Skip to main content
a promotional graphic telling you that PCI Compliance is no longer an annual exercise and that continuous monitory must be built in
Category: Laws and Regulations

Utah Consumer Privacy Act

Also known as: UCPA, S.B. 227, Utah Consumer Privacy Act (S.B. 227)
Simply put

The Utah Consumer Privacy Act (UCPA) is a state privacy law in Utah that gives consumers certain rights over their personal data, such as the ability to access and delete it, and imposes obligations on qualifying businesses. It took effect on December 31, 2023, making Utah one of the earlier US states to enact a comprehensive consumer privacy law. Compared with similar laws in states like California and Virginia, it is generally regarded as more limited in scope and applies mainly to larger businesses.

Formal definition

The UCPA (enacted as S.B. 227) is Utah's comprehensive consumer privacy statute, in effect since December 31, 2023. It grants consumers rights that generally include access, deletion, and data portability, along with the right to opt out of certain processing such as targeted advertising and the sale of personal data, reflecting the opt-out model typical of US state privacy frameworks rather than the opt-in consent model prevalent in the EU. It imposes obligations on controllers and processors, including transparency through privacy notices, purpose limitation, and reasonable data security. It is widely described as among the most limited of the US state privacy laws, applying to larger businesses and containing narrower obligations than comparable laws in California, Virginia, and elsewhere. This entry does not detail specific applicability thresholds, exemptions, or enforcement mechanisms, which depend on the statutory text and evolving guidance; practitioners should consult the current law directly, and note that the UCPA does not govern the cookie consent obligations that apply under EU or UK regimes.

Why it matters

The Utah Consumer Privacy Act is one of the earlier US state comprehensive privacy laws, having taken effect on December 31, 2023. For privacy teams tracking the patchwork of US state privacy obligations, the UCPA matters because it adds Utah to a growing list of states with their own requirements, and its comparatively narrow scope means organizations must assess whether it applies to them alongside laws in states such as California and Virginia. It reflects the opt-out model that is typical of US state privacy frameworks, which differs fundamentally from the opt-in consent model prevalent in the EU and UK.

Who it's relevant to

Privacy officers and data protection professionals
Those responsible for mapping US state privacy obligations need to determine whether the UCPA applies to their organization, given that it is generally understood to reach mainly larger businesses. They should treat it as one component of a broader multi-state compliance program rather than a standalone framework, and confirm applicability against the current statutory text.
Legal counsel and compliance teams
Counsel advising on US privacy exposure should note that the UCPA follows an opt-out model for uses such as targeted advertising and the sale of personal data, which differs from EU and UK opt-in consent requirements. Because specific thresholds, exemptions, and enforcement details depend on the statute and evolving guidance, legal review of the current law is advisable before drawing conclusions about obligations.
Marketing and advertising compliance teams
Teams running targeted advertising or activities that may qualify as a sale of personal data should understand that the UCPA generally provides consumers a right to opt out, requiring appropriate mechanisms to honor those requests. This is distinct from the prior-consent obligations that apply to cookies and similar technologies under EU and UK law.
Web developers and engineering teams
Developers implementing rights-request and opt-out functionality should support UCPA consumer rights such as access, deletion, and data portability, alongside opt-out signals for targeted advertising and sale. They should coordinate with legal and privacy teams to align technical implementations with the specific requirements of the current law and with any separate cookie consent tooling needed for EU or UK visitors.

Inside UCPA

Opt-Out Consent Model
The Utah Consumer Privacy Act (UCPA) follows an opt-out approach rather than the opt-in model prevalent in the EU. Consumers are generally permitted to opt out of certain processing activities, rather than being required to provide prior affirmative consent before their data is processed. This differs materially from the consent standard applicable in most EU jurisdictions under the GDPR and ePrivacy rules.
Right to Opt Out of Targeted Advertising and Sales
The UCPA generally provides consumers the ability to opt out of the processing of their personal data for purposes of targeted advertising and the sale of personal data. Because cookies, pixels, and similar tracking technologies frequently support targeted advertising, these opt-out rights can be relevant to how such technologies are deployed on websites.
Applicability Thresholds
The UCPA applies to certain businesses meeting defined criteria, which may include factors such as revenue and volume of consumer data processed. Not every organization operating in Utah falls within scope. The precise thresholds and definitions should be confirmed against the text of the law, as scope determinations depend on facts not fully covered by a general definition.
Relationship to Cookie and Tracking Technologies
Where cookies, SDKs, or similar technologies process personal data for targeted advertising or sale, the UCPA's opt-out framework may govern the associated data processing. Unlike the EU regime, there is generally no equivalent to the ePrivacy Directive's separate consent requirement for placing or accessing information on a device; the UCPA focuses on the processing of personal data rather than device access as such.
State-Specific Scope
The UCPA is one of several US state privacy laws and applies to conduct connected to consumers in Utah. Its requirements are not universal and differ from those of other US states such as California, as well as from EU and UK frameworks. Compliance obligations under the UCPA should not be assumed to satisfy requirements elsewhere.

Common questions

Answers to the questions practitioners most commonly ask about UCPA.

Does the Utah Consumer Privacy Act require an opt-in cookie consent banner like the EU?
No. The UCPA follows an opt-out model rather than the opt-in consent model used in most EU jurisdictions under the ePrivacy Directive and GDPR. Under the UCPA, businesses within scope are generally not required to obtain prior affirmative consent before setting most cookies; instead, consumers are typically given the right to opt out of certain processing, such as targeted advertising and the sale of personal data. This differs substantially from EU practice, where valid consent must be freely given, specific, informed, and unambiguous before non-essential cookies are placed. Organizations operating in both regions should not assume a single banner design satisfies both regimes.
Does complying with the UCPA mean a business also complies with California's CCPA/CPRA or with EU rules?
No. The UCPA is a distinct state law with its own scope, thresholds, definitions, and consumer rights. While it shares an opt-out orientation with California's framework, the two are not identical, and obligations, definitions (for example, of 'sale' or 'sensitive data'), and enforcement approaches may differ. Neither aligns automatically with EU or UK requirements, which are opt-in for non-essential cookies. Businesses subject to multiple regimes generally need to map their obligations under each separately rather than treating compliance with one as satisfying the others. Legal judgment specific to each jurisdiction is advisable.
How should a business determine whether it falls within the scope of the UCPA?
Scope generally depends on factors such as whether the business operates in or targets consumers in Utah and meets applicable revenue and data-volume thresholds defined in the statute. Because these thresholds and definitions are set by the law and may be interpreted through evolving guidance, organizations should review the current statutory text and assess their specific processing activities, revenue, and consumer numbers rather than relying on general summaries. This entry does not restate the specific thresholds; a scope determination typically warrants legal review.
What mechanism should a business provide for consumers to exercise UCPA opt-out rights related to cookies and tracking?
Under an opt-out model, businesses within scope typically need to offer a clear, accessible method for consumers to opt out of relevant processing, such as targeted advertising or the sale of personal data. In practice this may involve links or controls that allow consumers to signal their preference, and organizations often coordinate these with cookie and tracking technologies through a consent or preference management tool. Whether and how universal opt-out signals must be honored can depend on the statute and any applicable guidance, so businesses should confirm the current requirements rather than assume a particular mechanism is sufficient.
Do the UCPA's rules extend to tracking technologies other than cookies, such as pixels, SDKs, and local storage?
Privacy laws of this type generally focus on the processing of personal data rather than on cookies specifically, so similar tracking technologies, pixels, software development kits, local storage, and fingerprinting techniques, may fall within scope where they involve personal data used for covered purposes such as targeted advertising or sale. Organizations should therefore review the full range of tracking technologies they deploy, not just cookies, when assessing obligations. The precise treatment depends on how each technology processes data and on statutory definitions, which should be reviewed for the specific facts.
Can a consent management platform (CMP) ensure UCPA compliance?
A CMP can support UCPA compliance by helping present opt-out mechanisms, manage preferences, control tracking technologies, and maintain records, but no tool guarantees compliance on its own. Configuration, accurate mapping of data flows, correct categorization of processing, and ongoing legal judgment remain the organization's responsibility. A CMP configured for an EU opt-in model may not be appropriate for the UCPA's opt-out approach without adjustment. Businesses should treat CMPs as one component of a broader compliance program rather than a substitute for legal review.

Common misconceptions

The UCPA requires opt-in consent for cookies like the GDPR does.
The UCPA generally relies on an opt-out model rather than the opt-in, prior-consent standard applied in most EU jurisdictions. It does not impose the same freely given, specific, informed, and unambiguous consent requirement, and there is generally no separate device-access consent obligation equivalent to the EU's ePrivacy rules.
Complying with the UCPA means a business is compliant with cookie consent obligations everywhere.
The UCPA is a state-specific law that governs conduct connected to Utah consumers. Its requirements differ from those of other US states, the UK, and the EU. Meeting UCPA obligations does not automatically satisfy the opt-in consent standards commonly required under EU law or the differing requirements of other regimes.
The UCPA applies to every organization that uses cookies on a website visited by Utah residents.
The UCPA applies only to businesses meeting defined applicability criteria. Organizations falling below the relevant thresholds may be out of scope. Whether a specific business is covered depends on facts not resolved by a general definition and should be assessed against the statutory text.

Best practices

Confirm whether your organization meets the UCPA's applicability thresholds before assuming the law governs your use of cookies and tracking technologies, as scope depends on facts specific to your business.
Where cookies, pixels, or SDKs support targeted advertising or the sale of personal data, implement a clear and accessible mechanism for Utah consumers to exercise applicable opt-out rights.
Do not rely on a single opt-out configuration to meet requirements across jurisdictions; map how UCPA obligations differ from opt-in standards in most EU jurisdictions and from other US state laws such as California's.
Treat cookies, pixels, local storage, SDKs, and similar technologies consistently within your compliance program where they process personal data for in-scope purposes, rather than focusing on literal cookies alone.
Use consent or preference management tooling to support opt-out handling and record-keeping, while recognizing that such tools assist but do not replace legal judgment or a case-by-case scope assessment.
Verify UCPA-specific requirements, thresholds, and any applicable signal or opt-out mechanisms against the current statutory text and evolving regulatory guidance rather than assuming EU-style obligations apply.
Promotional banner for the Pentest Readiness checklist download