Utah
Utah Data Breach Notification Laws: Reporting Rules & Timelines (2026)
Independently fact-checked against primary sources (last audited August 15, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 15, 2026. · 5 primary sources cited on this page. How we verify our legal content

Utah's Protection of Personal Information Act requires businesses to notify affected residents of a data breach in the most expedient time possible and without unreasonable delay. Under Utah Code 13-44-202, there is no fixed-day deadline; the timeline accounts for investigation scope and law enforcement needs.
Utah's data breach notification law is codified as the Protection of Personal Information Act, Utah Code 13-44-101 et seq., and has been in effect since 2006. The law received a significant update in 2024 through Senate Bill 98, effective May 1, 2024, which added new requirements for notifying the Attorney General and the Utah Cyber Center.
Utah's approach to breach notification is distinctive in several ways. The law requires entities to investigate first and notify only if identity theft or fraud is reasonably likely. The timeline uses a "without unreasonable delay" standard rather than a fixed-day deadline. And the penalty structure caps damages at modest levels compared to many other states.
This guide covers the full scope of Utah's breach notification requirements, including how they connect to the broader Utah data privacy laws framework, which also includes the Utah Consumer Privacy Act (UCPA).
Who Must Comply
Utah's law applies to any person who owns or licenses computerized data that includes personal information concerning a Utah resident. The term "person" includes businesses, corporations, partnerships, and other entities. Businesses located outside Utah are subject to the law if they hold data belonging to Utah residents.
Financial Institutions Are Exempt
Chapter 44 carries one categorical exemption. Under Utah Code 13-44-103, the chapter does not apply to a financial institution, or to an affiliate of a financial institution, as those terms are defined in 15 U.S.C. Section 6809.
Banks, credit unions, and other entities that fall within that federal definition are outside Chapter 44 entirely. The investigation duty, the resident notification duty, and the Attorney General and Cyber Center reporting thresholds described below do not reach them.
Third-Party Data Holders
When a third party maintains data on behalf of another entity, the third party must notify the data owner or licensee of the breach. The data owner then bears the responsibility for investigating and notifying affected residents.
Own Security Policy Exception
An entity that maintains its own notification procedures as part of an information security policy is deemed in compliance with the notification requirements, as long as those procedures are consistent with the timing requirements of the statute.
A second safe harbor covers regulated entities. Under Subsection 13-44-202(5)(c), a person who is regulated by state or federal law and maintains breach procedures under the applicable law established by its primary state or federal regulator is considered to be in compliance with this part, provided the person notifies each affected Utah resident in accordance with that other applicable law. Healthcare providers, insurers, and other entities already operating under a regulator's breach rules can rely on this provision.
The Investigation Requirement
Utah stands out from many states by requiring entities to conduct a good faith investigation before triggering notification obligations.
Under Section 13-44-202, when an entity becomes aware of a breach of system security, it must conduct a good faith, reasonable, and prompt investigation to determine the likelihood that personal information has been or will be misused for identity theft or fraud.
Notification is required only if the investigation reveals that misuse of personal information for identity theft or fraud has occurred or is reasonably likely. This risk-based approach means not every breach automatically requires notification. If an entity determines through its investigation that misuse is unlikely, it may not be required to notify.
What Constitutes a Breach
Under Section 13-44-102, a "breach of system security" means an unauthorized acquisition of computerized data maintained by a person that compromises the security, confidentiality, or integrity of personal information.
The definition focuses on acquisition, not just access. Unauthorized access without actual acquisition of the data may not trigger the investigation obligation.
The Employee and Agent Carve-Out
Subsection 13-44-102(1)(b) expressly narrows the definition: a breach of system security does not include the acquisition of personal information by an employee or agent of the person possessing unencrypted computerized data, unless the personal information is used for an unlawful purpose or disclosed in an unauthorized manner.
For an insider incident, the statutory question is therefore what the employee did with the data, not whether the employee should have had it. An employee who pulls records outside the scope of their role, without using the information unlawfully or disclosing it without authorization, does not create a reportable breach under Chapter 44.
Encryption Safe Harbor
If personal information was encrypted or protected by another method that renders the data unreadable or unusable, the breach notification requirements do not apply. Utah does not specify a particular encryption standard (unlike some states that require FIPS 140-2 or 128-bit encryption).
Personal Information That Triggers the Law
Under Section 13-44-102, personal information means a person's first name or first initial and last name, combined with any one or more of the following data elements, when either the name or data element is unencrypted or not protected by another method that renders the data unreadable or unusable:
- Social Security number
- Financial account number, or credit or debit card number, combined with any required security code, access code, or password that would permit access to the account
- Driver's license number or state identification card number
What Utah's Law Does Not Cover
Utah's definition is relatively narrow. It does not include:
- Medical or health information
- Health insurance identification numbers
- Biometric data
- Email credentials (usernames with passwords)
- Passport numbers
- Taxpayer identification numbers (other than SSNs)
Personal information does not include information contained in federal, state, or local government records or in widely distributed media that are lawfully made available to the general public.
Notification Timeline

Utah requires notification in the most expedient time possible without unreasonable delay, considering:
- Legitimate investigative needs of law enforcement
- The time needed to determine the scope of the breach
- The time needed to restore the reasonable integrity of the system
There is no fixed-day deadline. This gives entities some flexibility but also means compliance depends on what is "reasonable" under the circumstances.
Law Enforcement Delay
Notification may be delayed if a law enforcement agency determines that notification will impede a criminal investigation. Notification must proceed once law enforcement indicates it will no longer compromise the investigation.
Who Must Be Notified
Affected Individuals
Every Utah resident whose personal information was, or is reasonably believed to have been, misused or reasonably likely to be misused for identity theft or fraud must receive notification.
Attorney General and Utah Cyber Center (500+ Threshold)

Under the 2024 amendments added by SB 98, the trigger is not a raw headcount of affected people. When the good faith investigation reveals that misuse of personal information relating to 500 or more Utah residents, for identity theft or fraud purposes, has occurred or is reasonably likely to occur, the entity must also notify:
- The Office of the Utah Attorney General
- The Utah Cyber Center
The notification must include: the date the breach occurred, the date it was discovered, the total number of people affected (including the number of Utah residents), the type of personal information involved, and a short description of the breach.
Documents submitted to the AG or Cyber Center may be classified as protected records under certain circumstances, providing confidentiality protections during the investigation.
Consumer Reporting Agencies (1,000+ Threshold)
When the investigation reveals that misuse of personal information relating to 1,000 or more Utah residents, for identity theft or fraud purposes, has occurred or is reasonably likely to occur, the entity must also notify each consumer reporting agency that compiles and maintains files on consumers on a nationwide basis, as defined in 15 U.S.C. Section 1681a.
Methods of Notification
Utah permits several notification methods:
- Written notice sent by first-class mail
- Electronic notice, if the entity's primary method of communication with the resident is electronic
- Telephone notice, including through the use of automatic dialing technology
Substitute Notice
Utah also provides for notice by publishing in a newspaper of general circulation. This is available when other methods of notification are impractical.
Penalties and Enforcement

Civil Penalties
Under Section 13-44-301, a person who violates the statute is subject to:
- Up to $2,500 per consumer for a violation or series of violations concerning a specific consumer
- Up to $100,000 in the aggregate for related violations concerning more than one consumer
The $100,000 cap can be exceeded if the violations concern 10,000 or more consumers who are Utah residents and 10,000 or more consumers who are residents of other states, or if the person agrees to settle for a greater amount.
Attorney General Enforcement
Only the Attorney General can enforce the statute. The AG may seek:
- Civil penalties as outlined above
- Injunctive relief to prevent future violations
- Attorney's fees and costs
No Private Right of Action
Utah's breach notification law does not create a private right of action. Individuals cannot sue under this statute. They may pursue claims under other legal theories such as negligence, but not under the Protection of Personal Information Act itself.
Connection to the Utah Consumer Privacy Act
The Utah Consumer Privacy Act (UCPA), effective December 31, 2023, is a separate comprehensive privacy law that governs how businesses collect and use personal data. UCPA does not replace or modify the breach notification requirements of Chapter 44. The two laws operate independently:
- Chapter 44 governs what happens when personal information is compromised in a breach
- UCPA governs the collection, use, and sharing of personal data in the ordinary course of business
Businesses that handle Utah consumer data should ensure compliance with both statutes.
This article provides general legal information about Utah data privacy laws and breach notification requirements. It is not legal advice, and it does not create an attorney-client relationship. Data breach response involves time-sensitive obligations. Consult a qualified attorney licensed in Utah for guidance specific to your situation.
More Utah Laws
Frequently Asked Questions
How quickly must a business notify Utah residents after a data breach?
Utah requires notification in the most expedient time possible without unreasonable delay. There is no fixed-day deadline like the 30, 45, or 60 days many other states impose. The timeline must account for legitimate law enforcement needs, the time to determine the breach scope, and the time to restore system integrity.
Does Utah require Attorney General notification for data breaches?
Yes, as of May 2024. Senate Bill 98 added a requirement to notify the Attorney General and the Utah Cyber Center when the good faith investigation reveals that misuse of personal information relating to 500 or more Utah residents, for identity theft or fraud purposes, has occurred or is reasonably likely to occur. It is not a raw count of people whose data was exposed. The notification must include the breach date, discovery date, total affected individuals, type of personal information, and a description of the breach.
Does Utah's breach notification law apply to banks and credit unions?
No. Utah Code 13-44-103 states that the chapter does not apply to a financial institution or an affiliate of a financial institution, as defined in 15 U.S.C. Section 6809. Institutions within that definition are outside Chapter 44 entirely, including its investigation duty and its Attorney General and Cyber Center reporting thresholds.
What are the penalties for failing to notify about a data breach in Utah?
Civil penalties are capped at $2,500 per consumer and $100,000 in the aggregate for related violations. The aggregate cap can be exceeded in cases involving 10,000 or more consumers in both Utah and other states, or if the parties agree to a higher settlement. Only the Attorney General can enforce the law.
Must businesses investigate before sending breach notification in Utah?
Yes. Utah requires entities to conduct a good faith, reasonable, and prompt investigation upon becoming aware of a breach. Notification is required only if the investigation reveals that personal information has been or is reasonably likely to be misused for identity theft or fraud. This risk-based approach distinguishes Utah from states that require notification for any unauthorized acquisition.
Is it a reportable breach if an employee looks at data they should not have?
Usually not, on its own. Utah Code 13-44-102(1)(b) provides that a breach of system security does not include the acquisition of personal information by an employee or agent of the person possessing unencrypted computerized data, unless the personal information is used for an unlawful purpose or disclosed in an unauthorized manner. The reportability question turns on what the insider did with the information.
Does Utah's breach notification law cover medical or health information?
No. Utah's personal information definition only covers SSNs, financial account numbers with security codes, and driver's license or state ID numbers. Medical information, health insurance data, biometric data, and email credentials are not covered under the breach notification statute.
Affected by a data breach or biometric privacy violation?
If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.
Updates
Corrected the 500-resident Attorney General and Cyber Center trigger to match the statute's investigation-based misuse standard, and added Utah's financial-institution exemption, the employee and agent carve-out from the breach definition, and the safe harbor for entities that follow their primary regulator's breach procedures.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Governing law re-checked for recent changes
Corrected a claim that Utah's breach notification law does not require notifying consumer reporting agencies; Section 13-44-202(1)(d) requires it once a breach affects 1,000 or more Utah residents.
Governing law re-checked for recent changes
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
Utah Code, Title 13: Commerce and Trade
§ 13-44-202Personal information -- Disclosure of system security breach.In forcecited in 2 of our articles
(1) (a) A person who owns or licenses computerized data that includes personal information concerning a Utah resident shall, when the person becomes aware of a breach of system security, conduct in good faith a reasonable and prompt investigation to determine the likelihood that personal information has been or will be misused for identity theft or fraud purposes. (b) If an investigation under Subsection (1)(a) reveals that the misuse of personal information for identity theft or fraud purposes has occurred, or is reasonably likely to occur, the person shall provide notification to each affected Utah resident. (c) If an investigation under Subsection (1)(a) reveals that the misuse of personal information relating to 500 or more Utah residents, for identity theft or fraud purposes, has occurred or is reasonably likely to occur, the person shall, in addition to the notification required in Subsection (1)(b), provide notification to: (i) the Office of the Attorney General; and (ii) the Utah Cyber Center created in Section 63A-16-1102.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at le.utah.gov
Also relied on in: Utah Data Privacy Laws: UCPA Consumer Rights Guide (2026)
§ 13-44-102Definitions.In forcecited in 2 of our articles
As used in this chapter: (1) (a) "Breach of system security" means an unauthorized acquisition of computerized data maintained by a person that compromises the security, confidentiality, or integrity of personal information. (b) "Breach of system security" does not include the acquisition of personal information by an employee or agent of the person possessing unencrypted computerized data unless the personal information is used for an unlawful purpose or disclosed in an unauthorized manner. (2) "Consumer" means a natural person. (3) "Financial institution" means the same as that term is defined in 15 U.S.C. Sec. 6809.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at le.utah.gov
§ 13-44-301Enforcement -- Confidentiality agreement -- Penalties.In forcecited in 2 of our articles
(1) The attorney general may enforce this chapter's provisions. (2) (a) Nothing in this chapter creates a private right of action. (b) Nothing in this chapter affects any private right of action existing under other law, including contract or tort. (3) A person who violates this chapter's provisions is subject to a civil penalty of: (a) no greater than $2,500 for a violation or series of violations concerning a specific consumer; and (b) no greater than $100,000 in the aggregate for related violations concerning more than one consumer, unless: (i) the violations concern: (A) 10,000 or more consumers who are residents of the state; and (B) 10,000 or more consumers who are residents of other states; or (ii) the person agrees to settle for a greater amount. (4) (a) In addition to the penalties provided in Subsection (3), the attorney general may seek, in an action brought under this chapter: (i) injunctive relief to prevent future violations of this chapter; and (ii) attorney fees and costs.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at le.utah.gov
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- Utah Code 13-44-202 - Disclosure of System Security Breach(le.utah.gov).gov
- Utah Code 13-44-301 - Enforcement(le.utah.gov).gov
- Senate Bill 98 (2024) - Online Data Security and Privacy Amendments(le.utah.gov).gov
- Utah Cyber Center - Report a Breach(cybercenter.utah.gov).gov
- Utah Code 13-44-102 Definitions(le.utah.gov).gov
- Utah Code 13-44-103 - Applicability (financial institution exemption)(le.utah.gov)