BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//fru.dev//Rulebook//EN
CALSCALE:GREGORIAN
METHOD:PUBLISH
X-WR-CALNAME:Regulation deadlines (Rulebook)
X-WR-CALDESC:Compliance deadlines tracked at rulebook.fru.dev
REFRESH-INTERVAL;VALUE=DURATION:P1D
X-PUBLISHED-TTL:P1D
BEGIN:VEVENT
UID:deadline-203@regulations.fru.dev
DTSTAMP:20260924T094351Z
DTSTART;VALUE=DATE:20260630
DTEND;VALUE=DATE:20260701
SUMMARY:Colorado AI Act: Delayed effective date (superseded)
DESCRIPTION:SB 25B-004 date\; superseded by SB 26-189 before it arrived\, s
 o no obligations applied.\n\nColorado SB 24-205 (Consumer Protections for 
 Artificial Intelligence)\, as delayed by SB 25B-004 and repealed and reena
 cted by SB 26-189 (Automated Decision-Making Technology) (Colorado)\n\nSou
 rce: https://leg.colorado.gov/bills/sb25b-004\n\nhttps://rulebook.fru.dev/
 regulations/us-co-ai-act
URL:https://rulebook.fru.dev/regulations/us-co-ai-act
CATEGORIES:Colorado,ai,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-267@regulations.fru.dev
DTSTAMP:20260924T094351Z
DTSTART;VALUE=DATE:20260630
DTEND;VALUE=DATE:20260701
SUMMARY:New Jersey NJDPA: A5328 sensitive data sale ban takes effect
DESCRIPTION:A5328\, signed June 30\, 2026\, prohibits selling sensitive per
 sonal data\; the ban took effect on signing.\n\nNew Jersey Data Privacy Ac
 t (P.L.2023\, c.266\; S332) (New Jersey)\n\nSource: https://www.njleg.stat
 e.nj.us/bill-search/2026/A5328\n\nhttps://rulebook.fru.dev/regulations/us-
 nj-njdpa
URL:https://rulebook.fru.dev/regulations/us-nj-njdpa
CATEGORIES:New Jersey,privacy,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-218@regulations.fru.dev
DTSTAMP:20260924T094351Z
DTSTART;VALUE=DATE:20260701
DTEND;VALUE=DATE:20260702
SUMMARY:Connecticut Data Privacy Act (CTDPA): PA 25-113 (SB 1295) amendment
 s take effect
DESCRIPTION:Thresholds drop to 35\,000 consumers or any sensitive-data proc
 essing or data sale\; expanded sensitive data\, minors' protections\, and 
 LLM-training disclosure in privacy notices.\n\nConnecticut Data Privacy Ac
 t (Public Act 22-15)\, Conn. Gen. Stat. 42-515 et seq.\, as amended by Pub
 lic Act 25-113 (SB 1295) and Public Act 26-64 (SB 4) (Connecticut)\n\nSour
 ce: https://www.cga.ct.gov/2025/ACT/PA/PDF/2025PA-00113-R00SB-01295-PA.PDF
 \n\nhttps://rulebook.fru.dev/regulations/us-ct-ctdpa
URL:https://rulebook.fru.dev/regulations/us-ct-ctdpa
CATEGORIES:Connecticut,privacy,children,ai,health
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-268@regulations.fru.dev
DTSTAMP:20260924T094351Z
DTSTART;VALUE=DATE:20260701
DTEND;VALUE=DATE:20260702
SUMMARY:New Jersey NJDPA: Mandatory 30-day cure period expires
DESCRIPTION:The Division's duty to issue a cure notice before enforcement e
 nds on the first day of the 18th month after the effective date (N.J.S.A. 
 56:8-166.17(b)).\n\nNew Jersey Data Privacy Act (P.L.2023\, c.266\; S332) 
 (New Jersey)\n\nSource: https://pub.njleg.state.nj.us/Bills/2022/PL23/266_
 .PDF\n\nhttps://rulebook.fru.dev/regulations/us-nj-njdpa
URL:https://rulebook.fru.dev/regulations/us-nj-njdpa
CATEGORIES:New Jersey,privacy,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-309@regulations.fru.dev
DTSTAMP:20260924T094351Z
DTSTART;VALUE=DATE:20260701
DTEND;VALUE=DATE:20260702
SUMMARY:Utah UCPA: Right to correct takes effect
DESCRIPTION:Consumers may ask controllers to correct inaccurate personal da
 ta (13-61-201(4)\, as amended by Laws 2025\, ch. 468).\n\nUtah Consumer Pr
 ivacy Act (SB 227\, 2022) (Utah)\n\nSource: https://le.utah.gov/xcode/Titl
 e13/Chapter61/13-61-S201.html\n\nhttps://rulebook.fru.dev/regulations/us-u
 t-ucpa
URL:https://rulebook.fru.dev/regulations/us-ut-ucpa
CATEGORIES:Utah,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-314@regulations.fru.dev
DTSTAMP:20260924T094351Z
DTSTART;VALUE=DATE:20260701
DTEND;VALUE=DATE:20260702
SUMMARY:Virginia VCDPA: Ban on selling precise geolocation data (SB 338)
DESCRIPTION:Controllers may not sell consumers' precise geolocation data (1
 \,750-ft radius)\, replacing the prior consent-based treatment.\n\nVirgini
 a Consumer Data Protection Act (SB 1392 / HB 2307\, 2021) (Virginia)\n\nSo
 urce: https://lis.virginia.gov/bill-details/20261/SB338\n\nhttps://ruleboo
 k.fru.dev/regulations/us-va-vcdpa
URL:https://rulebook.fru.dev/regulations/us-va-vcdpa
CATEGORIES:Virginia,privacy,children,online-safety
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-122@regulations.fru.dev
DTSTAMP:20260924T094351Z
DTSTART;VALUE=DATE:20260717
DTEND;VALUE=DATE:20260718
SUMMARY:Japan APPI: 2026 APPI amendment act promulgated
DESCRIPTION:Amendment enacted by the Diet on 10 July 2026 and promulgated\;
  main provisions take effect by cabinet order within two years of promulga
 tion.\n\nAct on the Protection of Personal Information (Act No. 57 of 2003
 )\, as amended including the 2026 amendment act (Japan)\n\nSource: https:/
 /www.ppc.go.jp/files/pdf/260731_shiryou-1.pdf\n\nhttps://rulebook.fru.dev/
 regulations/jp-appi
URL:https://rulebook.fru.dev/regulations/jp-appi
CATEGORIES:Japan,privacy,children,biometrics,breach-notification,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-40@regulations.fru.dev
DTSTAMP:20260924T094351Z
DTSTART;VALUE=DATE:20260727
DTEND;VALUE=DATE:20260728
SUMMARY:EU AI Act: Digital Omnibus on AI enters into force
DESCRIPTION:Regulation (EU) 2026/1744 (adopted 8 July 2026\, OJ 24 July 202
 6) enters into force on the third day after publication. Amended Articles 
 102 to 110 apply from this date (new Art 113(d)).\n\nRegulation (EU) 2024/
 1689 laying down harmonised rules on artificial intelligence (Artificial I
 ntelligence Act)\, as amended by Regulation (EU) 2026/1744 (Digital Omnibu
 s on AI) (European Union)\n\nSource: https://eur-lex.europa.eu/eli/reg/202
 6/1744/oj\n\nhttps://rulebook.fru.dev/regulations/eu-ai-act
URL:https://rulebook.fru.dev/regulations/eu-ai-act
CATEGORIES:European Union,ai,biometrics,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-178@regulations.fru.dev
DTSTAMP:20260924T094351Z
DTSTART;VALUE=DATE:20260801
DTEND;VALUE=DATE:20260802
SUMMARY:California Delete Act / DROP: Data brokers must begin processing DR
 OP deletion requests
DESCRIPTION:Brokers must access DROP at least every 45 days\, process verif
 ied deletion requests within 45 days\, and treat unverified requests as op
 t-outs of sale/sharing.\n\nCalifornia Delete Act (SB 362\, 2023)\, Cal. Ci
 v. Code 1798.99.80 et seq.\, and DROP regulations (California)\n\nSource: 
 https://www.cppa.ca.gov/data_brokers/\n\nhttps://rulebook.fru.dev/regulati
 ons/us-ca-delete-act
URL:https://rulebook.fru.dev/regulations/us-ca-delete-act
CATEGORIES:California,privacy,data-access
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-219@regulations.fru.dev
DTSTAMP:20260924T094351Z
DTSTART;VALUE=DATE:20260801
DTEND;VALUE=DATE:20260802
SUMMARY:Connecticut Data Privacy Act (CTDPA): Profiling impact assessments 
 apply
DESCRIPTION:Impact assessment requirements apply to profiling activities cr
 eated or generated on or after Aug 1\, 2026 (Conn. Gen. Stat. 42-522 as am
 ended).\n\nConnecticut Data Privacy Act (Public Act 22-15)\, Conn. Gen. St
 at. 42-515 et seq.\, as amended by Public Act 25-113 (SB 1295) and Public 
 Act 26-64 (SB 4) (Connecticut)\n\nSource: https://www.cga.ct.gov/2025/ACT/
 PA/PDF/2025PA-00113-R00SB-01295-PA.PDF\n\nhttps://rulebook.fru.dev/regulat
 ions/us-ct-ctdpa
URL:https://rulebook.fru.dev/regulations/us-ct-ctdpa
CATEGORIES:Connecticut,privacy,children,ai,health
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-190@regulations.fru.dev
DTSTAMP:20260924T094351Z
DTSTART;VALUE=DATE:20260802
DTEND;VALUE=DATE:20260803
SUMMARY:California AI Transparency Act (SB 942): Covered provider duties ap
 ply
DESCRIPTION:Detection tool\, manifest and latent disclosures\, and license-
 revocation duties become operative.\n\nCalifornia AI Transparency Act (SB 
 942\, Stats. 2024\, ch. 291)\, as amended by AB 853 (Stats. 2025\, ch. 674
 ) (California)\n\nSource: https://leginfo.legislature.ca.gov/faces/billNav
 Client.xhtml?bill_id=202520260AB853\n\nhttps://rulebook.fru.dev/regulation
 s/us-ca-sb942
URL:https://rulebook.fru.dev/regulations/us-ca-sb942
CATEGORIES:California,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-41@regulations.fru.dev
DTSTAMP:20260924T094351Z
DTSTART;VALUE=DATE:20260802
DTEND;VALUE=DATE:20260803
SUMMARY:EU AI Act: General application: transparency obligations\, GPAI fin
 es\, most other rules
DESCRIPTION:The AI Act's general date of application. Article 50 transparen
 cy obligations (chatbot disclosure\, deepfake labelling\, machine-readable
  marking of synthetic content) and Commission fines on GPAI providers (Art
  101) apply. Not deferred by the Omnibus.\n\nRegulation (EU) 2024/1689 lay
 ing down harmonised rules on artificial intelligence (Artificial Intellige
 nce Act)\, as amended by Regulation (EU) 2026/1744 (Digital Omnibus on AI)
  (European Union)\n\nSource: https://eur-lex.europa.eu/eli/reg/2024/1689/o
 j\n\nhttps://rulebook.fru.dev/regulations/eu-ai-act
URL:https://rulebook.fru.dev/regulations/eu-ai-act
CATEGORIES:European Union,ai,biometrics,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-79@regulations.fru.dev
DTSTAMP:20260924T094351Z
DTSTART;VALUE=DATE:20260831
DTEND;VALUE=DATE:20260901
SUMMARY:Digital Services Act: ChatGPT designated as VLOSE\; Reddit and Robl
 ox as VLOPs
DESCRIPTION:Commission designated ChatGPT as a very large online search eng
 ine and Reddit and Roblox as very large online platforms. They have four m
 onths (by January 2027) to meet VLOP/VLOSE obligations.\n\nRegulation (EU)
  2022/2065 on a Single Market for Digital Services (Digital Services Act) 
 (European Union)\n\nSource: https://digital-strategy.ec.europa.eu/en/news/
 commission-designates-chatgpt-reddit-roblox-under-digital-services-act\n\n
 https://rulebook.fru.dev/regulations/eu-dsa
URL:https://rulebook.fru.dev/regulations/eu-dsa
CATEGORIES:European Union,online-safety,children,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-50@regulations.fru.dev
DTSTAMP:20260924T094351Z
DTSTART;VALUE=DATE:20260911
DTEND;VALUE=DATE:20260912
SUMMARY:Cyber Resilience Act: Vulnerability and incident reporting obligati
 ons apply
DESCRIPTION:Art 14: manufacturers must report actively exploited vulnerabil
 ities and severe incidents (24-hour early warning\, 72-hour notification) 
 via the single reporting platform. Also covers products placed on the mark
 et before 11 Dec 2027 (Art 69(3)).\n\nRegulation (EU) 2024/2847 on horizon
 tal cybersecurity requirements for products with digital elements (Cyber R
 esilience Act) (European Union)\n\nSource: https://eur-lex.europa.eu/eli/r
 eg/2024/2847/oj\n\nhttps://rulebook.fru.dev/regulations/eu-cra
URL:https://rulebook.fru.dev/regulations/eu-cra
CATEGORIES:European Union,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-126@regulations.fru.dev
DTSTAMP:20260924T094351Z
DTSTART;VALUE=DATE:20260911
DTEND;VALUE=DATE:20260912
SUMMARY:South Korea PIPA: 2026 PIPA amendments take effect
DESCRIPTION:10%-of-revenue fines\, CEO accountability\, and notice duties f
 or possible breaches apply.\n\nPersonal Information Protection Act (as ame
 nded by Act No. 21445\, 2026) (South Korea)\n\nSource: https://www.law.go.
 kr/법령/개인정보보호법\n\nhttps://rulebook.fru.dev/regulations/kr
 -pipa
URL:https://rulebook.fru.dev/regulations/kr-pipa
CATEGORIES:South Korea,privacy,breach-notification,biometrics,data-residenc
 y
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-59@regulations.fru.dev
DTSTAMP:20260924T094351Z
DTSTART;VALUE=DATE:20260912
DTEND;VALUE=DATE:20260913
SUMMARY:EU Data Act: Access-by-design for new connected products
DESCRIPTION:Art 3(1) design obligation (product data and related service da
 ta accessible to the user by default) applies to connected products and re
 lated services placed on the market after 12 Sep 2026.\n\nRegulation (EU) 
 2023/2854 on harmonised rules on fair access to and use of data (Data Act)
  (European Union)\n\nSource: https://eur-lex.europa.eu/eli/reg/2023/2854/o
 j\n\nhttps://rulebook.fru.dev/regulations/eu-data-act
URL:https://rulebook.fru.dev/regulations/eu-data-act
CATEGORIES:European Union,data-access,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-152@regulations.fru.dev
DTSTAMP:20260924T094351Z
DTSTART;VALUE=DATE:20260930
DTEND;VALUE=DATE:20261001
SUMMARY:Data (Use and Access) Act: ICO abolished\; Information Commission t
 akes over
DESCRIPTION:Sections 118-119 commence: office of Information Commissioner a
 bolished and functions transferred to the Information Commission (Commence
 ment No. 9 Regulations 2026).\n\nData (Use and Access) Act 2025 (United Ki
 ngdom)\n\nSource: https://www.legislation.gov.uk/uksi/2026/1015/regulation
 /2/made\n\nhttps://rulebook.fru.dev/regulations/uk-duaa
URL:https://rulebook.fru.dev/regulations/uk-duaa
CATEGORIES:United Kingdom,privacy,data-access,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-220@regulations.fru.dev
DTSTAMP:20260924T094351Z
DTSTART;VALUE=DATE:20261001
DTEND;VALUE=DATE:20261002
SUMMARY:Connecticut Data Privacy Act (CTDPA): PA 26-64 (SB 4) amendments ta
 ke effect
DESCRIPTION:Prohibits controllers and third parties from selling precise ge
 olocation data and enacts data broker and other consumer protection provis
 ions.\n\nConnecticut Data Privacy Act (Public Act 22-15)\, Conn. Gen. Stat
 . 42-515 et seq.\, as amended by Public Act 25-113 (SB 1295) and Public Ac
 t 26-64 (SB 4) (Connecticut)\n\nSource: https://www.cga.ct.gov/2026/ACT/PA
 /PDF/2026PA-00064-R00SB-00004-PA.PDF\n\nhttps://rulebook.fru.dev/regulatio
 ns/us-ct-ctdpa
URL:https://rulebook.fru.dev/regulations/us-ct-ctdpa
CATEGORIES:Connecticut,privacy,children,ai,health
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-147@regulations.fru.dev
DTSTAMP:20260924T094351Z
DTSTART;VALUE=DATE:20261026
DTEND;VALUE=DATE:20261027
SUMMARY:UK Cyber Security and Resilience Bill: Lords report stage scheduled
DESCRIPTION:House of Lords report stage scheduled (committee stage sat 1\, 
 3 and 7 Sept 2026).\n\nTentative: depends on a proposal not yet adopted.\n
 \nCyber Security and Resilience (Network and Information Systems) Bill (Un
 ited Kingdom)\n\nSource: https://bills.parliament.uk/bills/4035\n\nhttps:/
 /rulebook.fru.dev/regulations/uk-csr-bill
URL:https://rulebook.fru.dev/regulations/uk-csr-bill
CATEGORIES:United Kingdom,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-196@regulations.fru.dev
DTSTAMP:20260924T094351Z
DTSTART;VALUE=DATE:20261110
DTEND;VALUE=DATE:20261111
SUMMARY:CMMC 2.0: Phase 2: Level 2 C3PAO certification
DESCRIPTION:Phase 2 begins one calendar year after Phase 1\; applicable sol
 icitations require CMMC Level 2 third-party (C3PAO) certification (32 CFR 
 170.3(e)(2)).\n\nCybersecurity Maturity Model Certification (CMMC) Program
  (32 CFR Part 170) and DFARS acquisition rule (48 CFR Parts 204\, 212\, 21
 7\, 252) (United States (Federal))\n\nSource: https://www.federalregister.
 gov/documents/2024/10/15/2024-22905/cybersecurity-maturity-model-certifica
 tion-cmmc-program\n\nhttps://rulebook.fru.dev/regulations/us-cmmc
URL:https://rulebook.fru.dev/regulations/us-cmmc
CATEGORIES:United States (Federal),cybersecurity
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-117@regulations.fru.dev
DTSTAMP:20260924T094351Z
DTSTART;VALUE=DATE:20261113
DTEND;VALUE=DATE:20261114
SUMMARY:India DPDP Act: Consent Manager registration rule in force (12 mont
 hs)
DESCRIPTION:Rule 4 (registration and obligations of Consent Managers) comes
  into force one year after publication.\n\nDigital Personal Data Protectio
 n Act\, 2023 and Digital Personal Data Protection Rules\, 2025 (India)\n\n
 Source: https://egazette.gov.in/WriteReadData/2025/267650.pdf\n\nhttps://r
 ulebook.fru.dev/regulations/in-dpdp
URL:https://rulebook.fru.dev/regulations/in-dpdp
CATEGORIES:India,privacy,children,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-27@regulations.fru.dev
DTSTAMP:20260924T094351Z
DTSTART;VALUE=DATE:20261201
DTEND;VALUE=DATE:20261202
SUMMARY:Chile Personal Data Protection Law (Ley 21.719): Law in force
DESCRIPTION:Main obligations apply and the Personal Data Protection Agency 
 begins supervision.\n\nLey Nº 21.719 que regula la protección y el trata
 miento de los datos personales y crea la Agencia de Protección de Datos P
 ersonales (Chile)\n\nSource: https://www.bcn.cl/leychile/navegar?idNorma=1
 209272\n\nhttps://rulebook.fru.dev/regulations/cl-pdpl
URL:https://rulebook.fru.dev/regulations/cl-pdpl
CATEGORIES:Chile,privacy,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-42@regulations.fru.dev
DTSTAMP:20260924T094351Z
DTSTART;VALUE=DATE:20261202
DTEND;VALUE=DATE:20261203
SUMMARY:EU AI Act: New bans on sexual deepfakes and CSAM generation\; Art 5
 0(2) grace period ends
DESCRIPTION:New Art 5(1)(ba)/(bb) prohibitions on AI systems that generate 
 non-consensual intimate imagery of identifiable persons or child sexual ab
 use material apply. Generative AI systems placed on the market before 2 Au
 g 2026 must comply with the Art 50(2) marking duty by this date (new Art 1
 11(4)).\n\nRegulation (EU) 2024/1689 laying down harmonised rules on artif
 icial intelligence (Artificial Intelligence Act)\, as amended by Regulatio
 n (EU) 2026/1744 (Digital Omnibus on AI) (European Union)\n\nSource: https
 ://eur-lex.europa.eu/eli/reg/2026/1744/oj\n\nhttps://rulebook.fru.dev/regu
 lations/eu-ai-act
URL:https://rulebook.fru.dev/regulations/eu-ai-act
CATEGORIES:European Union,ai,biometrics,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-107@regulations.fru.dev
DTSTAMP:20260924T094351Z
DTSTART;VALUE=DATE:20261209
DTEND;VALUE=DATE:20261210
SUMMARY:Product Liability Directive: Transposition deadline\; old PLD repea
 led
DESCRIPTION:Member States must transpose by 9 Dec 2026 (Art 22). Directive 
 85/374/EEC is repealed from that date but still applies to products placed
  on the market before it (Art 21).\n\nDirective (EU) 2024/2853 on liabilit
 y for defective products (new Product Liability Directive) (European Union
 )\n\nSource: https://eur-lex.europa.eu/eli/dir/2024/2853/oj\n\nhttps://rul
 ebook.fru.dev/regulations/eu-pld
URL:https://rulebook.fru.dev/regulations/eu-pld
CATEGORIES:European Union,ai,cybersecurity
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6@regulations.fru.dev
DTSTAMP:20260924T094351Z
DTSTART;VALUE=DATE:20261210
DTEND;VALUE=DATE:20261211
SUMMARY:Australia Privacy Act: Children's Online Privacy Code must be regis
 tered
DESCRIPTION:OAIC must develop and register the Children's Online Privacy Co
 de within 24 months of Royal Assent.\n\nPrivacy Act 1988 (Cth)\, as amende
 d by the Privacy and Other Legislation Amendment Act 2024 (Australia)\n\nS
 ource: https://www.oaic.gov.au/privacy/privacy-registers/privacy-codes/chi
 ldrens-online-privacy-code\n\nhttps://rulebook.fru.dev/regulations/au-priv
 acy-act
URL:https://rulebook.fru.dev/regulations/au-privacy-act
CATEGORIES:Australia,privacy,children,breach-notification,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-7@regulations.fru.dev
DTSTAMP:20260924T094351Z
DTSTART;VALUE=DATE:20261210
DTEND;VALUE=DATE:20261211
SUMMARY:Australia Privacy Act: Automated decision-making transparency appli
 es
DESCRIPTION:Privacy policies must disclose the kinds of personal informatio
 n used in substantially automated decisions that significantly affect indi
 viduals (24 months after assent).\n\nPrivacy Act 1988 (Cth)\, as amended b
 y the Privacy and Other Legislation Amendment Act 2024 (Australia)\n\nSour
 ce: https://www.legislation.gov.au/C2024A00128/asmade\n\nhttps://rulebook.
 fru.dev/regulations/au-privacy-act
URL:https://rulebook.fru.dev/regulations/au-privacy-act
CATEGORIES:Australia,privacy,children,breach-notification,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-88@regulations.fru.dev
DTSTAMP:20260924T094351Z
DTSTART;VALUE=DATE:20261224
DTEND;VALUE=DATE:20261225
SUMMARY:eIDAS 2 / EU Digital Identity Wallet: Member States must provide EU
  Digital Identity Wallets
DESCRIPTION:Each Member State must provide at least one wallet within 24 mo
 nths of the entry into force of the implementing acts under Arts 5a(23) an
 d 5c(6) (Art 5a(1)).\n\nRegulation (EU) 2024/1183 amending Regulation (EU)
  No 910/2014 as regards establishing the European Digital Identity Framewo
 rk (eIDAS 2) (European Union)\n\nSource: https://eur-lex.europa.eu/eli/reg
 _impl/2024/2977/oj\n\nhttps://rulebook.fru.dev/regulations/eu-eidas2
URL:https://rulebook.fru.dev/regulations/eu-eidas2
CATEGORIES:European Union,privacy,data-access,biometrics
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-191@regulations.fru.dev
DTSTAMP:20260924T094351Z
DTSTART;VALUE=DATE:20270101
DTEND;VALUE=DATE:20270102
SUMMARY:California AI Transparency Act (SB 942): Large online platform and 
 hosting platform duties
DESCRIPTION:Large online platforms and GenAI hosting platforms must meet th
 e provenance duties added by AB 853.\n\nCalifornia AI Transparency Act (SB
  942\, Stats. 2024\, ch. 291)\, as amended by AB 853 (Stats. 2025\, ch. 67
 4) (California)\n\nSource: https://leginfo.legislature.ca.gov/faces/billNa
 vClient.xhtml?bill_id=202520260AB853\n\nhttps://rulebook.fru.dev/regulatio
 ns/us-ca-sb942
URL:https://rulebook.fru.dev/regulations/us-ca-sb942
CATEGORIES:California,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-186@regulations.fru.dev
DTSTAMP:20260924T094351Z
DTSTART;VALUE=DATE:20270101
DTEND;VALUE=DATE:20270102
SUMMARY:California SB 53 (TFAIA): First OES anonymized incident report and 
 CDT definition review
DESCRIPTION:OES begins publishing annual anonymized incident summaries and 
 the Department of Technology begins annual review of the act's definitions
 \; the CalCompute framework report is due to the Legislature.\n\nCaliforni
 a SB 53\, Transparency in Frontier Artificial Intelligence Act (Stats. 202
 5\, ch. 138) (California)\n\nSource: https://leginfo.legislature.ca.gov/fa
 ces/billNavClient.xhtml?bill_id=202520260SB53\n\nhttps://rulebook.fru.dev/
 regulations/us-ca-sb53
URL:https://rulebook.fru.dev/regulations/us-ca-sb53
CATEGORIES:California,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-169@regulations.fru.dev
DTSTAMP:20260924T094351Z
DTSTART;VALUE=DATE:20270101
DTEND;VALUE=DATE:20270102
SUMMARY:CCPA / CPRA: ADMT requirements compliance date
DESCRIPTION:Businesses using ADMT for significant decisions must comply wit
 h Article 11 (pre-use notice\, opt-out\, access rights) by this date (11 C
 CR 7200(b)).\n\nCalifornia Consumer Privacy Act of 2018\, as amended by th
 e California Privacy Rights Act of 2020 (Cal. Civ. Code 1798.100 et seq.) 
 and CPPA regulations (Cal. Code Regs. tit. 11\, 7000 et seq.) (California)
 \n\nSource: https://cppa.ca.gov/regulations/pdf/ccpa_updates_cyber_risk_ad
 mt_appr_text.pdf\n\nhttps://rulebook.fru.dev/regulations/us-ca-ccpa
URL:https://rulebook.fru.dev/regulations/us-ca-ccpa
CATEGORIES:California,privacy,ai,cybersecurity,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-170@regulations.fru.dev
DTSTAMP:20260924T094351Z
DTSTART;VALUE=DATE:20270101
DTEND;VALUE=DATE:20270102
SUMMARY:CCPA / CPRA: Browsers must support opt-out preference signal (AB 56
 6)
DESCRIPTION:Businesses that develop or maintain a browser must include cons
 umer-configurable functionality to send an opt-out preference signal (Civ.
  Code 1798.136\, operative Jan 1\, 2027).\n\nCalifornia Consumer Privacy A
 ct of 2018\, as amended by the California Privacy Rights Act of 2020 (Cal.
  Civ. Code 1798.100 et seq.) and CPPA regulations (Cal. Code Regs. tit. 11
 \, 7000 et seq.) (California)\n\nSource: https://leginfo.legislature.ca.go
 v/faces/billStatusClient.xhtml?bill_id=202520260AB566\n\nhttps://rulebook.
 fru.dev/regulations/us-ca-ccpa
URL:https://rulebook.fru.dev/regulations/us-ca-ccpa
CATEGORIES:California,privacy,ai,cybersecurity,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-204@regulations.fru.dev
DTSTAMP:20260924T094351Z
DTSTART;VALUE=DATE:20270101
DTEND;VALUE=DATE:20270102
SUMMARY:Colorado AI Act: ADMT obligations apply
DESCRIPTION:Developer documentation\, consumer notices\, post-adverse-outco
 me disclosure\, correction and human-review rights take effect.\n\nColorad
 o SB 24-205 (Consumer Protections for Artificial Intelligence)\, as delaye
 d by SB 25B-004 and repealed and reenacted by SB 26-189 (Automated Decisio
 n-Making Technology) (Colorado)\n\nSource: https://leg.colorado.gov/bills/
 sb26-189\n\nhttps://rulebook.fru.dev/regulations/us-co-ai-act
URL:https://rulebook.fru.dev/regulations/us-co-ai-act
CATEGORIES:Colorado,ai,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-205@regulations.fru.dev
DTSTAMP:20260924T094351Z
DTSTART;VALUE=DATE:20270101
DTEND;VALUE=DATE:20270102
SUMMARY:Colorado AI Act: AG rules due
DESCRIPTION:Attorney General must adopt rules clarifying the post-adverse-o
 utcome disclosure requirements.\n\nColorado SB 24-205 (Consumer Protection
 s for Artificial Intelligence)\, as delayed by SB 25B-004 and repealed and
  reenacted by SB 26-189 (Automated Decision-Making Technology) (Colorado)\
 n\nSource: https://leg.colorado.gov/bills/sb26-189\n\nhttps://rulebook.fru
 .dev/regulations/us-co-ai-act
URL:https://rulebook.fru.dev/regulations/us-co-ai-act
CATEGORIES:Colorado,ai,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-221@regulations.fru.dev
DTSTAMP:20260924T094351Z
DTSTART;VALUE=DATE:20270101
DTEND;VALUE=DATE:20270102
SUMMARY:Connecticut Data Privacy Act (CTDPA): Data broker registration requ
 ired
DESCRIPTION:Data brokers may not sell or license brokered personal data in 
 Connecticut unless registered with the Department of Consumer Protection (
 $2\,500 initial fee).\n\nConnecticut Data Privacy Act (Public Act 22-15)\,
  Conn. Gen. Stat. 42-515 et seq.\, as amended by Public Act 25-113 (SB 129
 5) and Public Act 26-64 (SB 4) (Connecticut)\n\nSource: https://www.cga.ct
 .gov/2026/ACT/PA/PDF/2026PA-00064-R00SB-00004-PA.PDF\n\nhttps://rulebook.f
 ru.dev/regulations/us-ct-ctdpa
URL:https://rulebook.fru.dev/regulations/us-ct-ctdpa
CATEGORIES:Connecticut,privacy,children,ai,health
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-226@regulations.fru.dev
DTSTAMP:20260924T094351Z
DTSTART;VALUE=DATE:20270101
DTEND;VALUE=DATE:20270102
SUMMARY:Delaware Personal Data Privacy Act (DPDPA): Amended thresholds and 
 third-party duties take effect
DESCRIPTION:Applicability drops to 10\,000 consumers (or 5\,000 + 20% reven
 ue from sale) and new third-party duties (12D-107A) apply.\n\nDelaware Per
 sonal Data Privacy Act (HB 154)\, 6 Del. C. ch. 12D (Delaware)\n\nSource: 
 https://delcode.delaware.gov/title6/c012d/index.html\n\nhttps://rulebook.f
 ru.dev/regulations/us-de-dpdpa
URL:https://rulebook.fru.dev/regulations/us-de-dpdpa
CATEGORIES:Delaware,privacy,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-250@regulations.fru.dev
DTSTAMP:20260924T094351Z
DTSTART;VALUE=DATE:20270101
DTEND;VALUE=DATE:20270102
SUMMARY:Louisiana Data Privacy Act: Louisiana Data Privacy Act takes effect
DESCRIPTION:Consumer rights and controller duties apply (Act 502\, Section 
 2)\; data protection assessment requirements apply to processing from this
  date.\n\nLouisiana Data Privacy Act (SB 386\, 2026 Regular Session\, Act 
 No. 502)\, La. R.S. 51:1780.1-1780.5 (Louisiana)\n\nSource: https://legis.
 la.gov/legis/ViewDocument.aspx?d=1480202\n\nhttps://rulebook.fru.dev/regul
 ations/us-la-ldpa
URL:https://rulebook.fru.dev/regulations/us-la-ldpa
CATEGORIES:Louisiana,privacy,biometrics
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-263@regulations.fru.dev
DTSTAMP:20260924T094351Z
DTSTART;VALUE=DATE:20270101
DTEND;VALUE=DATE:20270102
SUMMARY:New Hampshire Privacy Act: Ban on selling personal data of children
  under 13 (HB 1460)
DESCRIPTION:HB 1460 (2026\, ch. 168) prohibits controllers from selling the
  personal data of a child under 13.\n\nNew Hampshire Privacy Act (SB 255\,
  2024)\, RSA chapter 507-H (New Hampshire)\n\nSource: https://gc.nh.gov/bi
 ll_status/billinfo.aspx?id=2443&inflect=2\n\nhttps://rulebook.fru.dev/regu
 lations/us-nh-privacy
URL:https://rulebook.fru.dev/regulations/us-nh-privacy
CATEGORIES:New Hampshire,privacy,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-280@regulations.fru.dev
DTSTAMP:20260924T094351Z
DTSTART;VALUE=DATE:20270101
DTEND;VALUE=DATE:20270102
SUMMARY:NY RAISE Act: RAISE Act takes effect
DESCRIPTION:Transparency reports\, frontier AI frameworks\, incident report
 ing and DFS disclosure filings apply.\n\nNew York Responsible AI Safety an
 d Education (RAISE) Act (S6953-B/A6453-B of 2025)\, as amended by chapter 
 amendment S8828 of 2026 (New York)\n\nSource: https://www.nysenate.gov/leg
 islation/bills/2025/S8828\n\nhttps://rulebook.fru.dev/regulations/us-ny-ra
 ise
URL:https://rulebook.fru.dev/regulations/us-ny-raise
CATEGORIES:New York,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-282@regulations.fru.dev
DTSTAMP:20260924T094351Z
DTSTART;VALUE=DATE:20270101
DTEND;VALUE=DATE:20270102
SUMMARY:Oklahoma OKCDPA: Oklahoma Consumer Data Privacy Act takes effect
DESCRIPTION:All OKCDPA obligations and consumer rights apply.\n\nOklahoma C
 onsumer Data Privacy Act (SB 546\, 2026) (Oklahoma)\n\nSource: https://www
 .okhouse.gov/posts/news-20260323_2\n\nhttps://rulebook.fru.dev/regulations
 /us-ok-okcdpa
URL:https://rulebook.fru.dev/regulations/us-ok-okcdpa
CATEGORIES:Oklahoma,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-310@regulations.fru.dev
DTSTAMP:20260924T094351Z
DTSTART;VALUE=DATE:20270101
DTEND;VALUE=DATE:20270102
SUMMARY:Utah UCPA: UCPA extends to motor vehicle manufacturers
DESCRIPTION:Motor vehicle manufacturers whose vehicles are sold or leased i
 n Utah and that collect personal data through vehicle data systems are cov
 ered regardless of the revenue and consumer thresholds (13-61-102\, as ame
 nded by Laws 2026\, ch. 193).\n\nUtah Consumer Privacy Act (SB 227\, 2022)
  (Utah)\n\nSource: https://le.utah.gov/xcode/Title13/Chapter61/13-61-S102.
 html\n\nhttps://rulebook.fru.dev/regulations/us-ut-ucpa
URL:https://rulebook.fru.dev/regulations/us-ut-ucpa
CATEGORIES:Utah,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-60@regulations.fru.dev
DTSTAMP:20260924T094351Z
DTSTART;VALUE=DATE:20270112
DTEND;VALUE=DATE:20270113
SUMMARY:EU Data Act: Cloud switching charges abolished
DESCRIPTION:Providers of data processing services may no longer impose any 
 switching charges on customers (Art 29(1)).\n\nRegulation (EU) 2023/2854 o
 n harmonised rules on fair access to and use of data (Data Act) (European 
 Union)\n\nSource: https://eur-lex.europa.eu/eli/reg/2023/2854/oj\n\nhttps:
 //rulebook.fru.dev/regulations/eu-data-act
URL:https://rulebook.fru.dev/regulations/eu-data-act
CATEGORIES:European Union,data-access,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-114@regulations.fru.dev
DTSTAMP:20260924T094351Z
DTSTART;VALUE=DATE:20270116
DTEND;VALUE=DATE:20270117
SUMMARY:Indonesia PDP Law: Implementing regulation GR 33/2026 takes effect
DESCRIPTION:Detailed PDP implementing rules (DPIA\, cross-border\, children
 's consent) apply\, 6 months after the 16 Jul 2026 enactment.\n\nLaw No. 2
 7 of 2022 on Personal Data Protection (Undang-Undang Pelindungan Data Prib
 adi) (Indonesia)\n\nSource: https://www.kk-advocates.com/news/read/indones
 ia-gr-pdp-personal-data-protection-compliance-regime-new-phase\n\nhttps://
 rulebook.fru.dev/regulations/id-pdp
URL:https://rulebook.fru.dev/regulations/id-pdp
CATEGORIES:Indonesia,privacy,breach-notification,data-residency,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-179@regulations.fru.dev
DTSTAMP:20260924T094351Z
DTSTART;VALUE=DATE:20270131
DTEND;VALUE=DATE:20270201
SUMMARY:California Delete Act / DROP: Annual data broker registration deadl
 ine
DESCRIPTION:Data brokers must renew registration with CalPrivacy by January
  31 following each year they meet the definition.\n\nCalifornia Delete Act
  (SB 362\, 2023)\, Cal. Civ. Code 1798.99.80 et seq.\, and DROP regulation
 s (California)\n\nSource: https://leginfo.legislature.ca.gov/faces/codes_d
 isplaySection.xhtml?lawCode=CIV&sectionNum=1798.99.82\n\nhttps://rulebook.
 fru.dev/regulations/us-ca-delete-act
URL:https://rulebook.fru.dev/regulations/us-ca-delete-act
CATEGORIES:California,privacy,data-access
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-322@regulations.fru.dev
DTSTAMP:20260924T094351Z
DTSTART;VALUE=DATE:20270301
DTEND;VALUE=DATE:20270302
SUMMARY:Vietnam AI Law: Transition ends for existing AI systems (general)
DESCRIPTION:Existing AI systems in most sectors must comply (12-month trans
 ition).\n\nLaw on Artificial Intelligence (Law No. 134/2025/QH15) (Vietnam
 )\n\nSource: https://www.vilaf.com.vn/blog/vietnam-enacts-its-first-law-on
 -artificial-intelligence-key-regulatory-obligations-from-1-march-2026/\n\n
 https://rulebook.fru.dev/regulations/vn-ai-law
URL:https://rulebook.fru.dev/regulations/vn-ai-law
CATEGORIES:Vietnam,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-81@regulations.fru.dev
DTSTAMP:20260924T094351Z
DTSTART;VALUE=DATE:20270326
DTEND;VALUE=DATE:20270327
SUMMARY:European Health Data Space (EHDS): EHDS general application date
DESCRIPTION:The regulation applies generally from 26 Mar 2027\, subject to 
 the phased exceptions below (final article).\n\nRegulation (EU) 2025/327 o
 n the European Health Data Space (European Union)\n\nSource: https://eur-l
 ex.europa.eu/eli/reg/2025/327/oj\n\nhttps://rulebook.fru.dev/regulations/e
 u-ehds
URL:https://rulebook.fru.dev/regulations/eu-ehds
CATEGORIES:European Union,health,privacy,data-access
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-254@regulations.fru.dev
DTSTAMP:20260924T094351Z
DTSTART;VALUE=DATE:20270401
DTEND;VALUE=DATE:20270402
SUMMARY:Maryland Online Data Privacy Act (MODPA): Discretionary 60-day cure
  period ends
DESCRIPTION:The Division's discretionary notice-and-cure (at least 60 days)
  applies only to violations occurring on or before April 1\, 2027 (Com. La
 w 14-4614).\n\nMaryland Online Data Privacy Act of 2024 (SB 541 / HB 567)\
 , Md. Code\, Com. Law 14-4601 et seq. (Maryland)\n\nSource: https://mgaleg
 .maryland.gov/2024RS/Chapters_noln/CH_455_sb0541e.pdf\n\nhttps://rulebook.
 fru.dev/regulations/us-md-modpa
URL:https://rulebook.fru.dev/regulations/us-md-modpa
CATEGORIES:Maryland,privacy,children,health,biometrics
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-97@regulations.fru.dev
DTSTAMP:20260924T094351Z
DTSTART;VALUE=DATE:20270402
DTEND;VALUE=DATE:20270403
SUMMARY:GDPR: GDPR Procedural Regulation applies
DESCRIPTION:Harmonised rules for cross-border complaint admissibility\, rig
 hts to be heard and access to preliminary findings\, and investigation tim
 elines apply to DPAs from 2 April 2027 (Regulation (EU) 2025/2518\, final 
 article).\n\nRegulation (EU) 2016/679 (General Data Protection Regulation)
  (European Union)\n\nSource: https://eur-lex.europa.eu/eli/reg/2025/2518/o
 j\n\nhttps://rulebook.fru.dev/regulations/eu-gdpr
URL:https://rulebook.fru.dev/regulations/eu-gdpr
CATEGORIES:European Union,privacy,breach-notification,data-access,children,
 biometrics,health
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-104@regulations.fru.dev
DTSTAMP:20260924T094351Z
DTSTART;VALUE=DATE:20270417
DTEND;VALUE=DATE:20270418
SUMMARY:NIS2: Next biennial entity notification
DESCRIPTION:Competent authorities notify the Commission and Cooperation Gro
 up of the number of essential and important entities\, repeated every two 
 years after 17 Apr 2025 (Art 3(5)).\n\nDirective (EU) 2022/2555 on measure
 s for a high common level of cybersecurity across the Union (NIS2 Directiv
 e) (European Union)\n\nSource: https://eur-lex.europa.eu/eli/dir/2022/2555
 /oj\n\nhttps://rulebook.fru.dev/regulations/eu-nis2
URL:https://rulebook.fru.dev/regulations/eu-nis2
CATEGORIES:European Union,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-161@regulations.fru.dev
DTSTAMP:20260924T094351Z
DTSTART;VALUE=DATE:20270501
DTEND;VALUE=DATE:20270502
SUMMARY:Alabama Personal Data Protection Act (APDPA): APDPA takes effect
DESCRIPTION:Consumer rights and controller/processor obligations apply (HB 
 351 section 12).\n\nAlabama Personal Data Protection Act (HB 351\, 2026 Re
 gular Session) (Alabama)\n\nSource: https://alison.legislature.state.al.us
 /files/pdf/SearchableInstruments/2026RS/HB351-enr.pdf\n\nhttps://rulebook.
 fru.dev/regulations/us-al-apdpa
URL:https://rulebook.fru.dev/regulations/us-al-apdpa
CATEGORIES:Alabama,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-118@regulations.fru.dev
DTSTAMP:20260924T094351Z
DTSTART;VALUE=DATE:20270513
DTEND;VALUE=DATE:20270514
SUMMARY:India DPDP Act: Main data fiduciary obligations apply (18 months)
DESCRIPTION:Rules 3\, 5-16\, 22 and 23 (notice\, security safeguards\, brea
 ch notification\, retention\, children's consent\, SDF duties\, cross-bord
 er) come into force 18 months after publication.\n\nDigital Personal Data 
 Protection Act\, 2023 and Digital Personal Data Protection Rules\, 2025 (I
 ndia)\n\nSource: https://egazette.gov.in/WriteReadData/2025/267650.pdf\n\n
 https://rulebook.fru.dev/regulations/in-dpdp
URL:https://rulebook.fru.dev/regulations/in-dpdp
CATEGORIES:India,privacy,children,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-183@regulations.fru.dev
DTSTAMP:20260924T094351Z
DTSTART;VALUE=DATE:20270701
DTEND;VALUE=DATE:20270702
SUMMARY:California SB 243 (companion chatbots): First annual report to Offi
 ce of Suicide Prevention
DESCRIPTION:Operators begin annual reporting on crisis referrals and detect
 ion protocols.\n\nCalifornia SB 243\, Companion Chatbots (Stats. 2025\, ch
 . 677) (California)\n\nSource: https://leginfo.legislature.ca.gov/faces/bi
 llNavClient.xhtml?bill_id=202520260SB243\n\nhttps://rulebook.fru.dev/regul
 ations/us-ca-sb243
URL:https://rulebook.fru.dev/regulations/us-ca-sb243
CATEGORIES:California,ai,children,online-safety
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-127@regulations.fru.dev
DTSTAMP:20260924T094351Z
DTSTART;VALUE=DATE:20270701
DTEND;VALUE=DATE:20270702
SUMMARY:South Korea PIPA: Mandatory ISMS-P certification
DESCRIPTION:ISMS-P certification becomes mandatory for private entities mee
 ting the statutory criteria.\n\nPersonal Information Protection Act (as am
 ended by Act No. 21445\, 2026) (South Korea)\n\nSource: https://www.law.go
 .kr/법령/개인정보보호법\n\nhttps://rulebook.fru.dev/regulations/k
 r-pipa
URL:https://rulebook.fru.dev/regulations/kr-pipa
CATEGORIES:South Korea,privacy,breach-notification,biometrics,data-residenc
 y
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-307@regulations.fru.dev
DTSTAMP:20260924T094351Z
DTSTART;VALUE=DATE:20270701
DTEND;VALUE=DATE:20270702
SUMMARY:Utah AI Policy Act: Scheduled repeal of Title 13\, Ch. 72
DESCRIPTION:SB 332 extends the AI Policy Act repeal date from May 1\, 2025 
 to July 1\, 2027.\n\nUtah Artificial Intelligence Policy Act (SB 149\, 202
 4)\, as amended by SB 226 and SB 332 (2025) (Utah)\n\nSource: https://le.u
 tah.gov/~2025/bills/static/SB0332.html\n\nhttps://rulebook.fru.dev/regulat
 ions/us-ut-aipa
URL:https://rulebook.fru.dev/regulations/us-ut-aipa
CATEGORIES:Utah,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-251@regulations.fru.dev
DTSTAMP:20260924T094351Z
DTSTART;VALUE=DATE:20270731
DTEND;VALUE=DATE:20270801
SUMMARY:Louisiana Data Privacy Act: 30-day cure period expires
DESCRIPTION:AG's obligation to give 30-day notice and allow cure before inv
 estigating applies only from Jan 1 through July 31\, 2027 (R.S. 51:1780.5(
 D)).\n\nLouisiana Data Privacy Act (SB 386\, 2026 Regular Session\, Act No
 . 502)\, La. R.S. 51:1780.1-1780.5 (Louisiana)\n\nSource: https://legis.la
 .gov/legis/ViewDocument.aspx?d=1480202\n\nhttps://rulebook.fru.dev/regulat
 ions/us-la-ldpa
URL:https://rulebook.fru.dev/regulations/us-la-ldpa
CATEGORIES:Louisiana,privacy,biometrics
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-43@regulations.fru.dev
DTSTAMP:20260924T094351Z
DTSTART;VALUE=DATE:20270802
DTEND;VALUE=DATE:20270803
SUMMARY:EU AI Act: Legacy GPAI models must comply\; national AI sandboxes o
 perational
DESCRIPTION:Providers of GPAI models placed on the market before 2 Aug 2025
  must comply (Art 111(3)). Each Member State must have at least one nation
 al AI regulatory sandbox operational (Art 57(1) as amended by the Omnibus)
 .\n\nRegulation (EU) 2024/1689 laying down harmonised rules on artificial 
 intelligence (Artificial Intelligence Act)\, as amended by Regulation (EU)
  2026/1744 (Digital Omnibus on AI) (European Union)\n\nSource: https://eur
 -lex.europa.eu/eli/reg/2024/1689/oj\n\nhttps://rulebook.fru.dev/regulation
 s/eu-ai-act
URL:https://rulebook.fru.dev/regulations/eu-ai-act
CATEGORIES:European Union,ai,biometrics,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-323@regulations.fru.dev
DTSTAMP:20260924T094351Z
DTSTART;VALUE=DATE:20270901
DTEND;VALUE=DATE:20270902
SUMMARY:Vietnam AI Law: Transition ends for existing AI systems in health\,
  education and finance
DESCRIPTION:Existing AI systems in healthcare\, education and finance must 
 comply (18-month transition).\n\nLaw on Artificial Intelligence (Law No. 1
 34/2025/QH15) (Vietnam)\n\nSource: https://www.vilaf.com.vn/blog/vietnam-e
 nacts-its-first-law-on-artificial-intelligence-key-regulatory-obligations-
 from-1-march-2026/\n\nhttps://rulebook.fru.dev/regulations/vn-ai-law
URL:https://rulebook.fru.dev/regulations/vn-ai-law
CATEGORIES:Vietnam,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-61@regulations.fru.dev
DTSTAMP:20260924T094351Z
DTSTART;VALUE=DATE:20270912
DTEND;VALUE=DATE:20270913
SUMMARY:EU Data Act: Unfair-terms rules extend to older long-term contracts
DESCRIPTION:Chapter IV (unfair contractual terms) applies to contracts conc
 luded on or before 12 Sep 2025 that are of indefinite duration or expire a
 t least 10 years from 11 Jan 2024 (Art 50).\n\nRegulation (EU) 2023/2854 o
 n harmonised rules on fair access to and use of data (Data Act) (European 
 Union)\n\nSource: https://eur-lex.europa.eu/eli/reg/2023/2854/oj\n\nhttps:
 //rulebook.fru.dev/regulations/eu-data-act
URL:https://rulebook.fru.dev/regulations/eu-data-act
CATEGORIES:European Union,data-access,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-105@regulations.fru.dev
DTSTAMP:20260924T094351Z
DTSTART;VALUE=DATE:20271017
DTEND;VALUE=DATE:20271018
SUMMARY:NIS2: Commission review of NIS2
DESCRIPTION:Commission must review the functioning of NIS2 and report to Pa
 rliament and Council\, then every 36 months (Art 40).\n\nDirective (EU) 20
 22/2555 on measures for a high common level of cybersecurity across the Un
 ion (NIS2 Directive) (European Union)\n\nSource: https://eur-lex.europa.eu
 /eli/dir/2022/2555/oj\n\nhttps://rulebook.fru.dev/regulations/eu-nis2
URL:https://rulebook.fru.dev/regulations/eu-nis2
CATEGORIES:European Union,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-197@regulations.fru.dev
DTSTAMP:20260924T094351Z
DTSTART;VALUE=DATE:20271110
DTEND;VALUE=DATE:20271111
SUMMARY:CMMC 2.0: Phase 3: Level 3 certification
DESCRIPTION:Phase 3 begins one year after Phase 2\; Level 3 (DIBCAC) requir
 ements added to applicable solicitations (32 CFR 170.3(e)(3)).\n\nCybersec
 urity Maturity Model Certification (CMMC) Program (32 CFR Part 170) and DF
 ARS acquisition rule (48 CFR Parts 204\, 212\, 217\, 252) (United States (
 Federal))\n\nSource: https://www.federalregister.gov/documents/2024/10/15/
 2024-22905/cybersecurity-maturity-model-certification-cmmc-program\n\nhttp
 s://rulebook.fru.dev/regulations/us-cmmc
URL:https://rulebook.fru.dev/regulations/us-cmmc
CATEGORIES:United States (Federal),cybersecurity
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-28@regulations.fru.dev
DTSTAMP:20260924T094351Z
DTSTART;VALUE=DATE:20271201
DTEND;VALUE=DATE:20271202
SUMMARY:Chile Personal Data Protection Law (Ley 21.719): Proposed postponem
 ent of entry into force
DESCRIPTION:Government bill Boletin 18623-07 (filed 1 Sep 2026\, 'suma' urg
 ency) would replace the 24-month vacatio legis in transitional Art 1 with 
 a fixed date of 1 Dec 2027\; in first committee stage in the Senate\, not 
 law.\n\nTentative: depends on a proposal not yet adopted.\n\nLey Nº 21.71
 9 que regula la protección y el tratamiento de los datos personales y cre
 a la Agencia de Protección de Datos Personales (Chile)\n\nSource: https:/
 /tramitacion.senado.cl/appsenado/templates/tramitacion/index.php?boletin_i
 ni=18623-07\n\nhttps://rulebook.fru.dev/regulations/cl-pdpl
URL:https://rulebook.fru.dev/regulations/cl-pdpl
CATEGORIES:Chile,privacy,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-44@regulations.fru.dev
DTSTAMP:20260924T094351Z
DTSTART;VALUE=DATE:20271202
DTEND;VALUE=DATE:20271203
SUMMARY:EU AI Act: High-risk obligations apply to Annex III systems
DESCRIPTION:Chapter III Sections 1-3 (high-risk requirements and provider/d
 eployer obligations) apply to AI systems classified high-risk under Art 6(
 2) and Annex III (employment\, credit scoring\, education\, biometrics\, e
 ssential services and similar). Deferred from 2 Aug 2026 by Regulation (EU
 ) 2026/1744.\n\nRegulation (EU) 2024/1689 laying down harmonised rules on 
 artificial intelligence (Artificial Intelligence Act)\, as amended by Regu
 lation (EU) 2026/1744 (Digital Omnibus on AI) (European Union)\n\nSource: 
 https://eur-lex.europa.eu/eli/reg/2026/1744/oj\n\nhttps://rulebook.fru.dev
 /regulations/eu-ai-act
URL:https://rulebook.fru.dev/regulations/eu-ai-act
CATEGORIES:European Union,ai,biometrics,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-51@regulations.fru.dev
DTSTAMP:20260924T094351Z
DTSTART;VALUE=DATE:20271211
DTEND;VALUE=DATE:20271212
SUMMARY:Cyber Resilience Act: CRA fully applies
DESCRIPTION:All remaining obligations\, including essential cybersecurity r
 equirements\, conformity assessment and CE marking\, apply (Art 71(2)). Pr
 oducts placed on the market earlier are covered only if substantially modi
 fied (Art 69(2)).\n\nRegulation (EU) 2024/2847 on horizontal cybersecurity
  requirements for products with digital elements (Cyber Resilience Act) (E
 uropean Union)\n\nSource: https://eur-lex.europa.eu/eli/reg/2024/2847/oj\n
 \nhttps://rulebook.fru.dev/regulations/eu-cra
URL:https://rulebook.fru.dev/regulations/eu-cra
CATEGORIES:European Union,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-89@regulations.fru.dev
DTSTAMP:20260924T094351Z
DTSTART;VALUE=DATE:20271224
DTEND;VALUE=DATE:20271225
SUMMARY:eIDAS 2 / EU Digital Identity Wallet: Private relying parties must 
 accept wallets
DESCRIPTION:Private relying parties required by law or contract to use stro
 ng user authentication must accept wallets on user request within 36 month
 s of the implementing acts' entry into force (Art 5f(2)).\n\nRegulation (E
 U) 2024/1183 amending Regulation (EU) No 910/2014 as regards establishing 
 the European Digital Identity Framework (eIDAS 2) (European Union)\n\nSour
 ce: https://eur-lex.europa.eu/eli/reg_impl/2024/2977/oj\n\nhttps://ruleboo
 k.fru.dev/regulations/eu-eidas2
URL:https://rulebook.fru.dev/regulations/eu-eidas2
CATEGORIES:European Union,privacy,data-access,biometrics
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-171@regulations.fru.dev
DTSTAMP:20260924T094351Z
DTSTART;VALUE=DATE:20271231
DTEND;VALUE=DATE:20280101
SUMMARY:CCPA / CPRA: Risk assessments for pre-existing processing due
DESCRIPTION:Risk assessments must be completed and documented for high-risk
  processing that began before Jan 1\, 2026 and continues after (11 CCR 715
 5(b)).\n\nCalifornia Consumer Privacy Act of 2018\, as amended by the Cali
 fornia Privacy Rights Act of 2020 (Cal. Civ. Code 1798.100 et seq.) and CP
 PA regulations (Cal. Code Regs. tit. 11\, 7000 et seq.) (California)\n\nSo
 urce: https://cppa.ca.gov/regulations/pdf/ccpa_updates_cyber_risk_admt_app
 r_text.pdf\n\nhttps://rulebook.fru.dev/regulations/us-ca-ccpa
URL:https://rulebook.fru.dev/regulations/us-ca-ccpa
CATEGORIES:California,privacy,ai,cybersecurity,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-192@regulations.fru.dev
DTSTAMP:20260924T094351Z
DTSTART;VALUE=DATE:20280101
DTEND;VALUE=DATE:20280102
SUMMARY:California AI Transparency Act (SB 942): Capture device manufacture
 r duties
DESCRIPTION:Capture device manufacturer provenance requirements become oper
 ative.\n\nCalifornia AI Transparency Act (SB 942\, Stats. 2024\, ch. 291)\
 , as amended by AB 853 (Stats. 2025\, ch. 674) (California)\n\nSource: htt
 ps://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=20252026
 0AB853\n\nhttps://rulebook.fru.dev/regulations/us-ca-sb942
URL:https://rulebook.fru.dev/regulations/us-ca-sb942
CATEGORIES:California,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-180@regulations.fru.dev
DTSTAMP:20260924T094351Z
DTSTART;VALUE=DATE:20280101
DTEND;VALUE=DATE:20280102
SUMMARY:California Delete Act / DROP: Independent third-party audits begin
DESCRIPTION:Beginning Jan 1\, 2028 and every 3 years thereafter\, data brok
 ers must undergo an independent audit of Delete Act compliance.\n\nCalifor
 nia Delete Act (SB 362\, 2023)\, Cal. Civ. Code 1798.99.80 et seq.\, and D
 ROP regulations (California)\n\nSource: https://www.cppa.ca.gov/data_broke
 rs/\n\nhttps://rulebook.fru.dev/regulations/us-ca-delete-act
URL:https://rulebook.fru.dev/regulations/us-ca-delete-act
CATEGORIES:California,privacy,data-access
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-315@regulations.fru.dev
DTSTAMP:20260924T094351Z
DTSTART;VALUE=DATE:20280101
DTEND;VALUE=DATE:20280102
SUMMARY:Vermont VDPOSA: Vermont Data Privacy and Online Surveillance Act ta
 kes effect
DESCRIPTION:All obligations under Act 145 apply (sec. 4).\n\nVermont Data P
 rivacy and Online Surveillance Act (S.71\, Act 145 of 2026) (Vermont)\n\nS
 ource: https://legislature.vermont.gov/Documents/2026/Docs/ACTS/ACT145/ACT
 145%20As%20Enacted.pdf\n\nhttps://rulebook.fru.dev/regulations/us-vt-vdpos
 a
URL:https://rulebook.fru.dev/regulations/us-vt-vdposa
CATEGORIES:Vermont,privacy,health,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-172@regulations.fru.dev
DTSTAMP:20260924T094351Z
DTSTART;VALUE=DATE:20280401
DTEND;VALUE=DATE:20280402
SUMMARY:CCPA / CPRA: First risk assessment submission to CPPA
DESCRIPTION:Businesses must submit required risk assessment information and
  attestation for assessments conducted in 2026 and 2027 (11 CCR 7157(a)(1)
 )\; annually by April 1 thereafter.\n\nCalifornia Consumer Privacy Act of 
 2018\, as amended by the California Privacy Rights Act of 2020 (Cal. Civ. 
 Code 1798.100 et seq.) and CPPA regulations (Cal. Code Regs. tit. 11\, 700
 0 et seq.) (California)\n\nSource: https://cppa.ca.gov/regulations/pdf/ccp
 a_updates_cyber_risk_admt_appr_text.pdf\n\nhttps://rulebook.fru.dev/regula
 tions/us-ca-ccpa
URL:https://rulebook.fru.dev/regulations/us-ca-ccpa
CATEGORIES:California,privacy,ai,cybersecurity,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-173@regulations.fru.dev
DTSTAMP:20260924T094351Z
DTSTART;VALUE=DATE:20280401
DTEND;VALUE=DATE:20280402
SUMMARY:CCPA / CPRA: Cybersecurity audit due: revenue over $100M
DESCRIPTION:First cybersecurity audit report (covering Jan 1\, 2027 - Jan 1
 \, 2028) and certification due for businesses with 2026 annual gross reven
 ue over $100M (11 CCR 7121(a)(1)).\n\nCalifornia Consumer Privacy Act of 2
 018\, as amended by the California Privacy Rights Act of 2020 (Cal. Civ. C
 ode 1798.100 et seq.) and CPPA regulations (Cal. Code Regs. tit. 11\, 7000
  et seq.) (California)\n\nSource: https://cppa.ca.gov/regulations/pdf/ccpa
 _updates_cyber_risk_admt_appr_text.pdf\n\nhttps://rulebook.fru.dev/regulat
 ions/us-ca-ccpa
URL:https://rulebook.fru.dev/regulations/us-ca-ccpa
CATEGORIES:California,privacy,ai,cybersecurity,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-52@regulations.fru.dev
DTSTAMP:20260924T094351Z
DTSTART;VALUE=DATE:20280611
DTEND;VALUE=DATE:20280612
SUMMARY:Cyber Resilience Act: Legacy type-examination certificates expire
DESCRIPTION:EU type-examination certificates and approval decisions on cybe
 rsecurity requirements under other harmonisation legislation remain valid 
 until this date unless they expire earlier (Art 69(1)).\n\nRegulation (EU)
  2024/2847 on horizontal cybersecurity requirements for products with digi
 tal elements (Cyber Resilience Act) (European Union)\n\nSource: https://eu
 r-lex.europa.eu/eli/reg/2024/2847/oj\n\nhttps://rulebook.fru.dev/regulatio
 ns/eu-cra
URL:https://rulebook.fru.dev/regulations/eu-cra
CATEGORIES:European Union,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-45@regulations.fru.dev
DTSTAMP:20260924T094351Z
DTSTART;VALUE=DATE:20280802
DTEND;VALUE=DATE:20280803
SUMMARY:EU AI Act: High-risk obligations apply to Annex I product-embedded 
 systems
DESCRIPTION:Chapter III Sections 1-3 apply to AI systems classified high-ri
 sk under Art 6(1) and Annex I (safety components of products covered by EU
  harmonisation legislation). Deferred from 2 Aug 2027 by Regulation (EU) 2
 026/1744.\n\nRegulation (EU) 2024/1689 laying down harmonised rules on art
 ificial intelligence (Artificial Intelligence Act)\, as amended by Regulat
 ion (EU) 2026/1744 (Digital Omnibus on AI) (European Union)\n\nSource: htt
 ps://eur-lex.europa.eu/eli/reg/2026/1744/oj\n\nhttps://rulebook.fru.dev/re
 gulations/eu-ai-act
URL:https://rulebook.fru.dev/regulations/eu-ai-act
CATEGORIES:European Union,ai,biometrics,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-53@regulations.fru.dev
DTSTAMP:20260924T094351Z
DTSTART;VALUE=DATE:20280911
DTEND;VALUE=DATE:20280912
SUMMARY:Cyber Resilience Act: Report on single reporting platform
DESCRIPTION:Commission report assessing the single reporting platform's eff
 ectiveness (Art 70(2)).\n\nRegulation (EU) 2024/2847 on horizontal cyberse
 curity requirements for products with digital elements (Cyber Resilience A
 ct) (European Union)\n\nSource: https://eur-lex.europa.eu/eli/reg/2024/284
 7/oj\n\nhttps://rulebook.fru.dev/regulations/eu-cra
URL:https://rulebook.fru.dev/regulations/eu-cra
CATEGORIES:European Union,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-62@regulations.fru.dev
DTSTAMP:20260924T094351Z
DTSTART;VALUE=DATE:20280912
DTEND;VALUE=DATE:20280913
SUMMARY:EU Data Act: Commission evaluation
DESCRIPTION:Commission evaluation report due\, including the impact of clou
 d switching rules (Arts 23-31) (Art 49(2)).\n\nRegulation (EU) 2023/2854 o
 n harmonised rules on fair access to and use of data (Data Act) (European 
 Union)\n\nSource: https://eur-lex.europa.eu/eli/reg/2023/2854/oj\n\nhttps:
 //rulebook.fru.dev/regulations/eu-data-act
URL:https://rulebook.fru.dev/regulations/eu-data-act
CATEGORIES:European Union,data-access,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-222@regulations.fru.dev
DTSTAMP:20260924T094351Z
DTSTART;VALUE=DATE:20281001
DTEND;VALUE=DATE:20281002
SUMMARY:Connecticut Data Privacy Act (CTDPA): Data brokers must process sta
 te deletion mechanism requests
DESCRIPTION:Registered data brokers must access the DCP accessible deletion
  mechanism at least every 45 days and process deletion requests.\n\nConnec
 ticut Data Privacy Act (Public Act 22-15)\, Conn. Gen. Stat. 42-515 et seq
 .\, as amended by Public Act 25-113 (SB 1295) and Public Act 26-64 (SB 4) 
 (Connecticut)\n\nSource: https://www.cga.ct.gov/2026/ACT/PA/PDF/2026PA-000
 64-R00SB-00004-PA.PDF\n\nhttps://rulebook.fru.dev/regulations/us-ct-ctdpa
URL:https://rulebook.fru.dev/regulations/us-ct-ctdpa
CATEGORIES:Connecticut,privacy,children,ai,health
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-198@regulations.fru.dev
DTSTAMP:20260924T094351Z
DTSTART;VALUE=DATE:20281110
DTEND;VALUE=DATE:20281111
SUMMARY:CMMC 2.0: Phase 4: full implementation
DESCRIPTION:CMMC requirements included in all applicable DoD solicitations 
 and contracts\, including option periods (32 CFR 170.3(e)(4)).\n\nCybersec
 urity Maturity Model Certification (CMMC) Program (32 CFR Part 170) and DF
 ARS acquisition rule (48 CFR Parts 204\, 212\, 217\, 252) (United States (
 Federal))\n\nSource: https://www.federalregister.gov/documents/2024/10/15/
 2024-22905/cybersecurity-maturity-model-certification-cmmc-program\n\nhttp
 s://rulebook.fru.dev/regulations/us-cmmc
URL:https://rulebook.fru.dev/regulations/us-cmmc
CATEGORIES:United States (Federal),cybersecurity
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-82@regulations.fru.dev
DTSTAMP:20260924T094351Z
DTSTART;VALUE=DATE:20290326
DTEND;VALUE=DATE:20290327
SUMMARY:European Health Data Space (EHDS): Primary use for first data categ
 ories\; secondary use framework applies
DESCRIPTION:Patient rights and EHR rules apply to patient summaries\, ePres
 criptions and eDispensations (Art 14(1)(a)-(c)). Chapter IV secondary-use 
 rules (data permits\, Health Data Access Bodies) apply.\n\nRegulation (EU)
  2025/327 on the European Health Data Space (European Union)\n\nSource: ht
 tps://eur-lex.europa.eu/eli/reg/2025/327/oj\n\nhttps://rulebook.fru.dev/re
 gulations/eu-ehds
URL:https://rulebook.fru.dev/regulations/eu-ehds
CATEGORIES:European Union,health,privacy,data-access
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-174@regulations.fru.dev
DTSTAMP:20260924T094351Z
DTSTART;VALUE=DATE:20290401
DTEND;VALUE=DATE:20290402
SUMMARY:CCPA / CPRA: Cybersecurity audit due: revenue $50M-$100M
DESCRIPTION:First cybersecurity audit report (covering 2028) due for busine
 sses with 2027 annual gross revenue between $50M and $100M (11 CCR 7121(a)
 (2)).\n\nCalifornia Consumer Privacy Act of 2018\, as amended by the Calif
 ornia Privacy Rights Act of 2020 (Cal. Civ. Code 1798.100 et seq.) and CPP
 A regulations (Cal. Code Regs. tit. 11\, 7000 et seq.) (California)\n\nSou
 rce: https://cppa.ca.gov/regulations/pdf/ccpa_updates_cyber_risk_admt_appr
 _text.pdf\n\nhttps://rulebook.fru.dev/regulations/us-ca-ccpa
URL:https://rulebook.fru.dev/regulations/us-ca-ccpa
CATEGORIES:California,privacy,ai,cybersecurity,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-316@regulations.fru.dev
DTSTAMP:20260924T094351Z
DTSTART;VALUE=DATE:20290630
DTEND;VALUE=DATE:20290701
SUMMARY:Vermont VDPOSA: Mandatory 60-day cure period expires
DESCRIPTION:The AG's duty to issue a cure notice before enforcement ends Ju
 ne 30\, 2029 (Act 145 sec. 3).\n\nVermont Data Privacy and Online Surveill
 ance Act (S.71\, Act 145 of 2026) (Vermont)\n\nSource: https://legislature
 .vermont.gov/Documents/2026/Docs/ACTS/ACT145/ACT145%20As%20Enacted.pdf\n\n
 https://rulebook.fru.dev/regulations/us-vt-vdposa
URL:https://rulebook.fru.dev/regulations/us-vt-vdposa
CATEGORIES:Vermont,privacy,health,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-257@regulations.fru.dev
DTSTAMP:20260924T094351Z
DTSTART;VALUE=DATE:20290731
DTEND;VALUE=DATE:20290801
SUMMARY:Minnesota Consumer Data Privacy Act (MCDPA): Postsecondary institut
 ions must comply
DESCRIPTION:Postsecondary institutions regulated by the Office of Higher Ed
 ucation must comply by July 31\, 2029.\n\nMinnesota Consumer Data Privacy 
 Act (HF 4757\, 2024 Minn. Laws ch. 121\, art. 5)\, Minn. Stat. 325M.10-325
 M.21 (Minnesota)\n\nSource: https://www.revisor.mn.gov/statutes/cite/325M.
 20\n\nhttps://rulebook.fru.dev/regulations/us-mn-mcdpa
URL:https://rulebook.fru.dev/regulations/us-mn-mcdpa
CATEGORIES:Minnesota,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-206@regulations.fru.dev
DTSTAMP:20260924T094351Z
DTSTART;VALUE=DATE:20300101
DTEND;VALUE=DATE:20300102
SUMMARY:Colorado AI Act: Mandatory cure period ends
DESCRIPTION:The AG's obligation to offer a 60-day notice-and-cure period ex
 pires.\n\nColorado SB 24-205 (Consumer Protections for Artificial Intellig
 ence)\, as delayed by SB 25B-004 and repealed and reenacted by SB 26-189 (
 Automated Decision-Making Technology) (Colorado)\n\nSource: https://leg.co
 lorado.gov/bills/sb26-189\n\nhttps://rulebook.fru.dev/regulations/us-co-ai
 -act
URL:https://rulebook.fru.dev/regulations/us-co-ai-act
CATEGORIES:Colorado,ai,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-175@regulations.fru.dev
DTSTAMP:20260924T094351Z
DTSTART;VALUE=DATE:20300401
DTEND;VALUE=DATE:20300402
SUMMARY:CCPA / CPRA: Cybersecurity audit due: revenue under $50M
DESCRIPTION:First cybersecurity audit report (covering 2029) due for covere
 d businesses with 2028 annual gross revenue under $50M (11 CCR 7121(a)(3))
 \; annual by April 1 thereafter.\n\nCalifornia Consumer Privacy Act of 201
 8\, as amended by the California Privacy Rights Act of 2020 (Cal. Civ. Cod
 e 1798.100 et seq.) and CPPA regulations (Cal. Code Regs. tit. 11\, 7000 e
 t seq.) (California)\n\nSource: https://cppa.ca.gov/regulations/pdf/ccpa_u
 pdates_cyber_risk_admt_appr_text.pdf\n\nhttps://rulebook.fru.dev/regulatio
 ns/us-ca-ccpa
URL:https://rulebook.fru.dev/regulations/us-ca-ccpa
CATEGORIES:California,privacy,ai,cybersecurity,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-46@regulations.fru.dev
DTSTAMP:20260924T094351Z
DTSTART;VALUE=DATE:20300802
DTEND;VALUE=DATE:20300803
SUMMARY:EU AI Act: Public-authority high-risk systems must comply
DESCRIPTION:Providers and deployers of high-risk AI systems intended for us
 e by public authorities that were placed on the market before the Chapter 
 III application date must comply (Art 111(2)\, as replaced by the Omnibus)
 .\n\nRegulation (EU) 2024/1689 laying down harmonised rules on artificial 
 intelligence (Artificial Intelligence Act)\, as amended by Regulation (EU)
  2026/1744 (Digital Omnibus on AI) (European Union)\n\nSource: https://eur
 -lex.europa.eu/eli/reg/2026/1744/oj\n\nhttps://rulebook.fru.dev/regulation
 s/eu-ai-act
URL:https://rulebook.fru.dev/regulations/eu-ai-act
CATEGORIES:European Union,ai,biometrics,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-54@regulations.fru.dev
DTSTAMP:20260924T094351Z
DTSTART;VALUE=DATE:20301211
DTEND;VALUE=DATE:20301212
SUMMARY:Cyber Resilience Act: First CRA evaluation
DESCRIPTION:Commission evaluation and review report\, then every four years
  (Art 70(1)).\n\nRegulation (EU) 2024/2847 on horizontal cybersecurity req
 uirements for products with digital elements (Cyber Resilience Act) (Europ
 ean Union)\n\nSource: https://eur-lex.europa.eu/eli/reg/2024/2847/oj\n\nht
 tps://rulebook.fru.dev/regulations/eu-cra
URL:https://rulebook.fru.dev/regulations/eu-cra
CATEGORIES:European Union,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-47@regulations.fru.dev
DTSTAMP:20260924T094351Z
DTSTART;VALUE=DATE:20301231
DTEND;VALUE=DATE:20310101
SUMMARY:EU AI Act: Large-scale EU IT systems must comply
DESCRIPTION:AI systems that are components of the large-scale IT systems in
  Annex X (e.g. SIS\, VIS\, Eurodac\, EES\, ETIAS) placed on the market bef
 ore 2 Aug 2027 must be brought into compliance (Art 111(1)).\n\nRegulation
  (EU) 2024/1689 laying down harmonised rules on artificial intelligence (A
 rtificial Intelligence Act)\, as amended by Regulation (EU) 2026/1744 (Dig
 ital Omnibus on AI) (European Union)\n\nSource: https://eur-lex.europa.eu/
 eli/reg/2024/1689/oj\n\nhttps://rulebook.fru.dev/regulations/eu-ai-act
URL:https://rulebook.fru.dev/regulations/eu-ai-act
CATEGORIES:European Union,ai,biometrics,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-83@regulations.fru.dev
DTSTAMP:20260924T094351Z
DTSTART;VALUE=DATE:20310326
DTEND;VALUE=DATE:20310327
SUMMARY:European Health Data Space (EHDS): Primary use for second data cate
 gories\; EHR systems in service\; extra secondary-use categories
DESCRIPTION:Primary-use rules extend to medical images\, lab results and di
 scharge reports (Art 14(1)(d)-(f)). Chapter III applies to EHR systems put
  into service under Art 26(2). Additional secondary-use categories in Art 
 51(1)(b)\,(f)\,(g)\,(m)\,(p) apply.\n\nRegulation (EU) 2025/327 on the Eur
 opean Health Data Space (European Union)\n\nSource: https://eur-lex.europa
 .eu/eli/reg/2025/327/oj\n\nhttps://rulebook.fru.dev/regulations/eu-ehds
URL:https://rulebook.fru.dev/regulations/eu-ehds
CATEGORIES:European Union,health,privacy,data-access
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-84@regulations.fru.dev
DTSTAMP:20260924T094351Z
DTSTART;VALUE=DATE:20350326
DTEND;VALUE=DATE:20350327
SUMMARY:European Health Data Space (EHDS): Third-country participation in s
 econdary use
DESCRIPTION:Art 75(5) applies from 26 Mar 2035.\n\nRegulation (EU) 2025/327
  on the European Health Data Space (European Union)\n\nSource: https://eur
 -lex.europa.eu/eli/reg/2025/327/oj\n\nhttps://rulebook.fru.dev/regulations
 /eu-ehds
URL:https://rulebook.fru.dev/regulations/eu-ehds
CATEGORIES:European Union,health,privacy,data-access
TRANSP:TRANSPARENT
END:VEVENT
END:VCALENDAR
