Utah Statutes

§ 13-61-303 — Processing deidentified data or pseudonymous data.

Utah·Title 13 Commerce and Trade·Ch. 13-61 Utah Consumer Privacy Act·Part 13-61-3 Requirements for Controllers and Processors
(1)The provisions of this chapter do not require a controller or processor to:
(1)(a) reidentify deidentified data or pseudonymous data;
(1)(b) maintain data in identifiable form or obtain, retain, or access any data or technology for the purpose of allowing the controller or processor to associate a consumer request with personal data; or
(1)(c) comply with an authenticated consumer request to exercise a right described in Subsections 13-61-202(1) through (3), if:
(1)(c)(i) (1)(c)(i)(A) the controller is not reasonably capable of associating the request with the personal data; or
(1)(c)(i)(B) it would be unreasonably burdensome for the controller to associate the request with the personal data;
(1)(c)(ii) the controller does not:
(1)(c)(ii)(A) use the personal data to recognize or resp

Free access — add to your briefcase to read the full text and ask questions with AI

Utah § 13-61-303 (Processing deidentified data or pseudonymous data.) — published by Counsel Stack Legal Research, free access to 12M+ legal documents.

Legislative History

Enacted by Chapter 462, 2022 General Session

Nearby Sections

15
View on official source ↗