Obtainer
Use case

Utah Consumer Privacy Act (UCPA) Compliance: Access, Deletion, and the New Right to Correct

The Utah Consumer Privacy Act gives Utah residents the right to access, delete, and port their personal data, and since July 1, 2026, to correct it. A verified request starts a 45-day clock. Utah is one of the few states that still gives you a permanent 30-day window to cure a violation, but the correction right is brand new and most teams have no workflow for it. Obtainer finds where a person's data lives across your systems, compiles one reviewable manifest, drafts the response, and tracks the deadline.

See how it works
Discovery across your systems Human redaction gate Helps you comply, not legal advice
Request Studio
Requester
Compiled the manifest and drafted the response - illustrative sample request
0
records found
0
systems scanned
Data manifest
Response draft

Assembling the cover letter from the template...

You approve what is disclosed before anything ships

Helps you comply, not legal advice

In short

The Utah Consumer Privacy Act (UCPA) took effect December 31, 2023. It applies to a controller that does business in Utah or targets Utah residents, has annual revenue of $25,000,000 or more, and either controls or processes the personal data of 100,000 or more Utah consumers in a calendar year, or derives over 50 percent of gross revenue from selling personal data while processing the data of 25,000 or more consumers. That revenue floor makes Utah one of the narrowest state privacy laws in the country, so plenty of companies caught by Colorado or Connecticut fall outside Utah entirely. Utah consumers can confirm whether you process their personal data and access it, delete data they provided, obtain a portable copy, and opt out of the sale of their data and targeted advertising. House Bill 418 added a right to correct inaccurate personal data, and that right became enforceable on July 1, 2026, which leaves Iowa as the only comprehensive state law without one. You generally must respond within 45 days, extendable once by another 45 days with notice. Utah keeps a permanent 30-day right to cure: the attorney general and the Division of Consumer Protection must give you written notice and 30 days to fix a violation before seeking penalties of up to $7,500 per violation. There is no private right of action. Obtainer handles the operational side of a UCPA request: it intakes the request, discovers where the person's data lives across your systems, compiles a source-system manifest, drafts a deadline-safe response, and tracks the 45-day clock. Nothing is disclosed or changed automatically; a human reviews, redacts, and approves. Obtainer helps you comply. It is not legal advice, so scope and exemption calls stay with your team. Self-serve from $49/mo.

// THE FIT

Why it fits

Utah businesses and out-of-state SaaS, ecommerce, and B2B firms above the $25 million revenue floor that target Utah residents, and multi-state teams that need one workflow covering Utah access, deletion, portability, and the new correction right on the 45-day clock.

The correction right is new and most workflows are not ready

Utah consumers gained the right to correct inaccurate personal data on July 1, 2026. A correction request is operationally harder than an access request, because you have to find every copy of the wrong value, not just report it once, and then push the fix through the systems that already consumed it. Obtainer surfaces every place the record lives so the correction reaches all of them rather than the one system you thought of first.

A $25 million revenue floor narrows the field

Utah is the only state law that pairs a consumer-count threshold with a hard $25,000,000 revenue floor and a 50 percent data-sale test, so a mid-market SaaS company under that line is out of scope in Utah while still fully covered in Colorado, Connecticut, and Texas. Knowing which of your requests are actually UCPA requests changes what you owe and when.

The 30-day cure is permanent, and documentation is what earns it

Most states have let their cure windows sunset. Utah did not. You still get written notice and 30 days to fix a violation before the attorney general can seek up to $7,500 per violation. That grace only helps if you can show what happened: a timestamped intake record, a manifest of what you found, and a dated approval on what went out. Obtainer keeps that record as a by-product of doing the work.

// FAQ

Questions

Common questions about this

Who has to comply with the Utah Consumer Privacy Act?

A controller doing business in Utah or targeting Utah residents that has annual revenue of $25,000,000 or more and either processes the personal data of 100,000 or more Utah consumers in a calendar year, or derives more than 50 percent of gross revenue from selling personal data while processing the data of 25,000 or more consumers. Both the revenue floor and one of the volume tests must be met, which is why Utah covers fewer companies than most state laws.

Does Utah have a right to correct personal data?

Yes, since July 1, 2026. House Bill 418 added a correction right to the UCPA, and a covered business generally has 45 days to respond to a valid correction request, extendable once when reasonably necessary with notice to the consumer. Utah did not have this right at all before that date, so it is the newest obligation in the statute and the one most request workflows have not been updated for.

What are the penalties for violating the UCPA?

Civil penalties reach $7,500 per violation, and the attorney general has exclusive enforcement authority. Utah keeps a permanent 30-day right to cure, so the Division of Consumer Protection must give written notice of the alleged violation and let you fix it before penalties attach. There is no private right of action, so consumers cannot sue you directly under the UCPA.

How long do I have to respond to a Utah data subject request?

Forty-five days from receipt of a verified request, with one 45-day extension available when reasonably necessary, provided you tell the consumer about the extension inside the original window. That matches the 45-day standard used by eighteen of the twenty state laws, so a single 45-day process works nearly everywhere; Iowa is the outlier at 90 days and Florida caps its extension at 15. Utah does not require an appeal mechanism the way Colorado, Connecticut, and New Jersey do.

Run a data subject access request end to end

Obtainer finds where a person's data lives across your systems, compiles it into one manifest, drafts the deadline-safe response, and tracks the GDPR and CCPA clock. You review, redact, and approve what gets disclosed. Helps you comply; not legal advice.