{"regulations":[{"id":"us-al-apdpa","name":"Alabama Personal Data Protection Act (HB 351, 2026 Regular Session)","shortName":"Alabama Personal Data Protection Act (APDPA)","jurisdiction":"us-al","jurisdictionName":"Alabama","region":"us-states","topics":["privacy"],"status":"enacted","citation":"HB 351 (2026 RS), Act 2026-552","enactedDate":"2026-04-17","effectiveDate":"2027-05-01","summary":"Alabama's comprehensive privacy law, enacted April 2026, grants rights to confirm, correct, delete, port and opt out of targeted advertising, sale and profiling. Unusually, it does not require data protection assessments, generally excludes analytics and certain marketing disclosures from 'sale', and broadly exempts small businesses that don't sell data.","appliesTo":"Persons doing business in Alabama or targeting residents that control or process personal data of more than 25,000 consumers (excluding payment-only data), or derive more than 25% of gross revenue from the sale of personal data regardless of volume. Exempts businesses with fewer than 500 employees and nonprofits with fewer than 100 employees that do not sell personal data.","penalties":"Civil penalty up to $15,000 per violation, only after the controller fails to correct within the permanent 45-day notice-and-cure period; injunctive relief. No private right of action.","enforcer":"Alabama Attorney General (exclusive)","sourceUrl":"https://alison.legislature.state.al.us/files/pdf/SearchableInstruments/2026RS/HB351-enr.pdf","extraSources":["https://www.wilmerhale.com/en/insights/blogs/wilmerhale-privacy-and-cybersecurity-law/20260422-alabama-enacts-nations-twenty-first-state-comprehensive-privacy-law","https://www.venable.com/insights/publications/2026/07/2026-mid-year-state-privacy-law-update"],"notes":"Fact-check 2026-09-22: the official ALISON record lists HB 351 as Act 2026-552, delivered to the Governor 8 Apr 2026 and 'Enacted' 17 Apr 2026; enacted_date uses the official 17 Apr 2026 date (WilmerHale and Privacy Daily reported signing on 16 Apr 2026). Enrolled text Section 12: effective 1 May 2027. The 45-day cure period is permanent, so no cure-expiry deadline.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-24 02:56:54","deadlines":[{"id":161,"regulationId":"us-al-apdpa","date":"2027-05-01","title":"APDPA takes effect","description":"Consumer rights and controller/processor obligations apply (HB 351 section 12).","kind":"effective","sourceUrl":"https://alison.legislature.state.al.us/files/pdf/SearchableInstruments/2026RS/HB351-enr.pdf","tentative":false,"review":"verified"}]},{"id":"au-cyber-security-act","name":"Cyber Security Act 2024 (Cth) and Cyber Security (Ransomware Payment Reporting) Rules 2025","shortName":"Australia Cyber Security Act (ransomware reporting)","jurisdiction":"au","jurisdictionName":"Australia","region":"apac","topics":["cybersecurity","breach-notification"],"status":"in_force","citation":"Act No. 98, 2024","enactedDate":"2024-11-29","effectiveDate":"2024-11-30","summary":"Australia's first standalone cyber law: mandatory reporting of ransomware or cyber-extortion payments within 72 hours, security standards for consumer smart devices, 'limited use' protections for information shared with ASD and the National Cyber Security Coordinator, and a Cyber Incident Review Board. Ransomware payment reporting has applied since 30 May 2025.","appliesTo":"Ransomware reporting: entities carrying on business in Australia with annual turnover above AUD 3 million in the previous financial year (pro-rated for part years), plus responsible entities for critical infrastructure assets regardless of turnover, that make or have a ransomware payment made on their behalf.","penalties":"Failure to report a ransomware payment: civil penalty of 60 penalty units (AUD 19,800 at the rate cited by commentators).","enforcer":"Department of Home Affairs; reports go to the Australian Signals Directorate (ASD)","sourceUrl":"https://www.legislation.gov.au/C2024A00098/asmade","extraSources":["https://www.homeaffairs.gov.au/cyber-security-subsite/files/factsheet-ransomware-payment-reporting.pdf"],"notes":"Royal Assent was 29 Nov 2024 (from secondary sources); Part 1 commenced the next day. Commencement dates for the smart-device security standards were not verified here. Penalty unit values are indexed, and the AUD 19,800 figure uses the rate at commencement.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-24 02:56:54","deadlines":[{"id":2,"regulationId":"au-cyber-security-act","date":"2025-05-30","title":"Ransomware payment reporting starts","description":"Reporting business entities must report ransomware/cyber-extortion payments to ASD within 72 hours of payment.","kind":"effective","sourceUrl":"https://www.homeaffairs.gov.au/cyber-security-subsite/files/factsheet-ransomware-payment-reporting.pdf","tentative":false,"review":"verified"},{"id":3,"regulationId":"au-cyber-security-act","date":"2026-01-01","title":"Ransomware reporting moves to compliance phase","description":"The education-first phase (30 May-31 Dec 2025) ends; Home Affairs moves to a compliance and education approach for missed reports.","kind":"enforcement","sourceUrl":"https://www.homeaffairs.gov.au/cyber-security-subsite/files/factsheet-ransomware-payment-reporting.pdf","tentative":false,"review":"verified"}]},{"id":"au-privacy-act","name":"Privacy Act 1988 (Cth), as amended by the Privacy and Other Legislation Amendment Act 2024","shortName":"Australia Privacy Act","jurisdiction":"au","jurisdictionName":"Australia","region":"apac","topics":["privacy","children","breach-notification","ai"],"status":"amended","citation":"Privacy Act 1988 (Cth); Privacy and Other Legislation Amendment Act 2024 (No. 128, 2024)","enactedDate":"2024-12-10","effectiveDate":"2024-12-11","summary":"Australia's federal privacy law (13 Australian Privacy Principles, Notifiable Data Breaches scheme). The 2024 amendment adds a statutory tort for serious invasions of privacy, tiered civil penalties and infringement notices, a mandate for a Children's Online Privacy Code, clearer security duties, and privacy-policy transparency for substantially automated decisions from 10 December 2026. It also adds criminal doxxing offences.","appliesTo":"APP entities: Australian Government agencies and organizations with annual turnover above AUD 3 million, plus some smaller businesses (e.g. health service providers, data traders). The statutory tort applies to anyone, not only APP entities. The Children's Online Privacy Code will cover social media, relevant electronic and designated internet services likely to be accessed by children.","penalties":"Serious interference with privacy: for bodies corporate, the greater of AUD 50 million, 3x the benefit obtained, or 30% of adjusted turnover. New mid-tier civil penalty for interferences with privacy (up to AUD 3.3 million for bodies corporate) and infringement notices for administrative breaches. Statutory tort: court-awarded damages, with a cap on damages for non-economic loss.","enforcer":"Office of the Australian Information Commissioner (OAIC); courts (statutory tort)","sourceUrl":"https://www.legislation.gov.au/C2024A00128/asmade","extraSources":["https://www.oaic.gov.au/privacy/privacy-registers/privacy-codes/childrens-online-privacy-code","https://www.legislation.gov.au/C2024A00128/asmade/2024-12-10/text/original/pdf","https://ministers.ag.gov.au/media-centre/draft-childrens-online-privacy-code-released-31-03-2026"],"notes":"The OAIC released an exposure draft Privacy (Children's Online Privacy) Code 2026 for consultation from 31 Mar to 5 Jun 2026; it was not registered as of Aug 2026, and its commencement date for regulated entities is not yet set. 'Tranche 2' reforms (e.g. removing the small business exemption, a fair and reasonable test) are not yet legislated. The mid-tier and tort cap figures come from the Act and secondary summaries; check against the current indexed penalty unit value.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-24 02:56:54","deadlines":[{"id":4,"regulationId":"au-privacy-act","date":"2024-12-11","title":"Most POLA Act 2024 amendments commence","description":"Tiered penalties, infringement notices, OAIC powers, security and overseas-transfer clarifications and doxxing offences commence the day after Royal Assent.","kind":"effective","sourceUrl":"https://www.legislation.gov.au/C2024A00128/asmade","tentative":false,"review":"verified"},{"id":5,"regulationId":"au-privacy-act","date":"2025-06-10","title":"Statutory tort for serious invasions of privacy commences","description":"Individuals can sue for serious invasions of privacy (Schedule 2), 6 months after Royal Assent.","kind":"effective","sourceUrl":"https://www.legislation.gov.au/C2024A00128/asmade","tentative":false,"review":"verified"},{"id":6,"regulationId":"au-privacy-act","date":"2026-12-10","title":"Children's Online Privacy Code must be registered","description":"OAIC must develop and register the Children's Online Privacy Code within 24 months of Royal Assent.","kind":"compliance","sourceUrl":"https://www.oaic.gov.au/privacy/privacy-registers/privacy-codes/childrens-online-privacy-code","tentative":false,"review":"verified"},{"id":7,"regulationId":"au-privacy-act","date":"2026-12-10","title":"Automated decision-making transparency applies","description":"Privacy policies must disclose the kinds of personal information used in substantially automated decisions that significantly affect individuals (24 months after assent).","kind":"compliance","sourceUrl":"https://www.legislation.gov.au/C2024A00128/asmade","tentative":false,"review":"verified"}]},{"id":"au-social-media-min-age","name":"Online Safety Amendment (Social Media Minimum Age) Act 2024","shortName":"Australia Social Media Minimum Age","jurisdiction":"au","jurisdictionName":"Australia","region":"apac","topics":["children","online-safety"],"status":"in_force","citation":"Act No. 127, 2024 (amending the Online Safety Act 2021)","enactedDate":"2024-12-10","effectiveDate":"2025-12-10","summary":"Requires providers of age-restricted social media platforms to take reasonable steps to stop Australians under 16 from having accounts. Platforms may not rely only on government ID for age assurance, and must protect data collected for age checks and destroy it after use. eSafety has named platforms including Facebook, Instagram, Snapchat, TikTok, X, YouTube, Reddit, Threads, Twitch and Kick.","appliesTo":"Providers of 'age-restricted social media platforms' (services whose significant purpose is online social interaction, allowing users to link and post), subject to exclusions (e.g. messaging, gaming, education and health services).","penalties":"Up to 150,000 penalty units (AUD 49.5 million) for corporations failing to take reasonable steps. Separate penalties apply for misusing age-assurance data under the Privacy Act.","enforcer":"eSafety Commissioner (minimum age obligation); OAIC (privacy of age-assurance data)","sourceUrl":"https://www.legislation.gov.au/C2024A00127/asmade","extraSources":["https://www.esafety.gov.au/about-us/industry-regulation/social-media-age-restrictions","https://www.pm.gov.au/media/stronger-powers-and-double-penalties-world-leading-social-media-law"],"notes":"On 28 June 2026 the Government announced legislation to double the maximum penalty for systemic breaches to AUD 99 million and give eSafety stronger information-gathering powers; it is not yet enacted as of verification. eSafety is investigating five platforms.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-24 02:56:54","deadlines":[{"id":8,"regulationId":"au-social-media-min-age","date":"2025-12-10","title":"Social media minimum age obligation applies","description":"Age-restricted platforms must take reasonable steps to prevent under-16s from holding accounts.","kind":"effective","sourceUrl":"https://www.legislation.gov.au/C2024A00127/asmade","tentative":false,"review":"verified"}]},{"id":"br-ai-bill","name":"Projeto de Lei nº 2338/2023 (Brazilian AI Legal Framework)","shortName":"Brazil AI Bill (PL 2338/2023)","jurisdiction":"br","jurisdictionName":"Brazil","region":"americas","topics":["ai"],"status":"proposed","citation":"PL 2338/2023","enactedDate":"","effectiveDate":"","summary":"Risk-based AI framework inspired by the EU AI Act: prohibited (excessive-risk) uses, high-risk system obligations, algorithmic impact assessments, rights for affected persons and copyright remuneration provisions, coordinated by a national AI regulation system (SIA) led by the ANPD.","appliesTo":"Developers, distributors and deployers of AI systems in Brazil (per Senate text).","penalties":"Senate text: fines up to BRL 50 million per infraction or up to 2% of group revenue in Brazil; suspension of development or supply.","enforcer":"ANPD as coordinator of the National AI Regulation and Governance System (SIA) (proposed)","sourceUrl":"https://www25.senado.leg.br/web/atividade/materias/-/materia/157233","extraSources":["https://www.camara.leg.br/proposicoesWeb/fichadetramitacao?idProposicao=2487262"],"notes":"As of September 2026 the Chamber's tramitação page shows the bill still awaiting the rapporteur's opinion in the Special Commission; a plenary vote reported for late May 2026 did not occur. If the Chamber amends it, the bill returns to the Senate. Penalty figures are from the Senate-approved text as reported, not re-verified.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-24 02:56:54","deadlines":[{"id":9,"regulationId":"br-ai-bill","date":"2024-12-10","title":"Approved by the Federal Senate","description":"Senate approves the consolidated text and sends it to the Chamber of Deputies.","kind":"effective","sourceUrl":"https://www25.senado.leg.br/web/atividade/materias/-/materia/157233","tentative":false,"review":"verified"}]},{"id":"br-eca-digital","name":"Estatuto Digital da Criança e do Adolescente (Law No. 15.211/2025)","shortName":"Brazil ECA Digital","jurisdiction":"br","jurisdictionName":"Brazil","region":"americas","topics":["children","online-safety","privacy"],"status":"in_force","citation":"Lei nº 15.211/2025","enactedDate":"2025-09-17","effectiveDate":"2026-03-17","summary":"Requires digital products and services likely to be accessed by children and adolescents to apply protection by design and default, reliable age verification, parental supervision tools, links between under-16 accounts and guardians, and swift removal of harmful content; bans profiling-based advertising to children and loot boxes in games for minors.","appliesTo":"Providers of information technology products or services directed at, or likely to be accessed by, children and adolescents in Brazil: social networks, games, app stores, operating systems, streaming and similar services, regardless of location.","penalties":"Warning; simple fine up to 10% of the economic group's revenue in Brazil in the last fiscal year or, absent revenue, BRL 10 to BRL 1,000 per registered user, capped at BRL 50 million per infraction; temporary suspension or prohibition of activities (judicial).","enforcer":"Autonomous administrative authority for children's digital rights (ANPD designated); courts for suspension/prohibition","sourceUrl":"https://www.planalto.gov.br/ccivil_03/_ato2023-2026/2025/lei/L15211.htm","extraSources":["https://www.machadomeyer.com.br/pt/inteligencia-juridica/publicacoes-ij/direito-digital/estatuto-digital-da-crianca-e-do-adolescente-lei-n-15-211-2025-entra-em-vigor-em-17-de-marco-de-2026"],"notes":"Published 18 Sept 2025. Designation of ANPD as the enforcing authority is from secondary reporting.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-24 02:56:54","deadlines":[{"id":10,"regulationId":"br-eca-digital","date":"2026-03-17","title":"ECA Digital in force","description":"Art. 41-A (as set by Law 15.352/2026, following MP 1.319/2025) fixes entry into force on 17 March 2026.","kind":"effective","sourceUrl":"https://www.planalto.gov.br/ccivil_03/_ato2023-2026/2025/lei/L15211.htm","tentative":false,"review":"verified"}]},{"id":"br-lgpd","name":"Lei Geral de Proteção de Dados Pessoais (Law No. 13.709/2018)","shortName":"Brazil LGPD","jurisdiction":"br","jurisdictionName":"Brazil","region":"americas","topics":["privacy","breach-notification","data-residency"],"status":"in_force","citation":"Lei nº 13.709, de 14 de agosto de 2018","enactedDate":"2018-08-14","effectiveDate":"2020-09-18","summary":"Brazil's GDPR-style general data protection law: ten legal bases, data subject rights, DPO (encarregado), incident reporting and international transfer rules. ANPD's Resolution CD/ANPD 19/2024 set the international transfer regime and mandatory standard contractual clauses.","appliesTo":"Any processing carried out in Brazil, targeting individuals in Brazil, or of data collected in Brazil, regardless of the controller's location. Simplified rules for small-scale agents (Resolution CD/ANPD 2/2022).","penalties":"Fines up to 2% of the company's/group's revenue in Brazil in the prior fiscal year, capped at BRL 50 million per infraction; daily fines; publicisation; blocking or deletion of data; suspension of processing.","enforcer":"Autoridade Nacional de Proteção de Dados (ANPD)","sourceUrl":"https://www.planalto.gov.br/ccivil_03/_ato2015-2018/2018/lei/l13709.htm","extraSources":["https://www.in.gov.br/en/web/dou/-/resolucao-cd/anpd-n-19-de-23-de-agosto-de-2024-580095396","https://www.gov.br/anpd/"],"notes":"In 2025 the ANPD was restructured into a regulatory agency (MP 1.317/2025); not separately verified.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-24 02:56:54","deadlines":[{"id":11,"regulationId":"br-lgpd","date":"2020-09-18","title":"LGPD in force","description":"Main LGPD provisions take effect.","kind":"effective","sourceUrl":"https://www.planalto.gov.br/ccivil_03/_ato2015-2018/2018/lei/l13709.htm","tentative":false,"review":"verified"},{"id":12,"regulationId":"br-lgpd","date":"2021-08-01","title":"ANPD sanctions enforceable","description":"Administrative sanctions (Arts. 52-54) become applicable per Law 14.010/2020.","kind":"enforcement","sourceUrl":"https://www.planalto.gov.br/ccivil_03/_ato2015-2018/2018/lei/l13709.htm","tentative":false,"review":"verified"},{"id":13,"regulationId":"br-lgpd","date":"2024-08-23","title":"International transfer regulation published","description":"Resolution CD/ANPD 19/2024 on international transfers and standard contractual clauses published and in force.","kind":"effective","sourceUrl":"https://www.in.gov.br/en/web/dou/-/resolucao-cd/anpd-n-19-de-23-de-agosto-de-2024-580095396","tentative":false,"review":"verified"},{"id":14,"regulationId":"br-lgpd","date":"2025-08-23","title":"Deadline to adopt ANPD standard contractual clauses","description":"Agents relying on contractual clauses for international transfers must incorporate the ANPD-approved SCCs into their contracts within 12 months of publication.","kind":"compliance","sourceUrl":"https://www.in.gov.br/en/web/dou/-/resolucao-cd/anpd-n-19-de-23-de-agosto-de-2024-580095396","tentative":false,"review":"verified"}]},{"id":"us-ca-ccpa","name":"California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 (Cal. Civ. Code 1798.100 et seq.) and CPPA regulations (Cal. Code Regs. tit. 11, 7000 et seq.)","shortName":"CCPA / CPRA","jurisdiction":"us-ca","jurisdictionName":"California","region":"us-states","topics":["privacy","ai","cybersecurity","children"],"status":"amended","citation":"Cal. Civ. Code 1798.100-1798.199.100 (AB 375, Stats. 2018 ch. 55; Proposition 24 (2020)); 11 CCR 7000 et seq.","enactedDate":"2018-06-28","effectiveDate":"2020-01-01","summary":"Gives California residents (including employees and B2B contacts) rights to know, delete, correct, and opt out of sale/sharing of personal information and to limit use of sensitive personal information. CPPA regulations approved Sept 22, 2025 (effective Jan 1, 2026) add automated decisionmaking technology (ADMT) rights, mandatory risk assessments with submissions to the agency, and annual independent cybersecurity audits. AB 566 (2025) requires browsers to offer an opt-out preference signal from Jan 1, 2027.","appliesTo":"For-profit businesses doing business in California that meet any of: annual gross revenue over $25M as CPI-adjusted ($26,625,000 from Jan 1, 2025); buy, sell or share personal information of 100,000+ consumers or households; or derive 50%+ of annual revenue from selling or sharing personal information. Cybersecurity audits apply to businesses deriving 50%+ revenue from selling/sharing PI, or over the revenue threshold and processing PI of 250,000+ consumers/households or sensitive PI of 50,000+ consumers.","penalties":"Administrative fines/civil penalties up to $2,663 per violation and $7,988 per intentional violation or violation involving minors under 16 (CPI-adjusted from Jan 1, 2025; statutory base $2,500/$7,500). Private right of action for data breaches: $107-$799 per consumer per incident or actual damages. No statutory cure period (the 30-day cure was removed by the CPRA; CPPA may consider cure discretionarily).","enforcer":"California Privacy Protection Agency (CalPrivacy) and California Attorney General","sourceUrl":"https://cppa.ca.gov/regulations/ccpa_updates.html","extraSources":["https://cppa.ca.gov/regulations/pdf/ccpa_updates_cyber_risk_admt_appr_text.pdf","https://cppa.ca.gov/regulations/cpi_adjustment.html","https://leginfo.legislature.ca.gov/faces/billStatusClient.xhtml?bill_id=202520260AB566","https://cppa.ca.gov/regulations/pdf/ccpa_statute_eff_20260101.pdf","https://www.alston.com/en/insights/publications/2026/08/california-privacy-opt-out-signals-data-brokers"],"notes":"Monetary thresholds are CPI-adjusted every odd year; a January 2027 adjustment is expected but not yet published as of verification. CPPA rebranded as CalPrivacy. Additional 2025 bills (e.g. SB 361 data broker disclosures) and further CPPA rulemaking (reported for late 2026/2027 on notices and employee data) are not captured as deadlines. Risk assessment submission deadline is April 1, 2028 per 11 CCR 7157 (not April 21).","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-24 02:56:54","deadlines":[{"id":164,"regulationId":"us-ca-ccpa","date":"2020-01-01","title":"CCPA takes effect","description":"Original CCPA consumer rights and business obligations take effect.","kind":"effective","sourceUrl":"https://cppa.ca.gov/regulations/pdf/ccpa_statute_eff_20260101.pdf","tentative":false,"review":"verified"},{"id":165,"regulationId":"us-ca-ccpa","date":"2023-01-01","title":"CPRA amendments operative","description":"CPRA amendments (correction right, sensitive PI limits, sharing opt-out, employee/B2B data coverage) become operative.","kind":"effective","sourceUrl":"https://cppa.ca.gov/regulations/pdf/ccpa_statute_eff_20260101.pdf","tentative":false,"review":"verified"},{"id":166,"regulationId":"us-ca-ccpa","date":"2025-01-01","title":"CPI adjustment of thresholds and fines","description":"Revenue threshold rises to $26,625,000 and fines to $2,663 / $7,988 per violation.","kind":"transition","sourceUrl":"https://cppa.ca.gov/regulations/cpi_adjustment.html","tentative":false,"review":"verified"},{"id":167,"regulationId":"us-ca-ccpa","date":"2025-09-22","title":"ADMT, risk assessment and cybersecurity audit regulations approved","description":"OAL approves the CCPA Updates, Cybersecurity Audit, Risk Assessment, ADMT and Insurance regulations and files them with the Secretary of State.","kind":"transition","sourceUrl":"https://cppa.ca.gov/regulations/ccpa_updates.html","tentative":false,"review":"verified"},{"id":168,"regulationId":"us-ca-ccpa","date":"2026-01-01","title":"New CCPA regulations take effect","description":"ADMT, risk assessment, cybersecurity audit and updated CCPA regulations become effective; risk assessments required for new high-risk processing.","kind":"effective","sourceUrl":"https://cppa.ca.gov/regulations/ccpa_updates.html","tentative":false,"review":"verified"},{"id":169,"regulationId":"us-ca-ccpa","date":"2027-01-01","title":"ADMT requirements compliance date","description":"Businesses using ADMT for significant decisions must comply with Article 11 (pre-use notice, opt-out, access rights) by this date (11 CCR 7200(b)).","kind":"compliance","sourceUrl":"https://cppa.ca.gov/regulations/pdf/ccpa_updates_cyber_risk_admt_appr_text.pdf","tentative":false,"review":"verified"},{"id":170,"regulationId":"us-ca-ccpa","date":"2027-01-01","title":"Browsers must support opt-out preference signal (AB 566)","description":"Businesses that develop or maintain a browser must include consumer-configurable functionality to send an opt-out preference signal (Civ. Code 1798.136, operative Jan 1, 2027).","kind":"compliance","sourceUrl":"https://leginfo.legislature.ca.gov/faces/billStatusClient.xhtml?bill_id=202520260AB566","tentative":false,"review":"verified"},{"id":171,"regulationId":"us-ca-ccpa","date":"2027-12-31","title":"Risk assessments for pre-existing processing due","description":"Risk assessments must be completed and documented for high-risk processing that began before Jan 1, 2026 and continues after (11 CCR 7155(b)).","kind":"compliance","sourceUrl":"https://cppa.ca.gov/regulations/pdf/ccpa_updates_cyber_risk_admt_appr_text.pdf","tentative":false,"review":"verified"},{"id":172,"regulationId":"us-ca-ccpa","date":"2028-04-01","title":"First risk assessment submission to CPPA","description":"Businesses must submit required risk assessment information and attestation for assessments conducted in 2026 and 2027 (11 CCR 7157(a)(1)); annually by April 1 thereafter.","kind":"reporting","sourceUrl":"https://cppa.ca.gov/regulations/pdf/ccpa_updates_cyber_risk_admt_appr_text.pdf","tentative":false,"review":"verified"},{"id":173,"regulationId":"us-ca-ccpa","date":"2028-04-01","title":"Cybersecurity audit due: revenue over $100M","description":"First cybersecurity audit report (covering Jan 1, 2027 - Jan 1, 2028) and certification due for businesses with 2026 annual gross revenue over $100M (11 CCR 7121(a)(1)).","kind":"reporting","sourceUrl":"https://cppa.ca.gov/regulations/pdf/ccpa_updates_cyber_risk_admt_appr_text.pdf","tentative":false,"review":"verified"},{"id":174,"regulationId":"us-ca-ccpa","date":"2029-04-01","title":"Cybersecurity audit due: revenue $50M-$100M","description":"First cybersecurity audit report (covering 2028) due for businesses with 2027 annual gross revenue between $50M and $100M (11 CCR 7121(a)(2)).","kind":"reporting","sourceUrl":"https://cppa.ca.gov/regulations/pdf/ccpa_updates_cyber_risk_admt_appr_text.pdf","tentative":false,"review":"verified"},{"id":175,"regulationId":"us-ca-ccpa","date":"2030-04-01","title":"Cybersecurity audit due: revenue under $50M","description":"First cybersecurity audit report (covering 2029) due for covered businesses with 2028 annual gross revenue under $50M (11 CCR 7121(a)(3)); annual by April 1 thereafter.","kind":"reporting","sourceUrl":"https://cppa.ca.gov/regulations/pdf/ccpa_updates_cyber_risk_admt_appr_text.pdf","tentative":false,"review":"verified"}]},{"id":"us-circia","name":"Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA) and proposed implementing rule (6 CFR Part 226)","shortName":"CIRCIA","jurisdiction":"us","jurisdictionName":"United States (Federal)","region":"us-federal","topics":["cybersecurity","breach-notification"],"status":"enacted","citation":"6 U.S.C. 681-681g; Pub. L. 117-103, div. Y; NPRM 89 FR 23644 (Apr. 4, 2024), RIN 1670-AA04","enactedDate":"2022-03-15","effectiveDate":"","summary":"Directs CISA to require covered critical infrastructure entities to report covered cyber incidents within 72 hours of reasonably believing one occurred and ransom payments within 24 hours of payment, and to preserve related data. Reporting obligations begin only once CISA's final rule takes effect.","appliesTo":"As proposed: entities in any of the 16 critical infrastructure sectors that exceed the SBA small business size standard for their industry, or meet sector-based criteria (e.g. hospitals, certain IT and communications providers, water systems). CISA estimated about 316,244 covered entities.","penalties":"CISA may issue requests for information and subpoenas; failure to comply with a subpoena may be referred to DOJ for a civil action and contempt. False statements are subject to 18 U.S.C. 1001; federal contractors may face procurement actions including suspension or debarment.","enforcer":"Cybersecurity and Infrastructure Security Agency (CISA), DHS; DOJ for civil enforcement of subpoenas","sourceUrl":"https://www.federalregister.gov/documents/2024/04/04/2024-06526/cyber-incident-reporting-for-critical-infrastructure-act-circia-reporting-requirements","extraSources":["https://www.cisa.gov/topics/cyber-threats-and-advisories/information-sharing/circia","https://www.reginfo.gov/public/do/eAgendaViewRule?pubId=202510&RIN=1670-AA04","https://www.federalregister.gov/documents/2026/05/26/2026-10417/town-hall-meetings-to-provide-input-on-cyber-incident-reporting-for-critical-infrastructure-act","https://www.hunton.com/privacy-and-cybersecurity-law-blog/cisa-plans-to-finalize-cyber-incident-reporting-regulations-in-september-2026"],"notes":"Final rule not yet published as of 2026-09-22 (Federal Register search). CISA missed the statutory October 2025 deadline, then targeted May 2026, and the latest Unified Agenda lists the final rule for 09/2026 (month only). CISA held further town halls in 2026 (Federal Register notices of Feb. 13 and May 26, 2026) and has said it intends to streamline scope. Obligations will start on the final rule's effective date, expected to be well after publication.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-24 02:56:54","deadlines":[{"id":193,"regulationId":"us-circia","date":"2024-07-03","title":"NPRM comment period closed","description":"Extended comment period on the CIRCIA proposed rule closed.","kind":"transition","sourceUrl":"https://www.federalregister.gov/documents/2024/04/04/2024-06526/cyber-incident-reporting-for-critical-infrastructure-act-circia-reporting-requirements","tentative":false,"review":"verified"}]},{"id":"us-cmmc","name":"Cybersecurity Maturity Model Certification (CMMC) Program (32 CFR Part 170) and DFARS acquisition rule (48 CFR Parts 204, 212, 217, 252)","shortName":"CMMC 2.0","jurisdiction":"us","jurisdictionName":"United States (Federal)","region":"us-federal","topics":["cybersecurity"],"status":"in_force","citation":"32 CFR Part 170 (89 FR 83092, Oct. 15, 2024); DFARS Case 2019-D041, 90 FR 43560 (Sept. 10, 2025)","enactedDate":"2024-10-15","effectiveDate":"2024-12-16","summary":"Requires defense contractors and subcontractors that handle Federal Contract Information (FCI) or Controlled Unclassified Information (CUI) to meet a specified CMMC level (Level 1 self-assessment, Level 2 self- or third-party (C3PAO) assessment against NIST SP 800-171, Level 3 DIBCAC assessment against selected NIST SP 800-172 controls) as a condition of contract award. Requirements are phased into DoD solicitations over four years.","appliesTo":"DoD prime contractors and subcontractors at all tiers whose information systems process, store or transmit FCI or CUI in contract performance; excludes contracts solely for commercially available off-the-shelf (COTS) items.","penalties":"Ineligibility for award or option exercise; misrepresented affirmations can create False Claims Act and contractual liability.","enforcer":"U.S. Department of Defense (DoD CIO, contracting officers, DCMA DIBCAC); Cyber AB accredits C3PAOs","sourceUrl":"https://www.federalregister.gov/documents/2025/09/10/2025-17359/defense-federal-acquisition-regulation-supplement-assessing-contractor-implementation-of","extraSources":["https://www.federalregister.gov/documents/2024/10/15/2024-22905/cybersecurity-maturity-model-certification-cmmc-program","https://dodcio.defense.gov/CMMC/"],"notes":"Phase dates computed per 32 CFR 170.3(e): Phase 1 starts on the later of the Part 170 or the 48 CFR rule effective date (November 10, 2025), each later phase one calendar year after the previous; DoD may include higher requirements earlier at its discretion. The DoD CIO site could not be fetched during verification.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-24 02:56:54","deadlines":[{"id":194,"regulationId":"us-cmmc","date":"2024-12-16","title":"CMMC Program rule (32 CFR Part 170) effective","description":"The program rule establishing CMMC levels and assessment processes took effect; contract enforcement awaited the DFARS rule.","kind":"effective","sourceUrl":"https://www.federalregister.gov/documents/2024/10/15/2024-22905/cybersecurity-maturity-model-certification-cmmc-program","tentative":false,"review":"verified"},{"id":195,"regulationId":"us-cmmc","date":"2025-11-10","title":"DFARS rule effective; Phase 1 begins","description":"CMMC Level 1 and Level 2 self-assessment requirements begin appearing in applicable DoD solicitations and contracts (32 CFR 170.3(e)(1)).","kind":"effective","sourceUrl":"https://www.federalregister.gov/documents/2025/09/10/2025-17359/defense-federal-acquisition-regulation-supplement-assessing-contractor-implementation-of","tentative":false,"review":"verified"},{"id":196,"regulationId":"us-cmmc","date":"2026-11-10","title":"Phase 2: Level 2 C3PAO certification","description":"Phase 2 begins one calendar year after Phase 1; applicable solicitations require CMMC Level 2 third-party (C3PAO) certification (32 CFR 170.3(e)(2)).","kind":"compliance","sourceUrl":"https://www.federalregister.gov/documents/2024/10/15/2024-22905/cybersecurity-maturity-model-certification-cmmc-program","tentative":false,"review":"verified"},{"id":197,"regulationId":"us-cmmc","date":"2027-11-10","title":"Phase 3: Level 3 certification","description":"Phase 3 begins one year after Phase 2; Level 3 (DIBCAC) requirements added to applicable solicitations (32 CFR 170.3(e)(3)).","kind":"compliance","sourceUrl":"https://www.federalregister.gov/documents/2024/10/15/2024-22905/cybersecurity-maturity-model-certification-cmmc-program","tentative":false,"review":"verified"},{"id":198,"regulationId":"us-cmmc","date":"2028-11-10","title":"Phase 4: full implementation","description":"CMMC requirements included in all applicable DoD solicitations and contracts, including option periods (32 CFR 170.3(e)(4)).","kind":"compliance","sourceUrl":"https://www.federalregister.gov/documents/2024/10/15/2024-22905/cybersecurity-maturity-model-certification-cmmc-program","tentative":false,"review":"verified"}]},{"id":"us-coppa","name":"Children's Online Privacy Protection Rule (16 CFR Part 312), as amended April 2025","shortName":"COPPA Rule","jurisdiction":"us","jurisdictionName":"United States (Federal)","region":"us-federal","topics":["privacy","children"],"status":"amended","citation":"15 U.S.C. 6501-6506; 16 CFR Part 312; amendments at 90 FR 16918 (Apr. 22, 2025)","enactedDate":"1998-10-21","effectiveDate":"2000-04-21","summary":"Requires operators of child-directed online services, or those with actual knowledge they collect personal information from children under 13, to give notice and obtain verifiable parental consent before collecting, using or disclosing that data. The 2025 amendments add separate parental consent for disclosures to third parties (including for targeted advertising), require a written data retention policy and a written information security program, expand 'personal information' to include biometric identifiers and government-issued identifiers, and tighten Safe Harbor program oversight.","appliesTo":"Operators of commercial websites, online services and apps directed to children under 13 (including mixed-audience services), and general-audience operators with actual knowledge they collect personal information from a child under 13. No revenue or volume threshold.","penalties":"Violations are treated as violations of an FTC trade regulation rule: civil penalties up to $53,088 per violation (FTC Act 5(m)(1)(A) amount as adjusted January 2025, 90 FR 5580; adjusted annually for inflation). State attorneys general may also sue.","enforcer":"Federal Trade Commission; State Attorneys General","sourceUrl":"https://www.federalregister.gov/documents/2025/04/22/2025-05904/childrens-online-privacy-protection-rule","extraSources":["https://www.ecfr.gov/current/title-16/chapter-I/subchapter-C/part-312","https://www.federalregister.gov/documents/2025/01/17/2025-01361/adjustments-to-civil-penalty-amounts"],"notes":"Safe Harbor program obligations had earlier compliance dates set relative to publication: 90 days after publication for 312.11(d)(4) and six months after publication for 312.11(d)(1) and (g) (i.e. around July 21, 2025 and October 22, 2025); omitted as rows because the rule states them relatively. The FTC civil penalty figure is the January 2025 adjustment; no 2026 FTC adjustment was found in the Federal Register as of verification.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-24 02:56:54","deadlines":[{"id":213,"regulationId":"us-coppa","date":"2025-06-23","title":"Amended COPPA Rule takes effect","description":"The April 2025 amendments to 16 CFR Part 312 became effective; during the transition operators could comply with either the pre-2025 or the amended Rule.","kind":"effective","sourceUrl":"https://www.federalregister.gov/documents/2025/04/22/2025-05904/childrens-online-privacy-protection-rule","tentative":false,"review":"verified"},{"id":214,"regulationId":"us-coppa","date":"2026-04-22","title":"Full compliance with amended COPPA Rule","description":"Operators must comply with all amended provisions (separate third-party disclosure consent, written retention policy, written security program, updated notices); excludes Safe Harbor provisions 312.11(d)(1), (d)(4) and (g), which had earlier dates.","kind":"compliance","sourceUrl":"https://www.federalregister.gov/documents/2025/04/22/2025-05904/childrens-online-privacy-protection-rule","tentative":false,"review":"verified"}]},{"id":"us-ca-ab2013","name":"California AB 2013, Generative Artificial Intelligence: Training Data Transparency (Stats. 2024, ch. 817)","shortName":"California AB 2013 (AI training data transparency)","jurisdiction":"us-ca","jurisdictionName":"California","region":"us-states","topics":["ai","privacy"],"status":"in_force","citation":"AB 2013 (2024), Stats. 2024, ch. 817; Civ. Code 3110-3111","enactedDate":"2024-09-28","effectiveDate":"2026-01-01","summary":"Developers of generative AI systems made publicly available to Californians must post documentation of the training data on their websites. It must cover a high-level summary of the datasets, their sources and owners, the number of data points, the types of data, whether the data includes copyrighted material or personal information, whether it was licensed or purchased, cleaning and processing steps, collection periods, and whether synthetic data was used.","appliesTo":"Any developer, including those that substantially modify a system, of a generative AI system or service released on or after January 1, 2022 and publicly available to Californians. Exempt: systems whose sole purpose is security and integrity, systems for operating aircraft in national airspace, and systems for federal national security, military or defense purposes. No size threshold.","penalties":"The statute sets no specific penalty. Enforcement would rely on general California law, for example the Unfair Competition Law.","enforcer":"Not specified in statute (California Attorney General under general consumer protection law)","sourceUrl":"https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202320240AB2013","extraSources":[],"notes":"Enforcement route is not explicit in the statute. Constitutional challenges to AB 2013 were reported but not verified for this record.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-24 02:56:54","deadlines":[{"id":162,"regulationId":"us-ca-ab2013","date":"2024-09-28","title":"AB 2013 signed","description":"AB 2013 chaptered (ch. 817).","kind":"transition","sourceUrl":"https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202320240AB2013","tentative":false,"review":"verified"},{"id":163,"regulationId":"us-ca-ab2013","date":"2026-01-01","title":"Training-data documentation due","description":"Documentation must be posted for GenAI systems released since January 1, 2022, and before each later release or substantial modification.","kind":"compliance","sourceUrl":"https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202320240AB2013","tentative":false,"review":"verified"}]},{"id":"us-ca-sb942","name":"California AI Transparency Act (SB 942, Stats. 2024, ch. 291), as amended by AB 853 (Stats. 2025, ch. 674)","shortName":"California AI Transparency Act (SB 942)","jurisdiction":"us-ca","jurisdictionName":"California","region":"us-states","topics":["ai"],"status":"amended","citation":"Bus. & Prof. Code 22757 et seq.; SB 942 (2024) ch. 291; AB 853 (2025) ch. 674","enactedDate":"2024-09-19","effectiveDate":"2026-08-02","summary":"Covered generative AI providers must offer a free AI-content detection tool, give users the option of a visible (manifest) disclosure on AI-generated image, video or audio, and embed a latent, machine-readable provenance disclosure. Licensees must keep those disclosures intact, and providers must revoke a license within 96 hours of learning a licensee disabled them. AB 853 delayed the operative date to August 2, 2026 and extends duties to large online platforms and GenAI hosting platforms from 2027 and to capture-device makers from 2028.","appliesTo":"Covered providers: creators of GenAI systems with over 1,000,000 monthly visitors or users that are publicly accessible in California. From 2027: large online platforms with more than 2,000,000 unique monthly users in the preceding 12 months, and GenAI system hosting platforms. From 2028: capture device manufacturers.","penalties":"Civil penalty of $5,000 per violation, each day a separate violation, plus attorney fees and costs for a prevailing plaintiff. Injunctive relief against licensees.","enforcer":"California Attorney General, city attorneys, county counsel","sourceUrl":"https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202520260AB853","extraSources":["https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202320240SB942","https://www.troutmanprivacy.com/2025/10/california-ai-transparency-act-amendments-signed-into-law/"],"notes":"The August 2, 2026 operative date was set by AB 853. Many trackers still cite January 1, 2026, which is superseded.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-24 02:56:54","deadlines":[{"id":187,"regulationId":"us-ca-sb942","date":"2024-09-19","title":"SB 942 signed","description":"SB 942 chaptered (ch. 291) with an original operative date of January 1, 2026.","kind":"transition","sourceUrl":"https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202320240SB942","tentative":false,"review":"verified"},{"id":188,"regulationId":"us-ca-sb942","date":"2025-10-13","title":"AB 853 signed","description":"AB 853 (ch. 674) delays the operative date and adds platform and device duties.","kind":"transition","sourceUrl":"https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202520260AB853","tentative":false,"review":"verified"},{"id":189,"regulationId":"us-ca-sb942","date":"2026-01-01","title":"Original operative date (superseded)","description":"Original SB 942 date; delayed to August 2, 2026 by AB 853.","kind":"transition","sourceUrl":"https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202320240SB942","tentative":false,"review":"verified"},{"id":190,"regulationId":"us-ca-sb942","date":"2026-08-02","title":"Covered provider duties apply","description":"Detection tool, manifest and latent disclosures, and license-revocation duties become operative.","kind":"effective","sourceUrl":"https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202520260AB853","tentative":false,"review":"verified"},{"id":191,"regulationId":"us-ca-sb942","date":"2027-01-01","title":"Large online platform and hosting platform duties","description":"Large online platforms and GenAI hosting platforms must meet the provenance duties added by AB 853.","kind":"compliance","sourceUrl":"https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202520260AB853","tentative":false,"review":"verified"},{"id":192,"regulationId":"us-ca-sb942","date":"2028-01-01","title":"Capture device manufacturer duties","description":"Capture device manufacturer provenance requirements become operative.","kind":"compliance","sourceUrl":"https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202520260AB853","tentative":false,"review":"verified"}]},{"id":"us-ca-delete-act","name":"California Delete Act (SB 362, 2023), Cal. Civ. Code 1798.99.80 et seq., and DROP regulations","shortName":"California Delete Act / DROP","jurisdiction":"us-ca","jurisdictionName":"California","region":"us-states","topics":["privacy","data-access"],"status":"in_force","citation":"SB 362 (Stats. 2023, ch. 709); Cal. Civ. Code 1798.99.80-1798.99.89","enactedDate":"2023-10-10","effectiveDate":"2024-01-01","summary":"Requires data brokers to register annually with the California Privacy Protection Agency and to process consumer deletion requests submitted through the agency's Delete Request and Opt-out Platform (DROP). DROP opened to consumers Jan 1, 2026; from Aug 1, 2026 brokers must pull and process requests at least every 45 days. Brokers face independent compliance audits every three years from 2028.","appliesTo":"Data brokers: businesses that knowingly collect and sell to third parties the personal information of consumers with whom they do not have a direct relationship (Civ. Code 1798.99.80). No revenue or volume threshold.","penalties":"Administrative fines of $200 per day for failure to register, plus unpaid fees; $200 per deletion request per day for failure to delete as required by 1798.99.86; plus reasonable enforcement costs.","enforcer":"California Privacy Protection Agency (CalPrivacy)","sourceUrl":"https://www.cppa.ca.gov/data_brokers/","extraSources":["https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=CIV&sectionNum=1798.99.82","https://cppa.ca.gov/regulations/drop.html","https://www.alston.com/en/insights/publications/2026/08/california-privacy-opt-out-signals-data-brokers"],"notes":"Registration fee reported to rise from $6,000 to $9,500 for 2027 (Alston & Bird, Aug 2026); not verified on cppa.ca.gov. Signing date Oct 10, 2023 per legislative history (chaptered as ch. 709).","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-24 02:56:54","deadlines":[{"id":176,"regulationId":"us-ca-delete-act","date":"2026-01-01","title":"DROP opens to consumers","description":"Consumers can submit a single deletion request to all registered data brokers through DROP.","kind":"effective","sourceUrl":"https://www.cppa.ca.gov/data_brokers/","tentative":false,"review":"verified"},{"id":177,"regulationId":"us-ca-delete-act","date":"2026-01-31","title":"Annual data broker registration deadline","description":"Data brokers must register with CalPrivacy and pay the annual fee ($6,000 for 2026) by January 31.","kind":"reporting","sourceUrl":"https://www.cppa.ca.gov/data_brokers/","tentative":false,"review":"verified"},{"id":178,"regulationId":"us-ca-delete-act","date":"2026-08-01","title":"Data brokers must begin processing DROP deletion requests","description":"Brokers must access DROP at least every 45 days, process verified deletion requests within 45 days, and treat unverified requests as opt-outs of sale/sharing.","kind":"compliance","sourceUrl":"https://www.cppa.ca.gov/data_brokers/","tentative":false,"review":"verified"},{"id":179,"regulationId":"us-ca-delete-act","date":"2027-01-31","title":"Annual data broker registration deadline","description":"Data brokers must renew registration with CalPrivacy by January 31 following each year they meet the definition.","kind":"reporting","sourceUrl":"https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=CIV&sectionNum=1798.99.82","tentative":false,"review":"verified"},{"id":180,"regulationId":"us-ca-delete-act","date":"2028-01-01","title":"Independent third-party audits begin","description":"Beginning Jan 1, 2028 and every 3 years thereafter, data brokers must undergo an independent audit of Delete Act compliance.","kind":"compliance","sourceUrl":"https://www.cppa.ca.gov/data_brokers/","tentative":false,"review":"verified"}]},{"id":"us-ca-sb243","name":"California SB 243, Companion Chatbots (Stats. 2025, ch. 677)","shortName":"California SB 243 (companion chatbots)","jurisdiction":"us-ca","jurisdictionName":"California","region":"us-states","topics":["ai","children","online-safety"],"status":"in_force","citation":"SB 243 (2025), Stats. 2025, ch. 677","enactedDate":"2025-10-13","effectiveDate":"2026-01-01","summary":"Operators of companion chatbot platforms must clearly disclose that the chatbot is AI where a user could reasonably think they are talking to a human. They must keep and publish protocols that prevent suicidal-ideation and self-harm content and refer users to crisis services. For known minors, operators must disclose AI use, remind them every three hours to take a break, and block sexually explicit content. Annual reports to the Office of Suicide Prevention begin July 1, 2027.","appliesTo":"Operators of companion chatbot platforms available to users in California. No size threshold.","penalties":"Private right of action: injunctive relief, the greater of actual damages or $1,000 per violation, and reasonable attorney fees and costs.","enforcer":"Private right of action; Office of Suicide Prevention receives reports","sourceUrl":"https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202520260SB243","extraSources":[],"notes":"Added as a major 2025 California AI law affecting consumer AI products.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-24 02:56:54","deadlines":[{"id":181,"regulationId":"us-ca-sb243","date":"2025-10-13","title":"SB 243 signed","description":"SB 243 chaptered (ch. 677).","kind":"transition","sourceUrl":"https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202520260SB243","tentative":false,"review":"verified"},{"id":182,"regulationId":"us-ca-sb243","date":"2026-01-01","title":"Chatbot safeguards apply","description":"AI disclosure, suicide and self-harm protocols, and minor protections apply.","kind":"effective","sourceUrl":"https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202520260SB243","tentative":false,"review":"verified"},{"id":183,"regulationId":"us-ca-sb243","date":"2027-07-01","title":"First annual report to Office of Suicide Prevention","description":"Operators begin annual reporting on crisis referrals and detection protocols.","kind":"reporting","sourceUrl":"https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202520260SB243","tentative":false,"review":"verified"}]},{"id":"us-ca-sb53","name":"California SB 53, Transparency in Frontier Artificial Intelligence Act (Stats. 2025, ch. 138)","shortName":"California SB 53 (TFAIA)","jurisdiction":"us-ca","jurisdictionName":"California","region":"us-states","topics":["ai"],"status":"in_force","citation":"SB 53 (2025), Stats. 2025, ch. 138","enactedDate":"2025-09-29","effectiveDate":"2026-01-01","summary":"Frontier AI developers must publish transparency reports when deploying new or substantially modified frontier models and report critical safety incidents to the Office of Emergency Services (OES). Large frontier developers must also write, implement and publish a frontier AI framework for catastrophic risk, update it annually, and send OES quarterly summaries of their catastrophic-risk assessments. The act also adds whistleblower protections and creates the CalCompute public computing consortium.","appliesTo":"Frontier developers: trained or started training a foundation model with more than 10^26 integer or floating-point operations, counting fine-tuning. Large frontier developers: those whose revenue with affiliates exceeded $500,000,000 in annual gross revenue in the preceding calendar year.","penalties":"Civil penalty up to $1,000,000 per violation, recoverable only in a civil action by the Attorney General.","enforcer":"California Attorney General; Office of Emergency Services receives incident reports","sourceUrl":"https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202520260SB53","extraSources":["https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=202520260SB53"],"notes":"CalCompute depends on a budget appropriation. The quarterly catastrophic-risk summary schedule can be set with OES.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-24 02:56:54","deadlines":[{"id":184,"regulationId":"us-ca-sb53","date":"2025-09-29","title":"SB 53 signed","description":"Governor Newsom signs SB 53 (chapter 138).","kind":"transition","sourceUrl":"https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202520260SB53","tentative":false,"review":"verified"},{"id":185,"regulationId":"us-ca-sb53","date":"2026-01-01","title":"Frontier developer obligations apply","description":"Frontier AI frameworks, transparency reports, critical safety incident reporting (15 days, or 24 hours for imminent risk of death or serious injury) and whistleblower protections apply.","kind":"effective","sourceUrl":"https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202520260SB53","tentative":false,"review":"verified"},{"id":186,"regulationId":"us-ca-sb53","date":"2027-01-01","title":"First OES anonymized incident report and CDT definition review","description":"OES begins publishing annual anonymized incident summaries and the Department of Technology begins annual review of the act's definitions; the CalCompute framework report is due to the Legislature.","kind":"reporting","sourceUrl":"https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202520260SB53","tentative":false,"review":"verified"}]},{"id":"ca-c36-ppcda","name":"Bill C-36, An Act to enact the Protecting Privacy and Consumer Data Act","shortName":"Canada Bill C-36 (PPCDA)","jurisdiction":"ca","jurisdictionName":"Canada","region":"americas","topics":["privacy","breach-notification"],"status":"proposed","citation":"Bill C-36 (45th Parliament, 1st Session)","enactedDate":"","effectiveDate":"","summary":"Would replace PIPEDA's private-sector rules with a modernised statute (successor to C-27's CPPA) including stronger consent, de-identification and re-identification rules, and administrative penalties, with oversight housed in a new Digital Safety and Data Protection Commission. Does not include an AI act.","appliesTo":"Organisations handling personal information in the course of commercial activity (as under PIPEDA).","penalties":"As tabled: administrative monetary penalties up to the greater of CAD 10 million and 3% of global revenue; criminal fines up to the greater of CAD 25 million and 5% of global revenue on indictment.","enforcer":"Digital Safety and Data Protection Commission of Canada (proposed)","sourceUrl":"https://www.parl.ca/DocumentViewer/en/45-1/bill/C-36/first-reading","extraSources":["https://iapp.org/news/a/canada-s-bill-c-36-introduces-privacy-reforms-enforcement-changes","https://www.osler.com/en/insights/reports/the-protecting-privacy-and-consumer-data-act-bill-c-36-key-obligations-and-enforcement-overview/"],"notes":"Penalty figures are from law-firm/IAPP summaries of the first-reading text. No federal AI successor to AIDA has been tabled as of Aug 2026.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-24 02:56:54","deadlines":[{"id":15,"regulationId":"ca-c36-ppcda","date":"2026-06-15","title":"Bill C-36 tabled (first reading)","description":"Government introduces the PPCDA in the House of Commons.","kind":"effective","sourceUrl":"https://www.parl.ca/DocumentViewer/en/45-1/bill/C-36/first-reading","tentative":false,"review":"verified"}]},{"id":"ca-ccspa","name":"Critical Cyber Systems Protection Act (enacted by Bill C-8, An Act respecting cyber security)","shortName":"Canada Bill C-8 / CCSPA","jurisdiction":"ca","jurisdictionName":"Canada","region":"americas","topics":["cybersecurity","breach-notification"],"status":"enacted","citation":"S.C. 2026, c. 9 (Bill C-8, 45th Parl., 1st Sess.)","enactedDate":"2026-06-15","effectiveDate":"","summary":"Requires designated operators in federally regulated critical sectors to establish cyber security programs, mitigate supply-chain risks, report cyber incidents and comply with government cyber security directions; also amends the Telecommunications Act to let government order telecom providers to secure their networks.","appliesTo":"Designated operators in classes listed in the Act's schedule for vital federal services and systems: finance/banking, telecommunications, energy (pipelines, nuclear, interprovincial power) and transportation.","penalties":"Administrative monetary penalties and offences under the CCSPA; exact maxima in the final text not verified here.","enforcer":"Sector regulators (e.g. OSFI, CRTC, CER, CNSC, Transport Canada) and the Minister of Public Safety; Communications Security Establishment receives incident reports","sourceUrl":"https://www.parl.ca/legisinfo/en/bill/45-1/c-8","extraSources":["https://www.parl.ca/DocumentViewer/en/45-1/bill/C-8/royal-assent","https://www.canada.ca/en/public-safety-canada/news/2026/06/government-of-canada-strengthens-cyber-security-and-critical-infrastructure-with-royal-assent-of-bill-c8.html"],"notes":"Parliament's LEGISinfo lists Royal Assent on 15 June 2026; the Public Safety Canada news release is dated 16 June 2026. The CCSPA itself comes into force by order in council in phases; no date announced as of late July 2026. Predecessor C-26 proposed 72-hour incident reporting and AMPs up to CAD 15M for organisations; final figures not verified.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-24 02:56:54","deadlines":[{"id":16,"regulationId":"ca-ccspa","date":"2025-06-18","title":"Bill C-8 introduced","description":"First reading in the House of Commons.","kind":"transition","sourceUrl":"https://www.parl.ca/legisinfo/en/bill/45-1/c-8","tentative":false,"review":"verified"},{"id":17,"regulationId":"ca-ccspa","date":"2026-06-15","title":"Royal Assent","description":"Bill C-8 receives Royal Assent (S.C. 2026, c. 9); Telecommunications Act amendments take effect.","kind":"effective","sourceUrl":"https://www.parl.ca/legisinfo/en/bill/45-1/c-8","tentative":false,"review":"verified"}]},{"id":"cl-pdpl","name":"Ley Nº 21.719 que regula la protección y el tratamiento de los datos personales y crea la Agencia de Protección de Datos Personales","shortName":"Chile Personal Data Protection Law (Ley 21.719)","jurisdiction":"cl","jurisdictionName":"Chile","region":"americas","topics":["privacy","breach-notification"],"status":"enacted","citation":"Ley Nº 21.719 (Diario Oficial 13 Dec 2024)","enactedDate":"2024-11-25","effectiveDate":"2026-12-01","summary":"Replaces Chile's 1999 data law with a GDPR-style regime: legal bases, data subject rights (including portability and objection to automated decisions), security and breach notification, international transfer rules, a voluntary compliance (crime-prevention-style) model, and a new independent Personal Data Protection Agency.","appliesTo":"Controllers and processors established in Chile, and those outside Chile offering goods/services to or monitoring individuals in Chile. No size threshold (graduated fines for small businesses).","penalties":"Fines up to 5,000 UTM (minor), 10,000 UTM (serious) and 20,000 UTM (very serious) infringements; repeat serious/very serious infringements by larger companies can reach a percentage of annual revenue (up to 4%) per secondary sources.","enforcer":"Agencia de Protección de Datos Personales","sourceUrl":"https://www.bcn.cl/leychile/navegar?idNorma=1209272","extraSources":["https://www.senado.cl/appsenado/index.php?mo=tramitacion&ac=getDocto&iddocto=19307&tipodoc=mensaje_mocion","https://lawwwing.com/la-nueva-era-de-la-proteccion-de-datos-en-chile-que-cambia-con-la-ley-21-719/"],"notes":"Fact-check 2026-09-22 against BCN LeyChile metadata: promulgated 25 Nov 2024 ('Santiago, 25 de noviembre de 2024'), published in the Diario Oficial 13 Dec 2024, deferred entry into force 1 Dec 2026 (first day of the 24th month after publication, transitional Art 1). Pending amendment: government bill Boletin 18623-07 (filed 1 Sep 2026 with 'suma' urgency, Senate Constitution Committee first report stage) would postpone entry into force to 1 Dec 2027 and require the Agency's first board appointments at least 12 months before; a separate member's bill 18060-07 (Jan 2026) is also in committee. Until enacted, 1 Dec 2026 remains the legal date.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-24 02:56:54","deadlines":[{"id":26,"regulationId":"cl-pdpl","date":"2024-12-13","title":"Published in Diario Oficial","description":"Law 21.719 published; 24-month vacatio legis begins.","kind":"effective","sourceUrl":"https://www.bcn.cl/leychile/navegar?idNorma=1209272","tentative":false,"review":"verified"},{"id":27,"regulationId":"cl-pdpl","date":"2026-12-01","title":"Law in force","description":"Main obligations apply and the Personal Data Protection Agency begins supervision.","kind":"effective","sourceUrl":"https://www.bcn.cl/leychile/navegar?idNorma=1209272","tentative":false,"review":"verified"},{"id":28,"regulationId":"cl-pdpl","date":"2027-12-01","title":"Proposed postponement of entry into force","description":"Government bill Boletin 18623-07 (filed 1 Sep 2026, 'suma' urgency) would replace the 24-month vacatio legis in transitional Art 1 with a fixed date of 1 Dec 2027; in first committee stage in the Senate, not law.","kind":"effective","sourceUrl":"https://tramitacion.senado.cl/appsenado/templates/tramitacion/index.php?boletin_ini=18623-07","tentative":true,"review":"verified"}]},{"id":"cn-ai-labeling","name":"Measures for Labeling AI-Generated Synthetic Content","shortName":"China AI Content Labeling Measures","jurisdiction":"cn","jurisdictionName":"China","region":"apac","topics":["ai","online-safety"],"status":"in_force","citation":"Joint notice of CAC, MIIT, Ministry of Public Security and NRTA (14 Mar 2025)","enactedDate":"2025-03-14","effectiveDate":"2025-09-01","summary":"Requires generative AI service providers to add explicit (visible) labels to AI-generated text, images, audio, video and virtual scenes, and implicit labels (metadata) to generated files. Content distribution platforms must detect and label AI-generated content, and app stores must check labeling functions when apps are listed. A mandatory national standard (GB 45438-2025) takes effect on the same date.","appliesTo":"Internet information service providers in China that provide generative AI, deep synthesis, or content distribution services, and app distribution platforms.","penalties":"No standalone fines; violations are handled under existing laws and regulations (CSL, generative AI and deep synthesis rules). CAC ran enforcement actions against non-compliant apps in November 2025.","enforcer":"CAC with MIIT, Ministry of Public Security and National Radio and Television Administration","sourceUrl":"https://www.cac.gov.cn/2025-03/14/c_1743654684782215.htm","extraSources":["https://www.cac.gov.cn/2025-03/14/c_1743654685899683.htm","https://www.cac.gov.cn/2025-11/25/c_1765795550841819.htm"],"notes":"Official notice document number not captured here.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-24 02:56:54","deadlines":[{"id":29,"regulationId":"cn-ai-labeling","date":"2025-09-01","title":"AI content labeling measures and GB 45438-2025 take effect","description":"Explicit and implicit labeling duties for AI-generated content and platform detection duties apply.","kind":"effective","sourceUrl":"https://www.cac.gov.cn/2025-03/14/c_1743654684782215.htm","tentative":false,"review":"verified"}]},{"id":"cn-cross-border","name":"Provisions on Promoting and Regulating Cross-Border Data Flows (CAC Order No. 16)","shortName":"China Cross-Border Data Flow Provisions","jurisdiction":"cn","jurisdictionName":"China","region":"apac","topics":["data-residency","privacy"],"status":"in_force","citation":"CAC Order No. 16","enactedDate":"2024-03-22","effectiveDate":"2024-03-22","summary":"Relaxes China's data export regime by exempting common transfers (contracts with the individual, cross-border HR, emergencies, and non-CII transfers of PI of fewer than 100,000 people a year) and setting volume thresholds for when a CAC security assessment, standard contract or certification is needed. Data is not 'important data' unless regulators have notified or published it as such.","appliesTo":"Data processors exporting data from China. Non-CII processors: fewer than 100,000 individuals' non-sensitive PI per year is exempt (Art. 5); 100,000 to under 1 million non-sensitive PI, or fewer than 10,000 individuals' sensitive PI, needs a standard contract or certification (Art. 8); 1 million+ non-sensitive PI, 10,000+ sensitive PI, or any important data needs a CAC security assessment (Art. 7). CII operators exporting PI or important data always need an assessment.","penalties":"Enforced through PIPL, DSL and CSL penalties (e.g. PIPL up to RMB 50 million or 5% of turnover; DSL up to RMB 10 million for serious unlawful important-data exports).","enforcer":"Cyberspace Administration of China (national and provincial)","sourceUrl":"https://www.cac.gov.cn/2024-03/22/c_1712776611775634.htm","extraSources":["https://www.cac.gov.cn/2024-03/22/c_1712776612187994.htm"],"notes":"Counts are cumulative from 1 January of each year. Free trade zones may issue negative lists. Security assessment approvals last 3 years and may be extended on application.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-24 02:56:54","deadlines":[{"id":30,"regulationId":"cn-cross-border","date":"2024-03-22","title":"Cross-border data flow provisions take effect","description":"Exemptions and volume thresholds apply from publication (Art. 14); security assessment results are valid for 3 years (Art. 9).","kind":"effective","sourceUrl":"https://www.cac.gov.cn/2024-03/22/c_1712776611775634.htm","tentative":false,"review":"verified"}]},{"id":"cn-csl","name":"Cybersecurity Law of the People's Republic of China (as amended by the NPC Standing Committee Decision of 28 October 2025)","shortName":"China Cybersecurity Law","jurisdiction":"cn","jurisdictionName":"China","region":"apac","topics":["cybersecurity","data-residency","ai","privacy"],"status":"amended","citation":"Order of the President No. 53 (2016); amended by Decision of the 14th NPC Standing Committee, 18th session, 28 Oct 2025","enactedDate":"2016-11-07","effectiveDate":"2017-06-01","summary":"China's base cybersecurity statute: multi-level protection scheme duties for network operators, localization and security review duties for critical information infrastructure (CII) operators, and content controls. The 2025 amendment, in force from 1 January 2026, adds AI governance support, ties PI processing to PIPL, allows fines on first violations and sharply raises maximum fines.","appliesTo":"All network operators in China (owners, managers and service providers of networks); stricter duties for CII operators. Amended Art. 77 allows sanctions such as asset freezes on foreign organizations whose activities endanger China's cybersecurity.","penalties":"Post-amendment (Art. 61): network operators RMB 10,000-50,000 on a first violation, RMB 50,000-500,000 for refusal to correct; CII operators RMB 50,000-100,000 rising to RMB 100,000-1 million. Serious harm (e.g. large data leaks): RMB 500,000-2 million; particularly serious harm: RMB 2-10 million, with responsible individuals fined up to RMB 1 million. Using unreviewed network products in CII: 1-10x the purchase amount.","enforcer":"CAC, Ministry of Public Security, MIIT and sector regulators","sourceUrl":"https://www.gov.cn/yaowen/liebiao/202510/content_7046194.htm","extraSources":[],"notes":"Amendment adopted 2025-10-28 and effective 2026-01-01, per the official Decision text on gov.cn. The original 2016 enactment date comes from the 2016 promulgation, not re-verified here.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-24 02:56:54","deadlines":[{"id":31,"regulationId":"cn-csl","date":"2017-06-01","title":"Cybersecurity Law takes effect","description":"Original CSL obligations for network operators and CII operators apply.","kind":"effective","sourceUrl":"https://www.gov.cn/yaowen/liebiao/202510/content_7046194.htm","tentative":false,"review":"verified"},{"id":32,"regulationId":"cn-csl","date":"2026-01-01","title":"2025 amendments take effect","description":"Higher fines, first-violation fines, AI governance provisions and PIPL-alignment duties apply under the 28 Oct 2025 NPCSC Decision.","kind":"effective","sourceUrl":"https://www.gov.cn/yaowen/liebiao/202510/content_7046194.htm","tentative":false,"review":"verified"}]},{"id":"cn-dsl","name":"Data Security Law of the People's Republic of China","shortName":"China Data Security Law","jurisdiction":"cn","jurisdictionName":"China","region":"apac","topics":["cybersecurity","data-residency","data-access"],"status":"in_force","citation":"Order of the President of the PRC No. 84","enactedDate":"2021-06-10","effectiveDate":"2021-09-01","summary":"Sets up China's data classification and grading system, with heightened protection for 'important data' and 'core data'. Requires data processors to run data security management systems, risk monitoring and incident handling, and restricts giving data stored in China to foreign judicial or law-enforcement bodies without approval.","appliesTo":"All organizations and individuals carrying out data processing activities in China, plus offshore activities that harm China's national security or public interest. Important-data processors must appoint a data security officer and submit periodic risk assessments.","penalties":"Failure to meet security duties: up to RMB 500,000, rising to RMB 500,000-2 million for refusal to correct or serious consequences such as large data leaks (Art. 45). Violating the national core data regime: RMB 2-10 million plus suspension or license revocation. Unlawful export of important data: RMB 100,000-1 million, up to RMB 10 million if serious (Art. 46).","enforcer":"Sector regulators, public security and national security authorities; CAC coordinates network data security","sourceUrl":"http://www.cac.gov.cn/2021-06/11/c_1624994566919140.htm","extraSources":[],"notes":"Important-data catalogs are issued by region and sector; the Network Data Security Management Regulations (effective 2025-01-01) detail important-data processor duties such as annual risk assessments.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-24 02:56:54","deadlines":[{"id":33,"regulationId":"cn-dsl","date":"2021-09-01","title":"Data Security Law takes effect","description":"Data classification, important-data protection and data export restrictions apply (Art. 55).","kind":"effective","sourceUrl":"http://www.cac.gov.cn/2021-06/11/c_1624994566919140.htm","tentative":false,"review":"verified"}]},{"id":"cn-network-data-regs","name":"Regulations on Network Data Security Management (State Council Order No. 790)","shortName":"China Network Data Security Regulations","jurisdiction":"cn","jurisdictionName":"China","region":"apac","topics":["privacy","cybersecurity","data-residency"],"status":"in_force","citation":"State Council Order No. 790","enactedDate":"2024-09-24","effectiveDate":"2025-01-01","summary":"Implementing regulations under the CSL, DSL and PIPL covering personal information, important data, cross-border data and platform duties. Processors of PI of 10 million+ people must also meet important-data processor duties, such as naming a security lead and filing annual risk assessments. Platforms must offer an easy opt-out from personalized recommendations.","appliesTo":"Network data processing activities in China, plus offshore processing of data of people in China that harms national security or public interest. Processors of PI of 10 million or more individuals take on the important-data duties in Arts. 30 and 32 (Art. 28). Important-data processors must file annual risk assessment reports with provincial-level regulators (Art. 33).","penalties":"Violating specified articles (e.g. Arts. 12, 16-20, 22, 40-42): warning and confiscation, and for refusal or serious cases fines up to RMB 1 million plus possible suspension or license revocation; responsible individuals RMB 10,000-100,000 (Art. 55). Other violations are punished under the CSL, DSL and PIPL.","enforcer":"CAC, telecom, public security and other competent departments","sourceUrl":"https://www.gov.cn/zhengce/content/202409/content_6977766.htm","extraSources":["https://www.cac.gov.cn/2024-09/30/c_1729384452307680.htm"],"notes":"Adopted at the State Council executive meeting of 2024-08-30, signed as Order No. 790 on 2024-09-24, published 2024-09-30. Annual risk assessment timing is 'each year' with no fixed calendar date.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-24 02:56:54","deadlines":[{"id":34,"regulationId":"cn-network-data-regs","date":"2025-01-01","title":"Network Data Regulations take effect","description":"All provisions, including the 10-million-person threshold duties and annual important-data risk assessments, apply.","kind":"effective","sourceUrl":"https://www.gov.cn/zhengce/content/202409/content_6977766.htm","tentative":false,"review":"verified"}]},{"id":"cn-pi-compliance-audit","name":"Administrative Measures for Personal Information Protection Compliance Audits (CAC Order No. 18)","shortName":"China PI Compliance Audit Measures","jurisdiction":"cn","jurisdictionName":"China","region":"apac","topics":["privacy"],"status":"in_force","citation":"CAC Order No. 18","enactedDate":"2025-02-14","effectiveDate":"2025-05-01","summary":"Implements PIPL Arts. 54 and 64: PI processors must audit their own PIPL compliance regularly, and regulators can order an audit by a professional firm when they find high risk or an incident. Processors of PI of more than 10 million people must audit at least once every two years.","appliesTo":"All personal information processors in China; mandatory biennial audits for processors handling PI of more than 10 million individuals. The related CAC Q&A ties the DPO requirement to processors handling PI of 1 million+ individuals.","penalties":"Penalties are imposed under the PIPL (up to RMB 50 million or 5% of prior-year turnover for serious violations).","enforcer":"CAC and departments with PI protection duties","sourceUrl":"https://www.cac.gov.cn/2025-02/14/c_1741233507681519.htm","extraSources":["https://www.cac.gov.cn/2025-02/14/c_1741232791991016.htm"],"notes":"The measures fix no calendar date for the first biennial audit. The 1-million DPO threshold comes from the CAC announcement and law-firm summaries, not re-read in the official text here.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-24 02:56:54","deadlines":[{"id":35,"regulationId":"cn-pi-compliance-audit","date":"2025-05-01","title":"PI compliance audit measures take effect","description":"Self-audit and regulator-ordered audit regime applies; 10M+ processors must audit at least every two years.","kind":"effective","sourceUrl":"https://www.cac.gov.cn/2025-02/14/c_1741233507681519.htm","tentative":false,"review":"verified"}]},{"id":"cn-pipl","name":"Personal Information Protection Law of the People's Republic of China","shortName":"China PIPL","jurisdiction":"cn","jurisdictionName":"China","region":"apac","topics":["privacy","data-residency","biometrics","children"],"status":"in_force","citation":"Order of the President of the PRC No. 91 (adopted by the 13th NPC Standing Committee, 30th session)","enactedDate":"2021-08-20","effectiveDate":"2021-11-01","summary":"China's comprehensive personal information law: requires a legal basis (usually consent) for processing, separate consent for sensitive data and cross-border transfers, PI impact assessments, and data subject rights. Applies extraterritorially to processing of data of people in China to provide products/services or analyze their behavior. Cross-border transfers need a CAC security assessment, standard contract, or certification.","appliesTo":"Any personal information processor handling PI of natural persons in China, including offshore processors that target or analyze people in China (must appoint a local representative). CII operators and processors reaching CAC-set volumes must store PI in China (Art. 40).","penalties":"Ordinary violations: rectification, confiscation of illegal gains, fines up to RMB 1 million (individuals responsible RMB 10,000-100,000). Serious violations: fines up to RMB 50 million or 5% of prior-year turnover, suspension of business or license revocation; responsible individuals RMB 100,000-1 million (Art. 66).","enforcer":"Cyberspace Administration of China (CAC) and other departments with PI protection duties at county level and above","sourceUrl":"http://www.cac.gov.cn/2021-08/20/c_1631050028355286.htm","extraSources":["https://www.gov.cn/yaowen/liebiao/202510/content_7046194.htm"],"notes":"Implementing rules layered on PIPL: Network Data Security Management Regulations (2025-01-01), PI Compliance Audit Measures (2025-05-01), cross-border data flow provisions (2024-03-22). The 2025 Cybersecurity Law amendment adds an express duty for network operators to follow PIPL when processing PI. Reports indicate CAC/SAMR measures on PI export certification took effect 2026-01-01; not verified against the official text here.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-24 02:56:54","deadlines":[{"id":36,"regulationId":"cn-pipl","date":"2021-11-01","title":"PIPL takes effect","description":"All PIPL obligations (legal bases, consent, cross-border rules, data subject rights) apply (Art. 74).","kind":"effective","sourceUrl":"http://www.cac.gov.cn/2021-08/20/c_1631050028355286.htm","tentative":false,"review":"verified"}]},{"id":"us-co-ai-act","name":"Colorado SB 24-205 (Consumer Protections for Artificial Intelligence), as delayed by SB 25B-004 and repealed and reenacted by SB 26-189 (Automated Decision-Making Technology)","shortName":"Colorado AI Act","jurisdiction":"us-co","jurisdictionName":"Colorado","region":"us-states","topics":["ai","privacy"],"status":"enacted","citation":"SB 24-205 (2024); SB 25B-004 (2025 1st Extraordinary Session); SB 26-189 (2026); C.R.S. Title 6, Art. 1, Part 17","enactedDate":"2024-05-17","effectiveDate":"2027-01-01","summary":"Colorado's 2024 high-risk AI law (risk-management programs, impact assessments) never took effect: it was delayed to June 30, 2026 and then repealed and reenacted by SB 26-189, signed May 14, 2026, as a narrower automated decision-making technology (ADMT) law. From January 1, 2027, developers must give deployers technical documentation (intended uses, training data categories, limitations) and deployers must notify consumers at the point of interaction, explain ADMT's role within 30 days after an adverse outcome, and offer data correction and meaningful human review. Impact-assessment and risk-management-program mandates were dropped; 3-year record retention remains.","appliesTo":"Developers and deployers of covered ADMT that processes personal data to materially influence consequential decisions about Colorado consumers in education, employment, housing, financial/lending services, insurance, health care and essential government services. No revenue or volume threshold identified. SB 26-189 removed the federally-regulated-entity exemptions in SB 24-205.","penalties":"Violations are deceptive trade practices under the Colorado Consumer Protection Act (civil penalties under C.R.S. 6-1-112). No private right of action. Until January 1, 2030 the AG must give a 60-day notice and opportunity to cure where a cure is possible.","enforcer":"Colorado Attorney General (exclusive)","sourceUrl":"https://leg.colorado.gov/bills/sb26-189","extraSources":["https://leg.colorado.gov/bills/sb24-205","https://leg.colorado.gov/bills/sb25b-004","https://coag.gov/ai/","https://www.consumerfinancemonitor.com/2026/05/12/colorado-rewrites-its-landmark-ai-law-unpacking-sb-26-189-and-what-it-means-for-businesses/","https://www.akingump.com/en/insights/ai-law-and-regulation-tracker/colorado-postpones-implementation-of-colorado-ai-act-sb-24-205"],"notes":"SB 24-205's high-risk AI obligations never became operative. SB 26-189 was signed May 14, 2026, which is why the June 30, 2026 date never took effect. Specific Colorado AG rulemaking hearing dates under SB 26-189 were not verified. The per-violation civil penalty amount comes from the general Colorado CPA and is not restated in SB 26-189.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-24 02:56:54","deadlines":[{"id":199,"regulationId":"us-co-ai-act","date":"2024-05-17","title":"SB 24-205 signed","description":"Governor Polis signs the original Colorado AI Act with a February 1, 2026 effective date.","kind":"effective","sourceUrl":"https://leg.colorado.gov/bills/sb24-205","tentative":false,"review":"verified"},{"id":200,"regulationId":"us-co-ai-act","date":"2025-08-28","title":"SB 25B-004 delays the act","description":"Special-session bill pushes the SB 24-205 effective date from February 1, 2026 to June 30, 2026.","kind":"transition","sourceUrl":"https://leg.colorado.gov/bills/sb25b-004","tentative":false,"review":"verified"},{"id":201,"regulationId":"us-co-ai-act","date":"2026-02-01","title":"Original effective date (superseded)","description":"Original SB 24-205 date; postponed by SB 25B-004, so no obligations applied.","kind":"transition","sourceUrl":"https://leg.colorado.gov/bills/sb24-205","tentative":false,"review":"verified"},{"id":202,"regulationId":"us-co-ai-act","date":"2026-05-14","title":"SB 26-189 signed (repeal and reenact)","description":"SB 26-189 replaces SB 24-205 with a narrower ADMT disclosure framework and moves the effective date to January 1, 2027.","kind":"transition","sourceUrl":"https://leg.colorado.gov/bills/sb26-189","tentative":false,"review":"verified"},{"id":203,"regulationId":"us-co-ai-act","date":"2026-06-30","title":"Delayed effective date (superseded)","description":"SB 25B-004 date; superseded by SB 26-189 before it arrived, so no obligations applied.","kind":"transition","sourceUrl":"https://leg.colorado.gov/bills/sb25b-004","tentative":false,"review":"verified"},{"id":204,"regulationId":"us-co-ai-act","date":"2027-01-01","title":"ADMT obligations apply","description":"Developer documentation, consumer notices, post-adverse-outcome disclosure, correction and human-review rights take effect.","kind":"effective","sourceUrl":"https://leg.colorado.gov/bills/sb26-189","tentative":false,"review":"verified"},{"id":205,"regulationId":"us-co-ai-act","date":"2027-01-01","title":"AG rules due","description":"Attorney General must adopt rules clarifying the post-adverse-outcome disclosure requirements.","kind":"compliance","sourceUrl":"https://leg.colorado.gov/bills/sb26-189","tentative":false,"review":"verified"},{"id":206,"regulationId":"us-co-ai-act","date":"2030-01-01","title":"Mandatory cure period ends","description":"The AG's obligation to offer a 60-day notice-and-cure period expires.","kind":"sunset","sourceUrl":"https://leg.colorado.gov/bills/sb26-189","tentative":false,"review":"verified"}]},{"id":"us-co-cpa","name":"Colorado Privacy Act (SB 21-190), C.R.S. 6-1-1301 et seq., as amended by HB 24-1130, SB 24-041 and SB 25-276","shortName":"Colorado Privacy Act (CPA)","jurisdiction":"us-co","jurisdictionName":"Colorado","region":"us-states","topics":["privacy","children","biometrics"],"status":"amended","citation":"SB 21-190 (2021 Colo. Sess. Laws ch. 483); C.R.S. 6-1-1301 to 6-1-1313; 4 CCR 904-3 (CPA Rules)","enactedDate":"2021-07-07","effectiveDate":"2023-07-01","summary":"Comprehensive privacy law giving Colorado consumers rights to access, correct, delete, port and opt out of targeted advertising, sale and certain profiling, with mandatory recognition of universal opt-out mechanisms and data protection assessments for high-risk processing. 2024 amendments added biometric identifier duties (July 1, 2025) and heightened protections for minors under 18 (Oct 1, 2025); 2025's SB 25-276 expanded precise geolocation rules and requires consent before selling sensitive data.","appliesTo":"Controllers doing business in Colorado or targeting Colorado residents that control or process personal data of 100,000+ consumers per year, or derive revenue or discounts from selling personal data and process personal data of 25,000+ consumers. Biometric provisions (HB 24-1130) and minors' provisions (SB 24-041) apply regardless of these volume thresholds.","penalties":"Violations are deceptive trade practices under the Colorado Consumer Protection Act: civil penalties up to $20,000 per violation (up to $50,000 per violation against an elderly person), per C.R.S. 6-1-112. 60-day cure period applied only until Jan 1, 2025.","enforcer":"Colorado Attorney General and district attorneys","sourceUrl":"https://leg.colorado.gov/bills/sb21-190","extraSources":["https://leg.colorado.gov/bills/hb24-1130","https://leg.colorado.gov/bills/sb24-041","https://leg.colorado.gov/bills/sb25-276","https://coag.gov/resources/colorado-privacy-act/"],"notes":"CO AG site (coag.gov) could not be fetched directly during verification; dates taken from leg.colorado.gov bill pages. The separate Colorado AI Act (SB 24-205, rewritten 2026) is a distinct law not covered here. No 2026 CPA amendments were confirmed; web search budget ran out before a full 2026 session check.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-24 02:56:54","deadlines":[{"id":207,"regulationId":"us-co-cpa","date":"2023-07-01","title":"CPA takes effect","description":"Core consumer rights and controller duties apply.","kind":"effective","sourceUrl":"https://leg.colorado.gov/bills/sb21-190","tentative":false,"review":"verified"},{"id":208,"regulationId":"us-co-cpa","date":"2024-07-01","title":"Universal opt-out mechanism recognition required","description":"Controllers must honor AG-recognized universal opt-out mechanisms (e.g. Global Privacy Control).","kind":"compliance","sourceUrl":"https://leg.colorado.gov/bills/sb21-190","tentative":false,"review":"verified"},{"id":209,"regulationId":"us-co-cpa","date":"2025-01-01","title":"60-day cure period expires","description":"Mandatory 60-day notice-and-cure before AG enforcement ends; enforcement may proceed without cure.","kind":"enforcement","sourceUrl":"https://leg.colorado.gov/bills/sb21-190","tentative":false,"review":"verified"},{"id":210,"regulationId":"us-co-cpa","date":"2025-05-23","title":"SB 25-276 geolocation and sensitive-data sale amendment effective","description":"Adds precise geolocation data definitions and prohibits selling sensitive data without consent (effective on signature).","kind":"effective","sourceUrl":"https://leg.colorado.gov/bills/sb25-276","tentative":false,"review":"verified"},{"id":211,"regulationId":"us-co-cpa","date":"2025-07-01","title":"Biometric identifier amendment (HB 24-1130) effective","description":"Any controller processing biometric identifiers must adopt a written biometric policy, give notice, obtain consent and follow retention/deletion rules.","kind":"effective","sourceUrl":"https://leg.colorado.gov/bills/hb24-1130","tentative":false,"review":"verified"},{"id":212,"regulationId":"us-co-cpa","date":"2025-10-01","title":"Minors' data amendment (SB 24-041) effective","description":"Controllers offering online services to minors must use reasonable care, conduct assessments, and obtain consent for targeted ads, sale and certain profiling of minors.","kind":"effective","sourceUrl":"https://leg.colorado.gov/bills/sb24-041","tentative":false,"review":"verified"}]},{"id":"us-ct-ctdpa","name":"Connecticut Data Privacy Act (Public Act 22-15), Conn. Gen. Stat. 42-515 et seq., as amended by Public Act 25-113 (SB 1295) and Public Act 26-64 (SB 4)","shortName":"Connecticut Data Privacy Act (CTDPA)","jurisdiction":"us-ct","jurisdictionName":"Connecticut","region":"us-states","topics":["privacy","children","ai","health"],"status":"amended","citation":"Public Act 22-15 (SB 6, 2022); Conn. Gen. Stat. 42-515 to 42-526; PA 25-113; PA 26-64","enactedDate":"2022-05-10","effectiveDate":"2023-07-01","summary":"Comprehensive privacy law with access, correction, deletion, portability and opt-out rights. PA 25-113 (effective July 1, 2026) sharply lowered applicability thresholds, broadened sensitive data, added profiling impact assessments, and requires disclosure of whether personal data is used to train large language models. PA 26-64 (effective Oct 1, 2026) bans the sale of precise geolocation data and creates a data broker registry (registration required from Jan 1, 2027) and a state deletion mechanism brokers must honor from Oct 1, 2028.","appliesTo":"From July 1, 2026: entities doing business in Connecticut or targeting residents that in the preceding calendar year (1) controlled or processed personal data of 35,000+ consumers (excluding payment-only data), (2) controlled or processed any consumers' sensitive data, or (3) offered consumers' personal data for sale. Before July 1, 2026: 100,000+ consumers, or 25,000+ consumers and more than 25% of gross revenue from selling personal data.","penalties":"Violations are unfair trade practices under CUTPA; civil penalties up to $5,000 per willful violation, plus restitution and injunctive relief. Mandatory 60-day cure period ended Dec 31, 2024; AG now has discretion to offer a cure.","enforcer":"Connecticut Attorney General","sourceUrl":"https://www.cga.ct.gov/2025/ACT/PA/PDF/2025PA-00113-R00SB-01295-PA.PDF","extraSources":["https://www.cga.ct.gov/asp/cgabillstatus/cgabillstatus.asp?selBillType=Bill&which_year=2022&bill_num=6","https://www.cga.ct.gov/2026/ACT/PA/PDF/2026PA-00064-R00SB-00004-PA.PDF","https://www.cga.ct.gov/asp/cgabillstatus/cgabillstatus.asp?selBillType=Bill&which_year=2026&bill_num=4","https://www.wiley.law/alert-Major-Changes-to-Connecticut-Consumer-Privacy-Law-Will-Take-Effect-July-1-2026"],"notes":"PA 25-113 is an omnibus act (also covers broadband, gaming, social media). Opt-out preference signal date (Jan 1, 2025) and CUTPA $5,000 willful-violation penalty are from the original act/CUTPA and not re-verified line by line. The DCP must establish the deletion mechanism by July 1, 2028. Consumer health data and minors' provisions added by PA 23-56 (2023) are folded into this record.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-24 02:56:54","deadlines":[{"id":215,"regulationId":"us-ct-ctdpa","date":"2023-07-01","title":"CTDPA takes effect","description":"Core consumer rights and controller obligations apply.","kind":"effective","sourceUrl":"https://www.cga.ct.gov/asp/cgabillstatus/cgabillstatus.asp?selBillType=Bill&which_year=2022&bill_num=6","tentative":false,"review":"verified"},{"id":216,"regulationId":"us-ct-ctdpa","date":"2024-12-31","title":"Mandatory 60-day cure period expires","description":"After Dec 31, 2024, the AG is no longer required to offer a 60-day cure before enforcement; cure becomes discretionary.","kind":"enforcement","sourceUrl":"https://www.cga.ct.gov/asp/cgabillstatus/cgabillstatus.asp?selBillType=Bill&which_year=2022&bill_num=6","tentative":false,"review":"verified"},{"id":217,"regulationId":"us-ct-ctdpa","date":"2025-01-01","title":"Universal opt-out preference signals required","description":"Controllers must honor opt-out preference signals for targeted advertising and sale (effective Jan 1, 2025).","kind":"compliance","sourceUrl":"https://www.cga.ct.gov/asp/cgabillstatus/cgabillstatus.asp?selBillType=Bill&which_year=2022&bill_num=6","tentative":false,"review":"verified"},{"id":218,"regulationId":"us-ct-ctdpa","date":"2026-07-01","title":"PA 25-113 (SB 1295) amendments take effect","description":"Thresholds drop to 35,000 consumers or any sensitive-data processing or data sale; expanded sensitive data, minors' protections, and LLM-training disclosure in privacy notices.","kind":"effective","sourceUrl":"https://www.cga.ct.gov/2025/ACT/PA/PDF/2025PA-00113-R00SB-01295-PA.PDF","tentative":false,"review":"verified"},{"id":219,"regulationId":"us-ct-ctdpa","date":"2026-08-01","title":"Profiling impact assessments apply","description":"Impact assessment requirements apply to profiling activities created or generated on or after Aug 1, 2026 (Conn. Gen. Stat. 42-522 as amended).","kind":"compliance","sourceUrl":"https://www.cga.ct.gov/2025/ACT/PA/PDF/2025PA-00113-R00SB-01295-PA.PDF","tentative":false,"review":"verified"},{"id":220,"regulationId":"us-ct-ctdpa","date":"2026-10-01","title":"PA 26-64 (SB 4) amendments take effect","description":"Prohibits controllers and third parties from selling precise geolocation data and enacts data broker and other consumer protection provisions.","kind":"effective","sourceUrl":"https://www.cga.ct.gov/2026/ACT/PA/PDF/2026PA-00064-R00SB-00004-PA.PDF","tentative":false,"review":"verified"},{"id":221,"regulationId":"us-ct-ctdpa","date":"2027-01-01","title":"Data broker registration required","description":"Data brokers may not sell or license brokered personal data in Connecticut unless registered with the Department of Consumer Protection ($2,500 initial fee).","kind":"compliance","sourceUrl":"https://www.cga.ct.gov/2026/ACT/PA/PDF/2026PA-00064-R00SB-00004-PA.PDF","tentative":false,"review":"verified"},{"id":222,"regulationId":"us-ct-ctdpa","date":"2028-10-01","title":"Data brokers must process state deletion mechanism requests","description":"Registered data brokers must access the DCP accessible deletion mechanism at least every 45 days and process deletion requests.","kind":"compliance","sourceUrl":"https://www.cga.ct.gov/2026/ACT/PA/PDF/2026PA-00064-R00SB-00004-PA.PDF","tentative":false,"review":"verified"}]},{"id":"eu-cra","name":"Regulation (EU) 2024/2847 on horizontal cybersecurity requirements for products with digital elements (Cyber Resilience Act)","shortName":"Cyber Resilience Act","jurisdiction":"eu","jurisdictionName":"European Union","region":"eu","topics":["cybersecurity","breach-notification"],"status":"enacted","citation":"OJ L, 2024/2847, 20.11.2024","enactedDate":"2024-10-23","effectiveDate":"2024-12-10","summary":"Sets mandatory cybersecurity requirements for hardware and software products with digital elements sold in the EU: secure by design, vulnerability handling, security updates for the support period, SBOMs, and CE marking after conformity assessment. Manufacturers must report actively exploited vulnerabilities and severe incidents to CSIRTs and ENISA from 11 Sep 2026.","appliesTo":"Manufacturers, importers and distributors of products with digital elements (connected hardware and software, including remote data processing solutions) made available on the EU market. Stricter conformity assessment for 'important' and 'critical' products. Non-commercial open source is largely excluded, with light-touch rules for open-source software stewards.","penalties":"Essential requirements and Arts 13-14 obligations: up to EUR 15M or 2.5% of worldwide annual turnover, whichever is higher. Other obligations: up to EUR 10M or 2%. Incorrect or misleading information: up to EUR 5M or 1% (Art 64).","enforcer":"National market surveillance authorities; CSIRTs and ENISA (vulnerability and incident reporting via the single reporting platform); European Commission","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2024/2847/oj","extraSources":[],"notes":"Status is 'enacted' because the main product obligations do not apply until 11 Dec 2027, although reporting obligations apply from 11 Sep 2026. No proposal to delay CRA dates was confirmed in this research. The Digital Omnibus's single-entry point for incident reporting is designed to build on the CRA single reporting platform.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-24 02:56:54","deadlines":[{"id":48,"regulationId":"eu-cra","date":"2024-12-10","title":"CRA enters into force","description":"Entered into force on the twentieth day after publication in the OJ on 20 Nov 2024 (Art 71(1)).","kind":"effective","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2024/2847/oj","tentative":false,"review":"verified"},{"id":49,"regulationId":"eu-cra","date":"2026-06-11","title":"Conformity assessment body provisions apply","description":"Chapter IV (Arts 35-51, notification of conformity assessment bodies) applies (Art 71(2)).","kind":"effective","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2024/2847/oj","tentative":false,"review":"verified"},{"id":50,"regulationId":"eu-cra","date":"2026-09-11","title":"Vulnerability and incident reporting obligations apply","description":"Art 14: manufacturers must report actively exploited vulnerabilities and severe incidents (24-hour early warning, 72-hour notification) via the single reporting platform. Also covers products placed on the market before 11 Dec 2027 (Art 69(3)).","kind":"reporting","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2024/2847/oj","tentative":false,"review":"verified"},{"id":51,"regulationId":"eu-cra","date":"2027-12-11","title":"CRA fully applies","description":"All remaining obligations, including essential cybersecurity requirements, conformity assessment and CE marking, apply (Art 71(2)). Products placed on the market earlier are covered only if substantially modified (Art 69(2)).","kind":"compliance","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2024/2847/oj","tentative":false,"review":"verified"},{"id":52,"regulationId":"eu-cra","date":"2028-06-11","title":"Legacy type-examination certificates expire","description":"EU type-examination certificates and approval decisions on cybersecurity requirements under other harmonisation legislation remain valid until this date unless they expire earlier (Art 69(1)).","kind":"sunset","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2024/2847/oj","tentative":false,"review":"verified"},{"id":53,"regulationId":"eu-cra","date":"2028-09-11","title":"Report on single reporting platform","description":"Commission report assessing the single reporting platform's effectiveness (Art 70(2)).","kind":"reporting","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2024/2847/oj","tentative":false,"review":"verified"},{"id":54,"regulationId":"eu-cra","date":"2030-12-11","title":"First CRA evaluation","description":"Commission evaluation and review report, then every four years (Art 70(1)).","kind":"reporting","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2024/2847/oj","tentative":false,"review":"verified"}]},{"id":"us-doj-bulk-data","name":"Preventing Access to U.S. Sensitive Personal Data and Government-Related Data by Countries of Concern or Covered Persons (28 CFR Part 202) - DOJ Data Security Program","shortName":"DOJ Bulk Data Rule","jurisdiction":"us","jurisdictionName":"United States (Federal)","region":"us-federal","topics":["privacy","data-residency","cybersecurity","biometrics","health","financial"],"status":"in_force","citation":"28 CFR Part 202; 90 FR 1636 (Jan. 8, 2025); Executive Order 14117; IEEPA (50 U.S.C. 1701 et seq.)","enactedDate":"2025-01-08","effectiveDate":"2025-04-08","summary":"Prohibits U.S. persons from data brokerage and genomic-data transactions with countries of concern or covered persons, and restricts vendor, employment and investment agreements involving bulk U.S. sensitive personal data or government-related data unless CISA security requirements are met. Restricted transactions require a data compliance program, due diligence, audits, recordkeeping and reporting.","appliesTo":"U.S. persons (companies and individuals) engaging in covered data transactions with China (incl. Hong Kong and Macau), Cuba, Iran, North Korea, Russia or Venezuela, or covered persons. Bulk thresholds over the preceding 12 months: human genomic data on 100+ U.S. persons; other human 'omic data or biometric identifiers on 1,000+; precise geolocation on 1,000+ devices; personal health or personal financial data on 10,000+; covered personal identifiers on 100,000+. Government-related data has no threshold.","penalties":"Civil penalty up to the greater of $368,136 (as stated in the rule; inflation-adjusted) or twice the transaction value per violation; willful violations up to $1,000,000 in fines and, for individuals, up to 20 years' imprisonment (IEEPA).","enforcer":"U.S. Department of Justice, National Security Division","sourceUrl":"https://www.federalregister.gov/documents/2025/01/08/2024-31486/preventing-access-to-us-sensitive-personal-data-and-government-related-data-by-countries-of-concern","extraSources":["https://www.ecfr.gov/current/title-28/chapter-I/part-202","https://www.justice.gov/nsd/data-security","https://www.federalregister.gov/documents/2025/04/18/2025-06477/pertaining-to-preventing-access-to-us-sensitive-personal-data-and-government-related-data-by"],"notes":"DOJ announced a 90-day limited enforcement period after April 8, 2025 for good-faith efforts (per DOJ NSD policy, not re-verified here). An April 18, 2025 technical amendment (90 FR 16466) corrected the rule. Penalty figure is the one printed in the January 2025 rule.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-24 02:56:54","deadlines":[{"id":227,"regulationId":"us-doj-bulk-data","date":"2025-04-08","title":"Prohibitions and restrictions take effect","description":"Core prohibitions on covered data transactions and security requirements for restricted transactions apply.","kind":"effective","sourceUrl":"https://www.federalregister.gov/documents/2025/01/08/2024-31486/preventing-access-to-us-sensitive-personal-data-and-government-related-data-by-countries-of-concern","tentative":false,"review":"verified"},{"id":228,"regulationId":"us-doj-bulk-data","date":"2025-10-06","title":"Due diligence, audit and reporting obligations apply","description":"Subpart J (data compliance program, due diligence and audits for restricted transactions) and reporting requirements in 202.1103 and 202.1104 apply.","kind":"compliance","sourceUrl":"https://www.federalregister.gov/documents/2025/01/08/2024-31486/preventing-access-to-us-sensitive-personal-data-and-government-related-data-by-countries-of-concern","tentative":false,"review":"verified"}]},{"id":"eu-dora","name":"Regulation (EU) 2022/2554 on digital operational resilience for the financial sector (Digital Operational Resilience Act)","shortName":"DORA","jurisdiction":"eu","jurisdictionName":"European Union","region":"eu","topics":["cybersecurity","financial","breach-notification"],"status":"in_force","citation":"OJ L 333, 27.12.2022, p. 1","enactedDate":"2022-12-14","effectiveDate":"2023-01-16","summary":"Harmonised ICT risk-management, major ICT-incident reporting, digital operational resilience testing (including threat-led penetration testing) and ICT third-party risk rules for EU financial entities. Financial entities must keep a register of all ICT third-party contracts. Critical ICT third-party providers (cloud, data centres and similar) come under direct EU oversight.","appliesTo":"About 20 types of EU financial entities (credit institutions, payment and e-money institutions, investment firms, crypto-asset service providers, insurers, trading venues, CCPs and others) and ICT third-party service providers designated as critical. Microenterprises and some small entities get a simplified framework.","penalties":"Administrative penalties for financial entities are set by Member States. Critical ICT third-party providers face periodic penalty payments of up to 1% of average daily worldwide turnover of the preceding business year, imposed daily for up to six months (Art 35(8)).","enforcer":"National competent authorities for financial supervision; the European Supervisory Authorities (EBA, EIOPA, ESMA) as Lead Overseers of critical ICT third-party providers","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2022/2554/oj","extraSources":["https://www.eba.europa.eu/publications-and-media/press-releases/esas-announce-timeline-collect-information-designation-critical-ict-third-party-service-providers","https://www.eba.europa.eu/publications-and-media/press-releases/european-supervisory-authorities-designate-critical-ict-third-party-providers-under-digital","https://eur-lex.europa.eu/eli/reg_del/2025/1190/oj"],"notes":"TLPT must be performed at least every three years by entities identified by their competent authority (Art 26). There is no single EU-wide first-test date; each authority notifies its entities. Registers of information are now collected annually; confirm each year's deadline with the national authority. The Digital Omnibus proposal COM(2025) 837 does not amend DORA in its title, but its single-entry point for incident reporting could interact with DORA reporting.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-24 02:56:54","deadlines":[{"id":70,"regulationId":"eu-dora","date":"2023-01-16","title":"DORA enters into force","description":"Entered into force on the twentieth day after publication in OJ L 333 of 27 Dec 2022 (Art 64).","kind":"effective","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2022/2554/oj","tentative":false,"review":"verified"},{"id":71,"regulationId":"eu-dora","date":"2025-01-17","title":"DORA applies","description":"All DORA obligations (ICT risk management, incident reporting, testing, third-party risk, register of information) apply from 17 Jan 2025 (Art 64).","kind":"effective","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2022/2554/oj","tentative":false,"review":"verified"},{"id":72,"regulationId":"eu-dora","date":"2025-04-30","title":"First registers of information submitted to the ESAs","description":"Competent authorities had to submit financial entities' registers of ICT third-party contractual arrangements (reference date 31 Mar 2025) to the ESAs by 30 Apr 2025. National authorities set earlier deadlines for entities.","kind":"reporting","sourceUrl":"https://www.eba.europa.eu/publications-and-media/press-releases/esas-announce-timeline-collect-information-designation-critical-ict-third-party-service-providers","tentative":false,"review":"verified"},{"id":73,"regulationId":"eu-dora","date":"2025-07-08","title":"TLPT regulatory technical standards enter into force","description":"Commission Delegated Regulation (EU) 2025/1190 (published 18 June 2025) sets criteria for which financial entities must run threat-led penetration testing, plus methodology and tester requirements.","kind":"effective","sourceUrl":"https://eur-lex.europa.eu/eli/reg_del/2025/1190/oj","tentative":false,"review":"verified"},{"id":74,"regulationId":"eu-dora","date":"2025-11-18","title":"First critical ICT third-party providers designated","description":"The ESAs published the first list of 19 critical ICT third-party providers (including AWS, Google Cloud and Microsoft), which now come under direct EU oversight.","kind":"enforcement","sourceUrl":"https://www.eba.europa.eu/publications-and-media/press-releases/european-supervisory-authorities-designate-critical-ict-third-party-providers-under-digital","tentative":false,"review":"verified"}]},{"id":"uk-duaa","name":"Data (Use and Access) Act 2025","shortName":"Data (Use and Access) Act","jurisdiction":"uk","jurisdictionName":"United Kingdom","region":"uk-europe","topics":["privacy","data-access","ai"],"status":"in_force","citation":"2025 c. 18","enactedDate":"2025-06-19","effectiveDate":"2025-08-20","summary":"Amends the UK GDPR, DPA 2018 and PECR (recognised legitimate interests, relaxed automated decision-making rules, reasonable-and-proportionate DSAR searches, new transfer test, cookie exemptions, PECR fines raised to UK GDPR levels), creates Smart Data schemes and digital verification services, and replaces the ICO with an Information Commission. Commenced in stages from August 2025 to 2026.","appliesTo":"All organisations subject to UK GDPR / PECR; Smart Data provisions apply to sectors designated by regulations; digital verification services providers.","penalties":"PECR fines raised to UK GDPR levels (up to GBP 17.5 million or 4% of worldwide annual turnover).","enforcer":"Information Commissioner's Office / Information Commission; DSIT for Smart Data and digital verification","sourceUrl":"https://www.legislation.gov.uk/ukpga/2025/18/contents","extraSources":["https://www.legislation.gov.uk/uksi/2026/82/contents/made","https://www.legislation.gov.uk/uksi/2026/1015/contents/made","https://www.hunton.com/privacy-and-information-security-law/uk-government-publishes-commencement-dates-for-the-uk-data-use-and-access-act","https://privacymatters.dlapiper.com/2026/02/uk-commencement-of-the-data-protection-provisions-in-the-data-use-and-access-act/"],"notes":"Stage 2 (digital verification services, retention of data on a child's death) was planned for roughly 3-4 months after Royal Assent (autumn 2025); exact date not verified so omitted. Further Stage 4 items (e.g. National Underground Asset Register, births/deaths registration) commence on separate dates not all verified.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-24 02:56:54","deadlines":[{"id":148,"regulationId":"uk-duaa","date":"2025-06-19","title":"Royal Assent","description":"The Act receives Royal Assent; commencement staged by regulations.","kind":"effective","sourceUrl":"https://www.legislation.gov.uk/ukpga/2025/18/contents","tentative":false,"review":"verified"},{"id":149,"regulationId":"uk-duaa","date":"2025-08-20","title":"Stage 1 commencement","description":"Technical data protection provisions, ICO statutory objects, Smart Data framework (Part 1) and AI/copyright reporting duties commence (Commencement No. 1 Regulations 2025).","kind":"effective","sourceUrl":"https://www.legislation.gov.uk/ukpga/2025/18/contents","tentative":false,"review":"verified"},{"id":150,"regulationId":"uk-duaa","date":"2026-02-05","title":"Stage 3: main data protection changes commence","description":"Recognised legitimate interests, ADM reforms, DSAR changes, international transfer test, cookie exemptions and PECR fines at UK GDPR levels apply (Commencement No. 6 Regulations 2026, reg. 2).","kind":"effective","sourceUrl":"https://www.legislation.gov.uk/uksi/2026/82/contents/made","tentative":false,"review":"verified"},{"id":151,"regulationId":"uk-duaa","date":"2026-06-19","title":"Mandatory data protection complaints procedure","description":"Controllers must have a process for data subject complaints (s.103 and Sch. 10), per Commencement No. 6 Regulations 2026, reg. 3.","kind":"compliance","sourceUrl":"https://www.legislation.gov.uk/uksi/2026/82/contents/made","tentative":false,"review":"verified"},{"id":152,"regulationId":"uk-duaa","date":"2026-09-30","title":"ICO abolished; Information Commission takes over","description":"Sections 118-119 commence: office of Information Commissioner abolished and functions transferred to the Information Commission (Commencement No. 9 Regulations 2026).","kind":"effective","sourceUrl":"https://www.legislation.gov.uk/uksi/2026/1015/regulation/2/made","tentative":false,"review":"verified"}]},{"id":"eu-dga","name":"Regulation (EU) 2022/868 on European data governance (Data Governance Act)","shortName":"Data Governance Act","jurisdiction":"eu","jurisdictionName":"European Union","region":"eu","topics":["data-access","privacy"],"status":"amended","citation":"OJ L 152, 3.6.2022, p. 1","enactedDate":"2022-05-30","effectiveDate":"2022-06-23","summary":"Sets conditions for re-use of protected public-sector data (personal data, trade secrets, IP) and creates a notification and neutrality regime for data intermediation services. It also sets up voluntary registration of 'recognised data altruism organisations'. Data intermediaries must stay neutral, separate the intermediation service from other services and notify a competent authority.","appliesTo":"Public sector bodies making protected data available for re-use and re-users; providers of data intermediation services (data marketplaces, data-sharing pools, data cooperatives) offered in the EU; data altruism organisations seeking recognition.","penalties":"Set by Member States (Art 34); no EU-level maximum.","enforcer":"National competent authorities for data intermediation services and data altruism; European Data Innovation Board","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2022/868/oj","extraSources":["https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:52025PC0837"],"notes":"The Digital Omnibus proposal COM(2025) 837 would repeal Regulation (EU) 2022/868 and move its content into the Data Act. It is still pending (not adopted as of Sept 2026), hence status 'amended' (amendment pending).","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-24 02:56:54","deadlines":[{"id":63,"regulationId":"eu-dga","date":"2022-06-23","title":"DGA enters into force","description":"Entered into force on the twentieth day after publication in OJ L 152 of 3 June 2022 (Art 38).","kind":"effective","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2022/868/oj","tentative":false,"review":"verified"},{"id":64,"regulationId":"eu-dga","date":"2023-09-24","title":"DGA applies","description":"All DGA rules apply (Art 38).","kind":"effective","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2022/868/oj","tentative":false,"review":"verified"},{"id":65,"regulationId":"eu-dga","date":"2025-09-24","title":"Legacy data intermediaries must comply","description":"Entities that were already providing data intermediation services on 23 June 2022 had to comply with Chapter III by 24 Sep 2025 (Art 37).","kind":"compliance","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2022/868/oj","tentative":false,"review":"verified"}]},{"id":"us-de-dpdpa","name":"Delaware Personal Data Privacy Act (HB 154), 6 Del. C. ch. 12D","shortName":"Delaware Personal Data Privacy Act (DPDPA)","jurisdiction":"us-de","jurisdictionName":"Delaware","region":"us-states","topics":["privacy","children"],"status":"amended","citation":"HB 154 (152nd GA), 84 Del. Laws c. 197; amended by 85 Del. Laws c. 463; 6 Del. C. 12D-101 to 12D-111","enactedDate":"2023-09-11","effectiveDate":"2025-01-01","summary":"Comprehensive privacy law with low applicability thresholds and no exemption for nonprofits. Grants rights to access, correct, delete, port, and opt out of targeted advertising, sale and profiling, and requires honoring opt-out preference signals from Jan 1, 2026. A 2026 amendment (85 Del. Laws c. 463) lowers thresholds further and adds third-party duties from Jan 1, 2027.","appliesTo":"Until Jan 1, 2027: persons doing business in Delaware or targeting residents that controlled or processed personal data of 35,000+ consumers (excluding payment-only data), or 10,000+ consumers and derived over 20% of gross revenue from selling personal data. From Jan 1, 2027: 10,000+ consumers, or 5,000+ consumers and over 20% of gross revenue from sale, plus third parties that acquire personal data from a controller.","penalties":"Violations are unlawful practices under 6 Del. C. 2513 and subchapter II of chapter 25 of Title 29, enforced by the Department of Justice (civil penalties up to $10,000 per willful violation under Delaware consumer fraud law). Mandatory 60-day cure ran Jan 1 - Dec 31, 2025; from Jan 1, 2026 cure is at DOJ discretion.","enforcer":"Delaware Department of Justice (Attorney General)","sourceUrl":"https://delcode.delaware.gov/title6/c012d/index.html","extraSources":[],"notes":"The 2026 amending act is cited in the Delaware Code as 85 Del. Laws c. 463; the underlying bill number and signing date were not verified. The per-violation penalty amount comes from Delaware's general consumer fraud enforcement law (the DPDPA itself does not state a dollar figure) and was not re-verified on the official code page.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-24 02:56:54","deadlines":[{"id":223,"regulationId":"us-de-dpdpa","date":"2025-01-01","title":"DPDPA takes effect","description":"Consumer rights and controller duties apply; 60-day mandatory cure period begins.","kind":"effective","sourceUrl":"https://delcode.delaware.gov/title6/c012d/index.html","tentative":false,"review":"verified"},{"id":224,"regulationId":"us-de-dpdpa","date":"2025-12-31","title":"Mandatory 60-day cure period expires","description":"Mandatory notice-and-cure ends Dec 31, 2025; from Jan 1, 2026 DOJ decides whether to offer a cure using statutory factors.","kind":"enforcement","sourceUrl":"https://delcode.delaware.gov/title6/c012d/index.html","tentative":false,"review":"verified"},{"id":225,"regulationId":"us-de-dpdpa","date":"2026-01-01","title":"Opt-out preference signals must be honored","description":"Controllers must allow opt-out of targeted advertising and sale via opt-out preference signals (12D-106).","kind":"compliance","sourceUrl":"https://delcode.delaware.gov/title6/c012d/index.html","tentative":false,"review":"verified"},{"id":226,"regulationId":"us-de-dpdpa","date":"2027-01-01","title":"Amended thresholds and third-party duties take effect","description":"Applicability drops to 10,000 consumers (or 5,000 + 20% revenue from sale) and new third-party duties (12D-107A) apply.","kind":"effective","sourceUrl":"https://delcode.delaware.gov/title6/c012d/index.html","tentative":false,"review":"verified"}]},{"id":"eu-dma","name":"Regulation (EU) 2022/1925 on contestable and fair markets in the digital sector (Digital Markets Act)","shortName":"Digital Markets Act","jurisdiction":"eu","jurisdictionName":"European Union","region":"eu","topics":["data-access","privacy"],"status":"in_force","citation":"OJ L 265, 12.10.2022, p. 1","enactedDate":"2022-09-14","effectiveDate":"2022-11-01","summary":"Imposes ex-ante do's and don'ts on designated gatekeepers. Examples: no combining personal data across services without consent, no self-preferencing, interoperability, data portability, and business-user data access. Gatekeepers must notify all acquisitions and submit an audited description of consumer profiling techniques.","appliesTo":"Undertakings providing a core platform service with annual EU turnover of at least EUR 7.5bn (or market capitalisation of at least EUR 75bn), in at least three Member States, with 45M+ monthly active EU end users and 10,000+ yearly active EU business users in each of the last three financial years (Art 3). Designated by the Commission.","penalties":"Up to 10% of total worldwide turnover; up to 20% for repeated infringement within 8 years. Up to 1% for procedural breaches (Art 30). Periodic penalties up to 5% of average daily turnover. Systematic non-compliance can lead to structural remedies.","enforcer":"European Commission (exclusive enforcer), assisted by national competition authorities","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2022/1925/oj","extraSources":["https://digital-markets-act.ec.europa.eu/gatekeepers_en","https://ec.europa.eu/commission/presscorner/detail/en/ip_23_4328"],"notes":"The 7 Mar 2024 compliance date comes from the six-month period after the 6 Sep 2023 designation (Art 8 / press release IP/23/4328); the press release itself says 'six months'. Later designations (e.g. Booking) have their own six-month deadlines.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-24 02:56:54","deadlines":[{"id":66,"regulationId":"eu-dma","date":"2022-11-01","title":"DMA enters into force","description":"Entered into force twenty days after publication; certain procedural articles apply from this date (Art 54).","kind":"effective","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2022/1925/oj","tentative":false,"review":"verified"},{"id":67,"regulationId":"eu-dma","date":"2023-05-02","title":"DMA applies","description":"DMA becomes applicable; undertakings meeting thresholds must notify the Commission within two months (Arts 3(3), 54).","kind":"effective","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2022/1925/oj","tentative":false,"review":"verified"},{"id":68,"regulationId":"eu-dma","date":"2023-09-06","title":"First six gatekeepers designated","description":"Commission designated Alphabet, Amazon, Apple, ByteDance, Meta and Microsoft (22 core platform services). They had six months to fully comply.","kind":"enforcement","sourceUrl":"https://digital-markets-act.ec.europa.eu/gatekeepers_en","tentative":false,"review":"verified"},{"id":69,"regulationId":"eu-dma","date":"2024-03-07","title":"Gatekeeper compliance deadline (first designations)","description":"First-wave gatekeepers had to comply with Arts 5-7 obligations and submit compliance reports six months after the 6 Sep 2023 designation.","kind":"compliance","sourceUrl":"https://ec.europa.eu/commission/presscorner/detail/en/ip_23_4328","tentative":false,"review":"verified"}]},{"id":"eu-digital-omnibus","name":"Proposal for a Regulation amending Regulations (EU) 2016/679, 2018/1724, 2018/1725, 2023/2854 and Directives 2002/58/EC, 2022/2555 and 2022/2557 as regards the simplification of the digital legislative framework (Digital Omnibus)","shortName":"Digital Omnibus (data/GDPR)","jurisdiction":"eu","jurisdictionName":"European Union","region":"eu","topics":["privacy","data-access","cybersecurity","breach-notification","ai"],"status":"proposed","citation":"COM(2025) 837 final, 2025/0360(COD)","enactedDate":"","effectiveDate":"","summary":"Commission proposal to simplify EU digital rules. It would amend the GDPR (personal data definition, processing for AI, a new cookie/terminal-equipment consent regime in Art 88a/88b, breach notification only for high-risk breaches within 96 hours) and the ePrivacy Directive, NIS2, CER Directive and Data Act. A single-entry point would handle incident reporting, and the Data Governance Act, Free Flow Regulation, Platform-to-Business Regulation and Open Data Directive would be repealed and merged into the Data Act. The AI Act part was split out and adopted separately as Regulation (EU) 2026/1744.","appliesTo":"Would affect all GDPR controllers/processors, website and app operators using cookies, NIS2/CER entities (incident reporting), and Data Act/DGA actors.","penalties":"No new penalties; existing regimes (GDPR, Data Act, NIS2) would continue to apply.","enforcer":"N/A (legislative proposal); European Parliament (ITRE/LIBE) and Council","sourceUrl":"https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:52025PC0837","extraSources":["https://www.europarl.europa.eu/legislative-train/theme-a-new-plan-for-europe-s-sustainable-prosperity-and-competitiveness/file-digital-package","https://digital-strategy.ec.europa.eu/en/library/digital-omnibus-regulation-proposal"],"notes":"Tabled 19 Nov 2025. Per the European Parliament Legislative Train (updated 1 Aug 2026): ITRE/LIBE joint draft report published 22 June 2026, amendment deadline 15 July 2026 with 1,750+ amendments, and no plenary vote date. A Council negotiating-mandate vote planned for 26 June 2026 was cancelled, and work continues under the Irish Presidency. No trilogues had started, and adoption is not expected before late 2026 at the earliest. No dates apply until it is adopted.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-24 02:56:54","deadlines":[]},{"id":"eu-dsa","name":"Regulation (EU) 2022/2065 on a Single Market for Digital Services (Digital Services Act)","shortName":"Digital Services Act","jurisdiction":"eu","jurisdictionName":"European Union","region":"eu","topics":["online-safety","children","privacy"],"status":"in_force","citation":"OJ L 277, 27.10.2022, p. 1","enactedDate":"2022-10-19","effectiveDate":"2022-11-16","summary":"Layered obligations for intermediary services: notice-and-action for illegal content, statements of reasons, complaint handling, transparency reporting, and ad and recommender transparency. Profiling-based ads to minors and ads based on sensitive data are banned. Very large online platforms and search engines (45M+ EU users) must also run annual systemic-risk assessments and audits and give researchers data access.","appliesTo":"Intermediary services offered to EU recipients (mere conduit, caching, hosting, online platforms, marketplaces, search engines). VLOP/VLOSE tier: 45 million or more average monthly active EU recipients, designated by the Commission. Micro and small enterprises are exempt from some platform duties.","penalties":"Up to 6% of annual worldwide turnover for failure to comply. Up to 1% for incorrect, incomplete or misleading information or failure to submit to inspection. Periodic penalty payments up to 5% of average daily worldwide turnover (Arts 52, 74).","enforcer":"European Commission (VLOPs/VLOSEs); national Digital Services Coordinators; European Board for Digital Services","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2022/2065/oj","extraSources":["https://digital-strategy.ec.europa.eu/en/policies/list-designated-vlops-and-vloses","https://digital-strategy.ec.europa.eu/en/news/commission-designates-chatgpt-reddit-roblox-under-digital-services-act"],"notes":"The exact compliance date for the Aug 2026 designations depends on the notification date (four months after notification); the Commission says 'by January 2027', so no exact deadline row. The 31 Aug 2026 date is the date of the Commission news item.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-24 02:56:54","deadlines":[{"id":75,"regulationId":"eu-dsa","date":"2022-11-16","title":"DSA enters into force","description":"Entered into force twenty days after publication; VLOP designation provisions (Art 33(3)-(6)) and Commission enforcement sections apply from this date (Art 93).","kind":"effective","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2022/2065/oj","tentative":false,"review":"verified"},{"id":76,"regulationId":"eu-dsa","date":"2023-02-17","title":"Platforms publish EU user numbers","description":"Online platforms and search engines had to publish average monthly active EU recipients, and must update them at least every six months (Art 24(2)).","kind":"reporting","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2022/2065/oj","tentative":false,"review":"verified"},{"id":77,"regulationId":"eu-dsa","date":"2023-04-25","title":"First VLOP/VLOSE designations","description":"Commission designated the first 19 very large online platforms and search engines (e.g. Amazon Store, Facebook, Google Search, TikTok, X). Obligations apply four months after notification.","kind":"enforcement","sourceUrl":"https://digital-strategy.ec.europa.eu/en/policies/list-designated-vlops-and-vloses","tentative":false,"review":"verified"},{"id":78,"regulationId":"eu-dsa","date":"2024-02-17","title":"DSA applies to all intermediary services","description":"Full application to all providers of intermediary services (Art 93(2)).","kind":"effective","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2022/2065/oj","tentative":false,"review":"verified"},{"id":79,"regulationId":"eu-dsa","date":"2026-08-31","title":"ChatGPT designated as VLOSE; Reddit and Roblox as VLOPs","description":"Commission designated ChatGPT as a very large online search engine and Reddit and Roblox as very large online platforms. They have four months (by January 2027) to meet VLOP/VLOSE obligations.","kind":"enforcement","sourceUrl":"https://digital-strategy.ec.europa.eu/en/news/commission-designates-chatgpt-reddit-roblox-under-digital-services-act","tentative":false,"review":"verified"}]},{"id":"eu-ai-act","name":"Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act), as amended by Regulation (EU) 2026/1744 (Digital Omnibus on AI)","shortName":"EU AI Act","jurisdiction":"eu","jurisdictionName":"European Union","region":"eu","topics":["ai","biometrics","children"],"status":"amended","citation":"OJ L, 2024/1689, 12.7.2024; amended by OJ L, 2026/1744, 24.7.2026","enactedDate":"2024-06-13","effectiveDate":"2024-08-01","summary":"A risk-based product-safety regime for AI. It bans certain AI practices, imposes strict requirements on high-risk AI systems (risk management, data governance, documentation, human oversight, conformity assessment), sets transparency duties for chatbots, deepfakes and AI-generated content, and sets obligations for general-purpose AI model providers. The Digital Omnibus on AI (Regulation (EU) 2026/1744, in force 27 July 2026) pushed the high-risk dates back to 2 December 2027 (Annex III) and 2 August 2028 (Annex I). It also softened the AI literacy duty and added bans on non-consensual sexual deepfakes and child sexual abuse material (CSAM) generation.","appliesTo":"Providers placing AI systems or general-purpose AI models on the EU market (wherever established), deployers of AI systems in the EU, importers, distributors, and non-EU providers/deployers whose AI output is used in the EU. GPAI models trained with more than 10^25 FLOPs are presumed to have systemic risk.","penalties":"Prohibited practices: up to EUR 35M or 7% of worldwide annual turnover, whichever is higher. Most other operator obligations: up to EUR 15M or 3%. Incorrect or misleading information to authorities: up to EUR 7.5M or 1%. For SMEs, and since the 2026 Omnibus also small mid-caps (SMCs), the lower of the two amounts applies. GPAI providers: Commission fines up to EUR 15M or 3% (Art 101).","enforcer":"National market surveillance authorities and notifying authorities; European Commission AI Office (GPAI models and AI systems built on them); European AI Board","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","extraSources":["https://eur-lex.europa.eu/eli/reg/2026/1744/oj","https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-113","https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-111","https://www.freshfields.com/en/our-thinking/blogs/technology-quotient/eu-ai-act-unpacked-34-the-final-digital-omnibus-on-ai-key-amendments-to-the-a-102nber"],"notes":"The Digital Omnibus on AI (Commission proposal 19 Nov 2025; EP position 16 June 2026; Council decision 29 June 2026; signed 8 July 2026) was published in the OJ on 24 July 2026 as Regulation (EU) 2026/1744 and has been in force since 27 July 2026. The high-risk delays are therefore legally binding, not tentative. Other Omnibus changes: Art 4 AI literacy recast as 'take measures to support' AI literacy (no guaranteed level); SME relief extended to small mid-caps; registration for Art 6(3) non-high-risk systems simplified; machinery moved from Annex I Section A to Section B; Commission guidance on post-market monitoring due 2 Sep 2027. Existing high-risk systems placed on the market before the relevant Chapter III date are covered only if significantly changed afterwards (Art 111(2)). The AI Act Service Desk article pages had not yet been updated to show the Omnibus text when checked.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-24 02:56:54","deadlines":[{"id":37,"regulationId":"eu-ai-act","date":"2024-08-01","title":"AI Act enters into force","description":"Regulation (EU) 2024/1689 enters into force twenty days after publication on 12 July 2024 (Art 113).","kind":"effective","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","tentative":false,"review":"verified"},{"id":38,"regulationId":"eu-ai-act","date":"2025-02-02","title":"Prohibited practices and AI literacy apply","description":"Chapters I and II apply, including the Article 5 bans on prohibited AI practices and the Article 4 AI literacy duty (Art 113(a)).","kind":"effective","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","tentative":false,"review":"verified"},{"id":39,"regulationId":"eu-ai-act","date":"2025-08-02","title":"GPAI, governance, notified bodies and penalties apply","description":"Chapter III Section 4 (notifying authorities), Chapter V (general-purpose AI model obligations), Chapter VII (governance), Chapter XII (penalties, except Art 101) and Art 78 apply (Art 113(b)).","kind":"effective","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","tentative":false,"review":"verified"},{"id":40,"regulationId":"eu-ai-act","date":"2026-07-27","title":"Digital Omnibus on AI enters into force","description":"Regulation (EU) 2026/1744 (adopted 8 July 2026, OJ 24 July 2026) enters into force on the third day after publication. Amended Articles 102 to 110 apply from this date (new Art 113(d)).","kind":"transition","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","tentative":false,"review":"verified"},{"id":41,"regulationId":"eu-ai-act","date":"2026-08-02","title":"General application: transparency obligations, GPAI fines, most other rules","description":"The AI Act's general date of application. Article 50 transparency obligations (chatbot disclosure, deepfake labelling, machine-readable marking of synthetic content) and Commission fines on GPAI providers (Art 101) apply. Not deferred by the Omnibus.","kind":"effective","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","tentative":false,"review":"verified"},{"id":42,"regulationId":"eu-ai-act","date":"2026-12-02","title":"New bans on sexual deepfakes and CSAM generation; Art 50(2) grace period ends","description":"New Art 5(1)(ba)/(bb) prohibitions on AI systems that generate non-consensual intimate imagery of identifiable persons or child sexual abuse material apply. Generative AI systems placed on the market before 2 Aug 2026 must comply with the Art 50(2) marking duty by this date (new Art 111(4)).","kind":"compliance","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","tentative":false,"review":"verified"},{"id":43,"regulationId":"eu-ai-act","date":"2027-08-02","title":"Legacy GPAI models must comply; national AI sandboxes operational","description":"Providers of GPAI models placed on the market before 2 Aug 2025 must comply (Art 111(3)). Each Member State must have at least one national AI regulatory sandbox operational (Art 57(1) as amended by the Omnibus).","kind":"compliance","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","tentative":false,"review":"verified"},{"id":44,"regulationId":"eu-ai-act","date":"2027-12-02","title":"High-risk obligations apply to Annex III systems","description":"Chapter III Sections 1-3 (high-risk requirements and provider/deployer obligations) apply to AI systems classified high-risk under Art 6(2) and Annex III (employment, credit scoring, education, biometrics, essential services and similar). Deferred from 2 Aug 2026 by Regulation (EU) 2026/1744.","kind":"compliance","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","tentative":false,"review":"verified"},{"id":45,"regulationId":"eu-ai-act","date":"2028-08-02","title":"High-risk obligations apply to Annex I product-embedded systems","description":"Chapter III Sections 1-3 apply to AI systems classified high-risk under Art 6(1) and Annex I (safety components of products covered by EU harmonisation legislation). Deferred from 2 Aug 2027 by Regulation (EU) 2026/1744.","kind":"compliance","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","tentative":false,"review":"verified"},{"id":46,"regulationId":"eu-ai-act","date":"2030-08-02","title":"Public-authority high-risk systems must comply","description":"Providers and deployers of high-risk AI systems intended for use by public authorities that were placed on the market before the Chapter III application date must comply (Art 111(2), as replaced by the Omnibus).","kind":"compliance","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","tentative":false,"review":"verified"},{"id":47,"regulationId":"eu-ai-act","date":"2030-12-31","title":"Large-scale EU IT systems must comply","description":"AI systems that are components of the large-scale IT systems in Annex X (e.g. SIS, VIS, Eurodac, EES, ETIAS) placed on the market before 2 Aug 2027 must be brought into compliance (Art 111(1)).","kind":"compliance","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","tentative":false,"review":"verified"}]},{"id":"eu-data-act","name":"Regulation (EU) 2023/2854 on harmonised rules on fair access to and use of data (Data Act)","shortName":"EU Data Act","jurisdiction":"eu","jurisdictionName":"European Union","region":"eu","topics":["data-access","privacy"],"status":"in_force","citation":"OJ L, 2023/2854, 22.12.2023","enactedDate":"2023-12-13","effectiveDate":"2024-01-11","summary":"Gives users of connected products and related services the right to access and share the data those products generate, and sets rules for business-to-business data sharing. It bans unfair data-sharing contract terms imposed on businesses and lets public bodies obtain data in cases of exceptional need. Cloud and other data processing service providers must make switching easy, and switching charges are phased out.","appliesTo":"Manufacturers of connected products and providers of related services placed on the EU market; data holders and data recipients; providers of data processing services (cloud/edge) to EU customers; participants in data spaces. Micro and small enterprises are exempt from some data-holder obligations.","penalties":"Set by Member States (Art 40), which had to notify their rules by 12 Sep 2025. Where personal data is involved, data protection authorities may impose GDPR-level fines (up to EUR 20M or 4% of worldwide turnover).","enforcer":"National competent authorities designated by each Member State (data coordinator); data protection authorities for personal data; European Data Innovation Board (EDIB)","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2023/2854/oj","extraSources":["https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:52025PC0837","https://www.europarl.europa.eu/legislative-train/theme-a-new-plan-for-europe-s-sustainable-prosperity-and-competitiveness/file-digital-package"],"notes":"The Digital Omnibus proposal COM(2025) 837 would amend the Data Act and fold in the Data Governance Act, Free Flow of Non-Personal Data Regulation and Open Data Directive. Still under negotiation as of Sept 2026 (Legislative Train status 'tabled', 1 Aug 2026), so no Data Act dates have changed.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-24 02:56:54","deadlines":[{"id":55,"regulationId":"eu-data-act","date":"2024-01-11","title":"Data Act enters into force","description":"Entered into force on the twentieth day after publication in the OJ on 22 Dec 2023 (Art 50).","kind":"effective","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2023/2854/oj","tentative":false,"review":"verified"},{"id":56,"regulationId":"eu-data-act","date":"2024-01-11","title":"Reduced switching charges period begins","description":"From 11 Jan 2024 to 12 Jan 2027, data processing providers may charge only reduced switching fees, capped at costs directly linked to switching (Art 29(2)-(3)).","kind":"transition","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2023/2854/oj","tentative":false,"review":"verified"},{"id":57,"regulationId":"eu-data-act","date":"2025-09-12","title":"Data Act applies","description":"Most obligations apply, including user data access and sharing (Chapters II-III), cloud switching (Chapter VI) and interoperability; Chapter IV unfair terms apply to contracts concluded after this date (Art 50).","kind":"effective","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2023/2854/oj","tentative":false,"review":"verified"},{"id":58,"regulationId":"eu-data-act","date":"2025-09-12","title":"Member States notify penalty rules","description":"Member States had to notify the Commission of their penalty rules (Art 40(2)).","kind":"reporting","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2023/2854/oj","tentative":false,"review":"verified"},{"id":59,"regulationId":"eu-data-act","date":"2026-09-12","title":"Access-by-design for new connected products","description":"Art 3(1) design obligation (product data and related service data accessible to the user by default) applies to connected products and related services placed on the market after 12 Sep 2026.","kind":"compliance","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2023/2854/oj","tentative":false,"review":"verified"},{"id":60,"regulationId":"eu-data-act","date":"2027-01-12","title":"Cloud switching charges abolished","description":"Providers of data processing services may no longer impose any switching charges on customers (Art 29(1)).","kind":"compliance","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2023/2854/oj","tentative":false,"review":"verified"},{"id":61,"regulationId":"eu-data-act","date":"2027-09-12","title":"Unfair-terms rules extend to older long-term contracts","description":"Chapter IV (unfair contractual terms) applies to contracts concluded on or before 12 Sep 2025 that are of indefinite duration or expire at least 10 years from 11 Jan 2024 (Art 50).","kind":"compliance","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2023/2854/oj","tentative":false,"review":"verified"},{"id":62,"regulationId":"eu-data-act","date":"2028-09-12","title":"Commission evaluation","description":"Commission evaluation report due, including the impact of cloud switching rules (Arts 23-31) (Art 49(2)).","kind":"reporting","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2023/2854/oj","tentative":false,"review":"verified"}]},{"id":"eu-us-dpf","name":"Commission Implementing Decision (EU) 2023/1795 on the adequate level of protection of personal data under the EU-US Data Privacy Framework","shortName":"EU-US Data Privacy Framework","jurisdiction":"eu","jurisdictionName":"European Union","region":"eu","topics":["privacy","data-residency"],"status":"in_force","citation":"OJ L 231, 20.9.2023, p. 118 (notified under document C(2023)4745)","enactedDate":"2023-07-10","effectiveDate":"2023-07-10","summary":"GDPR Art 45 adequacy decision letting personal data flow from the EEA to US organisations self-certified under the Data Privacy Framework with the US Department of Commerce, with no further transfer mechanism needed. It relies on US Executive Order 14086 safeguards and the Data Protection Review Court for redress. The EU General Court upheld it in Latombe v Commission (T-553/23) on 3 Sep 2025, and an appeal is pending before the Court of Justice.","appliesTo":"EEA exporters transferring personal data to US organisations on the DPF List (self-certified, under FTC or DOT jurisdiction). Transfers to non-certified US recipients still need SCCs/BCRs, which benefit from the same US safeguards.","penalties":"No standalone fines; unlawful transfers fall under GDPR Art 83(5) (up to EUR 20M or 4% of worldwide turnover). US certified organisations face FTC/DOT enforcement.","enforcer":"European Commission (monitoring, periodic review); EU data protection authorities; US Department of Commerce, FTC and DOT","sourceUrl":"https://eur-lex.europa.eu/eli/dec_impl/2023/1795/oj","extraSources":["https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/eu-us-data-transfers_en","https://curia.europa.eu/jcms/upload/docs/application/pdf/2025-09/cp250106en.pdf","https://iapp.org/news/a/european-general-court-dismisses-latombe-challenge-upholds-eu-us-data-privacy-framework","https://www.wilmerhale.com/en/insights/blogs/wilmerhale-privacy-and-cybersecurity-law/20251201-european-court-of-justice-to-review-challenge-to-eu-us-data-privacy-framework"],"notes":"Art 3(4) required a first review one year after notification. The Commission completed the first periodic review in October 2024 (exact date not re-verified here), with the next review expected after about three years. Appeal case number C-703/25 P and the 31 Oct 2025 lodging date come from secondary sources, not CURIA directly. No CJEU hearing or judgment was found as of the research date. The decision's validity also depends on US safeguards (EO 14086, PCLOB functioning), which the Commission monitors.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-24 02:56:54","deadlines":[{"id":108,"regulationId":"eu-us-dpf","date":"2023-07-10","title":"DPF adequacy decision adopted and effective","description":"Commission adopted Implementing Decision (EU) 2023/1795, effective on notification to Member States; EU-US transfers to DPF-certified organisations may proceed without additional safeguards.","kind":"effective","sourceUrl":"https://eur-lex.europa.eu/eli/dec_impl/2023/1795/oj","tentative":false,"review":"verified"},{"id":109,"regulationId":"eu-us-dpf","date":"2025-09-03","title":"General Court upholds DPF (Latombe v Commission)","description":"General Court dismissed Philippe Latombe's action for annulment (Case T-553/23) and confirmed the US offered adequate protection when the decision was adopted.","kind":"enforcement","sourceUrl":"https://curia.europa.eu/jcms/upload/docs/application/pdf/2025-09/cp250106en.pdf","tentative":false,"review":"verified"},{"id":110,"regulationId":"eu-us-dpf","date":"2025-10-31","title":"Latombe appeal lodged at the Court of Justice","description":"Latombe appealed the General Court judgment to the Court of Justice on points of law (reported as Case C-703/25 P); the DPF stays valid while it is pending.","kind":"enforcement","sourceUrl":"https://www.wilmerhale.com/en/insights/blogs/wilmerhale-privacy-and-cybersecurity-law/20251201-european-court-of-justice-to-review-challenge-to-eu-us-data-privacy-framework","tentative":false,"review":"verified"}]},{"id":"eu-ehds","name":"Regulation (EU) 2025/327 on the European Health Data Space","shortName":"European Health Data Space (EHDS)","jurisdiction":"eu","jurisdictionName":"European Union","region":"eu","topics":["health","privacy","data-access"],"status":"enacted","citation":"OJ L, 2025/327, 5.3.2025","enactedDate":"2025-02-11","effectiveDate":"2025-03-25","summary":"Gives individuals electronic access to, and control over, their health data across the EU (primary use), with a cross-border MyHealth@EU infrastructure and mandatory requirements for electronic health record (EHR) systems. It also creates a permit-based framework for secondary use of health data (research, innovation, policy) through national Health Data Access Bodies, with data holders required to make data available.","appliesTo":"Health data holders (healthcare providers, researchers, companies holding electronic health data; micro-enterprises largely exempt as data holders), manufacturers and distributors of EHR systems and wellness apps claiming interoperability, health data users seeking secondary use, and Member State digital health authorities.","penalties":"Secondary-use infringements by data holders/users: up to EUR 10M or 2% of worldwide annual turnover, and up to EUR 20M or 4% for the most serious infringements, e.g. unlawful re-identification or use outside a data permit (Art 64). Member States set other penalties.","enforcer":"National digital health authorities, Health Data Access Bodies, market surveillance authorities (EHR systems), data protection authorities; EHDS Board and European Commission","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2025/327/oj","extraSources":[],"notes":"Some provisions (e.g. Art 55(6), 70, 73(5), 75(1),(12), 77(4), 78(6)) apply from 26 Mar 2027. Many details depend on implementing acts still being adopted. The effective date is computed as the twentieth day after the 5 Mar 2025 OJ publication.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-24 02:56:54","deadlines":[{"id":80,"regulationId":"eu-ehds","date":"2025-03-25","title":"EHDS enters into force","description":"Regulation (EU) 2025/327, published 5 Mar 2025, enters into force on the twentieth day following publication.","kind":"effective","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2025/327/oj","tentative":false,"review":"verified"},{"id":81,"regulationId":"eu-ehds","date":"2027-03-26","title":"EHDS general application date","description":"The regulation applies generally from 26 Mar 2027, subject to the phased exceptions below (final article).","kind":"effective","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2025/327/oj","tentative":false,"review":"verified"},{"id":82,"regulationId":"eu-ehds","date":"2029-03-26","title":"Primary use for first data categories; secondary use framework applies","description":"Patient rights and EHR rules apply to patient summaries, ePrescriptions and eDispensations (Art 14(1)(a)-(c)). Chapter IV secondary-use rules (data permits, Health Data Access Bodies) apply.","kind":"compliance","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2025/327/oj","tentative":false,"review":"verified"},{"id":83,"regulationId":"eu-ehds","date":"2031-03-26","title":"Primary use for second data categories; EHR systems in service; extra secondary-use categories","description":"Primary-use rules extend to medical images, lab results and discharge reports (Art 14(1)(d)-(f)). Chapter III applies to EHR systems put into service under Art 26(2). Additional secondary-use categories in Art 51(1)(b),(f),(g),(m),(p) apply.","kind":"compliance","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2025/327/oj","tentative":false,"review":"verified"},{"id":84,"regulationId":"eu-ehds","date":"2035-03-26","title":"Third-country participation in secondary use","description":"Art 75(5) applies from 26 Mar 2035.","kind":"effective","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2025/327/oj","tentative":false,"review":"verified"}]},{"id":"us-fcc-cpni-breach","name":"FCC Data Breach Reporting Requirements for telecommunications carriers, interconnected VoIP and TRS providers (47 CFR 64.2011, 64.5111)","shortName":"FCC CPNI Breach Rule","jurisdiction":"us","jurisdictionName":"United States (Federal)","region":"us-federal","topics":["privacy","breach-notification","cybersecurity"],"status":"amended","citation":"47 CFR 64.2011 and 64.5111; FCC 23-111, WC Docket No. 22-21; 89 FR 9968 (Feb. 12, 2024)","enactedDate":"2024-02-12","effectiveDate":"2024-03-13","summary":"The 2023 order expands carrier breach rules from CPNI to all customer personally identifiable information, covers inadvertent disclosures, requires notice to the FCC (in addition to the Secret Service and FBI) within seven business days, and adopts a harm-based trigger for customer notice. Until the revised 64.2011 takes effect, the existing CPNI breach rule (law enforcement notice within 7 business days, customer notice after a waiting period) continues to apply.","appliesTo":"Telecommunications carriers, interconnected VoIP providers, and telecommunications relay service (TRS) providers. As adopted, breaches affecting fewer than 500 customers with no reasonable likelihood of harm may be reported in an annual summary.","penalties":"Forfeitures under the Communications Act (47 U.S.C. 503); no rule-specific amount.","enforcer":"Federal Communications Commission (Enforcement Bureau)","sourceUrl":"https://www.federalregister.gov/documents/2024/02/12/2024-01667/data-breach-reporting-requirements","extraSources":["https://www.ecfr.gov/current/title-47/chapter-I/subchapter-B/part-64/subpart-U/section-64.2011","https://www.opn.ca6.uscourts.gov/opinions.pdf/25a0224p-06.pdf"],"notes":"As of 2026-09-22 eCFR still shows the revised 64.2011 as a pending amendment (89 FR 10002) and no Federal Register notice announcing its effective date was found. The Sixth Circuit upheld the order in Ohio Telecom Ass'n v. FCC (Aug. 2025).","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-24 02:56:54","deadlines":[{"id":229,"regulationId":"us-fcc-cpni-breach","date":"2024-03-13","title":"Order effective except revised notification rules","description":"Definitions and other parts of the order took effect; the revised 64.2011 and 64.5111 notification requirements were delayed pending OMB approval.","kind":"effective","sourceUrl":"https://www.federalregister.gov/documents/2024/02/12/2024-01667/data-breach-reporting-requirements","tentative":false,"review":"verified"}]},{"id":"us-ftc-hbnr","name":"FTC Health Breach Notification Rule (16 CFR Part 318), as amended 2024","shortName":"FTC Health Breach Notification Rule","jurisdiction":"us","jurisdictionName":"United States (Federal)","region":"us-federal","topics":["health","privacy","breach-notification"],"status":"amended","citation":"16 CFR Part 318; 74 FR 42962 (2009); amendments 89 FR 47028 (May 30, 2024)","enactedDate":"2009-08-25","effectiveDate":"2009-09-24","summary":"Requires vendors of personal health records (including health and wellness apps) and PHR related entities not covered by HIPAA to notify affected individuals, the FTC and, for 500+ residents of a state, prominent media, after a breach of unsecured PHR identifiable health information. The 2024 amendments confirm that unauthorized disclosures (not just hacks) are breaches, clarify coverage of health apps drawing data from multiple sources, allow email notice, and expand notice content.","appliesTo":"Vendors of personal health records, PHR related entities, and their third-party service providers that are not HIPAA covered entities or business associates. Notice to individuals within 60 calendar days of discovery; FTC notice for breaches of 500+ individuals contemporaneously with individual notice; smaller breaches logged and reported annually.","penalties":"Treated as violations of an FTC trade regulation rule: civil penalties up to $53,088 per violation (FTC Act 5(m)(1)(A) amount as adjusted January 2025, 90 FR 5580; adjusted annually for inflation).","enforcer":"Federal Trade Commission","sourceUrl":"https://www.federalregister.gov/documents/2024/05/30/2024-10855/health-breach-notification-rule","extraSources":["https://www.ecfr.gov/current/title-16/chapter-I/subchapter-C/part-318","https://www.federalregister.gov/citation/74-FR-42962"],"notes":"Prior FTC enforcement: GoodRx ($1.5 million civil penalty, 2023) and Easy Healthcare ($100,000, 2023), cited in the 2024 rule.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-24 02:56:54","deadlines":[{"id":231,"regulationId":"us-ftc-hbnr","date":"2010-02-22","title":"Full compliance with original Rule","description":"Full compliance with the 2009 Health Breach Notification Rule was required.","kind":"compliance","sourceUrl":"https://www.federalregister.gov/citation/74-FR-42962","tentative":false,"review":"verified"},{"id":232,"regulationId":"us-ftc-hbnr","date":"2024-07-29","title":"2024 amendments effective","description":"Amendments clarifying health app coverage, unauthorized disclosure as breach, email notice and FTC notice timing took effect.","kind":"effective","sourceUrl":"https://www.federalregister.gov/documents/2024/05/30/2024-10855/health-breach-notification-rule","tentative":false,"review":"verified"}]},{"id":"us-fl-fdbr","name":"Florida Digital Bill of Rights (CS/CS/SB 262, 2023)","shortName":"Florida Digital Bill of Rights","jurisdiction":"us-fl","jurisdictionName":"Florida","region":"us-states","topics":["privacy","children"],"status":"in_force","citation":"Fla. Stat. 501.701 to 501.722 (Ch. 2023-201, Laws of Fla.)","enactedDate":"2023-06-07","effectiveDate":"2024-07-01","summary":"Privacy law aimed at very large tech companies: access, correction, deletion, portability and opt-out rights (sale, targeted ads, profiling), opt-in consent for sensitive data, voice/face recognition limits, data retention schedules and protections for known children. Separately, any for-profit business that sells sensitive data must post a notice, and the sale-of-sensitive-data consent rule applies beyond the big-tech controllers.","appliesTo":"Controllers: for-profit entities doing business in Florida with over $1 billion in global gross annual revenue that also (a) derive 50%+ of global revenue from online ad sales, (b) operate a consumer smart speaker and voice command service with a cloud-connected virtual assistant, or (c) operate an app store or digital distribution platform with at least 250,000 software applications (501.702(9)). Some provisions (e.g. sensitive data sale) reach other for-profit entities.","penalties":"Unfair and deceptive trade practice enforceable only by the Department of Legal Affairs: civil penalty up to $50,000 per violation, tripled for violations involving known children, failure to delete or correct after a verified request, or continuing to sell/share after opt-out (501.72(1)). The Department may grant a 45-day cure period at its discretion (not available for child violations) (501.72(2)). No private right of action.","enforcer":"Florida Department of Legal Affairs (Attorney General)","sourceUrl":"https://www.flsenate.gov/Session/Bill/2023/262","extraSources":["http://www.leg.state.fl.us/statutes/index.cfm?App_mode=Display_Statute&URL=0500-0599/0501/Sections/0501.72.html","http://www.leg.state.fl.us/statutes/index.cfm?App_mode=Display_Statute&URL=0500-0599/0501/Sections/0501.702.html"],"notes":"Approved by the Governor June 7, 2023 (Ch. 2023-201), per the Florida Senate bill page. The cure period is discretionary and has no sunset. The app-store threshold (250,000 apps) is from the statute's controller definition, sub-subparagraph c; only (a) and (b) were read verbatim. No amendments found through Sept 2026.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-24 02:56:54","deadlines":[{"id":230,"regulationId":"us-fl-fdbr","date":"2024-07-01","title":"Florida Digital Bill of Rights takes effect","description":"SB 262 obligations under Fla. Stat. 501.701-501.722 apply.","kind":"effective","sourceUrl":"https://www.flsenate.gov/Session/Bill/2023/262","tentative":false,"review":"verified"}]},{"id":"eu-gdpr","name":"Regulation (EU) 2016/679 (General Data Protection Regulation)","shortName":"GDPR","jurisdiction":"eu","jurisdictionName":"European Union","region":"eu","topics":["privacy","breach-notification","data-access","children","biometrics","health"],"status":"amended","citation":"OJ L 119, 4.5.2016, p. 1","enactedDate":"2016-04-27","effectiveDate":"2016-05-24","summary":"The EU's core data protection law: any processing of personal data needs a lawful basis, must follow principles such as purpose limitation and data minimisation, and gives individuals rights of access, erasure, portability and objection. Controllers must notify breaches to the supervisory authority within 72 hours and restrict transfers outside the EEA to adequate countries or safeguarded mechanisms. Regulation (EU) 2025/2518 adds harmonised procedural rules for cross-border enforcement from 2 April 2027.","appliesTo":"Controllers and processors established in the EU, and non-EU controllers/processors that offer goods or services to, or monitor the behaviour of, individuals in the EU. No revenue or volume threshold; some record-keeping relief below 250 employees.","penalties":"Up to EUR 20M or 4% of total worldwide annual turnover of the preceding year, whichever is higher (Art 83(5)); up to EUR 10M or 2% for other infringements (Art 83(4)).","enforcer":"National data protection supervisory authorities (DPAs), coordinated by the European Data Protection Board (EDPB) via the one-stop-shop mechanism","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2016/679/oj","extraSources":["https://eur-lex.europa.eu/eli/reg/2025/2518/oj","https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:52025PC0837","https://www.europarl.europa.eu/legislative-train/theme-a-new-plan-for-europe-s-sustainable-prosperity-and-competitiveness/file-digital-package","https://www.consilium.europa.eu/en/press/press-releases/2025/11/17/council-adopts-new-eu-law-to-speed-up-handling-cross-border-data-protection-complaints/"],"notes":"Digital Omnibus proposal COM(2025) 837 (19 Nov 2025, procedure 2025/0360(COD)) would amend the GDPR: clarify the definition of personal data, move cookie/terminal-equipment consent from the ePrivacy Directive into a new GDPR Art 88a, add machine-readable preference signals (Art 88b), and require breach notification to DPAs only for high-risk breaches within 96 hours via a single-entry point. As of the Parliament Legislative Train update of 1 Aug 2026 it is still 'tabled': ITRE/LIBE draft report 22 June 2026, 1,750+ amendments, no plenary vote, a planned Council mandate vote on 26 June 2026 was cancelled, and no trilogues. None of these changes are law. The procedural regulation's 12- and 15-month investigation timelines are reported by the Council; check the regulation text for exact extensions.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-24 02:56:54","deadlines":[{"id":93,"regulationId":"eu-gdpr","date":"2016-05-24","title":"GDPR enters into force","description":"Regulation entered into force on the twentieth day after publication in OJ L 119 of 4 May 2016 (Art 99(1)).","kind":"effective","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2016/679/oj","tentative":false,"review":"verified"},{"id":94,"regulationId":"eu-gdpr","date":"2018-05-25","title":"GDPR applies","description":"All GDPR obligations apply from 25 May 2018 (Art 99(2)), replacing Directive 95/46/EC.","kind":"effective","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2016/679/oj","tentative":false,"review":"verified"},{"id":95,"regulationId":"eu-gdpr","date":"2025-11-26","title":"GDPR Procedural Regulation adopted","description":"Regulation (EU) 2025/2518 laying down additional procedural rules for cross-border GDPR enforcement signed by Parliament and Council.","kind":"transition","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2025/2518/oj","tentative":false,"review":"verified"},{"id":96,"regulationId":"eu-gdpr","date":"2026-01-01","title":"GDPR Procedural Regulation enters into force","description":"Regulation (EU) 2025/2518, published in the OJ on 12 December 2025, enters into force on the twentieth day after publication.","kind":"transition","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2025/2518/oj","tentative":false,"review":"verified"},{"id":97,"regulationId":"eu-gdpr","date":"2027-04-02","title":"GDPR Procedural Regulation applies","description":"Harmonised rules for cross-border complaint admissibility, rights to be heard and access to preliminary findings, and investigation timelines apply to DPAs from 2 April 2027 (Regulation (EU) 2025/2518, final article).","kind":"enforcement","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2025/2518/oj","tentative":false,"review":"verified"}]},{"id":"us-glba-safeguards","name":"FTC Standards for Safeguarding Customer Information (Safeguards Rule), 16 CFR Part 314, under the Gramm-Leach-Bliley Act","shortName":"GLBA Safeguards Rule","jurisdiction":"us","jurisdictionName":"United States (Federal)","region":"us-federal","topics":["financial","cybersecurity","breach-notification","privacy"],"status":"amended","citation":"15 U.S.C. 6801(b), 6805(b)(2); 16 CFR Part 314; amendments at 86 FR 70272 (2021) and 88 FR 77499 (2023)","enactedDate":"1999-11-12","effectiveDate":"2003-05-23","summary":"Requires non-bank financial institutions under FTC jurisdiction to maintain a written information security program with a qualified individual, risk assessments, access controls, encryption, MFA, monitoring and board reporting. Since May 13, 2024, institutions must notify the FTC within 30 days of discovering a 'notification event' (unauthorized acquisition of unencrypted customer information) affecting at least 500 consumers.","appliesTo":"Financial institutions subject to FTC jurisdiction (e.g. mortgage brokers, lenders, auto dealers, tax preparers, payment and fintech companies, and other non-bank entities significantly engaged in financial activities). Certain program elements (written risk assessment, continuous monitoring/pen testing, incident response plan, annual board report) do not apply to institutions holding customer information on fewer than 5,000 consumers.","penalties":"The Rule itself carries no civil penalty; the FTC enforces through Section 5 of the FTC Act (injunctive orders), with civil penalties for violating resulting orders.","enforcer":"Federal Trade Commission","sourceUrl":"https://www.ecfr.gov/current/title-16/chapter-I/subchapter-C/part-314","extraSources":["https://www.federalregister.gov/documents/2023/11/13/2023-24412/standards-for-safeguarding-customer-information","https://www.federalregister.gov/documents/2022/11/23/2022-25201/standards-for-safeguarding-customer-information","https://www.federalregister.gov/documents/2021/12/09/2021-25736/standards-for-safeguarding-customer-information"],"notes":"Banks and credit unions follow the parallel Interagency Guidelines, not this Rule. FTC notices of notification events may be made public.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-24 02:56:54","deadlines":[{"id":233,"regulationId":"us-glba-safeguards","date":"2022-01-10","title":"2021 Safeguards Rule amendments effective","description":"The amended Safeguards Rule published December 9, 2021 took effect, with the more detailed program elements in 314.5 deferred.","kind":"effective","sourceUrl":"https://www.federalregister.gov/documents/2021/12/09/2021-25736/standards-for-safeguarding-customer-information","tentative":false,"review":"verified"},{"id":234,"regulationId":"us-glba-safeguards","date":"2023-06-09","title":"Compliance with expanded security program elements","description":"Applicability of the 314.5 provisions (qualified individual, written risk assessment, encryption, MFA, pen testing, incident response plan, board reporting) was delayed from December 9, 2022 to this date.","kind":"compliance","sourceUrl":"https://www.federalregister.gov/documents/2022/11/23/2022-25201/standards-for-safeguarding-customer-information","tentative":false,"review":"verified"},{"id":235,"regulationId":"us-glba-safeguards","date":"2024-05-13","title":"FTC breach notification requirement effective","description":"Section 314.4(j) requires notice to the FTC within 30 days of discovering a notification event involving at least 500 consumers.","kind":"effective","sourceUrl":"https://www.federalregister.gov/documents/2023/11/13/2023-24412/standards-for-safeguarding-customer-information","tentative":false,"review":"verified"}]},{"id":"us-hipaa","name":"HIPAA Privacy, Security and Breach Notification Rules (45 CFR Parts 160 and 164)","shortName":"HIPAA","jurisdiction":"us","jurisdictionName":"United States (Federal)","region":"us-federal","topics":["privacy","health","cybersecurity","breach-notification"],"status":"amended","citation":"Pub. L. 104-191; 42 U.S.C. 1320d et seq.; 45 CFR Parts 160 and 164","enactedDate":"1996-08-21","effectiveDate":"2003-04-14","summary":"Sets national standards for the use and disclosure of protected health information (Privacy Rule), administrative, physical and technical safeguards for electronic PHI (Security Rule), and notification of breaches of unsecured PHI. A proposed overhaul of the Security Rule (Jan. 2025 NPRM) would make most 'addressable' specifications mandatory, require asset inventories, MFA, encryption, annual compliance audits and 72-hour restoration planning, but it is not final. The 2024 reproductive health care privacy amendments were vacated nationwide in June 2025.","appliesTo":"Covered entities (health plans, health care clearinghouses, and health care providers that conduct standard electronic transactions) and their business associates, including cloud and data vendors that create, receive, maintain or transmit PHI. No size threshold.","penalties":"Civil money penalties, 2026 inflation-adjusted (91 FR 3665): tiered from $145 to $73,011 per violation, with a calendar-year cap of $2,190,294 per identical provision. Criminal penalties under 42 U.S.C. 1320d-6 up to $250,000 and 10 years' imprisonment for offenses with intent to sell or use PHI for commercial advantage or malicious harm.","enforcer":"HHS Office for Civil Rights (OCR); State Attorneys General (HITECH); DOJ for criminal violations","sourceUrl":"https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164","extraSources":["https://www.federalregister.gov/documents/2025/01/06/2024-30983/hipaa-security-rule-to-strengthen-the-cybersecurity-of-electronic-protected-health-information","https://www.federalregister.gov/documents/2024/04/26/2024-08503/hipaa-privacy-rule-to-support-reproductive-health-care-privacy","https://www.federalregister.gov/documents/2026/01/28/2026-01688/annual-civil-monetary-penalties-inflation-adjustment","https://www.reginfo.gov/public/do/eAgendaViewRule?pubId=202510&RIN=0945-AA22","https://www.hklaw.com/en/insights/publications/2025/06/hipaas-reproductive-health-rule-is-vacated-nationally","https://www.americanbar.org/groups/health_law/news/2025/signaling-end-purl-case/"],"notes":"Security Rule NPRM (90 FR 898, Jan. 6, 2025; RIN 0945-AA22): the Unified Agenda lists final action for 07/2027 (month only, so no deadline row). The NPRM proposed a compliance date 180 days after a final rule's effective date. Reproductive health rule vacated June 18, 2025 (Purl v. HHS, N.D. Tex.), except NPP amendments tied to Part 2; the Fifth Circuit dismissed the appeal in September 2025 (per ABA/law firm reporting). Original Privacy Rule compliance date April 14, 2003 (small health plans April 14, 2004); Security Rule compliance April 20, 2005. HHS also exercises 2019 enforcement discretion capping annual penalties per tier below the statutory cap.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-24 02:56:54","deadlines":[{"id":236,"regulationId":"us-hipaa","date":"2024-06-25","title":"Reproductive health care privacy rule effective (later vacated)","description":"The HIPAA Privacy Rule to Support Reproductive Health Care Privacy (89 FR 32976) took effect; it was vacated nationwide on June 18, 2025 in Purl v. HHS (N.D. Tex.).","kind":"effective","sourceUrl":"https://www.federalregister.gov/documents/2024/04/26/2024-08503/hipaa-privacy-rule-to-support-reproductive-health-care-privacy","tentative":false,"review":"verified"},{"id":237,"regulationId":"us-hipaa","date":"2024-12-23","title":"Reproductive health privacy compliance date (vacated)","description":"Original compliance date for the reproductive health care privacy provisions, including the attestation requirement; these provisions no longer apply after the June 2025 vacatur.","kind":"compliance","sourceUrl":"https://www.federalregister.gov/documents/2024/04/26/2024-08503/hipaa-privacy-rule-to-support-reproductive-health-care-privacy","tentative":false,"review":"verified"},{"id":238,"regulationId":"us-hipaa","date":"2025-03-07","title":"Security Rule NPRM comment period closed","description":"Comments closed on the proposed HIPAA Security Rule update (90 FR 898); OCR has not issued a final rule.","kind":"transition","sourceUrl":"https://www.federalregister.gov/documents/2025/01/06/2024-30983/hipaa-security-rule-to-strengthen-the-cybersecurity-of-electronic-protected-health-information","tentative":false,"review":"verified"},{"id":239,"regulationId":"us-hipaa","date":"2026-02-16","title":"Notice of Privacy Practices updates (Part 2 alignment)","description":"Covered entities must update Notices of Privacy Practices under 45 CFR 164.520 for the 2024 Part 2 (substance use disorder records) changes; this NPP piece survived the Purl vacatur.","kind":"compliance","sourceUrl":"https://www.federalregister.gov/documents/2024/04/26/2024-08503/hipaa-privacy-rule-to-support-reproductive-health-care-privacy","tentative":false,"review":"verified"}]},{"id":"hk-pcico","name":"Protection of Critical Infrastructures (Computer Systems) Ordinance (Cap. 653)","shortName":"Hong Kong Critical Infrastructure Cyber Ordinance","jurisdiction":"hk","jurisdictionName":"Hong Kong","region":"apac","topics":["cybersecurity","breach-notification"],"status":"in_force","citation":"Cap. 653","enactedDate":"2025-03-28","effectiveDate":"2026-01-01","summary":"Hong Kong's critical infrastructure cybersecurity law. Designated critical infrastructure operators (CIOs) must keep a Hong Kong office, set up a computer-system security management unit, run risk assessments and audits, keep security and emergency plans, take part in drills, and report incidents. Serious incidents must be reported within 12 hours and other incidents within 48 hours.","appliesTo":"Operators designated by regulators in 8 sectors: energy, IT, banking and financial services, air transport, land transport, maritime transport, healthcare, and telecommunications and broadcasting (plus other infrastructure critical to society). Only designated CIOs and their designated critical computer systems are covered.","penalties":"Fines from HKD 300,000 up to HKD 5 million, plus daily fines for continuing offences.","enforcer":"Commissioner of Critical Infrastructure (Computer-system Security) under the Security Bureau; Hong Kong Monetary Authority and Communications Authority as designated authorities for their sectors","sourceUrl":"https://www.elegislation.gov.hk/hk/cap653","extraSources":["https://www.info.gov.hk/gia/general/202506/27/P2025062700238.htm","https://www.coms-auth.hk/en/policies_regulations/other/pcicso/index.html","https://www.mayerbrown.com/en/insights/publications/2026/01/hong-kong-issues-code-of-practice-under-the-protection-of-critical-infrastructures-computer-systems-ordinance"],"notes":"Gazetted 28 Mar 2025 (the date used as enacted_date); commencement notice gazetted 27 Jun 2025. Duties for each operator run from its designation date, so there is no fixed calendar deadline. The penalty range comes from the Baker McKenzie summary. Reporting windows come from the Code of Practice via Mayer Brown.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-24 02:56:54","deadlines":[{"id":111,"regulationId":"hk-pcico","date":"2026-01-01","title":"PCICSO comes into operation","description":"Commissioner's Office is established and designation of CIOs begins; obligations apply to designated operators.","kind":"effective","sourceUrl":"https://www.info.gov.hk/gia/general/202506/27/P2025062700238.htm","tentative":false,"review":"verified"}]},{"id":"us-il-hb3773","name":"Illinois HB 3773 (Public Act 103-0804), amending the Illinois Human Rights Act on artificial intelligence in employment","shortName":"Illinois AI in Employment Law (HB 3773)","jurisdiction":"us-il","jurisdictionName":"Illinois","region":"us-states","topics":["ai"],"status":"in_force","citation":"Public Act 103-0804; 775 ILCS 5/2-102(L)","enactedDate":"2024-08-09","effectiveDate":"2026-01-01","summary":"Makes it a civil-rights violation for an employer to use AI that has the effect of discriminating against employees or applicants on the basis of a protected class in recruitment, hiring, promotion, discipline, discharge or the terms of employment. It also bars using ZIP codes as a proxy for a protected class. Employers must notify employees when they use AI for these decisions; IDHR is to set the notice rules.","appliesTo":"Employers covered by the Illinois Human Rights Act, generally those with 1 or more employees in Illinois, using AI (including generative AI) for covered employment decisions.","penalties":"Remedies under the Illinois Human Rights Act (e.g., actual damages, back pay, attorney fees) through IDHR charge process and Human Rights Commission or civil action. No AI-specific fine amount.","enforcer":"Illinois Department of Human Rights; Illinois Human Rights Commission; private civil action after the IDHR process","sourceUrl":"https://www.ilga.gov/ftp/legislation/103/BillStatus/HTML/10300HB3773.html","extraSources":["https://ogletree.com/insights-resources/blog-posts/illinois-postpones-proposed-regulations-on-ai-in-employment/"],"notes":"The statute applies without implementing rules. As of September 2026, IDHR's notice rules were withdrawn and pending, with no timeline announced. The 1-employee IHRA coverage threshold is general IHRA law and was not re-verified for this record.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-24 02:56:54","deadlines":[{"id":244,"regulationId":"us-il-hb3773","date":"2024-08-09","title":"HB 3773 signed","description":"Governor Pritzker signs Public Act 103-0804.","kind":"transition","sourceUrl":"https://www.ilga.gov/ftp/legislation/103/BillStatus/HTML/10300HB3773.html","tentative":false,"review":"verified"},{"id":245,"regulationId":"us-il-hb3773","date":"2026-01-01","title":"AI anti-discrimination and notice duties apply","description":"Prohibition on discriminatory AI use and the employee notice requirement take effect.","kind":"effective","sourceUrl":"https://www.ilga.gov/ftp/legislation/103/BillStatus/HTML/10300HB3773.html","tentative":false,"review":"verified"},{"id":246,"regulationId":"us-il-hb3773","date":"2026-05-15","title":"IDHR proposed notice rules published","description":"IDHR publishes proposed Subpart J rules on AI notice in the Illinois Register.","kind":"transition","sourceUrl":"https://ogletree.com/insights-resources/blog-posts/illinois-postpones-proposed-regulations-on-ai-in-employment/","tentative":false,"review":"verified"},{"id":247,"regulationId":"us-il-hb3773","date":"2026-06-02","title":"IDHR withdraws and postpones proposed rules","description":"IDHR withdraws the Subpart J proposal and postpones the June 10, 2026 hearing; no new date announced.","kind":"transition","sourceUrl":"https://ogletree.com/insights-resources/blog-posts/illinois-postpones-proposed-regulations-on-ai-in-employment/","tentative":false,"review":"verified"}]},{"id":"us-il-bipa","name":"Illinois Biometric Information Privacy Act (740 ILCS 14), as amended by SB 2979 (Public Act 103-0769)","shortName":"Illinois BIPA","jurisdiction":"us-il","jurisdictionName":"Illinois","region":"us-states","topics":["biometrics","privacy"],"status":"amended","citation":"740 ILCS 14; Public Act 95-994; Public Act 103-0769","enactedDate":"","effectiveDate":"2008-10-03","summary":"Private entities must publish a biometric retention and destruction policy, give written notice, and obtain a written release before collecting biometric identifiers such as fingerprints, face geometry or voiceprints. They may not sell or profit from biometric data and need consent to disclose it. The 2024 SB 2979 amendment treats repeated collection or disclosure from the same person by the same method as a single violation and allows electronic signatures for consent. The Seventh Circuit held on April 1, 2026 that the amendment applies retroactively to pending cases.","appliesTo":"Any private entity (individual, company, partnership, etc.) collecting, capturing, purchasing, receiving, possessing or disclosing biometric identifiers or information of Illinois residents. No size threshold; government agencies excluded.","penalties":"Private right of action: $1,000 liquidated damages per negligent violation or $5,000 per intentional or reckless violation (or actual damages if greater), plus attorney fees. After PA 103-0769, at most one recovery per person per method of collection.","enforcer":"Private right of action (courts)","sourceUrl":"https://www.ilga.gov/legislation/ilcs/ilcs3.asp?ActID=3004&ChapterID=57","extraSources":["https://www.ilga.gov/Legislation/publicacts/view/103-0769","https://law.justia.com/cases/federal/appellate-courts/ca7/25-2185/25-2185-2026-04-01.html"],"notes":"BIPA's enacted date is not included here; its effective date comes from Public Act 95-994. The Illinois Supreme Court has not ruled on whether the amendment is retroactive, so the Seventh Circuit decision binds federal courts only.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-24 02:56:54","deadlines":[{"id":241,"regulationId":"us-il-bipa","date":"2008-10-03","title":"BIPA effective","description":"The Biometric Information Privacy Act takes effect.","kind":"effective","sourceUrl":"https://www.ilga.gov/legislation/ilcs/ilcs3.asp?ActID=3004&ChapterID=57","tentative":false,"review":"verified"},{"id":242,"regulationId":"us-il-bipa","date":"2024-08-02","title":"SB 2979 amendment effective","description":"Public Act 103-0769 signed and effective immediately: single recovery per person and electronic signatures allowed for consent.","kind":"effective","sourceUrl":"https://www.ilga.gov/Legislation/publicacts/view/103-0769","tentative":false,"review":"verified"},{"id":243,"regulationId":"us-il-bipa","date":"2026-04-01","title":"Seventh Circuit: amendment applies retroactively","description":"Clay v. Union Pacific (No. 25-2185) holds the damages amendment is remedial and applies to pending cases.","kind":"transition","sourceUrl":"https://law.justia.com/cases/federal/appellate-courts/ca7/25-2185/25-2185-2026-04-01.html","tentative":false,"review":"verified"}]},{"id":"in-dpdp","name":"Digital Personal Data Protection Act, 2023 and Digital Personal Data Protection Rules, 2025","shortName":"India DPDP Act","jurisdiction":"in","jurisdictionName":"India","region":"apac","topics":["privacy","children","breach-notification"],"status":"enacted","citation":"Act No. 22 of 2023; DPDP Rules 2025 G.S.R. 846(E) (13 Nov 2025); Act commencement notification G.S.R. 843(E)","enactedDate":"2023-08-11","effectiveDate":"2025-11-13","summary":"India's first comprehensive data protection law: consent-based processing with notice, data principal rights, security safeguards, breach notification to the Data Protection Board and affected individuals, verifiable parental consent for children under 18, and extra duties for Significant Data Fiduciaries. The Rules notified in November 2025 phase it in: Board and procedure now, consent managers at 12 months, and main fiduciary obligations at 18 months.","appliesTo":"Processing of digital personal data in India, and processing outside India connected with offering goods or services to data principals in India. No revenue or volume threshold; Significant Data Fiduciaries (designated by the government on volume and risk) have extra duties (DPO in India, annual DPIA and audit).","penalties":"Schedule to the Act: up to INR 250 crore for failing to take reasonable security safeguards to prevent a breach; up to INR 200 crore for failing to notify a breach or breaching children's-data obligations; up to INR 150 crore for Significant Data Fiduciary obligations; up to INR 50 crore for other breaches. Imposed by the Data Protection Board.","enforcer":"Data Protection Board of India (MeitY)","sourceUrl":"https://egazette.gov.in/WriteReadData/2025/267650.pdf","extraSources":["https://www.meity.gov.in/documents/act-and-policies/digital-personal-data-protection-rules-2025","https://dpdprules.org/rules/1"],"notes":"Fact-check 2026-09-22 against the eGazette PDF: Gazette of India Extraordinary No. 760, Part II Section 3(i), dated Thursday 13 November 2025, G.S.R. 846(E). The eGazette ID CG-DL-E-14112025-267650 reflects upload on 14 Nov 2025, which is why some sources cite 14 Nov; the publication date is 13 Nov 2025. Rule 1(3) and 1(4) run 'one year' and 'eighteen months after the date of publication of this Gazette', giving 13 Nov 2026 and 13 May 2027. Corrigendum G.S.R. 892(E) of 11 Dec 2025 fixed wording only. MeitY consulted in early 2026 on shortening the 18-month runway to 12 months; not notified as of verification. The MeitY page is JavaScript-rendered and could not be read directly; dates come from the Rule 1 text in the gazette.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-24 02:56:54","deadlines":[{"id":116,"regulationId":"in-dpdp","date":"2025-11-13","title":"DPDP Rules published; Board and procedural rules in force","description":"Rules 1, 2 and 17-21 (Data Protection Board constitution and functioning) take effect on publication in the Official Gazette.","kind":"effective","sourceUrl":"https://egazette.gov.in/WriteReadData/2025/267650.pdf","tentative":false,"review":"verified"},{"id":117,"regulationId":"in-dpdp","date":"2026-11-13","title":"Consent Manager registration rule in force (12 months)","description":"Rule 4 (registration and obligations of Consent Managers) comes into force one year after publication.","kind":"transition","sourceUrl":"https://egazette.gov.in/WriteReadData/2025/267650.pdf","tentative":false,"review":"verified"},{"id":118,"regulationId":"in-dpdp","date":"2027-05-13","title":"Main data fiduciary obligations apply (18 months)","description":"Rules 3, 5-16, 22 and 23 (notice, security safeguards, breach notification, retention, children's consent, SDF duties, cross-border) come into force 18 months after publication.","kind":"compliance","sourceUrl":"https://egazette.gov.in/WriteReadData/2025/267650.pdf","tentative":false,"review":"verified"}]},{"id":"us-in-icdpa","name":"Indiana Consumer Data Protection Act (SEA 5, 2023), Ind. Code 24-15","shortName":"Indiana Consumer Data Protection Act (ICDPA)","jurisdiction":"us-in","jurisdictionName":"Indiana","region":"us-states","topics":["privacy"],"status":"in_force","citation":"Senate Enrolled Act 5 (2023), P.L. 94-2023; Ind. Code 24-15-1 to 24-15-11","enactedDate":"2023-05-01","effectiveDate":"2026-01-01","summary":"Virginia-style comprehensive privacy law granting rights to confirm, access, correct, delete, obtain a copy of, and opt out of targeted advertising, sale and profiling. Requires consent for sensitive data processing and data protection impact assessments for high-risk processing.","appliesTo":"Persons doing business in Indiana or targeting Indiana residents that during a calendar year control or process personal data of 100,000+ Indiana consumers, or 25,000+ consumers and derive over 50% of gross revenue from the sale of personal data.","penalties":"Civil penalty up to $7,500 per violation plus injunctive relief. Permanent 30-day cure period (no sunset): AG must give 30 days' written notice and may not sue if the violation is cured.","enforcer":"Indiana Attorney General (exclusive)","sourceUrl":"https://iga.in.gov/legislative/2023/bills/senate/5/details","extraSources":["https://iapp.org/resources/article/us-state-privacy-legislation-tracker"],"notes":"Official Indiana legislature pages are JavaScript-rendered and could not be text-extracted during verification; thresholds, $7,500 penalty and permanent 30-day cure are consistent with IAPP and law-firm trackers. The cure period has no sunset, so there is no cure-expiry deadline. No 2025-2026 amendments confirmed.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-24 02:56:54","deadlines":[{"id":248,"regulationId":"us-in-icdpa","date":"2026-01-01","title":"ICDPA takes effect","description":"Consumer rights and controller/processor obligations apply; assessments required for processing activities created on or after this date.","kind":"effective","sourceUrl":"https://iga.in.gov/legislative/2023/bills/senate/5/details","tentative":false,"review":"verified"}]},{"id":"id-pdp","name":"Law No. 27 of 2022 on Personal Data Protection (Undang-Undang Pelindungan Data Pribadi)","shortName":"Indonesia PDP Law","jurisdiction":"id","jurisdictionName":"Indonesia","region":"apac","topics":["privacy","breach-notification","data-residency","children"],"status":"amended","citation":"Law No. 27 of 2022; implementing Government Regulation No. 33 of 2026","enactedDate":"2022-10-17","effectiveDate":"2022-10-17","summary":"Indonesia's GDPR-style data protection law: lawful bases, data subject rights, DPIAs for high-risk processing, DPOs, breach notification within 3x24 hours, and cross-border transfer rules. Full compliance was required after a 2-year transition ending 17 October 2024. Government Regulation 33/2026 (enacted 16 July 2026, effective 16 January 2027) adds implementing detail, including parental consent for children and cross-border transfer mechanisms.","appliesTo":"Any person, public body or international organization processing personal data in Indonesia, or abroad where the processing has legal effect in Indonesia or on Indonesian citizens abroad.","penalties":"Administrative fines up to 2% of annual revenue or receipts (per violating variable). Criminal penalties up to 4-6 years imprisonment and fines up to IDR 4-6 billion for individuals; corporate criminal fines up to 10x the maximum.","enforcer":"PDP Agency (not yet established); interim supervision by the Ministry of Communication and Digital Affairs (Komdigi)","sourceUrl":"https://peraturan.bpk.go.id/Details/229798/uu-no-27-tahun-2022","extraSources":["https://www.kk-advocates.com/news/read/indonesia-gr-pdp-personal-data-protection-compliance-regime-new-phase","https://conventuslaw.com/report/indonesia-personal-data-protection-under-2026-implementing-regulation/"],"notes":"GR 33/2026 dates come from law-firm reports; an official JDIH link was not found. One source says the PDP Law was amended by Law No. 1 of 2026 (probably criminal-provision alignment with the new Criminal Code, in force 2 Jan 2026), which is why status is 'amended'; this is unverified. The PDP Agency has still not been formed. The BPK JDIH source_url could not be fetched automatically (403), so the page ID should be confirmed.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-24 02:56:54","deadlines":[{"id":112,"regulationId":"id-pdp","date":"2022-10-17","title":"PDP Law enacted and in force","description":"Law takes effect on enactment, starting a 2-year transition.","kind":"effective","sourceUrl":"https://peraturan.bpk.go.id/Details/229798/uu-no-27-tahun-2022","tentative":false,"review":"verified"},{"id":113,"regulationId":"id-pdp","date":"2024-10-17","title":"PDP Law transition ends","description":"Controllers and processors must fully comply (Art. 74 two-year transition).","kind":"compliance","sourceUrl":"https://peraturan.bpk.go.id/Details/229798/uu-no-27-tahun-2022","tentative":false,"review":"verified"},{"id":114,"regulationId":"id-pdp","date":"2027-01-16","title":"Implementing regulation GR 33/2026 takes effect","description":"Detailed PDP implementing rules (DPIA, cross-border, children's consent) apply, 6 months after the 16 Jul 2026 enactment.","kind":"compliance","sourceUrl":"https://www.kk-advocates.com/news/read/indonesia-gr-pdp-personal-data-protection-compliance-regime-new-phase","tentative":false,"review":"verified"}]},{"id":"us-ia-icdpa","name":"Iowa Consumer Data Protection Act (SF 262, 2023), Iowa Code ch. 715D","shortName":"Iowa Consumer Data Protection Act (ICDPA)","jurisdiction":"us-ia","jurisdictionName":"Iowa","region":"us-states","topics":["privacy"],"status":"in_force","citation":"SF 262 (2023 Iowa Acts ch. 17); Iowa Code 715D.1-715D.9","enactedDate":"2023-03-28","effectiveDate":"2025-01-01","summary":"Business-friendly comprehensive privacy law giving rights to confirm, access, delete, obtain a copy of, and opt out of sale and targeted advertising (no correction right, no profiling opt-out). Sensitive data requires notice and an opt-out opportunity rather than opt-in consent.","appliesTo":"Persons conducting business in Iowa or targeting Iowa residents that during a calendar year control or process personal data of 100,000+ consumers, or 25,000+ consumers and derive over 50% of gross revenue from the sale of personal data.","penalties":"Civil penalties up to $7,500 per violation plus injunctive relief. Permanent 90-day cure period (no sunset): AG must give 90 days' written notice and may not sue if cured with a written statement.","enforcer":"Iowa Attorney General (exclusive)","sourceUrl":"https://www.legis.iowa.gov/docs/code/715D.pdf","extraSources":[],"notes":"90-day cure period is permanent, so no cure-expiry deadline. No 2025-2026 amendments found.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-24 02:56:54","deadlines":[{"id":240,"regulationId":"us-ia-icdpa","date":"2025-01-01","title":"ICDPA takes effect","description":"Consumer rights and controller/processor obligations apply.","kind":"effective","sourceUrl":"https://www.legis.iowa.gov/docs/code/715D.pdf","tentative":false,"review":"verified"}]},{"id":"il-ppl-amendment-13","name":"Privacy Protection Law, 5741-1981 (Amendment No. 13)","shortName":"Israel Privacy Protection Law Amendment 13","jurisdiction":"il","jurisdictionName":"Israel","region":"mea","topics":["privacy","breach-notification"],"status":"amended","citation":"Privacy Protection Law, 5741-1981, Amendment No. 13 (5784-2024)","enactedDate":"2024-08-05","effectiveDate":"2025-08-14","summary":"Major overhaul of Israel's privacy law: broadens definitions (personal and highly sensitive information), narrows database registration, requires privacy protection officers for certain entities, and gives the Privacy Protection Authority powers to impose large administrative fines and orders, plus statutory damages.","appliesTo":"Controllers and holders of databases in Israel; DPO requirement for public bodies, data brokers, and entities whose core activities involve large-scale systematic monitoring or processing of highly sensitive data.","penalties":"Administrative fines scaled to the number of data subjects and data sensitivity, reaching millions of shekels; statutory damages up to ILS 10,000 per violation without proof of harm; criminal offences.","enforcer":"Privacy Protection Authority (PPA)","sourceUrl":"https://www.gov.il/en/departments/the_privacy_protection_authority/govil-landing-page","extraSources":["https://www.pearlcohen.com/israel-significant-amendment-to-the-privacy-law-takes-effect/"],"notes":"Knesset approval 5 Aug 2024 from recollection/secondary sources. Exact fine tables not reproduced to avoid error.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-24 02:56:54","deadlines":[{"id":115,"regulationId":"il-ppl-amendment-13","date":"2025-08-14","title":"Amendment 13 in force","description":"Amended Privacy Protection Law, PPA enforcement powers and statutory damages take effect.","kind":"effective","sourceUrl":"https://www.gov.il/en/departments/the_privacy_protection_authority/govil-landing-page","tentative":false,"review":"verified"}]},{"id":"jp-ai-act","name":"Act on Promotion of Research and Development, and Utilization of Artificial Intelligence-Related Technology","shortName":"Japan AI Promotion Act","jurisdiction":"jp","jurisdictionName":"Japan","region":"apac","topics":["ai"],"status":"in_force","citation":"Enacted by the 217th Diet (bill submitted 28 Feb 2025)","enactedDate":"2025-05-28","effectiveDate":"2025-06-04","summary":"A framework law to promote AI R&D and use, not to restrict it. It sets up the AI Strategy Headquarters under the Prime Minister and an AI Basic Plan. The government can investigate cases where AI causes harm to rights and publish guidance and names. It sets no direct compliance obligations or fines for businesses, beyond a duty to cooperate with government measures.","appliesTo":"National and local government, research institutions, and businesses using or developing AI (duty to cooperate). No thresholds.","penalties":"None. No administrative fines or criminal penalties; the government may issue guidance, investigate, and publicize inappropriate cases.","enforcer":"AI Strategy Headquarters (Cabinet), Cabinet Office","sourceUrl":"https://www8.cao.go.jp/cstp/ai/ai_act/ai_act.html","extraSources":["https://www.cao.go.jp/houan/217/index.html","https://fpf.org/blog/understanding-japans-ai-promotion-act-an-innovation-first-blueprint-for-ai-regulation/"],"notes":"The Cabinet Office confirms promulgation and partial effect on 4 June 2025 and full effect on 1 September 2025. The Diet passage date (28 May 2025) comes from secondary sources. The law number is not verified.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-24 02:56:54","deadlines":[{"id":119,"regulationId":"jp-ai-act","date":"2025-06-04","title":"AI Promotion Act promulgated and partly in force","description":"Most provisions, including basic principles and stakeholder duties, take effect on promulgation.","kind":"effective","sourceUrl":"https://www8.cao.go.jp/cstp/ai/ai_act/ai_act.html","tentative":false,"review":"verified"},{"id":120,"regulationId":"jp-ai-act","date":"2025-09-01","title":"AI Promotion Act fully in force","description":"Provisions establishing the AI Strategy Headquarters and AI Basic Plan take effect.","kind":"effective","sourceUrl":"https://www8.cao.go.jp/cstp/ai/ai_act/ai_act.html","tentative":false,"review":"verified"}]},{"id":"jp-appi","name":"Act on the Protection of Personal Information (Act No. 57 of 2003), as amended including the 2026 amendment act","shortName":"Japan APPI","jurisdiction":"jp","jurisdictionName":"Japan","region":"apac","topics":["privacy","children","biometrics","breach-notification","ai"],"status":"amended","citation":"Act No. 57 of 2003; 2026 amendment act promulgated 17 July 2026","enactedDate":"2003-05-30","effectiveDate":"2005-04-01","summary":"Japan's general privacy law covering purpose specification, security, third-party transfer consent (with an opt-out scheme), cross-border transfer rules, mandatory breach reporting, and pseudonymized data. The 2026 amendment (promulgated 17 July 2026) adds Japan's first administrative fine (disgorgement of gains from serious violations), guardian consent for children under 16, stricter rules on facial-feature data, relaxed breach notification to individuals, and a consent exemption for statistics and AI development.","appliesTo":"All business operators handling personal information in Japan, with no size threshold, and foreign operators handling data of people in Japan in connection with supplying goods or services. Under the 2026 amendment, fines target serious violations involving large-scale misuse for economic gain; reported exclusions cover negligence or fewer than 1,000 affected people.","penalties":"Current: PPC orders; criminal penalties for violating orders up to 1 year imprisonment or JPY 1 million, and corporate fines up to JPY 100 million for order violations and unlawful database provision. 2026 amendment: administrative fine equal to the economic benefit from the violation (reported 1.5x uplift for repeat offenders within 10 years and a 50% cut for self-reporting), plus higher criminal penalties for unlawful database provision and new penalties for obtaining PI by fraud.","enforcer":"Personal Information Protection Commission (PPC)","sourceUrl":"https://www.ppc.go.jp/files/pdf/260731_shiryou-1.pdf","extraSources":["https://www.ppc.go.jp/files/pdf/260407_gaiyou.pdf","https://www.ppc.go.jp/news/press/2026/260407/","https://www.ppc.go.jp/en/legal/","https://www.bakermckenzie.com/en/insight/publications/2026/05/japan-appi-reform-key-changes"],"notes":"Main body of the 2026 amendment commences by cabinet order within 2 years of promulgation (by about July 2028); the PPC roadmap of 31 July 2026 gives a rough outlook of spring to July 2028, so no exact date is listed. One narrow provision (digitised service by public notice) takes effect 6 months after promulgation. The 1,000-person exclusion and the 1.5x and 50% fine adjustments come from law-firm summaries, not re-verified in the official text. Earlier dates (2003 enactment, 2005 full effect, 2022 amendments) are from the PPC legal page and general knowledge. Full English consolidation as of 1 Apr 2023 is at japaneselawtranslation.go.jp.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-24 02:56:54","deadlines":[{"id":121,"regulationId":"jp-appi","date":"2022-04-01","title":"2020 amendments in force","description":"Mandatory breach reporting, pseudonymized information and stricter cross-border rules apply.","kind":"effective","sourceUrl":"https://www.ppc.go.jp/en/legal/","tentative":false,"review":"verified"},{"id":122,"regulationId":"jp-appi","date":"2026-07-17","title":"2026 APPI amendment act promulgated","description":"Amendment enacted by the Diet on 10 July 2026 and promulgated; main provisions take effect by cabinet order within two years of promulgation.","kind":"transition","sourceUrl":"https://www.ppc.go.jp/files/pdf/260731_shiryou-1.pdf","tentative":false,"review":"verified"}]},{"id":"us-ky-kcdpa","name":"Kentucky Consumer Data Protection Act (HB 15, 2024), KRS 367.3611-367.3629","shortName":"Kentucky Consumer Data Protection Act (KCDPA)","jurisdiction":"us-ky","jurisdictionName":"Kentucky","region":"us-states","topics":["privacy"],"status":"in_force","citation":"HB 15 (2024 Ky. Acts ch. 72); KRS 367.3611 et seq.","enactedDate":"2024-04-04","effectiveDate":"2026-01-01","summary":"Virginia-style comprehensive privacy law granting rights to confirm, access, correct, delete, obtain a copy of, and opt out of targeted advertising, sale and profiling. Requires opt-in consent for sensitive data and data protection assessments for high-risk processing.","appliesTo":"Persons conducting business in Kentucky or targeting Kentucky residents that during a calendar year control or process personal data of 100,000+ consumers, or 25,000+ consumers and derive over 50% of gross revenue from the sale of personal data.","penalties":"Civil penalties up to $7,500 for each continued violation plus injunctive relief. Permanent 30-day cure period (no sunset).","enforcer":"Kentucky Attorney General (exclusive)","sourceUrl":"https://apps.legislature.ky.gov/record/24rs/hb15.html","extraSources":["https://apps.legislature.ky.gov/recorddocuments/bill/24RS/hb15/bill.pdf"],"notes":"30-day cure period is permanent, so no cure-expiry deadline. Penalty text refers to each 'continued' violation after the cure period. No 2025-2026 amendments confirmed.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-24 02:56:54","deadlines":[{"id":249,"regulationId":"us-ky-kcdpa","date":"2026-01-01","title":"KCDPA takes effect","description":"Consumer rights and controller/processor obligations apply (HB 15 section 12).","kind":"effective","sourceUrl":"https://apps.legislature.ky.gov/recorddocuments/bill/24RS/hb15/bill.pdf","tentative":false,"review":"verified"}]},{"id":"ke-dpa","name":"Data Protection Act, 2019 (No. 24 of 2019)","shortName":"Kenya Data Protection Act","jurisdiction":"ke","jurisdictionName":"Kenya","region":"mea","topics":["privacy","breach-notification","data-residency"],"status":"in_force","citation":"Act No. 24 of 2019","enactedDate":"2019-11-08","effectiveDate":"2019-11-25","summary":"Kenya's GDPR-inspired data protection law establishing the ODPC, mandatory registration of data controllers and processors, data subject rights, 72-hour breach notification to the Commissioner, DPIAs, and conditions on cross-border transfers (with some data localisation for strategic public interest processing).","appliesTo":"Controllers and processors established or resident in Kenya, or processing personal data of data subjects located in Kenya. Registration required unless exempt under the Registration Regulations (e.g. small entities below turnover/employee thresholds, except sectors listed as mandatory).","penalties":"Administrative fines up to KES 5 million or 1% of annual turnover of the preceding financial year, whichever is lower; criminal offences with fines and imprisonment.","enforcer":"Office of the Data Protection Commissioner (ODPC)","sourceUrl":"https://www.odpc.go.ke/","extraSources":["https://new.kenyalaw.org/akn/ke/act/2019/24/eng@2022-12-31"],"notes":"Data Protection (General), (Registration) and (Complaints Handling) Regulations 2021 followed; the registration compliance date (reported as July 2022) was not verified so is omitted. Assent date 8 Nov 2019 from recollection.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-24 02:56:54","deadlines":[{"id":123,"regulationId":"ke-dpa","date":"2019-11-25","title":"Data Protection Act in force","description":"Act commences.","kind":"effective","sourceUrl":"https://www.odpc.go.ke/","tentative":false,"review":"verified"}]},{"id":"us-la-ldpa","name":"Louisiana Data Privacy Act (SB 386, 2026 Regular Session, Act No. 502), La. R.S. 51:1780.1-1780.5","shortName":"Louisiana Data Privacy Act","jurisdiction":"us-la","jurisdictionName":"Louisiana","region":"us-states","topics":["privacy","biometrics"],"status":"enacted","citation":"SB 386 (2026 RS), Act No. 502; La. R.S. 51:1780.1-1780.5","enactedDate":"2026-05-29","effectiveDate":"2027-01-01","summary":"Louisiana's comprehensive privacy law, signed May 29, 2026, gives consumers access, deletion, correction, portability and opt-out rights and requires conspicuous notice when sensitive or biometric data is sold. It uses CCPA-style applicability thresholds, including a $25M revenue trigger.","appliesTo":"Persons doing business in Louisiana that (1) have annual gross revenues over $25 million, (2) annually buy, receive, sell or share for commercial purposes personal information of 75,000+ consumers, households or devices, or (3) derive 50%+ of annual revenues from selling consumers' personal information.","penalties":"Violations are unfair and deceptive trade practices under the Louisiana Unfair Trade Practices and Consumer Protection Law (R.S. 51:1401 et seq.), excluding private rights of action; LUTPA civil penalties apply. 30-day notice-and-cure available only Jan 1 - July 31, 2027.","enforcer":"Louisiana Attorney General","sourceUrl":"https://legis.la.gov/legis/BillInfo.aspx?s=26RS&b=SB386&sbi=y","extraSources":["https://legis.la.gov/legis/ViewDocument.aspx?d=1480202","https://www.afslaw.com/perspectives/privacy-counsel/new-state-privacy-laws-signal-growing-partisan-divide","https://www.concord.tech/blog/concord-privacy-news-6-30-26"],"notes":"The act does not state a dollar penalty; LUTPA (R.S. 51:1407) civil penalties apply (commonly up to $5,000 per violation) but the figure was not verified against the official statute. One secondary source (Venable) misidentified the bill as SB 546; the official record shows SB 386 / Act 502.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-24 02:56:54","deadlines":[{"id":250,"regulationId":"us-la-ldpa","date":"2027-01-01","title":"Louisiana Data Privacy Act takes effect","description":"Consumer rights and controller duties apply (Act 502, Section 2); data protection assessment requirements apply to processing from this date.","kind":"effective","sourceUrl":"https://legis.la.gov/legis/ViewDocument.aspx?d=1480202","tentative":false,"review":"verified"},{"id":251,"regulationId":"us-la-ldpa","date":"2027-07-31","title":"30-day cure period expires","description":"AG's obligation to give 30-day notice and allow cure before investigating applies only from Jan 1 through July 31, 2027 (R.S. 51:1780.5(D)).","kind":"enforcement","sourceUrl":"https://legis.la.gov/legis/ViewDocument.aspx?d=1480202","tentative":false,"review":"verified"}]},{"id":"my-pdpa","name":"Personal Data Protection Act 2010 (Act 709), as amended by the Personal Data Protection (Amendment) Act 2024 (Act A1727)","shortName":"Malaysia PDPA","jurisdiction":"my","jurisdictionName":"Malaysia","region":"apac","topics":["privacy","breach-notification","biometrics","data-residency"],"status":"amended","citation":"Act 709; Act A1727 (Royal Assent 9 Oct 2024, gazetted 17 Oct 2024)","enactedDate":"","effectiveDate":"2013-11-15","summary":"Malaysia's commercial-sector data protection law. The 2024 amendments, phased in during 2025, rename 'data users' as 'data controllers', add biometric data to sensitive data, apply the Security Principle directly to processors, replace the transfer whitelist with adequacy and safeguards tests, raise fines, and add mandatory DPOs, data breach notification and data portability.","appliesTo":"Anyone processing personal data in commercial transactions in Malaysia, or using equipment in Malaysia for processing (federal and state governments excluded). Certain classes of data controllers must register. The DPO and breach notification guidelines set scale-based triggers.","penalties":"General offences: fine up to RM 1,000,000 and/or imprisonment up to 3 years (raised from RM 500,000 / 2 years).","enforcer":"Personal Data Protection Commissioner (Jabatan Perlindungan Data Peribadi)","sourceUrl":"https://www.pdp.gov.my/ppdpv1/wp-content/uploads/2024/11/Act-A1727.pdf","extraSources":["https://www.pdp.gov.my/ppdpv1/en/personal-data-protection-amendment-act-2024-commencement-date-determination/","https://www.christopherleeong.com/viewpoints/news-alert-dates-of-coming-into-operation-of-the-personal-data-protection-amendment-act-2024/"],"notes":"The phase breakdown comes from Christopher & Lee Ong's reading of the Minister's commencement notice; the pdp.gov.my notice page did not render its contents. The PDPA's original commencement (15 Nov 2013) is from established knowledge. Breach notification timelines (Commissioner within 72 hours; data subjects within 7 days) are in the Commissioner's guideline and were not re-verified here. The Personal Data Protection (Amendment) Act 2024 received royal assent on 9 Oct 2024; the original Act 709 came into force on 15 Nov 2013.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-24 02:56:54","deadlines":[{"id":129,"regulationId":"my-pdpa","date":"2025-01-01","title":"PDPA amendments phase 1","description":"Miscellaneous provisions commence (e.g. electronic service of notices).","kind":"effective","sourceUrl":"https://www.pdp.gov.my/ppdpv1/en/personal-data-protection-amendment-act-2024-commencement-date-determination/","tentative":false,"review":"verified"},{"id":130,"regulationId":"my-pdpa","date":"2025-04-01","title":"PDPA amendments phase 2","description":"'Data controller' terminology, biometric data as sensitive data, higher penalties, Security Principle for processors, and removal of the cross-border whitelist take effect.","kind":"effective","sourceUrl":"https://www.pdp.gov.my/ppdpv1/en/personal-data-protection-amendment-act-2024-commencement-date-determination/","tentative":false,"review":"verified"},{"id":131,"regulationId":"my-pdpa","date":"2025-06-01","title":"PDPA amendments phase 3","description":"Mandatory DPO appointment, data breach notification, and data portability take effect.","kind":"compliance","sourceUrl":"https://www.pdp.gov.my/ppdpv1/en/personal-data-protection-amendment-act-2024-commencement-date-determination/","tentative":false,"review":"verified"}]},{"id":"us-md-modpa","name":"Maryland Online Data Privacy Act of 2024 (SB 541 / HB 567), Md. Code, Com. Law 14-4601 et seq.","shortName":"Maryland Online Data Privacy Act (MODPA)","jurisdiction":"us-md","jurisdictionName":"Maryland","region":"us-states","topics":["privacy","children","health","biometrics"],"status":"amended","citation":"2024 Md. Laws ch. 455 (SB 541) and ch. 454 (HB 567); Md. Code, Com. Law 14-4601 to 14-4614","enactedDate":"2024-05-09","effectiveDate":"2025-10-01","summary":"The strictest US state comprehensive privacy law: imposes data minimization limited to what is strictly necessary, bans the sale of sensitive data outright, and bans targeted advertising to and sale of data of consumers under 18 (known or should have known). Took effect Oct 1, 2025 but does not apply to personal data processing activities before April 1, 2026.","appliesTo":"Persons doing business in Maryland or targeting Maryland residents that in the preceding calendar year controlled or processed personal data of 35,000+ consumers (excluding payment-only data), or 10,000+ consumers and derived more than 20% of gross revenue from the sale of personal data.","penalties":"Violations are unfair, abusive or deceptive trade practices under the Maryland Consumer Protection Act (civil penalties up to $10,000 per violation and $25,000 for repeat violations). Discretionary 60-day cure period for violations occurring on or before April 1, 2027. Consumers may pursue other remedies but no private right of action under the MCPA's section 13-408.","enforcer":"Maryland Attorney General, Consumer Protection Division","sourceUrl":"https://mgaleg.maryland.gov/2024RS/Chapters_noln/CH_455_sb0541e.pdf","extraSources":["https://mgaleg.maryland.gov/mgawebsite/Legislation/Details/sb0541?ys=2024RS","https://www.venable.com/insights/publications/2026/07/2026-mid-year-state-privacy-law-update"],"notes":"A 2026 amendment reportedly expanded the precise geolocation definition (1,750-foot radius) effective July 1, 2026 (Venable, July 2026); bill number not verified, so no deadline row added. Penalty amounts come from the Maryland Consumer Protection Act (Com. Law 13-410), not restated in MODPA.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-24 02:56:54","deadlines":[{"id":252,"regulationId":"us-md-modpa","date":"2025-10-01","title":"MODPA takes effect","description":"Act takes effect; data protection assessments apply to processing activities on or after Oct 1, 2025.","kind":"effective","sourceUrl":"https://mgaleg.maryland.gov/2024RS/Chapters_noln/CH_455_sb0541e.pdf","tentative":false,"review":"verified"},{"id":253,"regulationId":"us-md-modpa","date":"2026-04-01","title":"MODPA applies to personal data processing","description":"The act applies to personal data processing activities from April 1, 2026 (Section 2 of ch. 455).","kind":"compliance","sourceUrl":"https://mgaleg.maryland.gov/2024RS/Chapters_noln/CH_455_sb0541e.pdf","tentative":false,"review":"verified"},{"id":254,"regulationId":"us-md-modpa","date":"2027-04-01","title":"Discretionary 60-day cure period ends","description":"The Division's discretionary notice-and-cure (at least 60 days) applies only to violations occurring on or before April 1, 2027 (Com. Law 14-4614).","kind":"enforcement","sourceUrl":"https://mgaleg.maryland.gov/2024RS/Chapters_noln/CH_455_sb0541e.pdf","tentative":false,"review":"verified"}]},{"id":"mx-lfpdppp","name":"Ley Federal de Protección de Datos Personales en Posesión de los Particulares (2025)","shortName":"Mexico LFPDPPP 2025","jurisdiction":"mx","jurisdictionName":"Mexico","region":"americas","topics":["privacy"],"status":"in_force","citation":"DOF 20-03-2025","enactedDate":"2025-03-20","effectiveDate":"2025-03-21","summary":"New federal private-sector data protection law replacing the 2010 law after the dissolution of INAI; keeps the ARCO rights and privacy-notice model, broadens the personal data definition and moves enforcement to the Secretaría Anticorrupción y Buen Gobierno.","appliesTo":"Private individuals and legal entities processing personal data in Mexico (credit bureaus and purely personal/domestic processing excluded).","penalties":"Fines from 100 to 320,000 times the UMA depending on the infraction (100-160,000 UMA for fractions II-VII; 200-320,000 UMA for fractions VIII-XVIII), doubled for sensitive data; criminal penalties for certain misuse.","enforcer":"Secretaría Anticorrupción y Buen Gobierno","sourceUrl":"https://www.diputados.gob.mx/LeyesBiblio/pdf/LFPDPPP.pdf","extraSources":["https://www.dof.gob.mx/","https://iapp.org/news/a/entendiendo-la-ley-federal-de-protecci-n-de-datos-personales-en-posesi-n-de-los-particulares-en-mexico"],"notes":"Implementing regulations (Reglamento) for the 2025 law were reported as still pending in 2026; the 2011 regulations apply where not contrary.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-24 02:56:54","deadlines":[{"id":128,"regulationId":"mx-lfpdppp","date":"2025-03-21","title":"New LFPDPPP in force","description":"Law published 20 March 2025 enters into force the following day, repealing the 2010 law.","kind":"effective","sourceUrl":"https://www.diputados.gob.mx/LeyesBiblio/pdf/LFPDPPP.pdf","tentative":false,"review":"verified"}]},{"id":"us-mn-mcdpa","name":"Minnesota Consumer Data Privacy Act (HF 4757, 2024 Minn. Laws ch. 121, art. 5), Minn. Stat. 325M.10-325M.21","shortName":"Minnesota Consumer Data Privacy Act (MCDPA)","jurisdiction":"us-mn","jurisdictionName":"Minnesota","region":"us-states","topics":["privacy"],"status":"in_force","citation":"2024 Minn. Laws ch. 121, art. 5; Minn. Stat. 325M.10-325M.21","enactedDate":"2024-05-24","effectiveDate":"2025-07-31","summary":"Comprehensive privacy law with distinctive rights to question the result of profiling decisions and to obtain a list of specific third parties that received the consumer's data. Requires data inventories, documented privacy policies and procedures, and data protection assessments.","appliesTo":"Legal entities doing business in Minnesota or targeting residents that during a calendar year control or process personal data of 100,000+ consumers (excluding payment-only data), or derive over 25% of gross revenue from the sale of personal data and process personal data of 25,000+ consumers. Small businesses as defined by the SBA are exempt except they may not sell sensitive data without consent.","penalties":"Civil penalty up to $7,500 per violation plus injunction and litigation expenses. 30-day warning-letter cure period expired Jan 31, 2026.","enforcer":"Minnesota Attorney General","sourceUrl":"https://www.revisor.mn.gov/statutes/cite/325M.20","extraSources":["https://www.revisor.mn.gov/statutes/cite/325M.12"],"notes":"SBA small-business exemption summarized from the act's structure; not re-verified line by line. No 2025-2026 amendments confirmed.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-24 02:56:54","deadlines":[{"id":255,"regulationId":"us-mn-mcdpa","date":"2025-07-31","title":"MCDPA takes effect","description":"Consumer rights and controller/processor obligations apply (postsecondary institutions excepted).","kind":"effective","sourceUrl":"https://www.revisor.mn.gov/statutes/cite/325M.20","tentative":false,"review":"verified"},{"id":256,"regulationId":"us-mn-mcdpa","date":"2026-01-31","title":"30-day cure period expires","description":"The requirement that the AG send a warning letter and allow 30 days to cure before suing expires Jan 31, 2026 (325M.20(a)).","kind":"enforcement","sourceUrl":"https://www.revisor.mn.gov/statutes/cite/325M.20","tentative":false,"review":"verified"},{"id":257,"regulationId":"us-mn-mcdpa","date":"2029-07-31","title":"Postsecondary institutions must comply","description":"Postsecondary institutions regulated by the Office of Higher Education must comply by July 31, 2029.","kind":"compliance","sourceUrl":"https://www.revisor.mn.gov/statutes/cite/325M.20","tentative":false,"review":"verified"}]},{"id":"us-mt-mcdpa","name":"Montana Consumer Data Privacy Act (SB 384, 2023), Mont. Code Ann. 30-14-2801 et seq., as amended by SB 297 (2025)","shortName":"Montana Consumer Data Privacy Act (MCDPA)","jurisdiction":"us-mt","jurisdictionName":"Montana","region":"us-states","topics":["privacy","children"],"status":"amended","citation":"SB 384 (2023 Mont. Laws ch. 681); SB 297 (2025 Mont. Laws ch. 567); MCA 30-14-2801 to 30-14-2819","enactedDate":"2023-05-19","effectiveDate":"2024-10-01","summary":"Comprehensive privacy law with access, correction, deletion, portability and opt-out rights and mandatory recognition of opt-out preference signals. SB 297 (2025) lowered thresholds, removed the cure period, added minors' protections that apply regardless of size, and lets the AG demand data protection assessments in investigations.","appliesTo":"From Oct 1, 2025: persons doing business in Montana or targeting residents that control or process personal data of 25,000+ consumers (excluding payment-only data), or 15,000+ consumers and derive over 25% of gross revenue from selling personal data. Minors' provisions (30-14-2811, -2818, -2819) apply to anyone doing business in Montana or intentionally targeting products at residents regardless of volume. Original thresholds (Oct 1, 2024): 50,000 consumers, or 25,000 + over 25% revenue from sale.","penalties":"AG enforces using Montana Unfair Trade Practices and Consumer Protection Act powers (MCA Title 30, ch. 14, parts 1-2); no private right of action. SB 297 eliminated the 60-day cure period.","enforcer":"Montana Attorney General (exclusive)","sourceUrl":"https://archive.legmt.gov/bills/mca/title_0300/chapter_0140/part_0280/section_0030/0300-0140-0280-0030.html","extraSources":["https://archive.legmt.gov/bills/mca/title_0300/chapter_0140/part_0280/section_0170/0300-0140-0280-0170.html","https://www.hunton.com/privacy-and-cybersecurity-law-blog/montana-amends-consumer-data-privacy-act"],"notes":"The original act's 60-day cure period was scheduled to expire April 1, 2026; SB 297 removed it effective Oct 1, 2025 (per Hunton; MCA 30-14-2817 as amended by ch. 567 L. 2025 no longer contains a cure provision). The Oct 1, 2025 effective date of SB 297 is from secondary sources and the task brief, not the session law text. Hunton reports penalties up to $7,500 per violation under SB 297, but the codified enforcement section (30-14-2817) contains no dollar figure; penalties flow from the Montana Consumer Protection Act, so no exact per-violation figure is asserted here.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-24 02:56:54","deadlines":[{"id":258,"regulationId":"us-mt-mcdpa","date":"2024-10-01","title":"MCDPA takes effect","description":"Consumer rights, controller duties and opt-out preference signal support apply.","kind":"effective","sourceUrl":"https://archive.legmt.gov/bills/mca/title_0300/chapter_0140/part_0280/section_0030/0300-0140-0280-0030.html","tentative":false,"review":"verified"},{"id":259,"regulationId":"us-mt-mcdpa","date":"2025-10-01","title":"SB 297 amendments take effect; cure period eliminated","description":"Lower thresholds (25,000 / 15,000 + 25%), minors' data protections, AG assessment demands; the 60-day cure period is removed.","kind":"enforcement","sourceUrl":"https://archive.legmt.gov/bills/mca/title_0300/chapter_0140/part_0280/section_0170/0300-0140-0280-0170.html","tentative":false,"review":"verified"}]},{"id":"eu-nis2","name":"Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union (NIS2 Directive)","shortName":"NIS2","jurisdiction":"eu","jurisdictionName":"European Union","region":"eu","topics":["cybersecurity","breach-notification"],"status":"amended","citation":"OJ L 333, 27.12.2022, p. 80","enactedDate":"2022-12-14","effectiveDate":"2023-01-16","summary":"Requires medium and large entities in 18 critical sectors, including cloud, data centres, managed services, online marketplaces, search and social networks, to adopt cybersecurity risk-management measures. They must report significant incidents within 24 hours (early warning), 72 hours (notification) and one month (final report). Management bodies are accountable. Obligations apply through national transposing laws.","appliesTo":"Essential and important entities in Annex I/II sectors, generally medium-sized or larger (50+ employees or over EUR 10M turnover/balance sheet). DNS, TLD registries, trust service providers and public electronic communications providers are covered regardless of size.","penalties":"Essential entities: maximum of at least EUR 10M or 2% of worldwide annual turnover, whichever is higher. Important entities: maximum of at least EUR 7M or 1.4% (Art 34). Management can be held personally liable and temporarily suspended in some cases.","enforcer":"National competent authorities and CSIRTs designated by each Member State; NIS Cooperation Group; ENISA","sourceUrl":"https://eur-lex.europa.eu/eli/dir/2022/2555/oj","extraSources":["https://eur-lex.europa.eu/eli/reg_impl/2024/2690/oj","https://www.insideprivacy.com/data-security/cybersecurity/european-commission-proposes-targeted-amendments-to-nis2-to-simplify-compliance-and-align-with-proposed-cybersecurity-act-2/"],"notes":"Transposition was late in most Member States, so obligations and registration deadlines differ by country. On 20 Jan 2026 the Commission proposed targeted NIS2 amendments alongside a revised Cybersecurity Act (CSA2): narrower scope, more harmonised measures, certification-based compliance and a bigger role for ENISA. The Digital Omnibus COM(2025) 837 also proposes a single-entry point for incident reporting. Neither was adopted as of Sept 2026. The 2027-04-17 date is computed from 'every two years' after 17 Apr 2025.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-24 02:56:54","deadlines":[{"id":98,"regulationId":"eu-nis2","date":"2023-01-16","title":"NIS2 enters into force","description":"Directive entered into force on the twentieth day after publication in OJ L 333 of 27 Dec 2022.","kind":"effective","sourceUrl":"https://eur-lex.europa.eu/eli/dir/2022/2555/oj","tentative":false,"review":"verified"},{"id":99,"regulationId":"eu-nis2","date":"2024-10-17","title":"Transposition deadline","description":"Member States had to adopt and publish national transposing measures by 17 Oct 2024 (Art 41(1)).","kind":"transition","sourceUrl":"https://eur-lex.europa.eu/eli/dir/2022/2555/oj","tentative":false,"review":"verified"},{"id":100,"regulationId":"eu-nis2","date":"2024-10-18","title":"National NIS2 measures apply; NIS1 repealed","description":"Member States apply their NIS2 measures from 18 Oct 2024 and Directive (EU) 2016/1148 (NIS1) is repealed (Arts 41(1), 44).","kind":"effective","sourceUrl":"https://eur-lex.europa.eu/eli/dir/2022/2555/oj","tentative":false,"review":"verified"},{"id":101,"regulationId":"eu-nis2","date":"2024-11-07","title":"Implementing Regulation 2024/2690 enters into force","description":"Commission Implementing Regulation (EU) 2024/2690 (published 18 Oct 2024) sets technical risk-management measures and significant-incident thresholds for DNS, TLD, cloud, data centre, CDN, managed (security) service providers, online marketplaces, search engines, social networks and trust service providers.","kind":"effective","sourceUrl":"https://eur-lex.europa.eu/eli/reg_impl/2024/2690/oj","tentative":false,"review":"verified"},{"id":102,"regulationId":"eu-nis2","date":"2025-01-17","title":"Digital infrastructure entities submit registration data","description":"DNS providers, TLD registries, domain registration services, cloud, data centre, CDN, managed (security) service providers, marketplaces, search engines and social networks had to submit registration details to competent authorities (Art 27(2)).","kind":"reporting","sourceUrl":"https://eur-lex.europa.eu/eli/dir/2022/2555/oj","tentative":false,"review":"verified"},{"id":103,"regulationId":"eu-nis2","date":"2025-04-17","title":"Member States establish entity lists","description":"Member States had to establish lists of essential and important entities and notify the Commission of entity numbers (Art 3(3) and (5)). Repeated every two years.","kind":"reporting","sourceUrl":"https://eur-lex.europa.eu/eli/dir/2022/2555/oj","tentative":false,"review":"verified"},{"id":104,"regulationId":"eu-nis2","date":"2027-04-17","title":"Next biennial entity notification","description":"Competent authorities notify the Commission and Cooperation Group of the number of essential and important entities, repeated every two years after 17 Apr 2025 (Art 3(5)).","kind":"reporting","sourceUrl":"https://eur-lex.europa.eu/eli/dir/2022/2555/oj","tentative":false,"review":"verified"},{"id":105,"regulationId":"eu-nis2","date":"2027-10-17","title":"Commission review of NIS2","description":"Commission must review the functioning of NIS2 and report to Parliament and Council, then every 36 months (Art 40).","kind":"reporting","sourceUrl":"https://eur-lex.europa.eu/eli/dir/2022/2555/oj","tentative":false,"review":"verified"}]},{"id":"us-ny-raise","name":"New York Responsible AI Safety and Education (RAISE) Act (S6953-B/A6453-B of 2025), as amended by chapter amendment S8828 of 2026","shortName":"NY RAISE Act","jurisdiction":"us-ny","jurisdictionName":"New York","region":"us-states","topics":["ai"],"status":"enacted","citation":"S6953-B/A6453-B (2025); S8828 (2026, chapter amendment, Laws of 2026 ch. 96); N.Y. Gen. Bus. Law Art. 44-B","enactedDate":"2025-12-19","effectiveDate":"2027-01-01","summary":"Frontier AI developers must publish transparency reports when they deploy models and report critical safety incidents to a new DFS oversight office within 72 hours, or within 24 hours to authorities where there is imminent risk of death or injury. Large frontier developers must also publish and annually update a Frontier AI Framework, submit catastrophic-risk assessments, file disclosure statements with DFS every two years, and pay a share of the office's costs. The March 2026 chapter amendment realigned the law closely with California SB 53.","appliesTo":"Frontier developers training models with more than 10^26 FLOPs; large frontier developers are those with $500 million or more in prior-year revenue, including affiliates.","penalties":"Civil penalties up to $1,000,000 for a first violation and up to $3,000,000 for subsequent violations, sought by the AG. The DFS office may fine $1,000 per day after notice and hearing for failing to file a disclosure statement.","enforcer":"New York Attorney General; DFS AI oversight office (disclosure filings, assessments, regulations)","sourceUrl":"https://www.governor.ny.gov/news/governor-hochul-signs-nation-leading-legislation-require-ai-frameworks-ai-frontier-models","extraSources":["https://www.nysenate.gov/legislation/bills/2025/S8828","https://www.wiley.law/alert-New-York-Finalizes-RAISE-Act-for-Frontier-AI-Models-Law-Takes-Effect-January-1-2027","https://www.dwt.com/blogs/artificial-intelligence-law-advisor/2026/04/ny-overhauls-frontier-ai-transparency-law"],"notes":"nysenate.gov confirms S8828 was signed March 27, 2026 as chapter 96, effective January 1, 2027. Some commentary cites July 1, 2027 for certain provisions; that was not confirmed. The first DFS annual report is due in January 2028 (exact day not verified).","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-24 02:56:54","deadlines":[{"id":278,"regulationId":"us-ny-raise","date":"2025-12-19","title":"RAISE Act signed","description":"Governor Hochul signs the RAISE Act with an agreed chapter amendment.","kind":"transition","sourceUrl":"https://www.governor.ny.gov/news/governor-hochul-signs-nation-leading-legislation-require-ai-frameworks-ai-frontier-models","tentative":false,"review":"verified"},{"id":279,"regulationId":"us-ny-raise","date":"2026-03-27","title":"Chapter amendment S8828 signed","description":"Chapter amendment (ch. 96) finalizes the RAISE Act text.","kind":"transition","sourceUrl":"https://www.nysenate.gov/legislation/bills/2025/S8828","tentative":false,"review":"verified"},{"id":280,"regulationId":"us-ny-raise","date":"2027-01-01","title":"RAISE Act takes effect","description":"Transparency reports, frontier AI frameworks, incident reporting and DFS disclosure filings apply.","kind":"effective","sourceUrl":"https://www.nysenate.gov/legislation/bills/2025/S8828","tentative":false,"review":"verified"}]},{"id":"us-nyc-ll144","name":"New York City Local Law 144 of 2021, Automated Employment Decision Tools (NYC Admin. Code 20-870 et seq.)","shortName":"NYC Local Law 144 (AEDT)","jurisdiction":"us-ny","jurisdictionName":"New York City, New York","region":"us-states","topics":["ai"],"status":"in_force","citation":"NYC Local Law 144 of 2021; NYC Admin. Code 20-870 to 20-874; 6 RCNY 5-300 et seq.","enactedDate":"","effectiveDate":"2023-07-05","summary":"Employers and employment agencies may not use an automated employment decision tool (AEDT) to screen candidates or employees for hiring or promotion unless the tool has had an independent bias audit within the past year. They must publish a summary of the audit results and give candidates at least 10 business days' notice that an AEDT will be used.","appliesTo":"Employers and employment agencies using AEDTs for hiring or promotion decisions for candidates or employees in New York City. No size threshold.","penalties":"Civil penalties up to $500 for a first violation (and each additional violation the same day) and $500 to $1,500 for each subsequent violation; each day of non-compliant use and each failure to notice is a separate violation.","enforcer":"NYC Department of Consumer and Worker Protection (DCWP)","sourceUrl":"https://www.nyc.gov/site/dca/about/automated-employment-decision-tools.page","extraSources":[],"notes":"Law enacted December 2021 with an original January 1, 2023 effective date; enforcement was postponed twice while DCWP finalized rules. Penalty amounts come from Admin. Code 20-872 and were not re-fetched for this record. No 2025-2026 amendments were verified; the search budget was exhausted before checking for proposed City Council amendments.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-24 02:56:54","deadlines":[{"id":281,"regulationId":"us-nyc-ll144","date":"2023-07-05","title":"DCWP enforcement begins","description":"Bias audit, results publication and candidate notice requirements are enforced.","kind":"enforcement","sourceUrl":"https://www.nyc.gov/site/dca/about/automated-employment-decision-tools.page","tentative":false,"review":"verified"}]},{"id":"us-ny-dfs-500","name":"New York DFS Cybersecurity Requirements for Financial Services Companies (23 NYCRR Part 500), Second Amendment","shortName":"NYDFS Cybersecurity Regulation (Part 500)","jurisdiction":"us-ny","jurisdictionName":"New York","region":"us-states","topics":["cybersecurity","breach-notification","financial"],"status":"amended","citation":"23 NYCRR Part 500 (Second Amendment effective 2023-11-01)","enactedDate":"2023-11-01","effectiveDate":"2017-03-01","summary":"DFS-licensed financial companies must keep a risk-based cybersecurity program, CISO, policies, access controls, MFA, encryption, an asset inventory, and incident response and business continuity plans. They must notify DFS within 72 hours of a cybersecurity event and within 24 hours of any extortion payment, and certify compliance or acknowledge non-compliance each April 15. The 2023 Second Amendment added governance duties, Class A company requirements and phased controls through November 1, 2025.","appliesTo":"Covered entities: persons operating under a DFS license, registration, charter or similar authorization (banks, insurers, money transmitters, etc.). Class A companies: at least $20,000,000 gross annual revenue in each of the last two fiscal years from NY business, and either over 2,000 employees averaged over two years or over $1,000,000,000 gross annual revenue in each of the last two fiscal years. Limited exemption for fewer than 20 employees and contractors, under $7,500,000 gross annual revenue in each of the last 3 fiscal years, or under $15,000,000 year-end total assets.","penalties":"Penalties under the Banking Law, Insurance Law and Financial Services Law. 500.20 lists the factors DFS weighs; the regulation sets no fixed maximum. A single act or failure, including failing to comply for any 24-hour period, is a violation.","enforcer":"New York State Department of Financial Services (DFS)","sourceUrl":"https://www.dfs.ny.gov/cybersecurity/23-NYCRR-Part-500","extraSources":["https://www.dfs.ny.gov/cybersecurity/exemptions"],"notes":"Dates are computed from the 500.22 transitional periods (30 days, 180 days, 1 year, 18 months and 2 years from the November 1, 2023 Second Amendment) and match DFS guidance. DFS also issued 2026 industry letters on frontier-AI cyber risk (May 21, 2026) and risk assessment (September 10, 2026); these are guidance, not rule changes.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-24 02:56:54","deadlines":[{"id":269,"regulationId":"us-ny-dfs-500","date":"2017-03-01","title":"Part 500 effective","description":"Original cybersecurity regulation takes effect.","kind":"effective","sourceUrl":"https://www.dfs.ny.gov/cybersecurity/23-NYCRR-Part-500","tentative":false,"review":"verified"},{"id":270,"regulationId":"us-ny-dfs-500","date":"2023-11-01","title":"Second Amendment effective","description":"Second Amendment takes effect; 500.19(e)-(h), 500.20, 500.21, 500.22 and 500.24 apply immediately.","kind":"effective","sourceUrl":"https://www.dfs.ny.gov/cybersecurity/23-NYCRR-Part-500","tentative":false,"review":"verified"},{"id":271,"regulationId":"us-ny-dfs-500","date":"2023-12-01","title":"Amended notification requirements (500.17)","description":"New 72-hour event notice, 24-hour extortion payment notice and certification changes apply (30 days).","kind":"compliance","sourceUrl":"https://www.dfs.ny.gov/cybersecurity/23-NYCRR-Part-500","tentative":false,"review":"verified"},{"id":272,"regulationId":"us-ny-dfs-500","date":"2024-04-15","title":"Annual compliance notification","description":"Certification of compliance or acknowledgment of non-compliance due (recurs every April 15).","kind":"reporting","sourceUrl":"https://www.dfs.ny.gov/cybersecurity/23-NYCRR-Part-500","tentative":false,"review":"verified"},{"id":273,"regulationId":"us-ny-dfs-500","date":"2024-04-29","title":"General 180-day transition ends","description":"Most new Second Amendment requirements apply, e.g. annual reporting to the board and risk assessment updates.","kind":"compliance","sourceUrl":"https://www.dfs.ny.gov/cybersecurity/23-NYCRR-Part-500","tentative":false,"review":"verified"},{"id":274,"regulationId":"us-ny-dfs-500","date":"2024-11-01","title":"Governance, encryption, IR/BCDR, exemptions","description":"500.4 governance, 500.15 encryption, 500.16 incident response and business continuity plans, and 500.19(a) revised exemptions apply.","kind":"compliance","sourceUrl":"https://www.dfs.ny.gov/cybersecurity/23-NYCRR-Part-500","tentative":false,"review":"verified"},{"id":275,"regulationId":"us-ny-dfs-500","date":"2025-05-01","title":"Vulnerability scans, access privileges, malware controls, Class A monitoring","description":"500.5(a)(2) automated scans, 500.7 access privilege restrictions, 500.14(a)(2) malicious code protection, and 500.14(b) Class A endpoint detection and centralized logging apply.","kind":"compliance","sourceUrl":"https://www.dfs.ny.gov/cybersecurity/23-NYCRR-Part-500","tentative":false,"review":"verified"},{"id":276,"regulationId":"us-ny-dfs-500","date":"2025-11-01","title":"Universal MFA and asset inventory","description":"500.12 multi-factor authentication for all users and 500.13(a) asset inventory requirements apply.","kind":"compliance","sourceUrl":"https://www.dfs.ny.gov/cybersecurity/23-NYCRR-Part-500","tentative":false,"review":"verified"},{"id":277,"regulationId":"us-ny-dfs-500","date":"2026-04-15","title":"Annual compliance notification","description":"Annual certification or acknowledgment covering calendar year 2025 due.","kind":"reporting","sourceUrl":"https://www.dfs.ny.gov/cybersecurity/23-NYCRR-Part-500","tentative":false,"review":"verified"}]},{"id":"us-ne-ndpa","name":"Nebraska Data Privacy Act (LB 1074, 2024)","shortName":"Nebraska NDPA","jurisdiction":"us-ne","jurisdictionName":"Nebraska","region":"us-states","topics":["privacy"],"status":"in_force","citation":"Neb. Rev. Stat. 87-1101 to 87-1130 (Laws 2024, LB 1074)","enactedDate":"2024-04-17","effectiveDate":"2025-01-01","summary":"Comprehensive consumer privacy law modeled on the Texas TDPSA: consumers get access, correction, deletion, portability and opt-out rights (targeted ads, sale, profiling). Controllers must post privacy notices, obtain opt-in consent for sensitive data, honor universal opt-out signals and run data protection assessments.","appliesTo":"Any person that conducts business in Nebraska or produces products/services consumed by Nebraska residents, processes or sells personal data, and is not a small business as defined by the federal Small Business Act (no consumer-count threshold). Small businesses are still barred from selling sensitive data without consent (87-1118). Exempts state agencies, GLBA financial institutions, HIPAA covered entities/business associates, nonprofits, higher education, utilities.","penalties":"Civil penalty up to $7,500 per violation (87-1124), plus injunctive relief and AG fees/expenses. Mandatory 30-day written-notice cure period before any action (87-1122); it does not sunset. No private right of action (87-1125).","enforcer":"Nebraska Attorney General (exclusive)","sourceUrl":"https://nebraskalegislature.gov/laws/statutes.php?statute=87-1103","extraSources":["https://nebraskalegislature.gov/laws/statutes.php?statute=87-1122","https://nebraskalegislature.gov/laws/statutes.php?statute=87-1124","https://nebraskalegislature.gov/bills/view_bill.php?DocumentID=54904"],"notes":"LB 1074 was approved by the Governor on April 17, 2024 (per the Legislature's bill history). The 30-day cure right is permanent, so there is no cure-sunset deadline. Nebraska's separate Age-Appropriate Online Design Code Act (LB 504, 2025) is a different statute and not covered in this record. No amendments to the NDPA found through Sept 2026.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-24 02:56:54","deadlines":[{"id":260,"regulationId":"us-ne-ndpa","date":"2025-01-01","title":"Nebraska Data Privacy Act takes effect","description":"Controller and processor obligations and consumer rights under Neb. Rev. Stat. 87-1101 et seq. apply.","kind":"effective","sourceUrl":"https://nebraskalegislature.gov/bills/view_bill.php?DocumentID=54904","tentative":false,"review":"verified"}]},{"id":"us-nh-privacy","name":"New Hampshire Privacy Act (SB 255, 2024), RSA chapter 507-H","shortName":"New Hampshire Privacy Act","jurisdiction":"us-nh","jurisdictionName":"New Hampshire","region":"us-states","topics":["privacy","children"],"status":"amended","citation":"RSA 507-H (Laws 2024, ch. 5; amended 2026, ch. 168 (HB 1460))","enactedDate":"2024-03-06","effectiveDate":"2025-01-01","summary":"Comprehensive consumer privacy law giving New Hampshire residents access, correction, deletion, portability and opt-out rights (sale, targeted ads, profiling), with opt-in consent for sensitive data, universal opt-out signal support and data protection assessments. A 2026 amendment (HB 1460) bans selling the personal data of children under 13 starting in 2027.","appliesTo":"Persons conducting business in NH or targeting NH residents that in a one-year period controlled or processed personal data of at least 35,000 unique consumers (excluding payment-only data), or at least 10,000 unique consumers while deriving more than 25% of gross revenue from selling personal data (RSA 507-H:2). Usual GLBA, HIPAA, nonprofit and higher-ed exemptions.","penalties":"Violations are unfair or deceptive acts under the Consumer Protection Act (RSA 358-A): civil penalties up to $10,000 per violation (RSA 358-A:4). 60-day cure notice was mandatory Jan 1 to Dec 31, 2025; from Jan 1, 2026 the AG may offer a cure at its discretion (RSA 507-H:11). No private right of action.","enforcer":"New Hampshire Attorney General (exclusive)","sourceUrl":"https://gc.nh.gov/rsa/html/LII/507-H/507-H-2.htm","extraSources":["https://gc.nh.gov/rsa/html/LII/507-H/507-H-11.htm","https://gc.nh.gov/rsa/html/XXXI/358-A/358-A-mrg.htm","https://gc.nh.gov/bill_status/billinfo.aspx?id=2443&inflect=2","https://www.insideprivacy.com/state-privacy/state-comprehensive-privacy-law-round-up-several-states-amend-their-privacy-statutes/"],"notes":"SB 255 signing date (March 6, 2024) is from contemporaneous reporting; RSA source note confirms Laws 2024, ch. 5. HB 1460 signed June 19, 2026 (chapter 168); Jan 1, 2027 effective date is per Covington Inside Privacy, cross-checked against the NH bill status page showing the bill was signed. The Secretary of State publishes the law link per RSA 507-H:2 II; AG rulemaking is not provided for.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-24 02:56:54","deadlines":[{"id":261,"regulationId":"us-nh-privacy","date":"2025-01-01","title":"New Hampshire Privacy Act takes effect","description":"RSA 507-H obligations and consumer rights apply (Laws 2024, 5:1, eff. Jan. 1, 2025).","kind":"effective","sourceUrl":"https://gc.nh.gov/rsa/html/LII/507-H/507-H-2.htm","tentative":false,"review":"verified"},{"id":262,"regulationId":"us-nh-privacy","date":"2026-01-01","title":"Mandatory 60-day cure period expires","description":"The AG's obligation to issue a cure notice ended Dec 31, 2025; from Jan 1, 2026 cure opportunities are discretionary (RSA 507-H:11 II-III).","kind":"enforcement","sourceUrl":"https://gc.nh.gov/rsa/html/LII/507-H/507-H-11.htm","tentative":false,"review":"verified"},{"id":263,"regulationId":"us-nh-privacy","date":"2027-01-01","title":"Ban on selling personal data of children under 13 (HB 1460)","description":"HB 1460 (2026, ch. 168) prohibits controllers from selling the personal data of a child under 13.","kind":"effective","sourceUrl":"https://gc.nh.gov/bill_status/billinfo.aspx?id=2443&inflect=2","tentative":false,"review":"verified"}]},{"id":"us-nj-njdpa","name":"New Jersey Data Privacy Act (P.L.2023, c.266; S332)","shortName":"New Jersey NJDPA","jurisdiction":"us-nj","jurisdictionName":"New Jersey","region":"us-states","topics":["privacy","children"],"status":"amended","citation":"P.L.2023, c.266; N.J.S.A. 56:8-166.4 et seq.","enactedDate":"2024-01-16","effectiveDate":"2025-01-15","summary":"Comprehensive consumer privacy law with access, correction, deletion, portability and opt-out rights, opt-in consent for sensitive data, consent for targeted advertising/sale/profiling of known 13-17 year olds, universal opt-out signal support and data protection assessments. It has no revenue-share floor for the smaller threshold, and the Division of Consumer Affairs has rulemaking authority. A June 2026 law (A5328) bans selling sensitive data and creates a data broker registry.","appliesTo":"Controllers conducting business in NJ or targeting NJ residents that in a calendar year control or process personal data of at least 100,000 consumers (excluding payment-only data), or at least 25,000 consumers where the controller derives revenue or receives a discount from selling personal data (any amount). Exempts GLBA financial institutions, HIPAA PHI, and certain other regulated data; nonprofits are NOT exempt.","penalties":"Violations are unlawful practices under the NJ Consumer Fraud Act (N.J.S.A. 56:8-1 et seq.): civil penalties up to $10,000 for the first violation and $20,000 for each subsequent violation (N.J.S.A. 56:8-13). 30-day cure notice required, where a cure is deemed possible, until July 1, 2026 (the first day of the 18th month after the effective date; N.J.S.A. 56:8-166.17). No private right of action.","enforcer":"New Jersey Attorney General / Division of Consumer Affairs","sourceUrl":"https://pub.njleg.state.nj.us/Bills/2022/PL23/266_.PDF","extraSources":["https://www.njoag.gov/murphy-administration-announces-proposed-rules-establishing-comprehensive-consumer-data-privacy-protections/","https://www.insideprivacy.com/state-privacy/state-comprehensive-privacy-law-round-up-several-states-amend-their-privacy-statutes/","https://www.venable.com/insights/publications/2026/07/2026-mid-year-state-privacy-law-update"],"notes":"Rules status: proposed N.J.A.C. 13:45L published June 2, 2025 (57 N.J.R. 1101(a)); no notice of adoption could be confirmed as of Sept 22, 2026. Under NJ's APA a proposal expires one year after publication unless adopted, so check whether the Division re-proposed. A5328 (signed June 30, 2026) details come from Covington Inside Privacy and Venable because the NJ Legislature bill page renders only via JavaScript and could not be read. It also creates a data broker registry with what are reported as the highest fees in the US; data broker obligations are reported to start 270 days after enactment (around late March 2027). That date is omitted because the exact start could not be verified.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-24 02:56:54","deadlines":[{"id":264,"regulationId":"us-nj-njdpa","date":"2025-01-15","title":"NJDPA takes effect","description":"The act takes effect on the 365th day after enactment on Jan 16, 2024 (sec. 17).","kind":"effective","sourceUrl":"https://pub.njleg.state.nj.us/Bills/2022/PL23/266_.PDF","tentative":false,"review":"verified"},{"id":265,"regulationId":"us-nj-njdpa","date":"2025-06-02","title":"Division of Consumer Affairs proposes NJDPA rules (N.J.A.C. 13:45L)","description":"Proposed rules published at 57 N.J.R. 1101(a); comments were due Aug 1, 2025.","kind":"transition","sourceUrl":"https://www.njoag.gov/murphy-administration-announces-proposed-rules-establishing-comprehensive-consumer-data-privacy-protections/","tentative":false,"review":"verified"},{"id":266,"regulationId":"us-nj-njdpa","date":"2025-07-15","title":"Universal opt-out mechanism must be honored","description":"Controllers that sell personal data or process it for targeted advertising must honor user-selected universal opt-out signals within six months of the effective date (N.J.S.A. 56:8-166.11).","kind":"compliance","sourceUrl":"https://pub.njleg.state.nj.us/Bills/2022/PL23/266_.PDF","tentative":false,"review":"verified"},{"id":267,"regulationId":"us-nj-njdpa","date":"2026-06-30","title":"A5328 sensitive data sale ban takes effect","description":"A5328, signed June 30, 2026, prohibits selling sensitive personal data; the ban took effect on signing.","kind":"effective","sourceUrl":"https://www.njleg.state.nj.us/bill-search/2026/A5328","tentative":false,"review":"verified"},{"id":268,"regulationId":"us-nj-njdpa","date":"2026-07-01","title":"Mandatory 30-day cure period expires","description":"The Division's duty to issue a cure notice before enforcement ends on the first day of the 18th month after the effective date (N.J.S.A. 56:8-166.17(b)).","kind":"enforcement","sourceUrl":"https://pub.njleg.state.nj.us/Bills/2022/PL23/266_.PDF","tentative":false,"review":"verified"}]},{"id":"nz-privacy-act","name":"Privacy Act 2020 (New Zealand), as amended by the Privacy Amendment Act 2025","shortName":"New Zealand Privacy Act","jurisdiction":"nz","jurisdictionName":"New Zealand","region":"apac","topics":["privacy","breach-notification"],"status":"amended","citation":"Privacy Act 2020 (2020 No 31); Privacy Amendment Act 2025","enactedDate":"2020-06-30","effectiveDate":"2020-12-01","summary":"New Zealand's privacy law, built on 13 Information Privacy Principles plus mandatory notification of serious privacy breaches. The Privacy Amendment Act 2025 adds IPP 3A from 1 May 2026: agencies that collect personal information indirectly (from third parties) must take reasonable steps to tell the individual about the collection, its purpose, recipients and their rights.","appliesTo":"All 'agencies' (public and private sector, any size) that collect or hold personal information, including overseas agencies carrying on business in New Zealand.","penalties":"Criminal fines up to NZD 10,000 for offences such as failing to notify a notifiable privacy breach, misleading an agency, or ignoring a compliance notice. The Human Rights Review Tribunal can award damages.","enforcer":"Office of the Privacy Commissioner; Human Rights Review Tribunal","sourceUrl":"https://www.justice.govt.nz/justice-sector-policy/key-initiatives/enhancing-the-privacy-act/","extraSources":["https://www.privacy.org.nz/privacy-principles/3a/"],"notes":"The 2020 Act assent date (30 Jun 2020) and the NZD 10,000 penalty come from established knowledge, not re-fetched.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-24 02:56:54","deadlines":[{"id":134,"regulationId":"nz-privacy-act","date":"2020-12-01","title":"Privacy Act 2020 in force","description":"IPPs, mandatory breach notification and compliance notices apply.","kind":"effective","sourceUrl":"https://www.justice.govt.nz/justice-sector-policy/key-initiatives/enhancing-the-privacy-act/","tentative":false,"review":"verified"},{"id":135,"regulationId":"nz-privacy-act","date":"2025-09-24","title":"Privacy Amendment Act 2025 technical changes commence","description":"Technical amendments commence the day after Royal Assent (23 Sep 2025).","kind":"effective","sourceUrl":"https://www.justice.govt.nz/justice-sector-policy/key-initiatives/enhancing-the-privacy-act/","tentative":false,"review":"verified"},{"id":136,"regulationId":"nz-privacy-act","date":"2026-05-01","title":"IPP 3A indirect-collection notification applies","description":"Agencies collecting personal information from third parties must take reasonable steps to notify individuals, subject to exceptions.","kind":"compliance","sourceUrl":"https://www.justice.govt.nz/justice-sector-policy/key-initiatives/enhancing-the-privacy-act/","tentative":false,"review":"verified"}]},{"id":"ng-ndpa","name":"Nigeria Data Protection Act, 2023 and NDPA General Application and Implementation Directive (GAID) 2025","shortName":"Nigeria NDPA","jurisdiction":"ng","jurisdictionName":"Nigeria","region":"mea","topics":["privacy","breach-notification","data-residency"],"status":"amended","citation":"Nigeria Data Protection Act, 2023","enactedDate":"2023-06-12","effectiveDate":"2023-06-12","summary":"Nigeria's primary data protection statute, establishing the NDPC, lawful bases, data subject rights, 72-hour breach notification, and special duties for data controllers and processors of major importance (registration, DPO, compliance audits). The GAID 2025 supersedes the NDPR 2019 and its Implementation Framework with detailed rules on audits, DPIAs, transfers and more.","appliesTo":"Controllers and processors domiciled or operating in Nigeria, or processing personal data of data subjects in Nigeria. 'Data controllers/processors of major importance' designated by NDPC thresholds (tiered by number of data subjects processed).","penalties":"Data controllers/processors of major importance: higher of NGN 10 million or 2% of annual gross revenue in the preceding financial year; others: higher of NGN 2 million or 2% of annual gross revenue.","enforcer":"Nigeria Data Protection Commission (NDPC)","sourceUrl":"https://ndpc.gov.ng/resources/","extraSources":["https://www.aluko-oyebode.com/insights/general-application-and-implementation-directive/","https://www.mondaq.com/nigeria/data-protection/1683848/the-operationality-of-the-nigeria-data-protection-act-ndpa-general-application-and-implementation-directive-gaid-2025"],"notes":"GAID was issued in March 2025 (exact issuance date not verified). Status marked 'amended' because GAID materially changed implementing rules in 2025.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-24 02:56:54","deadlines":[{"id":132,"regulationId":"ng-ndpa","date":"2023-06-12","title":"NDPA signed into law","description":"President signs the Nigeria Data Protection Act, 2023.","kind":"effective","sourceUrl":"https://ndpc.gov.ng/resources/","tentative":false,"review":"verified"},{"id":133,"regulationId":"ng-ndpa","date":"2025-09-19","title":"GAID 2025 takes effect","description":"General Application and Implementation Directive becomes effective, replacing the NDPR 2019 and NDPR Implementation Framework.","kind":"effective","sourceUrl":"https://ndpc.gov.ng/resources/","tentative":false,"review":"verified"}]},{"id":"us-ok-okcdpa","name":"Oklahoma Consumer Data Privacy Act (SB 546, 2026)","shortName":"Oklahoma OKCDPA","jurisdiction":"us-ok","jurisdictionName":"Oklahoma","region":"us-states","topics":["privacy"],"status":"enacted","citation":"SB 546 (60th Leg., 2nd Sess., 2026)","enactedDate":"2026-03-20","effectiveDate":"2027-01-01","summary":"New Virginia-style comprehensive privacy law: consumers get access, correction, deletion, portability and opt-out rights (sale, targeted ads, profiling), with opt-in consent for sensitive data, privacy notices and data protection assessments. It treats pseudonymous data as personal data and lets controllers authenticate opt-out requests.","appliesTo":"Controllers and processors doing business in Oklahoma or targeting Oklahoma residents that in the preceding calendar year controlled or processed personal data of at least 100,000 consumers, or at least 25,000 consumers while deriving over 50% of gross revenue from selling personal data. Exempts government, nonprofits, GLBA financial institutions, HIPAA entities, higher education; FCRA, FERPA, DPPA data; employee data.","penalties":"Civil penalty up to $7,500 per violation not cured, plus attorney fees and investigative costs. Mandatory 30-day notice-and-cure period that does not sunset. No private right of action.","enforcer":"Oklahoma Attorney General (exclusive)","sourceUrl":"http://www.oklegislature.gov/BillInfo.aspx?Bill=SB546&Session=2600","extraSources":["https://www.okhouse.gov/posts/news-20260323_2","https://www.dwt.com/blogs/privacy--security-law-blog/2026/03/oklahoma-privacy-law-sb-546","https://www.wilmerhale.com/en/insights/blogs/wilmerhale-privacy-and-cybersecurity-law/20260327-oklahoma-enacts-nations-twentieth-state-comprehensive-privacy-law"],"notes":"SB 546 was introduced in 2025 and passed the Senate in March 2025, but it was not enacted until the 2026 session; the Governor approved it March 20, 2026 per the Oklahoma Legislature bill history. So it was not effective Jan 1, 2026. Oklahoma Statutes codification is not yet confirmed. Thresholds, penalty and cure terms are from DWT, WilmerHale and the Oklahoma House press release.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-24 02:56:54","deadlines":[{"id":282,"regulationId":"us-ok-okcdpa","date":"2027-01-01","title":"Oklahoma Consumer Data Privacy Act takes effect","description":"All OKCDPA obligations and consumer rights apply.","kind":"effective","sourceUrl":"https://www.okhouse.gov/posts/news-20260323_2","tentative":false,"review":"verified"}]},{"id":"us-or-ocpa","name":"Oregon Consumer Privacy Act (SB 619, 2023)","shortName":"Oregon OCPA","jurisdiction":"us-or","jurisdictionName":"Oregon","region":"us-states","topics":["privacy","children"],"status":"amended","citation":"ORS 646A.570 to 646A.589 (Or. Laws 2023, ch. 369); amended by HB 2008 (2025) and HB 3875 (2025)","enactedDate":"2023-07-18","effectiveDate":"2024-07-01","summary":"Comprehensive consumer privacy law with access (including a list of specific third parties data was shared with), correction, deletion, portability and opt-out rights, opt-in consent for sensitive data, universal opt-out signals and data protection assessments. Unusually, it covers nonprofits. 2025 amendments ban selling precise geolocation data and data of consumers under 16, and bring all motor vehicle manufacturers into scope.","appliesTo":"Persons conducting business in Oregon or providing products/services to Oregon residents that in a calendar year control or process personal data of 100,000+ consumers (excluding payment-only data), or 25,000+ consumers while deriving 25%+ of annual gross revenue from selling personal data (ORS 646A.572). Nonprofits covered from July 1, 2025. Motor vehicle manufacturers and certain affiliates are covered regardless of thresholds (HB 3875).","penalties":"Civil penalty up to $7,500 per violation, plus injunctions and AG fees/costs (ORS 646A.589(4)). 30-day cure notice required, where a cure is possible, only until Jan 1, 2026. No private right of action.","enforcer":"Oregon Attorney General (Oregon DOJ Privacy Unit)","sourceUrl":"https://www.oregonlegislature.gov/bills_laws/ors/ors646A.html","extraSources":["https://www.doj.state.or.us/consumer-protection/id-theft-data-breaches/privacy/","https://www.doj.state.or.us/consumer-protection/for-businesses/privacy-law-faqs-for-nonprofits/","https://www.hunton.com/privacy-and-cybersecurity-law-blog/oregon-amends-consumer-privacy-act","https://www.dwt.com/blogs/privacy--security-law-blog/2025/06/oregon-teen-and-geolocation-privacy-law-2026"],"notes":"HB 3875 (signed May 27, 2025) extends OCPA to all motor vehicle manufacturers regardless of thresholds; its exact effective date was not verified, so it has no deadline row. HB 2008 was signed June 3, 2025. Oregon DOJ has released quarterly and annual enforcement reports.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-24 02:56:54","deadlines":[{"id":283,"regulationId":"us-or-ocpa","date":"2024-07-01","title":"OCPA takes effect for most controllers","description":"OCPA obligations apply to for-profit controllers meeting the thresholds.","kind":"effective","sourceUrl":"https://www.doj.state.or.us/consumer-protection/id-theft-data-breaches/privacy/","tentative":false,"review":"verified"},{"id":284,"regulationId":"us-or-ocpa","date":"2025-07-01","title":"OCPA applies to nonprofits","description":"Nonprofit organizations meeting the thresholds become subject to OCPA.","kind":"effective","sourceUrl":"https://www.doj.state.or.us/consumer-protection/for-businesses/privacy-law-faqs-for-nonprofits/","tentative":false,"review":"verified"},{"id":285,"regulationId":"us-or-ocpa","date":"2026-01-01","title":"Cure period sunsets","description":"The AG's 30-day notice-and-cure requirement expires; enforcement can proceed without a cure opportunity.","kind":"enforcement","sourceUrl":"https://www.oregonlegislature.gov/bills_laws/ors/ors646A.html","tentative":false,"review":"verified"},{"id":286,"regulationId":"us-or-ocpa","date":"2026-01-01","title":"Universal opt-out signals must be honored","description":"Controllers must honor opt-out preference signals such as Global Privacy Control.","kind":"compliance","sourceUrl":"https://www.doj.state.or.us/consumer-protection/id-theft-data-breaches/privacy/","tentative":false,"review":"verified"},{"id":287,"regulationId":"us-or-ocpa","date":"2026-01-01","title":"Sale ban on precise geolocation and under-16 data (HB 2008)","description":"Selling precise geolocation (1,750-ft radius) and the personal data of consumers the controller knows or willfully disregards are under 16 is prohibited.","kind":"effective","sourceUrl":"https://www.doj.state.or.us/consumer-protection/id-theft-data-breaches/privacy/","tentative":false,"review":"verified"}]},{"id":"us-padfa","name":"Protecting Americans' Data from Foreign Adversaries Act of 2024","shortName":"PADFA","jurisdiction":"us","jurisdictionName":"United States (Federal)","region":"us-federal","topics":["privacy","data-residency"],"status":"in_force","citation":"Pub. L. 118-50, div. I, sec. 2 (15 U.S.C. 9901)","enactedDate":"2024-04-24","effectiveDate":"2024-06-23","summary":"Makes it unlawful for a data broker to sell, license, transfer, disclose or otherwise make available personally identifiable sensitive data of U.S. individuals to a foreign adversary country (China, Iran, North Korea, Russia) or to an entity controlled by one. Covered data is broad, including health, financial, biometric, genetic, precise geolocation, private communications and data about minors.","appliesTo":"Data brokers: entities that, for valuable consideration, make available data of U.S. individuals they did not collect directly from those individuals. Excludes entities acting as service providers, entities whose product is not the data itself, and news reporting. 'Controlled by a foreign adversary' includes entities with 20%+ ownership by foreign adversary persons. No volume threshold.","penalties":"Violations are treated as violations of an FTC rule on unfair or deceptive practices: civil penalties up to $53,088 per violation (FTC Act 5(m)(1)(A) amount as adjusted January 2025, 90 FR 5580; adjusted annually for inflation).","enforcer":"Federal Trade Commission","sourceUrl":"https://www.govinfo.gov/content/pkg/PLAW-118publ50/html/PLAW-118publ50.htm","extraSources":["https://www.congress.gov/bill/118th-congress/house-bill/815"],"notes":"Overlaps with the DOJ bulk data rule (28 CFR Part 202); DOJ rule transactions subject to PADFA are carved out of certain DOJ provisions. No FTC implementing regulations are required.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-24 02:56:54","deadlines":[{"id":288,"regulationId":"us-padfa","date":"2024-06-23","title":"PADFA takes effect","description":"The prohibition takes effect 60 days after enactment (April 24, 2024).","kind":"effective","sourceUrl":"https://www.govinfo.gov/content/pkg/PLAW-118publ50/html/PLAW-118publ50.htm","tentative":false,"review":"verified"}]},{"id":"ca-pipeda","name":"Personal Information Protection and Electronic Documents Act","shortName":"PIPEDA","jurisdiction":"ca","jurisdictionName":"Canada","region":"americas","topics":["privacy","breach-notification"],"status":"in_force","citation":"S.C. 2000, c. 5","enactedDate":"2000-04-13","effectiveDate":"2001-01-01","summary":"Canada's federal private-sector privacy law based on 10 fair information principles, with mandatory breach reporting to the OPC and notification of individuals for breaches creating a real risk of significant harm. It is proposed to be replaced by the Protecting Privacy and Consumer Data Act (Bill C-36, tabled June 2026).","appliesTo":"Private-sector organisations collecting, using or disclosing personal information in the course of commercial activities (except in provinces with substantially similar laws, e.g. Quebec, Alberta, BC for intra-provincial activity), plus federal works, undertakings and businesses' employee data.","penalties":"Fines up to CAD 100,000 per offence for knowingly failing to report/record breaches or obstructing the Commissioner; no administrative monetary penalties.","enforcer":"Office of the Privacy Commissioner of Canada (Federal Court for orders)","sourceUrl":"https://laws-lois.justice.gc.ca/eng/acts/p-8.6/","extraSources":["https://www.priv.gc.ca/"],"notes":"Bill C-27 (CPPA/AIDA) died on the order paper in January 2025. Successor Bill C-36 is tracked separately as ca-c36-ppcda.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-24 02:56:54","deadlines":[{"id":18,"regulationId":"ca-pipeda","date":"2001-01-01","title":"PIPEDA Part 1 in force (phase 1)","description":"Applies to federally regulated organisations.","kind":"effective","sourceUrl":"https://laws-lois.justice.gc.ca/eng/acts/p-8.6/","tentative":false,"review":"verified"},{"id":19,"regulationId":"ca-pipeda","date":"2004-01-01","title":"PIPEDA applies to all commercial activity","description":"Extended to commercial activity in provinces without substantially similar legislation.","kind":"effective","sourceUrl":"https://laws-lois.justice.gc.ca/eng/acts/p-8.6/","tentative":false,"review":"verified"},{"id":20,"regulationId":"ca-pipeda","date":"2018-11-01","title":"Mandatory breach reporting","description":"Breach of security safeguards reporting, notification and record-keeping obligations take effect.","kind":"compliance","sourceUrl":"https://laws-lois.justice.gc.ca/eng/acts/p-8.6/","tentative":false,"review":"verified"}]},{"id":"eu-pld","name":"Directive (EU) 2024/2853 on liability for defective products (new Product Liability Directive)","shortName":"Product Liability Directive","jurisdiction":"eu","jurisdictionName":"European Union","region":"eu","topics":["ai","cybersecurity"],"status":"enacted","citation":"OJ L, 2024/2853, 18.11.2024","enactedDate":"2024-10-23","effectiveDate":"2024-12-08","summary":"Modernises EU strict (no-fault) liability for defective products. Software (including AI systems and SaaS), digital manufacturing files and related digital services now count as products. Destruction or corruption of non-professional data is compensable damage, and missing security updates or cybersecurity vulnerabilities can make a product defective. Courts can order evidence disclosure and presume defectiveness in complex cases.","appliesTo":"Manufacturers (including software developers and AI providers), importers, authorised representatives, fulfilment service providers and, in some cases, distributors and online platforms, for products placed on the EU market on or after 9 Dec 2026. Free and open-source software supplied outside a commercial activity is excluded.","penalties":"Civil liability: compensation for death, personal injury, damage to property and destruction/corruption of data. No regulatory fines. Claims expire 10 years after placing on the market (25 years for latent personal injury).","enforcer":"National courts (private claims by injured persons)","sourceUrl":"https://eur-lex.europa.eu/eli/dir/2024/2853/oj","extraSources":[],"notes":"The companion AI Liability Directive proposal was withdrawn by the Commission (2025 work programme); it is not covered here.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-24 02:56:54","deadlines":[{"id":106,"regulationId":"eu-pld","date":"2024-12-08","title":"New PLD enters into force","description":"Directive entered into force on the twentieth day after publication in the OJ on 18 Nov 2024 (Art 23).","kind":"effective","sourceUrl":"https://eur-lex.europa.eu/eli/dir/2024/2853/oj","tentative":false,"review":"verified"},{"id":107,"regulationId":"eu-pld","date":"2026-12-09","title":"Transposition deadline; old PLD repealed","description":"Member States must transpose by 9 Dec 2026 (Art 22). Directive 85/374/EEC is repealed from that date but still applies to products placed on the market before it (Art 21).","kind":"transition","sourceUrl":"https://eur-lex.europa.eu/eli/dir/2024/2853/oj","tentative":false,"review":"verified"}]},{"id":"ca-qc-law25","name":"Act to modernize legislative provisions as regards the protection of personal information (Law 25, formerly Bill 64)","shortName":"Quebec Law 25","jurisdiction":"ca-qc","jurisdictionName":"Quebec, Canada","region":"americas","topics":["privacy","breach-notification","biometrics"],"status":"in_force","citation":"S.Q. 2021, c. 25 (amending CQLR c. P-39.1)","enactedDate":"2021-09-22","effectiveDate":"2022-09-22","summary":"Overhauls Quebec's private-sector privacy law with GDPR-style duties: a designated person in charge of privacy, confidentiality incident reporting, privacy impact assessments (including before transfers outside Quebec), privacy by default, automated decision transparency, and data portability.","appliesTo":"Any enterprise collecting, holding, using or communicating personal information of individuals in Quebec in the course of carrying on an enterprise; no size threshold.","penalties":"Administrative monetary penalties up to CAD 10 million or 2% of worldwide turnover; penal fines up to CAD 25 million or 4% of worldwide turnover (whichever is greater), doubled for repeat offences; private right of action with punitive damages of at least CAD 1,000 for intentional or grossly negligent breaches.","enforcer":"Commission d'accès à l'information du Québec (CAI)","sourceUrl":"https://www.legisquebec.gouv.qc.ca/en/document/cs/P-39.1","extraSources":["https://www.cai.gouv.qc.ca/"],"notes":"Dates and penalties from well-established sources; LegisQuebec consolidation used as the official reference.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-24 02:56:54","deadlines":[{"id":21,"regulationId":"ca-qc-law25","date":"2021-09-22","title":"Assent","description":"Bill 64 assented to as S.Q. 2021, c. 25.","kind":"effective","sourceUrl":"https://www.legisquebec.gouv.qc.ca/en/document/cs/P-39.1","tentative":false,"review":"verified"},{"id":22,"regulationId":"ca-qc-law25","date":"2022-09-22","title":"Phase 1: privacy officer and incident reporting","description":"Person in charge of personal information protection, confidentiality incident notification and register apply.","kind":"compliance","sourceUrl":"https://www.legisquebec.gouv.qc.ca/en/document/cs/P-39.1","tentative":false,"review":"verified"},{"id":23,"regulationId":"ca-qc-law25","date":"2023-09-22","title":"Phase 2: main obligations and penalties","description":"Governance policies, PIAs, consent, transparency, privacy by default, ADM notices, cross-border PIAs and AMP/penal regime apply.","kind":"compliance","sourceUrl":"https://www.legisquebec.gouv.qc.ca/en/document/cs/P-39.1","tentative":false,"review":"verified"},{"id":24,"regulationId":"ca-qc-law25","date":"2024-09-22","title":"Phase 3: data portability","description":"Right to data portability in a structured, commonly used technological format applies.","kind":"compliance","sourceUrl":"https://www.legisquebec.gouv.qc.ca/en/document/cs/P-39.1","tentative":false,"review":"verified"}]},{"id":"us-ri-dtppa","name":"Rhode Island Data Transparency and Privacy Protection Act","shortName":"Rhode Island RIDTPPA","jurisdiction":"us-ri","jurisdictionName":"Rhode Island","region":"us-states","topics":["privacy"],"status":"in_force","citation":"R.I. Gen. Laws 6-48.1-1 et seq. (P.L. 2024, ch. 430 and ch. 453; H 7787 / S 2500)","enactedDate":"2024-06-28","effectiveDate":"2026-01-01","summary":"Comprehensive consumer privacy law giving access, correction, deletion, portability and opt-out rights, requiring opt-in consent for sensitive data and data protection assessments. A notable extra: any commercial website or ISP that sells personally identifiable information must disclose the categories collected and every third party it has sold or may sell data to, whatever its size.","appliesTo":"For-profit entities conducting business in RI or targeting RI residents that in the preceding calendar year controlled or processed personal data of at least 35,000 customers (excluding payment-only data), or at least 10,000 customers while deriving more than 20% of gross revenue from selling personal data (6-48.1-4). The 6-48.1-3 disclosure duties apply to any commercial website or ISP doing business in RI. Exempts government, nonprofits, higher education, GLBA and HIPAA entities.","penalties":"Violations are deceptive trade practices under R.I. Gen. Laws ch. 6-13.1 (civil penalty up to $10,000 per violation, 6-13.1-8). Intentional disclosures to shell entities or otherwise in violation of the act also carry a fine of $100 to $500 per disclosure (6-48.1-8). No cure period. No private right of action.","enforcer":"Rhode Island Attorney General (sole enforcement authority)","sourceUrl":"https://webserver.rilegislature.gov/Statutes/TITLE6/6-48.1/INDEX.htm","extraSources":["https://webserver.rilegislature.gov/Statutes/TITLE6/6-48.1/6-48.1-4.htm","https://webserver.rilegislature.gov/Statutes/TITLE6/6-48.1/6-48.1-8.htm","https://webserver.rilegislature.gov/Statutes/TITLE6/6-13.1/6-13.1-8.htm"],"notes":"The act became law without the Governor's signature in late June 2024; June 28, 2024 is the commonly reported date and was not confirmed on an official page. The statute has no cure period and no rulemaking authority. No amendments found through Sept 2026.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-24 02:56:54","deadlines":[{"id":289,"regulationId":"us-ri-dtppa","date":"2026-01-01","title":"RIDTPPA takes effect","description":"All provisions of R.I. Gen. Laws ch. 6-48.1 apply (P.L. 2024, ch. 430/453, effective Jan 1, 2026).","kind":"effective","sourceUrl":"https://webserver.rilegislature.gov/Statutes/TITLE6/6-48.1/INDEX.htm","tentative":false,"review":"verified"}]},{"id":"us-sec-cyber","name":"SEC Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure (Release No. 33-11216)","shortName":"SEC Cyber Disclosure Rules","jurisdiction":"us","jurisdictionName":"United States (Federal)","region":"us-federal","topics":["cybersecurity","breach-notification","financial"],"status":"in_force","citation":"Release No. 33-11216; 88 FR 51896 (Aug. 4, 2023); Form 8-K Item 1.05; Regulation S-K Item 106","enactedDate":"2023-07-26","effectiveDate":"2023-09-05","summary":"Public companies must disclose a material cybersecurity incident on Form 8-K Item 1.05 within four business days of determining it is material (foreign private issuers use Form 6-K), and describe cybersecurity risk management, strategy and governance annually in Form 10-K (Item 106) or Form 20-F (Item 16K).","appliesTo":"SEC registrants filing Exchange Act reports, including smaller reporting companies and foreign private issuers. Disclosure delay is available only if the U.S. Attorney General determines immediate disclosure poses a substantial risk to national security or public safety.","penalties":"No fixed fine schedule; violations enforced under the federal securities laws (civil penalties, disgorgement, injunctions, officer and director bars).","enforcer":"U.S. Securities and Exchange Commission","sourceUrl":"https://www.federalregister.gov/documents/2023/08/04/2023-16194/cybersecurity-risk-management-strategy-governance-and-incident-disclosure","extraSources":["https://www.sec.gov/newsroom/press-releases/2023-139","https://www.sec.gov/files/rules/final/2023/33-11216.pdf","https://www.federalregister.gov/documents/2025/06/17/2025-11110/withdrawal-of-proposed-regulatory-actions"],"notes":"Industry petitions (e.g. April 2026 comment letters) ask the SEC to rescind Item 1.05; no proposed rescission had appeared in the Federal Register as of 2026-09-22. In June 2025 the SEC withdrew its separate 2022/2023 cybersecurity risk management proposals for investment advisers/funds and for broker-dealers and other market entities.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-24 02:56:54","deadlines":[{"id":290,"regulationId":"us-sec-cyber","date":"2023-12-15","title":"Annual cybersecurity disclosures begin (Item 106 / 16K)","description":"Required in annual reports for fiscal years ending on or after this date.","kind":"compliance","sourceUrl":"https://www.federalregister.gov/documents/2023/08/04/2023-16194/cybersecurity-risk-management-strategy-governance-and-incident-disclosure","tentative":false,"review":"verified"},{"id":291,"regulationId":"us-sec-cyber","date":"2023-12-18","title":"Form 8-K Item 1.05 incident disclosure begins","description":"All registrants other than smaller reporting companies must file material incident disclosures from this date.","kind":"compliance","sourceUrl":"https://www.federalregister.gov/documents/2023/08/04/2023-16194/cybersecurity-risk-management-strategy-governance-and-incident-disclosure","tentative":false,"review":"verified"},{"id":292,"regulationId":"us-sec-cyber","date":"2024-06-15","title":"Smaller reporting companies: Item 1.05 compliance","description":"Smaller reporting companies must begin complying with Form 8-K Item 1.05 incident disclosure.","kind":"compliance","sourceUrl":"https://www.federalregister.gov/documents/2023/08/04/2023-16194/cybersecurity-risk-management-strategy-governance-and-incident-disclosure","tentative":false,"review":"verified"},{"id":293,"regulationId":"us-sec-cyber","date":"2024-12-15","title":"Inline XBRL tagging of annual cybersecurity disclosures","description":"Item 106 / Item 16K disclosures must be tagged in Inline XBRL for fiscal years ending on or after this date.","kind":"compliance","sourceUrl":"https://www.federalregister.gov/documents/2023/08/04/2023-16194/cybersecurity-risk-management-strategy-governance-and-incident-disclosure","tentative":false,"review":"verified"},{"id":294,"regulationId":"us-sec-cyber","date":"2024-12-18","title":"Inline XBRL tagging of Item 1.05 disclosures","description":"Form 8-K Item 1.05 and Form 6-K incident disclosures must be tagged in Inline XBRL.","kind":"compliance","sourceUrl":"https://www.federalregister.gov/documents/2023/08/04/2023-16194/cybersecurity-risk-management-strategy-governance-and-incident-disclosure","tentative":false,"review":"verified"}]},{"id":"us-sec-reg-sp","name":"Regulation S-P: Privacy of Consumer Financial Information and Safeguarding Customer Information (2024 amendments)","shortName":"SEC Regulation S-P","jurisdiction":"us","jurisdictionName":"United States (Federal)","region":"us-federal","topics":["financial","privacy","cybersecurity","breach-notification"],"status":"amended","citation":"17 CFR Part 248; 89 FR 47688 (June 3, 2024)","enactedDate":"2024-05-16","effectiveDate":"2024-08-02","summary":"Requires broker-dealers, investment companies, registered investment advisers and transfer agents to adopt a written incident response program and notify affected individuals as soon as practicable, and no later than 30 days, after becoming aware that sensitive customer information was, or is reasonably likely to have been, accessed or used without authorization. Service providers must be overseen and must notify the covered institution within 72 hours of a breach; recordkeeping and annual privacy notice changes also apply.","appliesTo":"SEC-registered broker-dealers (incl. funding portals), investment companies, registered investment advisers and transfer agents. 'Larger entities' (earlier deadline): investment companies with $1 billion+ net assets (with related funds), RIAs with $1.5 billion+ AUM, and broker-dealers and transfer agents that are not small entities; all others are smaller entities.","penalties":"No fixed fine schedule; enforced under the federal securities laws (civil penalties, cease-and-desist orders, censures, bars).","enforcer":"U.S. Securities and Exchange Commission","sourceUrl":"https://www.federalregister.gov/documents/2024/06/03/2024-11116/regulation-s-p-privacy-of-consumer-financial-information-and-safeguarding-customer-information","extraSources":["https://www.ecfr.gov/current/title-17/chapter-II/part-248/subpart-A/section-248.30"],"notes":"Compliance dates are stated in the release as 18 and 24 months after the June 3, 2024 publication. No delay of these dates was found in the Federal Register as of 2026-09-22.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-24 02:56:54","deadlines":[{"id":295,"regulationId":"us-sec-reg-sp","date":"2024-08-02","title":"Amendments effective","description":"The Regulation S-P amendments became effective; compliance tiered by entity size.","kind":"effective","sourceUrl":"https://www.federalregister.gov/documents/2024/06/03/2024-11116/regulation-s-p-privacy-of-consumer-financial-information-and-safeguarding-customer-information","tentative":false,"review":"verified"},{"id":296,"regulationId":"us-sec-reg-sp","date":"2025-12-03","title":"Larger entities must comply","description":"Larger covered institutions (18 months after Federal Register publication) must have incident response programs, 30-day customer notification, and service-provider oversight in place.","kind":"compliance","sourceUrl":"https://www.federalregister.gov/documents/2024/06/03/2024-11116/regulation-s-p-privacy-of-consumer-financial-information-and-safeguarding-customer-information","tentative":false,"review":"verified"},{"id":297,"regulationId":"us-sec-reg-sp","date":"2026-06-03","title":"Smaller entities must comply","description":"Smaller covered institutions (24 months after Federal Register publication) must comply with the amended Regulation S-P.","kind":"compliance","sourceUrl":"https://www.federalregister.gov/documents/2024/06/03/2024-11116/regulation-s-p-privacy-of-consumer-financial-information-and-safeguarding-customer-information","tentative":false,"review":"verified"}]},{"id":"sa-pdpl","name":"Personal Data Protection Law (Royal Decree M/19 of 9/2/1443H, as amended by Royal Decree M/148 of 5/9/1444H)","shortName":"Saudi PDPL","jurisdiction":"sa","jurisdictionName":"Saudi Arabia","region":"mea","topics":["privacy","data-residency","breach-notification"],"status":"in_force","citation":"Royal Decree M/19 (1443H); amended by Royal Decree M/148 (1444H)","enactedDate":"2021-09-16","effectiveDate":"2023-09-14","summary":"Saudi Arabia's comprehensive data protection law with implementing regulations and separate transfer regulations: legal bases, data subject rights, breach notification to SDAIA within 72 hours, DPO and registration requirements, and restrictions on transfers outside the Kingdom.","appliesTo":"Any processing of personal data of individuals in Saudi Arabia by entities inside or outside the Kingdom, including data of deceased persons.","penalties":"Disclosure/publication of sensitive data with intent to harm: up to 2 years' imprisonment and/or fine up to SAR 3 million; other violations: warning or fine up to SAR 5 million, which may be doubled for repeat violations.","enforcer":"Saudi Data and Artificial Intelligence Authority (SDAIA) / National Data Management Office","sourceUrl":"https://sdaia.gov.sa/en/SDAIA/about/Documents/Personal%20Data%20English%20V2-23April2023-%20Reviewed-.pdf","extraSources":["https://sdaia.gov.sa/","https://iapp.org/news/a/saudi-pdpl-s-first-anniversary-amendments-enforcement-and-ongoing-developments"],"notes":"SDAIA consulted on amendments to the implementing regulations (closed 27 May 2025); adoption not verified.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-24 02:56:54","deadlines":[{"id":137,"regulationId":"sa-pdpl","date":"2023-09-14","title":"PDPL in force","description":"PDPL and its implementing regulations take effect.","kind":"effective","sourceUrl":"https://sdaia.gov.sa/en/SDAIA/about/Documents/Personal%20Data%20English%20V2-23April2023-%20Reviewed-.pdf","tentative":false,"review":"verified"},{"id":138,"regulationId":"sa-pdpl","date":"2024-09-14","title":"One-year grace period ends","description":"Grace period for controllers to comply ends; PDPL fully enforceable.","kind":"enforcement","sourceUrl":"https://sdaia.gov.sa/en/SDAIA/about/Documents/Personal%20Data%20English%20V2-23April2023-%20Reviewed-.pdf","tentative":false,"review":"verified"}]},{"id":"sg-pdpa","name":"Personal Data Protection Act 2012 (Singapore)","shortName":"Singapore PDPA","jurisdiction":"sg","jurisdictionName":"Singapore","region":"apac","topics":["privacy","breach-notification"],"status":"in_force","citation":"Act 26 of 2012; amended by Personal Data Protection (Amendment) Act 2020","enactedDate":"2012-10-15","effectiveDate":"2014-07-02","summary":"Singapore's baseline private-sector data protection law covering consent, purpose limitation, notification, access and correction, protection, retention, transfer limitation, and the Do Not Call registry. The 2020 amendments added mandatory breach notification, expanded deemed consent and legitimate-interests exceptions, and raised fines.","appliesTo":"All private-sector organizations collecting, using or disclosing personal data in Singapore (public agencies excluded). Breach notification: notify PDPC within 3 calendar days of assessing a breach as notifiable (significant harm, or affecting 500+ individuals).","penalties":"Financial penalties up to 10% of annual Singapore turnover for organizations with turnover above SGD 10 million, otherwise up to SGD 1 million (since 1 Oct 2022). Criminal offences for individuals who mishandle personal data.","enforcer":"Personal Data Protection Commission (PDPC)","sourceUrl":"https://www.pdpc.gov.sg/overview-of-pdpa/the-legislation/personal-data-protection-act","extraSources":["https://sso.agc.gov.sg/Act/PDPA2012"],"notes":"Dates and thresholds come from established knowledge; the PDPC overview page did not list them and sso.agc.gov.sg blocked automated fetch. The data portability obligation has been legislated but not yet brought into force. No 2025-2026 PDPA amendment was found.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-24 02:56:54","deadlines":[{"id":139,"regulationId":"sg-pdpa","date":"2014-07-02","title":"PDPA data protection obligations take effect","description":"Main data protection provisions come into force.","kind":"effective","sourceUrl":"https://sso.agc.gov.sg/Act/PDPA2012","tentative":false,"review":"verified"},{"id":140,"regulationId":"sg-pdpa","date":"2021-02-01","title":"2020 amendments largely in force","description":"Mandatory data breach notification and revised consent framework apply.","kind":"effective","sourceUrl":"https://sso.agc.gov.sg/Act/PDPA2012","tentative":false,"review":"verified"},{"id":141,"regulationId":"sg-pdpa","date":"2022-10-01","title":"Higher financial penalty cap applies","description":"Maximum penalty rises to 10% of Singapore turnover for organizations with turnover above SGD 10 million.","kind":"enforcement","sourceUrl":"https://sso.agc.gov.sg/Act/PDPA2012","tentative":false,"review":"verified"}]},{"id":"za-popia","name":"Protection of Personal Information Act, 2013 (Act No. 4 of 2013)","shortName":"South Africa POPIA","jurisdiction":"za","jurisdictionName":"South Africa","region":"mea","topics":["privacy","breach-notification"],"status":"in_force","citation":"Act No. 4 of 2013","enactedDate":"2013-11-19","effectiveDate":"2020-07-01","summary":"South Africa's comprehensive data protection law built on eight conditions for lawful processing, with Information Officer registration, security compromise notification to the Regulator and data subjects, and restrictions on direct marketing and cross-border transfers. Protects juristic persons as well as individuals.","appliesTo":"Responsible parties domiciled in South Africa, or not domiciled but using automated or non-automated means in South Africa.","penalties":"Administrative fines up to ZAR 10 million; criminal offences punishable by fines or imprisonment up to 10 years (e.g. obstruction, unlawful acts relating to account numbers).","enforcer":"Information Regulator (South Africa)","sourceUrl":"https://www.gov.za/documents/protection-personal-information-act","extraSources":["https://inforegulator.org.za/"],"notes":"Amendments to the POPIA Regulations were reported as gazetted in April 2025 (including electronic breach reporting via the eServices portal); exact date not verified so omitted.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-24 02:56:54","deadlines":[{"id":325,"regulationId":"za-popia","date":"2020-07-01","title":"Main POPIA provisions commence","description":"Most sections commence with a 12-month grace period.","kind":"effective","sourceUrl":"https://www.gov.za/documents/protection-personal-information-act","tentative":false,"review":"verified"},{"id":326,"regulationId":"za-popia","date":"2021-07-01","title":"Compliance grace period ends","description":"Responsible parties must comply; Regulator enforcement begins (grace period ended 30 June 2021).","kind":"enforcement","sourceUrl":"https://www.gov.za/documents/protection-personal-information-act","tentative":false,"review":"verified"}]},{"id":"kr-ai-basic-act","name":"Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust (AI Basic Act)","shortName":"South Korea AI Basic Act","jurisdiction":"kr","jurisdictionName":"South Korea","region":"apac","topics":["ai"],"status":"in_force","citation":"Framework Act on AI Development and Trust (promulgated Jan 2025) and its Enforcement Decree","enactedDate":"2025-01-21","effectiveDate":"2026-01-22","summary":"Korea's comprehensive AI law: transparency duties (notify users in advance that AI is used, label generative AI outputs and deepfakes), risk management, explainability and human oversight for 'high-impact' AI (e.g. hiring, lending, healthcare), safety duties for very large models (10^26 FLOPs+ training compute), and a domestic representative for large foreign providers. MSIT is running a grace period of at least one year, deferring fact-finding and fines except in serious cases.","appliesTo":"AI business operators (developers and deployers) whose activities affect the Korean market. Foreign operators without a Korean address must appoint a domestic representative if they meet any of: prior-year total revenue of KRW 1 trillion+, AI-service revenue of KRW 10 billion+, or 1 million+ average daily Korean users over the prior 3 months.","penalties":"Administrative fines up to KRW 30 million, for example for failing to notify AI use or label outputs, failing to appoint a domestic representative, or not complying with corrective orders. Fines generally deferred during the grace period of at least one year from 22 Jan 2026.","enforcer":"Ministry of Science and ICT (MSIT)","sourceUrl":"https://www.law.go.kr/법령/인공지능발전과신뢰기반조성등에관한기본법","extraSources":["https://www.trade.gov/market-intelligence/south-korea-ai-basic-act","https://www.shinkim.com/eng/media/newsletter/3117","https://www.cooley.com/news/insight/2026/2026-01-27-south-koreas-ai-basic-act-overview-and-key-takeaways"],"notes":"The grace period is 'at least one year' with no fixed end date announced, so there is no enforcement deadline row. The promulgation date (21 Jan 2025) and passage (26 Dec 2024) come from general knowledge and secondary sources; law.go.kr could not be parsed. Labeling breaches may lead to corrective orders before fines.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-24 02:56:54","deadlines":[{"id":124,"regulationId":"kr-ai-basic-act","date":"2026-01-22","title":"AI Basic Act and Enforcement Decree take effect","description":"Transparency, labeling, high-impact AI, and domestic representative obligations apply (fines deferred during the grace period).","kind":"effective","sourceUrl":"https://www.law.go.kr/법령/인공지능발전과신뢰기반조성등에관한기본법","tentative":false,"review":"verified"}]},{"id":"kr-pipa","name":"Personal Information Protection Act (as amended by Act No. 21445, 2026)","shortName":"South Korea PIPA","jurisdiction":"kr","jurisdictionName":"South Korea","region":"apac","topics":["privacy","breach-notification","biometrics","data-residency"],"status":"amended","citation":"Act No. 10465 (2011); latest amendment Act No. 21445 (promulgated 10 Mar 2026)","enactedDate":"2011-03-29","effectiveDate":"2011-09-30","summary":"Korea's comprehensive privacy law, with consent-centric processing, breach notification, cross-border transfer rules, automated decision rights (since 2024), and revenue-based penalty surcharges. The 2026 amendment, effective 11 September 2026, raises the maximum fine to 10% of total revenue for aggravated cases, makes the CEO the ultimate responsible person, requires notice when a breach is merely possible, and makes ISMS-P certification mandatory for certain entities from 1 July 2027.","appliesTo":"All personal information controllers (public and private) processing personal information of people in Korea; foreign controllers above set thresholds must designate a domestic representative. 10% fines apply to repeat intentional or grossly negligent violations within 3 years, intentional or grossly negligent conduct affecting 10 million+ people, or a breach after ignoring a PIPC corrective order.","penalties":"Before 11 Sept 2026: penalty surcharge up to 3% of total revenue (excluding revenue unrelated to the violation), in place since 2023. From 11 Sept 2026: up to 10% of total revenue in aggravated cases, with reductions for qualifying privacy investment. Criminal penalties also apply.","enforcer":"Personal Information Protection Commission (PIPC)","sourceUrl":"https://www.law.go.kr/법령/개인정보보호법","extraSources":["https://www.pipc.go.kr/eng/index.do","https://www.hunton.com/privacy-and-cybersecurity-law-blog/south-korea-amends-privacy-law-to-authorize-fines-of-up-to-10-of-total-revenue","https://iapp.org/news/a/south-korea-overhauls-pipa-and-ties-fines-to-ceo-accountability","https://www.yulchon.com/en/resources/publications/newsletter-view/43667/page.do"],"notes":"The National Assembly passed the amendment on 12 Feb 2026 and the PIPC announced promulgation for 10 Mar 2026 with effect from 11 Sep 2026. Fact-check 2026-09-22 confirmed on law.go.kr: 개인정보 보호법 [시행 2026. 9. 11.] [법률 제21445호, 2026. 3. 10., 일부개정]; Addendum Art 1 sets effect 6 months after promulgation, except the Art 32-2(1) proviso (mandatory certification for controllers meeting Presidential Decree criteria on revenue and processing scale) and Art 75(2)15, which apply from 1 July 2027; Art 64-2(2) sets the 10% of total revenue cap (KRW 5 billion where revenue cannot be calculated) for repeat intentional or grossly negligent violations within 3 years, violations affecting 10 million+ people, or breaches after ignoring a corrective order. The 3% pre-existing cap comes from the 2023 amendment. The 2011 enactment and effective dates come from general knowledge. The ISMS-P scope criteria are set by decree.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-24 02:56:54","deadlines":[{"id":125,"regulationId":"kr-pipa","date":"2026-03-10","title":"2026 PIPA amendment promulgated (Act No. 21445)","description":"Amendment raising fines to 10% of revenue and adding CEO accountability promulgated.","kind":"transition","sourceUrl":"https://www.law.go.kr/법령/개인정보보호법","tentative":false,"review":"verified"},{"id":126,"regulationId":"kr-pipa","date":"2026-09-11","title":"2026 PIPA amendments take effect","description":"10%-of-revenue fines, CEO accountability, and notice duties for possible breaches apply.","kind":"effective","sourceUrl":"https://www.law.go.kr/법령/개인정보보호법","tentative":false,"review":"verified"},{"id":127,"regulationId":"kr-pipa","date":"2027-07-01","title":"Mandatory ISMS-P certification","description":"ISMS-P certification becomes mandatory for private entities meeting the statutory criteria.","kind":"compliance","sourceUrl":"https://www.law.go.kr/법령/개인정보보호법","tentative":false,"review":"verified"}]},{"id":"ch-fadp","name":"Federal Act on Data Protection (revised FADP) of 25 September 2020","shortName":"Swiss revised FADP (nFADP)","jurisdiction":"ch","jurisdictionName":"Switzerland","region":"uk-europe","topics":["privacy","breach-notification"],"status":"in_force","citation":"SR 235.1","enactedDate":"2020-09-25","effectiveDate":"2023-09-01","summary":"Switzerland's modernised data protection law, closely aligned to GDPR: privacy by design/default, records of processing, DPIAs, breach notification to the FDPIC as soon as possible, and cross-border transfer rules. Protects only natural persons' data.","appliesTo":"Private persons and federal bodies processing personal data of natural persons, including processing abroad that has effects in Switzerland. Records-of-processing exemption for companies with fewer than 250 employees unless high-risk processing.","penalties":"Criminal fines of up to CHF 250,000 imposed on responsible individuals (not the company) for intentional breaches of key duties.","enforcer":"Federal Data Protection and Information Commissioner (FDPIC); cantonal criminal prosecution authorities","sourceUrl":"https://www.fedlex.admin.ch/eli/cc/2022/491/en","extraSources":["https://www.edoeb.admin.ch/"],"notes":"No transition period was granted.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-24 02:56:54","deadlines":[{"id":25,"regulationId":"ch-fadp","date":"2023-09-01","title":"Revised FADP enters into force","description":"Revised FADP and Data Protection Ordinance apply with no transition period.","kind":"effective","sourceUrl":"https://www.fedlex.admin.ch/eli/cc/2022/491/en","tentative":false,"review":"verified"}]},{"id":"us-take-it-down","name":"Tools to Address Known Exploitation by Immobilizing Technological Deepfakes on Websites and Networks Act (TAKE IT DOWN Act)","shortName":"TAKE IT DOWN Act","jurisdiction":"us","jurisdictionName":"United States (Federal)","region":"us-federal","topics":["online-safety","ai","children","privacy"],"status":"in_force","citation":"Pub. L. 119-12 (S. 146)","enactedDate":"2025-05-19","effectiveDate":"2025-05-19","summary":"Criminalizes knowingly publishing non-consensual intimate images, including AI-generated 'digital forgeries', and threats to do so. Covered platforms must set up a notice-and-removal process and remove reported content, plus known identical copies, within 48 hours of a valid request.","appliesTo":"Covered platforms: public-facing websites, online services and apps that primarily host user-generated content, or regularly publish or host non-consensual intimate imagery. Excludes broadband providers and email, among others. Criminal provisions apply to any person.","penalties":"Platform failures to comply with notice-and-removal are treated as FTC rule violations: civil penalties up to $53,088 per violation (FTC Act 5(m)(1)(A) amount as adjusted January 2025, 90 FR 5580; adjusted annually for inflation). Individuals: fines and up to 2 years' imprisonment (adults depicted) or 3 years (minors depicted); threats carry lesser terms.","enforcer":"Federal Trade Commission (platform obligations, including over non-profits); DOJ (criminal provisions)","sourceUrl":"https://www.congress.gov/bill/119th-congress/senate-bill/146","extraSources":["https://www.govinfo.gov/content/pkg/PLAW-119publ12/html/PLAW-119publ12.htm"],"notes":"Platforms get a good-faith safe harbor for removals. FTC penalty figure is the January 2025 adjustment.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-24 02:56:54","deadlines":[{"id":298,"regulationId":"us-take-it-down","date":"2025-05-19","title":"Criminal provisions effective on enactment","description":"Publishing or threatening to publish non-consensual intimate images, including digital forgeries, became a federal crime upon signature.","kind":"effective","sourceUrl":"https://www.govinfo.gov/content/pkg/PLAW-119publ12/html/PLAW-119publ12.htm","tentative":false,"review":"verified"},{"id":299,"regulationId":"us-take-it-down","date":"2026-05-19","title":"Platform notice-and-removal process required","description":"Covered platforms must have a clear notice-and-removal process and remove valid reported content within 48 hours (Sec. 3, one year after enactment).","kind":"compliance","sourceUrl":"https://www.govinfo.gov/content/pkg/PLAW-119publ12/html/PLAW-119publ12.htm","tentative":false,"review":"verified"}]},{"id":"us-tx-traiga","name":"Texas Responsible Artificial Intelligence Governance Act (HB 149, 89th Legislature)","shortName":"TRAIGA","jurisdiction":"us-tx","jurisdictionName":"Texas","region":"us-states","topics":["ai","biometrics"],"status":"in_force","citation":"Tex. HB 149 (89th Leg., R.S., 2025)","enactedDate":"2025-06-22","effectiveDate":"2026-01-01","summary":"Bans developing or deploying AI with the intent to incite self-harm or crime, to unlawfully discriminate against a protected class, to produce child sexual abuse material or unlawful sexual deepfakes, or to infringe constitutional rights. Government agencies must also disclose AI use and may not use it for social scoring or biometric identification without consent. Creates a Texas AI regulatory sandbox, where approved participants can test systems for up to 36 months, and a Texas AI Council. Liability generally turns on intent, not disparate impact alone.","appliesTo":"Any person who promotes, advertises or conducts business in Texas, produces a product or service used by Texas residents, or develops or deploys an AI system in Texas. Most disclosure duties fall on governmental entities. No revenue threshold.","penalties":"Civil penalties: $10,000 to $12,000 per curable violation; $80,000 to $200,000 per uncurable violation; $2,000 to $40,000 per day for continuing violations. 60-day cure period after written AG notice. No private right of action.","enforcer":"Texas Attorney General (exclusive); state licensing agencies may impose additional sanctions on licensees","sourceUrl":"https://capitol.texas.gov/BillLookup/History.aspx?LegSess=89R&Bill=HB149","extraSources":["https://capitol.texas.gov/tlodocs/89R/billtext/html/HB00149F.htm","https://iapp.org/news/a/governor-signs-texas-responsible-artificial-intelligence-governance-act","https://www.klgates.com/Pared-Back-Version-of-the-Texas-Responsible-Artificial-Intelligence-Governance-Act-Signed-Into-Law-6-24-2025"],"notes":"Penalty ranges were confirmed via secondary sources (IAPP, K&L Gates) matching the enrolled text. No 2026 amendments were found; the Texas Legislature has no regular session in 2026.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-24 02:56:54","deadlines":[{"id":303,"regulationId":"us-tx-traiga","date":"2025-06-22","title":"HB 149 signed","description":"Governor Abbott signs TRAIGA.","kind":"transition","sourceUrl":"https://capitol.texas.gov/BillLookup/History.aspx?LegSess=89R&Bill=HB149","tentative":false,"review":"verified"},{"id":304,"regulationId":"us-tx-traiga","date":"2026-01-01","title":"TRAIGA takes effect","description":"Prohibited-practice rules, AG enforcement, sandbox program and government AI disclosure duties apply.","kind":"effective","sourceUrl":"https://capitol.texas.gov/BillLookup/History.aspx?LegSess=89R&Bill=HB149","tentative":false,"review":"verified"}]},{"id":"us-tn-tipa","name":"Tennessee Information Protection Act (HB 1181 / SB 73, 2023)","shortName":"Tennessee TIPA","jurisdiction":"us-tn","jurisdictionName":"Tennessee","region":"us-states","topics":["privacy"],"status":"in_force","citation":"Tenn. Code Ann. 47-18-3301 et seq. (Pub. Ch. 408, 2023)","enactedDate":"2023-05-24","effectiveDate":"2025-07-01","summary":"Comprehensive consumer privacy law with access, correction, deletion, portability and opt-out rights (sale, targeted ads, profiling), opt-in consent for sensitive data and data protection assessments. Controllers must keep a written privacy program that reasonably conforms to the NIST Privacy Framework, which also serves as an affirmative defense.","appliesTo":"Persons doing business in TN or targeting TN residents with annual revenue over $25 million that either control or process personal information of 175,000+ consumers in a calendar year, or control or process personal information of 25,000+ consumers and derive more than 50% of gross revenue from selling personal information. Exempts GLBA financial institutions, HIPAA entities, nonprofits, higher education, insurers and others.","penalties":"Civil penalty up to $7,500 per violation; treble damages for willful or knowing violations; injunctive relief and AG fees. 60-day cure notice required before any action; it does not sunset. No private right of action.","enforcer":"Tennessee Attorney General and Reporter (exclusive)","sourceUrl":"https://wapp.capitol.tn.gov/apps/BillInfo/Default.aspx?BillNumber=HB1181&GA=113","extraSources":[],"notes":"The Legislature's bill history records Pub. Ch. 408 signed by the Governor on May 24, 2023 (sent to the Governor May 11, 2023). The 60-day cure right is permanent, so there is no cure-sunset deadline. No amendments found through Sept 2026.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-24 02:56:54","deadlines":[{"id":300,"regulationId":"us-tn-tipa","date":"2025-07-01","title":"TIPA takes effect","description":"Controller and processor obligations and consumer rights under Tenn. Code Ann. 47-18-3301 et seq. apply.","kind":"effective","sourceUrl":"https://wapp.capitol.tn.gov/apps/BillInfo/Default.aspx?BillNumber=HB1181&GA=113","tentative":false,"review":"verified"}]},{"id":"us-tx-tdpsa","name":"Texas Data Privacy and Security Act (HB 4, 2023)","shortName":"Texas TDPSA","jurisdiction":"us-tx","jurisdictionName":"Texas","region":"us-states","topics":["privacy"],"status":"in_force","citation":"Tex. Bus. & Com. Code ch. 541 (Acts 2023, 88th Leg., R.S., HB 4)","enactedDate":"2023-06-18","effectiveDate":"2024-07-01","summary":"Comprehensive consumer privacy law with access, correction, deletion, portability and opt-out rights, opt-in consent for sensitive data, data protection assessments and a universal opt-out signal requirement. Scope turns on the SBA small-business definition instead of consumer-count thresholds, so it reaches most non-small businesses.","appliesTo":"Persons conducting business in Texas or producing products/services consumed by Texas residents that process or sell personal data and are not a small business as defined by the U.S. Small Business Administration (no consumer-count threshold). Small businesses may not sell sensitive data without consent. Exempts state agencies, GLBA financial institutions, HIPAA entities, nonprofits, higher education, utilities.","penalties":"Civil penalty up to $7,500 per violation, plus injunctive relief and AG fees/expenses. Mandatory 30-day notice-and-cure period before any action; it does not sunset. No private right of action.","enforcer":"Texas Attorney General (exclusive)","sourceUrl":"https://capitol.texas.gov/BillLookup/History.aspx?LegSess=88R&Bill=HB4","extraSources":["https://statutes.capitol.texas.gov/Docs/BC/htm/BC.541.htm"],"notes":"The penalty ($7,500) and cure terms are from the enrolled statute. They were not re-read from the official statute site on Sept 22, 2026 because that site renders via JavaScript. No amendments to ch. 541 found through Sept 2026. The Texas AG has brought TDPSA enforcement actions (e.g. against Allstate/Arity, Jan 2025).","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-24 02:56:54","deadlines":[{"id":301,"regulationId":"us-tx-tdpsa","date":"2024-07-01","title":"TDPSA takes effect","description":"Most TDPSA obligations and consumer rights apply.","kind":"effective","sourceUrl":"https://capitol.texas.gov/BillLookup/History.aspx?LegSess=88R&Bill=HB4","tentative":false,"review":"verified"},{"id":302,"regulationId":"us-tx-tdpsa","date":"2025-01-01","title":"Universal opt-out mechanism requirement applies","description":"Controllers must honor global privacy control / universal opt-out signals (Bus. & Com. Code 541.055(e)).","kind":"compliance","sourceUrl":"https://capitol.texas.gov/BillLookup/History.aspx?LegSess=88R&Bill=HB4","tentative":false,"review":"verified"}]},{"id":"th-pdpa","name":"Personal Data Protection Act B.E. 2562 (2019)","shortName":"Thailand PDPA","jurisdiction":"th","jurisdictionName":"Thailand","region":"apac","topics":["privacy","breach-notification","data-residency"],"status":"in_force","citation":"Government Gazette Vol. 136, Part 69 Kor, 27 May 2019","enactedDate":"2019-05-24","effectiveDate":"2022-06-01","summary":"Thailand's GDPR-style data protection law: lawful bases including explicit consent for sensitive data, data subject rights, DPOs for large-scale or sensitive processing, breach notification to the PDPC within 72 hours, and cross-border transfer restrictions. Main obligations applied from 1 June 2022 after two postponements.","appliesTo":"Data controllers and processors in Thailand, and those outside Thailand offering goods or services to, or monitoring the behaviour of, data subjects in Thailand.","penalties":"Administrative fines up to THB 5 million per violation; criminal penalties up to 1 year imprisonment and/or THB 1 million for some offences; civil punitive damages up to twice actual damages.","enforcer":"Personal Data Protection Committee (PDPC) and its Office","sourceUrl":"https://www.ratchakitcha.soc.go.th/DATA/PDF/2562/A/069/T_0052.PDF","extraSources":["https://www.pdpc.or.th/"],"notes":"Dates and penalty figures come from established knowledge; the official ratchakitcha and PDPC sites blocked automated fetch, so re-verification was not possible this run. The 24 May 2019 enactment date is the date of royal endorsement (the gazette was published 27 May 2019). No 2025-2026 amendment was checked (search budget exhausted).","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-24 02:56:54","deadlines":[{"id":142,"regulationId":"th-pdpa","date":"2022-06-01","title":"PDPA main obligations take effect","description":"Core data protection obligations and penalties apply after postponement Royal Decrees.","kind":"effective","sourceUrl":"https://www.ratchakitcha.soc.go.th/DATA/PDF/2562/A/069/T_0052.PDF","tentative":false,"review":"verified"}]},{"id":"tr-kvkk","name":"Law No. 6698 on the Protection of Personal Data (KVKK), as amended by Law No. 7499","shortName":"Turkey KVKK","jurisdiction":"tr","jurisdictionName":"Turkey","region":"uk-europe","topics":["privacy","data-residency"],"status":"amended","citation":"Law No. 6698 (OG 7 April 2016); amended by Law No. 7499 (OG 12 March 2024)","enactedDate":"2016-03-24","effectiveDate":"2016-04-07","summary":"Turkey's general data protection law. The 2024 amendments reworked sensitive-data processing and replaced the consent-first cross-border transfer rule with a GDPR-style tiered regime (adequacy, appropriate safeguards such as standard contracts that must be notified to the Authority within 5 business days, then limited derogations).","appliesTo":"All natural and legal persons processing personal data in Turkey; data controllers meeting VERBIS thresholds must register.","penalties":"Administrative fines set in Article 18 and revalued annually (amounts not verified here); under Law 7499, failure to notify standard contracts carries a separate administrative fine.","enforcer":"Personal Data Protection Authority (KVKK) / Personal Data Protection Board","sourceUrl":"https://www.resmigazete.gov.tr/eskiler/2024/03/20240312-1.htm","extraSources":["https://www.kvkk.gov.tr/"],"notes":"Dates from recollection cross-checked only against the Official Gazette issue reference; fine amounts omitted because they are revalued each year.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-24 02:56:54","deadlines":[{"id":143,"regulationId":"tr-kvkk","date":"2024-06-01","title":"Law 7499 amendments take effect","description":"New sensitive data and cross-border transfer rules (Arts. 6 and 9) apply.","kind":"effective","sourceUrl":"https://www.resmigazete.gov.tr/eskiler/2024/03/20240312-1.htm","tentative":false,"review":"verified"},{"id":144,"regulationId":"tr-kvkk","date":"2024-09-01","title":"Old transfer regime ends","description":"Transitional period ends in which the former Article 9 explicit-consent transfer basis could still be relied on.","kind":"transition","sourceUrl":"https://www.resmigazete.gov.tr/eskiler/2024/03/20240312-1.htm","tentative":false,"review":"verified"}]},{"id":"ae-pdpl","name":"Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data","shortName":"UAE PDPL","jurisdiction":"ae","jurisdictionName":"United Arab Emirates","region":"mea","topics":["privacy","breach-notification","data-residency"],"status":"in_force","citation":"Federal Decree-Law No. 45 of 2021","enactedDate":"2021-09-20","effectiveDate":"2022-01-02","summary":"Federal GDPR-style data protection law for the onshore UAE covering consent and other bases, data subject rights, breach notification, DPOs and cross-border transfers. Key details (including fines and some thresholds) depend on Executive Regulations that have not been issued.","appliesTo":"Processing of personal data of UAE residents or by controllers/processors established in the UAE; excludes free zones with their own laws (DIFC, ADGM), government data, and health/banking data covered by sectoral laws.","penalties":"Administrative penalties to be set by Cabinet decision; not yet issued.","enforcer":"UAE Data Office","sourceUrl":"https://uaelegislation.gov.ae/en/legislations/1972","extraSources":["https://u.ae/en/about-the-uae/digital-uae/data/data-protection-laws"],"notes":"Executive Regulations still unpublished as of 2026; organisations get six months from their issuance to comply. No dated compliance deadline yet.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-24 02:56:54","deadlines":[{"id":1,"regulationId":"ae-pdpl","date":"2022-01-02","title":"PDPL enters into force","description":"Decree-law takes effect; compliance obligations tied to Executive Regulations.","kind":"effective","sourceUrl":"https://uaelegislation.gov.ae/en/legislations/1972","tentative":false,"review":"verified"}]},{"id":"uk-csr-bill","name":"Cyber Security and Resilience (Network and Information Systems) Bill","shortName":"UK Cyber Security and Resilience Bill","jurisdiction":"uk","jurisdictionName":"United Kingdom","region":"uk-europe","topics":["cybersecurity","breach-notification"],"status":"proposed","citation":"Bill 4035 (HL Bill, 2026 session)","enactedDate":"","effectiveDate":"","summary":"Updates the NIS Regulations 2018: brings managed service providers and data centres into scope, lets regulators designate critical suppliers, tightens incident reporting (initial notice within 24 hours, full report within 72 hours) and strengthens regulator powers. Substantive duties will follow via secondary legislation after Royal Assent.","appliesTo":"Operators of essential services and relevant digital service providers under NIS, plus (proposed) managed service providers, data centres above capacity thresholds, and designated critical suppliers.","penalties":"Proposed higher maximum penalties aligned with turnover-based fines; final figures depend on the enacted text (not verified).","enforcer":"Sector NIS competent authorities and the ICO (for digital services); DSIT policy lead","sourceUrl":"https://bills.parliament.uk/bills/4035","extraSources":["https://bills-api.parliament.uk/api/v1/Bills/4035/Stages","https://compliancehub.wiki/uk-cyber-security-resilience-bill-lords-committee-september-2026-msp-data-centre-scope/"],"notes":"Not yet law as of 2026-09-22 (in House of Lords). Royal Assent expected late 2026 or early 2027; substantive obligations expected around 2028 via secondary legislation. 24h/72h reporting timeline is from the government's published policy, not the final text.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-24 02:56:54","deadlines":[{"id":145,"regulationId":"uk-csr-bill","date":"2025-11-12","title":"Introduced (Commons first reading)","description":"Bill introduced in the House of Commons.","kind":"effective","sourceUrl":"https://bills.parliament.uk/bills/4035","tentative":false,"review":"verified"},{"id":146,"regulationId":"uk-csr-bill","date":"2026-06-16","title":"Passes House of Commons","description":"Report stage and third reading completed in the Commons after carry-over into the new session.","kind":"effective","sourceUrl":"https://bills.parliament.uk/bills/4035","tentative":false,"review":"verified"},{"id":147,"regulationId":"uk-csr-bill","date":"2026-10-26","title":"Lords report stage scheduled","description":"House of Lords report stage scheduled (committee stage sat 1, 3 and 7 Sept 2026).","kind":"effective","sourceUrl":"https://bills.parliament.uk/bills/4035","tentative":true,"review":"verified"}]},{"id":"uk-gdpr","name":"UK General Data Protection Regulation and Data Protection Act 2018","shortName":"UK GDPR","jurisdiction":"uk","jurisdictionName":"United Kingdom","region":"uk-europe","topics":["privacy","breach-notification"],"status":"amended","citation":"Data Protection Act 2018 c. 12; UK GDPR (retained Regulation (EU) 2016/679)","enactedDate":"2018-05-23","effectiveDate":"2018-05-25","summary":"The UK's core data protection regime: lawful bases, transparency, data subject rights, security, breach notification within 72 hours, and international transfer rules. Retained EU GDPR became the UK GDPR from 1 January 2021 and was materially amended by the Data (Use and Access) Act 2025 from 5 February 2026.","appliesTo":"Controllers and processors established in the UK, and non-UK organisations offering goods/services to, or monitoring, individuals in the UK. No revenue or volume threshold.","penalties":"Up to GBP 17.5 million or 4% of total worldwide annual turnover, whichever is higher (lower tier GBP 8.7 million or 2%). Since 5 Feb 2026, PECR fines are aligned to the same UK GDPR levels.","enforcer":"Information Commissioner's Office (becoming the Information Commission on 30 Sept 2026)","sourceUrl":"https://www.legislation.gov.uk/ukpga/2018/12/contents","extraSources":["https://www.legislation.gov.uk/eur/2016/679/contents","https://ico.org.uk/"],"notes":"See uk-duaa for the full staged commencement of the 2025 amendments. UK adequacy decision from the EU was renewed in 2025 (not separately verified here).","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-24 02:56:54","deadlines":[{"id":153,"regulationId":"uk-gdpr","date":"2018-05-25","title":"Data Protection Act 2018 and GDPR apply","description":"DPA 2018 and EU GDPR began applying in the UK.","kind":"effective","sourceUrl":"https://www.legislation.gov.uk/ukpga/2018/12/contents","tentative":false,"review":"verified"},{"id":154,"regulationId":"uk-gdpr","date":"2021-01-01","title":"UK GDPR takes effect after Brexit transition","description":"Retained EU GDPR becomes the UK GDPR at the end of the Brexit implementation period.","kind":"effective","sourceUrl":"https://www.legislation.gov.uk/eur/2016/679/contents","tentative":false,"review":"verified"},{"id":155,"regulationId":"uk-gdpr","date":"2026-02-05","title":"DUAA amendments to UK GDPR commence","description":"Main Data (Use and Access) Act 2025 Part 5 amendments (recognised legitimate interests, ADM, DSAR, transfers, cookies, PECR fines) apply.","kind":"effective","sourceUrl":"https://www.legislation.gov.uk/uksi/2026/82/contents/made","tentative":false,"review":"verified"}]},{"id":"uk-osa","name":"Online Safety Act 2023","shortName":"UK Online Safety Act","jurisdiction":"uk","jurisdictionName":"United Kingdom","region":"uk-europe","topics":["online-safety","children"],"status":"in_force","citation":"2023 c. 50","enactedDate":"2023-10-26","effectiveDate":"2025-03-17","summary":"Imposes duties of care on user-to-user services and search engines to assess and mitigate illegal content risks and, where children can access the service, to protect children (including highly effective age assurance for pornography and other primary priority content). Categorised services face additional transparency, user empowerment and fraudulent advertising duties.","appliesTo":"User-to-user services, search services and pornography providers with links to the UK (significant number of UK users or UK target market), regardless of where based. Categorised (Category 1/2A/2B) services based on UK user numbers and functionality thresholds in secondary legislation. Fees payable by providers with qualifying worldwide revenue at or above the threshold set by regulations.","penalties":"Up to GBP 18 million or 10% of qualifying worldwide revenue, whichever is greater; business disruption measures and criminal liability for senior managers in some cases.","enforcer":"Ofcom","sourceUrl":"https://www.legislation.gov.uk/ukpga/2023/50/contents","extraSources":["https://www.ofcom.org.uk/online-safety/protecting-children/protection-of-children-duties-under-the-online-safety-act","https://www.ofcom.org.uk/online-safety/illegal-and-harmful-content/online-safety-fees-and-penalties","https://www.rpclegal.com/thinking/media/ofcom-publishes-register-of-categorised-services/"],"notes":"Ofcom published its register of categorised services on 10 July 2026 (per RPC and Bristows reporting; Ofcom page not fetched), with consultations on Category 1 duties open to 2 Oct 2026 and final codes expected by mid-2027. Fee notification close date (11 Apr 2026) taken from Ofcom-sourced reporting; Ofcom page returned 403 during verification.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-24 02:56:54","deadlines":[{"id":156,"regulationId":"uk-osa","date":"2023-10-26","title":"Royal Assent","description":"The Online Safety Act receives Royal Assent.","kind":"effective","sourceUrl":"https://www.legislation.gov.uk/ukpga/2023/50/contents","tentative":false,"review":"verified"},{"id":157,"regulationId":"uk-osa","date":"2025-03-17","title":"Illegal harms duties enforceable","description":"Illegal content safety duties apply; illegal content risk assessments had to be completed by 16 March 2025.","kind":"effective","sourceUrl":"https://www.ofcom.org.uk/online-safety/illegal-and-harmful-content","tentative":false,"review":"verified"},{"id":158,"regulationId":"uk-osa","date":"2025-04-16","title":"Children's access assessments due","description":"Services had to complete children's access assessments to determine whether children are likely to access them.","kind":"compliance","sourceUrl":"https://www.ofcom.org.uk/online-safety/protecting-children/protection-of-children-duties-under-the-online-safety-act","tentative":false,"review":"verified"},{"id":159,"regulationId":"uk-osa","date":"2025-07-25","title":"Protection of children duties apply","description":"Children's safety duties and Protection of Children Codes take effect, including highly effective age assurance; children's risk assessments due by 24 July 2025.","kind":"effective","sourceUrl":"https://www.ofcom.org.uk/online-safety/protecting-children/protection-of-children-duties-under-the-online-safety-act","tentative":false,"review":"verified"},{"id":160,"regulationId":"uk-osa","date":"2026-04-11","title":"Fee notification window closes (2026/27)","description":"Fee-liable providers must notify Ofcom before the notification window for the first charging year closes.","kind":"reporting","sourceUrl":"https://www.ofcom.org.uk/online-safety/illegal-and-harmful-content/online-safety-fees-and-penalties","tentative":false,"review":"verified"}]},{"id":"us-ut-aipa","name":"Utah Artificial Intelligence Policy Act (SB 149, 2024), as amended by SB 226 and SB 332 (2025)","shortName":"Utah AI Policy Act","jurisdiction":"us-ut","jurisdictionName":"Utah","region":"us-states","topics":["ai"],"status":"amended","citation":"Utah Code Title 13, Ch. 72 and Ch. 75; SB 149 (2024); SB 226 (2025); SB 332 (2025); Utah Code 63I-2-213","enactedDate":"2024-03-13","effectiveDate":"2024-05-01","summary":"Makes businesses liable under Utah consumer protection law for deceptive acts committed through generative AI. Businesses must disclose generative AI use when a consumer clearly and unequivocally asks, and must disclose it proactively in high-risk interactions and regulated-occupation services. The act created the Office of Artificial Intelligence Policy and a regulatory learning lab. In 2025, SB 226 narrowed the disclosure duties and added a safe harbor, and SB 332 moved the act's repeal date to July 1, 2027.","appliesTo":"Persons using generative AI to interact with consumers in connection with activities regulated by the Utah Division of Consumer Protection, and licensed regulated occupations. No size threshold.","penalties":"Division of Consumer Protection administrative fines up to $2,500 per violation; courts may impose fines up to $2,500 per violation, and violating an administrative or court order carries a civil penalty up to $5,000 per violation.","enforcer":"Utah Division of Consumer Protection; Utah Attorney General","sourceUrl":"https://le.utah.gov/~2025/bills/static/SB0332.html","extraSources":["https://le.utah.gov/~2025/bills/static/SB0226.html","https://le.utah.gov/~2024/bills/static/SB0149.html","https://le.utah.gov/Session/2025/bills/enrolled/SB0332.pdf","https://le.utah.gov/Session/2025/bills/enrolled/SB0226.pdf"],"notes":"SB 226 and SB 332 were verified from the enrolled bill text. The SB 149 signing date (March 13, 2024) was not re-verified. Whether the 2026 Utah session changed the July 1, 2027 repeal date was not verified because the search budget ran out. HB 452 (2025, mental health chatbots) is a related Utah law not covered here.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-24 02:56:54","deadlines":[{"id":305,"regulationId":"us-ut-aipa","date":"2024-05-01","title":"AI Policy Act effective","description":"Generative AI disclosure duties and the Office of AI Policy take effect.","kind":"effective","sourceUrl":"https://le.utah.gov/~2024/bills/static/SB0149.html","tentative":false,"review":"verified"},{"id":306,"regulationId":"us-ut-aipa","date":"2025-05-07","title":"SB 226 amendments effective","description":"Disclosure duties narrowed (on clear request or high-risk interactions), safe harbor added, provisions recodified in Title 13, Ch. 75.","kind":"effective","sourceUrl":"https://le.utah.gov/~2025/bills/static/SB0226.html","tentative":false,"review":"verified"},{"id":307,"regulationId":"us-ut-aipa","date":"2027-07-01","title":"Scheduled repeal of Title 13, Ch. 72","description":"SB 332 extends the AI Policy Act repeal date from May 1, 2025 to July 1, 2027.","kind":"sunset","sourceUrl":"https://le.utah.gov/~2025/bills/static/SB0332.html","tentative":false,"review":"verified"}]},{"id":"us-ut-ucpa","name":"Utah Consumer Privacy Act (SB 227, 2022)","shortName":"Utah UCPA","jurisdiction":"us-ut","jurisdictionName":"Utah","region":"us-states","topics":["privacy"],"status":"amended","citation":"Utah Code 13-61-101 et seq. (Laws 2022, ch. 462; amended 2025 ch. 468, 2026 ch. 193)","enactedDate":"2022-03-24","effectiveDate":"2023-12-31","summary":"Business-friendly comprehensive privacy law with access, deletion, portability and opt-out rights (targeted advertising, sale); sensitive data needs notice and a chance to opt out rather than opt-in consent, and data protection assessments are not required. A right to correct was added from July 1, 2026, and from Jan 1, 2027 the law covers motor vehicle manufacturers regardless of thresholds.","appliesTo":"Controllers or processors conducting business in Utah or targeting Utah residents with annual revenue of $25,000,000 or more that either control or process personal data of 100,000+ consumers in a calendar year, or derive over 50% of gross revenue from selling personal data and control or process data of 25,000+ consumers (13-61-102). From Jan 1, 2027, also any motor vehicle manufacturer whose vehicles are sold or leased in Utah and that collects personal data through a vehicle data collection system. Exempts government, tribes, higher education, nonprofits, HIPAA entities, GLBA, and others.","penalties":"AG may recover actual damages and up to $7,500 per violation not cured (13-61-402(3)(d)). Mandatory 30-day notice-and-cure period; it does not sunset. The Division of Consumer Protection takes complaints and refers cases to the AG. No private right of action.","enforcer":"Utah Attorney General (exclusive), on referral from the Utah Division of Consumer Protection","sourceUrl":"https://le.utah.gov/xcode/Title13/Chapter61/13-61.html","extraSources":["https://le.utah.gov/xcode/Title13/Chapter61/13-61-S102.html","https://le.utah.gov/xcode/Title13/Chapter61/13-61-S201.html","https://le.utah.gov/xcode/Title13/Chapter61/13-61-S402.html","https://www.gunster.com/newsroom/publications/2026-data-privacy-laws-state-changes-universal-opt-out-compliance"],"notes":"Amendments are identified by session-law chapter from the Utah Code version notes. The bill numbers behind 2025 ch. 468 and 2026 ch. 193 were not confirmed. Utah's separate 2025 social media data portability/interoperability law (Digital Choice Act) is reported to take effect July 2026 but sits outside the UCPA and is not included here. SB 227 signing date is March 24, 2022 per contemporaneous reporting.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-24 02:56:54","deadlines":[{"id":308,"regulationId":"us-ut-ucpa","date":"2023-12-31","title":"UCPA takes effect","description":"Utah Consumer Privacy Act obligations and consumer rights apply.","kind":"effective","sourceUrl":"https://le.utah.gov/xcode/Title13/Chapter61/13-61-S402.html","tentative":false,"review":"verified"},{"id":309,"regulationId":"us-ut-ucpa","date":"2026-07-01","title":"Right to correct takes effect","description":"Consumers may ask controllers to correct inaccurate personal data (13-61-201(4), as amended by Laws 2025, ch. 468).","kind":"effective","sourceUrl":"https://le.utah.gov/xcode/Title13/Chapter61/13-61-S201.html","tentative":false,"review":"verified"},{"id":310,"regulationId":"us-ut-ucpa","date":"2027-01-01","title":"UCPA extends to motor vehicle manufacturers","description":"Motor vehicle manufacturers whose vehicles are sold or leased in Utah and that collect personal data through vehicle data systems are covered regardless of the revenue and consumer thresholds (13-61-102, as amended by Laws 2026, ch. 193).","kind":"effective","sourceUrl":"https://le.utah.gov/xcode/Title13/Chapter61/13-61-S102.html","tentative":false,"review":"verified"}]},{"id":"us-vt-vdposa","name":"Vermont Data Privacy and Online Surveillance Act (S.71, Act 145 of 2026)","shortName":"Vermont VDPOSA","jurisdiction":"us-vt","jurisdictionName":"Vermont","region":"us-states","topics":["privacy","health","ai"],"status":"enacted","citation":"S.71, Act No. 145 (2026)","enactedDate":"2026-06-16","effectiveDate":"2028-01-01","summary":"New comprehensive privacy law with low applicability thresholds, broad consumer health data provisions that apply to all businesses, an expanded sensitive data definition, profiling and automated-decision transparency, and a disclosure requirement for using personal data to train AI models. Consumers get the usual access, correction, deletion, portability and opt-out rights.","appliesTo":"Persons conducting business in Vermont or targeting Vermont residents that in the preceding calendar year controlled or processed personal data of at least 35,000 consumers (excluding payment-only data), controlled or processed sensitive data of at least 3,000 consumers, or offered for sale personal data of at least 3,000 consumers. Consumer health data provisions apply regardless of thresholds.","penalties":"Violations are unfair and deceptive acts under the Vermont Consumer Protection Act (9 V.S.A. ch. 63): civil penalty up to $10,000 per unfair or deceptive act (9 V.S.A. 2458(b)(1)). Mandatory 60-day cure notice, where a cure is possible, from Jan 1, 2028 through June 30, 2029 (Act 145 sec. 3). No private right of action.","enforcer":"Vermont Attorney General (exclusive)","sourceUrl":"https://legislature.vermont.gov/bill/status/2026/S.71","extraSources":["https://legislature.vermont.gov/Documents/2026/Docs/ACTS/ACT145/ACT145%20As%20Enacted.pdf","https://legislature.vermont.gov/statutes/section/09/063/02458","https://www.mayerbrown.com/en/insights/publications/2026/06/vermont-enacts-comprehensive-consumer-privacy-law","https://www.hunton.com/privacy-and-cybersecurity-law-blog/vermont-becomes-23rd-state-with-comprehensive-consumer-privacy-law"],"notes":"The act has no penalty amount of its own; the $10,000 figure comes from the Vermont Consumer Protection Act's general civil penalty for unfair or deceptive acts. The AG must report annually by Dec 1 on notices of violation. Sources disagree on whether Vermont is the 23rd or 24th state with a comprehensive privacy law.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-24 02:56:54","deadlines":[{"id":315,"regulationId":"us-vt-vdposa","date":"2028-01-01","title":"Vermont Data Privacy and Online Surveillance Act takes effect","description":"All obligations under Act 145 apply (sec. 4).","kind":"effective","sourceUrl":"https://legislature.vermont.gov/Documents/2026/Docs/ACTS/ACT145/ACT145%20As%20Enacted.pdf","tentative":false,"review":"verified"},{"id":316,"regulationId":"us-vt-vdposa","date":"2029-06-30","title":"Mandatory 60-day cure period expires","description":"The AG's duty to issue a cure notice before enforcement ends June 30, 2029 (Act 145 sec. 3).","kind":"enforcement","sourceUrl":"https://legislature.vermont.gov/Documents/2026/Docs/ACTS/ACT145/ACT145%20As%20Enacted.pdf","tentative":false,"review":"verified"}]},{"id":"vn-ai-law","name":"Law on Artificial Intelligence (Law No. 134/2025/QH15)","shortName":"Vietnam AI Law","jurisdiction":"vn","jurisdictionName":"Vietnam","region":"apac","topics":["ai"],"status":"in_force","citation":"Law No. 134/2025/QH15","enactedDate":"2025-12-10","effectiveDate":"2026-03-01","summary":"Vietnam's first standalone AI law (35 articles). It classifies AI systems as high, medium or low risk based on their impact on life, health, rights and public order, requires human oversight, and requires disclosure when users interact with AI and labeling of AI-generated audio, image and video content. It applies to domestic and foreign actors in AI activities in Vietnam, with transition periods for existing systems.","appliesTo":"Vietnamese and foreign organizations and individuals researching, developing, providing, deploying or using AI systems in Vietnam.","penalties":"The law sets principles; administrative penalty amounts are left to implementing decrees (not verified).","enforcer":"Ministry of Science and Technology","sourceUrl":"https://beta-en.mic.gov.vn/first-ever-law-on-artificial-intelligence-approved-197251215231241888.htm","extraSources":["https://www.vilaf.com.vn/blog/vietnam-enacts-its-first-law-on-artificial-intelligence-key-regulatory-obligations-from-1-march-2026/","https://www.bakermckenzie.com/en/insight/publications/2026/02/vietnam-artificial-intelligence-law-foundation-and-outlook"],"notes":"Transition deadlines come from law-firm summaries (VILAF, Baker McKenzie), not the official text. The Law on Digital Technology Industry (No. 71/2025/QH15), which also contains AI provisions, was not verified here. The ministry page is the former MIC portal, now under the Ministry of Science and Technology.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-24 02:56:54","deadlines":[{"id":321,"regulationId":"vn-ai-law","date":"2026-03-01","title":"AI Law takes effect","description":"Risk classification, transparency and labeling obligations apply to new AI systems.","kind":"effective","sourceUrl":"https://beta-en.mic.gov.vn/first-ever-law-on-artificial-intelligence-approved-197251215231241888.htm","tentative":false,"review":"verified"},{"id":322,"regulationId":"vn-ai-law","date":"2027-03-01","title":"Transition ends for existing AI systems (general)","description":"Existing AI systems in most sectors must comply (12-month transition).","kind":"transition","sourceUrl":"https://www.vilaf.com.vn/blog/vietnam-enacts-its-first-law-on-artificial-intelligence-key-regulatory-obligations-from-1-march-2026/","tentative":false,"review":"verified"},{"id":323,"regulationId":"vn-ai-law","date":"2027-09-01","title":"Transition ends for existing AI systems in health, education and finance","description":"Existing AI systems in healthcare, education and finance must comply (18-month transition).","kind":"transition","sourceUrl":"https://www.vilaf.com.vn/blog/vietnam-enacts-its-first-law-on-artificial-intelligence-key-regulatory-obligations-from-1-march-2026/","tentative":false,"review":"verified"}]},{"id":"vn-pdpl","name":"Law on Personal Data Protection (Law No. 91/2025/QH15)","shortName":"Vietnam PDPL","jurisdiction":"vn","jurisdictionName":"Vietnam","region":"apac","topics":["privacy","data-residency","children","breach-notification"],"status":"in_force","citation":"Law No. 91/2025/QH15; implemented by Decree No. 356/2025/ND-CP","enactedDate":"2025-06-26","effectiveDate":"2026-01-01","summary":"Vietnam's first statute on personal data protection, replacing Decree 13/2023. It covers consent, data subject rights, processing and transfer impact assessments filed with the regulator, cross-border transfers, breach reporting, and bans on buying and selling personal data. Decree 356/2025 took effect alongside it and details DPIA/TIA and DPO requirements.","appliesTo":"Vietnamese and foreign agencies, organizations and individuals directly processing or involved in processing personal data of Vietnamese citizens and people in Vietnam. Household businesses and micro-enterprises are exempt from DPIA/TIA unless they provide data processing services, process sensitive data directly, or process data of large numbers of people. DPIA/TIA must be filed within 60 days of starting processing.","penalties":"Cross-border transfer violations: up to 5% of prior-year revenue. Illegal buying or selling of personal data: up to 10x the illegal proceeds (VND 3 billion cap if proceeds cannot be determined). Other violations: up to VND 3 billion for organizations. Criminal liability may apply. A separate penalty decree is still expected.","enforcer":"Ministry of Public Security (Department of Cybersecurity and High-Tech Crime Prevention, A05)","sourceUrl":"https://vanban.chinhphu.vn/?pageid=27160&docid=214590","extraSources":["https://datafiles.chinhphu.vn/cpp/files/vbpq/2025/7/91qh.signed.pdf","https://vanban.chinhphu.vn/?pageid=27160&docid=216387","https://english.luatvietnam.vn/legal-updates/the-latest-law-on-personal-data-protection-and-the-guiding-documents-892-106778-article.html","https://www.dfdl.com/insights/legal-and-tax-updates/vietnam-personal-data-protection-2026-what-foreign-organizations-need-to-know/","https://www.tilleke.com/insights/vietnams-new-personal-data-protection-law-a-closer-look/"],"notes":"source_url is the Government legal documents portal (vanban.chinhphu.vn) record for Law 91/2025/QH15: issued 26 Jun 2025 by the National Assembly (signed by Tran Thanh Man), effective 1 Jan 2026; the signed PDF is in extra_sources. The same portal lists Decree 356/2025/ND-CP as issued 31 Dec 2025, effective 1 Jan 2026. Reports of a 5-year exemption for small enterprises and startups from some duties were not verified. The implementing penalty decree was still pending as of the latest source.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-24 02:56:54","deadlines":[{"id":324,"regulationId":"vn-pdpl","date":"2026-01-01","title":"PDPL and Decree 356/2025 take effect","description":"Personal data protection obligations, DPIA/TIA filing and penalty framework apply; Decree 13/2023 replaced.","kind":"effective","sourceUrl":"https://vanban.chinhphu.vn/?pageid=27160&docid=214590","tentative":false,"review":"verified"}]},{"id":"us-va-vcdpa","name":"Virginia Consumer Data Protection Act (SB 1392 / HB 2307, 2021)","shortName":"Virginia VCDPA","jurisdiction":"us-va","jurisdictionName":"Virginia","region":"us-states","topics":["privacy","children","online-safety"],"status":"amended","citation":"Va. Code 59.1-575 to 59.1-585 (Acts 2021, Sp. Sess. I, ch. 35 and 36); amended 2025 (SB 854) and 2026 (SB 338)","enactedDate":"2021-03-02","effectiveDate":"2023-01-01","summary":"The second US comprehensive state privacy law: access, correction, deletion, portability and opt-out rights (targeted ads, sale, profiling), opt-in consent for sensitive data and data protection assessments. SB 854 (2025) added a 1-hour-per-day default social media limit for users under 16, effective Jan 1, 2026, but a federal court has preliminarily enjoined it. SB 338 (2026) bans selling precise geolocation data from July 1, 2026.","appliesTo":"Persons conducting business in Virginia or targeting Virginia residents that in a calendar year control or process personal data of at least 100,000 consumers, or control or process personal data of at least 25,000 consumers and derive over 50% of gross revenue from selling personal data (59.1-576). Exempts government, GLBA financial institutions, HIPAA entities, nonprofits, higher education.","penalties":"Civil penalties up to $7,500 per violation, plus injunction and AG expenses/fees (59.1-584). Mandatory 30-day notice-and-cure period; it does not sunset. No private right of action.","enforcer":"Virginia Attorney General (exclusive)","sourceUrl":"https://law.lis.virginia.gov/vacode/title59.1/chapter53/","extraSources":["https://law.lis.virginia.gov/vacode/title59.1/chapter53/section59.1-576/","https://law.lis.virginia.gov/vacode/title59.1/chapter53/section59.1-584/","https://netchoice.org/wp-content/uploads/2026/02/Virginia-PI-Opinion_Granted.pdf","https://www.hunton.com/privacy-and-cybersecurity-law-blog/virginia-bans-sale-of-geolocation-data","https://www.hunton.com/privacy-and-cybersecurity-law-blog/virginia-appeals-preliminary-injunction-barring-enforcement-of-age-based-restrictions-on-social-media-use"],"notes":"SB 338 signed by Gov. Spanberger on April 13, 2026 (per Hunton, Proskauer and Consumer Reports; the LIS bill page renders via JavaScript and could not be read). SB 854's Feb 27, 2026 injunction comes from the court opinion hosted by NetChoice; Virginia's appeal to the Fourth Circuit was pending as of the latest sources found. Treat the SB 854 obligations as unenforceable while the injunction stands.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-24 02:56:54","deadlines":[{"id":311,"regulationId":"us-va-vcdpa","date":"2023-01-01","title":"VCDPA takes effect","description":"VCDPA obligations and consumer rights apply.","kind":"effective","sourceUrl":"https://law.lis.virginia.gov/vacode/title59.1/chapter53/","tentative":false,"review":"verified"},{"id":312,"regulationId":"us-va-vcdpa","date":"2026-01-01","title":"Under-16 social media time limit (SB 854) takes effect","description":"Social media platforms must use commercially reasonable age determination and cap users under 16 at 1 hour/day unless a parent consents. A preliminary injunction issued Feb 27, 2026 bars enforcement.","kind":"effective","sourceUrl":"https://netchoice.org/wp-content/uploads/2026/02/Virginia-PI-Opinion_Granted.pdf","tentative":false,"review":"verified"},{"id":313,"regulationId":"us-va-vcdpa","date":"2026-02-27","title":"SB 854 preliminarily enjoined (NetChoice v. Jones)","description":"E.D. Va. preliminarily enjoined enforcement of the SB 854 social media time-limit provisions on First Amendment grounds; Virginia has appealed.","kind":"enforcement","sourceUrl":"https://netchoice.org/wp-content/uploads/2026/02/Virginia-PI-Opinion_Granted.pdf","tentative":false,"review":"verified"},{"id":314,"regulationId":"us-va-vcdpa","date":"2026-07-01","title":"Ban on selling precise geolocation data (SB 338)","description":"Controllers may not sell consumers' precise geolocation data (1,750-ft radius), replacing the prior consent-based treatment.","kind":"effective","sourceUrl":"https://lis.virginia.gov/bill-details/20261/SB338","tentative":false,"review":"verified"}]},{"id":"us-wa-mhmda","name":"Washington My Health My Data Act (HB 1155, Laws of 2023, ch. 191; RCW 19.373)","shortName":"Washington My Health My Data Act","jurisdiction":"us-wa","jurisdictionName":"Washington","region":"us-states","topics":["health","privacy"],"status":"in_force","citation":"RCW 19.373; Laws of 2023, ch. 191 (HB 1155)","enactedDate":"2023-04-27","effectiveDate":"2024-03-31","summary":"Regulated entities must publish a consumer health data privacy policy linked from their homepage and get opt-in consent to collect or share consumer health data. Selling it requires a signed authorization. Consumers get rights to access, delete and withdraw consent. Geofencing within 2,000 feet of health care facilities is banned. 'Consumer health data' is defined broadly and includes inferences from non-health data.","appliesTo":"Any legal entity that conducts business in Washington or targets Washington consumers and determines the purpose and means of processing consumer health data, with no revenue threshold. Small businesses (health data of fewer than 100,000 consumers a year, or under 50% of revenue from health data and fewer than 25,000 consumers) got a later compliance date.","penalties":"A violation is a per se violation of the Washington Consumer Protection Act: AG civil penalties up to $7,500 per violation (RCW 19.86.140). Private right of action for actual damages, with possible treble damages and attorney fees.","enforcer":"Washington Attorney General; private right of action","sourceUrl":"https://www.atg.wa.gov/protecting-washingtonians-personal-health-data-and-privacy","extraSources":["https://app.leg.wa.gov/billsummary?BillNumber=1155&Year=2023","https://app.leg.wa.gov/rcw/default.aspx?cite=19.373.010","https://app.leg.wa.gov/rcw/default.aspx?cite=19.86.140"],"notes":"The treble-damages cap for private actions (RCW 19.86.090) was not re-verified for this record.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-24 02:56:54","deadlines":[{"id":317,"regulationId":"us-wa-mhmda","date":"2023-04-27","title":"HB 1155 signed","description":"Governor signs My Health My Data Act.","kind":"transition","sourceUrl":"https://app.leg.wa.gov/billsummary?BillNumber=1155&Year=2023","tentative":false,"review":"verified"},{"id":318,"regulationId":"us-wa-mhmda","date":"2023-07-23","title":"Geofencing ban (Section 10) effective","description":"Ban on geofencing around health care facilities applies to all persons.","kind":"effective","sourceUrl":"https://www.atg.wa.gov/protecting-washingtonians-personal-health-data-and-privacy","tentative":false,"review":"verified"},{"id":319,"regulationId":"us-wa-mhmda","date":"2024-03-31","title":"Regulated entities must comply","description":"Sections 4-9 (privacy policy, consent, consumer rights, sale authorization) apply to regulated entities.","kind":"compliance","sourceUrl":"https://www.atg.wa.gov/protecting-washingtonians-personal-health-data-and-privacy","tentative":false,"review":"verified"},{"id":320,"regulationId":"us-wa-mhmda","date":"2024-06-30","title":"Small businesses must comply","description":"Sections 4-9 apply to small businesses.","kind":"compliance","sourceUrl":"https://www.atg.wa.gov/protecting-washingtonians-personal-health-data-and-privacy","tentative":false,"review":"verified"}]},{"id":"eu-eidas2","name":"Regulation (EU) 2024/1183 amending Regulation (EU) No 910/2014 as regards establishing the European Digital Identity Framework (eIDAS 2)","shortName":"eIDAS 2 / EU Digital Identity Wallet","jurisdiction":"eu","jurisdictionName":"European Union","region":"eu","topics":["privacy","data-access","biometrics"],"status":"enacted","citation":"OJ L, 2024/1183, 30.4.2024","enactedDate":"2024-04-11","effectiveDate":"2024-05-20","summary":"Requires every Member State to offer at least one European Digital Identity Wallet so people can identify themselves and share verified attributes with selective disclosure. It adds new qualified trust services such as electronic attestations of attributes and electronic ledgers. Private relying parties that must use strong authentication, and very large online platforms, have to accept the wallet when the user asks.","appliesTo":"Member States (wallet issuance); qualified and non-qualified trust service providers; relying parties relying on wallets, incl. private relying parties legally or contractually required to use strong user authentication (transport, energy, banking, financial services, health, telecoms and similar) and VLOPs under the DSA.","penalties":"Trust service providers: maximum of at least EUR 5M, or for legal persons EUR 5M or 1% of worldwide annual turnover, whichever is higher (Art 16 as amended). Other penalties set by Member States.","enforcer":"National supervisory bodies for trust services and wallets; European Commission","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2024/1183/oj","extraSources":["https://eur-lex.europa.eu/eli/reg_impl/2024/2977/oj"],"notes":"The 2026-12-24 and 2027-12-24 dates are computed as 24 and 36 months after the 24 Dec 2024 entry into force of the Art 5a(23)/5c(6) implementing acts (20th day after 4 Dec 2024 publication). The Commission often says 'by end of 2026' for wallets. Further implementing acts adopted in 2025 may affect specific features.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-24 02:56:54","deadlines":[{"id":85,"regulationId":"eu-eidas2","date":"2024-05-20","title":"eIDAS 2 enters into force","description":"Regulation (EU) 2024/1183 entered into force on the twentieth day after publication on 30 Apr 2024 (Art 2).","kind":"effective","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2024/1183/oj","tentative":false,"review":"verified"},{"id":86,"regulationId":"eu-eidas2","date":"2024-12-24","title":"First wallet implementing acts enter into force","description":"Commission Implementing Regulations (EU) 2024/2977, 2024/2979, 2024/2980, 2024/2981 and 2024/2982 (adopted 28 Nov 2024, published 4 Dec 2024) enter into force. This starts the wallet deadline clocks in Arts 5a and 5f.","kind":"effective","sourceUrl":"https://eur-lex.europa.eu/eli/reg_impl/2024/2977/oj","tentative":false,"review":"verified"},{"id":87,"regulationId":"eu-eidas2","date":"2026-05-21","title":"Legacy qualified trust service providers conformity report","description":"QTSPs qualified before 20 May 2024 had to submit a conformity assessment report proving compliance with Art 24(1), (1a) and (1b) by 21 May 2026.","kind":"compliance","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2024/1183/oj","tentative":false,"review":"verified"},{"id":88,"regulationId":"eu-eidas2","date":"2026-12-24","title":"Member States must provide EU Digital Identity Wallets","description":"Each Member State must provide at least one wallet within 24 months of the entry into force of the implementing acts under Arts 5a(23) and 5c(6) (Art 5a(1)).","kind":"compliance","sourceUrl":"https://eur-lex.europa.eu/eli/reg_impl/2024/2977/oj","tentative":false,"review":"verified"},{"id":89,"regulationId":"eu-eidas2","date":"2027-12-24","title":"Private relying parties must accept wallets","description":"Private relying parties required by law or contract to use strong user authentication must accept wallets on user request within 36 months of the implementing acts' entry into force (Art 5f(2)).","kind":"compliance","sourceUrl":"https://eur-lex.europa.eu/eli/reg_impl/2024/2977/oj","tentative":false,"review":"verified"}]},{"id":"eu-eprivacy","name":"Directive 2002/58/EC concerning the processing of personal data and the protection of privacy in the electronic communications sector (ePrivacy Directive), as amended by Directive 2009/136/EC","shortName":"ePrivacy Directive (cookie law)","jurisdiction":"eu","jurisdictionName":"European Union","region":"eu","topics":["privacy","breach-notification"],"status":"amended","citation":"OJ L 201, 31.7.2002, p. 37","enactedDate":"2002-07-12","effectiveDate":"2002-07-31","summary":"Requires prior consent to store or access information on a user's device (cookies, SDKs, fingerprinting), except where strictly necessary. Also covers confidentiality of communications, traffic and location data, and unsolicited direct marketing (opt-in for email/SMS to individuals). Telecom providers must notify personal data breaches. Enforced through national laws.","appliesTo":"Any entity storing or accessing information on users' terminal equipment in the EU (websites, apps, ad tech), senders of electronic direct marketing, and providers of publicly available electronic communications services.","penalties":"Set by national transposing laws; many Member States let DPAs apply GDPR-level fines. Amounts vary by country.","enforcer":"National data protection authorities and/or telecom regulators, depending on the Member State","sourceUrl":"https://eur-lex.europa.eu/eli/dir/2002/58/oj","extraSources":["https://eur-lex.europa.eu/eli/dir/2009/136/oj","https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:52025PC0837","https://www.europarl.europa.eu/legislative-train/theme-a-new-plan-for-europe-s-sustainable-prosperity-and-competitiveness/file-digital-package"],"notes":"The proposed ePrivacy Regulation (2017) was withdrawn by the Commission in 2025. The Digital Omnibus proposal COM(2025) 837 would move consent rules for personal data on terminal equipment into the GDPR (new Art 88a/88b, incl. browser-level preference signals). As of the 1 Aug 2026 Legislative Train update it is still under negotiation, and Council drafts reportedly drop some of the cookie provisions. Status 'amended' reflects the pending amendment.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-24 02:56:54","deadlines":[{"id":90,"regulationId":"eu-eprivacy","date":"2002-07-31","title":"ePrivacy Directive enters into force","description":"Entered into force on the day of publication in the OJ (Art 20).","kind":"effective","sourceUrl":"https://eur-lex.europa.eu/eli/dir/2002/58/oj","tentative":false,"review":"verified"},{"id":91,"regulationId":"eu-eprivacy","date":"2003-10-31","title":"Original transposition deadline","description":"Member States had to bring national laws into force before 31 Oct 2003 (Art 17).","kind":"transition","sourceUrl":"https://eur-lex.europa.eu/eli/dir/2002/58/oj","tentative":false,"review":"verified"},{"id":92,"regulationId":"eu-eprivacy","date":"2011-05-25","title":"Cookie consent amendment transposition deadline","description":"Directive 2009/136/EC, which changed Art 5(3) to require consent for cookies, had to be transposed by 25 May 2011.","kind":"transition","sourceUrl":"https://eur-lex.europa.eu/eli/dir/2009/136/oj","tentative":false,"review":"verified"}]},{"id":"eu-eu-kids-act","name":"EU KIDS Act","shortName":"eu-kids-act","jurisdiction":"eu","jurisdictionName":"European Union","region":"eu","topics":["children","online-safety","privacy"],"status":"proposed","citation":"","enactedDate":"","effectiveDate":"","summary":"A legislative initiative designed to restrict social media platforms' access to children within the European Union.","appliesTo":"","penalties":"","enforcer":"","sourceUrl":"https://digital-strategy.ec.europa.eu/en/news/eu-kids-act-restrict-social-media-platforms-access-children-eu","extraSources":[],"notes":"Found by the nightly agent. Not yet reviewed.","lastVerified":"2026-09-24","origin":"agent","review":"unverified","updatedAt":"2026-09-24 08:48:01","deadlines":[]}],"generatedAt":"2026-09-24T11:16:13.931Z","freshness":{"lastOk":"2026-09-24T08:48:01Z","lastAttempt":"2026-09-24T08:48:08Z","lastState":"skipped","lastNote":"run budget of 3 model calls used","verified":"2026-09-24"}}