Utah

Who Is Covered?

A person who owns or licenses computerized data that includes personal information concerning a Utah resident. Utah Code Ann. § 13-44-202(1)(a).

 

What Information Is Protected?

“Personal information” means a person’s first name or first initial and last name, combined with any one or more of the following data elements relating to that person when either the name or date element is unencrypted or not protected by another method that renders the data unreadable or unusable:

 

  1. Social Security number;
  2. (A) financial account number, or credit or debit card number; and (b) any required security code, access code, or password that would permit access to the person’s account; or
  3. Driver license number or state identification card number. Utah Code Ann. § 13-44-102(4).

 

What Is A “Breach”?

“Breach of system security” means an unauthorized acquisition of computerized data maintained by a person that compromises the security, confidentiality, or integrity of personal information. Utah Code Ann. § 13-44-102(1)(a).

 

What Triggers Notification?

When a person becomes aware of a breach of system security, the person must conduct in good faith a reasonable and prompt investigation to determine the likelihood that personal information has been or will be misused for identity theft or fraud purposes. Notification must be provided if the investigation reveals that the misuse of personal information for identity theft or fraud purposes has occurred, or is reasonably likely to occur, the person shall provide notification to each affected Utah resident. Utah Code Ann. § 13-44-202(1).

 

How Is Notice Provided To Individuals?

Timing: Notification must be made in the most expedient time possible without unreasonable delay considering the legitimate investigative needs of law enforcement, after determining the scope of the breach of system security and after restoring the reasonable integrity of the system. Utah Code Ann. § 13-44-202(2).

Delivery: Notification may be provided:

 

  1. In writing by first-class mail to the most recent address the person has for the resident;
  2. Electronically, if the person’s primary method of communication with the resident is by electronic means, or if provided in accordance with the consumer disclosure provisions of 15 U.S.C. Section 7001;
  3. By telephone, including through the use of automatic dialing technology not prohibited by other law; or
  4. For residents of the state for whom notification in a manner described above is not feasible, by publishing notice of the breach of system security: (A) in a newspaper of general circulation; and (B) as required in Section 45-1-101 [legal notice publication requirements]. Utah Code Ann. § 13-44-202.

Content: None specified.

 

Is Notice To The Government Required?

Yes. If the investigation reveals that the misuse of personal information relating to 500 or more Utah residents, for identity theft or fraud purposes, has occurred or is reasonably likely to occur, the person shall, in addition to the notification required in Subsection (1)(b), provide notification to: 

  1. the office of the Attorney General; and
  2. the Utah Cyber Center. Utah Code Ann. § 13-44-202(1)(c).

 

Is Notice To Credit Reporting Agencies Required?

Yes, if the investigation reveals that the misuse of personal information relating to 1,000 or more Utah residents, for identity theft or fraud purposes, has occurred or is reasonably likely to occur.
Utah Code Ann. § 13-44-202(1)(d).

 

Are There Security Measure Standards?

Yes. Any person who conducts business in the state and maintains personal information shall implement and maintain reasonable procedures to:

 

  1. Prevent unlawful use or disclosure of personal information collected or maintained in the regular course of business; and
  2. Destroy, or arrange for the destruction of, records containing personal information that are not to be retained by the person. 

The destruction of records shall be by: (a) shredding; (b) erasing; or (c) otherwise modifying the personal information to make the information indecipherable. Utah Code Ann. § 13-44-201.

 

What Are The Possible Consequences Of A Violation?

In addition to injunctive relief and attorney fees and costs, the attorney general may seek a civil penalty of:

 

  1. No greater than $2,500 for a violation or series of violations concerning a specific consumer; and
  2. No greater than $100,000 in the aggregate for related violations concerning more than one consumer, unless: a) the violations concern: (i) 10,000 or more consumers who are residents of the state; and (ii) 10,000 or more consumers who are residents of other states; or b) the person agrees to settle for a greater amount. Utah Code Ann. § 13-44-301(3), (4).

 

Are There Any Exemptions/Exceptions?

If a person maintains the person’s own notification procedures as part of an information security policy for the treatment of personal information the person is considered to be in compliance with this chapter’s notification requirements if the procedures are otherwise consistent with this chapter’s timing requirements and the person notifies each affected Utah resident in accordance with the person’s information security policy in the event of a breach. Utah Code Ann. § 13-44-202(5)(b).

Also, a person who is regulated by state or federal law and maintains procedures for a breach of system security under applicable law established by the primary state or federal regulator is considered to be in compliance with this part if the person notifies each affected Utah resident in accordance with the other applicable law in the event of a breach. Utah Code Ann. § 13-44-202(5)(c).