Law / United States / Utah

Utah

United States law applies in Utah Utah is a state of the United States, whose 32 researched instruments are listed on the United States page, not here. The law of Utah, described on this page below, applies here too.

21 of 22 named instruments researched to a stage, across five of the six areas of law we track: 13 in force, 6 enacted but not yet in force and 2 repealed, withdrawn or blocked. As of 12 September 2026.

When they take effect20 of 21 carry a date, 1 does not.
2019: 1 instrument (1 in force) ’19 2020: 0 instruments 2021: 1 instrument (1 in force) 2022: 0 instruments 2023: 6 instruments (6 in force) 2024: 2 instruments (1 in force, 1 repealed, withdrawn or blocked) 2025: 2 instruments (2 in force) ’25 2026: 2 instruments (2 in force) 2027: 5 instruments (5 enacted but not yet in force) 2028: 1 instrument (1 enacted but not yet in force) ’28 today

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

  1. AI law 6
  2. Privacy law 6
  3. Scraping law 3
  4. Cybersecurity law 2
  5. Age gating law 4
  6. News aggregation law none researched

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

AI law6 instruments, 3 in force, 3 enacted but not yet in force

Research summary (286 words)

Utah's consumer-facing generative AI disclosure duty, first enacted as Utah Code 13-2-12 by SB 149 (2024), was repealed by SB 226 (2025) and re-enacted as a narrower two-tier duty; the 2026 session claimed Chapters 75 and 76 for the Franchise Protection Act and the App Store Accountability Act, so the duty now sits at Chapter 77, Utah Code 13-77-103 to 13-77-104, unchanged in text and in its 7 May 2025 effective date.

SB 332 (2025) separately extended the sunset of the Artificial Intelligence Policy Act itself, Chapter 72 (now holding only the Office of AI Policy, the regulatory sandbox, and definitions), to 1 July 2027; HB 320 (2026) further amended that office's learning-laboratory and regulatory-mitigation-agreement procedures without binding any private party. A parallel, always-proactive disclosure duty covers mental health chatbots under Chapter 72a (HB 452, 2025).

The 2026 session added three further private-binding measures: HB 276 created Chapter 72b, the Digital Voyeurism Prevention Act (non-consensual AI-generated intimate images), and Chapter 72c, the Digital Content Provenance Standards Act (provenance-data and latent-disclosure duties for large platforms, large AI generators, and capture devices), both effective 1 January 2027; SB 319 added an AI-use disclosure duty for health-insurance preauthorization review at Utah Code 31A-22-650, effective 1 January 2027; and SB 256 amended the libel and personal-identity statutes, Utah Code 45-2 and 45-3, so generative AI is not a defense to defamation and the personal-identity consent right reaches an AI-generated replica, effective 6 May 2026.

HB 438 (2026), the Companion Chatbot Safety Act as introduced, passed the House and was reported to have passed the Senate, but corresponds to no chapter in the compiled code and no enrolled act is on file with the Legislature, so no instrument records it here.

AI prohibited practices

Digital Voyeurism Prevention Act (HB 276, 2026 General Session), Utah Code Title 13 Chapter 72b

Utah Code 13-72b-101 et seq.official Utah Code, live codified text, le.utah.gov

In force in 100 days, effective 1 January 2027. Binds private bodies.

What this law does

HB 276 (2026 General Session) creates new Chapter 72b, the Digital Voyeurism Prevention Act, effective 1 January 2027. A generation service, a person operating an interactive computer service that lets users generate intimate images using artificial intelligence technology, may not distribute a counterfeit intimate image of an identifiable individual without first obtaining that individual's affirmative, identity-verified consent, and must keep a record of the consent for at least seven years.

An injured individual may bring a civil action for an injunction, actual and punitive damages, and attorney fees, without needing to plead or prove actual damages. A generation service that maintains and follows a qualifying consent system and written policy, and responds promptly once it learns of a violation, has a safe harbor from that civil liability.

A covered platform must give users a way to report a non-consensual counterfeit intimate image and remove a reported image within 48 hours of notice, and a platform that follows those notice-and-takedown procedures in good faith is not liable for anything posted before it received notice.

What it requires

Identity Protection Modifications, AI Defamation and Identity Replication (SB 256, 2026 General Session)

Utah Code 45-2-3.5, 45-2-14, 45-3-2 to 45-3-7, as amendedofficial Utah Code (Section 45-2-3.5) and enrolled bill text, Utah State Legislature (official)

In force 5 months, effective 6 May 2026. Binds public and private bodies.

What this law does

SB 256 (2026 General Session), effective 6 May 2026, enacts Utah Code 45-2-3.5 to provide that it is not a defense to a libel or slander claim that the communication was created through generative artificial intelligence, computer animation, digital manipulation, or another technological means, or that it uses simulated content rather than an actual recording.

A new Section 45-2-14 requires written notice to the publisher before filing such an action and limits recovery to actual damages if the publisher removes the content within 10 days of notice.

The bill also amends Title 45 Chapter 3, the Abuse of Personal Identity Act, so that every individual's exclusive right to consent to use of their personal identity includes a replication right reaching an AI-generated, computer-animated, or digitally manipulated simulation of their likeness or voice; a person whose identity is abused, including through unauthorized distribution of or trafficking in identity-replication tools, may sue for injunctive relief, damages, exemplary damages, and attorney fees. The chapter does not impose liability on an interactive computer service for content provided by another person.

What it requires

AI sector rules

Health Insurance Preauthorization AI Disclosure (SB 319, 2026 General Session)

Utah Code 31A-22-650, as amendedenrolled bill text, Utah State Legislature (official)

In force in 100 days, effective 1 January 2027. Binds private bodies.

What this law does

SB 319 (2026 General Session) amends Utah Code 31A-22-650, effective 1 January 2027, to require a health insurer to disclose to the Insurance Department, to each network health care provider, and to each enrollee whether the insurer uses artificial intelligence in reviewing a preauthorization request, and to post that fact and its preauthorization statistics on its website.

An adverse preauthorization determination on clinical or medical necessity must be made using independent medical judgment and may not rely solely on a recommendation from any other source. The same bill sets a minimum authorization validity period of at least 12 months for a drug, device, or covered service treating a chronic or long-term care condition (shorter only for an experimental drug or on specified grounds). It separately sets a minimum authorization validity period of at least six months for an outpatient covered service.

What it requires

AI transparency

Digital Content Provenance Standards Act (HB 276, 2026 General Session), Utah Code Title 13 Chapter 72c

Utah Code 13-72c-101 et seq.official Utah Code, live codified text, le.utah.gov

In force in 100 days, effective 1 January 2027. Binds private bodies.

What this law does

HB 276 (2026 General Session), enacted as Chapter 352, Laws of Utah 2026, creates new Chapter 72c, the Digital Content Provenance Standards Act, effective 1 January 2027.

A large online platform (a public-facing social media, mass-messaging, or standalone search-engine service that exceeded 2,000,000 unique monthly users in the preceding 12 months) must detect compliant system provenance data in distributed content, give users a way to see it, and not knowingly strip it where technically feasible.

A covered provider (a person whose generative AI system has over 1,000,000 monthly visitors or users and is publicly accessible in the state) must include a latent disclosure in image, video, or audio content its system creates or substantially modifies. A capture device manufacturer must separately include a latent disclosure in captured content, for a device it produces for sale in the state on or after 1 January 2028.

The Division of Consumer Protection enforces the chapter, with an administrative fine of up to $2,500 per violation and equivalent court remedies.

What it requires

HB 452 (2025), mental health chatbot disclosure

Utah Code 13-72a-203official Utah Code, live codified text, le.utah.gov, confirmed

In force since 7 May 2025. Binds private bodies.

What this law does

A supplier of a mental health chatbot, an AI system that simulates the kind of confidential conversation a licensed mental health therapist would have and that the supplier represents or a reasonable person would believe can provide therapy, must cause the chatbot to clearly and conspicuously disclose it is artificial intelligence and not human.

The disclosure must occur before the user can access the chatbot's features, at the start of any interaction after seven days of non-use, and any time the user asks whether AI is being used. This duty is proactive and recurring, materially stronger than the general Chapter 77 duty, and unamended since enactment even though adjoining definitions and enforcement sections were touched in the 2026 session.

What it requires

SB 226 (2025), required disclosures for generative AI in consumer transactions

Utah Code 13-77-103 to 13-77-104enrolled bill text, Utah State Legislature (official), now codified at Utah Code 13-77-103 to 13-77-104

In force since 7 May 2025. Binds private bodies.

What this law does

A supplier using generative AI to interact with an individual in a consumer transaction must disclose that the individual is interacting with generative AI, but only if the individual makes a clear and unambiguous request.

An individual in a state-regulated occupation must proactively and prominently disclose generative AI use, verbally or in writing as applicable, but only where the interaction meets the statute's high-risk definition (collection of sensitive health, financial, or biometric information, or advice relied on for significant decisions).

This duty was enacted by SB 226 (2025), which repealed a broader duty SB 149 (2024) had placed at the former Utah Code 13-2-12 inside the original Artificial Intelligence Policy Act. The 2026 session claimed Chapters 75 and 76 for the Franchise Protection Act and the App Store Accountability Act, so the compiled code now carries this same duty, unchanged in text and in its 7 May 2025 effective date, at Chapter 77, Utah Code 13-77-103 to 13-77-104.

SB 332 (2025) separately extended the sunset of the Artificial Intelligence Policy Act itself, Chapter 72, to 1 July 2027 without touching this disclosure duty. A safe harbor at 13-77-104 excuses a supplier whose generative AI clearly and conspicuously discloses its non-human nature throughout the interaction.

What it requires

Privacy law6 instruments, 4 in force, 2 enacted but not yet in force

Research summary (217 words)

Utah regulates private-sector personal data primarily through the Utah Consumer Privacy Act (UCPA), Utah Code 13-61-101 et seq., which applies only to a controller or processor with 25 million dollars or more in annual revenue that also meets a 100,000-consumer (or 25,000-consumer-plus-half-of-revenue-from-sale) volume threshold, and which relies on disclosed opt-out rather than opt-in consent for sensitive data, sale, and targeted advertising.

UCPA treats biometric and genetic data as sensitive data requiring notice and an opt-out opportunity when processed to identify a specific individual, but its biometric-data definition categorically excludes any identifier generated from a photograph or from a video or audio recording, so most real-world voiceprint or faceprint capture falls outside its coverage.

A separate Genetic Information Privacy Act binds direct-to-consumer genetic testing companies with its own consent, access, and deletion regime, and a not-yet-effective sector-specific law (Utah Code 26B-2-244, effective 1 January 2028) will bar storing genetic-sequencing data in a foreign-adversary country.

Breach notification runs on the older, separate Protection of Personal Information Act, which unlike UCPA reaches governmental entities as well as private business; UCPA and that Act both bar any private right of action, leaving the Attorney General as exclusive enforcer, and the legislature is actively extending UCPA with a Motor Vehicle Data Privacy part that does not take effect until 1 January 2027.

Breach notification

Protection of Personal Information Act

Utah Code 13-44-101 et seq.official Utah Code text, Utah State Legislature

In force since 1 May 2024. Binds public and private bodies.

What this law does

Requires a person, a term Utah's general Title 68 definitions make broad enough to include a governmental subdivision or agency as well as a private business, who conducts business in Utah and maintains a resident's personal information (a name combined with an unencrypted Social Security number, driver license or state ID number, or financial account or card number with its access code) to implement reasonable procedures against unlawful use or disclosure and to destroy records no longer needed.

On a breach, the person must investigate in good faith and notify each affected Utah resident without unreasonable delay; a breach affecting 500 or more residents also triggers notice to the Attorney General and the Utah Cyber Center, added by a 2024 amendment, and one affecting 1,000 or more also triggers notice to nationwide consumer reporting agencies. Only a financial institution or its affiliate is exempt; unlike UCPA, no governmental-entity exemption appears anywhere in this chapter.

What it requires

Comprehensive regime

Utah Consumer Privacy Act

Utah Code 13-61-101 et seq.official Utah Code text, Utah State Legislature

In force since 31 December 2023. Binds private bodies.

What this law does

Utah's omnibus consumer-data-privacy statute, enacted as S.B. 227 (Chapter 462, 2022 General Session). Applies only to a controller or processor doing business in or targeting Utah consumers with 25 million dollars or more in annual revenue and either 100,000 or more consumers processed a year, or 25,000 or more consumers processed while deriving over half of revenue from data sales.

Exempts government entities and their contractors, tribes, higher-education institutions, nonprofits, Health Insurance Portability and Accountability Act (HIPAA)-covered entities, and several other sectoral categories. Gives consumers access, deletion, correction, portability, and opt-out rights exercisable against the controller within 45 days, extendable once by 45 more days. The Attorney General has exclusive enforcement authority with a mandatory 30-day cure period, and the Act bars any private right of action.

What it requires

Cross border transfer

Genetic sequencing, storage of genetic information (HB 182)

Utah Code 26B-2-244 (enacted by HB 182, 2026 General Session)official enrolled bill text, Utah State Legislature

In force in 465 days, effective 1 January 2028. Binds public and private bodies.

What this law does

Not yet in effect. Once effective, bars a medical facility or genomic research facility from using a genetic sequencer or sequencing software that is a final product of, or distributed by, a foreign adversary, its state-owned enterprise, or a person domiciled there.

Bars storing genetic-sequencing data within the territory of a foreign adversary, and bars remote access to stored sequencing data from within a foreign adversary absent written department approval, with an exemption for open, public-domain data and for certain clinical-trial data.

Requires a sworn compliance statement to the Attorney General and the state health department every 10 years, though that reporting duty does not apply to an entity already covered by the Genetic Information Privacy Act. The Attorney General has sole enforcement authority; fines of 10,000 dollars per violation become enforceable 1 May 2028.

What it requires

Data subject rights

Motor Vehicle Data Privacy

Utah Code 13-61-501 to 13-61-504official Utah Code text, Utah State Legislature, codified but not-yet-effective section

In force in 100 days, effective 1 January 2027. Binds private bodies.

What this law does

Enacted as a new Part 5 of UCPA by the 2026 General Session (Chapter 193), requires a motor vehicle manufacturer selling or leasing vehicles in Utah to provide, for model year 2030 and later vehicles, in-vehicle privacy controls letting a consumer view the categories of personal data the vehicle's data collection system collects and shares, opt out of sale or targeted-advertising processing, and delete readily accessible data, defined conjunctively as data the consumer directly input through the in-vehicle interface and that is stored locally on the vehicle.

Exempts data processed solely for vehicle safety, operation, or legal compliance, and data collected only for internal product improvement. Not yet in force.

What it requires

Sensitive categories

Genetic Information Privacy Act

Utah Code 13-60-101 et seq.official Utah Code text, Utah State Legislature

In force since 3 May 2023. Binds private bodies.

What this law does

Binds a direct-to-consumer genetic testing company, an entity that offers genetic testing products or services to consumers or that collects, uses, or analyzes genetic data a consumer provides. Requires a public privacy notice and the consumer's initial express consent to collect, use, or disclose genetic data, plus separate express consent to transfer or disclose the data beyond the company's vendors, to use it beyond the primary testing purpose, or to retain a biological sample after testing.

Requires valid legal process for law-enforcement disclosure absent express written consent, a comprehensive security program, and a process for a consumer to access their genetic data, delete their account and data, and have their biological sample destroyed. Bars disclosure to health, life, or long-term-care insurers or to the consumer's employer without written consent. Originally enacted in 2021 (Chapter 361), renumbered and amended into its current Part 1 structure in 2023 (Chapter 327).

What it requires

Utah Consumer Privacy Act, sensitive and biometric data provisions

Utah Code 13-61-101(6), 13-61-101(32)(a)(ii), 13-61-302(3)official Utah Code text, Utah State Legislature

In force since 31 December 2023. Binds private bodies.

What this law does

Defines biometric data as data generated by automatic measurement of an individual's unique biological characteristics, naming fingerprint, voiceprint, retina, iris, or any other unique biological pattern used to identify a specific individual, but excludes any physical or digital photograph, video or audio recording, or data generated from one.

Biometric and genetic data become sensitive data, alongside racial or ethnic origin, religious belief, sexual orientation, citizenship or immigration status, certain medical information, and specific geolocation, only when processed for the purpose of identifying a specific individual. A controller may not process sensitive data without first giving clear notice and an opportunity to opt out, an opt-out rather than opt-in model.

What it requires

Scraping law3 instruments, 3 in force

Research summary (214 words)

Utah diverges from federal scraping law chiefly in the personal_data family, structurally closer to California's three-prong publicly-available test than Colorado's narrower two-prong version, and in a genuine narrowing of unfair-competition exposure relative to both.

Utah's computer-crimes statute expressly recognizes implied consent within its definition of authorization, textually supporting a reading that ordinary access to an unrestricted public page is impliedly authorized absent a revocation event, though no Utah court has so held.

Its consumer privacy act excludes a bare photograph, video, or audio recording from biometric data unless used for identification, the same structural exclusion Colorado's Privacy Act uses and a different model from California's, which counts raw facial or voice recordings as biometric information in their own right.

Utah's principal deceptive-trade-practices statute is narrower than California's UCL or Colorado's Consumer Protection Act: it reaches only a deceptive act by a supplier in connection with a consumer transaction, so a scraper is unlikely to be a supplier transacting with the scraped site's operator as a consumer, narrowing this route relative to both other states even though it largely restates the federal FTC Act's own transaction-oriented baseline.

No Utah-specific scraping case law was found for any dimension. Copyright, database rights, and ToS enforceability add nothing beyond the federal position already covered in the national document.

Computer misuse

Utah Computer Crimes Act (unauthorized access, with an express implied-consent definition)

Utah Code Ann. §§ 76-6-702, 76-6-703official text, Utah State Legislature (le.utah.gov)

In force since 3 May 2023. Binds public and private bodies.

What this law does

Section 76-6-703(2)(a) reaches a person who, without authorization or in excess of authorization, accesses or attempts to access computer technology where that access results in the alteration, damage, destruction, copying, transmission, discovery, or disclosure of computer technology, and computer technology expressly includes computer data, so unauthorized copying of scraped data falls within the statute's plain text once without or exceeding authorization is shown.

Section 76-6-702(2) defines authorization as the express or implied consent or permission of the owner to access a computer in a manner not exceeding that consent, and this express recognition of implied consent textually supports treating ordinary access to a public, unrestricted page as impliedly authorized absent a revocation event, though no Utah court has confirmed this reading.

Both provisions were confirmed against Utah's own official code site; Section 76-6-703 carries an effective date of May 3, 2023 on its own page.

What it requires

Personal data

Utah Consumer Privacy Act, publicly-available-information exemption and biometric data

Utah Code Ann. § 13-61-101(6), (29), (32)official text, Utah State Legislature (le.utah.gov)

In force since 31 December 2023. Binds private bodies.

What this law does

Section 13-61-101(29) defines publicly available information with three prongs: information a person lawfully obtains from a governmental record, information a consumer or widely distributed media has lawfully made available to the general public, or information obtained from a person the consumer disclosed it to without restricting the audience, a near match to California's CCPA test and broader than Colorado's two-prong version.

Personal data scraped from a source that is neither a government record nor something the consumer themselves put out, such as a data broker or re-hosted directory, is not publicly available under this Act.

Biometric data under Section 13-61-101(6) means data from automatic measurement of an individual's unique biological characteristics used to identify a specific individual, and expressly excludes a physical or digital photograph, a video or audio recording, and data generated from either, the same structural exclusion Colorado uses.

Processing genetic or biometric data for the purpose of identifying a specific individual is sensitive data under Section 13-61-101(32)(a)(ii), triggering opt-in consent. Enforcement is Attorney-General-exclusive with a 30-day cure period and no private right of action; the Act took effect December 31, 2023.

What it requires

Unfair competition

Utah Consumer Sales Practices Act, deceptive act or practice by a supplier

Utah Code Ann. § 13-11-4official text, Utah State Legislature (le.utah.gov)

In force 5 months, effective 6 May 2026. Binds private bodies.

What this law does

Section 13-11-4 reaches only a deceptive act or practice by a supplier in connection with a consumer transaction, narrower in scope than California's UCL or Colorado's Consumer Protection Act, which are not limited to a transaction between the defendant and the plaintiff.

A scraper is unlikely to be a supplier transacting with the scraped site's operator as a consumer, so this statute likely does not reach scraping or misappropriation claims at all, a genuine narrowing relative to California specifically even though it largely restates the federal FTC Act's own transaction-oriented baseline.

This is flagged as a low-confidence, inclusive raise rather than a confirmed reach: no Utah case has tested it against a scraping fact pattern, and the statute's own text points the other way.

What it requires

Cybersecurity law2 instruments, 2 in force

Research summary (358 words)

Utah's private-sector security law is a two-part reasonable-security regime rather than a product-security or sector cyber-resilience one.

Utah Code 13-44-201, part of the Protection of Personal Information Act and effective May 14, 2019, requires any person who conducts business in the state and maintains personal information to implement reasonable procedures against unlawful use or disclosure and to destroy records no longer needed; the Act's own breach-notification duty is this jurisdiction's privacy-topic row rather than repeated here.

The Cybersecurity Affirmative Defense Act, Utah Code 78B-4-701 to 78B-4-704, effective May 5, 2021, layers an incentive rather than a mandate on top of that duty: a person sued over a breach of system security has an affirmative defense to three categories of claim, inadequate controls, inadequate response, and inadequate notification, where it maintained a written cybersecurity program that reasonably conforms to a named federal or industry framework, scaled to its size and the sensitivity of the information it holds, and the Act expressly creates no private cause of action of its own.

Neither statute arms a private plaintiff; the Attorney General is the sole enforcer of the reasonable-procedures duty, and no published enforcement record for it is confirmed in the primary text consulted here.

No enacted Utah statute is confirmed in the primary text consulted here to set security requirements a connected device or software product must meet to be placed on the market, comparable to California's or Oregon's connected-device statutes or the Cyber Resilience Act; that reading rests on the absence of such a statute from this jurisdiction's already-researched source dossier of 26 instruments spanning Titles 13, 15A, 17, 19, 45, 54, 59, 73, 76 and 78B, rather than on a further dedicated search of the point.

The same is true of a private-sector vulnerability or incident-reporting duty and of a sector-specific cyber-resilience regime naming a digital service: Utah's Cyber Center, created by the same 2024 amendment that added Attorney General and Cyber Center notice to the breach-notification duty, is a state government body rather than the source of a private-sector reporting statute, and no NIS2 or NY DFS Part 500-shaped regime is confirmed in the primary text consulted here.

Security baseline statutes

Cybersecurity Affirmative Defense Act

Utah Code 78B-4-701 to 78B-4-704official Utah Code text, Utah State Legislature

In force since 5 May 2021. Binds private bodies.

What this law does

The Cybersecurity Affirmative Defense Act, Utah Code 78B-4-701 to 78B-4-704, enacted by Chapter 40 of the 2021 General Session and effective May 5, 2021, gives a person sued in a Utah court on a claim arising from a breach of system security three affirmative defenses where a qualifying written cybersecurity program was in place at the time of the breach: a defense to a claim that the person failed to implement reasonable information security controls, a defense to a claim that the person failed to appropriately respond to the breach, and a defense to a claim that the person failed to appropriately notify an affected individual.

A qualifying program must be designed to protect the type of personal information obtained in the breach, be of a scale and scope appropriate to the person's size, complexity and activities and the sensitivity of the information, and either operate as a reasonable security program with a designated coordinator, detection and response procedures, employee training, and periodic risk assessment and adjustment, or reasonably conform to a named industry framework: NIST Special Publication 800-171; NIST Special Publications 800-53 and 800-53A; the FedRAMP Security Assessment Framework; the Center for Internet Security Critical Security Controls; the ISO/IEC 27000 family; the Health Insurance Portability and Accountability Act (HIPAA) Security Rule or Gramm-Leach-Bliley Title V regulations, for personal information those regimes already cover; or the PCI Data Security Standard, for payment card information.

A person loses the defense if it had actual notice of a threat or hazard to the information's security and did not act in a reasonable time to remediate it before the breach resulted; a risk assessment alone is not actual notice.

The Act imposes no duty to adopt a program and, by its own terms, may not be construed to create a private cause of action, including a class action, for a person's failure to comply with it: it is a defendant's shield, never a plaintiff's remedy, and Utah Code 13-44-201, researched separately below, is the reasonable-procedures duty the shield answers.

What it requires

Protection of Personal Information Act, reasonable procedures and records-destruction duty

Utah Code 13-44-201official Utah Code text, Utah State Legislature

In force since 14 May 2019. Binds public and private bodies.

What this law does

Utah Code 13-44-201, part of the Protection of Personal Information Act and effective May 14, 2019, requires any person who conducts business in the state and maintains personal information, reaching a governmental entity conducting business as well as a private business, the same broad reading of 'person' this jurisdiction's privacy-topic row already applies to the Act's breach-notification duty, to implement and maintain reasonable procedures to prevent the unlawful use or disclosure of personal information collected or maintained in the regular course of business, and to destroy, or arrange for the destruction of, records containing personal information that are not to be retained, by a method the section specifies.

The section states no further content for what 'reasonable' requires beyond that general standard, and, like the rest of the chapter, creates no private right of action: only the Attorney General may enforce it. The chapter's own breach-notification duty, requiring notice to an affected Utah resident and, for a large breach, to the Attorney General and the Utah Cyber Center, is this jurisdiction's privacy-topic row rather than repeated here.

What it requires

Age gating law4 instruments, 1 in force, 1 enacted but not yet in force, 2 repealed, withdrawn or blocked

Research summary (130 words)

Utah's adult content age verification law has been in effect since 2023 and was amended in 2026 to add Division of Consumer Protection enforcement, a VPN anti-circumvention rule, and an excise tax, an amendment now under constitutional challenge by Aylo.

Utah's first in the nation 2023 Social Media Regulation Act was repealed and replaced in 2024 by the Utah Minor Protection in Social Media Act plus a companion private right of action act, which remain preliminarily enjoined pending a Tenth Circuit appeal argued in November 2025.

Utah's first in the nation App Store Accountability Act (2025) was amended in March 2026 to remove Attorney General enforcement and delay its substantive requirements to May 6, 2027, which mooted the industry's constitutional challenge. Utah has not enacted a standalone design code law.

Adult content age verification (AV)

SB 287 (2023), Online Pornography Viewing Age Requirements, as amended by SB 73 (2026), Online Age Verification Amendments

Utah Code Ann. sections 78B-3-1001 to 78B-3-1008 (Title 78B, ch. 3, pt. 10), as amended by 2026 Utah Laws (S.B. 73)official enrolled bill text, Utah State Legislature

In force since 3 May 2023. Binds private bodies.

What this law does

Makes a commercial entity that publishes material harmful to minors on a website where more than one third of total material is harmful to minors civilly liable if it fails to verify that Utah visitors are 18 or older using a digitized identification card, an independent third party age verification service, or a commercially reasonable method relying on transactional data.

SB 73 (2026) added Division of Consumer Protection enforcement effective May 6, 2026, a rule treating a user as accessing the site from Utah even through a VPN, and a 2 percent excise tax on covered content revenue effective October 1, 2026 that funds youth mental health programs and enforcement.

Note and primary source

App store age verification (AV)

SB 142 (2025), App Store Accountability Act, as amended by HB 498 (2026), App Store Accountability Act Amendments

Utah Code Ann. Title 13, ch. 76official Utah Code text, Utah State Legislature

In force in 225 days, effective 6 May 2027. Binds private bodies.

What this law does

Requires app store providers to verify a user's age category, link a minor's account to a parent account, and obtain parental consent before a minor can download or purchase an app, including preinstalled apps. The original Act was signed March 26, 2025 with a May 6, 2026 compliance deadline.

A 2026 amendment (HB 498, signed March 18, 2026) removed Attorney General enforcement, limited enforcement to a private right of action with damages up to $1,000 per violation, extended coverage to preinstalled apps, and delayed the compliance deadline one year to May 6, 2027.

Note and primary source

Social media and minors

SB 152 and HB 311 (2023), Utah Social Media Regulation Act

Utah Code Ann. former Title 13, ch. 63 (repealed 2024)official bill page, Utah State Legislature

Repealed: no longer in force. Binds private bodies.

What this law does

First in the nation social media age verification law, signed March 2023. Would have required social media companies to verify the age of all Utah account holders, obtain parental consent for minors, impose a default curfew on minor accounts, and give parents access to minor accounts. Its effective date was postponed from March 1, 2024 to October 1, 2024, and the legislature repealed and replaced it in March 2024 with SB 194 and HB 464 before it was enforced.

Note and primary source

SB 194 (2024), Utah Minor Protection in Social Media Act, and HB 464 (2024), Social Media Amendments

Utah Code Ann. sections 13-71-101 to 13-71-401official Utah Code text, Utah State Legislature

Enjoined: enforcement paused by a court, effective 1 October 2024. Binds private bodies.

What this law does

Would require social media companies to implement an age assurance system for Utah account holders, apply default protections for known minors, and let verified parents supervise a minor's account. HB 464 additionally repealed Utah's original 2023 Social Media Regulation Act and created a private right of action for a minor's mental health harms tied to a platform's algorithmically curated feed.

Note and primary source

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.