Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

UCPA compliance is not a WordPress setting or a single plugin. First determine whether the Utah Consumer Privacy Act applies to your organization; then map the personal data your site and vendors handle, publish the required disclosures if you are a covered controller, and set up a process for privacy requests. A WordPress site that attracts Utah visitors is not automatically covered. This guide is general information, not legal advice; get legal review if your organization’s thresholds, exemptions, or roles are unclear.

Does the UCPA apply to your website?

The Utah Division of Consumer Protection describes the UCPA as applying to controllers and processors that do business in Utah or target Utah residents and meet the law’s revenue and processing tests, subject to exemptions. Its business fact sheet, accessed in 2026, gives these thresholds:

  • Annual revenue: at least $25 million; and
  • Processing threshold: either personal data of at least 100,000 consumers during a calendar year, or personal data of at least 25,000 consumers when more than 50% of gross revenue comes from selling personal data.

The tests are conjunctive: Utah business activity or targeting is not enough on its own, and revenue alone does not establish coverage. The law also has entity, data, and processing exemptions, so check those rather than treating the figures as the entire analysis. The fact sheet is the Utah Division of Consumer Protection’s summary of these thresholds.

Identify the organization’s role

A controller decides why and how personal data is processed. A processor handles personal data for another organization. A business may have either role, or both in different relationships; assess the organization and its data practices, not merely the WordPress installation. If you conclude the UCPA does not apply, that does not establish that other privacy laws impose no duties.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What rights and deadlines should a covered site handle?

Utah’s Division of Consumer Protection consumer fact sheet describes rights to confirm whether personal data is being processed, access it, request deletion of data the consumer provided, obtain a portable copy, and opt out of targeted advertising or the sale of personal data. The agency and Utah Attorney General’s Office guidance says businesses have 45 days to respond to a consumer request.

A 2025 Utah Code reproduction reports that an amendment effective July 1, 2026 added a right to request correction of inaccurate personal data, taking into account the data and the purposes of processing. Because that update is reported here through a secondary code reproduction, check the current official Utah Code before designing a correction-request procedure.

Make requests operational

Provide a way for a person to specify the right they want to exercise, assign a responsible person to receive and track requests, and plan how to verify and fulfill them. The 45-day response period is stated in Utah agency and Attorney General guidance; do not let requests sit in a general support inbox without an owner or deadline tracking.

What must a covered controller disclose?

The Utah Division of Consumer Protection’s business fact sheet says a covered controller must provide a clear, reasonably accessible privacy notice describing:

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Categories of personal data processed and the purposes for processing it.
  • How a consumer can exercise privacy rights.
  • Categories of personal data shared and categories of third parties that receive it.

If the controller sells personal data or uses it for targeted advertising, the notice must clearly explain how to opt out. Processing sensitive data requires clear notice and an opportunity to opt out. The fact sheet also describes reasonable administrative, technical, and physical data-security practices as a business duty.

How to map the data handled by a WordPress site

Start with a practical inventory rather than the list of plugins in the dashboard. WordPress’s privacy tools cannot discover every external service, and the site owner remains responsible for an accurate account of the site’s data practices.

Rank #3
Daily Warm Ups: Word Problems - Book - Grade 3
  • Sold as an Each
  • An ideal resource for helping students learn a variety of strategies for solving word problems
  • Includes 250 exercises that also help teach other math concepts as well
  • Prepare your students with both strategies and skills for solving a variety of word problems to ensure success
  • Ideal for grade level 3
  1. List collection points: check comments, account registration, contact and lead forms, ecommerce checkout, newsletter signups, and any custom forms or theme features.
  2. List tracking and embedded services: include analytics, advertising pixels, embedded media, social widgets, and scripts loaded through a tag manager.
  3. List storage and recipients: include the hosting provider, email or newsletter platform, payment and ecommerce services, backup systems, and any plugin or vendor that receives personal data.
  4. For each flow, record: the data category, purpose, retention, recipient, and whether the recipient is a vendor processing data for you or another kind of third party.
  5. Assign request ownership: note where each category is stored, who can access or delete it, and whether a request must also be sent to an outside provider.
  6. Review changes: update the inventory when you add or change a theme, plugin, tag, integration, or vendor.

This inventory supports notice writing, request handling, and security work; it is an operational aid, not a legal safe harbor.

Which WordPress tools help with privacy requests?

WordPress core provides useful components, but they do not cover every system that may hold site-related data.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Privacy policy helper

In the dashboard, open Settings > Privacy to use the privacy-policy helper. It supplies starter text from WordPress core and participating themes and plugins. Review and complete it so it describes the actual site, including services that the helper cannot detect, such as separate analytics or newsletter providers.

Export and erasure workflows

Open Tools > Export Personal Data or Tools > Erase Personal Data to work with applicable requests. These workflows send an email validation request and require an administrator to take action. They cover data handled by WordPress and participating plugins, not necessarily data held by analytics, advertising, newsletter, embed, or other external services. Those systems may need their own request or a separate manual step.

WordPress’s erasure documentation warns that deletion is permanent, does not remove backups or archives, and does not automatically erase registered user accounts and profile data. Administrators may need to handle those separately and consider archived copies if restoring them. Some information may need to be retained for legal or security reasons, so do not treat an erasure request as an instruction to delete every record without review.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Do you need a cookie consent plugin for Utah?

Not simply because you use WordPress or have Utah visitors. The UCPA obligations summarized by Utah’s agency materials connect opt-outs to the sale of personal data and targeted advertising, and require notice and an opportunity to opt out for sensitive-data processing. Determine what the site actually does and which laws apply before deciding whether it needs a banner, an opt-out control, or other tooling. WordPress core does not include consent tools.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A plugin or service may help manage controls, but its presence does not prove compliance. WordPress documentation notes that plugins exist; it does not certify that any particular one satisfies UCPA duties. Assess whether a candidate can control the technologies your site uses, cover relevant third-party tags and embeds, support preference changes accessibly, integrate with your current plugins, and remain maintainable.

Manual workflow or specialist privacy tool?

Both approaches can be part of a compliance process. Neither replaces deciding whether the law applies or accounting for data outside WordPress.

Approach What it involves Main consideration
Manual workflow Use WordPress privacy and request tools alongside vendor dashboards, documented procedures, and an inventory of data flows. Requires an owner to coordinate requests and keep procedures current across site and vendor systems.
Specialist privacy or consent tool Add a plugin or service to manage relevant preferences, tags, or request workflows alongside WordPress core. Confirm actual coverage, accessibility, compatibility, and ongoing administration needs; no particular vendor is established here as suitable.

Where the revenue or consumer thresholds, exemptions, sensitive-data processing, sale or advertising practices, or controller/processor roles are uncertain, a professional privacy review is a reasonable next step.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.