Cybersecurity Affirmative Defense Act
Utah Cybersecurity Affirmative Defense Act
Data security
Enacted by 2021 H.B. 80 and unchanged since, it gives a defense against claims of failing to implement reasonable controls, respond, or notify after a breach if the person had a written cybersecurity program reasonably conforming to NIST, CIS, ISO 27000, PCI DSS, HIPAA, GLBA, 13-44, or similar frameworks.
- Where
- Utah
- Citation
- Utah Code Title 78B, Chapter 4, Part 7 (78B-4-701 to 78B-4-706)
- Status
- In force
- In force since
- 2021-05-05
- Enforced by
- None (creates an affirmative defense)
- People can sue
- No
- Penalties
- No penalties; the Part creates affirmative defenses and no private cause of action (78B-4-704).
- Applies to
- Persons that create, maintain, and follow a written cybersecurity program reasonably conforming to a recognized framework at the time of a breach (78B-4-702, -703)
Security duties
- To claim the defense, maintain a written cybersecurity program, scaled appropriately and reasonably conforming to a recognized framework, that covers controls, response, and notification, and follow it.Utah Code 78B-4-702, 78B-4-703 · Only if: Entity relies on the affirmative defense
Other duties
- The defense is lost if the person had actual notice of a threat and did not act in a reasonable time.Utah Code 78B-4-702(5)
Sources
- Official text
- Utah Code 78B-4-702 (Utah Legislature, version C78B-4-S702_2021050520210505)
- Utah Code 78B-4-703 (Utah Legislature, version C78B-4-S703_2021050520210505)
- Utah Code 78B-4-704 (Utah Legislature, version C78B-4-S704_2021050520210505)
Checked against these sources on 2026-09-23 by research agent (Claude), primary sources.
Unverified: effective_date is read from the version file name (C78B-4-S701_2021050520210505), per the memo's version-file convention.
Research reference, not legal advice.