Utah Consumer Privacy Act (UCPA)
Overview
The Utah Consumer Privacy Act (UCPA), enacted in 2022 and effective as of December 31, 2023, is a comprehensive data privacy law that grants consumers rights over their personal data and imposes responsibilities on businesses to safeguard and responsibly process that data. The UCPA aims to promote transparency in data usage, allowing consumers to access, delete, and opt out of the sale or processing of their data for targeted advertising.
Regulation Summary
Timeline
- March 24, 2022: UCPA signed into law by Governor Spencer Cox.
- December 31, 2023: UCPA becomes effective.
What Businesses Are Affected
- Businesses that conduct operations in Utah or target Utah residents and meet the following criteria:
- Generate $25 million or more in annual revenue; and
- Either:
- Process data of 100,000 or more consumers annually, or
- Derive 50% or more of gross revenue from selling data of at least 25,000 consumers.
Exemptions
- Government entities and nonprofits.
- Entities governed by HIPAA, GLBA, or other federal regulations.
- Personal data used for employment or publicly available purposes.
Responsibilities for Businesses
- Transparency: Provide a clear privacy notice detailing data collection and sharing practices.
- Consumer Rights: Allow consumers to access, delete, or obtain copies of their data and opt out of targeted advertising and data sales.
- Data Security: Implement safeguards to protect personal data.
- Sensitive Data: Obtain explicit consent before processing sensitive personal data.
Specific Responsibilities for Website Owners
- Establish a designated request address for consumer inquiries.
- Respond to consumer requests within 45 days, extendable by an additional 45 days if necessary.
- Clearly disclose opt-out options and data practices.
Additional Requirements
- Controllers and processors must:
- Maintain contracts specifying data processing terms.
- Ensure data protection for shared or processed information.
Data Subject Rights
- Access: Request a copy of personal data.
- Deletion: Request deletion of data provided by the consumer.
- Portability: Receive data in a portable format.
- Opt-Out: Refuse data sales or targeted advertising.
Enforcement
- Enforced by the Utah Attorney General.
- Cure Period: 30 days to address violations.
- Penalties: Up to $7,500 per violation, including actual damages.
- No private right of action.
Questions?
If you would like to learn more, our compliance experts are happy to support you..
Leave us a Messagesupport@clym.io
+1 980 446 8535 +1 866 275 2596