Law / United States / Utah
Protection of Personal Information Act, reasonable procedures and records-destruction duty
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force since 14 May 2019.
A security baseline statutes rule binding public and private bodies.
As of 12 September 2026.
What it requires
- This binds any person who conducts business in Utah and maintains personal information collected or maintained in the regular course of business.
- Implement and maintain reasonable procedures to prevent the unlawful use or disclosure of that personal information. The statute states no further content for what 'reasonable' requires beyond this general standard.
- Destroy, or arrange for the destruction of, records containing personal information that are not to be retained, by the method the section specifies.
- There is no private right of action for a violation of this section; only the Utah Attorney General may enforce this chapter.
If you get it wrong
Private right of actionNo
What it reaches
Obligation class
Security
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Utah Code 13-44-201, part of the Protection of Personal Information Act and effective May 14, 2019, requires any person who conducts business in the state and maintains personal information, reaching a governmental entity conducting business as well as a private business, the same broad reading of 'person' this jurisdiction's privacy-topic row already applies to the Act's breach-notification duty, to implement and maintain reasonable procedures to prevent the unlawful use or disclosure of personal information collected or maintained in the regular course of business, and to destroy, or arrange for the destruction of, records containing personal information that are not to be retained, by a method the section specifies.
The section states no further content for what 'reasonable' requires beyond that general standard, and, like the rest of the chapter, creates no private right of action: only the Attorney General may enforce it. The chapter's own breach-notification duty, requiring notice to an affected Utah resident and, for a large breach, to the Attorney General and the Utah Cyber Center, is this jurisdiction's privacy-topic row rather than repeated here.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotautomated_outreachhigh_risk_decisionsprocesses_voiceprocesses_biometricsserves_minorsoperates_social_platformships_mobile_appdistributes_software_product