Utah Becomes the Second U.S. State to Establish Affirmative Defenses for Data Breach
Privacy, Cyber & AI Decoded Alert | 1 min read
Mar 22, 2021
In enacting the Cybersecurity Affirmative Defense Act, HB80, (Act) on March 11, 2021, Utah became the second state in the U.S. to create affirmative defenses for “persons” to certain causes of action arising out of a breach of system security.[1]
“Persons” is defined to include individuals, associations, corporations, partnerships, and other business entities.
The Act provides protection to persons that create, maintain, and reasonably comply with industry-recognized cybersecurity regulations, like the NIST, ISO 2700, and the HIPAA Security Rule, among others identified in the Act. The written cybersecurity program must provide administrative, technical, and physical safeguards to protect personal information.
The Act establishes the following three (3) affirmative defenses to tort-based claims brought under Utah law in a Utah state court:
- A person that creates, maintains, and reasonably compiles with written industry-recognized cybersecurity regulations that were in place at the time of the breach has an affirmative defense to a claim that the person failed to implement reasonable information security controls that resulted in the breach;
- A person that creates, maintains, and reasonably complies with their program and also had in place protocols for responding to a breach of system security at the time of the breach has an affirmative defense to a claim that the person failed to appropriately respond to a breach of a security system; and
- A person that creates, maintains, and reasonably compiles with their program and also had in place protocols for notifying an individual about a breach at the time of the breach has an affirmative defense to a claim that the person failed to appropriately notify an individual whose personal information was compromised in a breach of a security system.
The affirmative defenses established in the Act are generally not available in circumstances where the person had notice of a threat or hazard.
The Act expressly states that it does not create a private right of action for failing to comply with its provisions.
[1] Ohio was the first state to establish affirmative defenses with the OH Data Protection Act in 2018.
Related Capabilities
Featured Insights

Event
Mar 3 – 5, 2026
25th Annual Legal Malpractice & Risk Management (LMRM) Conference

Press Release
Feb 13, 2026
Hinshaw Team Wins Appeal in Criminal Indictment of Waukegan City Clerk Janet Kilkelly

Press Release
Feb 10, 2026
Hinshaw Trial Team Secures $0 Defense Verdict in $15 Million Auto Accident Trial

Press Release
Feb 4, 2026
Hinshaw Celebrates 17 Consecutive Years of Being Named an Equality 100 Award Winner

Press Release
Feb 5, 2026
Hinshaw Legal Team Secures Directed Verdict in Florida Equine Fraud Case

Press Release
Feb 2, 2026
Hinshaw Welcomes 16 Attorneys in Seven Offices and Announces Opening of a Cleveland Office

Press Release
Jan 20, 2026
Hinshaw Attorneys Named to the LCLD 2026 Fellowship Class and 2026 Pathfinder Program

Press Release
Jan 15, 2026
Hinshaw Client Secures a Complete Jury Verdict in Fraudulent Misrepresentation Horse Sale Case

Press Release
Jan 6, 2026
Hinshaw Adds Four-Member Consumer Financial Services Team in DC and Florida



