On March 24, 2022, Utah followed California, Virginia, and Colorado in adopting a comprehensive consumer data privacy law.
April 2022 AlertOn March 24, 2022, Utah Governor Spencer Cox signed the Consumer Privacy Act ("Act"), making Utah the most recent state to enact a comprehensive data privacy law. The Act takes effect on December 31, 2023.
The Act will apply to entities that: (i) conduct business or target consumers in Utah; (ii) generate $25 million or more in annual revenue; and (iii) either process or control: (a) the personal data of at least 100,000 Utah consumers; or (b) the personal data of at least 25,000 Utah consumers and derive at least half their gross revenue from selling personal data. Under the Act, consumers include individuals who are Utah residents and are acting in an individual or household context. The Act applies to residents acting in an individual or household context, not an employment or commercial context.
The Act borrows many core elements from peer legislation in California, Virginia, and Colorado. For example, the Act creates obligations for "controllers" (those determining the purposes and means of processing the personal data) and "processors" (those processing the personal data on a controller's behalf).
Under the Act, controllers have obligations to, among other things:
The Act does not create a private right of action, and grants exclusive enforcement authority to the Attorney General. If businesses do not cure violations within 30 days of the Attorney General's notice, the Attorney General may collect statutory damages up to $7,500 per violation, and actual damages to the consumer. Funds received by the Attorney General will be deposited into a Consumer Privacy Account for investigation and administrative costs, attorneys' fees, and providing consumer and business education.