Compare with different regulatory event:

Description

Implemented Consumer Privacy Act

On 31 December 2023, the Utah Consumer Privacy Act (SB 227) is implemented. The Act gives individuals new rights over their data, including the right of access, deletion and rectification and enables individuals to opt-out from having their data collected for sale or targeted advertising purposes. Furthermore, the Act requires companies to include in their privacy notice the categories of personal data collected, the purpose of data processing and the categories of data shared with third parties. Finally, the Act empowers the Division of Consumer Protection to open investigations into complaints regarding data processing and the Attorney General to issue penalties for non-compliance. However, it does not provide users with a private right of action and allows companies to cure alleged violations within a 30 days before enforcement ensues.

Original source

Scope

Policy Area
Data governance
Policy Instrument
Data protection regulation
Regulated Economic Activity
cross-cutting
Implementation Level
subnational
Government Branch
legislature
Government Body
parliament

Complete timeline of this policy change

Hide details
2022-02-17
under deliberation

On 17 February 2022, the Consumer Privacy Act (SB 227) was introduced in the Utah Senate. The Act w…

2022-03-03
adopted

On 3 March 2022, the Consumer Privacy Act (SB 227) was adopted by the Utah Senate and House and is …

2022-03-24
adopted

On 24 March 2022, the Utah Consumer Privacy Act (SB 227) was signed by the Governor of Utah. It wil…

2023-12-31
in force

On 31 December 2023, the Utah Consumer Privacy Act (SB 227) is implemented. The Act gives individua…

Key regulatory dimensions

Regulated subjects

The businesses, government agencies or individuals affected by this policy or regulatory change.
producer / supplier
1
Type Private organisation
Economic activity cross-cutting
Category All

Policy change by business practice

The detailed activities within the scope of this policy or regulatory change.
personal data (all forms): data collection
Regulatory tool
User right to access personal data
User right to deletion of personal data
User right to portability of personal data
User notification requirement
Complaint mechanism requirement
Corporate right to cure
Prohibition of discrimination on the basis of exercised user rights
Sanctions
Restitution of damages
Fine
Regulated subjects
1
personal data (all forms): data processing
Regulatory tool
User right to access personal data
User right to deletion of personal data
User notification requirement
Complaint mechanism requirement
User right to information about third-parties, with which data has been shared
Corporate right to cure
Prohibition of discrimination on the basis of exercised user rights
Sanctions
Restitution of damages
Fine
Regulated subjects
1
advertisement: contextual targeting: marketing (any form)
Regulatory tool
User consent: Permit user opt-out
Complaint mechanism requirement
User right to information about third-parties, with which data has been shared
Corporate right to cure
Prohibition of discrimination on the basis of exercised user rights
Sanctions
Restitution of damages
Fine
Regulated subjects
1
personal data (all forms): sale

Policy change by business practice

The detailed activities within the scope of this policy or regulatory change.

personal data (all forms): data collection

personal data (all forms): data processing

advertisement: contextual targeting: marketing (any form)

personal data (all forms): sale