Marketing Measurement ·

What marketers need to know about the Utah Consumer Privacy Act

The Utah Consumer Privacy Act (UCPA) changes what marketers can track and measure. See who it covers, what it requires, and how to prepare your reporting.

Listen
0:00 / 0:00
AI-generated audio
What marketers need to know about the Utah Consumer Privacy Act

A boutique owner keeps a clicker by the front door and taps it every time someone walks in. It works well until a chunk of shoppers start using the side entrance. The count still looks neat and the trend line still moves, but nobody tells her it's now wrong by an amount she can't see.

Privacy laws like the Utah Consumer Privacy Act are opening more of those side entrances for marketers. Every opt-out, blocked pixel, and deleted record—small as each one seems—pulls a little more of the customer picture out of the data your dashboards rely on. That's why it pays to know what this law asks of your business and where it changes your data. Teams that plan for it early keep their budget decisions on solid ground, while everyone else finds out later that their reporting drifted.

Key takeaways

  • The Utah Consumer Privacy Act has applied since December 31, 2023, and it covers businesses with $25 million or more in annual revenue that handle the personal data of enough Utah consumers.
  • Utah consumers can access, delete, correct, and port their personal data and opt out of targeted advertising and sales, and you have 45 days to answer each request.
  • Sensitive data, like specific geolocation data or health information, needs clear notice and a chance to opt out before you process it.
  • Utah's definition of targeted advertising leaves out processing done solely to measure ad performance, but the rules on sales, sensitive data, and vendor contracts still apply.
  • Aggregated data sits outside the definition of personal data, so measurement built on totals instead of individual tracking is less exposed to opt-outs.
  • Only the attorney general can enforce the law, with a 30-day cure period, penalties of up to $7,500 per violation, and no private right to sue.
  • The bigger threat to your tracking is the patchwork of around 20 state privacy laws, not Utah alone.

What the Utah Consumer Privacy Act is and when it took effect

The Utah Consumer Privacy Act (UCPA) gives Utah consumers more say over how businesses collect and use their personal data, and it sets ground rules for the businesses doing the collecting. Utah's Division of Consumer Protection handles consumer complaints under it. Three dates matter:

  • December 31, 2023: The original law takes effect.
  • May 6, 2026: HB 357 brings motor vehicle manufacturers under the law no matter how large they are.
  • July 1, 2026: The right to correct inaccurate data, added by HB 418, takes effect.

What counts as personal data

Personal data is information linked or reasonably linkable to an identified or identifiable individual. If your team processes personal data, keep in mind that "process" covers nearly everything you can do with it: collect, store, analyze, share, or delete.

Does the Utah Consumer Privacy Act apply to your business?

The law doesn't cover everyone, so start with three tests. A business has to meet all three. Annual revenue is the fastest to check, while the data volume test has two ways to qualify.

TestWhat the Utah Consumer Privacy Act requires
Utah connectionYour company conducts business in Utah or makes products or services aimed at Utah residents
Annual revenue$25 million or more
Data volumePersonal data of 100,000 or more Utah consumers in a calendar year, or personal data of 25,000 or more consumers while getting over 50% of gross revenue from selling personal data

You don't have to be based in Utah to qualify. A brand with Utah retail locations or a steady stream of Utah online orders can meet the first test from anywhere. The law also defines a Utah consumer as a resident acting in an individual or household context, so employees and business-to-business contacts don't count.

Who's exempt

Even if you clear the thresholds, some organizations and types of data are exempt. This table covers the ones marketers are most likely to run into.

Exempt groupWhat it covers
Public and nonprofit entitiesGovernment entities, tribes, higher education institutions, and nonprofits
Health careCovered entities and business associates under the Health Insurance Portability and Accountability Act, protected health information, and patient identifying information, including records held by a qualified service organization
Credit reportingActivity under the Fair Credit Reporting Act involving personal data bearing on a consumer's creditworthiness, character, or reputation
Financial servicesFinancial institutions governed by the Gramm-Leach-Bliley Act
Other federal lawsData handled under the Driver's Privacy Protection Act, personal data regulated by the Family Educational Rights and Privacy Act, and Farm Credit Act data
Workforce dataApplicant, employee, and contractor data, including data used to administer benefits and emergency contact information used for emergency contact purposes

If you rely on an exemption, you carry the burden of showing it applies. Check the data, not just the business type. The Health Insurance Portability and Accountability Act, for example, covers only part of what health and wellness brands collect, so business associates and other vendors should check which of their data counts.

What Utah consumers can ask you to do

The UCPA gives Utah consumers a short list of rights. If your company processes personal data about a Utah consumer, every one of these consumer requests creates work for someone on your team.

RightWhat it meansWatch for
AccessConfirm whether you process a consumer's personal data and see itData spread across ad platforms, email tools, and your CRM
DeleteDelete personal data provided to you by the consumerDeletions reaching every system
PortabilityGet a copy of personal data the consumer previously provided, portable to the extent technically feasibleA usable export process
CorrectFix inaccurate personal data (since July 1, 2026)A new request type, since Utah launched without it
Opt outStop targeted advertising or the sale of a consumer's personal dataAudience lists that stay in sync

Privacy software often calls the consumer the data subject, which is why you'll see data subject rights and data subject requests in your tools. Whatever the label, the clock is the same for all consumer requests. You have 45 days to act and tell the consumer what you did, with one 45-day extension if you explain why before the first period ends. You can't charge a fee unless it's the person's second or later request in 12 months.

Your other duties

Responding to consumer requests is only part of the job. The law calls a business that decides how and why data is used a controller, and a vendor that handles personal data for it a processor. Controllers have these duties:

  • A clear privacy notice. Provide consumers with a reasonably accessible notice covering the categories of personal data processed and why. When a controller shares personal data with third parties, the notice also has to name the categories of data and the types of third parties.
  • A visible opt-out. If you sell personal data or run targeted advertising, provide consumers with a clear way to opt out of the sale of a consumer's personal data or targeted ads.
  • Reasonable security. Maintain reasonable administrative, technical, and physical data security practices that reduce reasonably foreseeable risks of harm to consumers.
  • Processor contracts. Any vendor that processes personal data for you needs a written contract covering personal data processed on your behalf, confidentiality, and subcontractors.
  • No punishment for using a right. You can't deny service or change prices because someone used a right, and under Utah law a contract clause that waives those rights is void.

Sensitive data gets extra rules

Sensitive data is personal data that reveals certain traits, and it's the one category where you must give clear notice and a chance to opt out before you process a Utah consumer's information. Here's what counts:

  • Racial or ethnic origin
  • Religious beliefs
  • Sexual orientation
  • Citizenship or immigration status
  • Information about an individual's medical history, mental or physical health condition, or medical treatment or diagnosis by a health care professional
  • Genetic personal data or biometric data, when processed to identify a specific individual
  • Specific geolocation data, meaning location accurate to within 1,750 feet

This list reaches further into everyday campaigns than most teams expect. An audience segment built on inferred sexual orientation or immigration status, a lookalike list seeded from people researching medical treatment options, a store-visit campaign using specific geolocation data, an app with face login that collects biometric data, or a DNA kit brand handling genetic personal data could all trigger the duty. Processing such data without notice and an opt-out is a violation.

Children's data works differently. For a known child under 13, the UCPA points to the federal Children's Online Privacy Protection Act (COPPA). A controller meets any duty to obtain parental consent by following COPPA's verifiable parental consent mechanisms, so brands processing children's data should build that step in before launch.

What the Utah Consumer Privacy Act means for your tracking and measurement

The rights and duties above land hardest on how you find audiences and prove results. Four spots deserve your attention:

Targeted advertising opt-outs shrink your audiences

Utah has its own definition of targeted advertising, and knowing where the lines fall tells you which campaigns feel the impact. This table shows both sides.

Counts as targeted advertisingDoesn't count
Ads selected using a consumer's personal data from activity over time and across nonaffiliated websites or apps, to predict their preferences or interestsAds based on activity within your own or an affiliated website or app
Ads based on the context of a consumer's current search query or visit
Ads shown in response to a consumer's request for information, a product, a service, or feedback
Personal data processed solely to measure or report ad performance, reach, or frequency

When Utah consumers opt out, they drop out of cross-site targeting. Whether a particular retargeting setup counts depends on where the data came from, which is a question for your legal team. Either way, expect smaller audiences and platform-reported conversions that cover less of what's really happening, a gap that widens as opt-outs stack up across states.

The measurement carve-out helps, with limits

Tracking results with personal data processed solely for measurement isn't targeted advertising under Utah's rules, which is good news. It only removes that one label, though. Sales, sensitive data, privacy notices, security, and processor contracts all still apply, and you can still process personal data to deliver a product or service requested by a consumer.

\

The sale rules are where Utah is narrower than many states. A sale is the exchange of personal data for monetary consideration by a controller to a third party, and several things don't count:

  • A controller's disclosure of personal data to a processor or an affiliate
  • A disclosure that fits a consumer's reasonable expectations, given the context in which the consumer provided the data
  • A transfer a Utah consumer directs, such as asking you to share data with a third party
  • A transfer in a merger or acquisition where a third party assumes control of all or part of the controller's assets
  • Information a consumer intentionally makes available to the general public through mass media

California and Colorado define a sale more broadly, to include other valuable consideration. A data-sharing deal paid in something besides cash might fall outside Utah's definition and inside theirs, so design to the stricter standard.

Loyalty programs get some room too. You can offer different prices or perks tied to a consumer's voluntary participation in a bona fide loyalty or rewards program, or to someone who opted out of targeted advertising, so offers that provide consumers with a discount don't automatically break the no-punishment rule.

Aggregated data sits outside the definition

Aggregated data is information about a group or category of consumers from which individual consumer identities have been removed and that can't be linked to any consumer. The law's definition of personal data excludes it, so the consumer rights above don't apply to it.

Deidentified data gets the same treatment, with strings attached. It can't reasonably be linked to an identified or identifiable individual, and the business holding the deidentified data must take reasonable measures to prevent anyone from tying it to a person, publicly commit to keeping it that way, and require recipients by contract to do the same. Pseudonymous data has its own rules, separate from deidentified data, including keeping identifying details separate and protected by appropriate technical and organizational measures. Publicly available information, like what widely distributed media has made public or what a consumer disclosed without limiting the audience, is also outside the definition.

This is where measurement choices start to matter. Reporting built from totals, like weekly spend and revenue by channel, doesn't need to follow any individual person, so opt-outs don't chip away at it. That's why approaches that rely on aggregated data, like marketing mix modeling (MMM), are less exposed as opt-outs grow.

The state patchwork matters more than Utah alone

Utah is one of around 20 states with a broad privacy law, and the details vary. Connecticut's amendments took effect July 1, 2026, and cut its threshold from 100,000 consumers to 35,000. Oklahoma's law starts January 1, 2027, and Alabama's follows in May. This table shows where Utah is lighter than some peers.

FeatureUtahStricter states, for example
Definition of a saleMonetary consideration onlyCalifornia and Colorado also include other valuable consideration
Universal opt-out signalsNot required by the statuteRequired in California and Colorado
Data protection assessmentsNot requiredRequired in Colorado and Connecticut

Most national brands end up running one privacy setup built for the strictest states they touch since splitting by state costs more than it saves. So a light law in one state doesn't mean a light impact on your data. The California Consumer Privacy Act and its neighbors will shape how many opt-outs you see, and each one leaves a hole in user-level tracking.

Enforcement and penalties under the Utah Consumer Privacy Act

Utah's enforcement setup is lighter than most, but it still has teeth. Here's how it works:

  • Complaints: The Division of Consumer Protection investigates consumer complaints. If the director has reasonable cause to believe substantial evidence exists of a violation, the matter goes to the attorney general.
  • Who enforces: The attorney general has exclusive authority to enforce the law.
  • Cure period: The attorney general must give at least 30 days' written notice, and no action can start if you cure the violation in that window and confirm in writing it won't recur.
  • Penalties: If you don't cure it, the attorney general can seek actual damages to the consumer and up to $7,500 per violation. That money goes into the Consumer Privacy Account, which pays for enforcement and consumer and business education.
  • No private lawsuits: A violation doesn't create a private right of action under this law or any other.
  • Shared blame: When several controllers or processors are involved in one violation, liability is split by comparative fault, which matters if you work with agencies and vendors.

The attorney general and the Division also report on the law's liability and enforcement provisions and on the data protected and not protected by it, so expect adjustments. And a low chance of being sued doesn't protect your data quality, since opted-out audiences vanish from your reporting whether or not anyone enforces anything.

How to prepare: A checklist for marketing teams

These steps go roughly from quickest to most involved, so you can knock out the early ones between meetings.

  • Map your tags. List every pixel, SDK, and data partner that touches Utah traffic, and log the data processed through each.
  • Test your opt-out. Make it easy for a Utah consumer to find, and confirm it reaches your ad platforms and email tools.
  • Add correction requests. Build the new request type into your data subject request workflow with the 45-day clock.
  • Review vendor contracts. Every processor needs a written contract that covers instructions, confidentiality, and subcontractors.
  • Audit your audiences. Rework or drop segments built from personal data collected in ways that reveal sensitive data.
  • Check expectations. Make sure how you share personal data matches a consumer's reasonable expectations, given where they provided it.
  • Confirm parental consent. Kid-focused products should use verifiable parental consent mechanisms before collecting anything.
  • Watch the gap. Compare platform-reported results with an independent view as opted-out traffic grows.
  • Ask counsel. This guide is general information, not legal advice, so have your legal team confirm how the UCPA applies to your setup.

Where Prescient comes in

Prescient is a marketing mix model platform for omnichannel brands, and it doesn't use a pixel. It models the spend and revenue data you sync, including your history, so each new state opt-out doesn't shrink what it can see the way it shrinks user-level tracking. That keeps reporting steady while the tracking around it changes.

You'll also see Modeled ROAS right next to platform-reported ROAS, plus the marketing halo effects your campaigns create in other channels, including retail. That gives you a way to check the numbers the platforms hand you, which gets more valuable as their data gets thinner. Ready to see what your marketing is really doing no matter how many privacy laws pass? Book a demo with Prescient.

FAQs

What is the purpose of the Utah Consumer Privacy Act?

The Utah Consumer Privacy Act exists to give Utah consumers control over their personal data and to set clear rules for the businesses that collect it. It grants rights to access, delete, correct, and port data, and to opt out of targeted advertising and sales, while requiring notices, security practices, and vendor contracts from businesses. It's also lighter than the California Consumer Privacy Act, with a narrower definition of a sale and a built-in cure period.

What counts as a violation of the Utah Consumer Privacy Act?

A violation means failing to follow one of the law's duties. Common examples include ignoring an opt-out, missing the 45-day response window without a valid extension, processing sensitive data without notice and a chance to opt out, selling personal data or running targeted advertising without explaining how to opt out, sharing data with a vendor that has no processor contract, and charging someone a different price for using a right. The attorney general has to give 30 days' notice first, and curing the problem within that window stops an action.

Does the Utah Consumer Privacy Act apply if my business isn't based in Utah?

It can. The law reaches any business that processes personal data and conducts business in Utah or produces products or services targeted to Utah residents, as long as it also meets the annual revenue and data volume tests. A brand that ships to Utah customers, runs Utah-targeted campaigns, or operates Utah stores can qualify with headquarters anywhere. Only people acting in an individual or household context count, so purely business-to-business contacts fall outside it.

Do I need a cookie banner for Utah visitors?

The UCPA doesn't require an opt-in cookie banner. It uses an opt-out approach: you have to explain how consumers can opt out of sales and targeted advertising, and you need to give notice and a chance to opt out before processing sensitive data. Children are the exception, since COPPA's parental consent rules apply. Many brands still run one banner for every state because other laws are stricter, but that's a business choice.

Can I still run retargeting and targeted ads to Utah consumers?

In most cases, yes. Utah lets you run targeted advertising as long as you disclose it, offer an easy opt-out, and honor opt-outs. What changes is who's left in your audiences, since opted-out consumers have to stay out of cross-site targeting and sensitive data segments need notice and an opt-out first. How your specific retargeting setup fits Utah's definition depends on where the data came from, so ask your legal team to weigh in.

What other consumer protection laws does Utah have?

The Division of Consumer Protection administers a long list of laws beyond the UCPA, including the Utah Consumer Sales Practices Act, the Telephone and Facsimile Solicitation Act, the Prize Notices Regulation Act, and the Ticket Website Sales Act. Several touch marketing directly, covering sales practices, phone and fax outreach, and prize promotions. HB 418 also created the Utah Digital Choice Act, which sets portability and interoperability rules for social media companies.

The Halo

Exclusive insights, every week.

Subscribe to The Halo for sharper marketing thinking.

Keep reading