Data, privacy and AI regulations, deadline by deadline.
Every phased date, from the official text.
Due next
Refresh delayed- UK DUAAData (Use and Access) ActICO abolished; Information Commission takes overin 6d
- CTDPAConnecticut Data Privacy Act (CTDPA)PA 26-64 (SB 4) amendments take effectin 7d
- CMMC 2.0CMMC 2.0Phase 2: Level 2 C3PAO certificationin 47d
- India DPDPIndia DPDP ActConsent Manager registration rule in force (12 months)in 50d
- Chile PDPLChile Personal Data Protection Law (Ley 21.719)Law in forcein 2mo
Where the rules are
Shaded by how many tracked laws apply. Tap a place to open it.
27 jurisdictions with tracked laws. Tap one to open it.
Upcoming, month by month
September 20261 deadline
ICO abolished; Information Commission takes over
Sections 118-119 commence: office of Information Commissioner abolished and functions transferred to the Information Commission (Commencement No. 9 Regulations 2026).
October 20262 deadlines
PA 26-64 (SB 4) amendments take effect
Prohibits controllers and third parties from selling precise geolocation data and enacts data broker and other consumer protection provisions.
Lords report stage scheduled
House of Lords report stage scheduled (committee stage sat 1, 3 and 7 Sept 2026).
November 20262 deadlines
Consent Manager registration rule in force (12 months)
Rule 4 (registration and obligations of Consent Managers) comes into force one year after publication.
December 20266 deadlines
Law in force
Main obligations apply and the Personal Data Protection Agency begins supervision.
- EU AI ActEuropean Union
New bans on sexual deepfakes and CSAM generation; Art 50(2) grace period ends
New Art 5(1)(ba)/(bb) prohibitions on AI systems that generate non-consensual intimate imagery of identifiable persons or child sexual abuse material apply. Generative AI systems placed on the market before 2 Aug 2026 must comply with the Art 50(2) marking duty by this date (new Art 111(4)).
- Product Liability DirectiveEuropean Union
Transposition deadline; old PLD repealed
Member States must transpose by 9 Dec 2026 (Art 22). Directive 85/374/EEC is repealed from that date but still applies to products placed on the market before it (Art 21).
Children's Online Privacy Code must be registered
OAIC must develop and register the Children's Online Privacy Code within 24 months of Royal Assent.
Automated decision-making transparency applies
Privacy policies must disclose the kinds of personal information used in substantially automated decisions that significantly affect individuals (24 months after assent).
- eIDAS 2 / EU Digital Identity WalletEuropean Union
Member States must provide EU Digital Identity Wallets
Each Member State must provide at least one wallet within 24 months of the entry into force of the implementing acts under Arts 5a(23) and 5c(6) (Art 5a(1)).
January 20271 deadline
Large online platform and hosting platform duties
Large online platforms and GenAI hosting platforms must meet the provenance duties added by AB 853.
Add to calendar
Browse by region
EU
15Next: EU AI Act, Dec 2, 2026
US Federal
12Next: CMMC 2.0, Nov 10, 2026
US States
38Next: Connecticut Data Privacy Act (CTDPA), Oct 1, 2026
UK and Europe
6Next: Data (Use and Access) Act, Sep 30, 2026
APAC
23Next: India DPDP Act, Nov 13, 2026
Americas
9Next: Chile Personal Data Protection Law (Ley 21.719), Dec 1, 2026
Middle East and Africa
6Questions people ask
What are the EU AI Act deadlines?
Aug 1, 2024: AI Act enters into force. Feb 2, 2025: Prohibited practices and AI literacy apply. Aug 2, 2025: GPAI, governance, notified bodies and penalties apply. Jul 27, 2026: Digital Omnibus on AI enters into force. Aug 2, 2026: General application: transparency obligations, GPAI fines, most other rules. Dec 2, 2026: New bans on sexual deepfakes and CSAM generation; Art 50(2) grace period ends. Aug 2, 2027: Legacy GPAI models must comply; national AI sandboxes operational. Dec 2, 2027: High-risk obligations apply to Annex III systems. Aug 2, 2028: High-risk obligations apply to Annex I product-embedded systems. Aug 2, 2030: Public-authority high-risk systems must comply. Dec 31, 2030: Large-scale EU IT systems must comply.
Which state privacy laws take effect in 2027?
Taking effect in 2027: Alabama Personal Data Protection Act (APDPA) (Alabama) on May 1, 2027; Colorado AI Act (Colorado) on Jan 1, 2027; Delaware Personal Data Privacy Act (DPDPA) (Delaware) on Jan 1, 2027; Louisiana Data Privacy Act (Louisiana) on Jan 1, 2027; New Hampshire Privacy Act (New Hampshire) on Jan 1, 2027; Oklahoma OKCDPA (Oklahoma) on Jan 1, 2027; Utah UCPA (Utah) on Jan 1, 2027.
When is the DORA compliance deadline?
DORA has applied since Jan 17, 2025. Apr 30, 2025: First registers of information submitted to the ESAs. Jul 8, 2025: TLPT regulatory technical standards enter into force. Nov 18, 2025: First critical ICT third-party providers designated.
What is the NIS2 deadline?
Jan 16, 2023: NIS2 enters into force. Oct 17, 2024: Transposition deadline. Oct 18, 2024: National NIS2 measures apply; NIS1 repealed. Nov 7, 2024: Implementing Regulation 2024/2690 enters into force.
How is this data privacy regulations tracker kept up to date?
Every regulation was researched from official sources (legislatures, regulators and official journals) and carries its source link and the date it was last verified. An agent scans one region of the world every night for new laws and moved dates. New finds are labelled Unverified until reviewed, and a changed date never replaces a verified one until a person approves it.
Is this legal advice?
No. It is a research aid. Always confirm obligations against the official text and with counsel.