetic data receives additional sector-specific protection via Utah's Genetic Testing Privacy Act.
Claims (2):
The UCPA does not require opt-in consent for processing sensitive data; controllers must instead provide clear notice and an opportunity to opt out before processing sensitive data, a lighter standard than Iowa aside, most WPA-model peer states.
Utah's genetic-privacy framework requires notice and a right to opt out for genetic-data processing, treating genetic information as a distinct sensitive category alongside the UCPA's general sensitive-data provisions.
Pseudonymisation And AnonymisationGreen
Consumer opt-out rights under the UCPA do not extend to properly de-identified or pseudonymous data meeting the Act's safe-harbour definition, consistent with the pattern shared by Colorado, Connecticut and Virginia.
Claims (1):
Consistent with Colorado, Connecticut and Virginia, Utah's opt-out rights for sale/targeted-advertising extend to pseudonymous data, unlike Iowa's narrower approach which excludes pseudonymous data from opt-out coverage.
Category narrative45 words
The UCPA does not adopt a GDPR-style enumerated lawful-basis regime; it instead relies on notice-and-opt-out mechanics for targeted advertising, sale, and sensitive-data processing, reserving opt-in consent solely for known under-13 processing (COPPA-aligned). This is materially weaker than Virginia's or Colorado's opt-in model for sensitive data.
Sources and claims (5)
UncertainIAPP — Unlike the EU GDPR's enumerated lawful-basis model, the UCPA does not require a specific legal basis for general processing of personal data, relying instead on notice-and-opt-out rights for targeted advertising, sale, and sensitive-data processing.observed
UncertainIAPP — Processing personal data of consumers known to be under age 13 requires verifiable parental consent consistent with COPPA; this is the only UCPA-regulated activity requiring affirmative opt-in consent.observed
UncertainIAPP — The UCPA does not require opt-in consent for processing sensitive data; controllers must instead provide clear notice and an opportunity to opt out before processing sensitive data, a lighter standard than Iowa aside, most WPA-model peer states.observed
UncertainIAPP — Utah's genetic-privacy framework requires notice and a right to opt out for genetic-data processing, treating genetic information as a distinct sensitive category alongside the UCPA's general sensitive-data provisions.observed
UncertainIAPP — Consistent with Colorado, Connecticut and Virginia, Utah's opt-out rights for sale/targeted-advertising extend to pseudonymous data, unlike Iowa's narrower approach which excludes pseudonymous data from opt-out coverage.observed
Core access/deletion/portability rights are confirmed in force, but the absence of correction and profiling opt-out rights represents a material gap relative to peer state laws.
Traffic-light rationale — AmberCore access/deletion/portability rights are confirmed in force, but the absence of correction and profiling opt-out rights represents a material gap relative to peer state laws.
Sub-modules (5)
Access RightGreen
Consumers have a statutory right of access to their personal data held by a controller.
Claims (1):
The UCPA establishes new consumer rights including the right of access, deletion, and portability, and the right to opt out of targeted advertising or the sale of personal data.
Rectification And ErasureAmber
A right to delete exists, but the UCPA notably omits a right to correct inaccuracies in personal data, unlike California, Virginia and Colorado.
Claims (1):
Notably absent from the UCPA is a right to correct inaccuracies in personal data, distinguishing it from California, Virginia and Colorado's comprehensive privacy laws.
Restriction And ObjectionAmber
Consumers may opt out of targeted advertising and sale of personal data, but the UCPA provides no right to opt out of profiling and does not require recognition of universal opt-out signals such as the Global Privacy Control.
Claims (1):
The UCPA provides consumers the right to opt out of processing for targeted advertising and sale of personal data, but the right to opt out of profiling is absent, and controllers are not required to recognize universal opt-out signals.
Data PortabilityGreen
A statutory data-portability right is included among the UCPA's core consumer rights.
Claims (1):
The UCPA establishes a consumer right to data portability.
Deadlines And Response WindowsGreen
Controllers must act on and respond to consumer requests within 45 days, extendable once by a further 45 days when reasonably necessary, with notice to the consumer and no fee for the initial request.
Claims (1):
Controllers must act on and inform consumers of the outcome of a rights request within 45 days, extendable once for a further 45 days if reasonably necessary, and generally may not charge a fee for the initial request.
Category narrative53 words
The UCPA grants Utah consumers rights of access, deletion, portability, and opt-out of targeted advertising/sale, but notably omits a right to correct inaccurate data, a right to opt out of profiling, and any obligation to honor universal opt-out signals — all present in Virginia/Colorado/California equivalents. Response deadlines (45+45 days) mirror the WPA-model standard.
Sources and claims (5)
UncertainDataGuidance — The UCPA establishes new consumer rights including the right of access, deletion, and portability, and the right to opt out of targeted advertising or the sale of personal data.observed
UncertainIAPP — Notably absent from the UCPA is a right to correct inaccuracies in personal data, distinguishing it from California, Virginia and Colorado's comprehensive privacy laws.observed
UncertainIAPP — The UCPA provides consumers the right to opt out of processing for targeted advertising and sale of personal data, but the right to opt out of profiling is absent, and controllers are not required to recognize universal opt-out signals.observed
UncertainDataGuidance — The UCPA establishes a consumer right to data portability.observed
UncertainDataGuidance — Controllers must act on and inform consumers of the outcome of a rights request within 45 days, extendable once for a further 45 days if reasonably necessary, and generally may not charge a fee for the initial request.observed
Security and breach-notification duties are confirmed and in force, but accountability tooling (DPIA, DPO, ROPA) that is standard among peer comprehensive privacy laws is absent from the UCPA.
Primary frameworkUtah Consumer Privacy Act (UCPA); Utah Protection of Personal Information Act; Utah Technology Governance Act
Traffic-light rationale — AmberSecurity and breach-notification duties are confirmed and in force, but accountability tooling (DPIA, DPO, ROPA) that is standard among peer comprehensive privacy laws is absent from the UCPA.
Sub-modules (7)
Accountability And DpiaAmber
The UCPA does not expressly provide for data protection or privacy impact assessment requirements, unlike Colorado, Connecticut and Virginia.
Claims (1):
The UCPA does not expressly provide for data protection or privacy impact assessment requirements.
Dpo RequirementsRed
No statutory requirement for controllers to appoint a data protection officer was identified in the UCPA text or secondary analysis reviewed.
Absence provenance: unavailable. Searched: Utah Consumer Privacy Act UCPA effective date enforcement Division of Consumer Protection, Utah Consumer Privacy Act sensitive data consent opt-in requirement definition.
Ropa RequirementsRed
No statutory records-of-processing (ROPA) obligation was identified for UCPA-covered controllers.
Absence provenance: unavailable. Searched: Utah Consumer Privacy Act UCPA effective date enforcement Division of Consumer Protection.
Joint Controller ArrangementsRed
No UCPA-specific joint-controller or processor-contract provisions were independently verified in this research pass beyond the general WPA-model pattern common to peer states.
Absence provenance: unavailable. Searched: Utah Consumer Privacy Act right to access delete opt out targeted advertising sale profiling.
Security MeasuresGreen
Controllers must establish, implement and maintain reasonable administrative, technical and physical data-security practices to protect personal data, mirroring the CCPA/VCDPA/CPA security standard.
Claims (1):
As with the CCPA, VCDPA and CPA, UCPA controllers must establish, implement, and maintain reasonable administrative, technical, and physical data security practices to protect the confidentiality of personal data.
Breach NotificationGreen
Breach notification is governed by Utah's Protection of Personal Information Act (separate from the UCPA), recently amended alongside the Utah Technology Governance Act; a 2019 amendment (SB 193) increased civil penalties for large breaches and set differentiated statutes of limitation.
Claims (2):
Utah lawmakers updated the Utah Protection of Personal Information Act and the Utah Technology Governance Act with amendments including data-breach notification requirements intended to coordinate state, local and federal cybersecurity efforts.
A 2019 amendment (SB 193) to Utah's breach-notification law permits civil penalties greater than $100,000 for breaches affecting 10,000 or more consumers and establishes five-year (civil) and ten-year (administrative) statutes of limitation for violations.
Retention And DisposalRed
No explicit UCPA-mandated data-retention limit or disposal obligation was identified in sources reviewed.
Absence provenance: unavailable. Searched: Utah Consumer Privacy Act UCPA effective date enforcement Division of Consumer Protection.
Category narrative56 words
The UCPA imposes a general security-practices obligation but expressly omits DPIA/privacy-impact-assessment, DPO-appointment, and ROPA requirements that are standard in Colorado, Connecticut and Virginia. Breach notification is governed by a separate statute (the Utah Protection of Personal Information Act), recently amended alongside the Utah Technology Governance Act, with civil-penalty and limitations provisions dating to a 2019 amendment.
Sources and claims (4)
UncertainDataGuidance — The UCPA does not expressly provide for data protection or privacy impact assessment requirements.observed
UncertainIAPP — As with the CCPA, VCDPA and CPA, UCPA controllers must establish, implement, and maintain reasonable administrative, technical, and physical data security practices to protect the confidentiality of personal data.observed
UncertainIAPP — Utah lawmakers updated the Utah Protection of Personal Information Act and the Utah Technology Governance Act with amendments including data-breach notification requirements intended to coordinate state, local and federal cybersecurity efforts.observed
UncertainDataGuidance — A 2019 amendment (SB 193) to Utah's breach-notification law permits civil penalties greater than $100,000 for breaches affecting 10,000 or more consumers and establishes five-year (civil) and ten-year (administrative) statutes of limitation for violations.observed
No comprehensive cross-border transfer regime exists at the Utah state level; this is a legitimate 'no regime' finding rather than a research gap.
Traffic-light rationale — RedNo comprehensive cross-border transfer regime exists at the Utah state level; this is a legitimate 'no regime' finding rather than a research gap.
Sub-modules (6)
Transfer MechanismsRed
State comprehensive consumer-privacy statutes such as the UCPA impose obligations centered on notices, minimization, sensitive-data handling and opt-out rights; they do not include cross-border transfer mechanisms analogous to GDPR Art. 44-49.
Claims (1):
State comprehensive consumer-privacy statutes generally impose obligations that revolve around privacy notices, data minimization and purpose limitation, sensitive personal information, data protection assessments, and universal opt-out mechanisms, rather than cross-border transfer regulation.
Adequacy ReceivedRed
Not applicable — Utah has no adequacy-recognition framework for inbound data flows.
Absence provenance: unavailable. Searched: Utah Consumer Privacy Act UCPA effective date enforcement Division of Consumer Protection.
Adequacy GrantedRed
Not applicable — Utah has no authority or mechanism to grant adequacy determinations to other regimes.
Absence provenance: unavailable. Searched: Utah Consumer Privacy Act UCPA effective date enforcement Division of Consumer Protection.
Sccs And BcrsRed
No SCC or BCR framework exists under the UCPA or Utah law generally.
Absence provenance: unavailable. Searched: Utah Consumer Privacy Act UCPA effective date enforcement Division of Consumer Protection.
Transfer Impact AssessmentRed
No transfer-impact-assessment obligation exists under the UCPA.
Absence provenance: unavailable. Searched: Utah Consumer Privacy Act UCPA effective date enforcement Division of Consumer Protection.
Data LocalisationRed
No data-localisation mandate exists under Utah law for personal data covered by the UCPA.
Absence provenance: unavailable. Searched: Utah Consumer Privacy Act UCPA effective date enforcement Division of Consumer Protection.
Category narrative44 words
As a U.S. state consumer-privacy statute, the UCPA contains no GDPR-style cross-border transfer regime: no adequacy mechanism (received or granted), no SCC/BCR framework, no transfer-impact-assessment requirement, and no data-localisation mandate. This module is structurally inapplicable to Utah's legal framework rather than a compliance gap.
Sources and claims (1)
UncertainIAPP — State comprehensive consumer-privacy statutes generally impose obligations that revolve around privacy notices, data minimization and purpose limitation, sensitive personal information, data protection assessments, and universal opt-out mechanisms, rather than cross-border transfer regulation.observed
Traffic-light rationale — GreenSectoral carve-outs are clearly and consistently documented across primary and secondary sources for the major federal overlays.
Sub-modules (7)
Financial Sector OverlayGreen
Financial institutions and data governed by Title V of the Gramm-Leach-Bliley Act are exempt from the UCPA, leaving GLBA as the operative privacy regime for Utah financial-sector personal data.
Claims (1):
The UCPA exempts financial institutions and data subject to Title V of the Gramm-Leach-Bliley Act of 1999 from its scope.
Health Sector OverlayGreen
HIPAA-covered entities/business associates and protected health information are excluded from UCPA scope, leaving HIPAA/HITECH as the operative regime for Utah health-sector data.
Claims (1):
The UCPA exempts HIPAA-covered entities and business associates, and excludes protected health information and related health-context data from its scope.
Telecoms And EprivacyAmber
Utah has no dedicated ePrivacy-style prior-consent regime for cookies/electronic communications; tracking-based advertising is instead governed through the UCPA's general opt-out-for-sale/targeted-advertising mechanism.
Claims (1):
Where a controller sells personal data to third parties or engages in targeted advertising, the UCPA requires clear and conspicuous disclosure of the means for consumers to opt out, functioning as Utah's principal mechanism for regulating tracking-based advertising in lieu of a dedicated ePrivacy-style consent regime.
Employment DataGreen
Personal data processed or maintained in the employment context, including job-applicant data, is excluded from UCPA coverage.
Claims (1):
Data processed or maintained in the course of employment, including job applicant data, is exempt from UCPA coverage.
Credit And ScoringGreen
Information subject to the federal Fair Credit Reporting Act is excluded from UCPA scope, leaving FCRA as the operative regime for Utah credit-reporting data.
Claims (1):
The UCPA excludes information subject to the federal Fair Credit Reporting Act from its material scope.
EducationGreen
Institutions of higher education are entity-exempt and FERPA-governed data is excluded from UCPA scope.
Claims (1):
The UCPA exempts institutions of higher education and excludes data subject to the federal Family Educational Rights and Privacy Act (FERPA) from its scope.
InsuranceGreen
Utah's Genetic Testing Privacy Act separately restricts insurers from requesting, requiring, or using genetic test results of asymptomatic individuals or blood relatives for underwriting, subject to enumerated exceptions.
Claims (1):
Utah's Genetic Testing Privacy Act restricts insurers from requesting, requiring, or otherwise considering genetic test results of an asymptomatic individual or blood relative for underwriting purposes, subject to enumerated exceptions.
Category narrative56 words
The UCPA's material scope carves out the principal U.S. federal sectoral regimes — GLBA for financial data, HIPAA/HITECH for health data, FCRA for credit-reporting data, and FERPA for education records — leaving those federal statutes as the operative regime in their respective sectors. A separate Genetic Testing Privacy Act restricts insurer use of genetic test results.
Sources and claims (7)
UncertainDataGuidance — The UCPA exempts financial institutions and data subject to Title V of the Gramm-Leach-Bliley Act of 1999 from its scope.observed
UncertainDataGuidance — The UCPA exempts HIPAA-covered entities and business associates, and excludes protected health information and related health-context data from its scope.observed
UncertainIAPP — Data processed or maintained in the course of employment, including job applicant data, is exempt from UCPA coverage.observed
UncertainIAPP — The UCPA excludes information subject to the federal Fair Credit Reporting Act from its material scope.observed
UncertainIAPP — The UCPA exempts institutions of higher education and excludes data subject to the federal Family Educational Rights and Privacy Act (FERPA) from its scope.observed
UncertainState of Utah / hosted via DataGuidance — Utah's Genetic Testing Privacy Act restricts insurers from requesting, requiring, or otherwise considering genetic test results of an asymptomatic individual or blood relative for underwriting purposes, subject to enumerated exceptions.observed
UncertainDataGuidance — Where a controller sells personal data to third parties or engages in targeted advertising, the UCPA requires clear and conspicuous disclosure of the means for consumers to opt out, functioning as Utah's principal mechanism for regulating tracking-based advertising in lieu of a dedicated ePrivacy-style consent regime.observed
Traffic-light rationale — AmberA functioning opt-out mechanism exists but is narrower than peer-state frameworks on signal recognition, dark patterns, and sale definition breadth.
Sub-modules (6)
Cookies And TrackersAmber
Cookie/tracker-based data sales or targeted advertising trigger a disclosure-and-opt-out obligation rather than a prior-consent requirement.
Claims (1):
Where a controller sells personal data to third parties or engages in targeted advertising, the UCPA requires clear and conspicuous disclosure of the means for consumers to opt out, functioning as Utah's principal mechanism for regulating tracking-based advertising in lieu of a dedicated ePrivacy-style consent regime.
Dark PatternsRed
No UCPA prohibition on dark patterns in obtaining consent or facilitating opt-outs was identified, unlike California and Colorado.
Absence provenance: unavailable. Searched: Utah Consumer Privacy Act right to access delete opt out targeted advertising sale profiling.
Opt Out SignalsAmber
Unlike the Colorado Privacy Act, the UCPA does not require controllers to recognize universal opt-out signals such as the Global Privacy Control.
Claims (1):
Unlike the Colorado Privacy Act, controllers subject to the UCPA are not required to recognize universal opt-out signals as a method for consumers to exercise their opt-out rights.
Clean Rooms And DcrRed
No UCPA provisions addressing data clean rooms or data-collaboration arrangements were identified.
Absence provenance: unavailable. Searched: Utah Consumer Privacy Act right to access delete opt out targeted advertising sale profiling.
Cross Context AdvertisingAmber
The UCPA defines 'sale' narrowly as an exchange of personal data for monetary consideration only, excluding non-monetary exchanges that would qualify as a 'sale' or 'share' under California's broader CCPA/CPRA framework.
Claims (1):
The UCPA contains a VCDPA-like definition of 'sale' limited to exchanges of personal data for monetary consideration, narrower than the CCPA/CPA definitions covering monetary or other valuable consideration.
Direct MarketingAmber
The UCPA's targeted-advertising opt-out right functions as Utah's principal direct-marketing control mechanism, absent a dedicated telemarketing/e-marketing consent statute within the Act itself.
Claims (1):
Consumers have the right to opt out of processing of personal data for targeted-advertising purposes under the UCPA, serving as Utah's principal statutory lever over direct-marketing-adjacent data use.
Category narrative43 words
The UCPA's adtech/commercial-privacy toolkit is limited to a notice-and-opt-out right for sale and targeted advertising, using a narrow monetary-only definition of 'sale.' The Act does not mandate recognition of universal opt-out signals (unlike Colorado), contains no dark-patterns prohibition, and has no clean-room/data-collaboration-room provisions.
Sources and claims (3)
UncertainIAPP — Unlike the Colorado Privacy Act, controllers subject to the UCPA are not required to recognize universal opt-out signals as a method for consumers to exercise their opt-out rights.observed
UncertainIAPP — The UCPA contains a VCDPA-like definition of 'sale' limited to exchanges of personal data for monetary consideration, narrower than the CCPA/CPA definitions covering monetary or other valuable consideration.observed
UncertainIAPP — Consumers have the right to opt out of processing of personal data for targeted-advertising purposes under the UCPA, serving as Utah's principal statutory lever over direct-marketing-adjacent data use.observed
Traffic-light rationale — AmberAI-specific legislation exists and is in force, but ADM transparency, profiling opt-out, and dedicated biometric protections are largely absent.
Sub-modules (6)
Profiling RestrictionsAmber
Unlike Virginia and Colorado, the UCPA does not provide consumers a right to opt out of profiling.
Claims (1):
Unlike the VCDPA and CPA, the right to opt out of profiling is absent from the UCPA.
Automated Decision Making TransparencyRed
No ADM-transparency or explanation-right provision analogous to GDPR Art. 22 was identified under the UCPA.
Absence provenance: unavailable. Searched: Utah AI Policy Act 2024 automated decision biometric law social media minors.
Ai Risk AssessmentsAmber
Utah's Artificial Intelligence Policy Act (2024) clarifies that existing consumer-protection and privacy laws apply to generative-AI uses, targeting the most harmful applications rather than mandating formal AI risk assessments as Colorado's risk-based model does.
Claims (1):
Utah's Artificial Intelligence Policy Act (2024) takes a simpler approach than risk-based AI statutes by clarifying that existing consumer-protection laws apply to generative AI, focused on defining and prohibiting the most harmful uses of AI rather than mandating formal risk assessments.
Biometric RegimeAmber
Biometric identifiers are likely captured within the UCPA's general 'sensitive data' category (subject to notice-and-opt-out) rather than governed by a dedicated biometric-specific statute analogous to Illinois' BIPA.
Claims (1):
Biometric data is understood to fall within the UCPA's general 'sensitive data' category, subject to the Act's notice-and-opt-out (rather than opt-in consent) regime, in the absence of a dedicated Utah biometric-specific statute analogous to Illinois' BIPA.
Genetic DataGreen
Utah's Genetic Testing Privacy Act restricts genetic testing, disclosure, and insurer use of genetic information, operating alongside the UCPA's sensitive-data notice-and-opt-out provisions for genetic data collected by commercial controllers.
Claims (1):
Utah's Genetic Testing Privacy Act (Utah Code Title 26, Chapter 45) restricts insurer requests for, or consideration of, genetic test results of asymptomatic individuals or their blood relatives.
State Surveillance CarveoutsAmber
The UCPA does not apply to government entities or contracted third parties acting on a government entity's behalf, functioning as a blanket exemption for state/local government data processing including surveillance-adjacent activity.
Claims (1):
The UCPA does not apply to government entities or third parties under contract with a government entity acting on that entity's behalf, providing a blanket carve-out from the state's consumer-privacy framework for government-related processing.
Category narrative81 words
The UCPA provides no right to opt out of profiling and no ADM-transparency/explanation right analogous to GDPR Art. 22. Utah's separate Artificial Intelligence Policy Act (2024) clarifies that existing consumer-protection and privacy law applies to generative-AI use cases, adopting a narrower approach than risk-based statutes like Colorado's. There is no dedicated Utah biometric-specific statute (unlike Illinois' BIPA); biometric identifiers are addressed only as part of the UCPA's general sensitive-data category. Genetic data is separately regulated under the Genetic Testing Privacy Act.
Sources and claims (5)
UncertainIAPP — Unlike the VCDPA and CPA, the right to opt out of profiling is absent from the UCPA.observed
UncertainIAPP — Utah's Artificial Intelligence Policy Act (2024) takes a simpler approach than risk-based AI statutes by clarifying that existing consumer-protection laws apply to generative AI, focused on defining and prohibiting the most harmful uses of AI rather than mandating formal risk assessments.observed
UncertainIAPP — Biometric data is understood to fall within the UCPA's general 'sensitive data' category, subject to the Act's notice-and-opt-out (rather than opt-in consent) regime, in the absence of a dedicated Utah biometric-specific statute analogous to Illinois' BIPA.observed
UncertainState of Utah / hosted via DataGuidance — Utah's Genetic Testing Privacy Act (Utah Code Title 26, Chapter 45) restricts insurer requests for, or consideration of, genetic test results of asymptomatic individuals or their blood relatives.observed
UncertainIAPP — The UCPA does not apply to government entities or third parties under contract with a government entity acting on that entity's behalf, providing a blanket carve-out from the state's consumer-privacy framework for government-related processing.observed
COPPA-aligned parental-consent baseline is solid, but the flagship minors' social-media protection is under active, unresolved federal litigation, materially weakening current enforceability.
Primary frameworkUtah Consumer Privacy Act (UCPA); Utah Minor Protection in Social Media Act (SB 194/HB 464)
Traffic-light rationale — AmberCOPPA-aligned parental-consent baseline is solid, but the flagship minors' social-media protection is under active, unresolved federal litigation, materially weakening current enforceability.
Sub-modules (5)
Age VerificationAmber
Utah's Minor Protection in Social Media Act (successor to the Social Media Regulation Act) addresses minors' access to algorithmically curated social media, but is under a federal injunction as of the last confirmed status (September 2024); current appellate/litigation status as of August 2026 was not independently reconfirmed in this pass.
Claims (1):
Utah repealed the Social Media Regulation Act in the face of technology-industry lawsuits and replaced it with the Minor Protection in Social Media Act (SB 194/HB 464), addressing algorithmic harms to minors; a federal district court partially enjoined the successor act's provisions in early September 2024 on First Amendment grounds.
Parental ConsentGreen
Controllers processing personal data of consumers known to be under 13 must obtain verifiable parental consent consistent with COPPA.
Claims (1):
Controllers processing the personal data of consumers known to be under the age of 13 are required to obtain verifiable parental consent and process such data in accordance with COPPA.
Minor Profiling BansAmber
Utah's social-media legislation created a private right of action for minors whose mental health has been harmed by an algorithmically driven social-media feature — a notable exception to Utah's general no-private-right-of-action posture, though enforceability is complicated by the pending federal injunction against the successor Act.
Claims (1):
Utah's replacement social-media law allows for a private right of action for minors whose mental health has been harmed by a social-media algorithm, one of the few private-right-of-action mechanisms in Utah's broader privacy/consumer-protection framework.
Education SettingsAmber
FERPA-governed education records and higher-education-institution data are excluded from UCPA scope; Utah has no additional UCPA-specific K-12/higher-education data-privacy overlay identified in this research pass.
Claims (1):
The UCPA excludes data subject to FERPA and exempts institutions of higher education, leaving federal education-privacy law as the operative regime for education-sector data not otherwise covered by Utah-specific minors' legislation.
Dependent AdultsRed
No Utah-specific statutory protection for dependent/vulnerable adults' personal data (elderly, mentally incapacitated) was identified within the UCPA or related state privacy statutes reviewed.
Absence provenance: unavailable. Searched: Utah Consumer Privacy Act right to access delete opt out targeted advertising sale profiling, Utah Consumer Privacy Act UCPA effective date enforcement Division of Consumer Protection.
Category narrative75 words
The UCPA aligns its under-13 parental-consent threshold with COPPA. Utah's more consequential minors' protections sit outside the UCPA in the Minor Protection in Social Media Act (SB 194/HB 464), which replaced the original Social Media Regulation Act but was preliminarily enjoined by a federal court in September 2024 on First Amendment grounds; that law also created a private right of action for minors harmed by addictive social-media algorithms. No Utah-specific dependent-adults data-protection provision was identified.
Sources and claims (4)
UncertainIAPP — Controllers processing the personal data of consumers known to be under the age of 13 are required to obtain verifiable parental consent and process such data in accordance with COPPA.observed
UncertainIAPP — Utah repealed the Social Media Regulation Act in the face of technology-industry lawsuits and replaced it with the Minor Protection in Social Media Act (SB 194/HB 464), addressing algorithmic harms to minors; a federal district court partially enjoined the successor act's provisions in early September 2024 on First Amendment grounds.observed
UncertainIAPP — Utah's replacement social-media law allows for a private right of action for minors whose mental health has been harmed by a social-media algorithm, one of the few private-right-of-action mechanisms in Utah's broader privacy/consumer-protection framework.observed
UncertainIAPP — The UCPA excludes data subject to FERPA and exempts institutions of higher education, leaving federal education-privacy law as the operative regime for education-sector data not otherwise covered by Utah-specific minors' legislation.observed
Enforcement powers and penalty ceilings are clearly defined and in force, but observable enforcement activity specific to Utah is low/opaque, and structural redress avenues for consumers (private right of action, collective redress) are largely foreclosed.
Traffic-light rationale — AmberEnforcement powers and penalty ceilings are clearly defined and in force, but observable enforcement activity specific to Utah is low/opaque, and structural redress avenues for consumers (private right of action, collective redress) are largely foreclosed.
Sub-modules (6)
Regulator Powers And PenaltiesGreen
The Attorney General has exclusive authority to enforce the UCPA, must give 30 days' written notice of alleged violations, and may seek injunctive relief and civil penalties of up to $7,500 per violation plus actual damages if a controller fails to cure.
Claims (1):
The Utah Attorney General must provide 30 days' written notice of alleged UCPA violations before initiating enforcement, and may seek an injunction and civil penalties of up to $7,500 per violation if the controller/processor fails to cure.
Enforcement Activity IndexAmber
Public enforcement activity specific to the UCPA was not identified in sources reviewed; broader 2024 multi-state tracking found only two final public state-comprehensive-privacy enforcement actions nationally, both by California, with most other states (implicitly including Utah) remaining in non-public cure-period activity.
Claims (1):
As of 2024, most U.S. state comprehensive privacy laws remained in non-public 'right to cure' enforcement phases, with only two final public state-comprehensive-privacy enforcement actions recorded that year, both brought by California's Attorney General.
Regulator Funding And CapacityRed
No data on the Division of Consumer Protection's budget or headcount specific to UCPA enforcement capacity was identified in this research pass.
The UCPA does not allow a consumer to use a violation of the Act to support a claim under other Utah laws, foreclosing indirect class-action leverage via the UCPA itself.
Claims (1):
The UCPA does not allow a consumer to use a violation of the Act to support a claim under other Utah laws, limiting indirect collective-redress pathways.
Private Right Of ActionAmber
The UCPA does not provide consumers with a private right of action; enforcement runs exclusively through the Attorney General. (A narrow, statute-specific private right of action exists outside the UCPA under Utah's minors'/social-media legislation — see children_and_vulnerable_groups.)
Claims (1):
The UCPA does not provide consumers with a private right of action; the Utah Attorney General has exclusive authority to enforce its provisions.
Recent Developments 180DRed
No Utah-specific UCPA legislative amendment, enforcement action, or judicial ruling within the last 180 days (February-August 2026) was identified in the sources reviewed for this run.
Absence provenance: unavailable. Searched: Utah Attorney General UCPA enforcement action 2025 2026 fine, Utah Minor Protection Social Media Act injunction 2026 appeal status.
Category narrative91 words
The Utah Attorney General holds exclusive UCPA enforcement authority, subject to a mandatory 30-day cure period, with penalties capped at $7,500 per violation plus actual damages and available injunctive relief. There is no private right of action under the UCPA and no mechanism to bootstrap UCPA violations into other Utah-law claims. As of the most recent multi-state review available, Utah had not yet generated a final public UCPA enforcement action; most state comprehensive-privacy enforcement in 2024 remained in non-public cure-period stages, with only California generating final public enforcement actions that year.
Sources and claims (4)
UncertainDataGuidance — The Utah Attorney General must provide 30 days' written notice of alleged UCPA violations before initiating enforcement, and may seek an injunction and civil penalties of up to $7,500 per violation if the controller/processor fails to cure.observed
UncertainIAPP — As of 2024, most U.S. state comprehensive privacy laws remained in non-public 'right to cure' enforcement phases, with only two final public state-comprehensive-privacy enforcement actions recorded that year, both brought by California's Attorney General.observed
UncertainIAPP — The UCPA does not allow a consumer to use a violation of the Act to support a claim under other Utah laws, limiting indirect collective-redress pathways.observed
UncertainDataGuidance — The UCPA does not provide consumers with a private right of action; the Utah Attorney General has exclusive authority to enforce its provisions.observed
No categories match.
Filters combine as OR inside a group and AND across
groups.
Publication gate
Blocking. 3 failing check(s).
schema_valid
pass
min_architecture_patterns
0
min_red_flags
0
min_controls
0
worked_examples_count
0
decision_tree_nodes
0
counterparty_diligence_questions
0
min_t1_per_instrument_met
n/a — no subject in this jurisdiction
min_quoted_text_present
waived — floor 0%
translation_provenance_recorded
n/a — no subject in this jurisdiction
egress_verified
pass
board_briefing_present
FAIL
every_practical_object_has_source_id
FAIL
source_tier_integrity_ok
pass
jurisdiction_source_floor_met
FAIL
tier_a_b_national_primary_pct
0.0
aggregator_only_jurisdiction_count
0
manual_override
Editorial metadata
Provenance only. Nothing below gates publication or affects the render.
Editorial metadata for Utah, USA
Field
Value
trust.lawyer_review.status
never_reviewed
trust.lawyer_review.reviewer
no reviewer on record
trust.content_source
ai_generated
Provenance and declared absence
Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.
Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.
Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.
Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.
Suppressed by doctrine: derived risk score; derived_scores = {}.
Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.
Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 43 claim(s) (43 category placement(s)), 26 source(s) in the cumulative register.
Audit trail
Machine checkChallenged on 29 Sep 2026: nothing tested (no claim on this page was eligible for an automated test). An automated, adversarial test run by a second model; no person has assessed the result.
regulator_and_framework, data_subject_rights, sectoral_watch and enforcement_and_redress modules are well-supported by convergent T2 legal-analysis sources (IAPP, DataGuidance) plus one T1 regulator homepage and one T1 statute-text PDF (Genetic Testing Privacy Act). lawful_processing_and_special_data, controller_processor_duties, adtech_and_commercial_privacy, algorithmic_biometric_and_surveillance_governance and children_and_vulnerable_groups rely primarily on T2 secondary analysis with several sub-modules resolved as legitimate absences (no DPIA/DPO/ROPA, no dark-patterns rule, no dedicated biometric statute) rather than research gaps. cross_border_and_adequacy is a structural 'no regime' finding at the module level, consistent with US state consumer-privacy law generally lacking GDPR-style transfer mechanics. No direct fetch of the full Utah Code Title 13 Chapter 61 statutory text or the Utah AG/Division UCPA effectiveness report (due 1 July 2025) was performed in this pass; findings rely on convergent secondary legal-analysis sources plus targeted primary-source anchors (Division homepage, Genetic Testing Privacy Act text).
Unresolved questions (6):
Confirm current (August 2026) appellate/litigation status of the federal injunction against Utah's Minor Protection in Social Media Act (SB194/HB464).
Confirm exact effective date and current in-force text of the Utah Artificial Intelligence Policy Act following any 2025 amendments extending or altering its sunset/repeal provisions.
Obtain Utah Division of Consumer Protection budget/headcount data specific to UCPA enforcement capacity.
Confirm whether Utah has enacted a dedicated biometric-information-privacy statute since this research pass, given the UCPA's general sensitive-data treatment of biometric identifiers.
Verify whether the UCPA-mandated Attorney General/Division effectiveness report (due 1 July 2025) has been published, and whether it recommends amendments (e.g., DPIA, private right of action, universal opt-out signal recognition).
Confirm whether any UCPA-specific Attorney General enforcement action (settlement, fine, or injunction) has been publicly announced to date.