Utah · verified through August 25, 2026

Utah: law status and evidence context.

Law status, direct attached-library attribution, and public enforcement context are shown separately. A zero direct total does not mean no enforcement exists.

UT · 6 requirements mapped / control outcomes supported

Law status

Verified comprehensive law

Yes - Utah Consumer Privacy Act

Official name / citation
Utah Code tit. 13, ch. 61 (e.g., § 13-61-202)
Status / effective date
Codified; § 13-61-202 effective December 31, 2023
Principal enforcer
Utah Attorney General with the Utah Division of Consumer Protection (division/AG split not verified on the fetched pages)

Direct attached-library attribution

0 cases · $0

These totals are assigned solely by the attachment’s state heading. Shared multistate totals are not allocated in full to every state.

The attached library does not enumerate participant-level allocations for every multistate matter; shared settlement totals are presented once at the national level and are not duplicated into state totals.

Official law sources

Other generally applicable PII law

Also: Utah Code § 13-44-202 (breach disclosure), effective May 1, 2024 - https://le.utah.gov/xcode/Title13/Chapter44/C13-44-S202_2024050120240501.pdf

Public enforcement context

Tier 1

23andMe (bankruptcy claims)

$18 million multistate settlement; Utah share stated as $461,688 · n.a. (date not stated on page)

Utah joined a coalition of more than forty AGs settling claims over the 2023 23andMe breach affecting about 6.9 million users.

Legal basis: State data-privacy, consumer-protection and genetic-information privacy laws (no specific statute cited)

Official case source (opens in a new tab)

Mapped control outcomes

1 personal data inventory/data map; 2 sensitive-data discovery; 3 downstream copy tracking; 8 breach blast-radius analysis; 9 retention/minimization; 10 regulator audit evidence

Kestryl can evidence where regulated personal data actually resides across structured stores and unstructured attachments/images, produce audit rows and evidence packs showing when each location was discovered and reviewed, and apply structured-data remediation modes (mask, vault, strip) to reduce exposure. It does not alter source attachments or documents, and its output is technical evidence supporting controls, not proof of legal compliance.