Privacy
Utah Consumer Privacy Act
The law applies only to a controller or processor that conducts business in Utah or targets products or services to Utah residents, has annual revenue of $25,000,000 or more, and either controls or processes personal data of 100,000 or more consumers during a calendar year or derives over 50 percent of gross revenue from the sale of personal data while controlling or processing personal data of 25,000 or more consumers. It does not apply to governmental entities, tribes, institutions of higher education, nonprofit corporations, HIPAA covered entities, or business associates.
What the website needs
- A covered controller must provide a reasonably accessible and clear privacy notice that lists the categories of personal data processed, the purposes of processing, how consumers may exercise a right, the categories of personal data shared with third parties, and the categories of third parties with whom personal data is shared.
- A controller that sells personal data or engages in targeted advertising must clearly and conspicuously disclose how a consumer can opt out of the sale or of processing for targeted advertising.
- A controller may not process sensitive data without first giving the consumer clear notice and an opportunity to opt out, which is an opt-out standard rather than the opt-in consent used in most other states; data about a known child must be processed under the federal Children's Online Privacy Protection Act.
- Consumers may confirm and access their data, delete data they provided, obtain a portable copy, and opt out of targeted advertising and the sale of personal data, and the right to correct inaccuracies is added effective July 1, 2026.


