State Guide
Utah Privacy & Data Security Laws
Every statute below can apply to a business handling Utah residents' data, depending on your revenue, the number of Utah consumers you process, and what kind of data you collect. This is a general reference, not a determination for your specific business — run the full questionnaire to see which of these actually apply to you.
Comprehensive Privacy Law · 1
Requires BOTH $25M+ annual revenue AND (100,000+ Utah consumers, or 25,000+ with 50%+ of revenue from selling personal data).
Data Security & Breach Notification · 1
Requires notifying affected residents (and often the state AG/regulator) after a breach of unencrypted personal information such as SSNs, driver's license/state ID numbers, or financial account numbers. Applies regardless of company size whenever you hold covered personal information about a resident of this state.
Genetic Privacy · 1
Regulates direct-to-consumer genetic testing companies and/or genetic data generally — typically requiring express consent before collecting, using, or disclosing genetic data, and consent (or destruction) requirements for biological samples. AG civil enforcement only, up to $2,500/violation — no private right of action.
Children & Minors Online Safety · 1
Shifts age-verification duties to app stores and requires parental consent for minors' app downloads/purchases. A 2026 amendment stripped state enforcement authority, leaving only a private right of action, and pushed most obligations out to May 6, 2027. (Note: frequently miscited as Chapter 71 — that's Utah's unrelated Franchise Protection Act; the App Store Accountability Act is Chapter 76. This correction is corroborated by multiple independent sources but not a direct rendered-page fetch — worth a quick spot-check.)