EnglishEspañol
Utah flag

Utah

Utah Data Breach Notification Laws: Reporting Rules & Timelines (2026)

Independently fact-checked against primary sources (last audited August 15, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 15, 2026. · 5 primary sources cited on this page. How we verify our legal content

Utah Data Breach Notification Laws: Reporting Rules & Timelines (2026)

Frequently Asked Questions

How quickly must a business notify Utah residents after a data breach?

Utah requires notification in the most expedient time possible without unreasonable delay. There is no fixed-day deadline like the 30, 45, or 60 days many other states impose. The timeline must account for legitimate law enforcement needs, the time to determine the breach scope, and the time to restore system integrity.

Does Utah require Attorney General notification for data breaches?

Yes, as of May 2024. Senate Bill 98 added a requirement to notify the Attorney General and the Utah Cyber Center when the good faith investigation reveals that misuse of personal information relating to 500 or more Utah residents, for identity theft or fraud purposes, has occurred or is reasonably likely to occur. It is not a raw count of people whose data was exposed. The notification must include the breach date, discovery date, total affected individuals, type of personal information, and a description of the breach.

Does Utah's breach notification law apply to banks and credit unions?

No. Utah Code 13-44-103 states that the chapter does not apply to a financial institution or an affiliate of a financial institution, as defined in 15 U.S.C. Section 6809. Institutions within that definition are outside Chapter 44 entirely, including its investigation duty and its Attorney General and Cyber Center reporting thresholds.

What are the penalties for failing to notify about a data breach in Utah?

Civil penalties are capped at $2,500 per consumer and $100,000 in the aggregate for related violations. The aggregate cap can be exceeded in cases involving 10,000 or more consumers in both Utah and other states, or if the parties agree to a higher settlement. Only the Attorney General can enforce the law.

Must businesses investigate before sending breach notification in Utah?

Yes. Utah requires entities to conduct a good faith, reasonable, and prompt investigation upon becoming aware of a breach. Notification is required only if the investigation reveals that personal information has been or is reasonably likely to be misused for identity theft or fraud. This risk-based approach distinguishes Utah from states that require notification for any unauthorized acquisition.

Is it a reportable breach if an employee looks at data they should not have?

Usually not, on its own. Utah Code 13-44-102(1)(b) provides that a breach of system security does not include the acquisition of personal information by an employee or agent of the person possessing unencrypted computerized data, unless the personal information is used for an unlawful purpose or disclosed in an unauthorized manner. The reportability question turns on what the insider did with the information.

Does Utah's breach notification law cover medical or health information?

No. Utah's personal information definition only covers SSNs, financial account numbers with security codes, and driver's license or state ID numbers. Medical information, health insurance data, biometric data, and email credentials are not covered under the breach notification statute.

Affected by a data breach or biometric privacy violation?

If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.

Updates

Corrected the 500-resident Attorney General and Cyber Center trigger to match the statute's investigation-based misuse standard, and added Utah's financial-institution exemption, the employee and agent carve-out from the breach definition, and the safe harbor for entities that follow their primary regulator's breach procedures.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Governing law re-checked for recent changes

Corrected a claim that Utah's breach notification law does not require notifying consumer reporting agencies; Section 13-44-202(1)(d) requires it once a breach affects 1,000 or more Utah residents.

Governing law re-checked for recent changes

Reviewed and approved by an editor

Sources and References

  1. Utah Code 13-44-202 - Disclosure of System Security Breach(le.utah.gov).gov
  2. Utah Code 13-44-301 - Enforcement(le.utah.gov).gov
  3. Senate Bill 98 (2024) - Online Data Security and Privacy Amendments(le.utah.gov).gov
  4. Utah Cyber Center - Report a Breach(cybercenter.utah.gov).gov
  5. Utah Code 13-44-102 Definitions(le.utah.gov).gov
  6. Utah Code 13-44-103 - Applicability (financial institution exemption)(le.utah.gov)
Share: