Skip to content

Data, privacy and AI regulations, deadline by deadline.

Every phased date, from the official text.

Due next

Refresh delayed
See all deadlines
109
Regulations
326
Deadlines
55
Jurisdictions
10
Due in 90 days

Where the rules are

Shaded by how many tracked laws apply. Tap a place to open it.

FewerMore laws

27 jurisdictions with tracked laws. Tap one to open it.

Upcoming, month by month

September 20261 deadline

  1. ICO abolished; Information Commission takes over

    Sections 118-119 commence: office of Information Commissioner abolished and functions transferred to the Information Commission (Commencement No. 9 Regulations 2026).

    Takes effectin 6 daysSource

October 20262 deadlines

  1. PA 26-64 (SB 4) amendments take effect

    Prohibits controllers and third parties from selling precise geolocation data and enacts data broker and other consumer protection provisions.

    Takes effectin 7 daysSource
  2. Lords report stage scheduled

    House of Lords report stage scheduled (committee stage sat 1, 3 and 7 Sept 2026).

    Takes effectTentativein 32 daysSource

November 20262 deadlines

  1. CMMC 2.0

    Phase 2: Level 2 C3PAO certification

    Phase 2 begins one calendar year after Phase 1; applicable solicitations require CMMC Level 2 third-party (C3PAO) certification (32 CFR 170.3(e)(2)).

    Compliance deadlinein 47 daysSource
  2. Consent Manager registration rule in force (12 months)

    Rule 4 (registration and obligations of Consent Managers) comes into force one year after publication.

    Transitionin 50 daysSource

December 20266 deadlines

  1. Law in force

    Main obligations apply and the Personal Data Protection Agency begins supervision.

    Takes effectin 2 monthsSource
  2. EU AI Act

    New bans on sexual deepfakes and CSAM generation; Art 50(2) grace period ends

    New Art 5(1)(ba)/(bb) prohibitions on AI systems that generate non-consensual intimate imagery of identifiable persons or child sexual abuse material apply. Generative AI systems placed on the market before 2 Aug 2026 must comply with the Art 50(2) marking duty by this date (new Art 111(4)).

    Compliance deadlinein 2 monthsSource
  3. Transposition deadline; old PLD repealed

    Member States must transpose by 9 Dec 2026 (Art 22). Directive 85/374/EEC is repealed from that date but still applies to products placed on the market before it (Art 21).

    Transitionin 3 monthsSource
  4. Children's Online Privacy Code must be registered

    OAIC must develop and register the Children's Online Privacy Code within 24 months of Royal Assent.

    Compliance deadlinein 3 monthsSource
  5. Automated decision-making transparency applies

    Privacy policies must disclose the kinds of personal information used in substantially automated decisions that significantly affect individuals (24 months after assent).

    Compliance deadlinein 3 monthsSource
  6. Member States must provide EU Digital Identity Wallets

    Each Member State must provide at least one wallet within 24 months of the entry into force of the implementing acts under Arts 5a(23) and 5c(6) (Art 5a(1)).

    Compliance deadlinein 3 monthsSource

January 20271 deadline

  1. Large online platform and hosting platform duties

    Large online platforms and GenAI hosting platforms must meet the provenance duties added by AB 853.

    Compliance deadlinein 3 monthsSource
Every deadline

Browse by region

Questions people ask

What are the EU AI Act deadlines?

Aug 1, 2024: AI Act enters into force. Feb 2, 2025: Prohibited practices and AI literacy apply. Aug 2, 2025: GPAI, governance, notified bodies and penalties apply. Jul 27, 2026: Digital Omnibus on AI enters into force. Aug 2, 2026: General application: transparency obligations, GPAI fines, most other rules. Dec 2, 2026: New bans on sexual deepfakes and CSAM generation; Art 50(2) grace period ends. Aug 2, 2027: Legacy GPAI models must comply; national AI sandboxes operational. Dec 2, 2027: High-risk obligations apply to Annex III systems. Aug 2, 2028: High-risk obligations apply to Annex I product-embedded systems. Aug 2, 2030: Public-authority high-risk systems must comply. Dec 31, 2030: Large-scale EU IT systems must comply.

Which state privacy laws take effect in 2027?

Taking effect in 2027: Alabama Personal Data Protection Act (APDPA) (Alabama) on May 1, 2027; Colorado AI Act (Colorado) on Jan 1, 2027; Delaware Personal Data Privacy Act (DPDPA) (Delaware) on Jan 1, 2027; Louisiana Data Privacy Act (Louisiana) on Jan 1, 2027; New Hampshire Privacy Act (New Hampshire) on Jan 1, 2027; Oklahoma OKCDPA (Oklahoma) on Jan 1, 2027; Utah UCPA (Utah) on Jan 1, 2027.

When is the DORA compliance deadline?

DORA has applied since Jan 17, 2025. Apr 30, 2025: First registers of information submitted to the ESAs. Jul 8, 2025: TLPT regulatory technical standards enter into force. Nov 18, 2025: First critical ICT third-party providers designated.

What is the NIS2 deadline?

Jan 16, 2023: NIS2 enters into force. Oct 17, 2024: Transposition deadline. Oct 18, 2024: National NIS2 measures apply; NIS1 repealed. Nov 7, 2024: Implementing Regulation 2024/2690 enters into force.

How is this data privacy regulations tracker kept up to date?

Every regulation was researched from official sources (legislatures, regulators and official journals) and carries its source link and the date it was last verified. An agent scans one region of the world every night for new laws and moved dates. New finds are labelled Unverified until reviewed, and a changed date never replaces a verified one until a person approves it.

Is this legal advice?

No. It is a research aid. Always confirm obligations against the official text and with counsel.

When the rules change: new data, privacy and AI laws and deadlines, the next morning.