BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//fru.dev//Rulebook//EN
CALSCALE:GREGORIAN
METHOD:PUBLISH
X-WR-CALNAME:Regulation deadlines (Rulebook)
X-WR-CALDESC:Compliance deadlines tracked at rulebook.fru.dev
REFRESH-INTERVAL;VALUE=DURATION:P1D
X-PUBLISHED-TTL:P1D
BEGIN:VEVENT
UID:deadline-18@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20010101
DTEND;VALUE=DATE:20010102
SUMMARY:PIPEDA: PIPEDA Part 1 in force (phase 1)
DESCRIPTION:Applies to federally regulated organisations.\n\nPersonal Infor
 mation Protection and Electronic Documents Act (Canada)\n\nSource: https:/
 /laws-lois.justice.gc.ca/eng/acts/p-8.6/\n\nhttps://rulebook.fru.dev/regul
 ations/ca-pipeda
URL:https://rulebook.fru.dev/regulations/ca-pipeda
CATEGORIES:Canada,privacy,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-90@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20020731
DTEND;VALUE=DATE:20020801
SUMMARY:ePrivacy Directive (cookie law): ePrivacy Directive enters into for
 ce
DESCRIPTION:Entered into force on the day of publication in the OJ (Art 20)
 .\n\nDirective 2002/58/EC concerning the processing of personal data and t
 he protection of privacy in the electronic communications sector (ePrivacy
  Directive)\, as amended by Directive 2009/136/EC (European Union)\n\nSour
 ce: https://eur-lex.europa.eu/eli/dir/2002/58/oj\n\nhttps://rulebook.fru.d
 ev/regulations/eu-eprivacy
URL:https://rulebook.fru.dev/regulations/eu-eprivacy
CATEGORIES:European Union,privacy,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-91@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20031031
DTEND;VALUE=DATE:20031101
SUMMARY:ePrivacy Directive (cookie law): Original transposition deadline
DESCRIPTION:Member States had to bring national laws into force before 31 O
 ct 2003 (Art 17).\n\nDirective 2002/58/EC concerning the processing of per
 sonal data and the protection of privacy in the electronic communications 
 sector (ePrivacy Directive)\, as amended by Directive 2009/136/EC (Europea
 n Union)\n\nSource: https://eur-lex.europa.eu/eli/dir/2002/58/oj\n\nhttps:
 //rulebook.fru.dev/regulations/eu-eprivacy
URL:https://rulebook.fru.dev/regulations/eu-eprivacy
CATEGORIES:European Union,privacy,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-19@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20040101
DTEND;VALUE=DATE:20040102
SUMMARY:PIPEDA: PIPEDA applies to all commercial activity
DESCRIPTION:Extended to commercial activity in provinces without substantia
 lly similar legislation.\n\nPersonal Information Protection and Electronic
  Documents Act (Canada)\n\nSource: https://laws-lois.justice.gc.ca/eng/act
 s/p-8.6/\n\nhttps://rulebook.fru.dev/regulations/ca-pipeda
URL:https://rulebook.fru.dev/regulations/ca-pipeda
CATEGORIES:Canada,privacy,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-241@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20081003
DTEND;VALUE=DATE:20081004
SUMMARY:Illinois BIPA: BIPA effective
DESCRIPTION:The Biometric Information Privacy Act takes effect.\n\nIllinois
  Biometric Information Privacy Act (740 ILCS 14)\, as amended by SB 2979 (
 Public Act 103-0769) (Illinois)\n\nSource: https://www.ilga.gov/legislatio
 n/ilcs/ilcs3.asp?ActID=3004&ChapterID=57\n\nhttps://rulebook.fru.dev/regul
 ations/us-il-bipa
URL:https://rulebook.fru.dev/regulations/us-il-bipa
CATEGORIES:Illinois,biometrics,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-231@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20100222
DTEND;VALUE=DATE:20100223
SUMMARY:FTC Health Breach Notification Rule: Full compliance with original 
 Rule
DESCRIPTION:Full compliance with the 2009 Health Breach Notification Rule w
 as required.\n\nFTC Health Breach Notification Rule (16 CFR Part 318)\, as
  amended 2024 (United States (Federal))\n\nSource: https://www.federalregi
 ster.gov/citation/74-FR-42962\n\nhttps://rulebook.fru.dev/regulations/us-f
 tc-hbnr
URL:https://rulebook.fru.dev/regulations/us-ftc-hbnr
CATEGORIES:United States (Federal),health,privacy,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-92@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20110525
DTEND;VALUE=DATE:20110526
SUMMARY:ePrivacy Directive (cookie law): Cookie consent amendment transposi
 tion deadline
DESCRIPTION:Directive 2009/136/EC\, which changed Art 5(3) to require conse
 nt for cookies\, had to be transposed by 25 May 2011.\n\nDirective 2002/58
 /EC concerning the processing of personal data and the protection of priva
 cy in the electronic communications sector (ePrivacy Directive)\, as amend
 ed by Directive 2009/136/EC (European Union)\n\nSource: https://eur-lex.eu
 ropa.eu/eli/dir/2009/136/oj\n\nhttps://rulebook.fru.dev/regulations/eu-epr
 ivacy
URL:https://rulebook.fru.dev/regulations/eu-eprivacy
CATEGORIES:European Union,privacy,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-139@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20140702
DTEND;VALUE=DATE:20140703
SUMMARY:Singapore PDPA: PDPA data protection obligations take effect
DESCRIPTION:Main data protection provisions come into force.\n\nPersonal Da
 ta Protection Act 2012 (Singapore) (Singapore)\n\nSource: https://sso.agc.
 gov.sg/Act/PDPA2012\n\nhttps://rulebook.fru.dev/regulations/sg-pdpa
URL:https://rulebook.fru.dev/regulations/sg-pdpa
CATEGORIES:Singapore,privacy,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-93@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20160524
DTEND;VALUE=DATE:20160525
SUMMARY:GDPR: GDPR enters into force
DESCRIPTION:Regulation entered into force on the twentieth day after public
 ation in OJ L 119 of 4 May 2016 (Art 99(1)).\n\nRegulation (EU) 2016/679 (
 General Data Protection Regulation) (European Union)\n\nSource: https://eu
 r-lex.europa.eu/eli/reg/2016/679/oj\n\nhttps://rulebook.fru.dev/regulation
 s/eu-gdpr
URL:https://rulebook.fru.dev/regulations/eu-gdpr
CATEGORIES:European Union,privacy,breach-notification,data-access,children,
 biometrics,health
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-269@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20170301
DTEND;VALUE=DATE:20170302
SUMMARY:NYDFS Cybersecurity Regulation (Part 500): Part 500 effective
DESCRIPTION:Original cybersecurity regulation takes effect.\n\nNew York DFS
  Cybersecurity Requirements for Financial Services Companies (23 NYCRR Par
 t 500)\, Second Amendment (New York)\n\nSource: https://www.dfs.ny.gov/cyb
 ersecurity/23-NYCRR-Part-500\n\nhttps://rulebook.fru.dev/regulations/us-ny
 -dfs-500
URL:https://rulebook.fru.dev/regulations/us-ny-dfs-500
CATEGORIES:New York,cybersecurity,breach-notification,financial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-31@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20170601
DTEND;VALUE=DATE:20170602
SUMMARY:China Cybersecurity Law: Cybersecurity Law takes effect
DESCRIPTION:Original CSL obligations for network operators and CII operator
 s apply.\n\nCybersecurity Law of the People's Republic of China (as amende
 d by the NPC Standing Committee Decision of 28 October 2025) (China)\n\nSo
 urce: https://www.gov.cn/yaowen/liebiao/202510/content_7046194.htm\n\nhttp
 s://rulebook.fru.dev/regulations/cn-csl
URL:https://rulebook.fru.dev/regulations/cn-csl
CATEGORIES:China,cybersecurity,data-residency,ai,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-94@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20180525
DTEND;VALUE=DATE:20180526
SUMMARY:GDPR: GDPR applies
DESCRIPTION:All GDPR obligations apply from 25 May 2018 (Art 99(2))\, repla
 cing Directive 95/46/EC.\n\nRegulation (EU) 2016/679 (General Data Protect
 ion Regulation) (European Union)\n\nSource: https://eur-lex.europa.eu/eli/
 reg/2016/679/oj\n\nhttps://rulebook.fru.dev/regulations/eu-gdpr
URL:https://rulebook.fru.dev/regulations/eu-gdpr
CATEGORIES:European Union,privacy,breach-notification,data-access,children,
 biometrics,health
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-153@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20180525
DTEND;VALUE=DATE:20180526
SUMMARY:UK GDPR: Data Protection Act 2018 and GDPR apply
DESCRIPTION:DPA 2018 and EU GDPR began applying in the UK.\n\nUK General Da
 ta Protection Regulation and Data Protection Act 2018 (United Kingdom)\n\n
 Source: https://www.legislation.gov.uk/ukpga/2018/12/contents\n\nhttps://r
 ulebook.fru.dev/regulations/uk-gdpr
URL:https://rulebook.fru.dev/regulations/uk-gdpr
CATEGORIES:United Kingdom,privacy,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-20@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20181101
DTEND;VALUE=DATE:20181102
SUMMARY:PIPEDA: Mandatory breach reporting
DESCRIPTION:Breach of security safeguards reporting\, notification and reco
 rd-keeping obligations take effect.\n\nPersonal Information Protection and
  Electronic Documents Act (Canada)\n\nSource: https://laws-lois.justice.gc
 .ca/eng/acts/p-8.6/\n\nhttps://rulebook.fru.dev/regulations/ca-pipeda
URL:https://rulebook.fru.dev/regulations/ca-pipeda
CATEGORIES:Canada,privacy,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-123@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20191125
DTEND;VALUE=DATE:20191126
SUMMARY:Kenya Data Protection Act: Data Protection Act in force
DESCRIPTION:Act commences.\n\nData Protection Act\, 2019 (No. 24 of 2019) (
 Kenya)\n\nSource: https://www.odpc.go.ke/\n\nhttps://rulebook.fru.dev/regu
 lations/ke-dpa
URL:https://rulebook.fru.dev/regulations/ke-dpa
CATEGORIES:Kenya,privacy,breach-notification,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-164@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20200101
DTEND;VALUE=DATE:20200102
SUMMARY:CCPA / CPRA: CCPA takes effect
DESCRIPTION:Original CCPA consumer rights and business obligations take eff
 ect.\n\nCalifornia Consumer Privacy Act of 2018\, as amended by the Califo
 rnia Privacy Rights Act of 2020 (Cal. Civ. Code 1798.100 et seq.) and CPPA
  regulations (Cal. Code Regs. tit. 11\, 7000 et seq.) (California)\n\nSour
 ce: https://cppa.ca.gov/regulations/pdf/ccpa_statute_eff_20260101.pdf\n\nh
 ttps://rulebook.fru.dev/regulations/us-ca-ccpa
URL:https://rulebook.fru.dev/regulations/us-ca-ccpa
CATEGORIES:California,privacy,ai,cybersecurity,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-325@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20200701
DTEND;VALUE=DATE:20200702
SUMMARY:South Africa POPIA: Main POPIA provisions commence
DESCRIPTION:Most sections commence with a 12-month grace period.\n\nProtect
 ion of Personal Information Act\, 2013 (Act No. 4 of 2013) (South Africa)\
 n\nSource: https://www.gov.za/documents/protection-personal-information-ac
 t\n\nhttps://rulebook.fru.dev/regulations/za-popia
URL:https://rulebook.fru.dev/regulations/za-popia
CATEGORIES:South Africa,privacy,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-11@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20200918
DTEND;VALUE=DATE:20200919
SUMMARY:Brazil LGPD: LGPD in force
DESCRIPTION:Main LGPD provisions take effect.\n\nLei Geral de Proteção de
  Dados Pessoais (Law No. 13.709/2018) (Brazil)\n\nSource: https://www.plan
 alto.gov.br/ccivil_03/_ato2015-2018/2018/lei/l13709.htm\n\nhttps://ruleboo
 k.fru.dev/regulations/br-lgpd
URL:https://rulebook.fru.dev/regulations/br-lgpd
CATEGORIES:Brazil,privacy,breach-notification,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-134@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20201201
DTEND;VALUE=DATE:20201202
SUMMARY:New Zealand Privacy Act: Privacy Act 2020 in force
DESCRIPTION:IPPs\, mandatory breach notification and compliance notices app
 ly.\n\nPrivacy Act 2020 (New Zealand)\, as amended by the Privacy Amendmen
 t Act 2025 (New Zealand)\n\nSource: https://www.justice.govt.nz/justice-se
 ctor-policy/key-initiatives/enhancing-the-privacy-act/\n\nhttps://rulebook
 .fru.dev/regulations/nz-privacy-act
URL:https://rulebook.fru.dev/regulations/nz-privacy-act
CATEGORIES:New Zealand,privacy,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-154@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20210101
DTEND;VALUE=DATE:20210102
SUMMARY:UK GDPR: UK GDPR takes effect after Brexit transition
DESCRIPTION:Retained EU GDPR becomes the UK GDPR at the end of the Brexit i
 mplementation period.\n\nUK General Data Protection Regulation and Data Pr
 otection Act 2018 (United Kingdom)\n\nSource: https://www.legislation.gov.
 uk/eur/2016/679/contents\n\nhttps://rulebook.fru.dev/regulations/uk-gdpr
URL:https://rulebook.fru.dev/regulations/uk-gdpr
CATEGORIES:United Kingdom,privacy,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-140@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20210201
DTEND;VALUE=DATE:20210202
SUMMARY:Singapore PDPA: 2020 amendments largely in force
DESCRIPTION:Mandatory data breach notification and revised consent framewor
 k apply.\n\nPersonal Data Protection Act 2012 (Singapore) (Singapore)\n\nS
 ource: https://sso.agc.gov.sg/Act/PDPA2012\n\nhttps://rulebook.fru.dev/reg
 ulations/sg-pdpa
URL:https://rulebook.fru.dev/regulations/sg-pdpa
CATEGORIES:Singapore,privacy,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-326@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20210701
DTEND;VALUE=DATE:20210702
SUMMARY:South Africa POPIA: Compliance grace period ends
DESCRIPTION:Responsible parties must comply\; Regulator enforcement begins 
 (grace period ended 30 June 2021).\n\nProtection of Personal Information A
 ct\, 2013 (Act No. 4 of 2013) (South Africa)\n\nSource: https://www.gov.za
 /documents/protection-personal-information-act\n\nhttps://rulebook.fru.dev
 /regulations/za-popia
URL:https://rulebook.fru.dev/regulations/za-popia
CATEGORIES:South Africa,privacy,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-12@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20210801
DTEND;VALUE=DATE:20210802
SUMMARY:Brazil LGPD: ANPD sanctions enforceable
DESCRIPTION:Administrative sanctions (Arts. 52-54) become applicable per La
 w 14.010/2020.\n\nLei Geral de Proteção de Dados Pessoais (Law No. 13.70
 9/2018) (Brazil)\n\nSource: https://www.planalto.gov.br/ccivil_03/_ato2015
 -2018/2018/lei/l13709.htm\n\nhttps://rulebook.fru.dev/regulations/br-lgpd
URL:https://rulebook.fru.dev/regulations/br-lgpd
CATEGORIES:Brazil,privacy,breach-notification,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-33@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20210901
DTEND;VALUE=DATE:20210902
SUMMARY:China Data Security Law: Data Security Law takes effect
DESCRIPTION:Data classification\, important-data protection and data export
  restrictions apply (Art. 55).\n\nData Security Law of the People's Republ
 ic of China (China)\n\nSource: http://www.cac.gov.cn/2021-06/11/c_16249945
 66919140.htm\n\nhttps://rulebook.fru.dev/regulations/cn-dsl
URL:https://rulebook.fru.dev/regulations/cn-dsl
CATEGORIES:China,cybersecurity,data-residency,data-access
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-21@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20210922
DTEND;VALUE=DATE:20210923
SUMMARY:Quebec Law 25: Assent
DESCRIPTION:Bill 64 assented to as S.Q. 2021\, c. 25.\n\nAct to modernize l
 egislative provisions as regards the protection of personal information (L
 aw 25\, formerly Bill 64) (Quebec\, Canada)\n\nSource: https://www.legisqu
 ebec.gouv.qc.ca/en/document/cs/P-39.1\n\nhttps://rulebook.fru.dev/regulati
 ons/ca-qc-law25
URL:https://rulebook.fru.dev/regulations/ca-qc-law25
CATEGORIES:Quebec\, Canada,privacy,breach-notification,biometrics
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-36@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20211101
DTEND;VALUE=DATE:20211102
SUMMARY:China PIPL: PIPL takes effect
DESCRIPTION:All PIPL obligations (legal bases\, consent\, cross-border rule
 s\, data subject rights) apply (Art. 74).\n\nPersonal Information Protecti
 on Law of the People's Republic of China (China)\n\nSource: http://www.cac
 .gov.cn/2021-08/20/c_1631050028355286.htm\n\nhttps://rulebook.fru.dev/regu
 lations/cn-pipl
URL:https://rulebook.fru.dev/regulations/cn-pipl
CATEGORIES:China,privacy,data-residency,biometrics,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-1@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20220102
DTEND;VALUE=DATE:20220103
SUMMARY:UAE PDPL: PDPL enters into force
DESCRIPTION:Decree-law takes effect\; compliance obligations tied to Execut
 ive Regulations.\n\nFederal Decree-Law No. 45 of 2021 on the Protection of
  Personal Data (United Arab Emirates)\n\nSource: https://uaelegislation.go
 v.ae/en/legislations/1972\n\nhttps://rulebook.fru.dev/regulations/ae-pdpl
URL:https://rulebook.fru.dev/regulations/ae-pdpl
CATEGORIES:United Arab Emirates,privacy,breach-notification,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-233@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20220110
DTEND;VALUE=DATE:20220111
SUMMARY:GLBA Safeguards Rule: 2021 Safeguards Rule amendments effective
DESCRIPTION:The amended Safeguards Rule published December 9\, 2021 took ef
 fect\, with the more detailed program elements in 314.5 deferred.\n\nFTC S
 tandards for Safeguarding Customer Information (Safeguards Rule)\, 16 CFR 
 Part 314\, under the Gramm-Leach-Bliley Act (United States (Federal))\n\nS
 ource: https://www.federalregister.gov/documents/2021/12/09/2021-25736/sta
 ndards-for-safeguarding-customer-information\n\nhttps://rulebook.fru.dev/r
 egulations/us-glba-safeguards
URL:https://rulebook.fru.dev/regulations/us-glba-safeguards
CATEGORIES:United States (Federal),financial,cybersecurity,breach-notificat
 ion,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-121@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20220401
DTEND;VALUE=DATE:20220402
SUMMARY:Japan APPI: 2020 amendments in force
DESCRIPTION:Mandatory breach reporting\, pseudonymized information and stri
 cter cross-border rules apply.\n\nAct on the Protection of Personal Inform
 ation (Act No. 57 of 2003)\, as amended including the 2026 amendment act (
 Japan)\n\nSource: https://www.ppc.go.jp/en/legal/\n\nhttps://rulebook.fru.
 dev/regulations/jp-appi
URL:https://rulebook.fru.dev/regulations/jp-appi
CATEGORIES:Japan,privacy,children,biometrics,breach-notification,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-142@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20220601
DTEND;VALUE=DATE:20220602
SUMMARY:Thailand PDPA: PDPA main obligations take effect
DESCRIPTION:Core data protection obligations and penalties apply after post
 ponement Royal Decrees.\n\nPersonal Data Protection Act B.E. 2562 (2019) (
 Thailand)\n\nSource: https://www.ratchakitcha.soc.go.th/DATA/PDF/2562/A/06
 9/T_0052.PDF\n\nhttps://rulebook.fru.dev/regulations/th-pdpa
URL:https://rulebook.fru.dev/regulations/th-pdpa
CATEGORIES:Thailand,privacy,breach-notification,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-63@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20220623
DTEND;VALUE=DATE:20220624
SUMMARY:Data Governance Act: DGA enters into force
DESCRIPTION:Entered into force on the twentieth day after publication in OJ
  L 152 of 3 June 2022 (Art 38).\n\nRegulation (EU) 2022/868 on European da
 ta governance (Data Governance Act) (European Union)\n\nSource: https://eu
 r-lex.europa.eu/eli/reg/2022/868/oj\n\nhttps://rulebook.fru.dev/regulation
 s/eu-dga
URL:https://rulebook.fru.dev/regulations/eu-dga
CATEGORIES:European Union,data-access,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-22@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20220922
DTEND;VALUE=DATE:20220923
SUMMARY:Quebec Law 25: Phase 1: privacy officer and incident reporting
DESCRIPTION:Person in charge of personal information protection\, confident
 iality incident notification and register apply.\n\nAct to modernize legis
 lative provisions as regards the protection of personal information (Law 2
 5\, formerly Bill 64) (Quebec\, Canada)\n\nSource: https://www.legisquebec
 .gouv.qc.ca/en/document/cs/P-39.1\n\nhttps://rulebook.fru.dev/regulations/
 ca-qc-law25
URL:https://rulebook.fru.dev/regulations/ca-qc-law25
CATEGORIES:Quebec\, Canada,privacy,breach-notification,biometrics
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-141@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20221001
DTEND;VALUE=DATE:20221002
SUMMARY:Singapore PDPA: Higher financial penalty cap applies
DESCRIPTION:Maximum penalty rises to 10% of Singapore turnover for organiza
 tions with turnover above SGD 10 million.\n\nPersonal Data Protection Act 
 2012 (Singapore) (Singapore)\n\nSource: https://sso.agc.gov.sg/Act/PDPA201
 2\n\nhttps://rulebook.fru.dev/regulations/sg-pdpa
URL:https://rulebook.fru.dev/regulations/sg-pdpa
CATEGORIES:Singapore,privacy,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-112@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20221017
DTEND;VALUE=DATE:20221018
SUMMARY:Indonesia PDP Law: PDP Law enacted and in force
DESCRIPTION:Law takes effect on enactment\, starting a 2-year transition.\n
 \nLaw No. 27 of 2022 on Personal Data Protection (Undang-Undang Pelindunga
 n Data Pribadi) (Indonesia)\n\nSource: https://peraturan.bpk.go.id/Details
 /229798/uu-no-27-tahun-2022\n\nhttps://rulebook.fru.dev/regulations/id-pdp
URL:https://rulebook.fru.dev/regulations/id-pdp
CATEGORIES:Indonesia,privacy,breach-notification,data-residency,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-66@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20221101
DTEND;VALUE=DATE:20221102
SUMMARY:Digital Markets Act: DMA enters into force
DESCRIPTION:Entered into force twenty days after publication\; certain proc
 edural articles apply from this date (Art 54).\n\nRegulation (EU) 2022/192
 5 on contestable and fair markets in the digital sector (Digital Markets A
 ct) (European Union)\n\nSource: https://eur-lex.europa.eu/eli/reg/2022/192
 5/oj\n\nhttps://rulebook.fru.dev/regulations/eu-dma
URL:https://rulebook.fru.dev/regulations/eu-dma
CATEGORIES:European Union,data-access,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-75@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20221116
DTEND;VALUE=DATE:20221117
SUMMARY:Digital Services Act: DSA enters into force
DESCRIPTION:Entered into force twenty days after publication\; VLOP designa
 tion provisions (Art 33(3)-(6)) and Commission enforcement sections apply 
 from this date (Art 93).\n\nRegulation (EU) 2022/2065 on a Single Market f
 or Digital Services (Digital Services Act) (European Union)\n\nSource: htt
 ps://eur-lex.europa.eu/eli/reg/2022/2065/oj\n\nhttps://rulebook.fru.dev/re
 gulations/eu-dsa
URL:https://rulebook.fru.dev/regulations/eu-dsa
CATEGORIES:European Union,online-safety,children,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-165@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20230101
DTEND;VALUE=DATE:20230102
SUMMARY:CCPA / CPRA: CPRA amendments operative
DESCRIPTION:CPRA amendments (correction right\, sensitive PI limits\, shari
 ng opt-out\, employee/B2B data coverage) become operative.\n\nCalifornia C
 onsumer Privacy Act of 2018\, as amended by the California Privacy Rights 
 Act of 2020 (Cal. Civ. Code 1798.100 et seq.) and CPPA regulations (Cal. C
 ode Regs. tit. 11\, 7000 et seq.) (California)\n\nSource: https://cppa.ca.
 gov/regulations/pdf/ccpa_statute_eff_20260101.pdf\n\nhttps://rulebook.fru.
 dev/regulations/us-ca-ccpa
URL:https://rulebook.fru.dev/regulations/us-ca-ccpa
CATEGORIES:California,privacy,ai,cybersecurity,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-311@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20230101
DTEND;VALUE=DATE:20230102
SUMMARY:Virginia VCDPA: VCDPA takes effect
DESCRIPTION:VCDPA obligations and consumer rights apply.\n\nVirginia Consum
 er Data Protection Act (SB 1392 / HB 2307\, 2021) (Virginia)\n\nSource: ht
 tps://law.lis.virginia.gov/vacode/title59.1/chapter53/\n\nhttps://rulebook
 .fru.dev/regulations/us-va-vcdpa
URL:https://rulebook.fru.dev/regulations/us-va-vcdpa
CATEGORIES:Virginia,privacy,children,online-safety
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-70@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20230116
DTEND;VALUE=DATE:20230117
SUMMARY:DORA: DORA enters into force
DESCRIPTION:Entered into force on the twentieth day after publication in OJ
  L 333 of 27 Dec 2022 (Art 64).\n\nRegulation (EU) 2022/2554 on digital op
 erational resilience for the financial sector (Digital Operational Resilie
 nce Act) (European Union)\n\nSource: https://eur-lex.europa.eu/eli/reg/202
 2/2554/oj\n\nhttps://rulebook.fru.dev/regulations/eu-dora
URL:https://rulebook.fru.dev/regulations/eu-dora
CATEGORIES:European Union,cybersecurity,financial,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-98@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20230116
DTEND;VALUE=DATE:20230117
SUMMARY:NIS2: NIS2 enters into force
DESCRIPTION:Directive entered into force on the twentieth day after publica
 tion in OJ L 333 of 27 Dec 2022.\n\nDirective (EU) 2022/2555 on measures f
 or a high common level of cybersecurity across the Union (NIS2 Directive) 
 (European Union)\n\nSource: https://eur-lex.europa.eu/eli/dir/2022/2555/oj
 \n\nhttps://rulebook.fru.dev/regulations/eu-nis2
URL:https://rulebook.fru.dev/regulations/eu-nis2
CATEGORIES:European Union,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-76@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20230217
DTEND;VALUE=DATE:20230218
SUMMARY:Digital Services Act: Platforms publish EU user numbers
DESCRIPTION:Online platforms and search engines had to publish average mont
 hly active EU recipients\, and must update them at least every six months 
 (Art 24(2)).\n\nRegulation (EU) 2022/2065 on a Single Market for Digital S
 ervices (Digital Services Act) (European Union)\n\nSource: https://eur-lex
 .europa.eu/eli/reg/2022/2065/oj\n\nhttps://rulebook.fru.dev/regulations/eu
 -dsa
URL:https://rulebook.fru.dev/regulations/eu-dsa
CATEGORIES:European Union,online-safety,children,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-77@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20230425
DTEND;VALUE=DATE:20230426
SUMMARY:Digital Services Act: First VLOP/VLOSE designations
DESCRIPTION:Commission designated the first 19 very large online platforms 
 and search engines (e.g. Amazon Store\, Facebook\, Google Search\, TikTok\
 , X). Obligations apply four months after notification.\n\nRegulation (EU)
  2022/2065 on a Single Market for Digital Services (Digital Services Act) 
 (European Union)\n\nSource: https://digital-strategy.ec.europa.eu/en/polic
 ies/list-designated-vlops-and-vloses\n\nhttps://rulebook.fru.dev/regulatio
 ns/eu-dsa
URL:https://rulebook.fru.dev/regulations/eu-dsa
CATEGORIES:European Union,online-safety,children,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-317@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20230427
DTEND;VALUE=DATE:20230428
SUMMARY:Washington My Health My Data Act: HB 1155 signed
DESCRIPTION:Governor signs My Health My Data Act.\n\nWashington My Health M
 y Data Act (HB 1155\, Laws of 2023\, ch. 191\; RCW 19.373) (Washington)\n\
 nSource: https://app.leg.wa.gov/billsummary?BillNumber=1155&Year=2023\n\nh
 ttps://rulebook.fru.dev/regulations/us-wa-mhmda
URL:https://rulebook.fru.dev/regulations/us-wa-mhmda
CATEGORIES:Washington,health,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-67@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20230502
DTEND;VALUE=DATE:20230503
SUMMARY:Digital Markets Act: DMA applies
DESCRIPTION:DMA becomes applicable\; undertakings meeting thresholds must n
 otify the Commission within two months (Arts 3(3)\, 54).\n\nRegulation (EU
 ) 2022/1925 on contestable and fair markets in the digital sector (Digital
  Markets Act) (European Union)\n\nSource: https://eur-lex.europa.eu/eli/re
 g/2022/1925/oj\n\nhttps://rulebook.fru.dev/regulations/eu-dma
URL:https://rulebook.fru.dev/regulations/eu-dma
CATEGORIES:European Union,data-access,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-234@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20230609
DTEND;VALUE=DATE:20230610
SUMMARY:GLBA Safeguards Rule: Compliance with expanded security program ele
 ments
DESCRIPTION:Applicability of the 314.5 provisions (qualified individual\, w
 ritten risk assessment\, encryption\, MFA\, pen testing\, incident respons
 e plan\, board reporting) was delayed from December 9\, 2022 to this date.
 \n\nFTC Standards for Safeguarding Customer Information (Safeguards Rule)\
 , 16 CFR Part 314\, under the Gramm-Leach-Bliley Act (United States (Feder
 al))\n\nSource: https://www.federalregister.gov/documents/2022/11/23/2022-
 25201/standards-for-safeguarding-customer-information\n\nhttps://rulebook.
 fru.dev/regulations/us-glba-safeguards
URL:https://rulebook.fru.dev/regulations/us-glba-safeguards
CATEGORIES:United States (Federal),financial,cybersecurity,breach-notificat
 ion,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-132@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20230612
DTEND;VALUE=DATE:20230613
SUMMARY:Nigeria NDPA: NDPA signed into law
DESCRIPTION:President signs the Nigeria Data Protection Act\, 2023.\n\nNige
 ria Data Protection Act\, 2023 and NDPA General Application and Implementa
 tion Directive (GAID) 2025 (Nigeria)\n\nSource: https://ndpc.gov.ng/resour
 ces/\n\nhttps://rulebook.fru.dev/regulations/ng-ndpa
URL:https://rulebook.fru.dev/regulations/ng-ndpa
CATEGORIES:Nigeria,privacy,breach-notification,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-207@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20230701
DTEND;VALUE=DATE:20230702
SUMMARY:Colorado Privacy Act (CPA): CPA takes effect
DESCRIPTION:Core consumer rights and controller duties apply.\n\nColorado P
 rivacy Act (SB 21-190)\, C.R.S. 6-1-1301 et seq.\, as amended by HB 24-113
 0\, SB 24-041 and SB 25-276 (Colorado)\n\nSource: https://leg.colorado.gov
 /bills/sb21-190\n\nhttps://rulebook.fru.dev/regulations/us-co-cpa
URL:https://rulebook.fru.dev/regulations/us-co-cpa
CATEGORIES:Colorado,privacy,children,biometrics
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-215@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20230701
DTEND;VALUE=DATE:20230702
SUMMARY:Connecticut Data Privacy Act (CTDPA): CTDPA takes effect
DESCRIPTION:Core consumer rights and controller obligations apply.\n\nConne
 cticut Data Privacy Act (Public Act 22-15)\, Conn. Gen. Stat. 42-515 et se
 q.\, as amended by Public Act 25-113 (SB 1295) and Public Act 26-64 (SB 4)
  (Connecticut)\n\nSource: https://www.cga.ct.gov/asp/cgabillstatus/cgabill
 status.asp?selBillType=Bill&which_year=2022&bill_num=6\n\nhttps://rulebook
 .fru.dev/regulations/us-ct-ctdpa
URL:https://rulebook.fru.dev/regulations/us-ct-ctdpa
CATEGORIES:Connecticut,privacy,children,ai,health
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-281@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20230705
DTEND;VALUE=DATE:20230706
SUMMARY:NYC Local Law 144 (AEDT): DCWP enforcement begins
DESCRIPTION:Bias audit\, results publication and candidate notice requireme
 nts are enforced.\n\nNew York City Local Law 144 of 2021\, Automated Emplo
 yment Decision Tools (NYC Admin. Code 20-870 et seq.) (New York City\, New
  York)\n\nSource: https://www.nyc.gov/site/dca/about/automated-employment-
 decision-tools.page\n\nhttps://rulebook.fru.dev/regulations/us-nyc-ll144
URL:https://rulebook.fru.dev/regulations/us-nyc-ll144
CATEGORIES:New York City\, New York,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-108@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20230710
DTEND;VALUE=DATE:20230711
SUMMARY:EU-US Data Privacy Framework: DPF adequacy decision adopted and eff
 ective
DESCRIPTION:Commission adopted Implementing Decision (EU) 2023/1795\, effec
 tive on notification to Member States\; EU-US transfers to DPF-certified o
 rganisations may proceed without additional safeguards.\n\nCommission Impl
 ementing Decision (EU) 2023/1795 on the adequate level of protection of pe
 rsonal data under the EU-US Data Privacy Framework (European Union)\n\nSou
 rce: https://eur-lex.europa.eu/eli/dec_impl/2023/1795/oj\n\nhttps://rulebo
 ok.fru.dev/regulations/eu-us-dpf
URL:https://rulebook.fru.dev/regulations/eu-us-dpf
CATEGORIES:European Union,privacy,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-318@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20230723
DTEND;VALUE=DATE:20230724
SUMMARY:Washington My Health My Data Act: Geofencing ban (Section 10) effec
 tive
DESCRIPTION:Ban on geofencing around health care facilities applies to all 
 persons.\n\nWashington My Health My Data Act (HB 1155\, Laws of 2023\, ch.
  191\; RCW 19.373) (Washington)\n\nSource: https://www.atg.wa.gov/protecti
 ng-washingtonians-personal-health-data-and-privacy\n\nhttps://rulebook.fru
 .dev/regulations/us-wa-mhmda
URL:https://rulebook.fru.dev/regulations/us-wa-mhmda
CATEGORIES:Washington,health,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-25@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20230901
DTEND;VALUE=DATE:20230902
SUMMARY:Swiss revised FADP (nFADP): Revised FADP enters into force
DESCRIPTION:Revised FADP and Data Protection Ordinance apply with no transi
 tion period.\n\nFederal Act on Data Protection (revised FADP) of 25 Septem
 ber 2020 (Switzerland)\n\nSource: https://www.fedlex.admin.ch/eli/cc/2022/
 491/en\n\nhttps://rulebook.fru.dev/regulations/ch-fadp
URL:https://rulebook.fru.dev/regulations/ch-fadp
CATEGORIES:Switzerland,privacy,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-68@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20230906
DTEND;VALUE=DATE:20230907
SUMMARY:Digital Markets Act: First six gatekeepers designated
DESCRIPTION:Commission designated Alphabet\, Amazon\, Apple\, ByteDance\, M
 eta and Microsoft (22 core platform services). They had six months to full
 y comply.\n\nRegulation (EU) 2022/1925 on contestable and fair markets in 
 the digital sector (Digital Markets Act) (European Union)\n\nSource: https
 ://digital-markets-act.ec.europa.eu/gatekeepers_en\n\nhttps://rulebook.fru
 .dev/regulations/eu-dma
URL:https://rulebook.fru.dev/regulations/eu-dma
CATEGORIES:European Union,data-access,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-137@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20230914
DTEND;VALUE=DATE:20230915
SUMMARY:Saudi PDPL: PDPL in force
DESCRIPTION:PDPL and its implementing regulations take effect.\n\nPersonal 
 Data Protection Law (Royal Decree M/19 of 9/2/1443H\, as amended by Royal 
 Decree M/148 of 5/9/1444H) (Saudi Arabia)\n\nSource: https://sdaia.gov.sa/
 en/SDAIA/about/Documents/Personal%20Data%20English%20V2-23April2023-%20Rev
 iewed-.pdf\n\nhttps://rulebook.fru.dev/regulations/sa-pdpl
URL:https://rulebook.fru.dev/regulations/sa-pdpl
CATEGORIES:Saudi Arabia,privacy,data-residency,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-23@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20230922
DTEND;VALUE=DATE:20230923
SUMMARY:Quebec Law 25: Phase 2: main obligations and penalties
DESCRIPTION:Governance policies\, PIAs\, consent\, transparency\, privacy b
 y default\, ADM notices\, cross-border PIAs and AMP/penal regime apply.\n\
 nAct to modernize legislative provisions as regards the protection of pers
 onal information (Law 25\, formerly Bill 64) (Quebec\, Canada)\n\nSource: 
 https://www.legisquebec.gouv.qc.ca/en/document/cs/P-39.1\n\nhttps://rulebo
 ok.fru.dev/regulations/ca-qc-law25
URL:https://rulebook.fru.dev/regulations/ca-qc-law25
CATEGORIES:Quebec\, Canada,privacy,breach-notification,biometrics
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-64@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20230924
DTEND;VALUE=DATE:20230925
SUMMARY:Data Governance Act: DGA applies
DESCRIPTION:All DGA rules apply (Art 38).\n\nRegulation (EU) 2022/868 on Eu
 ropean data governance (Data Governance Act) (European Union)\n\nSource: h
 ttps://eur-lex.europa.eu/eli/reg/2022/868/oj\n\nhttps://rulebook.fru.dev/r
 egulations/eu-dga
URL:https://rulebook.fru.dev/regulations/eu-dga
CATEGORIES:European Union,data-access,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-156@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20231026
DTEND;VALUE=DATE:20231027
SUMMARY:UK Online Safety Act: Royal Assent
DESCRIPTION:The Online Safety Act receives Royal Assent.\n\nOnline Safety A
 ct 2023 (United Kingdom)\n\nSource: https://www.legislation.gov.uk/ukpga/2
 023/50/contents\n\nhttps://rulebook.fru.dev/regulations/uk-osa
URL:https://rulebook.fru.dev/regulations/uk-osa
CATEGORIES:United Kingdom,online-safety,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-270@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20231101
DTEND;VALUE=DATE:20231102
SUMMARY:NYDFS Cybersecurity Regulation (Part 500): Second Amendment effecti
 ve
DESCRIPTION:Second Amendment takes effect\; 500.19(e)-(h)\, 500.20\, 500.21
 \, 500.22 and 500.24 apply immediately.\n\nNew York DFS Cybersecurity Requ
 irements for Financial Services Companies (23 NYCRR Part 500)\, Second Ame
 ndment (New York)\n\nSource: https://www.dfs.ny.gov/cybersecurity/23-NYCRR
 -Part-500\n\nhttps://rulebook.fru.dev/regulations/us-ny-dfs-500
URL:https://rulebook.fru.dev/regulations/us-ny-dfs-500
CATEGORIES:New York,cybersecurity,breach-notification,financial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-271@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20231201
DTEND;VALUE=DATE:20231202
SUMMARY:NYDFS Cybersecurity Regulation (Part 500): Amended notification req
 uirements (500.17)
DESCRIPTION:New 72-hour event notice\, 24-hour extortion payment notice and
  certification changes apply (30 days).\n\nNew York DFS Cybersecurity Requ
 irements for Financial Services Companies (23 NYCRR Part 500)\, Second Ame
 ndment (New York)\n\nSource: https://www.dfs.ny.gov/cybersecurity/23-NYCRR
 -Part-500\n\nhttps://rulebook.fru.dev/regulations/us-ny-dfs-500
URL:https://rulebook.fru.dev/regulations/us-ny-dfs-500
CATEGORIES:New York,cybersecurity,breach-notification,financial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-290@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20231215
DTEND;VALUE=DATE:20231216
SUMMARY:SEC Cyber Disclosure Rules: Annual cybersecurity disclosures begin 
 (Item 106 / 16K)
DESCRIPTION:Required in annual reports for fiscal years ending on or after 
 this date.\n\nSEC Cybersecurity Risk Management\, Strategy\, Governance\, 
 and Incident Disclosure (Release No. 33-11216) (United States (Federal))\n
 \nSource: https://www.federalregister.gov/documents/2023/08/04/2023-16194/
 cybersecurity-risk-management-strategy-governance-and-incident-disclosure\
 n\nhttps://rulebook.fru.dev/regulations/us-sec-cyber
URL:https://rulebook.fru.dev/regulations/us-sec-cyber
CATEGORIES:United States (Federal),cybersecurity,breach-notification,financ
 ial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-291@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20231218
DTEND;VALUE=DATE:20231219
SUMMARY:SEC Cyber Disclosure Rules: Form 8-K Item 1.05 incident disclosure 
 begins
DESCRIPTION:All registrants other than smaller reporting companies must fil
 e material incident disclosures from this date.\n\nSEC Cybersecurity Risk 
 Management\, Strategy\, Governance\, and Incident Disclosure (Release No. 
 33-11216) (United States (Federal))\n\nSource: https://www.federalregister
 .gov/documents/2023/08/04/2023-16194/cybersecurity-risk-management-strateg
 y-governance-and-incident-disclosure\n\nhttps://rulebook.fru.dev/regulatio
 ns/us-sec-cyber
URL:https://rulebook.fru.dev/regulations/us-sec-cyber
CATEGORIES:United States (Federal),cybersecurity,breach-notification,financ
 ial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-308@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20231231
DTEND;VALUE=DATE:20240101
SUMMARY:Utah UCPA: UCPA takes effect
DESCRIPTION:Utah Consumer Privacy Act obligations and consumer rights apply
 .\n\nUtah Consumer Privacy Act (SB 227\, 2022) (Utah)\n\nSource: https://l
 e.utah.gov/xcode/Title13/Chapter61/13-61-S402.html\n\nhttps://rulebook.fru
 .dev/regulations/us-ut-ucpa
URL:https://rulebook.fru.dev/regulations/us-ut-ucpa
CATEGORIES:Utah,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-55@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20240111
DTEND;VALUE=DATE:20240112
SUMMARY:EU Data Act: Data Act enters into force
DESCRIPTION:Entered into force on the twentieth day after publication in th
 e OJ on 22 Dec 2023 (Art 50).\n\nRegulation (EU) 2023/2854 on harmonised r
 ules on fair access to and use of data (Data Act) (European Union)\n\nSour
 ce: https://eur-lex.europa.eu/eli/reg/2023/2854/oj\n\nhttps://rulebook.fru
 .dev/regulations/eu-data-act
URL:https://rulebook.fru.dev/regulations/eu-data-act
CATEGORIES:European Union,data-access,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-56@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20240111
DTEND;VALUE=DATE:20240112
SUMMARY:EU Data Act: Reduced switching charges period begins
DESCRIPTION:From 11 Jan 2024 to 12 Jan 2027\, data processing providers may
  charge only reduced switching fees\, capped at costs directly linked to s
 witching (Art 29(2)-(3)).\n\nRegulation (EU) 2023/2854 on harmonised rules
  on fair access to and use of data (Data Act) (European Union)\n\nSource: 
 https://eur-lex.europa.eu/eli/reg/2023/2854/oj\n\nhttps://rulebook.fru.dev
 /regulations/eu-data-act
URL:https://rulebook.fru.dev/regulations/eu-data-act
CATEGORIES:European Union,data-access,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-78@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20240217
DTEND;VALUE=DATE:20240218
SUMMARY:Digital Services Act: DSA applies to all intermediary services
DESCRIPTION:Full application to all providers of intermediary services (Art
  93(2)).\n\nRegulation (EU) 2022/2065 on a Single Market for Digital Servi
 ces (Digital Services Act) (European Union)\n\nSource: https://eur-lex.eur
 opa.eu/eli/reg/2022/2065/oj\n\nhttps://rulebook.fru.dev/regulations/eu-dsa
URL:https://rulebook.fru.dev/regulations/eu-dsa
CATEGORIES:European Union,online-safety,children,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-69@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20240307
DTEND;VALUE=DATE:20240308
SUMMARY:Digital Markets Act: Gatekeeper compliance deadline (first designat
 ions)
DESCRIPTION:First-wave gatekeepers had to comply with Arts 5-7 obligations 
 and submit compliance reports six months after the 6 Sep 2023 designation.
 \n\nRegulation (EU) 2022/1925 on contestable and fair markets in the digit
 al sector (Digital Markets Act) (European Union)\n\nSource: https://ec.eur
 opa.eu/commission/presscorner/detail/en/ip_23_4328\n\nhttps://rulebook.fru
 .dev/regulations/eu-dma
URL:https://rulebook.fru.dev/regulations/eu-dma
CATEGORIES:European Union,data-access,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-229@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20240313
DTEND;VALUE=DATE:20240314
SUMMARY:FCC CPNI Breach Rule: Order effective except revised notification r
 ules
DESCRIPTION:Definitions and other parts of the order took effect\; the revi
 sed 64.2011 and 64.5111 notification requirements were delayed pending OMB
  approval.\n\nFCC Data Breach Reporting Requirements for telecommunication
 s carriers\, interconnected VoIP and TRS providers (47 CFR 64.2011\, 64.51
 11) (United States (Federal))\n\nSource: https://www.federalregister.gov/d
 ocuments/2024/02/12/2024-01667/data-breach-reporting-requirements\n\nhttps
 ://rulebook.fru.dev/regulations/us-fcc-cpni-breach
URL:https://rulebook.fru.dev/regulations/us-fcc-cpni-breach
CATEGORIES:United States (Federal),privacy,breach-notification,cybersecurit
 y
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-30@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20240322
DTEND;VALUE=DATE:20240323
SUMMARY:China Cross-Border Data Flow Provisions: Cross-border data flow pro
 visions take effect
DESCRIPTION:Exemptions and volume thresholds apply from publication (Art. 1
 4)\; security assessment results are valid for 3 years (Art. 9).\n\nProvis
 ions on Promoting and Regulating Cross-Border Data Flows (CAC Order No. 16
 ) (China)\n\nSource: https://www.cac.gov.cn/2024-03/22/c_1712776611775634.
 htm\n\nhttps://rulebook.fru.dev/regulations/cn-cross-border
URL:https://rulebook.fru.dev/regulations/cn-cross-border
CATEGORIES:China,data-residency,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-319@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20240331
DTEND;VALUE=DATE:20240401
SUMMARY:Washington My Health My Data Act: Regulated entities must comply
DESCRIPTION:Sections 4-9 (privacy policy\, consent\, consumer rights\, sale
  authorization) apply to regulated entities.\n\nWashington My Health My Da
 ta Act (HB 1155\, Laws of 2023\, ch. 191\; RCW 19.373) (Washington)\n\nSou
 rce: https://www.atg.wa.gov/protecting-washingtonians-personal-health-data
 -and-privacy\n\nhttps://rulebook.fru.dev/regulations/us-wa-mhmda
URL:https://rulebook.fru.dev/regulations/us-wa-mhmda
CATEGORIES:Washington,health,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-272@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20240415
DTEND;VALUE=DATE:20240416
SUMMARY:NYDFS Cybersecurity Regulation (Part 500): Annual compliance notifi
 cation
DESCRIPTION:Certification of compliance or acknowledgment of non-compliance
  due (recurs every April 15).\n\nNew York DFS Cybersecurity Requirements f
 or Financial Services Companies (23 NYCRR Part 500)\, Second Amendment (Ne
 w York)\n\nSource: https://www.dfs.ny.gov/cybersecurity/23-NYCRR-Part-500\
 n\nhttps://rulebook.fru.dev/regulations/us-ny-dfs-500
URL:https://rulebook.fru.dev/regulations/us-ny-dfs-500
CATEGORIES:New York,cybersecurity,breach-notification,financial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-273@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20240429
DTEND;VALUE=DATE:20240430
SUMMARY:NYDFS Cybersecurity Regulation (Part 500): General 180-day transiti
 on ends
DESCRIPTION:Most new Second Amendment requirements apply\, e.g. annual repo
 rting to the board and risk assessment updates.\n\nNew York DFS Cybersecur
 ity Requirements for Financial Services Companies (23 NYCRR Part 500)\, Se
 cond Amendment (New York)\n\nSource: https://www.dfs.ny.gov/cybersecurity/
 23-NYCRR-Part-500\n\nhttps://rulebook.fru.dev/regulations/us-ny-dfs-500
URL:https://rulebook.fru.dev/regulations/us-ny-dfs-500
CATEGORIES:New York,cybersecurity,breach-notification,financial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-305@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20240501
DTEND;VALUE=DATE:20240502
SUMMARY:Utah AI Policy Act: AI Policy Act effective
DESCRIPTION:Generative AI disclosure duties and the Office of AI Policy tak
 e effect.\n\nUtah Artificial Intelligence Policy Act (SB 149\, 2024)\, as 
 amended by SB 226 and SB 332 (2025) (Utah)\n\nSource: https://le.utah.gov/
 ~2024/bills/static/SB0149.html\n\nhttps://rulebook.fru.dev/regulations/us-
 ut-aipa
URL:https://rulebook.fru.dev/regulations/us-ut-aipa
CATEGORIES:Utah,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-235@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20240513
DTEND;VALUE=DATE:20240514
SUMMARY:GLBA Safeguards Rule: FTC breach notification requirement effective
DESCRIPTION:Section 314.4(j) requires notice to the FTC within 30 days of d
 iscovering a notification event involving at least 500 consumers.\n\nFTC S
 tandards for Safeguarding Customer Information (Safeguards Rule)\, 16 CFR 
 Part 314\, under the Gramm-Leach-Bliley Act (United States (Federal))\n\nS
 ource: https://www.federalregister.gov/documents/2023/11/13/2023-24412/sta
 ndards-for-safeguarding-customer-information\n\nhttps://rulebook.fru.dev/r
 egulations/us-glba-safeguards
URL:https://rulebook.fru.dev/regulations/us-glba-safeguards
CATEGORIES:United States (Federal),financial,cybersecurity,breach-notificat
 ion,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-199@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20240517
DTEND;VALUE=DATE:20240518
SUMMARY:Colorado AI Act: SB 24-205 signed
DESCRIPTION:Governor Polis signs the original Colorado AI Act with a Februa
 ry 1\, 2026 effective date.\n\nColorado SB 24-205 (Consumer Protections fo
 r Artificial Intelligence)\, as delayed by SB 25B-004 and repealed and ree
 nacted by SB 26-189 (Automated Decision-Making Technology) (Colorado)\n\nS
 ource: https://leg.colorado.gov/bills/sb24-205\n\nhttps://rulebook.fru.dev
 /regulations/us-co-ai-act
URL:https://rulebook.fru.dev/regulations/us-co-ai-act
CATEGORIES:Colorado,ai,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-85@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20240520
DTEND;VALUE=DATE:20240521
SUMMARY:eIDAS 2 / EU Digital Identity Wallet: eIDAS 2 enters into force
DESCRIPTION:Regulation (EU) 2024/1183 entered into force on the twentieth d
 ay after publication on 30 Apr 2024 (Art 2).\n\nRegulation (EU) 2024/1183 
 amending Regulation (EU) No 910/2014 as regards establishing the European 
 Digital Identity Framework (eIDAS 2) (European Union)\n\nSource: https://e
 ur-lex.europa.eu/eli/reg/2024/1183/oj\n\nhttps://rulebook.fru.dev/regulati
 ons/eu-eidas2
URL:https://rulebook.fru.dev/regulations/eu-eidas2
CATEGORIES:European Union,privacy,data-access,biometrics
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-143@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20240601
DTEND;VALUE=DATE:20240602
SUMMARY:Turkey KVKK: Law 7499 amendments take effect
DESCRIPTION:New sensitive data and cross-border transfer rules (Arts. 6 and
  9) apply.\n\nLaw No. 6698 on the Protection of Personal Data (KVKK)\, as 
 amended by Law No. 7499 (Turkey)\n\nSource: https://www.resmigazete.gov.tr
 /eskiler/2024/03/20240312-1.htm\n\nhttps://rulebook.fru.dev/regulations/tr
 -kvkk
URL:https://rulebook.fru.dev/regulations/tr-kvkk
CATEGORIES:Turkey,privacy,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-292@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20240615
DTEND;VALUE=DATE:20240616
SUMMARY:SEC Cyber Disclosure Rules: Smaller reporting companies: Item 1.05 
 compliance
DESCRIPTION:Smaller reporting companies must begin complying with Form 8-K 
 Item 1.05 incident disclosure.\n\nSEC Cybersecurity Risk Management\, Stra
 tegy\, Governance\, and Incident Disclosure (Release No. 33-11216) (United
  States (Federal))\n\nSource: https://www.federalregister.gov/documents/20
 23/08/04/2023-16194/cybersecurity-risk-management-strategy-governance-and-
 incident-disclosure\n\nhttps://rulebook.fru.dev/regulations/us-sec-cyber
URL:https://rulebook.fru.dev/regulations/us-sec-cyber
CATEGORIES:United States (Federal),cybersecurity,breach-notification,financ
 ial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-288@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20240623
DTEND;VALUE=DATE:20240624
SUMMARY:PADFA: PADFA takes effect
DESCRIPTION:The prohibition takes effect 60 days after enactment (April 24\
 , 2024).\n\nProtecting Americans' Data from Foreign Adversaries Act of 202
 4 (United States (Federal))\n\nSource: https://www.govinfo.gov/content/pkg
 /PLAW-118publ50/html/PLAW-118publ50.htm\n\nhttps://rulebook.fru.dev/regula
 tions/us-padfa
URL:https://rulebook.fru.dev/regulations/us-padfa
CATEGORIES:United States (Federal),privacy,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-236@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20240625
DTEND;VALUE=DATE:20240626
SUMMARY:HIPAA: Reproductive health care privacy rule effective (later vacat
 ed)
DESCRIPTION:The HIPAA Privacy Rule to Support Reproductive Health Care Priv
 acy (89 FR 32976) took effect\; it was vacated nationwide on June 18\, 202
 5 in Purl v. HHS (N.D. Tex.).\n\nHIPAA Privacy\, Security and Breach Notif
 ication Rules (45 CFR Parts 160 and 164) (United States (Federal))\n\nSour
 ce: https://www.federalregister.gov/documents/2024/04/26/2024-08503/hipaa-
 privacy-rule-to-support-reproductive-health-care-privacy\n\nhttps://rulebo
 ok.fru.dev/regulations/us-hipaa
URL:https://rulebook.fru.dev/regulations/us-hipaa
CATEGORIES:United States (Federal),privacy,health,cybersecurity,breach-noti
 fication
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-320@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20240630
DTEND;VALUE=DATE:20240701
SUMMARY:Washington My Health My Data Act: Small businesses must comply
DESCRIPTION:Sections 4-9 apply to small businesses.\n\nWashington My Health
  My Data Act (HB 1155\, Laws of 2023\, ch. 191\; RCW 19.373) (Washington)\
 n\nSource: https://www.atg.wa.gov/protecting-washingtonians-personal-healt
 h-data-and-privacy\n\nhttps://rulebook.fru.dev/regulations/us-wa-mhmda
URL:https://rulebook.fru.dev/regulations/us-wa-mhmda
CATEGORIES:Washington,health,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-208@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20240701
DTEND;VALUE=DATE:20240702
SUMMARY:Colorado Privacy Act (CPA): Universal opt-out mechanism recognition
  required
DESCRIPTION:Controllers must honor AG-recognized universal opt-out mechanis
 ms (e.g. Global Privacy Control).\n\nColorado Privacy Act (SB 21-190)\, C.
 R.S. 6-1-1301 et seq.\, as amended by HB 24-1130\, SB 24-041 and SB 25-276
  (Colorado)\n\nSource: https://leg.colorado.gov/bills/sb21-190\n\nhttps://
 rulebook.fru.dev/regulations/us-co-cpa
URL:https://rulebook.fru.dev/regulations/us-co-cpa
CATEGORIES:Colorado,privacy,children,biometrics
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-230@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20240701
DTEND;VALUE=DATE:20240702
SUMMARY:Florida Digital Bill of Rights: Florida Digital Bill of Rights take
 s effect
DESCRIPTION:SB 262 obligations under Fla. Stat. 501.701-501.722 apply.\n\nF
 lorida Digital Bill of Rights (CS/CS/SB 262\, 2023) (Florida)\n\nSource: h
 ttps://www.flsenate.gov/Session/Bill/2023/262\n\nhttps://rulebook.fru.dev/
 regulations/us-fl-fdbr
URL:https://rulebook.fru.dev/regulations/us-fl-fdbr
CATEGORIES:Florida,privacy,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-283@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20240701
DTEND;VALUE=DATE:20240702
SUMMARY:Oregon OCPA: OCPA takes effect for most controllers
DESCRIPTION:OCPA obligations apply to for-profit controllers meeting the th
 resholds.\n\nOregon Consumer Privacy Act (SB 619\, 2023) (Oregon)\n\nSourc
 e: https://www.doj.state.or.us/consumer-protection/id-theft-data-breaches/
 privacy/\n\nhttps://rulebook.fru.dev/regulations/us-or-ocpa
URL:https://rulebook.fru.dev/regulations/us-or-ocpa
CATEGORIES:Oregon,privacy,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-301@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20240701
DTEND;VALUE=DATE:20240702
SUMMARY:Texas TDPSA: TDPSA takes effect
DESCRIPTION:Most TDPSA obligations and consumer rights apply.\n\nTexas Data
  Privacy and Security Act (HB 4\, 2023) (Texas)\n\nSource: https://capitol
 .texas.gov/BillLookup/History.aspx?LegSess=88R&Bill=HB4\n\nhttps://ruleboo
 k.fru.dev/regulations/us-tx-tdpsa
URL:https://rulebook.fru.dev/regulations/us-tx-tdpsa
CATEGORIES:Texas,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-193@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20240703
DTEND;VALUE=DATE:20240704
SUMMARY:CIRCIA: NPRM comment period closed
DESCRIPTION:Extended comment period on the CIRCIA proposed rule closed.\n\n
 Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA) 
 and proposed implementing rule (6 CFR Part 226) (United States (Federal))\
 n\nSource: https://www.federalregister.gov/documents/2024/04/04/2024-06526
 /cyber-incident-reporting-for-critical-infrastructure-act-circia-reporting
 -requirements\n\nhttps://rulebook.fru.dev/regulations/us-circia
URL:https://rulebook.fru.dev/regulations/us-circia
CATEGORIES:United States (Federal),cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-232@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20240729
DTEND;VALUE=DATE:20240730
SUMMARY:FTC Health Breach Notification Rule: 2024 amendments effective
DESCRIPTION:Amendments clarifying health app coverage\, unauthorized disclo
 sure as breach\, email notice and FTC notice timing took effect.\n\nFTC He
 alth Breach Notification Rule (16 CFR Part 318)\, as amended 2024 (United 
 States (Federal))\n\nSource: https://www.federalregister.gov/documents/202
 4/05/30/2024-10855/health-breach-notification-rule\n\nhttps://rulebook.fru
 .dev/regulations/us-ftc-hbnr
URL:https://rulebook.fru.dev/regulations/us-ftc-hbnr
CATEGORIES:United States (Federal),health,privacy,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-37@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20240801
DTEND;VALUE=DATE:20240802
SUMMARY:EU AI Act: AI Act enters into force
DESCRIPTION:Regulation (EU) 2024/1689 enters into force twenty days after p
 ublication on 12 July 2024 (Art 113).\n\nRegulation (EU) 2024/1689 laying 
 down harmonised rules on artificial intelligence (Artificial Intelligence 
 Act)\, as amended by Regulation (EU) 2026/1744 (Digital Omnibus on AI) (Eu
 ropean Union)\n\nSource: https://eur-lex.europa.eu/eli/reg/2024/1689/oj\n\
 nhttps://rulebook.fru.dev/regulations/eu-ai-act
URL:https://rulebook.fru.dev/regulations/eu-ai-act
CATEGORIES:European Union,ai,biometrics,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-242@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20240802
DTEND;VALUE=DATE:20240803
SUMMARY:Illinois BIPA: SB 2979 amendment effective
DESCRIPTION:Public Act 103-0769 signed and effective immediately: single re
 covery per person and electronic signatures allowed for consent.\n\nIllino
 is Biometric Information Privacy Act (740 ILCS 14)\, as amended by SB 2979
  (Public Act 103-0769) (Illinois)\n\nSource: https://www.ilga.gov/Legislat
 ion/publicacts/view/103-0769\n\nhttps://rulebook.fru.dev/regulations/us-il
 -bipa
URL:https://rulebook.fru.dev/regulations/us-il-bipa
CATEGORIES:Illinois,biometrics,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-295@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20240802
DTEND;VALUE=DATE:20240803
SUMMARY:SEC Regulation S-P: Amendments effective
DESCRIPTION:The Regulation S-P amendments became effective\; compliance tie
 red by entity size.\n\nRegulation S-P: Privacy of Consumer Financial Infor
 mation and Safeguarding Customer Information (2024 amendments) (United Sta
 tes (Federal))\n\nSource: https://www.federalregister.gov/documents/2024/0
 6/03/2024-11116/regulation-s-p-privacy-of-consumer-financial-information-a
 nd-safeguarding-customer-information\n\nhttps://rulebook.fru.dev/regulatio
 ns/us-sec-reg-sp
URL:https://rulebook.fru.dev/regulations/us-sec-reg-sp
CATEGORIES:United States (Federal),financial,privacy,cybersecurity,breach-n
 otification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-244@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20240809
DTEND;VALUE=DATE:20240810
SUMMARY:Illinois AI in Employment Law (HB 3773): HB 3773 signed
DESCRIPTION:Governor Pritzker signs Public Act 103-0804.\n\nIllinois HB 377
 3 (Public Act 103-0804)\, amending the Illinois Human Rights Act on artifi
 cial intelligence in employment (Illinois)\n\nSource: https://www.ilga.gov
 /ftp/legislation/103/BillStatus/HTML/10300HB3773.html\n\nhttps://rulebook.
 fru.dev/regulations/us-il-hb3773
URL:https://rulebook.fru.dev/regulations/us-il-hb3773
CATEGORIES:Illinois,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-13@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20240823
DTEND;VALUE=DATE:20240824
SUMMARY:Brazil LGPD: International transfer regulation published
DESCRIPTION:Resolution CD/ANPD 19/2024 on international transfers and stand
 ard contractual clauses published and in force.\n\nLei Geral de Proteção
  de Dados Pessoais (Law No. 13.709/2018) (Brazil)\n\nSource: https://www.i
 n.gov.br/en/web/dou/-/resolucao-cd/anpd-n-19-de-23-de-agosto-de-2024-58009
 5396\n\nhttps://rulebook.fru.dev/regulations/br-lgpd
URL:https://rulebook.fru.dev/regulations/br-lgpd
CATEGORIES:Brazil,privacy,breach-notification,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-144@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20240901
DTEND;VALUE=DATE:20240902
SUMMARY:Turkey KVKK: Old transfer regime ends
DESCRIPTION:Transitional period ends in which the former Article 9 explicit
 -consent transfer basis could still be relied on.\n\nLaw No. 6698 on the P
 rotection of Personal Data (KVKK)\, as amended by Law No. 7499 (Turkey)\n\
 nSource: https://www.resmigazete.gov.tr/eskiler/2024/03/20240312-1.htm\n\n
 https://rulebook.fru.dev/regulations/tr-kvkk
URL:https://rulebook.fru.dev/regulations/tr-kvkk
CATEGORIES:Turkey,privacy,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-138@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20240914
DTEND;VALUE=DATE:20240915
SUMMARY:Saudi PDPL: One-year grace period ends
DESCRIPTION:Grace period for controllers to comply ends\; PDPL fully enforc
 eable.\n\nPersonal Data Protection Law (Royal Decree M/19 of 9/2/1443H\, a
 s amended by Royal Decree M/148 of 5/9/1444H) (Saudi Arabia)\n\nSource: ht
 tps://sdaia.gov.sa/en/SDAIA/about/Documents/Personal%20Data%20English%20V2
 -23April2023-%20Reviewed-.pdf\n\nhttps://rulebook.fru.dev/regulations/sa-p
 dpl
URL:https://rulebook.fru.dev/regulations/sa-pdpl
CATEGORIES:Saudi Arabia,privacy,data-residency,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-187@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20240919
DTEND;VALUE=DATE:20240920
SUMMARY:California AI Transparency Act (SB 942): SB 942 signed
DESCRIPTION:SB 942 chaptered (ch. 291) with an original operative date of J
 anuary 1\, 2026.\n\nCalifornia AI Transparency Act (SB 942\, Stats. 2024\,
  ch. 291)\, as amended by AB 853 (Stats. 2025\, ch. 674) (California)\n\nS
 ource: https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_i
 d=202320240SB942\n\nhttps://rulebook.fru.dev/regulations/us-ca-sb942
URL:https://rulebook.fru.dev/regulations/us-ca-sb942
CATEGORIES:California,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-24@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20240922
DTEND;VALUE=DATE:20240923
SUMMARY:Quebec Law 25: Phase 3: data portability
DESCRIPTION:Right to data portability in a structured\, commonly used techn
 ological format applies.\n\nAct to modernize legislative provisions as reg
 ards the protection of personal information (Law 25\, formerly Bill 64) (Q
 uebec\, Canada)\n\nSource: https://www.legisquebec.gouv.qc.ca/en/document/
 cs/P-39.1\n\nhttps://rulebook.fru.dev/regulations/ca-qc-law25
URL:https://rulebook.fru.dev/regulations/ca-qc-law25
CATEGORIES:Quebec\, Canada,privacy,breach-notification,biometrics
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-162@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20240928
DTEND;VALUE=DATE:20240929
SUMMARY:California AB 2013 (AI training data transparency): AB 2013 signed
DESCRIPTION:AB 2013 chaptered (ch. 817).\n\nCalifornia AB 2013\, Generative
  Artificial Intelligence: Training Data Transparency (Stats. 2024\, ch. 81
 7) (California)\n\nSource: https://leginfo.legislature.ca.gov/faces/billNa
 vClient.xhtml?bill_id=202320240AB2013\n\nhttps://rulebook.fru.dev/regulati
 ons/us-ca-ab2013
URL:https://rulebook.fru.dev/regulations/us-ca-ab2013
CATEGORIES:California,ai,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-258@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20241001
DTEND;VALUE=DATE:20241002
SUMMARY:Montana Consumer Data Privacy Act (MCDPA): MCDPA takes effect
DESCRIPTION:Consumer rights\, controller duties and opt-out preference sign
 al support apply.\n\nMontana Consumer Data Privacy Act (SB 384\, 2023)\, M
 ont. Code Ann. 30-14-2801 et seq.\, as amended by SB 297 (2025) (Montana)\
 n\nSource: https://archive.legmt.gov/bills/mca/title_0300/chapter_0140/par
 t_0280/section_0030/0300-0140-0280-0030.html\n\nhttps://rulebook.fru.dev/r
 egulations/us-mt-mcdpa
URL:https://rulebook.fru.dev/regulations/us-mt-mcdpa
CATEGORIES:Montana,privacy,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-113@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20241017
DTEND;VALUE=DATE:20241018
SUMMARY:Indonesia PDP Law: PDP Law transition ends
DESCRIPTION:Controllers and processors must fully comply (Art. 74 two-year 
 transition).\n\nLaw No. 27 of 2022 on Personal Data Protection (Undang-Und
 ang Pelindungan Data Pribadi) (Indonesia)\n\nSource: https://peraturan.bpk
 .go.id/Details/229798/uu-no-27-tahun-2022\n\nhttps://rulebook.fru.dev/regu
 lations/id-pdp
URL:https://rulebook.fru.dev/regulations/id-pdp
CATEGORIES:Indonesia,privacy,breach-notification,data-residency,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-99@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20241017
DTEND;VALUE=DATE:20241018
SUMMARY:NIS2: Transposition deadline
DESCRIPTION:Member States had to adopt and publish national transposing mea
 sures by 17 Oct 2024 (Art 41(1)).\n\nDirective (EU) 2022/2555 on measures 
 for a high common level of cybersecurity across the Union (NIS2 Directive)
  (European Union)\n\nSource: https://eur-lex.europa.eu/eli/dir/2022/2555/o
 j\n\nhttps://rulebook.fru.dev/regulations/eu-nis2
URL:https://rulebook.fru.dev/regulations/eu-nis2
CATEGORIES:European Union,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-100@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20241018
DTEND;VALUE=DATE:20241019
SUMMARY:NIS2: National NIS2 measures apply\; NIS1 repealed
DESCRIPTION:Member States apply their NIS2 measures from 18 Oct 2024 and Di
 rective (EU) 2016/1148 (NIS1) is repealed (Arts 41(1)\, 44).\n\nDirective 
 (EU) 2022/2555 on measures for a high common level of cybersecurity across
  the Union (NIS2 Directive) (European Union)\n\nSource: https://eur-lex.eu
 ropa.eu/eli/dir/2022/2555/oj\n\nhttps://rulebook.fru.dev/regulations/eu-ni
 s2
URL:https://rulebook.fru.dev/regulations/eu-nis2
CATEGORIES:European Union,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-274@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20241101
DTEND;VALUE=DATE:20241102
SUMMARY:NYDFS Cybersecurity Regulation (Part 500): Governance\, encryption\
 , IR/BCDR\, exemptions
DESCRIPTION:500.4 governance\, 500.15 encryption\, 500.16 incident response
  and business continuity plans\, and 500.19(a) revised exemptions apply.\n
 \nNew York DFS Cybersecurity Requirements for Financial Services Companies
  (23 NYCRR Part 500)\, Second Amendment (New York)\n\nSource: https://www.
 dfs.ny.gov/cybersecurity/23-NYCRR-Part-500\n\nhttps://rulebook.fru.dev/reg
 ulations/us-ny-dfs-500
URL:https://rulebook.fru.dev/regulations/us-ny-dfs-500
CATEGORIES:New York,cybersecurity,breach-notification,financial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-101@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20241107
DTEND;VALUE=DATE:20241108
SUMMARY:NIS2: Implementing Regulation 2024/2690 enters into force
DESCRIPTION:Commission Implementing Regulation (EU) 2024/2690 (published 18
  Oct 2024) sets technical risk-management measures and significant-inciden
 t thresholds for DNS\, TLD\, cloud\, data centre\, CDN\, managed (security
 ) service providers\, online marketplaces\, search engines\, social networ
 ks and trust service providers.\n\nDirective (EU) 2022/2555 on measures fo
 r a high common level of cybersecurity across the Union (NIS2 Directive) (
 European Union)\n\nSource: https://eur-lex.europa.eu/eli/reg_impl/2024/269
 0/oj\n\nhttps://rulebook.fru.dev/regulations/eu-nis2
URL:https://rulebook.fru.dev/regulations/eu-nis2
CATEGORIES:European Union,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-106@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20241208
DTEND;VALUE=DATE:20241209
SUMMARY:Product Liability Directive: New PLD enters into force
DESCRIPTION:Directive entered into force on the twentieth day after publica
 tion in the OJ on 18 Nov 2024 (Art 23).\n\nDirective (EU) 2024/2853 on lia
 bility for defective products (new Product Liability Directive) (European 
 Union)\n\nSource: https://eur-lex.europa.eu/eli/dir/2024/2853/oj\n\nhttps:
 //rulebook.fru.dev/regulations/eu-pld
URL:https://rulebook.fru.dev/regulations/eu-pld
CATEGORIES:European Union,ai,cybersecurity
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-9@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20241210
DTEND;VALUE=DATE:20241211
SUMMARY:Brazil AI Bill (PL 2338/2023): Approved by the Federal Senate
DESCRIPTION:Senate approves the consolidated text and sends it to the Chamb
 er of Deputies.\n\nProjeto de Lei nº 2338/2023 (Brazilian AI Legal Framew
 ork) (Brazil)\n\nSource: https://www25.senado.leg.br/web/atividade/materia
 s/-/materia/157233\n\nhttps://rulebook.fru.dev/regulations/br-ai-bill
URL:https://rulebook.fru.dev/regulations/br-ai-bill
CATEGORIES:Brazil,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-48@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20241210
DTEND;VALUE=DATE:20241211
SUMMARY:Cyber Resilience Act: CRA enters into force
DESCRIPTION:Entered into force on the twentieth day after publication in th
 e OJ on 20 Nov 2024 (Art 71(1)).\n\nRegulation (EU) 2024/2847 on horizonta
 l cybersecurity requirements for products with digital elements (Cyber Res
 ilience Act) (European Union)\n\nSource: https://eur-lex.europa.eu/eli/reg
 /2024/2847/oj\n\nhttps://rulebook.fru.dev/regulations/eu-cra
URL:https://rulebook.fru.dev/regulations/eu-cra
CATEGORIES:European Union,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-4@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20241211
DTEND;VALUE=DATE:20241212
SUMMARY:Australia Privacy Act: Most POLA Act 2024 amendments commence
DESCRIPTION:Tiered penalties\, infringement notices\, OAIC powers\, securit
 y and overseas-transfer clarifications and doxxing offences commence the d
 ay after Royal Assent.\n\nPrivacy Act 1988 (Cth)\, as amended by the Priva
 cy and Other Legislation Amendment Act 2024 (Australia)\n\nSource: https:/
 /www.legislation.gov.au/C2024A00128/asmade\n\nhttps://rulebook.fru.dev/reg
 ulations/au-privacy-act
URL:https://rulebook.fru.dev/regulations/au-privacy-act
CATEGORIES:Australia,privacy,children,breach-notification,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-26@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20241213
DTEND;VALUE=DATE:20241214
SUMMARY:Chile Personal Data Protection Law (Ley 21.719): Published in Diari
 o Oficial
DESCRIPTION:Law 21.719 published\; 24-month vacatio legis begins.\n\nLey N
 º 21.719 que regula la protección y el tratamiento de los datos personal
 es y crea la Agencia de Protección de Datos Personales (Chile)\n\nSource:
  https://www.bcn.cl/leychile/navegar?idNorma=1209272\n\nhttps://rulebook.f
 ru.dev/regulations/cl-pdpl
URL:https://rulebook.fru.dev/regulations/cl-pdpl
CATEGORIES:Chile,privacy,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-293@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20241215
DTEND;VALUE=DATE:20241216
SUMMARY:SEC Cyber Disclosure Rules: Inline XBRL tagging of annual cybersecu
 rity disclosures
DESCRIPTION:Item 106 / Item 16K disclosures must be tagged in Inline XBRL f
 or fiscal years ending on or after this date.\n\nSEC Cybersecurity Risk Ma
 nagement\, Strategy\, Governance\, and Incident Disclosure (Release No. 33
 -11216) (United States (Federal))\n\nSource: https://www.federalregister.g
 ov/documents/2023/08/04/2023-16194/cybersecurity-risk-management-strategy-
 governance-and-incident-disclosure\n\nhttps://rulebook.fru.dev/regulations
 /us-sec-cyber
URL:https://rulebook.fru.dev/regulations/us-sec-cyber
CATEGORIES:United States (Federal),cybersecurity,breach-notification,financ
 ial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-194@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20241216
DTEND;VALUE=DATE:20241217
SUMMARY:CMMC 2.0: CMMC Program rule (32 CFR Part 170) effective
DESCRIPTION:The program rule establishing CMMC levels and assessment proces
 ses took effect\; contract enforcement awaited the DFARS rule.\n\nCybersec
 urity Maturity Model Certification (CMMC) Program (32 CFR Part 170) and DF
 ARS acquisition rule (48 CFR Parts 204\, 212\, 217\, 252) (United States (
 Federal))\n\nSource: https://www.federalregister.gov/documents/2024/10/15/
 2024-22905/cybersecurity-maturity-model-certification-cmmc-program\n\nhttp
 s://rulebook.fru.dev/regulations/us-cmmc
URL:https://rulebook.fru.dev/regulations/us-cmmc
CATEGORIES:United States (Federal),cybersecurity
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-294@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20241218
DTEND;VALUE=DATE:20241219
SUMMARY:SEC Cyber Disclosure Rules: Inline XBRL tagging of Item 1.05 disclo
 sures
DESCRIPTION:Form 8-K Item 1.05 and Form 6-K incident disclosures must be ta
 gged in Inline XBRL.\n\nSEC Cybersecurity Risk Management\, Strategy\, Gov
 ernance\, and Incident Disclosure (Release No. 33-11216) (United States (F
 ederal))\n\nSource: https://www.federalregister.gov/documents/2023/08/04/2
 023-16194/cybersecurity-risk-management-strategy-governance-and-incident-d
 isclosure\n\nhttps://rulebook.fru.dev/regulations/us-sec-cyber
URL:https://rulebook.fru.dev/regulations/us-sec-cyber
CATEGORIES:United States (Federal),cybersecurity,breach-notification,financ
 ial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-237@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20241223
DTEND;VALUE=DATE:20241224
SUMMARY:HIPAA: Reproductive health privacy compliance date (vacated)
DESCRIPTION:Original compliance date for the reproductive health care priva
 cy provisions\, including the attestation requirement\; these provisions n
 o longer apply after the June 2025 vacatur.\n\nHIPAA Privacy\, Security an
 d Breach Notification Rules (45 CFR Parts 160 and 164) (United States (Fed
 eral))\n\nSource: https://www.federalregister.gov/documents/2024/04/26/202
 4-08503/hipaa-privacy-rule-to-support-reproductive-health-care-privacy\n\n
 https://rulebook.fru.dev/regulations/us-hipaa
URL:https://rulebook.fru.dev/regulations/us-hipaa
CATEGORIES:United States (Federal),privacy,health,cybersecurity,breach-noti
 fication
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-86@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20241224
DTEND;VALUE=DATE:20241225
SUMMARY:eIDAS 2 / EU Digital Identity Wallet: First wallet implementing act
 s enter into force
DESCRIPTION:Commission Implementing Regulations (EU) 2024/2977\, 2024/2979\
 , 2024/2980\, 2024/2981 and 2024/2982 (adopted 28 Nov 2024\, published 4 D
 ec 2024) enter into force. This starts the wallet deadline clocks in Arts 
 5a and 5f.\n\nRegulation (EU) 2024/1183 amending Regulation (EU) No 910/20
 14 as regards establishing the European Digital Identity Framework (eIDAS 
 2) (European Union)\n\nSource: https://eur-lex.europa.eu/eli/reg_impl/2024
 /2977/oj\n\nhttps://rulebook.fru.dev/regulations/eu-eidas2
URL:https://rulebook.fru.dev/regulations/eu-eidas2
CATEGORIES:European Union,privacy,data-access,biometrics
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-216@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20241231
DTEND;VALUE=DATE:20250101
SUMMARY:Connecticut Data Privacy Act (CTDPA): Mandatory 60-day cure period 
 expires
DESCRIPTION:After Dec 31\, 2024\, the AG is no longer required to offer a 6
 0-day cure before enforcement\; cure becomes discretionary.\n\nConnecticut
  Data Privacy Act (Public Act 22-15)\, Conn. Gen. Stat. 42-515 et seq.\, a
 s amended by Public Act 25-113 (SB 1295) and Public Act 26-64 (SB 4) (Conn
 ecticut)\n\nSource: https://www.cga.ct.gov/asp/cgabillstatus/cgabillstatus
 .asp?selBillType=Bill&which_year=2022&bill_num=6\n\nhttps://rulebook.fru.d
 ev/regulations/us-ct-ctdpa
URL:https://rulebook.fru.dev/regulations/us-ct-ctdpa
CATEGORIES:Connecticut,privacy,children,ai,health
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-166@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20250101
DTEND;VALUE=DATE:20250102
SUMMARY:CCPA / CPRA: CPI adjustment of thresholds and fines
DESCRIPTION:Revenue threshold rises to $26\,625\,000 and fines to $2\,663 /
  $7\,988 per violation.\n\nCalifornia Consumer Privacy Act of 2018\, as am
 ended by the California Privacy Rights Act of 2020 (Cal. Civ. Code 1798.10
 0 et seq.) and CPPA regulations (Cal. Code Regs. tit. 11\, 7000 et seq.) (
 California)\n\nSource: https://cppa.ca.gov/regulations/cpi_adjustment.html
 \n\nhttps://rulebook.fru.dev/regulations/us-ca-ccpa
URL:https://rulebook.fru.dev/regulations/us-ca-ccpa
CATEGORIES:California,privacy,ai,cybersecurity,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-34@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20250101
DTEND;VALUE=DATE:20250102
SUMMARY:China Network Data Security Regulations: Network Data Regulations t
 ake effect
DESCRIPTION:All provisions\, including the 10-million-person threshold duti
 es and annual important-data risk assessments\, apply.\n\nRegulations on N
 etwork Data Security Management (State Council Order No. 790) (China)\n\nS
 ource: https://www.gov.cn/zhengce/content/202409/content_6977766.htm\n\nht
 tps://rulebook.fru.dev/regulations/cn-network-data-regs
URL:https://rulebook.fru.dev/regulations/cn-network-data-regs
CATEGORIES:China,privacy,cybersecurity,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-209@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20250101
DTEND;VALUE=DATE:20250102
SUMMARY:Colorado Privacy Act (CPA): 60-day cure period expires
DESCRIPTION:Mandatory 60-day notice-and-cure before AG enforcement ends\; e
 nforcement may proceed without cure.\n\nColorado Privacy Act (SB 21-190)\,
  C.R.S. 6-1-1301 et seq.\, as amended by HB 24-1130\, SB 24-041 and SB 25-
 276 (Colorado)\n\nSource: https://leg.colorado.gov/bills/sb21-190\n\nhttps
 ://rulebook.fru.dev/regulations/us-co-cpa
URL:https://rulebook.fru.dev/regulations/us-co-cpa
CATEGORIES:Colorado,privacy,children,biometrics
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-217@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20250101
DTEND;VALUE=DATE:20250102
SUMMARY:Connecticut Data Privacy Act (CTDPA): Universal opt-out preference 
 signals required
DESCRIPTION:Controllers must honor opt-out preference signals for targeted 
 advertising and sale (effective Jan 1\, 2025).\n\nConnecticut Data Privacy
  Act (Public Act 22-15)\, Conn. Gen. Stat. 42-515 et seq.\, as amended by 
 Public Act 25-113 (SB 1295) and Public Act 26-64 (SB 4) (Connecticut)\n\nS
 ource: https://www.cga.ct.gov/asp/cgabillstatus/cgabillstatus.asp?selBillT
 ype=Bill&which_year=2022&bill_num=6\n\nhttps://rulebook.fru.dev/regulation
 s/us-ct-ctdpa
URL:https://rulebook.fru.dev/regulations/us-ct-ctdpa
CATEGORIES:Connecticut,privacy,children,ai,health
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-223@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20250101
DTEND;VALUE=DATE:20250102
SUMMARY:Delaware Personal Data Privacy Act (DPDPA): DPDPA takes effect
DESCRIPTION:Consumer rights and controller duties apply\; 60-day mandatory 
 cure period begins.\n\nDelaware Personal Data Privacy Act (HB 154)\, 6 Del
 . C. ch. 12D (Delaware)\n\nSource: https://delcode.delaware.gov/title6/c01
 2d/index.html\n\nhttps://rulebook.fru.dev/regulations/us-de-dpdpa
URL:https://rulebook.fru.dev/regulations/us-de-dpdpa
CATEGORIES:Delaware,privacy,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-240@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20250101
DTEND;VALUE=DATE:20250102
SUMMARY:Iowa Consumer Data Protection Act (ICDPA): ICDPA takes effect
DESCRIPTION:Consumer rights and controller/processor obligations apply.\n\n
 Iowa Consumer Data Protection Act (SF 262\, 2023)\, Iowa Code ch. 715D (Io
 wa)\n\nSource: https://www.legis.iowa.gov/docs/code/715D.pdf\n\nhttps://ru
 lebook.fru.dev/regulations/us-ia-icdpa
URL:https://rulebook.fru.dev/regulations/us-ia-icdpa
CATEGORIES:Iowa,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-129@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20250101
DTEND;VALUE=DATE:20250102
SUMMARY:Malaysia PDPA: PDPA amendments phase 1
DESCRIPTION:Miscellaneous provisions commence (e.g. electronic service of n
 otices).\n\nPersonal Data Protection Act 2010 (Act 709)\, as amended by th
 e Personal Data Protection (Amendment) Act 2024 (Act A1727) (Malaysia)\n\n
 Source: https://www.pdp.gov.my/ppdpv1/en/personal-data-protection-amendmen
 t-act-2024-commencement-date-determination/\n\nhttps://rulebook.fru.dev/re
 gulations/my-pdpa
URL:https://rulebook.fru.dev/regulations/my-pdpa
CATEGORIES:Malaysia,privacy,breach-notification,biometrics,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-260@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20250101
DTEND;VALUE=DATE:20250102
SUMMARY:Nebraska NDPA: Nebraska Data Privacy Act takes effect
DESCRIPTION:Controller and processor obligations and consumer rights under 
 Neb. Rev. Stat. 87-1101 et seq. apply.\n\nNebraska Data Privacy Act (LB 10
 74\, 2024) (Nebraska)\n\nSource: https://nebraskalegislature.gov/bills/vie
 w_bill.php?DocumentID=54904\n\nhttps://rulebook.fru.dev/regulations/us-ne-
 ndpa
URL:https://rulebook.fru.dev/regulations/us-ne-ndpa
CATEGORIES:Nebraska,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-261@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20250101
DTEND;VALUE=DATE:20250102
SUMMARY:New Hampshire Privacy Act: New Hampshire Privacy Act takes effect
DESCRIPTION:RSA 507-H obligations and consumer rights apply (Laws 2024\, 5:
 1\, eff. Jan. 1\, 2025).\n\nNew Hampshire Privacy Act (SB 255\, 2024)\, RS
 A chapter 507-H (New Hampshire)\n\nSource: https://gc.nh.gov/rsa/html/LII/
 507-H/507-H-2.htm\n\nhttps://rulebook.fru.dev/regulations/us-nh-privacy
URL:https://rulebook.fru.dev/regulations/us-nh-privacy
CATEGORIES:New Hampshire,privacy,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-302@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20250101
DTEND;VALUE=DATE:20250102
SUMMARY:Texas TDPSA: Universal opt-out mechanism requirement applies
DESCRIPTION:Controllers must honor global privacy control / universal opt-o
 ut signals (Bus. & Com. Code 541.055(e)).\n\nTexas Data Privacy and Securi
 ty Act (HB 4\, 2023) (Texas)\n\nSource: https://capitol.texas.gov/BillLook
 up/History.aspx?LegSess=88R&Bill=HB4\n\nhttps://rulebook.fru.dev/regulatio
 ns/us-tx-tdpsa
URL:https://rulebook.fru.dev/regulations/us-tx-tdpsa
CATEGORIES:Texas,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-264@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20250115
DTEND;VALUE=DATE:20250116
SUMMARY:New Jersey NJDPA: NJDPA takes effect
DESCRIPTION:The act takes effect on the 365th day after enactment on Jan 16
 \, 2024 (sec. 17).\n\nNew Jersey Data Privacy Act (P.L.2023\, c.266\; S332
 ) (New Jersey)\n\nSource: https://pub.njleg.state.nj.us/Bills/2022/PL23/26
 6_.PDF\n\nhttps://rulebook.fru.dev/regulations/us-nj-njdpa
URL:https://rulebook.fru.dev/regulations/us-nj-njdpa
CATEGORIES:New Jersey,privacy,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-71@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20250117
DTEND;VALUE=DATE:20250118
SUMMARY:DORA: DORA applies
DESCRIPTION:All DORA obligations (ICT risk management\, incident reporting\
 , testing\, third-party risk\, register of information) apply from 17 Jan 
 2025 (Art 64).\n\nRegulation (EU) 2022/2554 on digital operational resilie
 nce for the financial sector (Digital Operational Resilience Act) (Europea
 n Union)\n\nSource: https://eur-lex.europa.eu/eli/reg/2022/2554/oj\n\nhttp
 s://rulebook.fru.dev/regulations/eu-dora
URL:https://rulebook.fru.dev/regulations/eu-dora
CATEGORIES:European Union,cybersecurity,financial,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-102@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20250117
DTEND;VALUE=DATE:20250118
SUMMARY:NIS2: Digital infrastructure entities submit registration data
DESCRIPTION:DNS providers\, TLD registries\, domain registration services\,
  cloud\, data centre\, CDN\, managed (security) service providers\, market
 places\, search engines and social networks had to submit registration det
 ails to competent authorities (Art 27(2)).\n\nDirective (EU) 2022/2555 on 
 measures for a high common level of cybersecurity across the Union (NIS2 D
 irective) (European Union)\n\nSource: https://eur-lex.europa.eu/eli/dir/20
 22/2555/oj\n\nhttps://rulebook.fru.dev/regulations/eu-nis2
URL:https://rulebook.fru.dev/regulations/eu-nis2
CATEGORIES:European Union,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-38@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20250202
DTEND;VALUE=DATE:20250203
SUMMARY:EU AI Act: Prohibited practices and AI literacy apply
DESCRIPTION:Chapters I and II apply\, including the Article 5 bans on prohi
 bited AI practices and the Article 4 AI literacy duty (Art 113(a)).\n\nReg
 ulation (EU) 2024/1689 laying down harmonised rules on artificial intellig
 ence (Artificial Intelligence Act)\, as amended by Regulation (EU) 2026/17
 44 (Digital Omnibus on AI) (European Union)\n\nSource: https://eur-lex.eur
 opa.eu/eli/reg/2024/1689/oj\n\nhttps://rulebook.fru.dev/regulations/eu-ai-
 act
URL:https://rulebook.fru.dev/regulations/eu-ai-act
CATEGORIES:European Union,ai,biometrics,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-238@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20250307
DTEND;VALUE=DATE:20250308
SUMMARY:HIPAA: Security Rule NPRM comment period closed
DESCRIPTION:Comments closed on the proposed HIPAA Security Rule update (90 
 FR 898)\; OCR has not issued a final rule.\n\nHIPAA Privacy\, Security and
  Breach Notification Rules (45 CFR Parts 160 and 164) (United States (Fede
 ral))\n\nSource: https://www.federalregister.gov/documents/2025/01/06/2024
 -30983/hipaa-security-rule-to-strengthen-the-cybersecurity-of-electronic-p
 rotected-health-information\n\nhttps://rulebook.fru.dev/regulations/us-hip
 aa
URL:https://rulebook.fru.dev/regulations/us-hipaa
CATEGORIES:United States (Federal),privacy,health,cybersecurity,breach-noti
 fication
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-157@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20250317
DTEND;VALUE=DATE:20250318
SUMMARY:UK Online Safety Act: Illegal harms duties enforceable
DESCRIPTION:Illegal content safety duties apply\; illegal content risk asse
 ssments had to be completed by 16 March 2025.\n\nOnline Safety Act 2023 (U
 nited Kingdom)\n\nSource: https://www.ofcom.org.uk/online-safety/illegal-a
 nd-harmful-content\n\nhttps://rulebook.fru.dev/regulations/uk-osa
URL:https://rulebook.fru.dev/regulations/uk-osa
CATEGORIES:United Kingdom,online-safety,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-128@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20250321
DTEND;VALUE=DATE:20250322
SUMMARY:Mexico LFPDPPP 2025: New LFPDPPP in force
DESCRIPTION:Law published 20 March 2025 enters into force the following day
 \, repealing the 2010 law.\n\nLey Federal de Protección de Datos Personal
 es en Posesión de los Particulares (2025) (Mexico)\n\nSource: https://www
 .diputados.gob.mx/LeyesBiblio/pdf/LFPDPPP.pdf\n\nhttps://rulebook.fru.dev/
 regulations/mx-lfpdppp
URL:https://rulebook.fru.dev/regulations/mx-lfpdppp
CATEGORIES:Mexico,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-80@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20250325
DTEND;VALUE=DATE:20250326
SUMMARY:European Health Data Space (EHDS): EHDS enters into force
DESCRIPTION:Regulation (EU) 2025/327\, published 5 Mar 2025\, enters into f
 orce on the twentieth day following publication.\n\nRegulation (EU) 2025/3
 27 on the European Health Data Space (European Union)\n\nSource: https://e
 ur-lex.europa.eu/eli/reg/2025/327/oj\n\nhttps://rulebook.fru.dev/regulatio
 ns/eu-ehds
URL:https://rulebook.fru.dev/regulations/eu-ehds
CATEGORIES:European Union,health,privacy,data-access
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-130@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20250401
DTEND;VALUE=DATE:20250402
SUMMARY:Malaysia PDPA: PDPA amendments phase 2
DESCRIPTION:'Data controller' terminology\, biometric data as sensitive dat
 a\, higher penalties\, Security Principle for processors\, and removal of 
 the cross-border whitelist take effect.\n\nPersonal Data Protection Act 20
 10 (Act 709)\, as amended by the Personal Data Protection (Amendment) Act 
 2024 (Act A1727) (Malaysia)\n\nSource: https://www.pdp.gov.my/ppdpv1/en/pe
 rsonal-data-protection-amendment-act-2024-commencement-date-determination/
 \n\nhttps://rulebook.fru.dev/regulations/my-pdpa
URL:https://rulebook.fru.dev/regulations/my-pdpa
CATEGORIES:Malaysia,privacy,breach-notification,biometrics,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-227@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20250408
DTEND;VALUE=DATE:20250409
SUMMARY:DOJ Bulk Data Rule: Prohibitions and restrictions take effect
DESCRIPTION:Core prohibitions on covered data transactions and security req
 uirements for restricted transactions apply.\n\nPreventing Access to U.S. 
 Sensitive Personal Data and Government-Related Data by Countries of Concer
 n or Covered Persons (28 CFR Part 202) - DOJ Data Security Program (United
  States (Federal))\n\nSource: https://www.federalregister.gov/documents/20
 25/01/08/2024-31486/preventing-access-to-us-sensitive-personal-data-and-go
 vernment-related-data-by-countries-of-concern\n\nhttps://rulebook.fru.dev/
 regulations/us-doj-bulk-data
URL:https://rulebook.fru.dev/regulations/us-doj-bulk-data
CATEGORIES:United States (Federal),privacy,data-residency,cybersecurity,bio
 metrics,health,financial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-158@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20250416
DTEND;VALUE=DATE:20250417
SUMMARY:UK Online Safety Act: Children's access assessments due
DESCRIPTION:Services had to complete children's access assessments to deter
 mine whether children are likely to access them.\n\nOnline Safety Act 2023
  (United Kingdom)\n\nSource: https://www.ofcom.org.uk/online-safety/protec
 ting-children/protection-of-children-duties-under-the-online-safety-act\n\
 nhttps://rulebook.fru.dev/regulations/uk-osa
URL:https://rulebook.fru.dev/regulations/uk-osa
CATEGORIES:United Kingdom,online-safety,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-103@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20250417
DTEND;VALUE=DATE:20250418
SUMMARY:NIS2: Member States establish entity lists
DESCRIPTION:Member States had to establish lists of essential and important
  entities and notify the Commission of entity numbers (Art 3(3) and (5)). 
 Repeated every two years.\n\nDirective (EU) 2022/2555 on measures for a hi
 gh common level of cybersecurity across the Union (NIS2 Directive) (Europe
 an Union)\n\nSource: https://eur-lex.europa.eu/eli/dir/2022/2555/oj\n\nhtt
 ps://rulebook.fru.dev/regulations/eu-nis2
URL:https://rulebook.fru.dev/regulations/eu-nis2
CATEGORIES:European Union,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-72@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20250430
DTEND;VALUE=DATE:20250501
SUMMARY:DORA: First registers of information submitted to the ESAs
DESCRIPTION:Competent authorities had to submit financial entities' registe
 rs of ICT third-party contractual arrangements (reference date 31 Mar 2025
 ) to the ESAs by 30 Apr 2025. National authorities set earlier deadlines f
 or entities.\n\nRegulation (EU) 2022/2554 on digital operational resilienc
 e for the financial sector (Digital Operational Resilience Act) (European 
 Union)\n\nSource: https://www.eba.europa.eu/publications-and-media/press-r
 eleases/esas-announce-timeline-collect-information-designation-critical-ic
 t-third-party-service-providers\n\nhttps://rulebook.fru.dev/regulations/eu
 -dora
URL:https://rulebook.fru.dev/regulations/eu-dora
CATEGORIES:European Union,cybersecurity,financial,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-35@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20250501
DTEND;VALUE=DATE:20250502
SUMMARY:China PI Compliance Audit Measures: PI compliance audit measures ta
 ke effect
DESCRIPTION:Self-audit and regulator-ordered audit regime applies\; 10M+ pr
 ocessors must audit at least every two years.\n\nAdministrative Measures f
 or Personal Information Protection Compliance Audits (CAC Order No. 18) (C
 hina)\n\nSource: https://www.cac.gov.cn/2025-02/14/c_1741233507681519.htm\
 n\nhttps://rulebook.fru.dev/regulations/cn-pi-compliance-audit
URL:https://rulebook.fru.dev/regulations/cn-pi-compliance-audit
CATEGORIES:China,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-275@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20250501
DTEND;VALUE=DATE:20250502
SUMMARY:NYDFS Cybersecurity Regulation (Part 500): Vulnerability scans\, ac
 cess privileges\, malware controls\, Class A monitoring
DESCRIPTION:500.5(a)(2) automated scans\, 500.7 access privilege restrictio
 ns\, 500.14(a)(2) malicious code protection\, and 500.14(b) Class A endpoi
 nt detection and centralized logging apply.\n\nNew York DFS Cybersecurity 
 Requirements for Financial Services Companies (23 NYCRR Part 500)\, Second
  Amendment (New York)\n\nSource: https://www.dfs.ny.gov/cybersecurity/23-N
 YCRR-Part-500\n\nhttps://rulebook.fru.dev/regulations/us-ny-dfs-500
URL:https://rulebook.fru.dev/regulations/us-ny-dfs-500
CATEGORIES:New York,cybersecurity,breach-notification,financial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-306@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20250507
DTEND;VALUE=DATE:20250508
SUMMARY:Utah AI Policy Act: SB 226 amendments effective
DESCRIPTION:Disclosure duties narrowed (on clear request or high-risk inter
 actions)\, safe harbor added\, provisions recodified in Title 13\, Ch. 75.
 \n\nUtah Artificial Intelligence Policy Act (SB 149\, 2024)\, as amended b
 y SB 226 and SB 332 (2025) (Utah)\n\nSource: https://le.utah.gov/~2025/bil
 ls/static/SB0226.html\n\nhttps://rulebook.fru.dev/regulations/us-ut-aipa
URL:https://rulebook.fru.dev/regulations/us-ut-aipa
CATEGORIES:Utah,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-298@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20250519
DTEND;VALUE=DATE:20250520
SUMMARY:TAKE IT DOWN Act: Criminal provisions effective on enactment
DESCRIPTION:Publishing or threatening to publish non-consensual intimate im
 ages\, including digital forgeries\, became a federal crime upon signature
 .\n\nTools to Address Known Exploitation by Immobilizing Technological Dee
 pfakes on Websites and Networks Act (TAKE IT DOWN Act) (United States (Fed
 eral))\n\nSource: https://www.govinfo.gov/content/pkg/PLAW-119publ12/html/
 PLAW-119publ12.htm\n\nhttps://rulebook.fru.dev/regulations/us-take-it-down
URL:https://rulebook.fru.dev/regulations/us-take-it-down
CATEGORIES:United States (Federal),online-safety,ai,children,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-210@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20250523
DTEND;VALUE=DATE:20250524
SUMMARY:Colorado Privacy Act (CPA): SB 25-276 geolocation and sensitive-dat
 a sale amendment effective
DESCRIPTION:Adds precise geolocation data definitions and prohibits selling
  sensitive data without consent (effective on signature).\n\nColorado Priv
 acy Act (SB 21-190)\, C.R.S. 6-1-1301 et seq.\, as amended by HB 24-1130\,
  SB 24-041 and SB 25-276 (Colorado)\n\nSource: https://leg.colorado.gov/bi
 lls/sb25-276\n\nhttps://rulebook.fru.dev/regulations/us-co-cpa
URL:https://rulebook.fru.dev/regulations/us-co-cpa
CATEGORIES:Colorado,privacy,children,biometrics
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-2@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20250530
DTEND;VALUE=DATE:20250531
SUMMARY:Australia Cyber Security Act (ransomware reporting): Ransomware pay
 ment reporting starts
DESCRIPTION:Reporting business entities must report ransomware/cyber-extort
 ion payments to ASD within 72 hours of payment.\n\nCyber Security Act 2024
  (Cth) and Cyber Security (Ransomware Payment Reporting) Rules 2025 (Austr
 alia)\n\nSource: https://www.homeaffairs.gov.au/cyber-security-subsite/fil
 es/factsheet-ransomware-payment-reporting.pdf\n\nhttps://rulebook.fru.dev/
 regulations/au-cyber-security-act
URL:https://rulebook.fru.dev/regulations/au-cyber-security-act
CATEGORIES:Australia,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-131@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20250601
DTEND;VALUE=DATE:20250602
SUMMARY:Malaysia PDPA: PDPA amendments phase 3
DESCRIPTION:Mandatory DPO appointment\, data breach notification\, and data
  portability take effect.\n\nPersonal Data Protection Act 2010 (Act 709)\,
  as amended by the Personal Data Protection (Amendment) Act 2024 (Act A172
 7) (Malaysia)\n\nSource: https://www.pdp.gov.my/ppdpv1/en/personal-data-pr
 otection-amendment-act-2024-commencement-date-determination/\n\nhttps://ru
 lebook.fru.dev/regulations/my-pdpa
URL:https://rulebook.fru.dev/regulations/my-pdpa
CATEGORIES:Malaysia,privacy,breach-notification,biometrics,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-265@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20250602
DTEND;VALUE=DATE:20250603
SUMMARY:New Jersey NJDPA: Division of Consumer Affairs proposes NJDPA rules
  (N.J.A.C. 13:45L)
DESCRIPTION:Proposed rules published at 57 N.J.R. 1101(a)\; comments were d
 ue Aug 1\, 2025.\n\nNew Jersey Data Privacy Act (P.L.2023\, c.266\; S332) 
 (New Jersey)\n\nSource: https://www.njoag.gov/murphy-administration-announ
 ces-proposed-rules-establishing-comprehensive-consumer-data-privacy-protec
 tions/\n\nhttps://rulebook.fru.dev/regulations/us-nj-njdpa
URL:https://rulebook.fru.dev/regulations/us-nj-njdpa
CATEGORIES:New Jersey,privacy,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-119@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20250604
DTEND;VALUE=DATE:20250605
SUMMARY:Japan AI Promotion Act: AI Promotion Act promulgated and partly in 
 force
DESCRIPTION:Most provisions\, including basic principles and stakeholder du
 ties\, take effect on promulgation.\n\nAct on Promotion of Research and De
 velopment\, and Utilization of Artificial Intelligence-Related Technology 
 (Japan)\n\nSource: https://www8.cao.go.jp/cstp/ai/ai_act/ai_act.html\n\nht
 tps://rulebook.fru.dev/regulations/jp-ai-act
URL:https://rulebook.fru.dev/regulations/jp-ai-act
CATEGORIES:Japan,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-5@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20250610
DTEND;VALUE=DATE:20250611
SUMMARY:Australia Privacy Act: Statutory tort for serious invasions of priv
 acy commences
DESCRIPTION:Individuals can sue for serious invasions of privacy (Schedule 
 2)\, 6 months after Royal Assent.\n\nPrivacy Act 1988 (Cth)\, as amended b
 y the Privacy and Other Legislation Amendment Act 2024 (Australia)\n\nSour
 ce: https://www.legislation.gov.au/C2024A00128/asmade\n\nhttps://rulebook.
 fru.dev/regulations/au-privacy-act
URL:https://rulebook.fru.dev/regulations/au-privacy-act
CATEGORIES:Australia,privacy,children,breach-notification,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-16@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20250618
DTEND;VALUE=DATE:20250619
SUMMARY:Canada Bill C-8 / CCSPA: Bill C-8 introduced
DESCRIPTION:First reading in the House of Commons.\n\nCritical Cyber System
 s Protection Act (enacted by Bill C-8\, An Act respecting cyber security) 
 (Canada)\n\nSource: https://www.parl.ca/legisinfo/en/bill/45-1/c-8\n\nhttp
 s://rulebook.fru.dev/regulations/ca-ccspa
URL:https://rulebook.fru.dev/regulations/ca-ccspa
CATEGORIES:Canada,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-148@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20250619
DTEND;VALUE=DATE:20250620
SUMMARY:Data (Use and Access) Act: Royal Assent
DESCRIPTION:The Act receives Royal Assent\; commencement staged by regulati
 ons.\n\nData (Use and Access) Act 2025 (United Kingdom)\n\nSource: https:/
 /www.legislation.gov.uk/ukpga/2025/18/contents\n\nhttps://rulebook.fru.dev
 /regulations/uk-duaa
URL:https://rulebook.fru.dev/regulations/uk-duaa
CATEGORIES:United Kingdom,privacy,data-access,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-303@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20250622
DTEND;VALUE=DATE:20250623
SUMMARY:TRAIGA: HB 149 signed
DESCRIPTION:Governor Abbott signs TRAIGA.\n\nTexas Responsible Artificial I
 ntelligence Governance Act (HB 149\, 89th Legislature) (Texas)\n\nSource: 
 https://capitol.texas.gov/BillLookup/History.aspx?LegSess=89R&Bill=HB149\n
 \nhttps://rulebook.fru.dev/regulations/us-tx-traiga
URL:https://rulebook.fru.dev/regulations/us-tx-traiga
CATEGORIES:Texas,ai,biometrics
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-213@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20250623
DTEND;VALUE=DATE:20250624
SUMMARY:COPPA Rule: Amended COPPA Rule takes effect
DESCRIPTION:The April 2025 amendments to 16 CFR Part 312 became effective\;
  during the transition operators could comply with either the pre-2025 or 
 the amended Rule.\n\nChildren's Online Privacy Protection Rule (16 CFR Par
 t 312)\, as amended April 2025 (United States (Federal))\n\nSource: https:
 //www.federalregister.gov/documents/2025/04/22/2025-05904/childrens-online
 -privacy-protection-rule\n\nhttps://rulebook.fru.dev/regulations/us-coppa
URL:https://rulebook.fru.dev/regulations/us-coppa
CATEGORIES:United States (Federal),privacy,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-211@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20250701
DTEND;VALUE=DATE:20250702
SUMMARY:Colorado Privacy Act (CPA): Biometric identifier amendment (HB 24-1
 130) effective
DESCRIPTION:Any controller processing biometric identifiers must adopt a wr
 itten biometric policy\, give notice\, obtain consent and follow retention
 /deletion rules.\n\nColorado Privacy Act (SB 21-190)\, C.R.S. 6-1-1301 et 
 seq.\, as amended by HB 24-1130\, SB 24-041 and SB 25-276 (Colorado)\n\nSo
 urce: https://leg.colorado.gov/bills/hb24-1130\n\nhttps://rulebook.fru.dev
 /regulations/us-co-cpa
URL:https://rulebook.fru.dev/regulations/us-co-cpa
CATEGORIES:Colorado,privacy,children,biometrics
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-284@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20250701
DTEND;VALUE=DATE:20250702
SUMMARY:Oregon OCPA: OCPA applies to nonprofits
DESCRIPTION:Nonprofit organizations meeting the thresholds become subject t
 o OCPA.\n\nOregon Consumer Privacy Act (SB 619\, 2023) (Oregon)\n\nSource:
  https://www.doj.state.or.us/consumer-protection/for-businesses/privacy-la
 w-faqs-for-nonprofits/\n\nhttps://rulebook.fru.dev/regulations/us-or-ocpa
URL:https://rulebook.fru.dev/regulations/us-or-ocpa
CATEGORIES:Oregon,privacy,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-300@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20250701
DTEND;VALUE=DATE:20250702
SUMMARY:Tennessee TIPA: TIPA takes effect
DESCRIPTION:Controller and processor obligations and consumer rights under 
 Tenn. Code Ann. 47-18-3301 et seq. apply.\n\nTennessee Information Protect
 ion Act (HB 1181 / SB 73\, 2023) (Tennessee)\n\nSource: https://wapp.capit
 ol.tn.gov/apps/BillInfo/Default.aspx?BillNumber=HB1181&GA=113\n\nhttps://r
 ulebook.fru.dev/regulations/us-tn-tipa
URL:https://rulebook.fru.dev/regulations/us-tn-tipa
CATEGORIES:Tennessee,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-73@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20250708
DTEND;VALUE=DATE:20250709
SUMMARY:DORA: TLPT regulatory technical standards enter into force
DESCRIPTION:Commission Delegated Regulation (EU) 2025/1190 (published 18 Ju
 ne 2025) sets criteria for which financial entities must run threat-led pe
 netration testing\, plus methodology and tester requirements.\n\nRegulatio
 n (EU) 2022/2554 on digital operational resilience for the financial secto
 r (Digital Operational Resilience Act) (European Union)\n\nSource: https:/
 /eur-lex.europa.eu/eli/reg_del/2025/1190/oj\n\nhttps://rulebook.fru.dev/re
 gulations/eu-dora
URL:https://rulebook.fru.dev/regulations/eu-dora
CATEGORIES:European Union,cybersecurity,financial,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-266@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20250715
DTEND;VALUE=DATE:20250716
SUMMARY:New Jersey NJDPA: Universal opt-out mechanism must be honored
DESCRIPTION:Controllers that sell personal data or process it for targeted 
 advertising must honor user-selected universal opt-out signals within six 
 months of the effective date (N.J.S.A. 56:8-166.11).\n\nNew Jersey Data Pr
 ivacy Act (P.L.2023\, c.266\; S332) (New Jersey)\n\nSource: https://pub.nj
 leg.state.nj.us/Bills/2022/PL23/266_.PDF\n\nhttps://rulebook.fru.dev/regul
 ations/us-nj-njdpa
URL:https://rulebook.fru.dev/regulations/us-nj-njdpa
CATEGORIES:New Jersey,privacy,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-159@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20250725
DTEND;VALUE=DATE:20250726
SUMMARY:UK Online Safety Act: Protection of children duties apply
DESCRIPTION:Children's safety duties and Protection of Children Codes take 
 effect\, including highly effective age assurance\; children's risk assess
 ments due by 24 July 2025.\n\nOnline Safety Act 2023 (United Kingdom)\n\nS
 ource: https://www.ofcom.org.uk/online-safety/protecting-children/protecti
 on-of-children-duties-under-the-online-safety-act\n\nhttps://rulebook.fru.
 dev/regulations/uk-osa
URL:https://rulebook.fru.dev/regulations/uk-osa
CATEGORIES:United Kingdom,online-safety,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-255@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20250731
DTEND;VALUE=DATE:20250801
SUMMARY:Minnesota Consumer Data Privacy Act (MCDPA): MCDPA takes effect
DESCRIPTION:Consumer rights and controller/processor obligations apply (pos
 tsecondary institutions excepted).\n\nMinnesota Consumer Data Privacy Act 
 (HF 4757\, 2024 Minn. Laws ch. 121\, art. 5)\, Minn. Stat. 325M.10-325M.21
  (Minnesota)\n\nSource: https://www.revisor.mn.gov/statutes/cite/325M.20\n
 \nhttps://rulebook.fru.dev/regulations/us-mn-mcdpa
URL:https://rulebook.fru.dev/regulations/us-mn-mcdpa
CATEGORIES:Minnesota,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-39@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20250802
DTEND;VALUE=DATE:20250803
SUMMARY:EU AI Act: GPAI\, governance\, notified bodies and penalties apply
DESCRIPTION:Chapter III Section 4 (notifying authorities)\, Chapter V (gene
 ral-purpose AI model obligations)\, Chapter VII (governance)\, Chapter XII
  (penalties\, except Art 101) and Art 78 apply (Art 113(b)).\n\nRegulation
  (EU) 2024/1689 laying down harmonised rules on artificial intelligence (A
 rtificial Intelligence Act)\, as amended by Regulation (EU) 2026/1744 (Dig
 ital Omnibus on AI) (European Union)\n\nSource: https://eur-lex.europa.eu/
 eli/reg/2024/1689/oj\n\nhttps://rulebook.fru.dev/regulations/eu-ai-act
URL:https://rulebook.fru.dev/regulations/eu-ai-act
CATEGORIES:European Union,ai,biometrics,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-115@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20250814
DTEND;VALUE=DATE:20250815
SUMMARY:Israel Privacy Protection Law Amendment 13: Amendment 13 in force
DESCRIPTION:Amended Privacy Protection Law\, PPA enforcement powers and sta
 tutory damages take effect.\n\nPrivacy Protection Law\, 5741-1981 (Amendme
 nt No. 13) (Israel)\n\nSource: https://www.gov.il/en/departments/the_priva
 cy_protection_authority/govil-landing-page\n\nhttps://rulebook.fru.dev/reg
 ulations/il-ppl-amendment-13
URL:https://rulebook.fru.dev/regulations/il-ppl-amendment-13
CATEGORIES:Israel,privacy,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-149@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20250820
DTEND;VALUE=DATE:20250821
SUMMARY:Data (Use and Access) Act: Stage 1 commencement
DESCRIPTION:Technical data protection provisions\, ICO statutory objects\, 
 Smart Data framework (Part 1) and AI/copyright reporting duties commence (
 Commencement No. 1 Regulations 2025).\n\nData (Use and Access) Act 2025 (U
 nited Kingdom)\n\nSource: https://www.legislation.gov.uk/ukpga/2025/18/con
 tents\n\nhttps://rulebook.fru.dev/regulations/uk-duaa
URL:https://rulebook.fru.dev/regulations/uk-duaa
CATEGORIES:United Kingdom,privacy,data-access,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-14@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20250823
DTEND;VALUE=DATE:20250824
SUMMARY:Brazil LGPD: Deadline to adopt ANPD standard contractual clauses
DESCRIPTION:Agents relying on contractual clauses for international transfe
 rs must incorporate the ANPD-approved SCCs into their contracts within 12 
 months of publication.\n\nLei Geral de Proteção de Dados Pessoais (Law N
 o. 13.709/2018) (Brazil)\n\nSource: https://www.in.gov.br/en/web/dou/-/res
 olucao-cd/anpd-n-19-de-23-de-agosto-de-2024-580095396\n\nhttps://rulebook.
 fru.dev/regulations/br-lgpd
URL:https://rulebook.fru.dev/regulations/br-lgpd
CATEGORIES:Brazil,privacy,breach-notification,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-200@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20250828
DTEND;VALUE=DATE:20250829
SUMMARY:Colorado AI Act: SB 25B-004 delays the act
DESCRIPTION:Special-session bill pushes the SB 24-205 effective date from F
 ebruary 1\, 2026 to June 30\, 2026.\n\nColorado SB 24-205 (Consumer Protec
 tions for Artificial Intelligence)\, as delayed by SB 25B-004 and repealed
  and reenacted by SB 26-189 (Automated Decision-Making Technology) (Colora
 do)\n\nSource: https://leg.colorado.gov/bills/sb25b-004\n\nhttps://ruleboo
 k.fru.dev/regulations/us-co-ai-act
URL:https://rulebook.fru.dev/regulations/us-co-ai-act
CATEGORIES:Colorado,ai,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-29@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20250901
DTEND;VALUE=DATE:20250902
SUMMARY:China AI Content Labeling Measures: AI content labeling measures an
 d GB 45438-2025 take effect
DESCRIPTION:Explicit and implicit labeling duties for AI-generated content 
 and platform detection duties apply.\n\nMeasures for Labeling AI-Generated
  Synthetic Content (China)\n\nSource: https://www.cac.gov.cn/2025-03/14/c_
 1743654684782215.htm\n\nhttps://rulebook.fru.dev/regulations/cn-ai-labelin
 g
URL:https://rulebook.fru.dev/regulations/cn-ai-labeling
CATEGORIES:China,ai,online-safety
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-120@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20250901
DTEND;VALUE=DATE:20250902
SUMMARY:Japan AI Promotion Act: AI Promotion Act fully in force
DESCRIPTION:Provisions establishing the AI Strategy Headquarters and AI Bas
 ic Plan take effect.\n\nAct on Promotion of Research and Development\, and
  Utilization of Artificial Intelligence-Related Technology (Japan)\n\nSour
 ce: https://www8.cao.go.jp/cstp/ai/ai_act/ai_act.html\n\nhttps://rulebook.
 fru.dev/regulations/jp-ai-act
URL:https://rulebook.fru.dev/regulations/jp-ai-act
CATEGORIES:Japan,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-109@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20250903
DTEND;VALUE=DATE:20250904
SUMMARY:EU-US Data Privacy Framework: General Court upholds DPF (Latombe v 
 Commission)
DESCRIPTION:General Court dismissed Philippe Latombe's action for annulment
  (Case T-553/23) and confirmed the US offered adequate protection when the
  decision was adopted.\n\nCommission Implementing Decision (EU) 2023/1795 
 on the adequate level of protection of personal data under the EU-US Data 
 Privacy Framework (European Union)\n\nSource: https://curia.europa.eu/jcms
 /upload/docs/application/pdf/2025-09/cp250106en.pdf\n\nhttps://rulebook.fr
 u.dev/regulations/eu-us-dpf
URL:https://rulebook.fru.dev/regulations/eu-us-dpf
CATEGORIES:European Union,privacy,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-57@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20250912
DTEND;VALUE=DATE:20250913
SUMMARY:EU Data Act: Data Act applies
DESCRIPTION:Most obligations apply\, including user data access and sharing
  (Chapters II-III)\, cloud switching (Chapter VI) and interoperability\; C
 hapter IV unfair terms apply to contracts concluded after this date (Art 5
 0).\n\nRegulation (EU) 2023/2854 on harmonised rules on fair access to and
  use of data (Data Act) (European Union)\n\nSource: https://eur-lex.europa
 .eu/eli/reg/2023/2854/oj\n\nhttps://rulebook.fru.dev/regulations/eu-data-a
 ct
URL:https://rulebook.fru.dev/regulations/eu-data-act
CATEGORIES:European Union,data-access,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-58@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20250912
DTEND;VALUE=DATE:20250913
SUMMARY:EU Data Act: Member States notify penalty rules
DESCRIPTION:Member States had to notify the Commission of their penalty rul
 es (Art 40(2)).\n\nRegulation (EU) 2023/2854 on harmonised rules on fair a
 ccess to and use of data (Data Act) (European Union)\n\nSource: https://eu
 r-lex.europa.eu/eli/reg/2023/2854/oj\n\nhttps://rulebook.fru.dev/regulatio
 ns/eu-data-act
URL:https://rulebook.fru.dev/regulations/eu-data-act
CATEGORIES:European Union,data-access,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-133@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20250919
DTEND;VALUE=DATE:20250920
SUMMARY:Nigeria NDPA: GAID 2025 takes effect
DESCRIPTION:General Application and Implementation Directive becomes effect
 ive\, replacing the NDPR 2019 and NDPR Implementation Framework.\n\nNigeri
 a Data Protection Act\, 2023 and NDPA General Application and Implementati
 on Directive (GAID) 2025 (Nigeria)\n\nSource: https://ndpc.gov.ng/resource
 s/\n\nhttps://rulebook.fru.dev/regulations/ng-ndpa
URL:https://rulebook.fru.dev/regulations/ng-ndpa
CATEGORIES:Nigeria,privacy,breach-notification,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-167@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20250922
DTEND;VALUE=DATE:20250923
SUMMARY:CCPA / CPRA: ADMT\, risk assessment and cybersecurity audit regulat
 ions approved
DESCRIPTION:OAL approves the CCPA Updates\, Cybersecurity Audit\, Risk Asse
 ssment\, ADMT and Insurance regulations and files them with the Secretary 
 of State.\n\nCalifornia Consumer Privacy Act of 2018\, as amended by the C
 alifornia Privacy Rights Act of 2020 (Cal. Civ. Code 1798.100 et seq.) and
  CPPA regulations (Cal. Code Regs. tit. 11\, 7000 et seq.) (California)\n\
 nSource: https://cppa.ca.gov/regulations/ccpa_updates.html\n\nhttps://rule
 book.fru.dev/regulations/us-ca-ccpa
URL:https://rulebook.fru.dev/regulations/us-ca-ccpa
CATEGORIES:California,privacy,ai,cybersecurity,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-65@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20250924
DTEND;VALUE=DATE:20250925
SUMMARY:Data Governance Act: Legacy data intermediaries must comply
DESCRIPTION:Entities that were already providing data intermediation servic
 es on 23 June 2022 had to comply with Chapter III by 24 Sep 2025 (Art 37).
 \n\nRegulation (EU) 2022/868 on European data governance (Data Governance 
 Act) (European Union)\n\nSource: https://eur-lex.europa.eu/eli/reg/2022/86
 8/oj\n\nhttps://rulebook.fru.dev/regulations/eu-dga
URL:https://rulebook.fru.dev/regulations/eu-dga
CATEGORIES:European Union,data-access,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-135@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20250924
DTEND;VALUE=DATE:20250925
SUMMARY:New Zealand Privacy Act: Privacy Amendment Act 2025 technical chang
 es commence
DESCRIPTION:Technical amendments commence the day after Royal Assent (23 Se
 p 2025).\n\nPrivacy Act 2020 (New Zealand)\, as amended by the Privacy Ame
 ndment Act 2025 (New Zealand)\n\nSource: https://www.justice.govt.nz/justi
 ce-sector-policy/key-initiatives/enhancing-the-privacy-act/\n\nhttps://rul
 ebook.fru.dev/regulations/nz-privacy-act
URL:https://rulebook.fru.dev/regulations/nz-privacy-act
CATEGORIES:New Zealand,privacy,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-184@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20250929
DTEND;VALUE=DATE:20250930
SUMMARY:California SB 53 (TFAIA): SB 53 signed
DESCRIPTION:Governor Newsom signs SB 53 (chapter 138).\n\nCalifornia SB 53\
 , Transparency in Frontier Artificial Intelligence Act (Stats. 2025\, ch. 
 138) (California)\n\nSource: https://leginfo.legislature.ca.gov/faces/bill
 NavClient.xhtml?bill_id=202520260SB53\n\nhttps://rulebook.fru.dev/regulati
 ons/us-ca-sb53
URL:https://rulebook.fru.dev/regulations/us-ca-sb53
CATEGORIES:California,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-212@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20251001
DTEND;VALUE=DATE:20251002
SUMMARY:Colorado Privacy Act (CPA): Minors' data amendment (SB 24-041) effe
 ctive
DESCRIPTION:Controllers offering online services to minors must use reasona
 ble care\, conduct assessments\, and obtain consent for targeted ads\, sal
 e and certain profiling of minors.\n\nColorado Privacy Act (SB 21-190)\, C
 .R.S. 6-1-1301 et seq.\, as amended by HB 24-1130\, SB 24-041 and SB 25-27
 6 (Colorado)\n\nSource: https://leg.colorado.gov/bills/sb24-041\n\nhttps:/
 /rulebook.fru.dev/regulations/us-co-cpa
URL:https://rulebook.fru.dev/regulations/us-co-cpa
CATEGORIES:Colorado,privacy,children,biometrics
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-252@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20251001
DTEND;VALUE=DATE:20251002
SUMMARY:Maryland Online Data Privacy Act (MODPA): MODPA takes effect
DESCRIPTION:Act takes effect\; data protection assessments apply to process
 ing activities on or after Oct 1\, 2025.\n\nMaryland Online Data Privacy A
 ct of 2024 (SB 541 / HB 567)\, Md. Code\, Com. Law 14-4601 et seq. (Maryla
 nd)\n\nSource: https://mgaleg.maryland.gov/2024RS/Chapters_noln/CH_455_sb0
 541e.pdf\n\nhttps://rulebook.fru.dev/regulations/us-md-modpa
URL:https://rulebook.fru.dev/regulations/us-md-modpa
CATEGORIES:Maryland,privacy,children,health,biometrics
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-259@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20251001
DTEND;VALUE=DATE:20251002
SUMMARY:Montana Consumer Data Privacy Act (MCDPA): SB 297 amendments take e
 ffect\; cure period eliminated
DESCRIPTION:Lower thresholds (25\,000 / 15\,000 + 25%)\, minors' data prote
 ctions\, AG assessment demands\; the 60-day cure period is removed.\n\nMon
 tana Consumer Data Privacy Act (SB 384\, 2023)\, Mont. Code Ann. 30-14-280
 1 et seq.\, as amended by SB 297 (2025) (Montana)\n\nSource: https://archi
 ve.legmt.gov/bills/mca/title_0300/chapter_0140/part_0280/section_0170/0300
 -0140-0280-0170.html\n\nhttps://rulebook.fru.dev/regulations/us-mt-mcdpa
URL:https://rulebook.fru.dev/regulations/us-mt-mcdpa
CATEGORIES:Montana,privacy,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-228@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20251006
DTEND;VALUE=DATE:20251007
SUMMARY:DOJ Bulk Data Rule: Due diligence\, audit and reporting obligations
  apply
DESCRIPTION:Subpart J (data compliance program\, due diligence and audits f
 or restricted transactions) and reporting requirements in 202.1103 and 202
 .1104 apply.\n\nPreventing Access to U.S. Sensitive Personal Data and Gove
 rnment-Related Data by Countries of Concern or Covered Persons (28 CFR Par
 t 202) - DOJ Data Security Program (United States (Federal))\n\nSource: ht
 tps://www.federalregister.gov/documents/2025/01/08/2024-31486/preventing-a
 ccess-to-us-sensitive-personal-data-and-government-related-data-by-countri
 es-of-concern\n\nhttps://rulebook.fru.dev/regulations/us-doj-bulk-data
URL:https://rulebook.fru.dev/regulations/us-doj-bulk-data
CATEGORIES:United States (Federal),privacy,data-residency,cybersecurity,bio
 metrics,health,financial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-188@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20251013
DTEND;VALUE=DATE:20251014
SUMMARY:California AI Transparency Act (SB 942): AB 853 signed
DESCRIPTION:AB 853 (ch. 674) delays the operative date and adds platform an
 d device duties.\n\nCalifornia AI Transparency Act (SB 942\, Stats. 2024\,
  ch. 291)\, as amended by AB 853 (Stats. 2025\, ch. 674) (California)\n\nS
 ource: https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_i
 d=202520260AB853\n\nhttps://rulebook.fru.dev/regulations/us-ca-sb942
URL:https://rulebook.fru.dev/regulations/us-ca-sb942
CATEGORIES:California,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-181@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20251013
DTEND;VALUE=DATE:20251014
SUMMARY:California SB 243 (companion chatbots): SB 243 signed
DESCRIPTION:SB 243 chaptered (ch. 677).\n\nCalifornia SB 243\, Companion Ch
 atbots (Stats. 2025\, ch. 677) (California)\n\nSource: https://leginfo.leg
 islature.ca.gov/faces/billNavClient.xhtml?bill_id=202520260SB243\n\nhttps:
 //rulebook.fru.dev/regulations/us-ca-sb243
URL:https://rulebook.fru.dev/regulations/us-ca-sb243
CATEGORIES:California,ai,children,online-safety
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-110@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20251031
DTEND;VALUE=DATE:20251101
SUMMARY:EU-US Data Privacy Framework: Latombe appeal lodged at the Court of
  Justice
DESCRIPTION:Latombe appealed the General Court judgment to the Court of Jus
 tice on points of law (reported as Case C-703/25 P)\; the DPF stays valid 
 while it is pending.\n\nCommission Implementing Decision (EU) 2023/1795 on
  the adequate level of protection of personal data under the EU-US Data Pr
 ivacy Framework (European Union)\n\nSource: https://www.wilmerhale.com/en/
 insights/blogs/wilmerhale-privacy-and-cybersecurity-law/20251201-european-
 court-of-justice-to-review-challenge-to-eu-us-data-privacy-framework\n\nht
 tps://rulebook.fru.dev/regulations/eu-us-dpf
URL:https://rulebook.fru.dev/regulations/eu-us-dpf
CATEGORIES:European Union,privacy,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-276@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20251101
DTEND;VALUE=DATE:20251102
SUMMARY:NYDFS Cybersecurity Regulation (Part 500): Universal MFA and asset 
 inventory
DESCRIPTION:500.12 multi-factor authentication for all users and 500.13(a) 
 asset inventory requirements apply.\n\nNew York DFS Cybersecurity Requirem
 ents for Financial Services Companies (23 NYCRR Part 500)\, Second Amendme
 nt (New York)\n\nSource: https://www.dfs.ny.gov/cybersecurity/23-NYCRR-Par
 t-500\n\nhttps://rulebook.fru.dev/regulations/us-ny-dfs-500
URL:https://rulebook.fru.dev/regulations/us-ny-dfs-500
CATEGORIES:New York,cybersecurity,breach-notification,financial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-195@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20251110
DTEND;VALUE=DATE:20251111
SUMMARY:CMMC 2.0: DFARS rule effective\; Phase 1 begins
DESCRIPTION:CMMC Level 1 and Level 2 self-assessment requirements begin app
 earing in applicable DoD solicitations and contracts (32 CFR 170.3(e)(1)).
 \n\nCybersecurity Maturity Model Certification (CMMC) Program (32 CFR Part
  170) and DFARS acquisition rule (48 CFR Parts 204\, 212\, 217\, 252) (Uni
 ted States (Federal))\n\nSource: https://www.federalregister.gov/documents
 /2025/09/10/2025-17359/defense-federal-acquisition-regulation-supplement-a
 ssessing-contractor-implementation-of\n\nhttps://rulebook.fru.dev/regulati
 ons/us-cmmc
URL:https://rulebook.fru.dev/regulations/us-cmmc
CATEGORIES:United States (Federal),cybersecurity
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-145@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20251112
DTEND;VALUE=DATE:20251113
SUMMARY:UK Cyber Security and Resilience Bill: Introduced (Commons first re
 ading)
DESCRIPTION:Bill introduced in the House of Commons.\n\nCyber Security and 
 Resilience (Network and Information Systems) Bill (United Kingdom)\n\nSour
 ce: https://bills.parliament.uk/bills/4035\n\nhttps://rulebook.fru.dev/reg
 ulations/uk-csr-bill
URL:https://rulebook.fru.dev/regulations/uk-csr-bill
CATEGORIES:United Kingdom,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-116@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20251113
DTEND;VALUE=DATE:20251114
SUMMARY:India DPDP Act: DPDP Rules published\; Board and procedural rules i
 n force
DESCRIPTION:Rules 1\, 2 and 17-21 (Data Protection Board constitution and f
 unctioning) take effect on publication in the Official Gazette.\n\nDigital
  Personal Data Protection Act\, 2023 and Digital Personal Data Protection 
 Rules\, 2025 (India)\n\nSource: https://egazette.gov.in/WriteReadData/2025
 /267650.pdf\n\nhttps://rulebook.fru.dev/regulations/in-dpdp
URL:https://rulebook.fru.dev/regulations/in-dpdp
CATEGORIES:India,privacy,children,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-74@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20251118
DTEND;VALUE=DATE:20251119
SUMMARY:DORA: First critical ICT third-party providers designated
DESCRIPTION:The ESAs published the first list of 19 critical ICT third-part
 y providers (including AWS\, Google Cloud and Microsoft)\, which now come 
 under direct EU oversight.\n\nRegulation (EU) 2022/2554 on digital operati
 onal resilience for the financial sector (Digital Operational Resilience A
 ct) (European Union)\n\nSource: https://www.eba.europa.eu/publications-and
 -media/press-releases/european-supervisory-authorities-designate-critical-
 ict-third-party-providers-under-digital\n\nhttps://rulebook.fru.dev/regula
 tions/eu-dora
URL:https://rulebook.fru.dev/regulations/eu-dora
CATEGORIES:European Union,cybersecurity,financial,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-95@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20251126
DTEND;VALUE=DATE:20251127
SUMMARY:GDPR: GDPR Procedural Regulation adopted
DESCRIPTION:Regulation (EU) 2025/2518 laying down additional procedural rul
 es for cross-border GDPR enforcement signed by Parliament and Council.\n\n
 Regulation (EU) 2016/679 (General Data Protection Regulation) (European Un
 ion)\n\nSource: https://eur-lex.europa.eu/eli/reg/2025/2518/oj\n\nhttps://
 rulebook.fru.dev/regulations/eu-gdpr
URL:https://rulebook.fru.dev/regulations/eu-gdpr
CATEGORIES:European Union,privacy,breach-notification,data-access,children,
 biometrics,health
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-296@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20251203
DTEND;VALUE=DATE:20251204
SUMMARY:SEC Regulation S-P: Larger entities must comply
DESCRIPTION:Larger covered institutions (18 months after Federal Register p
 ublication) must have incident response programs\, 30-day customer notific
 ation\, and service-provider oversight in place.\n\nRegulation S-P: Privac
 y of Consumer Financial Information and Safeguarding Customer Information 
 (2024 amendments) (United States (Federal))\n\nSource: https://www.federal
 register.gov/documents/2024/06/03/2024-11116/regulation-s-p-privacy-of-con
 sumer-financial-information-and-safeguarding-customer-information\n\nhttps
 ://rulebook.fru.dev/regulations/us-sec-reg-sp
URL:https://rulebook.fru.dev/regulations/us-sec-reg-sp
CATEGORIES:United States (Federal),financial,privacy,cybersecurity,breach-n
 otification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-8@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20251210
DTEND;VALUE=DATE:20251211
SUMMARY:Australia Social Media Minimum Age: Social media minimum age obliga
 tion applies
DESCRIPTION:Age-restricted platforms must take reasonable steps to prevent 
 under-16s from holding accounts.\n\nOnline Safety Amendment (Social Media 
 Minimum Age) Act 2024 (Australia)\n\nSource: https://www.legislation.gov.a
 u/C2024A00127/asmade\n\nhttps://rulebook.fru.dev/regulations/au-social-med
 ia-min-age
URL:https://rulebook.fru.dev/regulations/au-social-media-min-age
CATEGORIES:Australia,children,online-safety
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-278@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20251219
DTEND;VALUE=DATE:20251220
SUMMARY:NY RAISE Act: RAISE Act signed
DESCRIPTION:Governor Hochul signs the RAISE Act with an agreed chapter amen
 dment.\n\nNew York Responsible AI Safety and Education (RAISE) Act (S6953-
 B/A6453-B of 2025)\, as amended by chapter amendment S8828 of 2026 (New Yo
 rk)\n\nSource: https://www.governor.ny.gov/news/governor-hochul-signs-nati
 on-leading-legislation-require-ai-frameworks-ai-frontier-models\n\nhttps:/
 /rulebook.fru.dev/regulations/us-ny-raise
URL:https://rulebook.fru.dev/regulations/us-ny-raise
CATEGORIES:New York,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-224@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20251231
DTEND;VALUE=DATE:20260101
SUMMARY:Delaware Personal Data Privacy Act (DPDPA): Mandatory 60-day cure p
 eriod expires
DESCRIPTION:Mandatory notice-and-cure ends Dec 31\, 2025\; from Jan 1\, 202
 6 DOJ decides whether to offer a cure using statutory factors.\n\nDelaware
  Personal Data Privacy Act (HB 154)\, 6 Del. C. ch. 12D (Delaware)\n\nSour
 ce: https://delcode.delaware.gov/title6/c012d/index.html\n\nhttps://rulebo
 ok.fru.dev/regulations/us-de-dpdpa
URL:https://rulebook.fru.dev/regulations/us-de-dpdpa
CATEGORIES:Delaware,privacy,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-3@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20260101
DTEND;VALUE=DATE:20260102
SUMMARY:Australia Cyber Security Act (ransomware reporting): Ransomware rep
 orting moves to compliance phase
DESCRIPTION:The education-first phase (30 May-31 Dec 2025) ends\; Home Affa
 irs moves to a compliance and education approach for missed reports.\n\nCy
 ber Security Act 2024 (Cth) and Cyber Security (Ransomware Payment Reporti
 ng) Rules 2025 (Australia)\n\nSource: https://www.homeaffairs.gov.au/cyber
 -security-subsite/files/factsheet-ransomware-payment-reporting.pdf\n\nhttp
 s://rulebook.fru.dev/regulations/au-cyber-security-act
URL:https://rulebook.fru.dev/regulations/au-cyber-security-act
CATEGORIES:Australia,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-163@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20260101
DTEND;VALUE=DATE:20260102
SUMMARY:California AB 2013 (AI training data transparency): Training-data d
 ocumentation due
DESCRIPTION:Documentation must be posted for GenAI systems released since J
 anuary 1\, 2022\, and before each later release or substantial modificatio
 n.\n\nCalifornia AB 2013\, Generative Artificial Intelligence: Training Da
 ta Transparency (Stats. 2024\, ch. 817) (California)\n\nSource: https://le
 ginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202320240AB2013
 \n\nhttps://rulebook.fru.dev/regulations/us-ca-ab2013
URL:https://rulebook.fru.dev/regulations/us-ca-ab2013
CATEGORIES:California,ai,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-189@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20260101
DTEND;VALUE=DATE:20260102
SUMMARY:California AI Transparency Act (SB 942): Original operative date (s
 uperseded)
DESCRIPTION:Original SB 942 date\; delayed to August 2\, 2026 by AB 853.\n\
 nCalifornia AI Transparency Act (SB 942\, Stats. 2024\, ch. 291)\, as amen
 ded by AB 853 (Stats. 2025\, ch. 674) (California)\n\nSource: https://legi
 nfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202320240SB942\n\
 nhttps://rulebook.fru.dev/regulations/us-ca-sb942
URL:https://rulebook.fru.dev/regulations/us-ca-sb942
CATEGORIES:California,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-176@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20260101
DTEND;VALUE=DATE:20260102
SUMMARY:California Delete Act / DROP: DROP opens to consumers
DESCRIPTION:Consumers can submit a single deletion request to all registere
 d data brokers through DROP.\n\nCalifornia Delete Act (SB 362\, 2023)\, Ca
 l. Civ. Code 1798.99.80 et seq.\, and DROP regulations (California)\n\nSou
 rce: https://www.cppa.ca.gov/data_brokers/\n\nhttps://rulebook.fru.dev/reg
 ulations/us-ca-delete-act
URL:https://rulebook.fru.dev/regulations/us-ca-delete-act
CATEGORIES:California,privacy,data-access
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-182@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20260101
DTEND;VALUE=DATE:20260102
SUMMARY:California SB 243 (companion chatbots): Chatbot safeguards apply
DESCRIPTION:AI disclosure\, suicide and self-harm protocols\, and minor pro
 tections apply.\n\nCalifornia SB 243\, Companion Chatbots (Stats. 2025\, c
 h. 677) (California)\n\nSource: https://leginfo.legislature.ca.gov/faces/b
 illNavClient.xhtml?bill_id=202520260SB243\n\nhttps://rulebook.fru.dev/regu
 lations/us-ca-sb243
URL:https://rulebook.fru.dev/regulations/us-ca-sb243
CATEGORIES:California,ai,children,online-safety
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-185@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20260101
DTEND;VALUE=DATE:20260102
SUMMARY:California SB 53 (TFAIA): Frontier developer obligations apply
DESCRIPTION:Frontier AI frameworks\, transparency reports\, critical safety
  incident reporting (15 days\, or 24 hours for imminent risk of death or s
 erious injury) and whistleblower protections apply.\n\nCalifornia SB 53\, 
 Transparency in Frontier Artificial Intelligence Act (Stats. 2025\, ch. 13
 8) (California)\n\nSource: https://leginfo.legislature.ca.gov/faces/billNa
 vClient.xhtml?bill_id=202520260SB53\n\nhttps://rulebook.fru.dev/regulation
 s/us-ca-sb53
URL:https://rulebook.fru.dev/regulations/us-ca-sb53
CATEGORIES:California,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-168@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20260101
DTEND;VALUE=DATE:20260102
SUMMARY:CCPA / CPRA: New CCPA regulations take effect
DESCRIPTION:ADMT\, risk assessment\, cybersecurity audit and updated CCPA r
 egulations become effective\; risk assessments required for new high-risk 
 processing.\n\nCalifornia Consumer Privacy Act of 2018\, as amended by the
  California Privacy Rights Act of 2020 (Cal. Civ. Code 1798.100 et seq.) a
 nd CPPA regulations (Cal. Code Regs. tit. 11\, 7000 et seq.) (California)\
 n\nSource: https://cppa.ca.gov/regulations/ccpa_updates.html\n\nhttps://ru
 lebook.fru.dev/regulations/us-ca-ccpa
URL:https://rulebook.fru.dev/regulations/us-ca-ccpa
CATEGORIES:California,privacy,ai,cybersecurity,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-32@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20260101
DTEND;VALUE=DATE:20260102
SUMMARY:China Cybersecurity Law: 2025 amendments take effect
DESCRIPTION:Higher fines\, first-violation fines\, AI governance provisions
  and PIPL-alignment duties apply under the 28 Oct 2025 NPCSC Decision.\n\n
 Cybersecurity Law of the People's Republic of China (as amended by the NPC
  Standing Committee Decision of 28 October 2025) (China)\n\nSource: https:
 //www.gov.cn/yaowen/liebiao/202510/content_7046194.htm\n\nhttps://rulebook
 .fru.dev/regulations/cn-csl
URL:https://rulebook.fru.dev/regulations/cn-csl
CATEGORIES:China,cybersecurity,data-residency,ai,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-225@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20260101
DTEND;VALUE=DATE:20260102
SUMMARY:Delaware Personal Data Privacy Act (DPDPA): Opt-out preference sign
 als must be honored
DESCRIPTION:Controllers must allow opt-out of targeted advertising and sale
  via opt-out preference signals (12D-106).\n\nDelaware Personal Data Priva
 cy Act (HB 154)\, 6 Del. C. ch. 12D (Delaware)\n\nSource: https://delcode.
 delaware.gov/title6/c012d/index.html\n\nhttps://rulebook.fru.dev/regulatio
 ns/us-de-dpdpa
URL:https://rulebook.fru.dev/regulations/us-de-dpdpa
CATEGORIES:Delaware,privacy,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-96@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20260101
DTEND;VALUE=DATE:20260102
SUMMARY:GDPR: GDPR Procedural Regulation enters into force
DESCRIPTION:Regulation (EU) 2025/2518\, published in the OJ on 12 December 
 2025\, enters into force on the twentieth day after publication.\n\nRegula
 tion (EU) 2016/679 (General Data Protection Regulation) (European Union)\n
 \nSource: https://eur-lex.europa.eu/eli/reg/2025/2518/oj\n\nhttps://rulebo
 ok.fru.dev/regulations/eu-gdpr
URL:https://rulebook.fru.dev/regulations/eu-gdpr
CATEGORIES:European Union,privacy,breach-notification,data-access,children,
 biometrics,health
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-111@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20260101
DTEND;VALUE=DATE:20260102
SUMMARY:Hong Kong Critical Infrastructure Cyber Ordinance: PCICSO comes int
 o operation
DESCRIPTION:Commissioner's Office is established and designation of CIOs be
 gins\; obligations apply to designated operators.\n\nProtection of Critica
 l Infrastructures (Computer Systems) Ordinance (Cap. 653) (Hong Kong)\n\nS
 ource: https://www.info.gov.hk/gia/general/202506/27/P2025062700238.htm\n\
 nhttps://rulebook.fru.dev/regulations/hk-pcico
URL:https://rulebook.fru.dev/regulations/hk-pcico
CATEGORIES:Hong Kong,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-245@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20260101
DTEND;VALUE=DATE:20260102
SUMMARY:Illinois AI in Employment Law (HB 3773): AI anti-discrimination and
  notice duties apply
DESCRIPTION:Prohibition on discriminatory AI use and the employee notice re
 quirement take effect.\n\nIllinois HB 3773 (Public Act 103-0804)\, amendin
 g the Illinois Human Rights Act on artificial intelligence in employment (
 Illinois)\n\nSource: https://www.ilga.gov/ftp/legislation/103/BillStatus/H
 TML/10300HB3773.html\n\nhttps://rulebook.fru.dev/regulations/us-il-hb3773
URL:https://rulebook.fru.dev/regulations/us-il-hb3773
CATEGORIES:Illinois,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-248@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20260101
DTEND;VALUE=DATE:20260102
SUMMARY:Indiana Consumer Data Protection Act (ICDPA): ICDPA takes effect
DESCRIPTION:Consumer rights and controller/processor obligations apply\; as
 sessments required for processing activities created on or after this date
 .\n\nIndiana Consumer Data Protection Act (SEA 5\, 2023)\, Ind. Code 24-15
  (Indiana)\n\nSource: https://iga.in.gov/legislative/2023/bills/senate/5/d
 etails\n\nhttps://rulebook.fru.dev/regulations/us-in-icdpa
URL:https://rulebook.fru.dev/regulations/us-in-icdpa
CATEGORIES:Indiana,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-249@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20260101
DTEND;VALUE=DATE:20260102
SUMMARY:Kentucky Consumer Data Protection Act (KCDPA): KCDPA takes effect
DESCRIPTION:Consumer rights and controller/processor obligations apply (HB 
 15 section 12).\n\nKentucky Consumer Data Protection Act (HB 15\, 2024)\, 
 KRS 367.3611-367.3629 (Kentucky)\n\nSource: https://apps.legislature.ky.go
 v/recorddocuments/bill/24RS/hb15/bill.pdf\n\nhttps://rulebook.fru.dev/regu
 lations/us-ky-kcdpa
URL:https://rulebook.fru.dev/regulations/us-ky-kcdpa
CATEGORIES:Kentucky,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-262@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20260101
DTEND;VALUE=DATE:20260102
SUMMARY:New Hampshire Privacy Act: Mandatory 60-day cure period expires
DESCRIPTION:The AG's obligation to issue a cure notice ended Dec 31\, 2025\
 ; from Jan 1\, 2026 cure opportunities are discretionary (RSA 507-H:11 II-
 III).\n\nNew Hampshire Privacy Act (SB 255\, 2024)\, RSA chapter 507-H (Ne
 w Hampshire)\n\nSource: https://gc.nh.gov/rsa/html/LII/507-H/507-H-11.htm\
 n\nhttps://rulebook.fru.dev/regulations/us-nh-privacy
URL:https://rulebook.fru.dev/regulations/us-nh-privacy
CATEGORIES:New Hampshire,privacy,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-285@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20260101
DTEND;VALUE=DATE:20260102
SUMMARY:Oregon OCPA: Cure period sunsets
DESCRIPTION:The AG's 30-day notice-and-cure requirement expires\; enforceme
 nt can proceed without a cure opportunity.\n\nOregon Consumer Privacy Act 
 (SB 619\, 2023) (Oregon)\n\nSource: https://www.oregonlegislature.gov/bill
 s_laws/ors/ors646A.html\n\nhttps://rulebook.fru.dev/regulations/us-or-ocpa
URL:https://rulebook.fru.dev/regulations/us-or-ocpa
CATEGORIES:Oregon,privacy,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-286@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20260101
DTEND;VALUE=DATE:20260102
SUMMARY:Oregon OCPA: Universal opt-out signals must be honored
DESCRIPTION:Controllers must honor opt-out preference signals such as Globa
 l Privacy Control.\n\nOregon Consumer Privacy Act (SB 619\, 2023) (Oregon)
 \n\nSource: https://www.doj.state.or.us/consumer-protection/id-theft-data-
 breaches/privacy/\n\nhttps://rulebook.fru.dev/regulations/us-or-ocpa
URL:https://rulebook.fru.dev/regulations/us-or-ocpa
CATEGORIES:Oregon,privacy,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-287@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20260101
DTEND;VALUE=DATE:20260102
SUMMARY:Oregon OCPA: Sale ban on precise geolocation and under-16 data (HB 
 2008)
DESCRIPTION:Selling precise geolocation (1\,750-ft radius) and the personal
  data of consumers the controller knows or willfully disregards are under 
 16 is prohibited.\n\nOregon Consumer Privacy Act (SB 619\, 2023) (Oregon)\
 n\nSource: https://www.doj.state.or.us/consumer-protection/id-theft-data-b
 reaches/privacy/\n\nhttps://rulebook.fru.dev/regulations/us-or-ocpa
URL:https://rulebook.fru.dev/regulations/us-or-ocpa
CATEGORIES:Oregon,privacy,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-289@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20260101
DTEND;VALUE=DATE:20260102
SUMMARY:Rhode Island RIDTPPA: RIDTPPA takes effect
DESCRIPTION:All provisions of R.I. Gen. Laws ch. 6-48.1 apply (P.L. 2024\, 
 ch. 430/453\, effective Jan 1\, 2026).\n\nRhode Island Data Transparency a
 nd Privacy Protection Act (Rhode Island)\n\nSource: https://webserver.rile
 gislature.gov/Statutes/TITLE6/6-48.1/INDEX.htm\n\nhttps://rulebook.fru.dev
 /regulations/us-ri-dtppa
URL:https://rulebook.fru.dev/regulations/us-ri-dtppa
CATEGORIES:Rhode Island,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-304@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20260101
DTEND;VALUE=DATE:20260102
SUMMARY:TRAIGA: TRAIGA takes effect
DESCRIPTION:Prohibited-practice rules\, AG enforcement\, sandbox program an
 d government AI disclosure duties apply.\n\nTexas Responsible Artificial I
 ntelligence Governance Act (HB 149\, 89th Legislature) (Texas)\n\nSource: 
 https://capitol.texas.gov/BillLookup/History.aspx?LegSess=89R&Bill=HB149\n
 \nhttps://rulebook.fru.dev/regulations/us-tx-traiga
URL:https://rulebook.fru.dev/regulations/us-tx-traiga
CATEGORIES:Texas,ai,biometrics
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-324@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20260101
DTEND;VALUE=DATE:20260102
SUMMARY:Vietnam PDPL: PDPL and Decree 356/2025 take effect
DESCRIPTION:Personal data protection obligations\, DPIA/TIA filing and pena
 lty framework apply\; Decree 13/2023 replaced.\n\nLaw on Personal Data Pro
 tection (Law No. 91/2025/QH15) (Vietnam)\n\nSource: https://vanban.chinhph
 u.vn/?pageid=27160&docid=214590\n\nhttps://rulebook.fru.dev/regulations/vn
 -pdpl
URL:https://rulebook.fru.dev/regulations/vn-pdpl
CATEGORIES:Vietnam,privacy,data-residency,children,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-312@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20260101
DTEND;VALUE=DATE:20260102
SUMMARY:Virginia VCDPA: Under-16 social media time limit (SB 854) takes eff
 ect
DESCRIPTION:Social media platforms must use commercially reasonable age det
 ermination and cap users under 16 at 1 hour/day unless a parent consents. 
 A preliminary injunction issued Feb 27\, 2026 bars enforcement.\n\nVirgini
 a Consumer Data Protection Act (SB 1392 / HB 2307\, 2021) (Virginia)\n\nSo
 urce: https://netchoice.org/wp-content/uploads/2026/02/Virginia-PI-Opinion
 _Granted.pdf\n\nhttps://rulebook.fru.dev/regulations/us-va-vcdpa
URL:https://rulebook.fru.dev/regulations/us-va-vcdpa
CATEGORIES:Virginia,privacy,children,online-safety
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-124@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20260122
DTEND;VALUE=DATE:20260123
SUMMARY:South Korea AI Basic Act: AI Basic Act and Enforcement Decree take 
 effect
DESCRIPTION:Transparency\, labeling\, high-impact AI\, and domestic represe
 ntative obligations apply (fines deferred during the grace period).\n\nFra
 mework Act on the Development of Artificial Intelligence and Establishment
  of a Foundation for Trust (AI Basic Act) (South Korea)\n\nSource: https:/
 /www.law.go.kr/법령/인공지능발전과신뢰기반조성등에관한
 기본법\n\nhttps://rulebook.fru.dev/regulations/kr-ai-basic-act
URL:https://rulebook.fru.dev/regulations/kr-ai-basic-act
CATEGORIES:South Korea,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-177@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20260131
DTEND;VALUE=DATE:20260201
SUMMARY:California Delete Act / DROP: Annual data broker registration deadl
 ine
DESCRIPTION:Data brokers must register with CalPrivacy and pay the annual f
 ee ($6\,000 for 2026) by January 31.\n\nCalifornia Delete Act (SB 362\, 20
 23)\, Cal. Civ. Code 1798.99.80 et seq.\, and DROP regulations (California
 )\n\nSource: https://www.cppa.ca.gov/data_brokers/\n\nhttps://rulebook.fru
 .dev/regulations/us-ca-delete-act
URL:https://rulebook.fru.dev/regulations/us-ca-delete-act
CATEGORIES:California,privacy,data-access
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-256@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20260131
DTEND;VALUE=DATE:20260201
SUMMARY:Minnesota Consumer Data Privacy Act (MCDPA): 30-day cure period exp
 ires
DESCRIPTION:The requirement that the AG send a warning letter and allow 30 
 days to cure before suing expires Jan 31\, 2026 (325M.20(a)).\n\nMinnesota
  Consumer Data Privacy Act (HF 4757\, 2024 Minn. Laws ch. 121\, art. 5)\, 
 Minn. Stat. 325M.10-325M.21 (Minnesota)\n\nSource: https://www.revisor.mn.
 gov/statutes/cite/325M.20\n\nhttps://rulebook.fru.dev/regulations/us-mn-mc
 dpa
URL:https://rulebook.fru.dev/regulations/us-mn-mcdpa
CATEGORIES:Minnesota,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-201@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20260201
DTEND;VALUE=DATE:20260202
SUMMARY:Colorado AI Act: Original effective date (superseded)
DESCRIPTION:Original SB 24-205 date\; postponed by SB 25B-004\, so no oblig
 ations applied.\n\nColorado SB 24-205 (Consumer Protections for Artificial
  Intelligence)\, as delayed by SB 25B-004 and repealed and reenacted by SB
  26-189 (Automated Decision-Making Technology) (Colorado)\n\nSource: https
 ://leg.colorado.gov/bills/sb24-205\n\nhttps://rulebook.fru.dev/regulations
 /us-co-ai-act
URL:https://rulebook.fru.dev/regulations/us-co-ai-act
CATEGORIES:Colorado,ai,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-150@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20260205
DTEND;VALUE=DATE:20260206
SUMMARY:Data (Use and Access) Act: Stage 3: main data protection changes co
 mmence
DESCRIPTION:Recognised legitimate interests\, ADM reforms\, DSAR changes\, 
 international transfer test\, cookie exemptions and PECR fines at UK GDPR 
 levels apply (Commencement No. 6 Regulations 2026\, reg. 2).\n\nData (Use 
 and Access) Act 2025 (United Kingdom)\n\nSource: https://www.legislation.g
 ov.uk/uksi/2026/82/contents/made\n\nhttps://rulebook.fru.dev/regulations/u
 k-duaa
URL:https://rulebook.fru.dev/regulations/uk-duaa
CATEGORIES:United Kingdom,privacy,data-access,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-155@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20260205
DTEND;VALUE=DATE:20260206
SUMMARY:UK GDPR: DUAA amendments to UK GDPR commence
DESCRIPTION:Main Data (Use and Access) Act 2025 Part 5 amendments (recognis
 ed legitimate interests\, ADM\, DSAR\, transfers\, cookies\, PECR fines) a
 pply.\n\nUK General Data Protection Regulation and Data Protection Act 201
 8 (United Kingdom)\n\nSource: https://www.legislation.gov.uk/uksi/2026/82/
 contents/made\n\nhttps://rulebook.fru.dev/regulations/uk-gdpr
URL:https://rulebook.fru.dev/regulations/uk-gdpr
CATEGORIES:United Kingdom,privacy,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-239@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20260216
DTEND;VALUE=DATE:20260217
SUMMARY:HIPAA: Notice of Privacy Practices updates (Part 2 alignment)
DESCRIPTION:Covered entities must update Notices of Privacy Practices under
  45 CFR 164.520 for the 2024 Part 2 (substance use disorder records) chang
 es\; this NPP piece survived the Purl vacatur.\n\nHIPAA Privacy\, Security
  and Breach Notification Rules (45 CFR Parts 160 and 164) (United States (
 Federal))\n\nSource: https://www.federalregister.gov/documents/2024/04/26/
 2024-08503/hipaa-privacy-rule-to-support-reproductive-health-care-privacy\
 n\nhttps://rulebook.fru.dev/regulations/us-hipaa
URL:https://rulebook.fru.dev/regulations/us-hipaa
CATEGORIES:United States (Federal),privacy,health,cybersecurity,breach-noti
 fication
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-313@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20260227
DTEND;VALUE=DATE:20260228
SUMMARY:Virginia VCDPA: SB 854 preliminarily enjoined (NetChoice v. Jones)
DESCRIPTION:E.D. Va. preliminarily enjoined enforcement of the SB 854 socia
 l media time-limit provisions on First Amendment grounds\; Virginia has ap
 pealed.\n\nVirginia Consumer Data Protection Act (SB 1392 / HB 2307\, 2021
 ) (Virginia)\n\nSource: https://netchoice.org/wp-content/uploads/2026/02/V
 irginia-PI-Opinion_Granted.pdf\n\nhttps://rulebook.fru.dev/regulations/us-
 va-vcdpa
URL:https://rulebook.fru.dev/regulations/us-va-vcdpa
CATEGORIES:Virginia,privacy,children,online-safety
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-321@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20260301
DTEND;VALUE=DATE:20260302
SUMMARY:Vietnam AI Law: AI Law takes effect
DESCRIPTION:Risk classification\, transparency and labeling obligations app
 ly to new AI systems.\n\nLaw on Artificial Intelligence (Law No. 134/2025/
 QH15) (Vietnam)\n\nSource: https://beta-en.mic.gov.vn/first-ever-law-on-ar
 tificial-intelligence-approved-197251215231241888.htm\n\nhttps://rulebook.
 fru.dev/regulations/vn-ai-law
URL:https://rulebook.fru.dev/regulations/vn-ai-law
CATEGORIES:Vietnam,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-125@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20260310
DTEND;VALUE=DATE:20260311
SUMMARY:South Korea PIPA: 2026 PIPA amendment promulgated (Act No. 21445)
DESCRIPTION:Amendment raising fines to 10% of revenue and adding CEO accoun
 tability promulgated.\n\nPersonal Information Protection Act (as amended b
 y Act No. 21445\, 2026) (South Korea)\n\nSource: https://www.law.go.kr/법
 령/개인정보보호법\n\nhttps://rulebook.fru.dev/regulations/kr-pipa
URL:https://rulebook.fru.dev/regulations/kr-pipa
CATEGORIES:South Korea,privacy,breach-notification,biometrics,data-residenc
 y
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-10@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20260317
DTEND;VALUE=DATE:20260318
SUMMARY:Brazil ECA Digital: ECA Digital in force
DESCRIPTION:Art. 41-A (as set by Law 15.352/2026\, following MP 1.319/2025)
  fixes entry into force on 17 March 2026.\n\nEstatuto Digital da Criança 
 e do Adolescente (Law No. 15.211/2025) (Brazil)\n\nSource: https://www.pla
 nalto.gov.br/ccivil_03/_ato2023-2026/2025/lei/L15211.htm\n\nhttps://rulebo
 ok.fru.dev/regulations/br-eca-digital
URL:https://rulebook.fru.dev/regulations/br-eca-digital
CATEGORIES:Brazil,children,online-safety,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-279@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20260327
DTEND;VALUE=DATE:20260328
SUMMARY:NY RAISE Act: Chapter amendment S8828 signed
DESCRIPTION:Chapter amendment (ch. 96) finalizes the RAISE Act text.\n\nNew
  York Responsible AI Safety and Education (RAISE) Act (S6953-B/A6453-B of 
 2025)\, as amended by chapter amendment S8828 of 2026 (New York)\n\nSource
 : https://www.nysenate.gov/legislation/bills/2025/S8828\n\nhttps://ruleboo
 k.fru.dev/regulations/us-ny-raise
URL:https://rulebook.fru.dev/regulations/us-ny-raise
CATEGORIES:New York,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-243@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20260401
DTEND;VALUE=DATE:20260402
SUMMARY:Illinois BIPA: Seventh Circuit: amendment applies retroactively
DESCRIPTION:Clay v. Union Pacific (No. 25-2185) holds the damages amendment
  is remedial and applies to pending cases.\n\nIllinois Biometric Informati
 on Privacy Act (740 ILCS 14)\, as amended by SB 2979 (Public Act 103-0769)
  (Illinois)\n\nSource: https://law.justia.com/cases/federal/appellate-cour
 ts/ca7/25-2185/25-2185-2026-04-01.html\n\nhttps://rulebook.fru.dev/regulat
 ions/us-il-bipa
URL:https://rulebook.fru.dev/regulations/us-il-bipa
CATEGORIES:Illinois,biometrics,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-253@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20260401
DTEND;VALUE=DATE:20260402
SUMMARY:Maryland Online Data Privacy Act (MODPA): MODPA applies to personal
  data processing
DESCRIPTION:The act applies to personal data processing activities from Apr
 il 1\, 2026 (Section 2 of ch. 455).\n\nMaryland Online Data Privacy Act of
  2024 (SB 541 / HB 567)\, Md. Code\, Com. Law 14-4601 et seq. (Maryland)\n
 \nSource: https://mgaleg.maryland.gov/2024RS/Chapters_noln/CH_455_sb0541e.
 pdf\n\nhttps://rulebook.fru.dev/regulations/us-md-modpa
URL:https://rulebook.fru.dev/regulations/us-md-modpa
CATEGORIES:Maryland,privacy,children,health,biometrics
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-160@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20260411
DTEND;VALUE=DATE:20260412
SUMMARY:UK Online Safety Act: Fee notification window closes (2026/27)
DESCRIPTION:Fee-liable providers must notify Ofcom before the notification 
 window for the first charging year closes.\n\nOnline Safety Act 2023 (Unit
 ed Kingdom)\n\nSource: https://www.ofcom.org.uk/online-safety/illegal-and-
 harmful-content/online-safety-fees-and-penalties\n\nhttps://rulebook.fru.d
 ev/regulations/uk-osa
URL:https://rulebook.fru.dev/regulations/uk-osa
CATEGORIES:United Kingdom,online-safety,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-277@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20260415
DTEND;VALUE=DATE:20260416
SUMMARY:NYDFS Cybersecurity Regulation (Part 500): Annual compliance notifi
 cation
DESCRIPTION:Annual certification or acknowledgment covering calendar year 2
 025 due.\n\nNew York DFS Cybersecurity Requirements for Financial Services
  Companies (23 NYCRR Part 500)\, Second Amendment (New York)\n\nSource: ht
 tps://www.dfs.ny.gov/cybersecurity/23-NYCRR-Part-500\n\nhttps://rulebook.f
 ru.dev/regulations/us-ny-dfs-500
URL:https://rulebook.fru.dev/regulations/us-ny-dfs-500
CATEGORIES:New York,cybersecurity,breach-notification,financial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-214@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20260422
DTEND;VALUE=DATE:20260423
SUMMARY:COPPA Rule: Full compliance with amended COPPA Rule
DESCRIPTION:Operators must comply with all amended provisions (separate thi
 rd-party disclosure consent\, written retention policy\, written security 
 program\, updated notices)\; excludes Safe Harbor provisions 312.11(d)(1)\
 , (d)(4) and (g)\, which had earlier dates.\n\nChildren's Online Privacy P
 rotection Rule (16 CFR Part 312)\, as amended April 2025 (United States (F
 ederal))\n\nSource: https://www.federalregister.gov/documents/2025/04/22/2
 025-05904/childrens-online-privacy-protection-rule\n\nhttps://rulebook.fru
 .dev/regulations/us-coppa
URL:https://rulebook.fru.dev/regulations/us-coppa
CATEGORIES:United States (Federal),privacy,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-136@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20260501
DTEND;VALUE=DATE:20260502
SUMMARY:New Zealand Privacy Act: IPP 3A indirect-collection notification ap
 plies
DESCRIPTION:Agencies collecting personal information from third parties mus
 t take reasonable steps to notify individuals\, subject to exceptions.\n\n
 Privacy Act 2020 (New Zealand)\, as amended by the Privacy Amendment Act 2
 025 (New Zealand)\n\nSource: https://www.justice.govt.nz/justice-sector-po
 licy/key-initiatives/enhancing-the-privacy-act/\n\nhttps://rulebook.fru.de
 v/regulations/nz-privacy-act
URL:https://rulebook.fru.dev/regulations/nz-privacy-act
CATEGORIES:New Zealand,privacy,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-202@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20260514
DTEND;VALUE=DATE:20260515
SUMMARY:Colorado AI Act: SB 26-189 signed (repeal and reenact)
DESCRIPTION:SB 26-189 replaces SB 24-205 with a narrower ADMT disclosure fr
 amework and moves the effective date to January 1\, 2027.\n\nColorado SB 2
 4-205 (Consumer Protections for Artificial Intelligence)\, as delayed by S
 B 25B-004 and repealed and reenacted by SB 26-189 (Automated Decision-Maki
 ng Technology) (Colorado)\n\nSource: https://leg.colorado.gov/bills/sb26-1
 89\n\nhttps://rulebook.fru.dev/regulations/us-co-ai-act
URL:https://rulebook.fru.dev/regulations/us-co-ai-act
CATEGORIES:Colorado,ai,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-246@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20260515
DTEND;VALUE=DATE:20260516
SUMMARY:Illinois AI in Employment Law (HB 3773): IDHR proposed notice rules
  published
DESCRIPTION:IDHR publishes proposed Subpart J rules on AI notice in the Ill
 inois Register.\n\nIllinois HB 3773 (Public Act 103-0804)\, amending the I
 llinois Human Rights Act on artificial intelligence in employment (Illinoi
 s)\n\nSource: https://ogletree.com/insights-resources/blog-posts/illinois-
 postpones-proposed-regulations-on-ai-in-employment/\n\nhttps://rulebook.fr
 u.dev/regulations/us-il-hb3773
URL:https://rulebook.fru.dev/regulations/us-il-hb3773
CATEGORIES:Illinois,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-299@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20260519
DTEND;VALUE=DATE:20260520
SUMMARY:TAKE IT DOWN Act: Platform notice-and-removal process required
DESCRIPTION:Covered platforms must have a clear notice-and-removal process 
 and remove valid reported content within 48 hours (Sec. 3\, one year after
  enactment).\n\nTools to Address Known Exploitation by Immobilizing Techno
 logical Deepfakes on Websites and Networks Act (TAKE IT DOWN Act) (United 
 States (Federal))\n\nSource: https://www.govinfo.gov/content/pkg/PLAW-119p
 ubl12/html/PLAW-119publ12.htm\n\nhttps://rulebook.fru.dev/regulations/us-t
 ake-it-down
URL:https://rulebook.fru.dev/regulations/us-take-it-down
CATEGORIES:United States (Federal),online-safety,ai,children,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-87@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20260521
DTEND;VALUE=DATE:20260522
SUMMARY:eIDAS 2 / EU Digital Identity Wallet: Legacy qualified trust servic
 e providers conformity report
DESCRIPTION:QTSPs qualified before 20 May 2024 had to submit a conformity a
 ssessment report proving compliance with Art 24(1)\, (1a) and (1b) by 21 M
 ay 2026.\n\nRegulation (EU) 2024/1183 amending Regulation (EU) No 910/2014
  as regards establishing the European Digital Identity Framework (eIDAS 2)
  (European Union)\n\nSource: https://eur-lex.europa.eu/eli/reg/2024/1183/o
 j\n\nhttps://rulebook.fru.dev/regulations/eu-eidas2
URL:https://rulebook.fru.dev/regulations/eu-eidas2
CATEGORIES:European Union,privacy,data-access,biometrics
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-247@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20260602
DTEND;VALUE=DATE:20260603
SUMMARY:Illinois AI in Employment Law (HB 3773): IDHR withdraws and postpon
 es proposed rules
DESCRIPTION:IDHR withdraws the Subpart J proposal and postpones the June 10
 \, 2026 hearing\; no new date announced.\n\nIllinois HB 3773 (Public Act 1
 03-0804)\, amending the Illinois Human Rights Act on artificial intelligen
 ce in employment (Illinois)\n\nSource: https://ogletree.com/insights-resou
 rces/blog-posts/illinois-postpones-proposed-regulations-on-ai-in-employmen
 t/\n\nhttps://rulebook.fru.dev/regulations/us-il-hb3773
URL:https://rulebook.fru.dev/regulations/us-il-hb3773
CATEGORIES:Illinois,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-297@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20260603
DTEND;VALUE=DATE:20260604
SUMMARY:SEC Regulation S-P: Smaller entities must comply
DESCRIPTION:Smaller covered institutions (24 months after Federal Register 
 publication) must comply with the amended Regulation S-P.\n\nRegulation S-
 P: Privacy of Consumer Financial Information and Safeguarding Customer Inf
 ormation (2024 amendments) (United States (Federal))\n\nSource: https://ww
 w.federalregister.gov/documents/2024/06/03/2024-11116/regulation-s-p-priva
 cy-of-consumer-financial-information-and-safeguarding-customer-information
 \n\nhttps://rulebook.fru.dev/regulations/us-sec-reg-sp
URL:https://rulebook.fru.dev/regulations/us-sec-reg-sp
CATEGORIES:United States (Federal),financial,privacy,cybersecurity,breach-n
 otification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-49@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20260611
DTEND;VALUE=DATE:20260612
SUMMARY:Cyber Resilience Act: Conformity assessment body provisions apply
DESCRIPTION:Chapter IV (Arts 35-51\, notification of conformity assessment 
 bodies) applies (Art 71(2)).\n\nRegulation (EU) 2024/2847 on horizontal cy
 bersecurity requirements for products with digital elements (Cyber Resilie
 nce Act) (European Union)\n\nSource: https://eur-lex.europa.eu/eli/reg/202
 4/2847/oj\n\nhttps://rulebook.fru.dev/regulations/eu-cra
URL:https://rulebook.fru.dev/regulations/eu-cra
CATEGORIES:European Union,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-15@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20260615
DTEND;VALUE=DATE:20260616
SUMMARY:Canada Bill C-36 (PPCDA): Bill C-36 tabled (first reading)
DESCRIPTION:Government introduces the PPCDA in the House of Commons.\n\nBil
 l C-36\, An Act to enact the Protecting Privacy and Consumer Data Act (Can
 ada)\n\nSource: https://www.parl.ca/DocumentViewer/en/45-1/bill/C-36/first
 -reading\n\nhttps://rulebook.fru.dev/regulations/ca-c36-ppcda
URL:https://rulebook.fru.dev/regulations/ca-c36-ppcda
CATEGORIES:Canada,privacy,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-17@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20260615
DTEND;VALUE=DATE:20260616
SUMMARY:Canada Bill C-8 / CCSPA: Royal Assent
DESCRIPTION:Bill C-8 receives Royal Assent (S.C. 2026\, c. 9)\; Telecommuni
 cations Act amendments take effect.\n\nCritical Cyber Systems Protection A
 ct (enacted by Bill C-8\, An Act respecting cyber security) (Canada)\n\nSo
 urce: https://www.parl.ca/legisinfo/en/bill/45-1/c-8\n\nhttps://rulebook.f
 ru.dev/regulations/ca-ccspa
URL:https://rulebook.fru.dev/regulations/ca-ccspa
CATEGORIES:Canada,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-146@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20260616
DTEND;VALUE=DATE:20260617
SUMMARY:UK Cyber Security and Resilience Bill: Passes House of Commons
DESCRIPTION:Report stage and third reading completed in the Commons after c
 arry-over into the new session.\n\nCyber Security and Resilience (Network 
 and Information Systems) Bill (United Kingdom)\n\nSource: https://bills.pa
 rliament.uk/bills/4035\n\nhttps://rulebook.fru.dev/regulations/uk-csr-bill
URL:https://rulebook.fru.dev/regulations/uk-csr-bill
CATEGORIES:United Kingdom,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-151@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20260619
DTEND;VALUE=DATE:20260620
SUMMARY:Data (Use and Access) Act: Mandatory data protection complaints pro
 cedure
DESCRIPTION:Controllers must have a process for data subject complaints (s.
 103 and Sch. 10)\, per Commencement No. 6 Regulations 2026\, reg. 3.\n\nDa
 ta (Use and Access) Act 2025 (United Kingdom)\n\nSource: https://www.legis
 lation.gov.uk/uksi/2026/82/contents/made\n\nhttps://rulebook.fru.dev/regul
 ations/uk-duaa
URL:https://rulebook.fru.dev/regulations/uk-duaa
CATEGORIES:United Kingdom,privacy,data-access,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-203@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20260630
DTEND;VALUE=DATE:20260701
SUMMARY:Colorado AI Act: Delayed effective date (superseded)
DESCRIPTION:SB 25B-004 date\; superseded by SB 26-189 before it arrived\, s
 o no obligations applied.\n\nColorado SB 24-205 (Consumer Protections for 
 Artificial Intelligence)\, as delayed by SB 25B-004 and repealed and reena
 cted by SB 26-189 (Automated Decision-Making Technology) (Colorado)\n\nSou
 rce: https://leg.colorado.gov/bills/sb25b-004\n\nhttps://rulebook.fru.dev/
 regulations/us-co-ai-act
URL:https://rulebook.fru.dev/regulations/us-co-ai-act
CATEGORIES:Colorado,ai,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-267@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20260630
DTEND;VALUE=DATE:20260701
SUMMARY:New Jersey NJDPA: A5328 sensitive data sale ban takes effect
DESCRIPTION:A5328\, signed June 30\, 2026\, prohibits selling sensitive per
 sonal data\; the ban took effect on signing.\n\nNew Jersey Data Privacy Ac
 t (P.L.2023\, c.266\; S332) (New Jersey)\n\nSource: https://www.njleg.stat
 e.nj.us/bill-search/2026/A5328\n\nhttps://rulebook.fru.dev/regulations/us-
 nj-njdpa
URL:https://rulebook.fru.dev/regulations/us-nj-njdpa
CATEGORIES:New Jersey,privacy,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-218@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20260701
DTEND;VALUE=DATE:20260702
SUMMARY:Connecticut Data Privacy Act (CTDPA): PA 25-113 (SB 1295) amendment
 s take effect
DESCRIPTION:Thresholds drop to 35\,000 consumers or any sensitive-data proc
 essing or data sale\; expanded sensitive data\, minors' protections\, and 
 LLM-training disclosure in privacy notices.\n\nConnecticut Data Privacy Ac
 t (Public Act 22-15)\, Conn. Gen. Stat. 42-515 et seq.\, as amended by Pub
 lic Act 25-113 (SB 1295) and Public Act 26-64 (SB 4) (Connecticut)\n\nSour
 ce: https://www.cga.ct.gov/2025/ACT/PA/PDF/2025PA-00113-R00SB-01295-PA.PDF
 \n\nhttps://rulebook.fru.dev/regulations/us-ct-ctdpa
URL:https://rulebook.fru.dev/regulations/us-ct-ctdpa
CATEGORIES:Connecticut,privacy,children,ai,health
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-268@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20260701
DTEND;VALUE=DATE:20260702
SUMMARY:New Jersey NJDPA: Mandatory 30-day cure period expires
DESCRIPTION:The Division's duty to issue a cure notice before enforcement e
 nds on the first day of the 18th month after the effective date (N.J.S.A. 
 56:8-166.17(b)).\n\nNew Jersey Data Privacy Act (P.L.2023\, c.266\; S332) 
 (New Jersey)\n\nSource: https://pub.njleg.state.nj.us/Bills/2022/PL23/266_
 .PDF\n\nhttps://rulebook.fru.dev/regulations/us-nj-njdpa
URL:https://rulebook.fru.dev/regulations/us-nj-njdpa
CATEGORIES:New Jersey,privacy,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-309@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20260701
DTEND;VALUE=DATE:20260702
SUMMARY:Utah UCPA: Right to correct takes effect
DESCRIPTION:Consumers may ask controllers to correct inaccurate personal da
 ta (13-61-201(4)\, as amended by Laws 2025\, ch. 468).\n\nUtah Consumer Pr
 ivacy Act (SB 227\, 2022) (Utah)\n\nSource: https://le.utah.gov/xcode/Titl
 e13/Chapter61/13-61-S201.html\n\nhttps://rulebook.fru.dev/regulations/us-u
 t-ucpa
URL:https://rulebook.fru.dev/regulations/us-ut-ucpa
CATEGORIES:Utah,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-314@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20260701
DTEND;VALUE=DATE:20260702
SUMMARY:Virginia VCDPA: Ban on selling precise geolocation data (SB 338)
DESCRIPTION:Controllers may not sell consumers' precise geolocation data (1
 \,750-ft radius)\, replacing the prior consent-based treatment.\n\nVirgini
 a Consumer Data Protection Act (SB 1392 / HB 2307\, 2021) (Virginia)\n\nSo
 urce: https://lis.virginia.gov/bill-details/20261/SB338\n\nhttps://ruleboo
 k.fru.dev/regulations/us-va-vcdpa
URL:https://rulebook.fru.dev/regulations/us-va-vcdpa
CATEGORIES:Virginia,privacy,children,online-safety
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-122@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20260717
DTEND;VALUE=DATE:20260718
SUMMARY:Japan APPI: 2026 APPI amendment act promulgated
DESCRIPTION:Amendment enacted by the Diet on 10 July 2026 and promulgated\;
  main provisions take effect by cabinet order within two years of promulga
 tion.\n\nAct on the Protection of Personal Information (Act No. 57 of 2003
 )\, as amended including the 2026 amendment act (Japan)\n\nSource: https:/
 /www.ppc.go.jp/files/pdf/260731_shiryou-1.pdf\n\nhttps://rulebook.fru.dev/
 regulations/jp-appi
URL:https://rulebook.fru.dev/regulations/jp-appi
CATEGORIES:Japan,privacy,children,biometrics,breach-notification,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-40@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20260727
DTEND;VALUE=DATE:20260728
SUMMARY:EU AI Act: Digital Omnibus on AI enters into force
DESCRIPTION:Regulation (EU) 2026/1744 (adopted 8 July 2026\, OJ 24 July 202
 6) enters into force on the third day after publication. Amended Articles 
 102 to 110 apply from this date (new Art 113(d)).\n\nRegulation (EU) 2024/
 1689 laying down harmonised rules on artificial intelligence (Artificial I
 ntelligence Act)\, as amended by Regulation (EU) 2026/1744 (Digital Omnibu
 s on AI) (European Union)\n\nSource: https://eur-lex.europa.eu/eli/reg/202
 6/1744/oj\n\nhttps://rulebook.fru.dev/regulations/eu-ai-act
URL:https://rulebook.fru.dev/regulations/eu-ai-act
CATEGORIES:European Union,ai,biometrics,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-178@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20260801
DTEND;VALUE=DATE:20260802
SUMMARY:California Delete Act / DROP: Data brokers must begin processing DR
 OP deletion requests
DESCRIPTION:Brokers must access DROP at least every 45 days\, process verif
 ied deletion requests within 45 days\, and treat unverified requests as op
 t-outs of sale/sharing.\n\nCalifornia Delete Act (SB 362\, 2023)\, Cal. Ci
 v. Code 1798.99.80 et seq.\, and DROP regulations (California)\n\nSource: 
 https://www.cppa.ca.gov/data_brokers/\n\nhttps://rulebook.fru.dev/regulati
 ons/us-ca-delete-act
URL:https://rulebook.fru.dev/regulations/us-ca-delete-act
CATEGORIES:California,privacy,data-access
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-219@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20260801
DTEND;VALUE=DATE:20260802
SUMMARY:Connecticut Data Privacy Act (CTDPA): Profiling impact assessments 
 apply
DESCRIPTION:Impact assessment requirements apply to profiling activities cr
 eated or generated on or after Aug 1\, 2026 (Conn. Gen. Stat. 42-522 as am
 ended).\n\nConnecticut Data Privacy Act (Public Act 22-15)\, Conn. Gen. St
 at. 42-515 et seq.\, as amended by Public Act 25-113 (SB 1295) and Public 
 Act 26-64 (SB 4) (Connecticut)\n\nSource: https://www.cga.ct.gov/2025/ACT/
 PA/PDF/2025PA-00113-R00SB-01295-PA.PDF\n\nhttps://rulebook.fru.dev/regulat
 ions/us-ct-ctdpa
URL:https://rulebook.fru.dev/regulations/us-ct-ctdpa
CATEGORIES:Connecticut,privacy,children,ai,health
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-190@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20260802
DTEND;VALUE=DATE:20260803
SUMMARY:California AI Transparency Act (SB 942): Covered provider duties ap
 ply
DESCRIPTION:Detection tool\, manifest and latent disclosures\, and license-
 revocation duties become operative.\n\nCalifornia AI Transparency Act (SB 
 942\, Stats. 2024\, ch. 291)\, as amended by AB 853 (Stats. 2025\, ch. 674
 ) (California)\n\nSource: https://leginfo.legislature.ca.gov/faces/billNav
 Client.xhtml?bill_id=202520260AB853\n\nhttps://rulebook.fru.dev/regulation
 s/us-ca-sb942
URL:https://rulebook.fru.dev/regulations/us-ca-sb942
CATEGORIES:California,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-41@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20260802
DTEND;VALUE=DATE:20260803
SUMMARY:EU AI Act: General application: transparency obligations\, GPAI fin
 es\, most other rules
DESCRIPTION:The AI Act's general date of application. Article 50 transparen
 cy obligations (chatbot disclosure\, deepfake labelling\, machine-readable
  marking of synthetic content) and Commission fines on GPAI providers (Art
  101) apply. Not deferred by the Omnibus.\n\nRegulation (EU) 2024/1689 lay
 ing down harmonised rules on artificial intelligence (Artificial Intellige
 nce Act)\, as amended by Regulation (EU) 2026/1744 (Digital Omnibus on AI)
  (European Union)\n\nSource: https://eur-lex.europa.eu/eli/reg/2024/1689/o
 j\n\nhttps://rulebook.fru.dev/regulations/eu-ai-act
URL:https://rulebook.fru.dev/regulations/eu-ai-act
CATEGORIES:European Union,ai,biometrics,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-79@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20260831
DTEND;VALUE=DATE:20260901
SUMMARY:Digital Services Act: ChatGPT designated as VLOSE\; Reddit and Robl
 ox as VLOPs
DESCRIPTION:Commission designated ChatGPT as a very large online search eng
 ine and Reddit and Roblox as very large online platforms. They have four m
 onths (by January 2027) to meet VLOP/VLOSE obligations.\n\nRegulation (EU)
  2022/2065 on a Single Market for Digital Services (Digital Services Act) 
 (European Union)\n\nSource: https://digital-strategy.ec.europa.eu/en/news/
 commission-designates-chatgpt-reddit-roblox-under-digital-services-act\n\n
 https://rulebook.fru.dev/regulations/eu-dsa
URL:https://rulebook.fru.dev/regulations/eu-dsa
CATEGORIES:European Union,online-safety,children,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-50@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20260911
DTEND;VALUE=DATE:20260912
SUMMARY:Cyber Resilience Act: Vulnerability and incident reporting obligati
 ons apply
DESCRIPTION:Art 14: manufacturers must report actively exploited vulnerabil
 ities and severe incidents (24-hour early warning\, 72-hour notification) 
 via the single reporting platform. Also covers products placed on the mark
 et before 11 Dec 2027 (Art 69(3)).\n\nRegulation (EU) 2024/2847 on horizon
 tal cybersecurity requirements for products with digital elements (Cyber R
 esilience Act) (European Union)\n\nSource: https://eur-lex.europa.eu/eli/r
 eg/2024/2847/oj\n\nhttps://rulebook.fru.dev/regulations/eu-cra
URL:https://rulebook.fru.dev/regulations/eu-cra
CATEGORIES:European Union,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-126@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20260911
DTEND;VALUE=DATE:20260912
SUMMARY:South Korea PIPA: 2026 PIPA amendments take effect
DESCRIPTION:10%-of-revenue fines\, CEO accountability\, and notice duties f
 or possible breaches apply.\n\nPersonal Information Protection Act (as ame
 nded by Act No. 21445\, 2026) (South Korea)\n\nSource: https://www.law.go.
 kr/법령/개인정보보호법\n\nhttps://rulebook.fru.dev/regulations/kr
 -pipa
URL:https://rulebook.fru.dev/regulations/kr-pipa
CATEGORIES:South Korea,privacy,breach-notification,biometrics,data-residenc
 y
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-59@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20260912
DTEND;VALUE=DATE:20260913
SUMMARY:EU Data Act: Access-by-design for new connected products
DESCRIPTION:Art 3(1) design obligation (product data and related service da
 ta accessible to the user by default) applies to connected products and re
 lated services placed on the market after 12 Sep 2026.\n\nRegulation (EU) 
 2023/2854 on harmonised rules on fair access to and use of data (Data Act)
  (European Union)\n\nSource: https://eur-lex.europa.eu/eli/reg/2023/2854/o
 j\n\nhttps://rulebook.fru.dev/regulations/eu-data-act
URL:https://rulebook.fru.dev/regulations/eu-data-act
CATEGORIES:European Union,data-access,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-152@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20260930
DTEND;VALUE=DATE:20261001
SUMMARY:Data (Use and Access) Act: ICO abolished\; Information Commission t
 akes over
DESCRIPTION:Sections 118-119 commence: office of Information Commissioner a
 bolished and functions transferred to the Information Commission (Commence
 ment No. 9 Regulations 2026).\n\nData (Use and Access) Act 2025 (United Ki
 ngdom)\n\nSource: https://www.legislation.gov.uk/uksi/2026/1015/regulation
 /2/made\n\nhttps://rulebook.fru.dev/regulations/uk-duaa
URL:https://rulebook.fru.dev/regulations/uk-duaa
CATEGORIES:United Kingdom,privacy,data-access,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-220@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20261001
DTEND;VALUE=DATE:20261002
SUMMARY:Connecticut Data Privacy Act (CTDPA): PA 26-64 (SB 4) amendments ta
 ke effect
DESCRIPTION:Prohibits controllers and third parties from selling precise ge
 olocation data and enacts data broker and other consumer protection provis
 ions.\n\nConnecticut Data Privacy Act (Public Act 22-15)\, Conn. Gen. Stat
 . 42-515 et seq.\, as amended by Public Act 25-113 (SB 1295) and Public Ac
 t 26-64 (SB 4) (Connecticut)\n\nSource: https://www.cga.ct.gov/2026/ACT/PA
 /PDF/2026PA-00064-R00SB-00004-PA.PDF\n\nhttps://rulebook.fru.dev/regulatio
 ns/us-ct-ctdpa
URL:https://rulebook.fru.dev/regulations/us-ct-ctdpa
CATEGORIES:Connecticut,privacy,children,ai,health
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-147@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20261026
DTEND;VALUE=DATE:20261027
SUMMARY:UK Cyber Security and Resilience Bill: Lords report stage scheduled
DESCRIPTION:House of Lords report stage scheduled (committee stage sat 1\, 
 3 and 7 Sept 2026).\n\nTentative: depends on a proposal not yet adopted.\n
 \nCyber Security and Resilience (Network and Information Systems) Bill (Un
 ited Kingdom)\n\nSource: https://bills.parliament.uk/bills/4035\n\nhttps:/
 /rulebook.fru.dev/regulations/uk-csr-bill
URL:https://rulebook.fru.dev/regulations/uk-csr-bill
CATEGORIES:United Kingdom,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-196@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20261110
DTEND;VALUE=DATE:20261111
SUMMARY:CMMC 2.0: Phase 2: Level 2 C3PAO certification
DESCRIPTION:Phase 2 begins one calendar year after Phase 1\; applicable sol
 icitations require CMMC Level 2 third-party (C3PAO) certification (32 CFR 
 170.3(e)(2)).\n\nCybersecurity Maturity Model Certification (CMMC) Program
  (32 CFR Part 170) and DFARS acquisition rule (48 CFR Parts 204\, 212\, 21
 7\, 252) (United States (Federal))\n\nSource: https://www.federalregister.
 gov/documents/2024/10/15/2024-22905/cybersecurity-maturity-model-certifica
 tion-cmmc-program\n\nhttps://rulebook.fru.dev/regulations/us-cmmc
URL:https://rulebook.fru.dev/regulations/us-cmmc
CATEGORIES:United States (Federal),cybersecurity
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-117@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20261113
DTEND;VALUE=DATE:20261114
SUMMARY:India DPDP Act: Consent Manager registration rule in force (12 mont
 hs)
DESCRIPTION:Rule 4 (registration and obligations of Consent Managers) comes
  into force one year after publication.\n\nDigital Personal Data Protectio
 n Act\, 2023 and Digital Personal Data Protection Rules\, 2025 (India)\n\n
 Source: https://egazette.gov.in/WriteReadData/2025/267650.pdf\n\nhttps://r
 ulebook.fru.dev/regulations/in-dpdp
URL:https://rulebook.fru.dev/regulations/in-dpdp
CATEGORIES:India,privacy,children,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-27@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20261201
DTEND;VALUE=DATE:20261202
SUMMARY:Chile Personal Data Protection Law (Ley 21.719): Law in force
DESCRIPTION:Main obligations apply and the Personal Data Protection Agency 
 begins supervision.\n\nLey Nº 21.719 que regula la protección y el trata
 miento de los datos personales y crea la Agencia de Protección de Datos P
 ersonales (Chile)\n\nSource: https://www.bcn.cl/leychile/navegar?idNorma=1
 209272\n\nhttps://rulebook.fru.dev/regulations/cl-pdpl
URL:https://rulebook.fru.dev/regulations/cl-pdpl
CATEGORIES:Chile,privacy,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-42@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20261202
DTEND;VALUE=DATE:20261203
SUMMARY:EU AI Act: New bans on sexual deepfakes and CSAM generation\; Art 5
 0(2) grace period ends
DESCRIPTION:New Art 5(1)(ba)/(bb) prohibitions on AI systems that generate 
 non-consensual intimate imagery of identifiable persons or child sexual ab
 use material apply. Generative AI systems placed on the market before 2 Au
 g 2026 must comply with the Art 50(2) marking duty by this date (new Art 1
 11(4)).\n\nRegulation (EU) 2024/1689 laying down harmonised rules on artif
 icial intelligence (Artificial Intelligence Act)\, as amended by Regulatio
 n (EU) 2026/1744 (Digital Omnibus on AI) (European Union)\n\nSource: https
 ://eur-lex.europa.eu/eli/reg/2026/1744/oj\n\nhttps://rulebook.fru.dev/regu
 lations/eu-ai-act
URL:https://rulebook.fru.dev/regulations/eu-ai-act
CATEGORIES:European Union,ai,biometrics,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-107@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20261209
DTEND;VALUE=DATE:20261210
SUMMARY:Product Liability Directive: Transposition deadline\; old PLD repea
 led
DESCRIPTION:Member States must transpose by 9 Dec 2026 (Art 22). Directive 
 85/374/EEC is repealed from that date but still applies to products placed
  on the market before it (Art 21).\n\nDirective (EU) 2024/2853 on liabilit
 y for defective products (new Product Liability Directive) (European Union
 )\n\nSource: https://eur-lex.europa.eu/eli/dir/2024/2853/oj\n\nhttps://rul
 ebook.fru.dev/regulations/eu-pld
URL:https://rulebook.fru.dev/regulations/eu-pld
CATEGORIES:European Union,ai,cybersecurity
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20261210
DTEND;VALUE=DATE:20261211
SUMMARY:Australia Privacy Act: Children's Online Privacy Code must be regis
 tered
DESCRIPTION:OAIC must develop and register the Children's Online Privacy Co
 de within 24 months of Royal Assent.\n\nPrivacy Act 1988 (Cth)\, as amende
 d by the Privacy and Other Legislation Amendment Act 2024 (Australia)\n\nS
 ource: https://www.oaic.gov.au/privacy/privacy-registers/privacy-codes/chi
 ldrens-online-privacy-code\n\nhttps://rulebook.fru.dev/regulations/au-priv
 acy-act
URL:https://rulebook.fru.dev/regulations/au-privacy-act
CATEGORIES:Australia,privacy,children,breach-notification,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-7@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20261210
DTEND;VALUE=DATE:20261211
SUMMARY:Australia Privacy Act: Automated decision-making transparency appli
 es
DESCRIPTION:Privacy policies must disclose the kinds of personal informatio
 n used in substantially automated decisions that significantly affect indi
 viduals (24 months after assent).\n\nPrivacy Act 1988 (Cth)\, as amended b
 y the Privacy and Other Legislation Amendment Act 2024 (Australia)\n\nSour
 ce: https://www.legislation.gov.au/C2024A00128/asmade\n\nhttps://rulebook.
 fru.dev/regulations/au-privacy-act
URL:https://rulebook.fru.dev/regulations/au-privacy-act
CATEGORIES:Australia,privacy,children,breach-notification,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-88@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20261224
DTEND;VALUE=DATE:20261225
SUMMARY:eIDAS 2 / EU Digital Identity Wallet: Member States must provide EU
  Digital Identity Wallets
DESCRIPTION:Each Member State must provide at least one wallet within 24 mo
 nths of the entry into force of the implementing acts under Arts 5a(23) an
 d 5c(6) (Art 5a(1)).\n\nRegulation (EU) 2024/1183 amending Regulation (EU)
  No 910/2014 as regards establishing the European Digital Identity Framewo
 rk (eIDAS 2) (European Union)\n\nSource: https://eur-lex.europa.eu/eli/reg
 _impl/2024/2977/oj\n\nhttps://rulebook.fru.dev/regulations/eu-eidas2
URL:https://rulebook.fru.dev/regulations/eu-eidas2
CATEGORIES:European Union,privacy,data-access,biometrics
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-191@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20270101
DTEND;VALUE=DATE:20270102
SUMMARY:California AI Transparency Act (SB 942): Large online platform and 
 hosting platform duties
DESCRIPTION:Large online platforms and GenAI hosting platforms must meet th
 e provenance duties added by AB 853.\n\nCalifornia AI Transparency Act (SB
  942\, Stats. 2024\, ch. 291)\, as amended by AB 853 (Stats. 2025\, ch. 67
 4) (California)\n\nSource: https://leginfo.legislature.ca.gov/faces/billNa
 vClient.xhtml?bill_id=202520260AB853\n\nhttps://rulebook.fru.dev/regulatio
 ns/us-ca-sb942
URL:https://rulebook.fru.dev/regulations/us-ca-sb942
CATEGORIES:California,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-186@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20270101
DTEND;VALUE=DATE:20270102
SUMMARY:California SB 53 (TFAIA): First OES anonymized incident report and 
 CDT definition review
DESCRIPTION:OES begins publishing annual anonymized incident summaries and 
 the Department of Technology begins annual review of the act's definitions
 \; the CalCompute framework report is due to the Legislature.\n\nCaliforni
 a SB 53\, Transparency in Frontier Artificial Intelligence Act (Stats. 202
 5\, ch. 138) (California)\n\nSource: https://leginfo.legislature.ca.gov/fa
 ces/billNavClient.xhtml?bill_id=202520260SB53\n\nhttps://rulebook.fru.dev/
 regulations/us-ca-sb53
URL:https://rulebook.fru.dev/regulations/us-ca-sb53
CATEGORIES:California,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-169@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20270101
DTEND;VALUE=DATE:20270102
SUMMARY:CCPA / CPRA: ADMT requirements compliance date
DESCRIPTION:Businesses using ADMT for significant decisions must comply wit
 h Article 11 (pre-use notice\, opt-out\, access rights) by this date (11 C
 CR 7200(b)).\n\nCalifornia Consumer Privacy Act of 2018\, as amended by th
 e California Privacy Rights Act of 2020 (Cal. Civ. Code 1798.100 et seq.) 
 and CPPA regulations (Cal. Code Regs. tit. 11\, 7000 et seq.) (California)
 \n\nSource: https://cppa.ca.gov/regulations/pdf/ccpa_updates_cyber_risk_ad
 mt_appr_text.pdf\n\nhttps://rulebook.fru.dev/regulations/us-ca-ccpa
URL:https://rulebook.fru.dev/regulations/us-ca-ccpa
CATEGORIES:California,privacy,ai,cybersecurity,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-170@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20270101
DTEND;VALUE=DATE:20270102
SUMMARY:CCPA / CPRA: Browsers must support opt-out preference signal (AB 56
 6)
DESCRIPTION:Businesses that develop or maintain a browser must include cons
 umer-configurable functionality to send an opt-out preference signal (Civ.
  Code 1798.136\, operative Jan 1\, 2027).\n\nCalifornia Consumer Privacy A
 ct of 2018\, as amended by the California Privacy Rights Act of 2020 (Cal.
  Civ. Code 1798.100 et seq.) and CPPA regulations (Cal. Code Regs. tit. 11
 \, 7000 et seq.) (California)\n\nSource: https://leginfo.legislature.ca.go
 v/faces/billStatusClient.xhtml?bill_id=202520260AB566\n\nhttps://rulebook.
 fru.dev/regulations/us-ca-ccpa
URL:https://rulebook.fru.dev/regulations/us-ca-ccpa
CATEGORIES:California,privacy,ai,cybersecurity,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-204@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20270101
DTEND;VALUE=DATE:20270102
SUMMARY:Colorado AI Act: ADMT obligations apply
DESCRIPTION:Developer documentation\, consumer notices\, post-adverse-outco
 me disclosure\, correction and human-review rights take effect.\n\nColorad
 o SB 24-205 (Consumer Protections for Artificial Intelligence)\, as delaye
 d by SB 25B-004 and repealed and reenacted by SB 26-189 (Automated Decisio
 n-Making Technology) (Colorado)\n\nSource: https://leg.colorado.gov/bills/
 sb26-189\n\nhttps://rulebook.fru.dev/regulations/us-co-ai-act
URL:https://rulebook.fru.dev/regulations/us-co-ai-act
CATEGORIES:Colorado,ai,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-205@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20270101
DTEND;VALUE=DATE:20270102
SUMMARY:Colorado AI Act: AG rules due
DESCRIPTION:Attorney General must adopt rules clarifying the post-adverse-o
 utcome disclosure requirements.\n\nColorado SB 24-205 (Consumer Protection
 s for Artificial Intelligence)\, as delayed by SB 25B-004 and repealed and
  reenacted by SB 26-189 (Automated Decision-Making Technology) (Colorado)\
 n\nSource: https://leg.colorado.gov/bills/sb26-189\n\nhttps://rulebook.fru
 .dev/regulations/us-co-ai-act
URL:https://rulebook.fru.dev/regulations/us-co-ai-act
CATEGORIES:Colorado,ai,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-221@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20270101
DTEND;VALUE=DATE:20270102
SUMMARY:Connecticut Data Privacy Act (CTDPA): Data broker registration requ
 ired
DESCRIPTION:Data brokers may not sell or license brokered personal data in 
 Connecticut unless registered with the Department of Consumer Protection (
 $2\,500 initial fee).\n\nConnecticut Data Privacy Act (Public Act 22-15)\,
  Conn. Gen. Stat. 42-515 et seq.\, as amended by Public Act 25-113 (SB 129
 5) and Public Act 26-64 (SB 4) (Connecticut)\n\nSource: https://www.cga.ct
 .gov/2026/ACT/PA/PDF/2026PA-00064-R00SB-00004-PA.PDF\n\nhttps://rulebook.f
 ru.dev/regulations/us-ct-ctdpa
URL:https://rulebook.fru.dev/regulations/us-ct-ctdpa
CATEGORIES:Connecticut,privacy,children,ai,health
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-226@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20270101
DTEND;VALUE=DATE:20270102
SUMMARY:Delaware Personal Data Privacy Act (DPDPA): Amended thresholds and 
 third-party duties take effect
DESCRIPTION:Applicability drops to 10\,000 consumers (or 5\,000 + 20% reven
 ue from sale) and new third-party duties (12D-107A) apply.\n\nDelaware Per
 sonal Data Privacy Act (HB 154)\, 6 Del. C. ch. 12D (Delaware)\n\nSource: 
 https://delcode.delaware.gov/title6/c012d/index.html\n\nhttps://rulebook.f
 ru.dev/regulations/us-de-dpdpa
URL:https://rulebook.fru.dev/regulations/us-de-dpdpa
CATEGORIES:Delaware,privacy,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-250@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20270101
DTEND;VALUE=DATE:20270102
SUMMARY:Louisiana Data Privacy Act: Louisiana Data Privacy Act takes effect
DESCRIPTION:Consumer rights and controller duties apply (Act 502\, Section 
 2)\; data protection assessment requirements apply to processing from this
  date.\n\nLouisiana Data Privacy Act (SB 386\, 2026 Regular Session\, Act 
 No. 502)\, La. R.S. 51:1780.1-1780.5 (Louisiana)\n\nSource: https://legis.
 la.gov/legis/ViewDocument.aspx?d=1480202\n\nhttps://rulebook.fru.dev/regul
 ations/us-la-ldpa
URL:https://rulebook.fru.dev/regulations/us-la-ldpa
CATEGORIES:Louisiana,privacy,biometrics
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-263@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20270101
DTEND;VALUE=DATE:20270102
SUMMARY:New Hampshire Privacy Act: Ban on selling personal data of children
  under 13 (HB 1460)
DESCRIPTION:HB 1460 (2026\, ch. 168) prohibits controllers from selling the
  personal data of a child under 13.\n\nNew Hampshire Privacy Act (SB 255\,
  2024)\, RSA chapter 507-H (New Hampshire)\n\nSource: https://gc.nh.gov/bi
 ll_status/billinfo.aspx?id=2443&inflect=2\n\nhttps://rulebook.fru.dev/regu
 lations/us-nh-privacy
URL:https://rulebook.fru.dev/regulations/us-nh-privacy
CATEGORIES:New Hampshire,privacy,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-280@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20270101
DTEND;VALUE=DATE:20270102
SUMMARY:NY RAISE Act: RAISE Act takes effect
DESCRIPTION:Transparency reports\, frontier AI frameworks\, incident report
 ing and DFS disclosure filings apply.\n\nNew York Responsible AI Safety an
 d Education (RAISE) Act (S6953-B/A6453-B of 2025)\, as amended by chapter 
 amendment S8828 of 2026 (New York)\n\nSource: https://www.nysenate.gov/leg
 islation/bills/2025/S8828\n\nhttps://rulebook.fru.dev/regulations/us-ny-ra
 ise
URL:https://rulebook.fru.dev/regulations/us-ny-raise
CATEGORIES:New York,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-282@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20270101
DTEND;VALUE=DATE:20270102
SUMMARY:Oklahoma OKCDPA: Oklahoma Consumer Data Privacy Act takes effect
DESCRIPTION:All OKCDPA obligations and consumer rights apply.\n\nOklahoma C
 onsumer Data Privacy Act (SB 546\, 2026) (Oklahoma)\n\nSource: https://www
 .okhouse.gov/posts/news-20260323_2\n\nhttps://rulebook.fru.dev/regulations
 /us-ok-okcdpa
URL:https://rulebook.fru.dev/regulations/us-ok-okcdpa
CATEGORIES:Oklahoma,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-310@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20270101
DTEND;VALUE=DATE:20270102
SUMMARY:Utah UCPA: UCPA extends to motor vehicle manufacturers
DESCRIPTION:Motor vehicle manufacturers whose vehicles are sold or leased i
 n Utah and that collect personal data through vehicle data systems are cov
 ered regardless of the revenue and consumer thresholds (13-61-102\, as ame
 nded by Laws 2026\, ch. 193).\n\nUtah Consumer Privacy Act (SB 227\, 2022)
  (Utah)\n\nSource: https://le.utah.gov/xcode/Title13/Chapter61/13-61-S102.
 html\n\nhttps://rulebook.fru.dev/regulations/us-ut-ucpa
URL:https://rulebook.fru.dev/regulations/us-ut-ucpa
CATEGORIES:Utah,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-60@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20270112
DTEND;VALUE=DATE:20270113
SUMMARY:EU Data Act: Cloud switching charges abolished
DESCRIPTION:Providers of data processing services may no longer impose any 
 switching charges on customers (Art 29(1)).\n\nRegulation (EU) 2023/2854 o
 n harmonised rules on fair access to and use of data (Data Act) (European 
 Union)\n\nSource: https://eur-lex.europa.eu/eli/reg/2023/2854/oj\n\nhttps:
 //rulebook.fru.dev/regulations/eu-data-act
URL:https://rulebook.fru.dev/regulations/eu-data-act
CATEGORIES:European Union,data-access,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-114@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20270116
DTEND;VALUE=DATE:20270117
SUMMARY:Indonesia PDP Law: Implementing regulation GR 33/2026 takes effect
DESCRIPTION:Detailed PDP implementing rules (DPIA\, cross-border\, children
 's consent) apply\, 6 months after the 16 Jul 2026 enactment.\n\nLaw No. 2
 7 of 2022 on Personal Data Protection (Undang-Undang Pelindungan Data Prib
 adi) (Indonesia)\n\nSource: https://www.kk-advocates.com/news/read/indones
 ia-gr-pdp-personal-data-protection-compliance-regime-new-phase\n\nhttps://
 rulebook.fru.dev/regulations/id-pdp
URL:https://rulebook.fru.dev/regulations/id-pdp
CATEGORIES:Indonesia,privacy,breach-notification,data-residency,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-179@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20270131
DTEND;VALUE=DATE:20270201
SUMMARY:California Delete Act / DROP: Annual data broker registration deadl
 ine
DESCRIPTION:Data brokers must renew registration with CalPrivacy by January
  31 following each year they meet the definition.\n\nCalifornia Delete Act
  (SB 362\, 2023)\, Cal. Civ. Code 1798.99.80 et seq.\, and DROP regulation
 s (California)\n\nSource: https://leginfo.legislature.ca.gov/faces/codes_d
 isplaySection.xhtml?lawCode=CIV&sectionNum=1798.99.82\n\nhttps://rulebook.
 fru.dev/regulations/us-ca-delete-act
URL:https://rulebook.fru.dev/regulations/us-ca-delete-act
CATEGORIES:California,privacy,data-access
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-322@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20270301
DTEND;VALUE=DATE:20270302
SUMMARY:Vietnam AI Law: Transition ends for existing AI systems (general)
DESCRIPTION:Existing AI systems in most sectors must comply (12-month trans
 ition).\n\nLaw on Artificial Intelligence (Law No. 134/2025/QH15) (Vietnam
 )\n\nSource: https://www.vilaf.com.vn/blog/vietnam-enacts-its-first-law-on
 -artificial-intelligence-key-regulatory-obligations-from-1-march-2026/\n\n
 https://rulebook.fru.dev/regulations/vn-ai-law
URL:https://rulebook.fru.dev/regulations/vn-ai-law
CATEGORIES:Vietnam,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-81@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20270326
DTEND;VALUE=DATE:20270327
SUMMARY:European Health Data Space (EHDS): EHDS general application date
DESCRIPTION:The regulation applies generally from 26 Mar 2027\, subject to 
 the phased exceptions below (final article).\n\nRegulation (EU) 2025/327 o
 n the European Health Data Space (European Union)\n\nSource: https://eur-l
 ex.europa.eu/eli/reg/2025/327/oj\n\nhttps://rulebook.fru.dev/regulations/e
 u-ehds
URL:https://rulebook.fru.dev/regulations/eu-ehds
CATEGORIES:European Union,health,privacy,data-access
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-254@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20270401
DTEND;VALUE=DATE:20270402
SUMMARY:Maryland Online Data Privacy Act (MODPA): Discretionary 60-day cure
  period ends
DESCRIPTION:The Division's discretionary notice-and-cure (at least 60 days)
  applies only to violations occurring on or before April 1\, 2027 (Com. La
 w 14-4614).\n\nMaryland Online Data Privacy Act of 2024 (SB 541 / HB 567)\
 , Md. Code\, Com. Law 14-4601 et seq. (Maryland)\n\nSource: https://mgaleg
 .maryland.gov/2024RS/Chapters_noln/CH_455_sb0541e.pdf\n\nhttps://rulebook.
 fru.dev/regulations/us-md-modpa
URL:https://rulebook.fru.dev/regulations/us-md-modpa
CATEGORIES:Maryland,privacy,children,health,biometrics
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-97@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20270402
DTEND;VALUE=DATE:20270403
SUMMARY:GDPR: GDPR Procedural Regulation applies
DESCRIPTION:Harmonised rules for cross-border complaint admissibility\, rig
 hts to be heard and access to preliminary findings\, and investigation tim
 elines apply to DPAs from 2 April 2027 (Regulation (EU) 2025/2518\, final 
 article).\n\nRegulation (EU) 2016/679 (General Data Protection Regulation)
  (European Union)\n\nSource: https://eur-lex.europa.eu/eli/reg/2025/2518/o
 j\n\nhttps://rulebook.fru.dev/regulations/eu-gdpr
URL:https://rulebook.fru.dev/regulations/eu-gdpr
CATEGORIES:European Union,privacy,breach-notification,data-access,children,
 biometrics,health
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-104@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20270417
DTEND;VALUE=DATE:20270418
SUMMARY:NIS2: Next biennial entity notification
DESCRIPTION:Competent authorities notify the Commission and Cooperation Gro
 up of the number of essential and important entities\, repeated every two 
 years after 17 Apr 2025 (Art 3(5)).\n\nDirective (EU) 2022/2555 on measure
 s for a high common level of cybersecurity across the Union (NIS2 Directiv
 e) (European Union)\n\nSource: https://eur-lex.europa.eu/eli/dir/2022/2555
 /oj\n\nhttps://rulebook.fru.dev/regulations/eu-nis2
URL:https://rulebook.fru.dev/regulations/eu-nis2
CATEGORIES:European Union,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-161@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20270501
DTEND;VALUE=DATE:20270502
SUMMARY:Alabama Personal Data Protection Act (APDPA): APDPA takes effect
DESCRIPTION:Consumer rights and controller/processor obligations apply (HB 
 351 section 12).\n\nAlabama Personal Data Protection Act (HB 351\, 2026 Re
 gular Session) (Alabama)\n\nSource: https://alison.legislature.state.al.us
 /files/pdf/SearchableInstruments/2026RS/HB351-enr.pdf\n\nhttps://rulebook.
 fru.dev/regulations/us-al-apdpa
URL:https://rulebook.fru.dev/regulations/us-al-apdpa
CATEGORIES:Alabama,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-118@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20270513
DTEND;VALUE=DATE:20270514
SUMMARY:India DPDP Act: Main data fiduciary obligations apply (18 months)
DESCRIPTION:Rules 3\, 5-16\, 22 and 23 (notice\, security safeguards\, brea
 ch notification\, retention\, children's consent\, SDF duties\, cross-bord
 er) come into force 18 months after publication.\n\nDigital Personal Data 
 Protection Act\, 2023 and Digital Personal Data Protection Rules\, 2025 (I
 ndia)\n\nSource: https://egazette.gov.in/WriteReadData/2025/267650.pdf\n\n
 https://rulebook.fru.dev/regulations/in-dpdp
URL:https://rulebook.fru.dev/regulations/in-dpdp
CATEGORIES:India,privacy,children,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-183@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20270701
DTEND;VALUE=DATE:20270702
SUMMARY:California SB 243 (companion chatbots): First annual report to Offi
 ce of Suicide Prevention
DESCRIPTION:Operators begin annual reporting on crisis referrals and detect
 ion protocols.\n\nCalifornia SB 243\, Companion Chatbots (Stats. 2025\, ch
 . 677) (California)\n\nSource: https://leginfo.legislature.ca.gov/faces/bi
 llNavClient.xhtml?bill_id=202520260SB243\n\nhttps://rulebook.fru.dev/regul
 ations/us-ca-sb243
URL:https://rulebook.fru.dev/regulations/us-ca-sb243
CATEGORIES:California,ai,children,online-safety
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-127@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20270701
DTEND;VALUE=DATE:20270702
SUMMARY:South Korea PIPA: Mandatory ISMS-P certification
DESCRIPTION:ISMS-P certification becomes mandatory for private entities mee
 ting the statutory criteria.\n\nPersonal Information Protection Act (as am
 ended by Act No. 21445\, 2026) (South Korea)\n\nSource: https://www.law.go
 .kr/법령/개인정보보호법\n\nhttps://rulebook.fru.dev/regulations/k
 r-pipa
URL:https://rulebook.fru.dev/regulations/kr-pipa
CATEGORIES:South Korea,privacy,breach-notification,biometrics,data-residenc
 y
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-307@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20270701
DTEND;VALUE=DATE:20270702
SUMMARY:Utah AI Policy Act: Scheduled repeal of Title 13\, Ch. 72
DESCRIPTION:SB 332 extends the AI Policy Act repeal date from May 1\, 2025 
 to July 1\, 2027.\n\nUtah Artificial Intelligence Policy Act (SB 149\, 202
 4)\, as amended by SB 226 and SB 332 (2025) (Utah)\n\nSource: https://le.u
 tah.gov/~2025/bills/static/SB0332.html\n\nhttps://rulebook.fru.dev/regulat
 ions/us-ut-aipa
URL:https://rulebook.fru.dev/regulations/us-ut-aipa
CATEGORIES:Utah,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-251@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20270731
DTEND;VALUE=DATE:20270801
SUMMARY:Louisiana Data Privacy Act: 30-day cure period expires
DESCRIPTION:AG's obligation to give 30-day notice and allow cure before inv
 estigating applies only from Jan 1 through July 31\, 2027 (R.S. 51:1780.5(
 D)).\n\nLouisiana Data Privacy Act (SB 386\, 2026 Regular Session\, Act No
 . 502)\, La. R.S. 51:1780.1-1780.5 (Louisiana)\n\nSource: https://legis.la
 .gov/legis/ViewDocument.aspx?d=1480202\n\nhttps://rulebook.fru.dev/regulat
 ions/us-la-ldpa
URL:https://rulebook.fru.dev/regulations/us-la-ldpa
CATEGORIES:Louisiana,privacy,biometrics
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-43@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20270802
DTEND;VALUE=DATE:20270803
SUMMARY:EU AI Act: Legacy GPAI models must comply\; national AI sandboxes o
 perational
DESCRIPTION:Providers of GPAI models placed on the market before 2 Aug 2025
  must comply (Art 111(3)). Each Member State must have at least one nation
 al AI regulatory sandbox operational (Art 57(1) as amended by the Omnibus)
 .\n\nRegulation (EU) 2024/1689 laying down harmonised rules on artificial 
 intelligence (Artificial Intelligence Act)\, as amended by Regulation (EU)
  2026/1744 (Digital Omnibus on AI) (European Union)\n\nSource: https://eur
 -lex.europa.eu/eli/reg/2024/1689/oj\n\nhttps://rulebook.fru.dev/regulation
 s/eu-ai-act
URL:https://rulebook.fru.dev/regulations/eu-ai-act
CATEGORIES:European Union,ai,biometrics,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-323@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20270901
DTEND;VALUE=DATE:20270902
SUMMARY:Vietnam AI Law: Transition ends for existing AI systems in health\,
  education and finance
DESCRIPTION:Existing AI systems in healthcare\, education and finance must 
 comply (18-month transition).\n\nLaw on Artificial Intelligence (Law No. 1
 34/2025/QH15) (Vietnam)\n\nSource: https://www.vilaf.com.vn/blog/vietnam-e
 nacts-its-first-law-on-artificial-intelligence-key-regulatory-obligations-
 from-1-march-2026/\n\nhttps://rulebook.fru.dev/regulations/vn-ai-law
URL:https://rulebook.fru.dev/regulations/vn-ai-law
CATEGORIES:Vietnam,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-61@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20270912
DTEND;VALUE=DATE:20270913
SUMMARY:EU Data Act: Unfair-terms rules extend to older long-term contracts
DESCRIPTION:Chapter IV (unfair contractual terms) applies to contracts conc
 luded on or before 12 Sep 2025 that are of indefinite duration or expire a
 t least 10 years from 11 Jan 2024 (Art 50).\n\nRegulation (EU) 2023/2854 o
 n harmonised rules on fair access to and use of data (Data Act) (European 
 Union)\n\nSource: https://eur-lex.europa.eu/eli/reg/2023/2854/oj\n\nhttps:
 //rulebook.fru.dev/regulations/eu-data-act
URL:https://rulebook.fru.dev/regulations/eu-data-act
CATEGORIES:European Union,data-access,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-105@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20271017
DTEND;VALUE=DATE:20271018
SUMMARY:NIS2: Commission review of NIS2
DESCRIPTION:Commission must review the functioning of NIS2 and report to Pa
 rliament and Council\, then every 36 months (Art 40).\n\nDirective (EU) 20
 22/2555 on measures for a high common level of cybersecurity across the Un
 ion (NIS2 Directive) (European Union)\n\nSource: https://eur-lex.europa.eu
 /eli/dir/2022/2555/oj\n\nhttps://rulebook.fru.dev/regulations/eu-nis2
URL:https://rulebook.fru.dev/regulations/eu-nis2
CATEGORIES:European Union,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-197@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20271110
DTEND;VALUE=DATE:20271111
SUMMARY:CMMC 2.0: Phase 3: Level 3 certification
DESCRIPTION:Phase 3 begins one year after Phase 2\; Level 3 (DIBCAC) requir
 ements added to applicable solicitations (32 CFR 170.3(e)(3)).\n\nCybersec
 urity Maturity Model Certification (CMMC) Program (32 CFR Part 170) and DF
 ARS acquisition rule (48 CFR Parts 204\, 212\, 217\, 252) (United States (
 Federal))\n\nSource: https://www.federalregister.gov/documents/2024/10/15/
 2024-22905/cybersecurity-maturity-model-certification-cmmc-program\n\nhttp
 s://rulebook.fru.dev/regulations/us-cmmc
URL:https://rulebook.fru.dev/regulations/us-cmmc
CATEGORIES:United States (Federal),cybersecurity
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-28@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20271201
DTEND;VALUE=DATE:20271202
SUMMARY:Chile Personal Data Protection Law (Ley 21.719): Proposed postponem
 ent of entry into force
DESCRIPTION:Government bill Boletin 18623-07 (filed 1 Sep 2026\, 'suma' urg
 ency) would replace the 24-month vacatio legis in transitional Art 1 with 
 a fixed date of 1 Dec 2027\; in first committee stage in the Senate\, not 
 law.\n\nTentative: depends on a proposal not yet adopted.\n\nLey Nº 21.71
 9 que regula la protección y el tratamiento de los datos personales y cre
 a la Agencia de Protección de Datos Personales (Chile)\n\nSource: https:/
 /tramitacion.senado.cl/appsenado/templates/tramitacion/index.php?boletin_i
 ni=18623-07\n\nhttps://rulebook.fru.dev/regulations/cl-pdpl
URL:https://rulebook.fru.dev/regulations/cl-pdpl
CATEGORIES:Chile,privacy,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-44@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20271202
DTEND;VALUE=DATE:20271203
SUMMARY:EU AI Act: High-risk obligations apply to Annex III systems
DESCRIPTION:Chapter III Sections 1-3 (high-risk requirements and provider/d
 eployer obligations) apply to AI systems classified high-risk under Art 6(
 2) and Annex III (employment\, credit scoring\, education\, biometrics\, e
 ssential services and similar). Deferred from 2 Aug 2026 by Regulation (EU
 ) 2026/1744.\n\nRegulation (EU) 2024/1689 laying down harmonised rules on 
 artificial intelligence (Artificial Intelligence Act)\, as amended by Regu
 lation (EU) 2026/1744 (Digital Omnibus on AI) (European Union)\n\nSource: 
 https://eur-lex.europa.eu/eli/reg/2026/1744/oj\n\nhttps://rulebook.fru.dev
 /regulations/eu-ai-act
URL:https://rulebook.fru.dev/regulations/eu-ai-act
CATEGORIES:European Union,ai,biometrics,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-51@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20271211
DTEND;VALUE=DATE:20271212
SUMMARY:Cyber Resilience Act: CRA fully applies
DESCRIPTION:All remaining obligations\, including essential cybersecurity r
 equirements\, conformity assessment and CE marking\, apply (Art 71(2)). Pr
 oducts placed on the market earlier are covered only if substantially modi
 fied (Art 69(2)).\n\nRegulation (EU) 2024/2847 on horizontal cybersecurity
  requirements for products with digital elements (Cyber Resilience Act) (E
 uropean Union)\n\nSource: https://eur-lex.europa.eu/eli/reg/2024/2847/oj\n
 \nhttps://rulebook.fru.dev/regulations/eu-cra
URL:https://rulebook.fru.dev/regulations/eu-cra
CATEGORIES:European Union,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-89@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20271224
DTEND;VALUE=DATE:20271225
SUMMARY:eIDAS 2 / EU Digital Identity Wallet: Private relying parties must 
 accept wallets
DESCRIPTION:Private relying parties required by law or contract to use stro
 ng user authentication must accept wallets on user request within 36 month
 s of the implementing acts' entry into force (Art 5f(2)).\n\nRegulation (E
 U) 2024/1183 amending Regulation (EU) No 910/2014 as regards establishing 
 the European Digital Identity Framework (eIDAS 2) (European Union)\n\nSour
 ce: https://eur-lex.europa.eu/eli/reg_impl/2024/2977/oj\n\nhttps://ruleboo
 k.fru.dev/regulations/eu-eidas2
URL:https://rulebook.fru.dev/regulations/eu-eidas2
CATEGORIES:European Union,privacy,data-access,biometrics
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-171@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20271231
DTEND;VALUE=DATE:20280101
SUMMARY:CCPA / CPRA: Risk assessments for pre-existing processing due
DESCRIPTION:Risk assessments must be completed and documented for high-risk
  processing that began before Jan 1\, 2026 and continues after (11 CCR 715
 5(b)).\n\nCalifornia Consumer Privacy Act of 2018\, as amended by the Cali
 fornia Privacy Rights Act of 2020 (Cal. Civ. Code 1798.100 et seq.) and CP
 PA regulations (Cal. Code Regs. tit. 11\, 7000 et seq.) (California)\n\nSo
 urce: https://cppa.ca.gov/regulations/pdf/ccpa_updates_cyber_risk_admt_app
 r_text.pdf\n\nhttps://rulebook.fru.dev/regulations/us-ca-ccpa
URL:https://rulebook.fru.dev/regulations/us-ca-ccpa
CATEGORIES:California,privacy,ai,cybersecurity,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-192@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20280101
DTEND;VALUE=DATE:20280102
SUMMARY:California AI Transparency Act (SB 942): Capture device manufacture
 r duties
DESCRIPTION:Capture device manufacturer provenance requirements become oper
 ative.\n\nCalifornia AI Transparency Act (SB 942\, Stats. 2024\, ch. 291)\
 , as amended by AB 853 (Stats. 2025\, ch. 674) (California)\n\nSource: htt
 ps://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=20252026
 0AB853\n\nhttps://rulebook.fru.dev/regulations/us-ca-sb942
URL:https://rulebook.fru.dev/regulations/us-ca-sb942
CATEGORIES:California,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-180@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20280101
DTEND;VALUE=DATE:20280102
SUMMARY:California Delete Act / DROP: Independent third-party audits begin
DESCRIPTION:Beginning Jan 1\, 2028 and every 3 years thereafter\, data brok
 ers must undergo an independent audit of Delete Act compliance.\n\nCalifor
 nia Delete Act (SB 362\, 2023)\, Cal. Civ. Code 1798.99.80 et seq.\, and D
 ROP regulations (California)\n\nSource: https://www.cppa.ca.gov/data_broke
 rs/\n\nhttps://rulebook.fru.dev/regulations/us-ca-delete-act
URL:https://rulebook.fru.dev/regulations/us-ca-delete-act
CATEGORIES:California,privacy,data-access
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-315@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20280101
DTEND;VALUE=DATE:20280102
SUMMARY:Vermont VDPOSA: Vermont Data Privacy and Online Surveillance Act ta
 kes effect
DESCRIPTION:All obligations under Act 145 apply (sec. 4).\n\nVermont Data P
 rivacy and Online Surveillance Act (S.71\, Act 145 of 2026) (Vermont)\n\nS
 ource: https://legislature.vermont.gov/Documents/2026/Docs/ACTS/ACT145/ACT
 145%20As%20Enacted.pdf\n\nhttps://rulebook.fru.dev/regulations/us-vt-vdpos
 a
URL:https://rulebook.fru.dev/regulations/us-vt-vdposa
CATEGORIES:Vermont,privacy,health,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-172@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20280401
DTEND;VALUE=DATE:20280402
SUMMARY:CCPA / CPRA: First risk assessment submission to CPPA
DESCRIPTION:Businesses must submit required risk assessment information and
  attestation for assessments conducted in 2026 and 2027 (11 CCR 7157(a)(1)
 )\; annually by April 1 thereafter.\n\nCalifornia Consumer Privacy Act of 
 2018\, as amended by the California Privacy Rights Act of 2020 (Cal. Civ. 
 Code 1798.100 et seq.) and CPPA regulations (Cal. Code Regs. tit. 11\, 700
 0 et seq.) (California)\n\nSource: https://cppa.ca.gov/regulations/pdf/ccp
 a_updates_cyber_risk_admt_appr_text.pdf\n\nhttps://rulebook.fru.dev/regula
 tions/us-ca-ccpa
URL:https://rulebook.fru.dev/regulations/us-ca-ccpa
CATEGORIES:California,privacy,ai,cybersecurity,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-173@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20280401
DTEND;VALUE=DATE:20280402
SUMMARY:CCPA / CPRA: Cybersecurity audit due: revenue over $100M
DESCRIPTION:First cybersecurity audit report (covering Jan 1\, 2027 - Jan 1
 \, 2028) and certification due for businesses with 2026 annual gross reven
 ue over $100M (11 CCR 7121(a)(1)).\n\nCalifornia Consumer Privacy Act of 2
 018\, as amended by the California Privacy Rights Act of 2020 (Cal. Civ. C
 ode 1798.100 et seq.) and CPPA regulations (Cal. Code Regs. tit. 11\, 7000
  et seq.) (California)\n\nSource: https://cppa.ca.gov/regulations/pdf/ccpa
 _updates_cyber_risk_admt_appr_text.pdf\n\nhttps://rulebook.fru.dev/regulat
 ions/us-ca-ccpa
URL:https://rulebook.fru.dev/regulations/us-ca-ccpa
CATEGORIES:California,privacy,ai,cybersecurity,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-52@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20280611
DTEND;VALUE=DATE:20280612
SUMMARY:Cyber Resilience Act: Legacy type-examination certificates expire
DESCRIPTION:EU type-examination certificates and approval decisions on cybe
 rsecurity requirements under other harmonisation legislation remain valid 
 until this date unless they expire earlier (Art 69(1)).\n\nRegulation (EU)
  2024/2847 on horizontal cybersecurity requirements for products with digi
 tal elements (Cyber Resilience Act) (European Union)\n\nSource: https://eu
 r-lex.europa.eu/eli/reg/2024/2847/oj\n\nhttps://rulebook.fru.dev/regulatio
 ns/eu-cra
URL:https://rulebook.fru.dev/regulations/eu-cra
CATEGORIES:European Union,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-45@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20280802
DTEND;VALUE=DATE:20280803
SUMMARY:EU AI Act: High-risk obligations apply to Annex I product-embedded 
 systems
DESCRIPTION:Chapter III Sections 1-3 apply to AI systems classified high-ri
 sk under Art 6(1) and Annex I (safety components of products covered by EU
  harmonisation legislation). Deferred from 2 Aug 2027 by Regulation (EU) 2
 026/1744.\n\nRegulation (EU) 2024/1689 laying down harmonised rules on art
 ificial intelligence (Artificial Intelligence Act)\, as amended by Regulat
 ion (EU) 2026/1744 (Digital Omnibus on AI) (European Union)\n\nSource: htt
 ps://eur-lex.europa.eu/eli/reg/2026/1744/oj\n\nhttps://rulebook.fru.dev/re
 gulations/eu-ai-act
URL:https://rulebook.fru.dev/regulations/eu-ai-act
CATEGORIES:European Union,ai,biometrics,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-53@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20280911
DTEND;VALUE=DATE:20280912
SUMMARY:Cyber Resilience Act: Report on single reporting platform
DESCRIPTION:Commission report assessing the single reporting platform's eff
 ectiveness (Art 70(2)).\n\nRegulation (EU) 2024/2847 on horizontal cyberse
 curity requirements for products with digital elements (Cyber Resilience A
 ct) (European Union)\n\nSource: https://eur-lex.europa.eu/eli/reg/2024/284
 7/oj\n\nhttps://rulebook.fru.dev/regulations/eu-cra
URL:https://rulebook.fru.dev/regulations/eu-cra
CATEGORIES:European Union,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-62@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20280912
DTEND;VALUE=DATE:20280913
SUMMARY:EU Data Act: Commission evaluation
DESCRIPTION:Commission evaluation report due\, including the impact of clou
 d switching rules (Arts 23-31) (Art 49(2)).\n\nRegulation (EU) 2023/2854 o
 n harmonised rules on fair access to and use of data (Data Act) (European 
 Union)\n\nSource: https://eur-lex.europa.eu/eli/reg/2023/2854/oj\n\nhttps:
 //rulebook.fru.dev/regulations/eu-data-act
URL:https://rulebook.fru.dev/regulations/eu-data-act
CATEGORIES:European Union,data-access,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-222@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20281001
DTEND;VALUE=DATE:20281002
SUMMARY:Connecticut Data Privacy Act (CTDPA): Data brokers must process sta
 te deletion mechanism requests
DESCRIPTION:Registered data brokers must access the DCP accessible deletion
  mechanism at least every 45 days and process deletion requests.\n\nConnec
 ticut Data Privacy Act (Public Act 22-15)\, Conn. Gen. Stat. 42-515 et seq
 .\, as amended by Public Act 25-113 (SB 1295) and Public Act 26-64 (SB 4) 
 (Connecticut)\n\nSource: https://www.cga.ct.gov/2026/ACT/PA/PDF/2026PA-000
 64-R00SB-00004-PA.PDF\n\nhttps://rulebook.fru.dev/regulations/us-ct-ctdpa
URL:https://rulebook.fru.dev/regulations/us-ct-ctdpa
CATEGORIES:Connecticut,privacy,children,ai,health
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-198@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20281110
DTEND;VALUE=DATE:20281111
SUMMARY:CMMC 2.0: Phase 4: full implementation
DESCRIPTION:CMMC requirements included in all applicable DoD solicitations 
 and contracts\, including option periods (32 CFR 170.3(e)(4)).\n\nCybersec
 urity Maturity Model Certification (CMMC) Program (32 CFR Part 170) and DF
 ARS acquisition rule (48 CFR Parts 204\, 212\, 217\, 252) (United States (
 Federal))\n\nSource: https://www.federalregister.gov/documents/2024/10/15/
 2024-22905/cybersecurity-maturity-model-certification-cmmc-program\n\nhttp
 s://rulebook.fru.dev/regulations/us-cmmc
URL:https://rulebook.fru.dev/regulations/us-cmmc
CATEGORIES:United States (Federal),cybersecurity
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-82@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20290326
DTEND;VALUE=DATE:20290327
SUMMARY:European Health Data Space (EHDS): Primary use for first data categ
 ories\; secondary use framework applies
DESCRIPTION:Patient rights and EHR rules apply to patient summaries\, ePres
 criptions and eDispensations (Art 14(1)(a)-(c)). Chapter IV secondary-use 
 rules (data permits\, Health Data Access Bodies) apply.\n\nRegulation (EU)
  2025/327 on the European Health Data Space (European Union)\n\nSource: ht
 tps://eur-lex.europa.eu/eli/reg/2025/327/oj\n\nhttps://rulebook.fru.dev/re
 gulations/eu-ehds
URL:https://rulebook.fru.dev/regulations/eu-ehds
CATEGORIES:European Union,health,privacy,data-access
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-174@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20290401
DTEND;VALUE=DATE:20290402
SUMMARY:CCPA / CPRA: Cybersecurity audit due: revenue $50M-$100M
DESCRIPTION:First cybersecurity audit report (covering 2028) due for busine
 sses with 2027 annual gross revenue between $50M and $100M (11 CCR 7121(a)
 (2)).\n\nCalifornia Consumer Privacy Act of 2018\, as amended by the Calif
 ornia Privacy Rights Act of 2020 (Cal. Civ. Code 1798.100 et seq.) and CPP
 A regulations (Cal. Code Regs. tit. 11\, 7000 et seq.) (California)\n\nSou
 rce: https://cppa.ca.gov/regulations/pdf/ccpa_updates_cyber_risk_admt_appr
 _text.pdf\n\nhttps://rulebook.fru.dev/regulations/us-ca-ccpa
URL:https://rulebook.fru.dev/regulations/us-ca-ccpa
CATEGORIES:California,privacy,ai,cybersecurity,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-316@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20290630
DTEND;VALUE=DATE:20290701
SUMMARY:Vermont VDPOSA: Mandatory 60-day cure period expires
DESCRIPTION:The AG's duty to issue a cure notice before enforcement ends Ju
 ne 30\, 2029 (Act 145 sec. 3).\n\nVermont Data Privacy and Online Surveill
 ance Act (S.71\, Act 145 of 2026) (Vermont)\n\nSource: https://legislature
 .vermont.gov/Documents/2026/Docs/ACTS/ACT145/ACT145%20As%20Enacted.pdf\n\n
 https://rulebook.fru.dev/regulations/us-vt-vdposa
URL:https://rulebook.fru.dev/regulations/us-vt-vdposa
CATEGORIES:Vermont,privacy,health,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-257@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20290731
DTEND;VALUE=DATE:20290801
SUMMARY:Minnesota Consumer Data Privacy Act (MCDPA): Postsecondary institut
 ions must comply
DESCRIPTION:Postsecondary institutions regulated by the Office of Higher Ed
 ucation must comply by July 31\, 2029.\n\nMinnesota Consumer Data Privacy 
 Act (HF 4757\, 2024 Minn. Laws ch. 121\, art. 5)\, Minn. Stat. 325M.10-325
 M.21 (Minnesota)\n\nSource: https://www.revisor.mn.gov/statutes/cite/325M.
 20\n\nhttps://rulebook.fru.dev/regulations/us-mn-mcdpa
URL:https://rulebook.fru.dev/regulations/us-mn-mcdpa
CATEGORIES:Minnesota,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-206@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20300101
DTEND;VALUE=DATE:20300102
SUMMARY:Colorado AI Act: Mandatory cure period ends
DESCRIPTION:The AG's obligation to offer a 60-day notice-and-cure period ex
 pires.\n\nColorado SB 24-205 (Consumer Protections for Artificial Intellig
 ence)\, as delayed by SB 25B-004 and repealed and reenacted by SB 26-189 (
 Automated Decision-Making Technology) (Colorado)\n\nSource: https://leg.co
 lorado.gov/bills/sb26-189\n\nhttps://rulebook.fru.dev/regulations/us-co-ai
 -act
URL:https://rulebook.fru.dev/regulations/us-co-ai-act
CATEGORIES:Colorado,ai,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-175@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20300401
DTEND;VALUE=DATE:20300402
SUMMARY:CCPA / CPRA: Cybersecurity audit due: revenue under $50M
DESCRIPTION:First cybersecurity audit report (covering 2029) due for covere
 d businesses with 2028 annual gross revenue under $50M (11 CCR 7121(a)(3))
 \; annual by April 1 thereafter.\n\nCalifornia Consumer Privacy Act of 201
 8\, as amended by the California Privacy Rights Act of 2020 (Cal. Civ. Cod
 e 1798.100 et seq.) and CPPA regulations (Cal. Code Regs. tit. 11\, 7000 e
 t seq.) (California)\n\nSource: https://cppa.ca.gov/regulations/pdf/ccpa_u
 pdates_cyber_risk_admt_appr_text.pdf\n\nhttps://rulebook.fru.dev/regulatio
 ns/us-ca-ccpa
URL:https://rulebook.fru.dev/regulations/us-ca-ccpa
CATEGORIES:California,privacy,ai,cybersecurity,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-46@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20300802
DTEND;VALUE=DATE:20300803
SUMMARY:EU AI Act: Public-authority high-risk systems must comply
DESCRIPTION:Providers and deployers of high-risk AI systems intended for us
 e by public authorities that were placed on the market before the Chapter 
 III application date must comply (Art 111(2)\, as replaced by the Omnibus)
 .\n\nRegulation (EU) 2024/1689 laying down harmonised rules on artificial 
 intelligence (Artificial Intelligence Act)\, as amended by Regulation (EU)
  2026/1744 (Digital Omnibus on AI) (European Union)\n\nSource: https://eur
 -lex.europa.eu/eli/reg/2026/1744/oj\n\nhttps://rulebook.fru.dev/regulation
 s/eu-ai-act
URL:https://rulebook.fru.dev/regulations/eu-ai-act
CATEGORIES:European Union,ai,biometrics,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-54@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20301211
DTEND;VALUE=DATE:20301212
SUMMARY:Cyber Resilience Act: First CRA evaluation
DESCRIPTION:Commission evaluation and review report\, then every four years
  (Art 70(1)).\n\nRegulation (EU) 2024/2847 on horizontal cybersecurity req
 uirements for products with digital elements (Cyber Resilience Act) (Europ
 ean Union)\n\nSource: https://eur-lex.europa.eu/eli/reg/2024/2847/oj\n\nht
 tps://rulebook.fru.dev/regulations/eu-cra
URL:https://rulebook.fru.dev/regulations/eu-cra
CATEGORIES:European Union,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-47@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20301231
DTEND;VALUE=DATE:20310101
SUMMARY:EU AI Act: Large-scale EU IT systems must comply
DESCRIPTION:AI systems that are components of the large-scale IT systems in
  Annex X (e.g. SIS\, VIS\, Eurodac\, EES\, ETIAS) placed on the market bef
 ore 2 Aug 2027 must be brought into compliance (Art 111(1)).\n\nRegulation
  (EU) 2024/1689 laying down harmonised rules on artificial intelligence (A
 rtificial Intelligence Act)\, as amended by Regulation (EU) 2026/1744 (Dig
 ital Omnibus on AI) (European Union)\n\nSource: https://eur-lex.europa.eu/
 eli/reg/2024/1689/oj\n\nhttps://rulebook.fru.dev/regulations/eu-ai-act
URL:https://rulebook.fru.dev/regulations/eu-ai-act
CATEGORIES:European Union,ai,biometrics,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-83@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20310326
DTEND;VALUE=DATE:20310327
SUMMARY:European Health Data Space (EHDS): Primary use for second data cate
 gories\; EHR systems in service\; extra secondary-use categories
DESCRIPTION:Primary-use rules extend to medical images\, lab results and di
 scharge reports (Art 14(1)(d)-(f)). Chapter III applies to EHR systems put
  into service under Art 26(2). Additional secondary-use categories in Art 
 51(1)(b)\,(f)\,(g)\,(m)\,(p) apply.\n\nRegulation (EU) 2025/327 on the Eur
 opean Health Data Space (European Union)\n\nSource: https://eur-lex.europa
 .eu/eli/reg/2025/327/oj\n\nhttps://rulebook.fru.dev/regulations/eu-ehds
URL:https://rulebook.fru.dev/regulations/eu-ehds
CATEGORIES:European Union,health,privacy,data-access
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-84@regulations.fru.dev
DTSTAMP:20260924T094634Z
DTSTART;VALUE=DATE:20350326
DTEND;VALUE=DATE:20350327
SUMMARY:European Health Data Space (EHDS): Third-country participation in s
 econdary use
DESCRIPTION:Art 75(5) applies from 26 Mar 2035.\n\nRegulation (EU) 2025/327
  on the European Health Data Space (European Union)\n\nSource: https://eur
 -lex.europa.eu/eli/reg/2025/327/oj\n\nhttps://rulebook.fru.dev/regulations
 /eu-ehds
URL:https://rulebook.fru.dev/regulations/eu-ehds
CATEGORIES:European Union,health,privacy,data-access
TRANSP:TRANSPARENT
END:VEVENT
END:VCALENDAR
