Utah Privacy Law
Utah’s comprehensive statute is the most business-friendly in the country and is the least interesting thing about privacy law in Utah. The Consumer Privacy Act applies only above $25 million in annual revenue, grants no profiling opt-out, and handled sensitive data by notice-and-opt-out rather than consent; a right to correct arrived only on July 1, 2026, four and a half years after enactment. What has actually moved is everything around it. The same 2025 bill that added the correction right created the Utah Digital Choice Act, a social-media data-portability and interoperability mandate with no analogue in any other state. The Minor Protection in Social Media Act requires age assurance and disables autoplay, infinite scroll and engagement notifications for minor account holders. And the Division of Consumer Protection has filed four suits against major social media companies since October 2023, making Utah one of the most litigious state privacy regulators despite having one of the mildest statutes.
The Utah Consumer Privacy Act (UCPA)
Chapter 61 of title 13 was enacted by S.B. 227 of the 2022 General Session, sponsored by Senator Kirk Cullimore with Representative Brady Brammer as floor sponsor, signed March 24, 2022 as chapter 462 and effective December 31, 2023. Section 13-61-102 is a conjunctive test rather than the disjunctive one most states use: the chapter applies only to a controller or processor that conducts business in Utah or targets Utah residents, and has annual revenue of $25,000,000 or more, and either controls or processes the personal data of 100,000 or more consumers during a calendar year or derives over fifty percent of gross revenue from the sale of personal data while controlling or processing the data of 25,000 or more consumers. Entity exemptions cover governmental entities and their contractors acting on their behalf, tribes, institutions of higher education, nonprofit corporations, and HIPAA covered entities and business associates. Section 13-61-201 as in force from December 31, 2023 granted four rights — confirmation and access, deletion of data the consumer provided, a portable copy, and an opt-out of processing for targeted advertising or the sale of personal data — with no correction right and no profiling opt-out. H.B. 418 of the 2025 session amended the section effective July 1, 2026 to add, as a new subsection (4), the right to request that a controller correct inaccuracies in the consumer’s personal data, taking into account the nature of the data and the purposes of processing.
| Effective date | December 31, 2023 |
|---|---|
| Citation | Utah Code § 13-61-101 et seq. |
| Enforced by | Utah Attorney General, on referral from the Division of Consumer Protection |
| Maximum penalty | Actual damages to the consumer plus up to $7,500 per violation under Utah Code § 13-61-402(3)(d) |
| Private right of action | No, enforcement by the state only |
| Right to cure | 30 days (permanent) |
Who Must Comply
The UCPA reaches a business that conducts business in Utah or targets Utah residents, and has annual revenue of $25,000,000 or more, and controls or processes the personal data of 100,000+ consumers in a calendar year, or derives over 50% of gross revenue from the sale of personal data while processing the data of 25,000+ consumers.
Utah splits investigation from enforcement. Section 13-61-401 puts the complaint system and investigative power in the Division of Consumer Protection, which refers a matter to the Attorney General where the director has reasonable cause to believe substantial evidence of a violation exists; § 13-61-402(1) gives the Attorney General exclusive authority to enforce, but only “upon referral from the division”. Section 13-61-402(5) allocates liability among multiple controllers or processors involved in the same violating processing according to the principles of comparative fault — a tort allocation rule no other state privacy statute contains. Recoveries go to a Consumer Privacy Restricted Account under § 13-61-403, and any year-end balance above $4,000,000 is transferred to the General Fund
Consumer Rights Under the UCPA
Residents of Utah can confirm whether a business is processing their data and obtain a copy of it, require correction of inaccurate personal data, require deletion of personal data the business holds about them, obtain their data in a portable, readily usable format, opt out of targeted advertising and opt out of the sale of their personal data.
opt-out (notice and opportunity to opt out)
Sector-Specific Privacy Laws in Utah
Utah Digital Choice Act (Utah Code tit. 13, ch. 75)
Chapter 75 was enacted by H.B. 418 of the 2025 General Session, “Data Sharing Amendments”, with most sections effective July 1, 2026. It is a social-media interoperability mandate rather than a privacy statute in the ordinary sense. Section 13-75-201 provides that where a consumer requests a copy of personal data under § 13-61-201, a social media service must provide it including the user’s social graph, in a format that is portable to the extent technically feasible, readily usable to the extent practicable, and transmissible to another controller without impediment. Section 13-75-202 goes further and requires a social media company to implement a transparent, third-party-accessible interoperability interface allowing users to share a common set of their personal data between services they designate and to let third parties access content they create and be notified when new content is available, with permission. To achieve that, the company must use an “open protocol” — defined at § 13-75-101 as a publicly available technical standard enabling interoperability and data exchange between social media services through a common data infrastructure, free from licensing fees and patent restrictions — maintain synchronous data sharing on reasonable, non-discriminatory terms, set proportionate thresholds on request frequency and volume beyond which a reasonable fee may be charged, offer other companies a functionally equivalent version of any internal interfaces built for its own services, and publish complete, accurate and regularly updated documentation of interface access. Data obtained through the interface may not be shared or received without the user’s consent. The same bill repealed chapter 63, the Utah Social Media Regulation Act, from the Division of Consumer Protection’s list of administered chapters.
Utah Minor Protection in Social Media Act (Utah Code tit. 13, ch. 71)
Chapter 71 was enacted by S.B. 194 of the 2024 General Session, effective October 1, 2024. Section 13-71-201 requires a social media company to implement an age assurance system to determine whether an account holder is a Utah minor, and restricts the personal information gathered for that purpose to age determination and the purposes enumerated at § 13-71-204(4). Section 13-71-202 sets defaults for minor account holders rather than leaving them to design choice: account visibility restricted to connected accounts, sharing limited to connected accounts, data collection and sale restricted to what is required for core functioning, search engine indexing of the profile disabled, direct messaging limited to connected accounts, and a downloadable file of all account information. It requires reasonable security measures including data encryption, an accessible notice describing what is collected and how it may be used or disclosed, deletion of the minor’s personal information on request, and removal of material the minor made publicly available. Subsection (5) is the design mandate: the company must disable autoplay functions that continuously play content without user interaction, scroll or pagination that loads additional content as long as the user keeps scrolling, and push notifications prompting repeated engagement. Section 13-71-203 requires supervisory tools a minor may choose to activate, letting a designated individual set daily time limits across devices, schedule mandatory breaks, and view total and average daily time, connected accounts and blocked accounts. Section 13-71-301 gives the Division of Consumer Protection administration and enforcement: the director may impose an administrative fine of up to $2,500 for each violation, and a court may impose a civil penalty of up to $2,500 per violation, order disgorgement and payment of disgorged money to injured consumers, award actual damages, and award the Division its attorney fees, court costs and investigative fees; violating an administrative or court order carries up to $5,000 per violation. Section 13-71-302 creates a safe harbor from § 13-71-201 enforcement for a company maintaining an age assurance system the Division’s rules certify as 95% accurate.
Protection of Personal Information Act (Utah Code § 13-44-101 et seq.)
Chapter 44 carries Utah’s breach duty, and § 13-44-202 as amended by S.B. 127 of the 2023 session turns on misuse rather than on acquisition. A person who owns or licenses computerized data including personal information about a Utah resident must, on becoming aware of a breach of system security, conduct in good faith a reasonable and prompt investigation to determine the likelihood that the information has been or will be misused for identity theft or fraud. Only if the investigation reveals that such misuse has occurred or is reasonably likely to occur does the notice duty attach. The statute then runs three escalating thresholds off that same finding: notice to each affected Utah resident at any number; notice additionally to the Office of the Attorney General and to the Utah Cyber Center created in § 62A-16-510 where 500 or more Utah residents are involved; and notice additionally to each nationwide consumer reporting agency where 1,000 or more are involved. Notice is due in the most expedient time possible without unreasonable delay, allowing for law enforcement needs, determining the scope of the breach, and restoring the reasonable integrity of the system. A person who merely maintains or possesses personal information on another’s behalf notifies and cooperates with the owner or licensee immediately following discovery.
Utah Consumer Sales Practices Act (Utah Code tit. 13, ch. 11)
Chapter 11 is Utah’s unfair-practices statute, administered and enforced by the Division of Consumer Protection under § 13-2-1, and it is the vehicle the Division and the Attorney General have used for their social media litigation rather than the Consumer Privacy Act. The Division’s claims against social media companies are pleaded around unconscionable design features and misrepresentations about platform safety — conduct that fits the deception and unconscionability standards of chapter 11 — rather than around the consumer-rights machinery of chapter 61, whose $25 million revenue floor and referral-gated enforcement make it a slower instrument.
Data Breach Notification in Utah
Section 13-44-202 does not treat unauthorized acquisition as the trigger. The duty begins with an investigation: a person aware of a breach of system security conducts in good faith a reasonable and prompt investigation to determine the likelihood that personal information has been or will be misused for identity theft or fraud purposes, and notice is owed only where that investigation reveals such misuse has occurred or is reasonably likely to occur. From that single finding the statute runs three thresholds, each additive: every affected Utah resident is notified regardless of number; at 500 or more Utah residents the Office of the Attorney General and the Utah Cyber Center created in § 62A-16-510 are added, a two-agency structure S.B. 127 introduced in 2023; and at 1,000 or more each nationwide consumer reporting agency as defined in 15 U.S.C. § 1681a is added. Notice may be written by first-class mail to the most recent address on record, electronic where that is the primary method of communication or where it complies with 15 U.S.C. § 7001, or by telephone including through automatic dialing technology not otherwise prohibited. A person may delay notice at the request of a law enforcement agency that determines it would impede a criminal investigation, and must notify in good faith without unreasonable delay once the agency says otherwise.
Residents must be notified in the most expedient time possible without unreasonable delay, once the investigation reveals that misuse for identity theft or fraud has occurred or is reasonably likely to occur. Notify the Office of the Attorney General and the Utah Cyber Center where 500 or more Utah residents are involved; notify the nationwide consumer reporting agencies where 1,000 or more are involved. Complaints are taken by the Utah Attorney General, which enforces the statute.
How the UCPA Is Enforced
A referral gate, a permanent cure period, and a capped account. Section 13-61-402(3)(a) requires the Attorney General, at least thirty days before initiating an enforcement action, to provide written notice identifying each provision alleged to have been violated together with an explanation of the basis for each allegation. No action may be initiated if the controller or processor cures the noticed violation within thirty days and provides an express written statement that it has been cured and that no further violation of it will occur. An action may be brought where the target fails to cure, or where it cures, gives that statement, and then continues to violate the chapter. Unlike the sunsetting cure periods in Colorado, Connecticut and Maryland, Utah’s has no expiry date.
Two enforcement schedules for minors’ platforms. The Minor Protection in Social Media Act is enforced by the Division of Consumer Protection rather than through the Attorney General referral route. Section 13-71-301 lets the director impose an administrative fine of up to $2,500 for each violation, and lets a court in a Division action declare the practice unlawful, enjoin it, order disgorgement and payment of disgorged money to injured consumers, impose a civil penalty of up to $2,500 per violation, and award actual damages. Where the Division obtains judgment or injunctive relief the court “shall” award it reasonable attorney fees, court costs and investigative fees. Violating an administrative or court order issued under the chapter carries a further civil penalty of up to $5,000 per violation, and receipts go to the Consumer Protection Education and Training Fund under § 13-2-8.
Recent Enforcement in Utah
State of Utah v. Snap Inc. — filed June 30, 2025 over My AI and platform design. On June 30, 2025 the Division of Consumer Protection and the Office of the Attorney General jointly filed suit in state court against Snap, Inc. The Attorney General’s office records it as the fourth suit the two offices have brought against a major social media company. The complaint alleges that Snap profits from unconscionable design features created to addict children to the app and that the platform facilitates illegal drug sales and sextortion, and it adds claims about the My AI chatbot: that it was introduced lacking proper testing and safety protocols and gave misleading or harmful advice to underage users, that it collects geolocation data even when “Ghost Mode” is activated, that Snap does not disclose OpenAI’s involvement in processing, and that its placement above human contacts and the inability to remove it are dark patterns. Attorney General Brown stated that “Snapchat’s features facilitate sexual predators and drug dealers’ efforts to target and exploit children”.
Utah v. TikTok — two suits, and the unsealing of Project Meramec. The state filed its first consumer protection case against TikTok on October 10, 2023, alleging that the company misrepresented the safety of its platform while using algorithms that encourage addictive use by children. A second suit followed on June 3, 2024, focused on the LIVE feature and alleging that the platform failed to protect minors from sexual exploitation and harm during real-time interactions. On January 3, 2025 the Division announced the release of previously redacted allegations in the second complaint, drawn from TikTok’s own internal investigation which the company called “Project Meramec”; the Division alleges that investigation showed the company knew hundreds of thousands of minors were accessing LIVE, that its age restrictions were ineffective, and that children were being sexually exploited while “TikTok decided not to stop anything because of the financial profits it was raking in”. The same unredacted filing describes a second internal investigation, “Project Jupiter”, documenting money laundering and terrorist financing through the LIVE feature. A suit against Meta was filed October 24, 2023 alleging design intended to keep children engaged for longer while downplaying known risks to youth mental health.
Pending Privacy Legislation
Utah’s legislature has amended its privacy framework in every recent session. S.B. 227 of 2022 enacted the Consumer Privacy Act as chapter 462, signed March 24, 2022 and effective December 31, 2023. S.B. 127 of 2023 rewrote the breach statute at § 13-44-202, adding the Utah Cyber Center as a second recipient at the 500-resident threshold and the nationwide consumer reporting agencies at 1,000. S.B. 194 of 2024 enacted the Minor Protection in Social Media Act at chapter 71 effective October 1, 2024, with age assurance, maximum-privacy defaults, disabled engagement mechanics and a 95%-accuracy safe harbor. H.B. 418 of 2025, “Data Sharing Amendments”, did the most: it added the right to correct at § 13-61-201(4) effective July 1, 2026, enacted the Utah Digital Choice Act at chapter 75 with its portability and interoperability mandates on the same date, and removed the repealed Utah Social Media Regulation Act at chapter 63 from the Division of Consumer Protection’s list of administered chapters.
Federal Privacy Laws That Apply in Utah
Federal privacy law applies in Utah by sector, whatever the state has enacted: HIPAA to health information, the Gramm-Leach-Bliley Act to financial institutions, FERPA to student education records, the Fair Credit Reporting Act to consumer reports, COPPA to children under 13, and Section 5 of the FTC Act to privacy claims that do not match practice.
The UCPA sits alongside those rules rather than displacing them: the Utah Attorney General, on referral from the Division of Consumer Protection enforces the state law, while the federal regulators continue to reach the sectors and activities they cover.
Utah Privacy Law FAQ
When did Utah consumers get a right to correct their data?
What does the Utah Digital Choice Act require of social media companies?
Who investigates a Utah Consumer Privacy Act complaint?
What can Utah recover for a privacy violation, and where does the money go?
How is liability divided when several companies are involved in one violation?
What must a Utah social media company turn off for minor account holders?
Does Utah’s breach law trigger on acquisition or on misuse?
Has Utah sued social media companies, and under what law?
Sources
This guide describes what these documents say. Follow them to check the description against the source.
- Utah S.B. 227 (2022) — Consumer Privacy Act, enrolled copy statute
- Utah S.B. 227 (2022) — bill status, sponsors and effective date legislation
- Utah Code § 13-61-201 — Consumer rights, version effective 12/31/2023 statute
- Utah S.B. 127 (2023) — Protection of Personal Information Act amendments, enrolled copy statute
- Utah S.B. 194 (2024) — Minor Protection in Social Media Act, enrolled copy statute
- Utah H.B. 418 (2025) — Data Sharing Amendments and the Utah Digital Choice Act, enrolled copy statute
- Utah Attorney General — social media litigation agency
- Utah Department of Commerce — Utah sues Snapchat over My AI and platform safety agency
- Utah Department of Commerce — release of previously redacted information in the TikTok complaint agency
- 45 CFR Part 164 — HIPAA Privacy and Security Rules regulation
- 15 U.S.C. 6801 — Gramm-Leach-Bliley Act statute
- 20 U.S.C. 1232g — Family Educational Rights and Privacy Act statute
- 15 U.S.C. 1681 — Fair Credit Reporting Act statute
- 16 CFR Part 312 — Children’s Online Privacy Protection Rule regulation
- Section 5 of the FTC Act, 15 U.S.C. 45 statute
Reporting, not legal advice. This guide describes privacy law using publicly available primary sources, which are linked at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.