The Utah Consumer Privacy Act (UCPA) has narrower applicability than similar privacy laws in other states. It sets specific criteria for businesses' annual revenue and data processing activities and offers exemptions to organizations governed by certain federal laws such as HIPAA.
The UCPA applies to businesses meeting specific revenue and data processing thresholds, encompassing those conducting business in the state or targeting Utah residents. Notably, the act offers consumers rights, including access to their personal data, the ability to request data deletion, and the right to opt out of certain data processing. The law also emphasizes data transparency, mandating clear privacy notices detailing data categories, processing purposes, and more. While the UCPA outlines consumer rights and controller obligations, enforcement falls under the Utah Attorney General, with a multi-step violation process.
See also: Do disclaimers make emails HIPAA compliant?
The UCPA applies to businesses that meet the following criteria:
See also: Spouses, family members and marriage under HIPAA
While the UCPA aims to protect consumer privacy and personal data, it incorporates specific exemptions to accommodate certain entities and scenarios. Notably, institutions of higher education, nonprofits, organizations under HIPAA, and institutions governed by the Gramm-Leach-Bliley Act, are exempt from UCPA requirements. Additionally, government entities, contractors, tribes, and air carriers fall within the scope of these exemptions. This aligns with UCPA's focus on consumer data privacy and recognizes certain sectors' adherence to federal regulations like HIPAA.
Organizations must provide clear and accessible privacy notices to consumers, detailing the categories of processed personal data, processing purposes, and how to exercise their rights. If personal data is sold or used for targeted advertising, they must disclose this and provide opt-out options. These organizations must also establish and maintain data security practices to protect the confidentiality and integrity of personal data.
See also: HIPAA Compliant Email: The Definitive Guide