What UCPA says about fingerprinting
The Utah Consumer Privacy Act took effect on 31 December 2023 and is codified at Utah Code §13-61-101 through §13-61-404. UCPA is the Virginia cluster's outlier: it imported the basic shape of VCDPA, opt-out rights, sensitive-data opt-in, AG enforcement, no private right of action, and stripped out the harder-to-implement obligations. There is no Data Protection Assessment requirement, no Universal Opt-Out Mechanism, no profiling opt-out, and a revenue gate that excludes mid-size companies from the law entirely.
Section 13-61-101(24) defines personal data using the same linked-or-reasonably-linkable wording as the rest of the cluster, so a fingerprint hash used to recognise a returning Utah consumer falls inside the definition. But the operational obligations that follow that classification are materially lighter in Utah than in any other state in the cluster.
The drafting choice was deliberate. Utah's legislative debate in 2021 and 2022 emphasised business-friendliness as the design goal. The result is a privacy law that protects the most-affected consumer rights without imposing the operational compliance overhead of CCPA, CPA, or CTDPA.
When UCPA applies to you
Section 13-61-102 applies UCPA only to controllers that (a) conduct business in Utah or produce products or services targeted to Utah residents, (b) have annual revenue of $25 million or more, AND (c) either control or process the personal data of at least 100,000 Utah consumers in a calendar year, or control or process the personal data of at least 25,000 Utah consumers AND derive over 50% of gross revenue from the sale of personal data.
The compound test matters. UCPA is the only US state-privacy law with a revenue gate at the applicability layer. A controller with $20 million in revenue and two million Utah users is outside UCPA. A controller with $30 million in revenue and 80,000 Utah users is outside UCPA (consumer-count below 100,000 and sale-revenue below 50%).
Consumer is defined at §13-61-101(7) as an individual who is a Utah resident acting in an individual or household context. Employees and B2B contacts are excluded, matching the cluster.
The opt-out triggers and how they apply to fingerprinting
Section 13-61-201 grants Utah consumers four rights: access, deletion, portability, and opt-out. The opt-out applies only to targeted advertising and sale of personal data. UCPA does not include a profiling opt-out, the right that exists in every other Virginia-cluster state. A fingerprint used as one input to a profiling decision with legal effect is not opt-out-able under UCPA.
Sale of personal data under §13-61-101(31) requires monetary consideration only, matching Virginia and narrower than Colorado. Sharing fingerprint hashes for non-monetary value is unlikely to count as sale.
Targeted advertising at §13-61-101(34) carries the standard scope. Cross-site behavioural ads selected based on activity on non-affiliated sites and applications is in. First-party retargeting, frequency capping on your own site, and contextual advertising are out.
Common fingerprinting purposes under UCPA
| Purpose | Personal data? | DPA required? | Opt-out right applies? |
|---|---|---|---|
| Anti-fraud at login or payment | Yes | N/A (no DPA requirement at all) | No |
| Account-takeover detection | Yes | N/A | No |
| Bot mitigation on a public form | Yes | N/A | No |
| Cross-site targeted advertising | Yes | N/A | Yes (targeted advertising) |
| Selling fingerprint-derived audience segments for a fee | Yes | N/A | Yes (sale) |
| Sharing fingerprint hashes for non-monetary value | Yes | N/A | Probably no for sale; yes if used for targeted ads |
| Profiling for credit / insurance / employment | Yes | N/A | No (UCPA does not have a profiling opt-out) |
| Product analytics on your own service | Yes | N/A | No |
No Data Protection Assessment requirement
Every other Virginia-cluster state requires a documented Data Protection Assessment before engaging in targeted advertising, sale, sensitive-data processing, or covered profiling. UCPA does not. There is no §13-61-XXX equivalent of VCDPA's §59.1-580 or CPA's 4 CCR 904-3 Rule 8.
This is the largest operational difference between Utah and every other cluster state. A fingerprinting deployment may be launched into Utah without a documented DPA, which does not mean the controller has no obligations, but it does mean the AG cannot ground an enforcement action on a missing assessment.
The practical implication: do not skip the DPA exercise. The DPA you produced for VCDPA, CPA, or CTDPA covers Utah operationally. The absence of a UCPA-specific requirement is a forgiveness clause, not a license to avoid the work.
No Universal Opt-Out Mechanism recognition
Utah is also the only Virginia-cluster state that does not require Universal Opt-Out Mechanism support. There is no statutory requirement to recognise Global Privacy Control, and the Utah AG has not adopted a UOOM-recognition stance through guidance.
Practically, this means a controller that operates only in Utah can run an on-site opt-out preference centre without a GPC header check. A controller that operates in Utah AND Colorado, Connecticut, Oregon, Montana, Delaware, or New Hampshire still needs the GPC check for the other states, but Utah-only is the rare case where a non-UOOM deployment is statutorily compliant.
Dual enforcement and the cure window
UCPA enforcement runs through two offices. The Utah Division of Consumer Protection (part of the Department of Commerce) investigates consumer complaints and refers actionable matters to the Utah Attorney General, which prosecutes. Civil penalties cap at $7,500 per violation under §13-61-402.
The 30-day cure period at §13-61-402(2)(b) remains in effect with no scheduled sunset. The Division of Consumer Protection has signalled it will use the cure window generously for first-time documentation gaps and inadvertent processing errors. Repeat or wilful violations are treated more strictly, but the cure remains the default operational posture.
Enforcement to date
- Utah's Division of Consumer Protection has handled UCPA inquiries primarily through informal letters since the law took effect in late 2023. The volume is materially lower than Colorado's or Connecticut's enforcement activity.
- No major UCPA settlement has been published at the time of writing. The cure-period mechanism appears to have resolved most identified issues without formal AG proceedings.
- There is no private right of action under UCPA. Class plaintiffs cannot bring UCPA claims directly. The Utah Consumer Sales Practices Act provides an alternate route for individual consumers in some circumstances but has not been used as a UCPA proxy.
- The Division of Consumer Protection has emphasised privacy-notice failures and unclear opt-out mechanisms as the early enforcement priorities, mirroring Connecticut's and Colorado's stance.
How Benny the Doorman fits into a UCPA-aware deployment
Three steps for a UCPA-aware deployment, all materially lighter than the equivalent CPA or CTDPA workflow. First, verify the $25 million revenue gate. If your average annual revenue over the prior three years is below $25 million, UCPA does not apply to you regardless of how many Utah consumers you process.
Second, implement an opt-out preference mechanism for targeted advertising and sale. UCPA does not require UOOM handling, so a clean on-site opt-out is sufficient, but if you operate in any other Virginia-cluster state with a UOOM requirement, you need the GPC check anyway and Utah is a free pass.
Third, treat the absence of a DPA requirement as a paperwork forgiveness clause, not a content-of-thinking forgiveness clause. Run the DPA exercise, Benny's documentation already provides the technical inputs, even though Utah's AG cannot ground enforcement on a missing one. The exercise itself surfaces operational issues before consumers do.
Frequently asked questions
Is browser fingerprinting illegal under UCPA?
No. Fingerprinting is regulated as personal data when it can be linked back to a Utah consumer, with opt-out rights for targeted advertising and sale. UCPA does not require a Data Protection Assessment, does not require Universal Opt-Out Mechanism support, and does not include a profiling opt-out, making it the friendliest law in the Virginia cluster for fingerprinting deployments.
Does UCPA apply to my company?
Only if you (a) conduct business in Utah or target Utah residents, (b) have annual revenue of $25 million or more, AND (c) either process 100,000 Utah consumers or process 25,000 Utah consumers with more than 50% of revenue from sale of personal data. Companies below the $25 million revenue threshold are entirely outside UCPA regardless of consumer count.
Do I need a Data Protection Assessment under UCPA?
No. UCPA is the only Virginia-cluster law without a DPA requirement. The AG cannot ground enforcement on a missing assessment. That said, if you operate in any other cluster state (Virginia, Colorado, Connecticut, Texas, Oregon, Montana, Delaware, Iowa, Tennessee, New Hampshire, or New Jersey), you already need the assessment for those states, Utah is a free pass once the work is done.
Do I need to honour Global Privacy Control under Utah law?
No. UCPA does not require Universal Opt-Out Mechanism support, and the Utah AG has not adopted a UOOM-recognition stance through guidance. A Utah-only deployment can run an on-site opt-out preference centre without a GPC header check. A deployment operating in Utah AND any UOOM state still needs the check for those other states.
Can I profile users in Utah without an opt-out?
Statutorily yes, UCPA does not include a profiling opt-out, but tread carefully. Profiling that affects financial services, healthcare, or insurance access is regulated under other Utah consumer-protection laws and federal statutes (FCRA, ECOA) regardless of UCPA's silence. The UCPA-only analysis is not the full compliance picture for high-stakes profiling.
What is the cure period under UCPA?
30 days from notice of violation, under §13-61-402(2)(b). Unlike Colorado and Connecticut, Utah did not sunset its cure window and has no current proposal to do so. The Division of Consumer Protection uses the cure window generously for first-time documentation gaps.
What are the fines for non-compliant fingerprinting under UCPA?
Civil penalties under §13-61-402 reach $7,500 per violation, matching Virginia's cap. Practical exposure is materially lower than Colorado or Connecticut because the Division of Consumer Protection has favoured the cure mechanism over formal enforcement, and there is no parallel CUTPA-style attachment route to escalate penalties.
How is UCPA different from VCDPA for fingerprinting?
Four differences. UCPA has a $25 million revenue gate at applicability, VCDPA does not. UCPA has no Data Protection Assessment requirement, VCDPA's §59.1-580 does. UCPA does not require Universal Opt-Out Mechanism support, VCDPA recognises UOOM via the on-site opt-out. UCPA has no profiling opt-out, VCDPA has one for decisions with legal effect. In every dimension, Utah is the friendlier law to controllers.
Tooling
Benny the Doorman is built for this compliance posture.
Free, cookieless fingerprinting that defers to your consent management platform, runs on Indian infrastructure, and ships with a DPA addendum sized for the jurisdiction above.
Last reviewed 2026-06-06

