Utah UCPA checklist
A 10-step action checklist for UCPA compliance efforts: scope, notices, opt-outs, sensitive data, the new right to correct, and portability audits.
A 10-step action checklist for UCPA compliance efforts: scope, notices, opt-outs, sensitive data, the new right to correct, and portability audits.
Use this checklist to review your business against the Utah Consumer Privacy Act (UCPA), including the H.B. 418 amendments that took effect July 1, 2026. Each step focuses on a specific action you can work through with your team or legal counsel.
For a deeper explanation of the UCPA requirements and what changed under H.B. 418, read Clym’s Utah Consumer Privacy Act business guide first, then return to this checklist to put those requirements into practice.
Work through the 10 items below in order. Each one explains what to check and what action to take, without repeating the full legal background.
H.B. 418 adds an important deadline. The right to correct and updated portability requirements apply from July 1, 2026.
A 30-day cure period still applies under the UCPA, giving businesses an opportunity to address certain issues before enforcement action proceeds.
There is no private right of action under the UCPA. Enforcement sits with the Utah attorney general following referral from the Division of Consumer Protection.
Your business is generally in scope if you have $25 million or more in annual revenue AND meet one of these two data conditions:
You control or process the personal data of 100,000 or more Utah consumers per year
You control or process the personal data of 25,000 or more Utah consumers per year, and derive more than 50 percent of your gross revenue from selling personal data
If your business meets the revenue threshold and either data-volume condition, continue through all 10 steps below.
Confirm your business meets the $25 million annual revenue floor. Revenue alone doesn’t trigger the law without a data-volume condition too
Confirm which data condition applies: the 100,000-consumer threshold, or the 25,000-consumer-plus-50%-revenue threshold
Record the date and basis for your determination
Check whether any sector-specific carve-out applies, such as HIPAA or GLBA coverage
List every category of personal data you collect, including whether it is sensitive or belongs to a known child
Document the purpose for collecting and processing each category
Confirm you get consent before using data for a new purpose that’s materially different from what you disclosed
Cut any collection point that gathers more data than the stated purpose requires
Add the categories of personal data you process and the purposes for processing
Add the categories of personal data and third parties involved in any sharing
Add a clear explanation of consumer rights, including the new right to correct
Keep the notice reasonably accessible and written in plain language
A privacy and cookie policy solution can help keep this information organized as your data practices change.
Build an opt-out method for the sale of personal data and targeted advertising
Confirm the opt-out is reasonably easy to use and doesn’t require unnecessary steps
A consent management experience that presents Utah visitors with the correct options is the most common implementation approach.
Provide notice and an opt-out option before processing sensitive data categories: precise geolocation, financial data, health information, race, ethnicity, religious beliefs, sexual orientation, and biometric identifiers
Obtain parental or guardian consent before collecting personal data from a known child under 13
Confirm your consent flow doesn’t rely on pre-checked boxes or bundled agreement
Set up intake, identity verification, and tracking for access, deletion, opt-out, and correction requests
Confirm you can respond within 45 days, with a documented process for the one-time 45-day extension
Add a workflow to verify a claimed inaccuracy, update the record, and confirm the correction back to the consumer
Check whether corrected data was shared with any processor, and whether that correction needs to flow downstream
A data subject request workflow helps track intake, deadlines, and documentation, including the new correction right, without manual spreadsheets.
Pull a sample data export from a real access request
Confirm it opens without proprietary software or specialist tools
Confirm the format is technically usable and easily transferable to another controller
Fix any export that requires conversion steps or is structurally incomplete before July 1, 2026
Confirm a correction request option is available to Utah visitors in your consent or preference widget
If you use a platform with jurisdiction-aware rights presentation, confirm it has been updated for the July 1, 2026 change rather than assuming it updates automatically
Check for any custom configuration that might override the correction workflow
Confirm your privacy notice, purpose specification, and data minimization practices are current
Confirm reasonable administrative, technical, and physical security measures are in place
Confirm your contracts don’t include unenforceable clauses that purport to waive consumer rights
Confirm you don’t discriminate against consumers who exercise their rights
Confirm your team knows the Utah attorney general is the sole enforcement authority. There is no private right of action
Confirm your team understands complaints route through the Division of Consumer Protection before any AG referral
Confirm your team knows a 30-day cure period applies after formal notice, before penalties of up to $7,500 per violation can be imposed
Assuming the UCPA applies based on data volume alone, without checking the $25 million revenue floor
Missing the H.B. 418 right to correct because it wasn’t in the original 2023 law
Continuing to export data in a proprietary or hard-to-use format that no longer meets the tightened portability standard
Assuming an unlimited cure period. The 30-day window is real, but it is not indefinite
Review your privacy notice and data practices at least once a year and whenever your processing activities change materially
Monitor Utah Division of Consumer Protection guidance for how the correction right and portability standard are being applied
Update your data map whenever you add new vendors, tools, or data collection methods
If you operate across multiple states, Clym’s U.S. state privacy law comparison guide covers thresholds, cure periods, and enforcement side by side
Deploy the right consumer rights options to Utah visitors automatically through ReadyCompliance®, including the correction request workflow
Present the right consent experience by location with geofencing features that detect visitor location automatically
Route, verify, track, and document data subject requests, including corrections, through the Governance Portal
Keep privacy notices accurate and up to date as your data practices evolve
Clym does not guarantee compliance. Your obligations depend on your specific data practices, legal advice, and internal processes. The platform provides tools to support your privacy operations and help you work toward the UCPA’s requirements.
Work through these 10 steps in order, starting with your thresholds. The 30-day cure period means you have real room to fix gaps, but only if you find them before an audit or complaint does.
For the full explanation behind any of these requirements and how the UCPA compares to other state privacy laws, go back to Clym’s Utah Consumer Privacy Act business guide.
It’s an action checklist for working through Utah Consumer Privacy Act requirements, including the H.B. 418 amendments effective July 1, 2026. Each step tells you what to check and do. For background on what the UCPA requires and why, see Clym’s Utah Consumer Privacy Act business guide.
Any business with $25 million or more in annual revenue that also meets one of the UCPA’s two data-volume conditions. Businesses below the revenue floor generally aren’t in scope, regardless of data volume.
Start with Step 6 and Step 7. Most gaps trace back to missing the new right to correct or continuing to export data in a format that no longer meets the tightened portability standard.
No. Unlike California’s CCPA or Colorado’s CPA, the UCPA does not require businesses to recognize universal opt-out signals. Building that support isn’t wasted effort if you operate in other states, but it isn’t a UCPA requirement on its own.
45 days, with one additional 45-day extension available when reasonably necessary.
Yes, two things. Add a correction request workflow to your rights process, and confirm your data exports meet the stricter portability standard. Both changes take effect July 1, 2026.