Utah was the fourth state to pass a comprehensive privacy law, and it deliberately wrote the most business-friendly version of the model: no data protection assessments, no right to correct, and opt-out rather than opt-in for sensitive data. This page sets out what the Utah Consumer Privacy Act actually requires, where lead.box sits relative to it, and why a lighter statute does not remove every question a vendor review will ask.
At a glance
- Framework
- Utah Consumer Privacy Act (UCPA), Utah Code §13-61-101 et seq., effective 31 December 2023
- Supervision
- Utah Division of Consumer Protection investigates and refers; Utah Attorney General brings enforcement actions; 30-day cure period
- Usual legal basis
- Legitimate business purpose; identification stays at company level, outside UCPA's definition of a 'consumer' or a 'sale' of personal data
- Processing location
- ISO-certified EU data centres
What the Utah Consumer Privacy Act actually covers
Regulation at a glance
- FrameworkUtah Consumer Privacy Act (UCPA), Utah Code §13-61-101 et seq., effective 31 December 2023
- SupervisionUtah Division of Consumer Protection investigates and refers; Utah Attorney General brings enforcement actions; 30-day cure period
- Usual legal basisLegitimate business purpose; identification stays at company level, outside UCPA's definition of a 'consumer' or a 'sale' of personal data
- Processing locationISO-certified EU data centres
The Utah Consumer Privacy Act, codified at Utah Code §13-61-101 et seq., took effect on 31 December 2023 as the fourth comprehensive US state privacy law. It was drafted with a lighter touch than California, Virginia or Colorado: there is no requirement to conduct a data protection assessment before high-risk processing, no consumer right to correct inaccurate data, and sensitive data processing needs only an opt-out mechanism rather than affirmative opt-in consent. Utah's legislature was explicit that it wanted a statute businesses could operationalise without the compliance overhead of its predecessors.
Applicability is also narrower than most peer states because the revenue test is conjunctive, not a simple population count. A controller must have at least $25 million in annual revenue and either process the personal data of 100,000 or more Utah residents, or derive over 50% of gross revenue from selling personal data while processing data of 25,000 or more residents. A large but low-revenue processor, or a mid-size company under the $25 million floor, can sit entirely outside the UCPA regardless of how much data it touches.
Enforcement runs as a two-step process rather than a single agency having authority end to end. The Utah Division of Consumer Protection receives and investigates consumer complaints, then refers matters it finds credible to the Utah Attorney General, who alone can bring an enforcement action. The statute also grants a 30-day cure period before any action proceeds, giving a business time to fix a violation once notified rather than facing immediate penalties.
Why B2B contact data sits outside the UCPA — and outside company-level identification too
The UCPA defines a 'consumer' as a Utah resident acting only in an individual or household context, and it says explicitly that someone acting in an employment context or on behalf of a business is not a consumer under the statute. That is the opposite of California's position: the CCPA/CPRA's temporary B2B and employee exemptions expired on 1 January 2023, so a business card exchanged at a conference is now personal data under California law but was never in scope in Utah to begin with. A Utah-based site handling only business contacts already sits outside the UCPA's core rights and obligations.
That exclusion, however, answers a narrower question than it appears to. It tells you the UCPA does not regulate a B2B email address or a work phone number — it says nothing about whether a website tool is reading browser storage, setting advertising identifiers, or building a cross-site profile of a named person, all of which can still raise other legal or contractual questions regardless of which consumer-privacy statute technically applies.
lead.box adds a third, separate distinction on top of both points: it identifies the organisation behind a website visit — the company name, industry and size band inferred from network-level signals — not a named individual. That means the product's design choice to stop at company level is independent of whether Utah's consumer-context carve-out would have covered the data anyway; it is a narrower scope by construction, not a reliance on a statutory exemption that could be interpreted differently elsewhere.
Start free
Install the snippet and see the first named companies on your own traffic.
The federal picture
This state page sits inside the wider United States market page, which covers the federal layer, cross-border transfers and the documentation a US buyer usually asks for.
United States overview →What you actually see
Named companies in your dashboard, with industry, size and the pages they read.
What Silicon Slopes vendor reviews still ask for
Utah's software cluster along the Wasatch Front — Lehi, Provo, Salt Lake City, and the corridor often branded Silicon Slopes — runs procurement processes shaped as much by enterprise customer expectations and investor diligence as by Utah state law itself. A UCPA-light regulatory environment does not mean a lighter vendor security review: SOC 2 questionnaires, data processing agreements and sub-processor lists are still standard asks, largely driven by out-of-state and enterprise customers whose own contracts require it.
A light-touch statute also does not answer the questions a legal team actually raises in a vendor review: what data is collected, whether it is sold or shared, where it is processed, and whether any individual is being tracked or profiled. lead.box answers those directly — no cookies for identification, no advertising identifiers, no sale of personal data, and processing in ISO-certified EU data centres with a published sub-processor list — regardless of whether the UCPA's narrower thresholds would have applied to the buyer at all.
This is background information, not legal advice, and Utah's applicability thresholds and consumer-context exclusion should be checked against your own counsel's reading of your specific data flows before you rely on them in a customer-facing statement.
How lead.box works here
GDPR-compliant visitor identification: the 5 rules
1. Company level only
Identification resolves the organisation behind a visit through network and IP-to-company matching. Individual people are never identified, and a visit that cannot be matched to a company stays anonymous.
2. Legal basis: legitimate interest, Art. 6(1)(f) GDPR
Company-level identification is commonly based on legitimate interest under Art. 6(1)(f) GDPR, documented with a balancing test. Consent is not required where no personal identifiers are processed; the final assessment stays with you as the controller.
3. No personal identifiers
No names, personal e-mail addresses, device fingerprints or cross-site profiles are created. Raw network addresses are not available in the interface, exports or API — only the resolved company is stored.
4. EU data processing
Personal and visitor data concerning the EU is processed in ISO-certified data centres in the European Union. EU visitor data is not moved outside the EU for this purpose.
5. Transparency and opt-out
Disclose the identification in your privacy policy — a copy-ready paragraph is on this page. Every visitor can object at any time through the public opt-out page.
lead.box applies all five rules by design.
Questions from this market
The UCPA regulates personal data tied to a 'consumer,' defined as a Utah resident acting in an individual or household context, and it expressly excludes someone acting in an employment or business context. lead.box resolves the visiting organisation — company name, industry, size band — from network-level signals rather than identifying a named person, which is a narrower activity than the UCPA's consumer-data provisions were written to reach in the first place. Beyond that, Utah's applicability thresholds are also unusually narrow: a controller needs at least $25 million in annual revenue plus either 100,000 Utah residents' data processed, or 25,000 residents' data combined with over 50% of revenue from data sales. Many sites fall outside the UCPA on thresholds alone, independent of the B2B question. Whether your specific deployment and data flows fall inside or outside UCPA's scope is a legal question for your own counsel, not something lead.box can certify on your behalf.
Utah excludes anyone acting in an employment or commercial context from its definition of 'consumer,' so a business card, a work email address, or a B2B contact record generally sits outside the UCPA's consumer-rights provisions entirely. California went the opposite direction: the CCPA's temporary business-to-business and employee exemptions expired on 1 January 2023, so the same work contact record is now personal information under California law with associated notice and rights obligations. A company operating in both states cannot apply one privacy posture nationwide and assume it satisfies both; the Utah exclusion does not travel with a California resident's data, and vice versa. lead.box's own scope — organisation-level identification, not named individuals — sits below both thresholds by design, but confirming how your own B2B data practices map to each state remains a task for your legal team, not a generic answer this page can provide.
Falling under $25 million in annual revenue, or below the 100,000-resident (or 25,000-resident-plus-50%-revenue) processing thresholds, means the UCPA itself likely does not apply to your business as a controller. It does not mean every data practice is automatically unregulated, because other laws can still reach the same conduct: the FTC Act's prohibition on unfair or deceptive practices applies regardless of size, other states' privacy laws may apply if you have visitors or customers there, and sector-specific rules can layer on top depending on your industry. Being outside UCPA's thresholds is a genuinely useful fact for a vendor review, but it answers one specific statutory question rather than a general compliance question. Treat it as one data point among several, and have counsel confirm which other frameworks might still be relevant to your specific business.
If the Utah Division of Consumer Protection investigates a complaint and refers it to the Attorney General, and the Attorney General determines a violation is curable, the business gets 30 days' written notice and an opportunity to fix the issue before any enforcement action can proceed. This is a more forgiving structure than statutes with immediate penalty exposure, and it reflects Utah's general legislative intent to keep compliance burden low. It does not mean violations are consequence-free or that the cure period applies indefinitely to repeat conduct; it is a one-time-per-notice opportunity to correct a specific identified problem. For a tool like lead.box, the practical relevance is limited because company-level identification is designed to sit outside personal-data processing in the first place, but the cure period is still a meaningful part of understanding Utah's overall enforcement posture.
The UCPA requires opt-in consent only for processing sensitive data categories about a consumer, and requires an opt-out mechanism, not opt-in consent, for other processing such as targeted advertising or the sale of personal data — a notably lighter consent regime than several peer states. lead.box's company-level identification does not process sensitive data categories, does not set advertising identifiers, and does not sell personal data, so it does not trigger either the UCPA's opt-in or opt-out consent mechanisms as currently structured. Whether your website needs a broader consent or cookie-preference tool for its other functions — analytics, advertising pixels, chat widgets — is a separate question governed by what else runs on the site, not by lead.box's own operation. Your own privacy notice should still describe what lead.box does in plain terms.
No, and this is a common misunderstanding for companies based along the Wasatch Front. An enterprise customer's procurement team applies its own vendor security standards — SOC 2 reports, data processing agreements, sub-processor disclosures, incident response commitments — largely independent of which state privacy law technically governs your headquarters. Those standards are usually stricter than what Utah's own statute requires, because they reflect the customer's own regulatory exposure, not yours. lead.box is built to a GDPR-grade baseline specifically because customers in stricter jurisdictions, or with stricter internal policies, need documentation that exceeds any single US state's minimum. Treating UCPA compliance as sufficient for out-of-state enterprise sales tends to slow deals down rather than speed them up.
The service resolves network-level signals — primarily IP address ranges associated with organisations — into a company name, industry and approximate size, without identifying a named individual, without setting cookies or device fingerprints, and without following a person's browsing across unrelated websites. No form submission, login or email address is required for identification to occur, and nothing produced links back to a specific employee or job title. What is stored is a record that a given organisation visited certain pages during a given window — the input a sales team uses to prioritise outreach. A list of named people, their titles or their personal contact details is explicitly not produced, since that would be a different and more sensitive category of data than company-level identification is built to handle.
Identification relies on mapping IP address ranges to organisations, which works reliably for a visit from a corporate office, a fixed business connection, or a company VPN, but is inherently less precise for visitors on residential ISPs, mobile networks, coworking spaces or consumer VPN services — categories that make up a meaningful share of traffic given how many Wasatch Front tech workers operate remotely or hybrid. In practice this means some visits will not resolve to a company at all rather than resolving incorrectly, and match rates vary by industry and by how a given organisation's own network is structured. Sales and marketing teams should treat the identified company list as a prioritisation signal for further outreach, not a confirmed record of exactly who viewed which page; this is general product guidance, not a legal or accuracy warranty.
See which Utah companies are already researching you
Install a first-party snippet, watch the first companies appear, and hand your legal team documentation built to a stricter standard than the UCPA requires.