Utah, Iowa, and Indiana all trigger privacy-law coverage at the same 100,000 consumers processed in a calendar year, but Utah's Consumer Privacy Act is the only one of the three that also requires $25 million or more in annual revenue before the law applies at all, according to the enrolled text of Utah Senate Bill 227 and Iowa's codified Consumer Data Protection Act. That single difference means a mid-size data broker or ad-tech firm can be squarely inside Iowa's and Indiana's scope while sitting outside Utah's, even while processing identical volumes of personal data in each state.
Figure 1: Only Utah requires a dollar-revenue floor before its privacy law applies. Source: Utah S.B. 227 (13-61-102), Iowa Code 715D.2.
Does the same consumer count trigger all three laws?
Yes. Utah, Iowa, and Indiana each pull a controller into scope once it controls or processes personal data of 100,000 or more residents during a calendar year, or, as an alternate path, 25,000 or more residents combined with deriving more than 50% of gross revenue from selling personal data. The wording is close to identical across all three statutes because Iowa and Indiana's laws were both drafted after Utah's and reused its threshold language almost verbatim.
The difference is what else has to be true. Utah Code 13-61-102 requires a controller to clear the consumer-count test and have annual revenue of $25,000,000 or more. Iowa Code 715D.2 and Indiana's Consumer Data Protection Act impose no such revenue floor: hitting the consumer-count threshold is enough on its own. A regional data broker with $8 million in annual revenue but a large consumer database would be regulated in Iowa and Indiana while falling outside Utah's law entirely. Florida takes the revenue test to the opposite extreme: its Digital Bill of Rights only reaches businesses over $1 billion in revenue, a threshold so high that Utah's $25 million floor looks broad by comparison.
Figure 2: Utah's extra revenue test is the only branch that can exempt an otherwise-covered business. Source: Utah Code 13-61-102, Iowa Code 715D.2, Indiana Consumer Data Protection Act applicability provisions.
A privacy policy generator that tracks state-by-state thresholds is the fastest way to check whether a specific consumer count and revenue figure actually crosses these lines, since the same data footprint can be in scope in two states and out of scope in the third.
How long is the cure period before an attorney general can sue?
Iowa gives a business the longest runway of the three: a full 90 days to fix a noticed violation before the attorney general may initiate an action, per Iowa Code 715D.8. Utah and Indiana both give 30 days, a full cure-period cycle shorter than Iowa's window.
None of the three cure periods currently carries a sunset date in the statutory text reviewed for this post, unlike a handful of other state privacy laws that phased their cure period out after an initial grace window. In all three states, curing the violation and providing a written statement that it will not recur closes out the matter without a fine, provided the business does not repeat the violation afterward.
Figure 3: Iowa's cure period runs three times longer than Utah's or Indiana's. Source: Iowa Code 715D.8, Utah Code 13-61-402.
What happens if a business does not cure the violation?
If a controller or processor fails to cure a noticed violation, or breaches its written statement that a cured violation will not recur, the attorney general can bring a civil action. All three states cap the penalty at the same figure: $7,500 per violation, per Utah Code 13-61-402, Iowa Code 715D.8, and Indiana's Consumer Data Protection Act enforcement provisions. Utah's statute also allows the attorney general to recover a consumer's actual damages on top of the per-violation penalty.
None of the three states grants consumers a private right of action. Enforcement runs exclusively through each state's attorney general, and in Utah's case, through the Division of Consumer Protection, which fields consumer complaints and refers substantiated cases to the attorney general's office. That is a narrower path than Washington takes for health data specifically: the Washington My Health My Data Act carries its own private right of action for a category of sensitive information none of these three general-purpose laws singles out the same way.
| Feature | Utah | Iowa | Indiana |
|---|---|---|---|
| Consumer threshold | 100,000, or 25,000 + 50% revenue from data sales | 100,000, or 25,000 + 50% revenue from data sales | 100,000, or 25,000 + 50% revenue from data sales |
| Revenue floor | $25,000,000 annual revenue required | None | None |
| Cure period | 30 days | 90 days | 30 days |
| Civil penalty cap | $7,500 per violation | $7,500 per violation | $7,500 per violation |
| Private right of action | No | No | No |
| Effective date | December 31, 2023 | January 1, 2025 | January 1, 2026 |
Sources: Utah S.B. 227 (Utah Code 13-61-101 to 13-61-404), Iowa Code Chapter 715D, Indiana Consumer Data Protection Act as summarized by Securiti's ICDPA compliance guide (2026).
When did each law actually take effect?
Utah moved first, with the Utah Consumer Privacy Act taking effect December 31, 2023, roughly a year after Virginia became the second state with a comprehensive privacy law behind California. Iowa followed just over a year later, on January 1, 2025. Indiana came last, starting enforcement on January 1, 2026, the same week two other states, Kentucky and Rhode Island, also joined the list of states with an active comprehensive privacy law.
Figure 4: Utah, Iowa, and Indiana staggered their start dates across three separate years. Source: Utah S.B. 227 effective-date clause, Iowa Code 715D history notes, US state privacy law tracker.
The staggered timing matters for compliance planning more than the thresholds do. A business that only checked Utah's requirements in 2024 could have missed that Iowa's law was already live, and could still be catching up now that Indiana's is too.
How do Utah, Iowa, and Indiana compare on overall reach?
Plotting applicability breadth against cure-period length shows why "Virginia-model" is a loose label rather than one identical rulebook. Utah sits in the narrower, shorter-grace corner because its revenue floor exempts more businesses while still giving them only 30 days to fix a problem. Iowa sits in the broader, longer-grace corner: no revenue floor, but three times the cure window. Indiana splits the difference on paper, matching Iowa's broad reach but Utah's short cure period.
Figure 5: Indiana pairs Iowa's broad consumer-only test with Utah's shorter cure period. Source: applicability and cure-period data compiled above.
None of the three states lands in the narrow-reach, long-grace-period quadrant, and that gap is not a coincidence. Iowa's drafters paired a broader consumer-only test with a longer cure window on purpose, treating the extra 60 days as a release valve for the businesses its broader threshold pulls in that Utah's revenue floor would have excluded. Indiana's legislature took the opposite trade: it kept Iowa's broad reach but declined to extend the cure period to match, leaving newly-covered Indiana businesses with the same 30-day clock Utah gives its narrower, higher-revenue population. A compliance team tracking only Utah's rules and assuming Iowa or Indiana will be similarly forgiving on timing would be working from the wrong assumption in both states.
That difference in reach is the one worth checking first, before cure periods or penalty amounts even come into play, because it decides whether a law applies at all.
The revenue floor is the cleanest single marker of which model a business is dealing with: if a state's privacy law asks about revenue at all before asking about consumer counts, that state is following Utah's variant, not Iowa's or Indiana's.
The Bottom Line
Utah, Iowa, and Indiana all use the same 100,000-consumer entry point, so a business already tracking one of these laws is most of the way to tracking all three. The parts that actually differ are Utah's added $25 million revenue floor, which can exempt a smaller high-volume data business from Utah's law while leaving it fully covered in Iowa and Indiana, and the cure period, where Iowa's 90 days gives three times the runway that Utah and Indiana provide. Penalties, private-right-of-action status, and the AG-only enforcement model are otherwise identical across all three, matching the pattern 19 of the 20 states with a comprehensive privacy law already in effect follow nationally. A business meeting any one of these three states' thresholds should assume it needs a policy that discloses the same rights, and check the revenue and cure-period columns above before assuming coverage transfers automatically between states.
Frequently Asked Questions
Do Utah, Iowa, and Indiana's privacy laws apply to the same size of business? Not quite. All three apply once a business controls or processes personal data of 100,000 or more residents a year, but Utah adds a second requirement on top of that: at least $25 million in annual revenue. Iowa and Indiana have no revenue floor at all, so a small but high-data-volume company can fall under their laws while staying outside Utah's.
How long is the cure period before an attorney general can sue? Iowa gives a controller or processor 90 days to fix a noticed violation before the attorney general can file suit, per Iowa Code 715D.8. Utah and Indiana both give 30 days, per Utah Code 13-61-402 and Indiana's Consumer Data Protection Act.
Can consumers sue directly under these laws? No. None of the three laws creates a private right of action. Utah Code 13-61-305 states this explicitly, as does Iowa Code 715D.8, and Indiana follows the same model. Enforcement in all three states runs exclusively through the state attorney general's office.
When did or will each law take effect? Utah's Consumer Privacy Act took effect December 31, 2023. Iowa's Consumer Data Protection Act took effect January 1, 2025. Indiana's Consumer Data Protection Act took effect January 1, 2026, more than two years after Utah started enforcement.
Where the Numbers Come From
- Utah State Legislature. (2022). "S.B. 227, Consumer Privacy Act, Enrolled Copy." Applicability thresholds at 13-61-102, enforcement at 13-61-401 to 13-61-404, effective date December 31, 2023.
- Iowa Legislature. "Iowa Code Chapter 715D, Consumer Data Protections." Scope and exemptions at 715D.2, enforcement and penalties at 715D.8, enacted 2023 Acts, chapter 17.
- Securiti. (2026). "Indiana Consumer Data Protection Act Compliance Guide." Effective date January 1, 2026, 100,000/25,000-consumer thresholds, 30-day cure period, $7,500 per-violation penalty cap.
- Securiti. (2026). "Iowa Consumer Data Protection Act Compliance Guide." Effective date January 1, 2025, corroborating Iowa Code 715D's own scope and enforcement text.
- IAPP. "US State Privacy Legislation Tracker." 20 states with a comprehensive privacy law in effect as of January 2026, only California with a private right of action.
Note: All figures verified as of August 2026. Indiana's thresholds and enforcement details are sourced from a compliance-tracking summary rather than directly from Indiana's codified statute text; readers relying on this post for compliance decisions should confirm against Indiana Code Title 24, Article 4.9 directly. Effective dates and civil penalty caps are refreshed at least twice a year as each state's attorney general publishes new guidance.