Skip to main content
Does Utah's Privacy Law Apply to You?Laws and Regulations
5 min readFor DSAR and Consent Operators

Does Utah's Privacy Law Apply to You?

You've built a consent setup for California and are handling DSARs from Colorado. Now, Utah's privacy law is on your desk, and the first question isn't how to comply, it's whether you're covered at all.

The Utah Consumer Privacy Act (UCPA) sets the highest revenue and data thresholds of any comprehensive state privacy law. Most mid-market companies won't need to worry about it. If you do fall under the UCPA, your existing multi-state controls probably already satisfy it, as Utah deliberately wrote the gentlest version of these rules.

Here's how to decide if the UCPA applies to you and what that means for your compliance setup.

The Decision You're Facing

Do you need a Utah-specific compliance workstream, or can you integrate Utah into your existing privacy program without adding process?

This isn't a technical question. It's a threshold question with two gates, and both must open before the UCPA applies to your organization.

Key Factors That Affect Your Choice

Revenue gate: Does your organization generate $25 million or more in annual revenue?

If not, you're fully exempt. The UCPA doesn't apply to you at any data volume.

If yes, move to the second gate.

Data footprint gate: Did you process personal data from 100,000 or more Utah consumers in the preceding calendar year?

Count people, not sessions or pageviews. Focus on Utah residents acting in a personal or household context. Employees and B2B contacts don't count. A good-faith estimate is acceptable; nobody expects a perfect deduplicated number across every system.

The threshold drops to 25,000 Utah consumers if you derive over half your gross revenue from selling personal data. "Selling" under Utah means exchanging data for money, not the broader "money or other valuable consideration" that California and Colorado use.

Both conditions must be true. A $30 million company processing data from 40,000 Utah consumers is exempt. A $10 million company processing data from 200,000 Utah consumers is also exempt.

Path A: You're Under the Thresholds

When to choose this path: Your revenue is below $25 million, OR your Utah consumer count is below 100,000 (or 25,000 if you're a data broker).

What it means: The UCPA doesn't apply to you. You owe Utah nothing under this statute.

What you still need: A truthful privacy notice. The FTC enforces deceptive practices everywhere, regardless of state privacy law coverage. If your notice says you don't sell data and you do, that's an FTC problem even if no state privacy law reaches you.

Next step: Check which other state laws do apply. Colorado's threshold is $25,000 in data sales revenue. Connecticut's applies to anyone who sells personal data, at any volume. You may be exempt from Utah and covered by three other states.

Path B: You Clear Both Thresholds

When to choose this path: Revenue exceeds $25 million AND you process data from 100,000+ Utah consumers (or 25,000+ if over half your revenue comes from data sales).

What it means: The UCPA applies. You're a "controller" under Utah law, and you owe the state's baseline compliance obligations.

What you can skip (for Utah visitors only):

  • Global Privacy Control. Utah doesn't require honoring GPC signals.
  • Opt-in consent for sensitive data. Utah requires clear notice and an opt-out opportunity before processing, not advance permission.
  • Data protection assessments. Not required.
  • Immediate penalties. Utah's 30-day cure period is permanent. You always get notified and get 30 days to fix a violation before penalties attach.

What you can't skip:

  • Privacy notice covering what you collect, why, and who receives it
  • Opt-out mechanism for sale and targeted advertising
  • Sensitive-data notice before processing those categories
  • Rights-request intake handling access, deletion, portability, opt-outs, and (since July 1, 2026) correction, with a 45-day response window
  • Reasonable security measures and processor contracts

Reality check: If you sell into Colorado, Connecticut, or California, their stricter rules apply to those visitors regardless of how relaxed Utah is. You're building for the strictest state that reaches each visitor, not the most permissive.

Path C: You're HIPAA-Covered

When to choose this path: Your organization is a HIPAA covered entity or business associate.

What it means: Utah exempts you entirely, at the entity level. That's broader than most states. Colorado exempts only the health data itself; Connecticut does both. A healthcare organization's obligations shift meaningfully at each state line.

What you still monitor: Your non-health business lines. If you run a health system with a consumer wellness app that isn't covered by HIPAA, that app's data may fall under the UCPA for the non-exempt portions of your business.

How This Fits Your Multi-State Program

Almost nobody builds consent infrastructure for Utah alone. Utah is the easy chapter in a 20-state compliance book.

The practical architecture is location-aware: meet the strictest rule that reaches a given visitor, ease off where a state genuinely allows it (Utah most of all), and let your Consent Management Platform decide which rules apply where.

What that looks like in practice: A Colorado visitor triggers a GPC listener and an opt-in gate for sensitive data. A Utah visitor from the same company sees notice-and-opt-out, no GPC requirement, and no assessment obligation. One configuration, different rulesets by location.

If your existing setup already handles California or Colorado, adding Utah typically means confirming your sensitive-data notice is visible and your DSAR intake now processes correction requests (required since July 2026). You're not building new infrastructure; you're confirming the strictest-state setup already covers the gaps.

Summary Matrix

Your Situation UCPA Applies? What You Owe Utah
Revenue < $25M No Truthful privacy notice (FTC standard)
Revenue ≥ $25M, Utah consumers < 100K No Truthful privacy notice (FTC standard)
Revenue ≥ $25M, Utah consumers ≥ 100K Yes Notice, opt-outs, sensitive-data notice, DSARs, security, contracts
Revenue ≥ $25M, data sales > 50% revenue, Utah consumers ≥ 25K Yes Same as above
HIPAA covered entity or business associate No (entity-level exemption) Monitor non-health business lines

If Utah applies to you, your real compliance work is probably happening in the states with lower thresholds and stricter rules. Utah's gentleness is deliberate, and for covered businesses, it's the floor, not the ceiling, of your U.S. privacy obligations.

You Might Also Like