Law / United States / Utah
Cybersecurity Affirmative Defense Act
Utah Code 78B-4-701 to 78B-4-704
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force since 5 May 2021.
A security baseline statutes rule binding private bodies.
As of 12 September 2026.
What it requires
- This is a defense available to any person sued in Utah on a claim arising from a breach of system security; it creates no independent duty to adopt a cybersecurity program, and under section 78B-4-704 may not be construed to create a private cause of action, including a class action, for failing to comply with it.
- To claim the defense against a claim of failing to implement reasonable information security controls, failing to appropriately respond to a breach, or failing to appropriately notify an affected individual, have in place at the time of the breach a written cybersecurity program designed to protect the type of personal information at issue and scaled to your size, complexity, activities, and the sensitivity of the information you hold.
- Build the program as a reasonable security program, a designated coordinator, procedures to detect, prevent and respond to a breach, employee training, and periodic risk assessments of network and software design, information handling, and data storage and disposal, adjusted as circumstances change, or have it reasonably conform to a current named framework: NIST SP 800-171; NIST SP 800-53 and 800-53A; the FedRAMP Security Assessment Framework; the CIS Critical Security Controls; the ISO/IEC 27000 family; the HIPAA Security Rule or Gramm-Leach-Bliley Title V regulations for information those regimes cover; or the PCI Data Security Standard for payment card information.
- Update the program to a revised framework within one year of the revision's publication, and to an amended regulation within a reasonable time weighed against the risk to personal information and the cost and effort of compliance.
- The defense is unavailable if you had actual notice of a threat or hazard to the information's security and did not act in a reasonable amount of time to take known remedial efforts before it resulted in the breach; a risk assessment to improve security is not itself actual notice.
What it reaches
Obligation class
Security
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
The Cybersecurity Affirmative Defense Act, Utah Code 78B-4-701 to 78B-4-704, enacted by Chapter 40 of the 2021 General Session and effective May 5, 2021, gives a person sued in a Utah court on a claim arising from a breach of system security three affirmative defenses where a qualifying written cybersecurity program was in place at the time of the breach: a defense to a claim that the person failed to implement reasonable information security controls, a defense to a claim that the person failed to appropriately respond to the breach, and a defense to a claim that the person failed to appropriately notify an affected individual.
A qualifying program must be designed to protect the type of personal information obtained in the breach, be of a scale and scope appropriate to the person's size, complexity and activities and the sensitivity of the information, and either operate as a reasonable security program with a designated coordinator, detection and response procedures, employee training, and periodic risk assessment and adjustment, or reasonably conform to a named industry framework: NIST Special Publication 800-171; NIST Special Publications 800-53 and 800-53A; the FedRAMP Security Assessment Framework; the Center for Internet Security Critical Security Controls; the ISO/IEC 27000 family; the HIPAA Security Rule or Gramm-Leach-Bliley Title V regulations, for personal information those regimes already cover; or the PCI Data Security Standard, for payment card information.
A person loses the defense if it had actual notice of a threat or hazard to the information's security and did not act in a reasonable time to remediate it before the breach resulted; a risk assessment alone is not actual notice.
The Act imposes no duty to adopt a program and, by its own terms, may not be construed to create a private cause of action, including a class action, for a person's failure to comply with it: it is a defendant's shield, never a plaintiff's remedy, and Utah Code 13-44-201, researched separately below, is the reasonable-procedures duty the shield answers.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotautomated_outreachhigh_risk_decisionsprocesses_voiceprocesses_biometricsserves_minorsoperates_social_platformships_mobile_appdistributes_software_product