Utah Consumer Privacy Act
Evidence request list. 27 controls, 27 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Enforcement
Per UCPA: Utah AG enforcement + 30-day cure period + civil penalties up to USD 7,500 per violation.
- UCPA evidence for UTAHUCPA-5
- sale opt-out + cure partial
Notice
Per UCPA: privacy notice + processor agreements.
- UCPA evidence for UTAHUCPA-4
- sale opt-out + cure partial
Rights
Per UCPA: consumer rights including Confirm and Access + Right to Delete + Right to Data Portability + Right to Opt Out of Sale + Right to Opt Out of Targeted Advertising. Note: no opt-out of profiling and no UOOM required (Comparative Note: Absence of UOOM).
- UCPA evidence for UTAHUCPA-2
- sale opt-out + cure partial
Scope
Per Utah Consumer Privacy Act (UCPA) effective Dec 2023: Scope and Applicability Thresholds + definitions including consumer + controller + processor + sensitive data.
- UCPA evidence for UTAHUCPA-1
- sale opt-out + cure partial
Sensitive
Per UCPA: sensitive data consent + children's data per Utah Code.
- UCPA evidence for UTAHUCPA-3
- sale opt-out + cure partial
Utah Code 13-61 Part 1: Scope and Definitions
Establishes statutory definitions including consumer (Utah resident acting in individual or household context, excluding employment or B2B contexts), controller (person determining purposes and means of processing), processor (person processing on behalf of controller), personal data (linked or reasonably linkable to identified or identifiable individual, excluding deidentified, aggregated, or publicly available data), sensitive data (racial or ethnic origin, religious beliefs, sexual orientation, citizenship or immigration status, medical or mental health information, genetic or biometric data processed to identify a specific individual, and specific geolocation data), sale (exchange of personal data for monetary consideration only), and targeted advertising.
- Applicability analysis identifying Utah residents in consumer (not employment/B2B) contexts
- Data classification scheme distinguishing personal data from deidentified, aggregated, public
- Sensitive data taxonomy aligned to UCPA categories
- Definition crosswalk to other state privacy laws (CCPA, VCDPA, CPA)
- Employment and B2B data incorrectly scoped in
- Sale defined per CCPA broad standard rather than UCPA monetary-only standard
- Sensitive data category list omits citizenship or immigration status
UCPA applies to a controller or processor that conducts business in Utah or produces a product or service targeted to Utah residents, has annual revenue of $25,000,000 or more, and satisfies one or both of the following: during a calendar year, controls or processes personal data of 100,000 or more Utah consumers; or derives over 50 percent of gross revenue from the sale of personal data and controls or processes personal data of 25,000 or more Utah consumers. Numerous exemptions apply including GLBA-regulated financial institutions, HIPAA-covered entities and business associates, FCRA-covered consumer reporting agencies, nonprofits, higher education institutions, and tribes.
- Annual revenue attestation crossing or not crossing $25M threshold
- Utah resident consumer count methodology and quarterly tracking
- Sale revenue percentage calculation showing under or over 50%
- Documented basis for any claimed entity-level or data-level exemption
- Annual reapplication review
- Revenue threshold not measured against US revenue only, or against full global revenue improperly
- Utah consumer counts based on accounts rather than unique consumers
- GLBA exemption claimed for entity but not data outside scope
- No annual reapplicability review
Utah Code 13-61 Part 2: Consumer Rights
A consumer has the right to confirm whether a controller is processing the consumer's personal data and to access that personal data, except where such confirmation or access would require disclosure of a trade secret. The controller shall respond to an authenticated consumer request within 45 days of receipt, extendable once by an additional 45 days where reasonably necessary with notice to the consumer.
- Consumer request intake mechanism (web form, email, account portal)
- Identity authentication procedure (reasonable, not unduly burdensome)
- Access response template covering categories and specific personal data
- Request log with receipt date, response date, extension notices, outcomes
- Trade secret withholding rationale documentation
- 45-day clock not tracked from receipt
- Extension notices not sent before original deadline lapses
- Authentication treated as a barrier rather than identity confirmation
- No documented basis for trade secret carve-out
A consumer has the right to delete the consumer's personal data that the consumer provided to the controller. Unlike Colorado, Virginia, and Connecticut, the UCPA deletion right is limited to data the consumer provided directly and does not extend to data the controller obtained from other sources.
- Deletion request intake mechanism
- Data provenance tagging that distinguishes consumer-provided data from third-party-sourced or derived data
- Deletion execution log with verification
- Documented exclusion of non-consumer-provided data with rationale
- Service provider deletion propagation (where applicable)
- Deletion treated as broad CCPA-style right rather than provider-scoped
- No provenance metadata to scope the right correctly
- Third-party-sourced data deleted unnecessarily or retained without justification
- No verification that deletion occurred in production and backups per retention policy
A consumer has the right to obtain a copy of the personal data that the consumer previously provided to the controller in a portable and, to the extent technically feasible, readily usable format that allows the consumer to transmit the data to another controller without impediment, where the processing is carried out by automated means.
- Portability request workflow
- Standard machine-readable export formats (CSV, JSON)
- Documentation of scope: consumer-provided data only
- Sample export demonstrating readability and transmissibility
- Request log with format selected and delivery confirmation
- Exports in PDF or other non-portable formats
- Portability scope expanded beyond consumer-provided data
- No documented method for delivering large exports securely
A consumer has the right to opt out of the processing of the consumer's personal data for purposes of the sale of personal data. Sale under UCPA is narrowly defined as the exchange of personal data for monetary consideration by a controller to a third party, excluding several scenarios such as disclosure to a processor, affiliate, or as part of a merger.
- Conspicuous opt-out method (privacy policy link, web form, email)
- Sale inventory: third parties receiving personal data for monetary consideration
- Opt-out request log with implementation evidence
- Suppression list propagated to recipients
- Documentation of excluded transfers (processor, affiliate, M&A) with rationale
- Opt-out limited to one channel making access difficult
- Sale inventory absent or based on CCPA non-monetary definition
- No suppression flag on consumer record
- Affiliates incorrectly treated as third parties
A consumer has the right to opt out of the processing of the consumer's personal data for purposes of targeted advertising. Targeted advertising is defined as displaying an advertisement to a consumer where the advertisement is selected based on personal data obtained from the consumer's activities over time and across nonaffiliated websites or online applications to predict the consumer's preferences or interests. UCPA does not require recognition of universal opt-out mechanisms (unlike CPA, CTDPA, and others).
- Targeted advertising opt-out mechanism (cookie banner setting, account preference, dedicated link)
- Inventory of advertising vendors and SDKs that trigger targeted ads
- Opt-out propagation evidence to advertising platforms
- Tag management documentation showing opt-out enforcement
- Exclusions documented for first-party contextual ads and frequency capping
- Opt-out blocked behind account creation
- Adtech vendors not configured to honor opt-out
- No distinction between first-party contextual and cross-context behavioral advertising
- Universal opt-out mechanism implemented unnecessarily and treated as required
A controller is not required to comply with a request from a consumer if the controller cannot authenticate the request using commercially reasonable efforts, and may request that the consumer provide additional information reasonably necessary to authenticate the request and the consumer's identity. The controller is not required to authenticate an opt-out request but may deny an opt-out request if the controller has a good faith, reasonable, and documented belief that the request is fraudulent.
- Tiered authentication procedure scaled to data sensitivity
- Authentication failure log and follow-up notices
- Fraud determination procedure with documented criteria for denying opt-out
- Records of authenticated requests that proceeded to fulfillment
- Excessive authentication used to discourage requests
- Opt-out requests authenticated as if access requests, slowing them
- No documented fraud criteria
A controller shall respond to a consumer request within 45 days after receipt, may extend by 45 additional days where reasonably necessary with notice including the reason, and may charge a reasonable fee or refuse to act on a manifestly unfounded, excessive, or repetitive request, with the controller bearing the burden of demonstrating manifestly unfounded or excessive nature. Notably, UCPA does not require a consumer appeals process (unlike VCDPA, CPA, CTDPA).
- SLA tracker measuring 45-day clock
- Extension notice templates with documented justification
- Reasonable fee schedule for repetitive or excessive requests
- Evidence supporting any manifestly unfounded determinations
- No appeal mechanism is required but if implemented, document procedure
- No tracking of receipt date versus response date
- Fees charged on first request rather than only on manifestly unfounded/excessive ones
- Appeal mechanism implemented and treated as legally required, creating false compliance baseline
Utah Code 13-61 Part 3: Controller and Processor Duties
A controller shall establish, implement, and maintain reasonable administrative, technical, and physical data security practices designed to protect the confidentiality and integrity of personal data and reduce reasonably foreseeable risks of harm to consumers relating to the processing of personal data. The practices shall be appropriate to the volume and nature of the personal data at issue.
- Written information security program (WISP) or equivalent
- Risk assessment correlating safeguards to personal data volume and nature
- Administrative controls (policies, training, vendor management)
- Technical controls (encryption, access control, logging)
- Physical controls
- Annual review and update evidence
- No documented mapping of controls to UCPA personal data
- Safeguards not scaled to data volume
- No documented incident response plan
- Vendor risk assessments absent
Where a controller possesses or controls deidentified data, the controller shall take reasonable measures to ensure the data cannot be associated with an individual, publicly commit to maintaining and using the deidentified data only in a deidentified form and not attempt to reidentify, and contractually obligate any recipients to comply with the same standards.
- Deidentification methodology documentation
- Technical controls preventing reidentification (k-anonymity, generalization, suppression)
- Public commitment statement in privacy notice or separate publication
- Contractual flow-down clauses with recipients
- Periodic reidentification risk testing
- Deidentification methodology unspecified
- No public commitment statement
- Recipient contracts lack flow-down
- Risk testing absent
A controller shall provide consumers with a reasonably accessible and clear privacy notice that includes the categories of personal data processed, the purposes for which the categories are processed, how consumers may exercise their rights, the categories of personal data the controller shares with third parties, and the categories of third parties with whom personal data is shared.
- Published privacy notice covering all five required categories
- Mapping of categories of personal data to processing purposes
- List of categories of third-party recipients
- Versioning history of notice with effective dates
- Reasonably accessible placement (homepage link, app settings)
- Third-party recipient categories vague (e.g. service providers)
- Rights exercise instructions buried or absent
- No notice tailored to Utah residents or no statement that Utah rights apply
Although UCPA generally uses an opt-out model for sensitive data, biometric data processed to identify a specific individual and specific geolocation data (within a radius of 1,750 feet) are part of the sensitive data definition and trigger the §13-61-302(4) notice and opt-out requirement. Controllers should treat biometric and precise geolocation processing with elevated documentation given the heightened risk profile and overlap with Utah biometric statute considerations.
- Biometric processing inventory with purpose and retention
- Geolocation precision determination (whether falls within 1,750 feet threshold)
- Pre-processing notice and opt-out evidence
- Vendor contracts addressing biometric processing limits
- Retention and deletion schedule for biometric templates
- Geolocation precision not measured against statutory radius
- Biometric retention indefinite
- No vendor flow-down for biometric handling
If a controller sells personal data to third parties or processes personal data for targeted advertising, the controller shall clearly and conspicuously disclose to the consumer the manner in which the consumer may exercise the right to opt out of the sale or targeted advertising.
- Privacy notice section explicitly addressing sale and targeted advertising practices
- Conspicuous opt-out link or instructions
- Screenshots of opt-out placement on consumer-facing surfaces
- Documentation of the determination whether sale or targeted advertising occurs
- Sale or targeted advertising disclosure missing despite practices that meet UCPA definitions
- Opt-out link placement inconspicuous
- No clear instructions for non-account holders
A controller may not process a consumer's sensitive data without first presenting the consumer with clear notice and an opportunity to opt out of the processing. This is a critical UCPA distinction: unlike VCDPA, CPA, and CTDPA which require opt-in consent for sensitive data, UCPA only requires notice and opt-out for most sensitive data. Processing of personal data concerning a known child must be in accordance with COPPA.
- Sensitive data inventory aligned to UCPA categories
- Pre-processing notice presented to consumers when sensitive data is collected
- Sensitive data opt-out mechanism
- Opt-out propagation evidence
- COPPA compliance documentation for known-child data
- Opt-in consent treated as required (over-compliance creating cost without benefit)
- Notice provided after processing begins rather than before
- Children's data processed without COPPA verifiable parental consent
A controller may not process personal data in violation of state and federal laws that prohibit unlawful discrimination against consumers, and may not discriminate against a consumer for exercising a right under UCPA by denying goods or services, charging different prices or rates, or providing different levels of quality, except where the differential treatment is reasonably related to the value provided by the consumer's data (e.g. loyalty programs).
- Non-discrimination policy referencing UCPA rights exercise
- Loyalty program documentation showing reasonable relationship to data value
- Training records for customer-facing teams
- Audit logs confirming consistent treatment of opted-out consumers
- Opt-out triggers loss of unrelated services or pricing
- Loyalty program data-value calculation absent
- Customer service scripts not updated to prevent discrimination
A processor shall adhere to the instructions of a controller and assist the controller in meeting its obligations, including responding to consumer rights requests and providing reasonable information necessary to demonstrate compliance. Processing by a processor shall be governed by a contract between the controller and processor that clearly sets forth instructions for processing, the nature and purpose, the type of data, duration, and the rights and obligations of both parties. Notably, UCPA does NOT require formal Data Protection Assessments (DPAs) unlike VCDPA, CPA, and CTDPA.
- Standard processor contract template containing all UCPA-required elements
- Vendor inventory classifying each as controller, processor, or third party
- Contract sampling showing instructions, purpose, data types, duration
- Processor assistance procedure for consumer rights requests
- Subcontractor flow-down provisions
- Legacy vendor agreements missing UCPA-specific clauses
- No classification of processor versus third party
- Subcontractor flow-down absent
- Over-compliance: full DPIA required of vendor where UCPA does not require it
UCPA does not apply to specified data and activities including: protected health information under HIPAA; data subject to GLBA; data subject to FCRA; data subject to the Driver's Privacy Protection Act; data subject to FERPA; data subject to the Farm Credit Act; employment-related information; emergency contact information; data necessary to administer benefits; certain research activities; and various other narrowly defined categories. A controller's compliance with the parental consent requirements of COPPA shall be deemed compliance with parental consent requirements under UCPA.
- Exemption analysis identifying which statutory exemptions apply to which data flows
- Data classification labeling exempt categories
- Documented limits of exemptions (e.g. HIPAA data only, not other entity data)
- COPPA compliance evidence where applied
- Entity-level exemption claimed for organization but not data outside scope
- HIPAA exemption applied to marketing data of HIPAA-covered entity
- Employment data exemption stretched to former-employee marketing
UCPA became effective on 31 December 2023. Obligations apply to processing occurring on or after that date, with no transition or grandfathering period for legacy data. Controllers must apply UCPA requirements to all in-scope personal data regardless of when it was collected.
- Compliance program implementation evidence dated on or before 31 December 2023 (or remediation log thereafter)
- Legacy data inventory and UCPA application analysis
- Ongoing program management calendar (annual review, training refresh, vendor reassessment)
- Quarterly threshold reassessment
- Legacy data not assessed under UCPA
- No anniversary review of program
- Vendor reassessment not on regular cadence
- Threshold not re-checked annually
Utah Code 13-61 Part 4: Enforcement
Before the Attorney General may initiate an enforcement action, the controller or processor must have an opportunity to cure the alleged violation within 30 days of receiving notice from the AG. If the controller cures the violation and provides the AG with an express written statement that the violation has been cured and no further violations will occur, no action may be initiated. Unlike Colorado, Connecticut, and Virginia (which sunset their cure periods), the UCPA cure period is permanent.
- Documented cure response procedure with 30-day SLA
- Standard written attestation template
- Root-cause analysis and remediation evidence for any cure scenarios
- Internal training on cure period mechanics
- Records demonstrating no recurrence
- No formal cure response procedure
- Written attestation omits no-recurrence statement
- Remediation cosmetic rather than systemic
If a violation is not cured within the 30-day period, the Attorney General may bring an action and the court may impose: actual damages to consumers; and an amount not to exceed $7,500 for each violation. Penalties are paid into a Consumer Privacy Account. The cap on penalty per violation is significantly higher than CCPA per-violation amounts but lacks the per-record multiplier seen elsewhere.
- Risk register entry quantifying potential penalty exposure
- Consumer count estimates for worst-case scenarios (per violation)
- Insurance coverage analysis (cyber, E&O)
- Board reporting on regulatory risk posture
- Penalty exposure not modeled
- Insurance coverage assumes private right of action standards
- No board-level visibility on Utah-specific risk
The Utah Attorney General has exclusive authority to enforce UCPA. The Division of Consumer Protection investigates suspected violations and refers substantiated cases to the Attorney General. The UCPA expressly does not provide a private right of action. The Attorney General may initiate an enforcement action only after providing the controller or processor written notice identifying the specific provisions alleged to be violated.
- Procedure for receiving and routing Utah AG or DCP notices
- Designated legal contact for state inquiries
- Documentation showing the absence of private right of action communicated in internal training
- Records of any AG/DCP communications and responses
- No designated point of contact for state regulator notice
- Privacy team unfamiliar with DCP role
- Defensive posture treats UCPA as enabling private litigation
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.