Privacy Law Library

Cybersecurity Affirmative Defense Act

Utah Cybersecurity Affirmative Defense Act

Data security

Enacted by 2021 H.B. 80 and unchanged since, it gives a defense against claims of failing to implement reasonable controls, respond, or notify after a breach if the person had a written cybersecurity program reasonably conforming to NIST, CIS, ISO 27000, PCI DSS, HIPAA, GLBA, 13-44, or similar frameworks.

Where
Utah
Citation
Utah Code Title 78B, Chapter 4, Part 7 (78B-4-701 to 78B-4-706)
Status
In force
In force since
2021-05-05
Enforced by
None (creates an affirmative defense)
People can sue
No
Penalties
No penalties; the Part creates affirmative defenses and no private cause of action (78B-4-704).
Applies to
  • Persons that create, maintain, and follow a written cybersecurity program reasonably conforming to a recognized framework at the time of a breach (78B-4-702, -703)

Security duties

  • To claim the defense, maintain a written cybersecurity program, scaled appropriately and reasonably conforming to a recognized framework, that covers controls, response, and notification, and follow it.Utah Code 78B-4-702, 78B-4-703 · Only if: Entity relies on the affirmative defense

Other duties

  • The defense is lost if the person had actual notice of a threat and did not act in a reasonable time.Utah Code 78B-4-702(5)

Sources

Checked against these sources on 2026-09-23 by research agent (Claude), primary sources.

Unverified: effective_date is read from the version file name (C78B-4-S701_2021050520210505), per the memo's version-file convention.

Research reference, not legal advice.