← All jurisdictions
UT · data breach notification

Utah

med

Utah Code §13-44-101 et seq.

Individual deadline
No fixed limit
Trigger standard
Risk of harm
AG / regulator
Required
Notice to individualsin the most expedient time possible and without unreasonable delay
Risk-of-harm standardnotice where misuse for identity theft/fraud has occurred or is reasonably likely
Encryption safe harborYes, encrypted data (key not compromised) generally exempt.
Regulator noticeUtah Attorney General + Utah Cyber Center, required at 500+ residents; without unreasonable delay after investigation
Written notice
Credit reporting agenciesNotify CRAs at 1,000+ residents.
Substitute noticeTypically available above $250,000 cost / 500,000 affected (verify).
Private right of actionNo, enforcement by the state.
Notes
Cybersecurity affirmative-defense statute; publication substitute always permitted

Rule last verified July 10, 2026 · confidence med. This is a reference summary, not legal advice; verify against the current statute. How we compile this →

Is a Utah breach part of a multi-state incident?

See every jurisdiction at once, with letters and filing packets generated.

Run the calculator →