Skip to content
Menu ▾
Patent pending

Regulayer  /  The 146 laws  /  Privacy law

Utah · Consumer Privacy Act (UCPA)

Controller duties & breach assistance.

Applies to: Controllers under Utah's UCPA (distinct from the AI act). Built · effective 31 Dec 2023

What the signed record shows

Security records, 45-day consumer-request signals, and processor breach-assistance references.

The proof is a signed, tamper-evident record. Anyone can check it, free, without an account, and nothing has to leave the building to make it. Evidence, not a promise.

Citation: Utah Code 13-61-203/301/302

In the same family

What to do about it

Seven days free, then $349 a month.

A signed record of which AI you used and what you checked, sealed to the exact file you deliver, made on your own machine and checkable free by anyone you send it to.

Start the free weekOr verify a real record, free →

Part of the Regulayer proof catalogue: 146 laws and standards, one sealed engine. This page is a product description, not legal advice.

What the statute requires, section by section

Utah Consumer Privacy Act (UCPA), Utah Code Title 13, Chapter 61 (13-61-101 et seq.). DISTINCT from the Utah Artificial Intelligence Policy Act (Title 13, Chapter 77). Provisions addressed:

§ 13-61-302
Responsibilities of controllers; transparency; purpose specification and data minimization; reasonable administrative, technical and physical data security practices; non-discrimination.
§ 13-61-203
Controller's response to requests; act within 45 days (one 45-day extension if reasonably necessary).
§ 13-61-301
Responsibility according to role; processor duties incl. assistance with security and breach notification (Utah Code
§ 13-44-202). Effective 31 December 2023. (UCPA is a light-touch law and does NOT require data protection assessments.)

Taken from the Regulayer entry for this instrument, which is built against the primary text.