Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

WordPress does not have a setting or plugin that automatically makes a site UCPA-compliant. First determine whether the Utah Consumer Privacy Act applies to your organization; then map the personal data your site and its vendors handle, publish the required disclosures if you are a covered controller, and establish a process for consumer requests. Utah visitors alone do not make every WordPress site subject to the law.

This guide explains the general requirements and practical WordPress steps. Applying statutory thresholds, exemptions, and overlapping privacy laws to a particular organization may require legal review.

Does the UCPA apply to your WordPress site?

The threshold test applies to an organization, not simply to a website or its WordPress installation. According to the Utah Division of Consumer Protection’s UCPA business fact sheet, the law applies to a controller or processor that does business in Utah or targets Utah residents, has at least $25 million in annual revenue, and meets either of the following processing tests:

  • Processes personal data of at least 100,000 consumers during a calendar year; or
  • Derives more than 50% of gross revenue from the sale of personal data and processes personal data of at least 25,000 consumers during a calendar year.

The agency also notes that exemptions may apply to certain entities, data, and processing. Meeting the numbers is not the only issue to assess, and a Utah audience by itself does not satisfy the full test. Other privacy laws may use different applicability tests, so a conclusion that the UCPA does not apply is not a conclusion that no privacy duties apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Understand your role

A controller determines why and how personal data is processed. A processor handles data on another organization’s behalf. A business may act as a controller for information collected through its own site and as a processor in a separate relationship. Assess the organization’s activities and relationships, not just which WordPress plugins are installed.

The thresholds above are from the Utah Division of Consumer Protection’s business fact sheet, accessed in 2026. If your revenue, consumer counts, or role is near the threshold—or an exemption may apply—get advice specific to your organization.

What must a covered controller tell people and do?

A covered controller needs a clear, reasonably accessible privacy notice. Utah’s Division of Consumer Protection says it should explain the categories of personal data processed and the purposes for processing; how consumers can exercise their rights; the categories of personal data shared; and the categories of third parties that receive it.

If the controller sells personal data or engages in targeted advertising, the notice must clearly explain how to opt out. Processing sensitive data requires clear notice and an opportunity to opt out. The agency also summarizes a duty to maintain reasonable administrative, technical, and physical data-security practices.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For a WordPress site, these duties depend on the actual data flow, not on the presence of a privacy-policy page. Make an inventory that records, for each collection or service, what data is involved, why it is used, where it goes, and who is responsible for responding to requests. This inventory is a practical aid, not a legal safe harbor.

Rights and the response deadline

Utah’s consumer guidance describes rights to confirm whether personal data is being processed, access data, request deletion of data the consumer provided, receive a portable copy, and opt out of targeted advertising or the sale of personal data. It describes a 45-day response period for consumer requests.

There is also a current-law change to account for: a reproduction of the 2025 Utah Code states that an amendment adding a right to request correction of inaccuracies, taking account of the data and the purposes of processing, took effect on July 1, 2026. The Utah agency fact sheets predate that change. Because the amendment detail is based here on a secondary code reproduction rather than a directly accessible current legislature page, verify the current official code before designing a correction-request procedure.

How to map the data your WordPress site handles

WordPress core cannot identify every place a site collects or sends personal data. Start with the whole site and its connected services, rather than relying on what appears in the WordPress dashboard.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Site features: comments, registered accounts, contact or lead forms, ecommerce, and membership features.
  • Tracking and communications: analytics, advertising pixels, mailing lists, and other marketing tools.
  • Third-party content: embedded media and other services that receive information when a visitor loads or uses a page.
  • Infrastructure and vendors: hosting, backups, plugins, and external services that store, receive, or process personal data.

For each item, record the data categories, purpose, retention, recipients, and whether a vendor receives the data. Note whether the activity relates to sale, targeted advertising, or sensitive data, since those activities affect notice and opt-out duties. Assign an owner to the inventory and review it whenever you add or change a theme, plugin, tag, or vendor.

What WordPress privacy tools can and cannot do

Policy-page helper

WordPress provides a privacy-policy helper that offers starter text drawn from core and participating themes and plugins. An administrator must complete and review it so the resulting policy accurately describes the site. WordPress warns that the helper cannot discover every external service, such as a separate analytics or newsletter provider. Add disclosures based on your inventory rather than assuming the generated text is complete.

Export and erasure workflows

In the dashboard, go to Tools > Export Personal Data or Tools > Erase Personal Data to begin the corresponding workflow. The tools send an email validation request and require administrator action. They can help with information handled by WordPress and participating plugins, but they do not automatically reach every analytics, newsletter, advertising, embedded-media, or other external service. You may need to use a vendor’s own process or handle that part of the request manually.

Erasure is permanent for the data the tool deletes, but WordPress says it does not erase backups or archives. If an archived copy is restored, deleted data may need to be addressed again. The erasure workflow also does not automatically remove registered user accounts and profile data; administrators may need to handle those separately. Some information may need to be retained for legal or security reasons, so assess retention rather than treating every deletion request as an instruction to erase every record unconditionally.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How to set up a workable request process

  1. Choose an intake route. Tell consumers in the privacy notice how to submit a request and specify the right they want to exercise. Make sure the address or form is monitored.
  2. Assign responsibility. Name the person or role that reviews requests, verifies them as appropriate, and coordinates work across the site and vendors.
  3. Identify affected systems. Use the data inventory to determine whether the request touches WordPress core, a plugin, a user account, a backup, or an external service.
  4. Carry out the request across the data flow. Use WordPress’s export or erasure workflow where it covers the relevant data, and contact vendors or use their tools for information WordPress does not control.
  5. Track the outcome and deadline. Keep a request log with the date received, right requested, systems and vendors checked, actions taken, and response date. Utah agency guidance describes a 45-day response period.
  6. Update the inventory when something changes. Record new services, changed purposes, or altered data flows so future notices and requests reflect the site as it operates.

Do you need a cookie-consent plugin for Utah?

Not automatically. WordPress says its core software has no built-in consent tools, but the UCPA duties summarized by Utah’s agency guidance are tied to activities such as sale, targeted advertising, and processing sensitive data—not to every WordPress site merely because it uses cookies. Determine what the site actually does and which laws apply before deciding what controls are needed. A cookie banner by itself does not establish compliance.

If you are evaluating a privacy or consent plugin or service, compare its coverage against the site’s actual data flows. Check whether it can control the relevant third-party tags and embedded services, support the applicable opt-outs, handle preference changes accessibly, work with the site’s other plugins, and provide a request workflow or audit trail you can maintain. WordPress’s documentation confirms that plugins exist, but it does not establish that any particular product meets UCPA requirements.

Manual workflow or specialist tool?

Either approach still depends on a complete inventory and a process for services outside WordPress. The choice is about how to operate the work, not a shortcut around deciding whether the law applies.

Approach What it involves What to assess
Manual workflow with WordPress core Use the policy helper and export/erasure tools where applicable, then coordinate vendor dashboards and request handling yourself. Whether you can cover every site and vendor system, track deadlines and actions, and keep notices current as services change.
Specialist privacy or consent tool alongside core Add a plugin or service for capabilities such as consent preferences, tag control, request intake, or recordkeeping. Actual coverage of your services and opt-outs, accessibility, compatibility, ongoing administration, and current pricing. A tool’s presence alone does not establish compliance.

Consider a professional privacy review if the revenue or processing thresholds, exemptions, sensitive-data use, sale or targeted-advertising activities, or controller/processor roles are unclear. WordPress’s tools can support parts of the work, but they do not make the legal applicability decision or ensure external vendors have fulfilled a request.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.