BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//fru.dev//Rulebook//EN
CALSCALE:GREGORIAN
METHOD:PUBLISH
X-WR-CALNAME:Regulation deadlines (Rulebook)
X-WR-CALDESC:Compliance deadlines tracked at rulebook.fru.dev
REFRESH-INTERVAL;VALUE=DURATION:P1D
X-PUBLISHED-TTL:P1D
BEGIN:VEVENT
UID:deadline-241@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20081003
DTEND;VALUE=DATE:20081004
SUMMARY:Illinois BIPA: BIPA effective
DESCRIPTION:The Biometric Information Privacy Act takes effect.\n\nIllinois
  Biometric Information Privacy Act (740 ILCS 14)\, as amended by SB 2979 (
 Public Act 103-0769) (Illinois)\n\nSource: https://www.ilga.gov/legislatio
 n/ilcs/ilcs3.asp?ActID=3004&ChapterID=57\n\nhttps://rulebook.fru.dev/regul
 ations/us-il-bipa
URL:https://rulebook.fru.dev/regulations/us-il-bipa
CATEGORIES:Illinois,biometrics,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-269@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20170301
DTEND;VALUE=DATE:20170302
SUMMARY:NYDFS Cybersecurity Regulation (Part 500): Part 500 effective
DESCRIPTION:Original cybersecurity regulation takes effect.\n\nNew York DFS
  Cybersecurity Requirements for Financial Services Companies (23 NYCRR Par
 t 500)\, Second Amendment (New York)\n\nSource: https://www.dfs.ny.gov/cyb
 ersecurity/23-NYCRR-Part-500\n\nhttps://rulebook.fru.dev/regulations/us-ny
 -dfs-500
URL:https://rulebook.fru.dev/regulations/us-ny-dfs-500
CATEGORIES:New York,cybersecurity,breach-notification,financial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-164@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20200101
DTEND;VALUE=DATE:20200102
SUMMARY:CCPA / CPRA: CCPA takes effect
DESCRIPTION:Original CCPA consumer rights and business obligations take eff
 ect.\n\nCalifornia Consumer Privacy Act of 2018\, as amended by the Califo
 rnia Privacy Rights Act of 2020 (Cal. Civ. Code 1798.100 et seq.) and CPPA
  regulations (Cal. Code Regs. tit. 11\, 7000 et seq.) (California)\n\nSour
 ce: https://cppa.ca.gov/regulations/pdf/ccpa_statute_eff_20260101.pdf\n\nh
 ttps://rulebook.fru.dev/regulations/us-ca-ccpa
URL:https://rulebook.fru.dev/regulations/us-ca-ccpa
CATEGORIES:California,privacy,ai,cybersecurity,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-165@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20230101
DTEND;VALUE=DATE:20230102
SUMMARY:CCPA / CPRA: CPRA amendments operative
DESCRIPTION:CPRA amendments (correction right\, sensitive PI limits\, shari
 ng opt-out\, employee/B2B data coverage) become operative.\n\nCalifornia C
 onsumer Privacy Act of 2018\, as amended by the California Privacy Rights 
 Act of 2020 (Cal. Civ. Code 1798.100 et seq.) and CPPA regulations (Cal. C
 ode Regs. tit. 11\, 7000 et seq.) (California)\n\nSource: https://cppa.ca.
 gov/regulations/pdf/ccpa_statute_eff_20260101.pdf\n\nhttps://rulebook.fru.
 dev/regulations/us-ca-ccpa
URL:https://rulebook.fru.dev/regulations/us-ca-ccpa
CATEGORIES:California,privacy,ai,cybersecurity,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-311@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20230101
DTEND;VALUE=DATE:20230102
SUMMARY:Virginia VCDPA: VCDPA takes effect
DESCRIPTION:VCDPA obligations and consumer rights apply.\n\nVirginia Consum
 er Data Protection Act (SB 1392 / HB 2307\, 2021) (Virginia)\n\nSource: ht
 tps://law.lis.virginia.gov/vacode/title59.1/chapter53/\n\nhttps://rulebook
 .fru.dev/regulations/us-va-vcdpa
URL:https://rulebook.fru.dev/regulations/us-va-vcdpa
CATEGORIES:Virginia,privacy,children,online-safety
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-317@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20230427
DTEND;VALUE=DATE:20230428
SUMMARY:Washington My Health My Data Act: HB 1155 signed
DESCRIPTION:Governor signs My Health My Data Act.\n\nWashington My Health M
 y Data Act (HB 1155\, Laws of 2023\, ch. 191\; RCW 19.373) (Washington)\n\
 nSource: https://app.leg.wa.gov/billsummary?BillNumber=1155&Year=2023\n\nh
 ttps://rulebook.fru.dev/regulations/us-wa-mhmda
URL:https://rulebook.fru.dev/regulations/us-wa-mhmda
CATEGORIES:Washington,health,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-207@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20230701
DTEND;VALUE=DATE:20230702
SUMMARY:Colorado Privacy Act (CPA): CPA takes effect
DESCRIPTION:Core consumer rights and controller duties apply.\n\nColorado P
 rivacy Act (SB 21-190)\, C.R.S. 6-1-1301 et seq.\, as amended by HB 24-113
 0\, SB 24-041 and SB 25-276 (Colorado)\n\nSource: https://leg.colorado.gov
 /bills/sb21-190\n\nhttps://rulebook.fru.dev/regulations/us-co-cpa
URL:https://rulebook.fru.dev/regulations/us-co-cpa
CATEGORIES:Colorado,privacy,children,biometrics
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-215@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20230701
DTEND;VALUE=DATE:20230702
SUMMARY:Connecticut Data Privacy Act (CTDPA): CTDPA takes effect
DESCRIPTION:Core consumer rights and controller obligations apply.\n\nConne
 cticut Data Privacy Act (Public Act 22-15)\, Conn. Gen. Stat. 42-515 et se
 q.\, as amended by Public Act 25-113 (SB 1295) and Public Act 26-64 (SB 4)
  (Connecticut)\n\nSource: https://www.cga.ct.gov/asp/cgabillstatus/cgabill
 status.asp?selBillType=Bill&which_year=2022&bill_num=6\n\nhttps://rulebook
 .fru.dev/regulations/us-ct-ctdpa
URL:https://rulebook.fru.dev/regulations/us-ct-ctdpa
CATEGORIES:Connecticut,privacy,children,ai,health
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-281@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20230705
DTEND;VALUE=DATE:20230706
SUMMARY:NYC Local Law 144 (AEDT): DCWP enforcement begins
DESCRIPTION:Bias audit\, results publication and candidate notice requireme
 nts are enforced.\n\nNew York City Local Law 144 of 2021\, Automated Emplo
 yment Decision Tools (NYC Admin. Code 20-870 et seq.) (New York City\, New
  York)\n\nSource: https://www.nyc.gov/site/dca/about/automated-employment-
 decision-tools.page\n\nhttps://rulebook.fru.dev/regulations/us-nyc-ll144
URL:https://rulebook.fru.dev/regulations/us-nyc-ll144
CATEGORIES:New York City\, New York,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-318@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20230723
DTEND;VALUE=DATE:20230724
SUMMARY:Washington My Health My Data Act: Geofencing ban (Section 10) effec
 tive
DESCRIPTION:Ban on geofencing around health care facilities applies to all 
 persons.\n\nWashington My Health My Data Act (HB 1155\, Laws of 2023\, ch.
  191\; RCW 19.373) (Washington)\n\nSource: https://www.atg.wa.gov/protecti
 ng-washingtonians-personal-health-data-and-privacy\n\nhttps://rulebook.fru
 .dev/regulations/us-wa-mhmda
URL:https://rulebook.fru.dev/regulations/us-wa-mhmda
CATEGORIES:Washington,health,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-270@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20231101
DTEND;VALUE=DATE:20231102
SUMMARY:NYDFS Cybersecurity Regulation (Part 500): Second Amendment effecti
 ve
DESCRIPTION:Second Amendment takes effect\; 500.19(e)-(h)\, 500.20\, 500.21
 \, 500.22 and 500.24 apply immediately.\n\nNew York DFS Cybersecurity Requ
 irements for Financial Services Companies (23 NYCRR Part 500)\, Second Ame
 ndment (New York)\n\nSource: https://www.dfs.ny.gov/cybersecurity/23-NYCRR
 -Part-500\n\nhttps://rulebook.fru.dev/regulations/us-ny-dfs-500
URL:https://rulebook.fru.dev/regulations/us-ny-dfs-500
CATEGORIES:New York,cybersecurity,breach-notification,financial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-271@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20231201
DTEND;VALUE=DATE:20231202
SUMMARY:NYDFS Cybersecurity Regulation (Part 500): Amended notification req
 uirements (500.17)
DESCRIPTION:New 72-hour event notice\, 24-hour extortion payment notice and
  certification changes apply (30 days).\n\nNew York DFS Cybersecurity Requ
 irements for Financial Services Companies (23 NYCRR Part 500)\, Second Ame
 ndment (New York)\n\nSource: https://www.dfs.ny.gov/cybersecurity/23-NYCRR
 -Part-500\n\nhttps://rulebook.fru.dev/regulations/us-ny-dfs-500
URL:https://rulebook.fru.dev/regulations/us-ny-dfs-500
CATEGORIES:New York,cybersecurity,breach-notification,financial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-308@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20231231
DTEND;VALUE=DATE:20240101
SUMMARY:Utah UCPA: UCPA takes effect
DESCRIPTION:Utah Consumer Privacy Act obligations and consumer rights apply
 .\n\nUtah Consumer Privacy Act (SB 227\, 2022) (Utah)\n\nSource: https://l
 e.utah.gov/xcode/Title13/Chapter61/13-61-S402.html\n\nhttps://rulebook.fru
 .dev/regulations/us-ut-ucpa
URL:https://rulebook.fru.dev/regulations/us-ut-ucpa
CATEGORIES:Utah,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-319@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20240331
DTEND;VALUE=DATE:20240401
SUMMARY:Washington My Health My Data Act: Regulated entities must comply
DESCRIPTION:Sections 4-9 (privacy policy\, consent\, consumer rights\, sale
  authorization) apply to regulated entities.\n\nWashington My Health My Da
 ta Act (HB 1155\, Laws of 2023\, ch. 191\; RCW 19.373) (Washington)\n\nSou
 rce: https://www.atg.wa.gov/protecting-washingtonians-personal-health-data
 -and-privacy\n\nhttps://rulebook.fru.dev/regulations/us-wa-mhmda
URL:https://rulebook.fru.dev/regulations/us-wa-mhmda
CATEGORIES:Washington,health,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-272@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20240415
DTEND;VALUE=DATE:20240416
SUMMARY:NYDFS Cybersecurity Regulation (Part 500): Annual compliance notifi
 cation
DESCRIPTION:Certification of compliance or acknowledgment of non-compliance
  due (recurs every April 15).\n\nNew York DFS Cybersecurity Requirements f
 or Financial Services Companies (23 NYCRR Part 500)\, Second Amendment (Ne
 w York)\n\nSource: https://www.dfs.ny.gov/cybersecurity/23-NYCRR-Part-500\
 n\nhttps://rulebook.fru.dev/regulations/us-ny-dfs-500
URL:https://rulebook.fru.dev/regulations/us-ny-dfs-500
CATEGORIES:New York,cybersecurity,breach-notification,financial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-273@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20240429
DTEND;VALUE=DATE:20240430
SUMMARY:NYDFS Cybersecurity Regulation (Part 500): General 180-day transiti
 on ends
DESCRIPTION:Most new Second Amendment requirements apply\, e.g. annual repo
 rting to the board and risk assessment updates.\n\nNew York DFS Cybersecur
 ity Requirements for Financial Services Companies (23 NYCRR Part 500)\, Se
 cond Amendment (New York)\n\nSource: https://www.dfs.ny.gov/cybersecurity/
 23-NYCRR-Part-500\n\nhttps://rulebook.fru.dev/regulations/us-ny-dfs-500
URL:https://rulebook.fru.dev/regulations/us-ny-dfs-500
CATEGORIES:New York,cybersecurity,breach-notification,financial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-305@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20240501
DTEND;VALUE=DATE:20240502
SUMMARY:Utah AI Policy Act: AI Policy Act effective
DESCRIPTION:Generative AI disclosure duties and the Office of AI Policy tak
 e effect.\n\nUtah Artificial Intelligence Policy Act (SB 149\, 2024)\, as 
 amended by SB 226 and SB 332 (2025) (Utah)\n\nSource: https://le.utah.gov/
 ~2024/bills/static/SB0149.html\n\nhttps://rulebook.fru.dev/regulations/us-
 ut-aipa
URL:https://rulebook.fru.dev/regulations/us-ut-aipa
CATEGORIES:Utah,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-199@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20240517
DTEND;VALUE=DATE:20240518
SUMMARY:Colorado AI Act: SB 24-205 signed
DESCRIPTION:Governor Polis signs the original Colorado AI Act with a Februa
 ry 1\, 2026 effective date.\n\nColorado SB 24-205 (Consumer Protections fo
 r Artificial Intelligence)\, as delayed by SB 25B-004 and repealed and ree
 nacted by SB 26-189 (Automated Decision-Making Technology) (Colorado)\n\nS
 ource: https://leg.colorado.gov/bills/sb24-205\n\nhttps://rulebook.fru.dev
 /regulations/us-co-ai-act
URL:https://rulebook.fru.dev/regulations/us-co-ai-act
CATEGORIES:Colorado,ai,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-320@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20240630
DTEND;VALUE=DATE:20240701
SUMMARY:Washington My Health My Data Act: Small businesses must comply
DESCRIPTION:Sections 4-9 apply to small businesses.\n\nWashington My Health
  My Data Act (HB 1155\, Laws of 2023\, ch. 191\; RCW 19.373) (Washington)\
 n\nSource: https://www.atg.wa.gov/protecting-washingtonians-personal-healt
 h-data-and-privacy\n\nhttps://rulebook.fru.dev/regulations/us-wa-mhmda
URL:https://rulebook.fru.dev/regulations/us-wa-mhmda
CATEGORIES:Washington,health,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-208@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20240701
DTEND;VALUE=DATE:20240702
SUMMARY:Colorado Privacy Act (CPA): Universal opt-out mechanism recognition
  required
DESCRIPTION:Controllers must honor AG-recognized universal opt-out mechanis
 ms (e.g. Global Privacy Control).\n\nColorado Privacy Act (SB 21-190)\, C.
 R.S. 6-1-1301 et seq.\, as amended by HB 24-1130\, SB 24-041 and SB 25-276
  (Colorado)\n\nSource: https://leg.colorado.gov/bills/sb21-190\n\nhttps://
 rulebook.fru.dev/regulations/us-co-cpa
URL:https://rulebook.fru.dev/regulations/us-co-cpa
CATEGORIES:Colorado,privacy,children,biometrics
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-230@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20240701
DTEND;VALUE=DATE:20240702
SUMMARY:Florida Digital Bill of Rights: Florida Digital Bill of Rights take
 s effect
DESCRIPTION:SB 262 obligations under Fla. Stat. 501.701-501.722 apply.\n\nF
 lorida Digital Bill of Rights (CS/CS/SB 262\, 2023) (Florida)\n\nSource: h
 ttps://www.flsenate.gov/Session/Bill/2023/262\n\nhttps://rulebook.fru.dev/
 regulations/us-fl-fdbr
URL:https://rulebook.fru.dev/regulations/us-fl-fdbr
CATEGORIES:Florida,privacy,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-283@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20240701
DTEND;VALUE=DATE:20240702
SUMMARY:Oregon OCPA: OCPA takes effect for most controllers
DESCRIPTION:OCPA obligations apply to for-profit controllers meeting the th
 resholds.\n\nOregon Consumer Privacy Act (SB 619\, 2023) (Oregon)\n\nSourc
 e: https://www.doj.state.or.us/consumer-protection/id-theft-data-breaches/
 privacy/\n\nhttps://rulebook.fru.dev/regulations/us-or-ocpa
URL:https://rulebook.fru.dev/regulations/us-or-ocpa
CATEGORIES:Oregon,privacy,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-301@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20240701
DTEND;VALUE=DATE:20240702
SUMMARY:Texas TDPSA: TDPSA takes effect
DESCRIPTION:Most TDPSA obligations and consumer rights apply.\n\nTexas Data
  Privacy and Security Act (HB 4\, 2023) (Texas)\n\nSource: https://capitol
 .texas.gov/BillLookup/History.aspx?LegSess=88R&Bill=HB4\n\nhttps://ruleboo
 k.fru.dev/regulations/us-tx-tdpsa
URL:https://rulebook.fru.dev/regulations/us-tx-tdpsa
CATEGORIES:Texas,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-242@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20240802
DTEND;VALUE=DATE:20240803
SUMMARY:Illinois BIPA: SB 2979 amendment effective
DESCRIPTION:Public Act 103-0769 signed and effective immediately: single re
 covery per person and electronic signatures allowed for consent.\n\nIllino
 is Biometric Information Privacy Act (740 ILCS 14)\, as amended by SB 2979
  (Public Act 103-0769) (Illinois)\n\nSource: https://www.ilga.gov/Legislat
 ion/publicacts/view/103-0769\n\nhttps://rulebook.fru.dev/regulations/us-il
 -bipa
URL:https://rulebook.fru.dev/regulations/us-il-bipa
CATEGORIES:Illinois,biometrics,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-244@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20240809
DTEND;VALUE=DATE:20240810
SUMMARY:Illinois AI in Employment Law (HB 3773): HB 3773 signed
DESCRIPTION:Governor Pritzker signs Public Act 103-0804.\n\nIllinois HB 377
 3 (Public Act 103-0804)\, amending the Illinois Human Rights Act on artifi
 cial intelligence in employment (Illinois)\n\nSource: https://www.ilga.gov
 /ftp/legislation/103/BillStatus/HTML/10300HB3773.html\n\nhttps://rulebook.
 fru.dev/regulations/us-il-hb3773
URL:https://rulebook.fru.dev/regulations/us-il-hb3773
CATEGORIES:Illinois,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-187@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20240919
DTEND;VALUE=DATE:20240920
SUMMARY:California AI Transparency Act (SB 942): SB 942 signed
DESCRIPTION:SB 942 chaptered (ch. 291) with an original operative date of J
 anuary 1\, 2026.\n\nCalifornia AI Transparency Act (SB 942\, Stats. 2024\,
  ch. 291)\, as amended by AB 853 (Stats. 2025\, ch. 674) (California)\n\nS
 ource: https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_i
 d=202320240SB942\n\nhttps://rulebook.fru.dev/regulations/us-ca-sb942
URL:https://rulebook.fru.dev/regulations/us-ca-sb942
CATEGORIES:California,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-162@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20240928
DTEND;VALUE=DATE:20240929
SUMMARY:California AB 2013 (AI training data transparency): AB 2013 signed
DESCRIPTION:AB 2013 chaptered (ch. 817).\n\nCalifornia AB 2013\, Generative
  Artificial Intelligence: Training Data Transparency (Stats. 2024\, ch. 81
 7) (California)\n\nSource: https://leginfo.legislature.ca.gov/faces/billNa
 vClient.xhtml?bill_id=202320240AB2013\n\nhttps://rulebook.fru.dev/regulati
 ons/us-ca-ab2013
URL:https://rulebook.fru.dev/regulations/us-ca-ab2013
CATEGORIES:California,ai,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-258@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20241001
DTEND;VALUE=DATE:20241002
SUMMARY:Montana Consumer Data Privacy Act (MCDPA): MCDPA takes effect
DESCRIPTION:Consumer rights\, controller duties and opt-out preference sign
 al support apply.\n\nMontana Consumer Data Privacy Act (SB 384\, 2023)\, M
 ont. Code Ann. 30-14-2801 et seq.\, as amended by SB 297 (2025) (Montana)\
 n\nSource: https://archive.legmt.gov/bills/mca/title_0300/chapter_0140/par
 t_0280/section_0030/0300-0140-0280-0030.html\n\nhttps://rulebook.fru.dev/r
 egulations/us-mt-mcdpa
URL:https://rulebook.fru.dev/regulations/us-mt-mcdpa
CATEGORIES:Montana,privacy,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-274@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20241101
DTEND;VALUE=DATE:20241102
SUMMARY:NYDFS Cybersecurity Regulation (Part 500): Governance\, encryption\
 , IR/BCDR\, exemptions
DESCRIPTION:500.4 governance\, 500.15 encryption\, 500.16 incident response
  and business continuity plans\, and 500.19(a) revised exemptions apply.\n
 \nNew York DFS Cybersecurity Requirements for Financial Services Companies
  (23 NYCRR Part 500)\, Second Amendment (New York)\n\nSource: https://www.
 dfs.ny.gov/cybersecurity/23-NYCRR-Part-500\n\nhttps://rulebook.fru.dev/reg
 ulations/us-ny-dfs-500
URL:https://rulebook.fru.dev/regulations/us-ny-dfs-500
CATEGORIES:New York,cybersecurity,breach-notification,financial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-216@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20241231
DTEND;VALUE=DATE:20250101
SUMMARY:Connecticut Data Privacy Act (CTDPA): Mandatory 60-day cure period 
 expires
DESCRIPTION:After Dec 31\, 2024\, the AG is no longer required to offer a 6
 0-day cure before enforcement\; cure becomes discretionary.\n\nConnecticut
  Data Privacy Act (Public Act 22-15)\, Conn. Gen. Stat. 42-515 et seq.\, a
 s amended by Public Act 25-113 (SB 1295) and Public Act 26-64 (SB 4) (Conn
 ecticut)\n\nSource: https://www.cga.ct.gov/asp/cgabillstatus/cgabillstatus
 .asp?selBillType=Bill&which_year=2022&bill_num=6\n\nhttps://rulebook.fru.d
 ev/regulations/us-ct-ctdpa
URL:https://rulebook.fru.dev/regulations/us-ct-ctdpa
CATEGORIES:Connecticut,privacy,children,ai,health
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-166@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20250101
DTEND;VALUE=DATE:20250102
SUMMARY:CCPA / CPRA: CPI adjustment of thresholds and fines
DESCRIPTION:Revenue threshold rises to $26\,625\,000 and fines to $2\,663 /
  $7\,988 per violation.\n\nCalifornia Consumer Privacy Act of 2018\, as am
 ended by the California Privacy Rights Act of 2020 (Cal. Civ. Code 1798.10
 0 et seq.) and CPPA regulations (Cal. Code Regs. tit. 11\, 7000 et seq.) (
 California)\n\nSource: https://cppa.ca.gov/regulations/cpi_adjustment.html
 \n\nhttps://rulebook.fru.dev/regulations/us-ca-ccpa
URL:https://rulebook.fru.dev/regulations/us-ca-ccpa
CATEGORIES:California,privacy,ai,cybersecurity,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-209@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20250101
DTEND;VALUE=DATE:20250102
SUMMARY:Colorado Privacy Act (CPA): 60-day cure period expires
DESCRIPTION:Mandatory 60-day notice-and-cure before AG enforcement ends\; e
 nforcement may proceed without cure.\n\nColorado Privacy Act (SB 21-190)\,
  C.R.S. 6-1-1301 et seq.\, as amended by HB 24-1130\, SB 24-041 and SB 25-
 276 (Colorado)\n\nSource: https://leg.colorado.gov/bills/sb21-190\n\nhttps
 ://rulebook.fru.dev/regulations/us-co-cpa
URL:https://rulebook.fru.dev/regulations/us-co-cpa
CATEGORIES:Colorado,privacy,children,biometrics
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-217@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20250101
DTEND;VALUE=DATE:20250102
SUMMARY:Connecticut Data Privacy Act (CTDPA): Universal opt-out preference 
 signals required
DESCRIPTION:Controllers must honor opt-out preference signals for targeted 
 advertising and sale (effective Jan 1\, 2025).\n\nConnecticut Data Privacy
  Act (Public Act 22-15)\, Conn. Gen. Stat. 42-515 et seq.\, as amended by 
 Public Act 25-113 (SB 1295) and Public Act 26-64 (SB 4) (Connecticut)\n\nS
 ource: https://www.cga.ct.gov/asp/cgabillstatus/cgabillstatus.asp?selBillT
 ype=Bill&which_year=2022&bill_num=6\n\nhttps://rulebook.fru.dev/regulation
 s/us-ct-ctdpa
URL:https://rulebook.fru.dev/regulations/us-ct-ctdpa
CATEGORIES:Connecticut,privacy,children,ai,health
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-223@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20250101
DTEND;VALUE=DATE:20250102
SUMMARY:Delaware Personal Data Privacy Act (DPDPA): DPDPA takes effect
DESCRIPTION:Consumer rights and controller duties apply\; 60-day mandatory 
 cure period begins.\n\nDelaware Personal Data Privacy Act (HB 154)\, 6 Del
 . C. ch. 12D (Delaware)\n\nSource: https://delcode.delaware.gov/title6/c01
 2d/index.html\n\nhttps://rulebook.fru.dev/regulations/us-de-dpdpa
URL:https://rulebook.fru.dev/regulations/us-de-dpdpa
CATEGORIES:Delaware,privacy,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-240@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20250101
DTEND;VALUE=DATE:20250102
SUMMARY:Iowa Consumer Data Protection Act (ICDPA): ICDPA takes effect
DESCRIPTION:Consumer rights and controller/processor obligations apply.\n\n
 Iowa Consumer Data Protection Act (SF 262\, 2023)\, Iowa Code ch. 715D (Io
 wa)\n\nSource: https://www.legis.iowa.gov/docs/code/715D.pdf\n\nhttps://ru
 lebook.fru.dev/regulations/us-ia-icdpa
URL:https://rulebook.fru.dev/regulations/us-ia-icdpa
CATEGORIES:Iowa,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-260@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20250101
DTEND;VALUE=DATE:20250102
SUMMARY:Nebraska NDPA: Nebraska Data Privacy Act takes effect
DESCRIPTION:Controller and processor obligations and consumer rights under 
 Neb. Rev. Stat. 87-1101 et seq. apply.\n\nNebraska Data Privacy Act (LB 10
 74\, 2024) (Nebraska)\n\nSource: https://nebraskalegislature.gov/bills/vie
 w_bill.php?DocumentID=54904\n\nhttps://rulebook.fru.dev/regulations/us-ne-
 ndpa
URL:https://rulebook.fru.dev/regulations/us-ne-ndpa
CATEGORIES:Nebraska,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-261@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20250101
DTEND;VALUE=DATE:20250102
SUMMARY:New Hampshire Privacy Act: New Hampshire Privacy Act takes effect
DESCRIPTION:RSA 507-H obligations and consumer rights apply (Laws 2024\, 5:
 1\, eff. Jan. 1\, 2025).\n\nNew Hampshire Privacy Act (SB 255\, 2024)\, RS
 A chapter 507-H (New Hampshire)\n\nSource: https://gc.nh.gov/rsa/html/LII/
 507-H/507-H-2.htm\n\nhttps://rulebook.fru.dev/regulations/us-nh-privacy
URL:https://rulebook.fru.dev/regulations/us-nh-privacy
CATEGORIES:New Hampshire,privacy,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-302@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20250101
DTEND;VALUE=DATE:20250102
SUMMARY:Texas TDPSA: Universal opt-out mechanism requirement applies
DESCRIPTION:Controllers must honor global privacy control / universal opt-o
 ut signals (Bus. & Com. Code 541.055(e)).\n\nTexas Data Privacy and Securi
 ty Act (HB 4\, 2023) (Texas)\n\nSource: https://capitol.texas.gov/BillLook
 up/History.aspx?LegSess=88R&Bill=HB4\n\nhttps://rulebook.fru.dev/regulatio
 ns/us-tx-tdpsa
URL:https://rulebook.fru.dev/regulations/us-tx-tdpsa
CATEGORIES:Texas,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-264@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20250115
DTEND;VALUE=DATE:20250116
SUMMARY:New Jersey NJDPA: NJDPA takes effect
DESCRIPTION:The act takes effect on the 365th day after enactment on Jan 16
 \, 2024 (sec. 17).\n\nNew Jersey Data Privacy Act (P.L.2023\, c.266\; S332
 ) (New Jersey)\n\nSource: https://pub.njleg.state.nj.us/Bills/2022/PL23/26
 6_.PDF\n\nhttps://rulebook.fru.dev/regulations/us-nj-njdpa
URL:https://rulebook.fru.dev/regulations/us-nj-njdpa
CATEGORIES:New Jersey,privacy,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-275@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20250501
DTEND;VALUE=DATE:20250502
SUMMARY:NYDFS Cybersecurity Regulation (Part 500): Vulnerability scans\, ac
 cess privileges\, malware controls\, Class A monitoring
DESCRIPTION:500.5(a)(2) automated scans\, 500.7 access privilege restrictio
 ns\, 500.14(a)(2) malicious code protection\, and 500.14(b) Class A endpoi
 nt detection and centralized logging apply.\n\nNew York DFS Cybersecurity 
 Requirements for Financial Services Companies (23 NYCRR Part 500)\, Second
  Amendment (New York)\n\nSource: https://www.dfs.ny.gov/cybersecurity/23-N
 YCRR-Part-500\n\nhttps://rulebook.fru.dev/regulations/us-ny-dfs-500
URL:https://rulebook.fru.dev/regulations/us-ny-dfs-500
CATEGORIES:New York,cybersecurity,breach-notification,financial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-306@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20250507
DTEND;VALUE=DATE:20250508
SUMMARY:Utah AI Policy Act: SB 226 amendments effective
DESCRIPTION:Disclosure duties narrowed (on clear request or high-risk inter
 actions)\, safe harbor added\, provisions recodified in Title 13\, Ch. 75.
 \n\nUtah Artificial Intelligence Policy Act (SB 149\, 2024)\, as amended b
 y SB 226 and SB 332 (2025) (Utah)\n\nSource: https://le.utah.gov/~2025/bil
 ls/static/SB0226.html\n\nhttps://rulebook.fru.dev/regulations/us-ut-aipa
URL:https://rulebook.fru.dev/regulations/us-ut-aipa
CATEGORIES:Utah,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-210@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20250523
DTEND;VALUE=DATE:20250524
SUMMARY:Colorado Privacy Act (CPA): SB 25-276 geolocation and sensitive-dat
 a sale amendment effective
DESCRIPTION:Adds precise geolocation data definitions and prohibits selling
  sensitive data without consent (effective on signature).\n\nColorado Priv
 acy Act (SB 21-190)\, C.R.S. 6-1-1301 et seq.\, as amended by HB 24-1130\,
  SB 24-041 and SB 25-276 (Colorado)\n\nSource: https://leg.colorado.gov/bi
 lls/sb25-276\n\nhttps://rulebook.fru.dev/regulations/us-co-cpa
URL:https://rulebook.fru.dev/regulations/us-co-cpa
CATEGORIES:Colorado,privacy,children,biometrics
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-265@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20250602
DTEND;VALUE=DATE:20250603
SUMMARY:New Jersey NJDPA: Division of Consumer Affairs proposes NJDPA rules
  (N.J.A.C. 13:45L)
DESCRIPTION:Proposed rules published at 57 N.J.R. 1101(a)\; comments were d
 ue Aug 1\, 2025.\n\nNew Jersey Data Privacy Act (P.L.2023\, c.266\; S332) 
 (New Jersey)\n\nSource: https://www.njoag.gov/murphy-administration-announ
 ces-proposed-rules-establishing-comprehensive-consumer-data-privacy-protec
 tions/\n\nhttps://rulebook.fru.dev/regulations/us-nj-njdpa
URL:https://rulebook.fru.dev/regulations/us-nj-njdpa
CATEGORIES:New Jersey,privacy,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-303@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20250622
DTEND;VALUE=DATE:20250623
SUMMARY:TRAIGA: HB 149 signed
DESCRIPTION:Governor Abbott signs TRAIGA.\n\nTexas Responsible Artificial I
 ntelligence Governance Act (HB 149\, 89th Legislature) (Texas)\n\nSource: 
 https://capitol.texas.gov/BillLookup/History.aspx?LegSess=89R&Bill=HB149\n
 \nhttps://rulebook.fru.dev/regulations/us-tx-traiga
URL:https://rulebook.fru.dev/regulations/us-tx-traiga
CATEGORIES:Texas,ai,biometrics
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-211@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20250701
DTEND;VALUE=DATE:20250702
SUMMARY:Colorado Privacy Act (CPA): Biometric identifier amendment (HB 24-1
 130) effective
DESCRIPTION:Any controller processing biometric identifiers must adopt a wr
 itten biometric policy\, give notice\, obtain consent and follow retention
 /deletion rules.\n\nColorado Privacy Act (SB 21-190)\, C.R.S. 6-1-1301 et 
 seq.\, as amended by HB 24-1130\, SB 24-041 and SB 25-276 (Colorado)\n\nSo
 urce: https://leg.colorado.gov/bills/hb24-1130\n\nhttps://rulebook.fru.dev
 /regulations/us-co-cpa
URL:https://rulebook.fru.dev/regulations/us-co-cpa
CATEGORIES:Colorado,privacy,children,biometrics
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-284@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20250701
DTEND;VALUE=DATE:20250702
SUMMARY:Oregon OCPA: OCPA applies to nonprofits
DESCRIPTION:Nonprofit organizations meeting the thresholds become subject t
 o OCPA.\n\nOregon Consumer Privacy Act (SB 619\, 2023) (Oregon)\n\nSource:
  https://www.doj.state.or.us/consumer-protection/for-businesses/privacy-la
 w-faqs-for-nonprofits/\n\nhttps://rulebook.fru.dev/regulations/us-or-ocpa
URL:https://rulebook.fru.dev/regulations/us-or-ocpa
CATEGORIES:Oregon,privacy,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-300@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20250701
DTEND;VALUE=DATE:20250702
SUMMARY:Tennessee TIPA: TIPA takes effect
DESCRIPTION:Controller and processor obligations and consumer rights under 
 Tenn. Code Ann. 47-18-3301 et seq. apply.\n\nTennessee Information Protect
 ion Act (HB 1181 / SB 73\, 2023) (Tennessee)\n\nSource: https://wapp.capit
 ol.tn.gov/apps/BillInfo/Default.aspx?BillNumber=HB1181&GA=113\n\nhttps://r
 ulebook.fru.dev/regulations/us-tn-tipa
URL:https://rulebook.fru.dev/regulations/us-tn-tipa
CATEGORIES:Tennessee,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-266@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20250715
DTEND;VALUE=DATE:20250716
SUMMARY:New Jersey NJDPA: Universal opt-out mechanism must be honored
DESCRIPTION:Controllers that sell personal data or process it for targeted 
 advertising must honor user-selected universal opt-out signals within six 
 months of the effective date (N.J.S.A. 56:8-166.11).\n\nNew Jersey Data Pr
 ivacy Act (P.L.2023\, c.266\; S332) (New Jersey)\n\nSource: https://pub.nj
 leg.state.nj.us/Bills/2022/PL23/266_.PDF\n\nhttps://rulebook.fru.dev/regul
 ations/us-nj-njdpa
URL:https://rulebook.fru.dev/regulations/us-nj-njdpa
CATEGORIES:New Jersey,privacy,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-255@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20250731
DTEND;VALUE=DATE:20250801
SUMMARY:Minnesota Consumer Data Privacy Act (MCDPA): MCDPA takes effect
DESCRIPTION:Consumer rights and controller/processor obligations apply (pos
 tsecondary institutions excepted).\n\nMinnesota Consumer Data Privacy Act 
 (HF 4757\, 2024 Minn. Laws ch. 121\, art. 5)\, Minn. Stat. 325M.10-325M.21
  (Minnesota)\n\nSource: https://www.revisor.mn.gov/statutes/cite/325M.20\n
 \nhttps://rulebook.fru.dev/regulations/us-mn-mcdpa
URL:https://rulebook.fru.dev/regulations/us-mn-mcdpa
CATEGORIES:Minnesota,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-200@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20250828
DTEND;VALUE=DATE:20250829
SUMMARY:Colorado AI Act: SB 25B-004 delays the act
DESCRIPTION:Special-session bill pushes the SB 24-205 effective date from F
 ebruary 1\, 2026 to June 30\, 2026.\n\nColorado SB 24-205 (Consumer Protec
 tions for Artificial Intelligence)\, as delayed by SB 25B-004 and repealed
  and reenacted by SB 26-189 (Automated Decision-Making Technology) (Colora
 do)\n\nSource: https://leg.colorado.gov/bills/sb25b-004\n\nhttps://ruleboo
 k.fru.dev/regulations/us-co-ai-act
URL:https://rulebook.fru.dev/regulations/us-co-ai-act
CATEGORIES:Colorado,ai,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-167@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20250922
DTEND;VALUE=DATE:20250923
SUMMARY:CCPA / CPRA: ADMT\, risk assessment and cybersecurity audit regulat
 ions approved
DESCRIPTION:OAL approves the CCPA Updates\, Cybersecurity Audit\, Risk Asse
 ssment\, ADMT and Insurance regulations and files them with the Secretary 
 of State.\n\nCalifornia Consumer Privacy Act of 2018\, as amended by the C
 alifornia Privacy Rights Act of 2020 (Cal. Civ. Code 1798.100 et seq.) and
  CPPA regulations (Cal. Code Regs. tit. 11\, 7000 et seq.) (California)\n\
 nSource: https://cppa.ca.gov/regulations/ccpa_updates.html\n\nhttps://rule
 book.fru.dev/regulations/us-ca-ccpa
URL:https://rulebook.fru.dev/regulations/us-ca-ccpa
CATEGORIES:California,privacy,ai,cybersecurity,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-184@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20250929
DTEND;VALUE=DATE:20250930
SUMMARY:California SB 53 (TFAIA): SB 53 signed
DESCRIPTION:Governor Newsom signs SB 53 (chapter 138).\n\nCalifornia SB 53\
 , Transparency in Frontier Artificial Intelligence Act (Stats. 2025\, ch. 
 138) (California)\n\nSource: https://leginfo.legislature.ca.gov/faces/bill
 NavClient.xhtml?bill_id=202520260SB53\n\nhttps://rulebook.fru.dev/regulati
 ons/us-ca-sb53
URL:https://rulebook.fru.dev/regulations/us-ca-sb53
CATEGORIES:California,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-212@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20251001
DTEND;VALUE=DATE:20251002
SUMMARY:Colorado Privacy Act (CPA): Minors' data amendment (SB 24-041) effe
 ctive
DESCRIPTION:Controllers offering online services to minors must use reasona
 ble care\, conduct assessments\, and obtain consent for targeted ads\, sal
 e and certain profiling of minors.\n\nColorado Privacy Act (SB 21-190)\, C
 .R.S. 6-1-1301 et seq.\, as amended by HB 24-1130\, SB 24-041 and SB 25-27
 6 (Colorado)\n\nSource: https://leg.colorado.gov/bills/sb24-041\n\nhttps:/
 /rulebook.fru.dev/regulations/us-co-cpa
URL:https://rulebook.fru.dev/regulations/us-co-cpa
CATEGORIES:Colorado,privacy,children,biometrics
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-252@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20251001
DTEND;VALUE=DATE:20251002
SUMMARY:Maryland Online Data Privacy Act (MODPA): MODPA takes effect
DESCRIPTION:Act takes effect\; data protection assessments apply to process
 ing activities on or after Oct 1\, 2025.\n\nMaryland Online Data Privacy A
 ct of 2024 (SB 541 / HB 567)\, Md. Code\, Com. Law 14-4601 et seq. (Maryla
 nd)\n\nSource: https://mgaleg.maryland.gov/2024RS/Chapters_noln/CH_455_sb0
 541e.pdf\n\nhttps://rulebook.fru.dev/regulations/us-md-modpa
URL:https://rulebook.fru.dev/regulations/us-md-modpa
CATEGORIES:Maryland,privacy,children,health,biometrics
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-259@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20251001
DTEND;VALUE=DATE:20251002
SUMMARY:Montana Consumer Data Privacy Act (MCDPA): SB 297 amendments take e
 ffect\; cure period eliminated
DESCRIPTION:Lower thresholds (25\,000 / 15\,000 + 25%)\, minors' data prote
 ctions\, AG assessment demands\; the 60-day cure period is removed.\n\nMon
 tana Consumer Data Privacy Act (SB 384\, 2023)\, Mont. Code Ann. 30-14-280
 1 et seq.\, as amended by SB 297 (2025) (Montana)\n\nSource: https://archi
 ve.legmt.gov/bills/mca/title_0300/chapter_0140/part_0280/section_0170/0300
 -0140-0280-0170.html\n\nhttps://rulebook.fru.dev/regulations/us-mt-mcdpa
URL:https://rulebook.fru.dev/regulations/us-mt-mcdpa
CATEGORIES:Montana,privacy,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-188@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20251013
DTEND;VALUE=DATE:20251014
SUMMARY:California AI Transparency Act (SB 942): AB 853 signed
DESCRIPTION:AB 853 (ch. 674) delays the operative date and adds platform an
 d device duties.\n\nCalifornia AI Transparency Act (SB 942\, Stats. 2024\,
  ch. 291)\, as amended by AB 853 (Stats. 2025\, ch. 674) (California)\n\nS
 ource: https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_i
 d=202520260AB853\n\nhttps://rulebook.fru.dev/regulations/us-ca-sb942
URL:https://rulebook.fru.dev/regulations/us-ca-sb942
CATEGORIES:California,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-181@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20251013
DTEND;VALUE=DATE:20251014
SUMMARY:California SB 243 (companion chatbots): SB 243 signed
DESCRIPTION:SB 243 chaptered (ch. 677).\n\nCalifornia SB 243\, Companion Ch
 atbots (Stats. 2025\, ch. 677) (California)\n\nSource: https://leginfo.leg
 islature.ca.gov/faces/billNavClient.xhtml?bill_id=202520260SB243\n\nhttps:
 //rulebook.fru.dev/regulations/us-ca-sb243
URL:https://rulebook.fru.dev/regulations/us-ca-sb243
CATEGORIES:California,ai,children,online-safety
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-276@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20251101
DTEND;VALUE=DATE:20251102
SUMMARY:NYDFS Cybersecurity Regulation (Part 500): Universal MFA and asset 
 inventory
DESCRIPTION:500.12 multi-factor authentication for all users and 500.13(a) 
 asset inventory requirements apply.\n\nNew York DFS Cybersecurity Requirem
 ents for Financial Services Companies (23 NYCRR Part 500)\, Second Amendme
 nt (New York)\n\nSource: https://www.dfs.ny.gov/cybersecurity/23-NYCRR-Par
 t-500\n\nhttps://rulebook.fru.dev/regulations/us-ny-dfs-500
URL:https://rulebook.fru.dev/regulations/us-ny-dfs-500
CATEGORIES:New York,cybersecurity,breach-notification,financial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-278@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20251219
DTEND;VALUE=DATE:20251220
SUMMARY:NY RAISE Act: RAISE Act signed
DESCRIPTION:Governor Hochul signs the RAISE Act with an agreed chapter amen
 dment.\n\nNew York Responsible AI Safety and Education (RAISE) Act (S6953-
 B/A6453-B of 2025)\, as amended by chapter amendment S8828 of 2026 (New Yo
 rk)\n\nSource: https://www.governor.ny.gov/news/governor-hochul-signs-nati
 on-leading-legislation-require-ai-frameworks-ai-frontier-models\n\nhttps:/
 /rulebook.fru.dev/regulations/us-ny-raise
URL:https://rulebook.fru.dev/regulations/us-ny-raise
CATEGORIES:New York,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-224@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20251231
DTEND;VALUE=DATE:20260101
SUMMARY:Delaware Personal Data Privacy Act (DPDPA): Mandatory 60-day cure p
 eriod expires
DESCRIPTION:Mandatory notice-and-cure ends Dec 31\, 2025\; from Jan 1\, 202
 6 DOJ decides whether to offer a cure using statutory factors.\n\nDelaware
  Personal Data Privacy Act (HB 154)\, 6 Del. C. ch. 12D (Delaware)\n\nSour
 ce: https://delcode.delaware.gov/title6/c012d/index.html\n\nhttps://rulebo
 ok.fru.dev/regulations/us-de-dpdpa
URL:https://rulebook.fru.dev/regulations/us-de-dpdpa
CATEGORIES:Delaware,privacy,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-163@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20260101
DTEND;VALUE=DATE:20260102
SUMMARY:California AB 2013 (AI training data transparency): Training-data d
 ocumentation due
DESCRIPTION:Documentation must be posted for GenAI systems released since J
 anuary 1\, 2022\, and before each later release or substantial modificatio
 n.\n\nCalifornia AB 2013\, Generative Artificial Intelligence: Training Da
 ta Transparency (Stats. 2024\, ch. 817) (California)\n\nSource: https://le
 ginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202320240AB2013
 \n\nhttps://rulebook.fru.dev/regulations/us-ca-ab2013
URL:https://rulebook.fru.dev/regulations/us-ca-ab2013
CATEGORIES:California,ai,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-189@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20260101
DTEND;VALUE=DATE:20260102
SUMMARY:California AI Transparency Act (SB 942): Original operative date (s
 uperseded)
DESCRIPTION:Original SB 942 date\; delayed to August 2\, 2026 by AB 853.\n\
 nCalifornia AI Transparency Act (SB 942\, Stats. 2024\, ch. 291)\, as amen
 ded by AB 853 (Stats. 2025\, ch. 674) (California)\n\nSource: https://legi
 nfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202320240SB942\n\
 nhttps://rulebook.fru.dev/regulations/us-ca-sb942
URL:https://rulebook.fru.dev/regulations/us-ca-sb942
CATEGORIES:California,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-176@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20260101
DTEND;VALUE=DATE:20260102
SUMMARY:California Delete Act / DROP: DROP opens to consumers
DESCRIPTION:Consumers can submit a single deletion request to all registere
 d data brokers through DROP.\n\nCalifornia Delete Act (SB 362\, 2023)\, Ca
 l. Civ. Code 1798.99.80 et seq.\, and DROP regulations (California)\n\nSou
 rce: https://www.cppa.ca.gov/data_brokers/\n\nhttps://rulebook.fru.dev/reg
 ulations/us-ca-delete-act
URL:https://rulebook.fru.dev/regulations/us-ca-delete-act
CATEGORIES:California,privacy,data-access
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-182@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20260101
DTEND;VALUE=DATE:20260102
SUMMARY:California SB 243 (companion chatbots): Chatbot safeguards apply
DESCRIPTION:AI disclosure\, suicide and self-harm protocols\, and minor pro
 tections apply.\n\nCalifornia SB 243\, Companion Chatbots (Stats. 2025\, c
 h. 677) (California)\n\nSource: https://leginfo.legislature.ca.gov/faces/b
 illNavClient.xhtml?bill_id=202520260SB243\n\nhttps://rulebook.fru.dev/regu
 lations/us-ca-sb243
URL:https://rulebook.fru.dev/regulations/us-ca-sb243
CATEGORIES:California,ai,children,online-safety
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-185@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20260101
DTEND;VALUE=DATE:20260102
SUMMARY:California SB 53 (TFAIA): Frontier developer obligations apply
DESCRIPTION:Frontier AI frameworks\, transparency reports\, critical safety
  incident reporting (15 days\, or 24 hours for imminent risk of death or s
 erious injury) and whistleblower protections apply.\n\nCalifornia SB 53\, 
 Transparency in Frontier Artificial Intelligence Act (Stats. 2025\, ch. 13
 8) (California)\n\nSource: https://leginfo.legislature.ca.gov/faces/billNa
 vClient.xhtml?bill_id=202520260SB53\n\nhttps://rulebook.fru.dev/regulation
 s/us-ca-sb53
URL:https://rulebook.fru.dev/regulations/us-ca-sb53
CATEGORIES:California,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-168@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20260101
DTEND;VALUE=DATE:20260102
SUMMARY:CCPA / CPRA: New CCPA regulations take effect
DESCRIPTION:ADMT\, risk assessment\, cybersecurity audit and updated CCPA r
 egulations become effective\; risk assessments required for new high-risk 
 processing.\n\nCalifornia Consumer Privacy Act of 2018\, as amended by the
  California Privacy Rights Act of 2020 (Cal. Civ. Code 1798.100 et seq.) a
 nd CPPA regulations (Cal. Code Regs. tit. 11\, 7000 et seq.) (California)\
 n\nSource: https://cppa.ca.gov/regulations/ccpa_updates.html\n\nhttps://ru
 lebook.fru.dev/regulations/us-ca-ccpa
URL:https://rulebook.fru.dev/regulations/us-ca-ccpa
CATEGORIES:California,privacy,ai,cybersecurity,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-225@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20260101
DTEND;VALUE=DATE:20260102
SUMMARY:Delaware Personal Data Privacy Act (DPDPA): Opt-out preference sign
 als must be honored
DESCRIPTION:Controllers must allow opt-out of targeted advertising and sale
  via opt-out preference signals (12D-106).\n\nDelaware Personal Data Priva
 cy Act (HB 154)\, 6 Del. C. ch. 12D (Delaware)\n\nSource: https://delcode.
 delaware.gov/title6/c012d/index.html\n\nhttps://rulebook.fru.dev/regulatio
 ns/us-de-dpdpa
URL:https://rulebook.fru.dev/regulations/us-de-dpdpa
CATEGORIES:Delaware,privacy,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-245@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20260101
DTEND;VALUE=DATE:20260102
SUMMARY:Illinois AI in Employment Law (HB 3773): AI anti-discrimination and
  notice duties apply
DESCRIPTION:Prohibition on discriminatory AI use and the employee notice re
 quirement take effect.\n\nIllinois HB 3773 (Public Act 103-0804)\, amendin
 g the Illinois Human Rights Act on artificial intelligence in employment (
 Illinois)\n\nSource: https://www.ilga.gov/ftp/legislation/103/BillStatus/H
 TML/10300HB3773.html\n\nhttps://rulebook.fru.dev/regulations/us-il-hb3773
URL:https://rulebook.fru.dev/regulations/us-il-hb3773
CATEGORIES:Illinois,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-248@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20260101
DTEND;VALUE=DATE:20260102
SUMMARY:Indiana Consumer Data Protection Act (ICDPA): ICDPA takes effect
DESCRIPTION:Consumer rights and controller/processor obligations apply\; as
 sessments required for processing activities created on or after this date
 .\n\nIndiana Consumer Data Protection Act (SEA 5\, 2023)\, Ind. Code 24-15
  (Indiana)\n\nSource: https://iga.in.gov/legislative/2023/bills/senate/5/d
 etails\n\nhttps://rulebook.fru.dev/regulations/us-in-icdpa
URL:https://rulebook.fru.dev/regulations/us-in-icdpa
CATEGORIES:Indiana,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-249@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20260101
DTEND;VALUE=DATE:20260102
SUMMARY:Kentucky Consumer Data Protection Act (KCDPA): KCDPA takes effect
DESCRIPTION:Consumer rights and controller/processor obligations apply (HB 
 15 section 12).\n\nKentucky Consumer Data Protection Act (HB 15\, 2024)\, 
 KRS 367.3611-367.3629 (Kentucky)\n\nSource: https://apps.legislature.ky.go
 v/recorddocuments/bill/24RS/hb15/bill.pdf\n\nhttps://rulebook.fru.dev/regu
 lations/us-ky-kcdpa
URL:https://rulebook.fru.dev/regulations/us-ky-kcdpa
CATEGORIES:Kentucky,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-262@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20260101
DTEND;VALUE=DATE:20260102
SUMMARY:New Hampshire Privacy Act: Mandatory 60-day cure period expires
DESCRIPTION:The AG's obligation to issue a cure notice ended Dec 31\, 2025\
 ; from Jan 1\, 2026 cure opportunities are discretionary (RSA 507-H:11 II-
 III).\n\nNew Hampshire Privacy Act (SB 255\, 2024)\, RSA chapter 507-H (Ne
 w Hampshire)\n\nSource: https://gc.nh.gov/rsa/html/LII/507-H/507-H-11.htm\
 n\nhttps://rulebook.fru.dev/regulations/us-nh-privacy
URL:https://rulebook.fru.dev/regulations/us-nh-privacy
CATEGORIES:New Hampshire,privacy,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-285@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20260101
DTEND;VALUE=DATE:20260102
SUMMARY:Oregon OCPA: Cure period sunsets
DESCRIPTION:The AG's 30-day notice-and-cure requirement expires\; enforceme
 nt can proceed without a cure opportunity.\n\nOregon Consumer Privacy Act 
 (SB 619\, 2023) (Oregon)\n\nSource: https://www.oregonlegislature.gov/bill
 s_laws/ors/ors646A.html\n\nhttps://rulebook.fru.dev/regulations/us-or-ocpa
URL:https://rulebook.fru.dev/regulations/us-or-ocpa
CATEGORIES:Oregon,privacy,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-286@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20260101
DTEND;VALUE=DATE:20260102
SUMMARY:Oregon OCPA: Universal opt-out signals must be honored
DESCRIPTION:Controllers must honor opt-out preference signals such as Globa
 l Privacy Control.\n\nOregon Consumer Privacy Act (SB 619\, 2023) (Oregon)
 \n\nSource: https://www.doj.state.or.us/consumer-protection/id-theft-data-
 breaches/privacy/\n\nhttps://rulebook.fru.dev/regulations/us-or-ocpa
URL:https://rulebook.fru.dev/regulations/us-or-ocpa
CATEGORIES:Oregon,privacy,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-287@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20260101
DTEND;VALUE=DATE:20260102
SUMMARY:Oregon OCPA: Sale ban on precise geolocation and under-16 data (HB 
 2008)
DESCRIPTION:Selling precise geolocation (1\,750-ft radius) and the personal
  data of consumers the controller knows or willfully disregards are under 
 16 is prohibited.\n\nOregon Consumer Privacy Act (SB 619\, 2023) (Oregon)\
 n\nSource: https://www.doj.state.or.us/consumer-protection/id-theft-data-b
 reaches/privacy/\n\nhttps://rulebook.fru.dev/regulations/us-or-ocpa
URL:https://rulebook.fru.dev/regulations/us-or-ocpa
CATEGORIES:Oregon,privacy,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-289@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20260101
DTEND;VALUE=DATE:20260102
SUMMARY:Rhode Island RIDTPPA: RIDTPPA takes effect
DESCRIPTION:All provisions of R.I. Gen. Laws ch. 6-48.1 apply (P.L. 2024\, 
 ch. 430/453\, effective Jan 1\, 2026).\n\nRhode Island Data Transparency a
 nd Privacy Protection Act (Rhode Island)\n\nSource: https://webserver.rile
 gislature.gov/Statutes/TITLE6/6-48.1/INDEX.htm\n\nhttps://rulebook.fru.dev
 /regulations/us-ri-dtppa
URL:https://rulebook.fru.dev/regulations/us-ri-dtppa
CATEGORIES:Rhode Island,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-304@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20260101
DTEND;VALUE=DATE:20260102
SUMMARY:TRAIGA: TRAIGA takes effect
DESCRIPTION:Prohibited-practice rules\, AG enforcement\, sandbox program an
 d government AI disclosure duties apply.\n\nTexas Responsible Artificial I
 ntelligence Governance Act (HB 149\, 89th Legislature) (Texas)\n\nSource: 
 https://capitol.texas.gov/BillLookup/History.aspx?LegSess=89R&Bill=HB149\n
 \nhttps://rulebook.fru.dev/regulations/us-tx-traiga
URL:https://rulebook.fru.dev/regulations/us-tx-traiga
CATEGORIES:Texas,ai,biometrics
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-312@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20260101
DTEND;VALUE=DATE:20260102
SUMMARY:Virginia VCDPA: Under-16 social media time limit (SB 854) takes eff
 ect
DESCRIPTION:Social media platforms must use commercially reasonable age det
 ermination and cap users under 16 at 1 hour/day unless a parent consents. 
 A preliminary injunction issued Feb 27\, 2026 bars enforcement.\n\nVirgini
 a Consumer Data Protection Act (SB 1392 / HB 2307\, 2021) (Virginia)\n\nSo
 urce: https://netchoice.org/wp-content/uploads/2026/02/Virginia-PI-Opinion
 _Granted.pdf\n\nhttps://rulebook.fru.dev/regulations/us-va-vcdpa
URL:https://rulebook.fru.dev/regulations/us-va-vcdpa
CATEGORIES:Virginia,privacy,children,online-safety
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-177@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20260131
DTEND;VALUE=DATE:20260201
SUMMARY:California Delete Act / DROP: Annual data broker registration deadl
 ine
DESCRIPTION:Data brokers must register with CalPrivacy and pay the annual f
 ee ($6\,000 for 2026) by January 31.\n\nCalifornia Delete Act (SB 362\, 20
 23)\, Cal. Civ. Code 1798.99.80 et seq.\, and DROP regulations (California
 )\n\nSource: https://www.cppa.ca.gov/data_brokers/\n\nhttps://rulebook.fru
 .dev/regulations/us-ca-delete-act
URL:https://rulebook.fru.dev/regulations/us-ca-delete-act
CATEGORIES:California,privacy,data-access
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-256@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20260131
DTEND;VALUE=DATE:20260201
SUMMARY:Minnesota Consumer Data Privacy Act (MCDPA): 30-day cure period exp
 ires
DESCRIPTION:The requirement that the AG send a warning letter and allow 30 
 days to cure before suing expires Jan 31\, 2026 (325M.20(a)).\n\nMinnesota
  Consumer Data Privacy Act (HF 4757\, 2024 Minn. Laws ch. 121\, art. 5)\, 
 Minn. Stat. 325M.10-325M.21 (Minnesota)\n\nSource: https://www.revisor.mn.
 gov/statutes/cite/325M.20\n\nhttps://rulebook.fru.dev/regulations/us-mn-mc
 dpa
URL:https://rulebook.fru.dev/regulations/us-mn-mcdpa
CATEGORIES:Minnesota,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-201@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20260201
DTEND;VALUE=DATE:20260202
SUMMARY:Colorado AI Act: Original effective date (superseded)
DESCRIPTION:Original SB 24-205 date\; postponed by SB 25B-004\, so no oblig
 ations applied.\n\nColorado SB 24-205 (Consumer Protections for Artificial
  Intelligence)\, as delayed by SB 25B-004 and repealed and reenacted by SB
  26-189 (Automated Decision-Making Technology) (Colorado)\n\nSource: https
 ://leg.colorado.gov/bills/sb24-205\n\nhttps://rulebook.fru.dev/regulations
 /us-co-ai-act
URL:https://rulebook.fru.dev/regulations/us-co-ai-act
CATEGORIES:Colorado,ai,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-313@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20260227
DTEND;VALUE=DATE:20260228
SUMMARY:Virginia VCDPA: SB 854 preliminarily enjoined (NetChoice v. Jones)
DESCRIPTION:E.D. Va. preliminarily enjoined enforcement of the SB 854 socia
 l media time-limit provisions on First Amendment grounds\; Virginia has ap
 pealed.\n\nVirginia Consumer Data Protection Act (SB 1392 / HB 2307\, 2021
 ) (Virginia)\n\nSource: https://netchoice.org/wp-content/uploads/2026/02/V
 irginia-PI-Opinion_Granted.pdf\n\nhttps://rulebook.fru.dev/regulations/us-
 va-vcdpa
URL:https://rulebook.fru.dev/regulations/us-va-vcdpa
CATEGORIES:Virginia,privacy,children,online-safety
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-279@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20260327
DTEND;VALUE=DATE:20260328
SUMMARY:NY RAISE Act: Chapter amendment S8828 signed
DESCRIPTION:Chapter amendment (ch. 96) finalizes the RAISE Act text.\n\nNew
  York Responsible AI Safety and Education (RAISE) Act (S6953-B/A6453-B of 
 2025)\, as amended by chapter amendment S8828 of 2026 (New York)\n\nSource
 : https://www.nysenate.gov/legislation/bills/2025/S8828\n\nhttps://ruleboo
 k.fru.dev/regulations/us-ny-raise
URL:https://rulebook.fru.dev/regulations/us-ny-raise
CATEGORIES:New York,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-243@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20260401
DTEND;VALUE=DATE:20260402
SUMMARY:Illinois BIPA: Seventh Circuit: amendment applies retroactively
DESCRIPTION:Clay v. Union Pacific (No. 25-2185) holds the damages amendment
  is remedial and applies to pending cases.\n\nIllinois Biometric Informati
 on Privacy Act (740 ILCS 14)\, as amended by SB 2979 (Public Act 103-0769)
  (Illinois)\n\nSource: https://law.justia.com/cases/federal/appellate-cour
 ts/ca7/25-2185/25-2185-2026-04-01.html\n\nhttps://rulebook.fru.dev/regulat
 ions/us-il-bipa
URL:https://rulebook.fru.dev/regulations/us-il-bipa
CATEGORIES:Illinois,biometrics,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-253@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20260401
DTEND;VALUE=DATE:20260402
SUMMARY:Maryland Online Data Privacy Act (MODPA): MODPA applies to personal
  data processing
DESCRIPTION:The act applies to personal data processing activities from Apr
 il 1\, 2026 (Section 2 of ch. 455).\n\nMaryland Online Data Privacy Act of
  2024 (SB 541 / HB 567)\, Md. Code\, Com. Law 14-4601 et seq. (Maryland)\n
 \nSource: https://mgaleg.maryland.gov/2024RS/Chapters_noln/CH_455_sb0541e.
 pdf\n\nhttps://rulebook.fru.dev/regulations/us-md-modpa
URL:https://rulebook.fru.dev/regulations/us-md-modpa
CATEGORIES:Maryland,privacy,children,health,biometrics
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-277@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20260415
DTEND;VALUE=DATE:20260416
SUMMARY:NYDFS Cybersecurity Regulation (Part 500): Annual compliance notifi
 cation
DESCRIPTION:Annual certification or acknowledgment covering calendar year 2
 025 due.\n\nNew York DFS Cybersecurity Requirements for Financial Services
  Companies (23 NYCRR Part 500)\, Second Amendment (New York)\n\nSource: ht
 tps://www.dfs.ny.gov/cybersecurity/23-NYCRR-Part-500\n\nhttps://rulebook.f
 ru.dev/regulations/us-ny-dfs-500
URL:https://rulebook.fru.dev/regulations/us-ny-dfs-500
CATEGORIES:New York,cybersecurity,breach-notification,financial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-202@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20260514
DTEND;VALUE=DATE:20260515
SUMMARY:Colorado AI Act: SB 26-189 signed (repeal and reenact)
DESCRIPTION:SB 26-189 replaces SB 24-205 with a narrower ADMT disclosure fr
 amework and moves the effective date to January 1\, 2027.\n\nColorado SB 2
 4-205 (Consumer Protections for Artificial Intelligence)\, as delayed by S
 B 25B-004 and repealed and reenacted by SB 26-189 (Automated Decision-Maki
 ng Technology) (Colorado)\n\nSource: https://leg.colorado.gov/bills/sb26-1
 89\n\nhttps://rulebook.fru.dev/regulations/us-co-ai-act
URL:https://rulebook.fru.dev/regulations/us-co-ai-act
CATEGORIES:Colorado,ai,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-246@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20260515
DTEND;VALUE=DATE:20260516
SUMMARY:Illinois AI in Employment Law (HB 3773): IDHR proposed notice rules
  published
DESCRIPTION:IDHR publishes proposed Subpart J rules on AI notice in the Ill
 inois Register.\n\nIllinois HB 3773 (Public Act 103-0804)\, amending the I
 llinois Human Rights Act on artificial intelligence in employment (Illinoi
 s)\n\nSource: https://ogletree.com/insights-resources/blog-posts/illinois-
 postpones-proposed-regulations-on-ai-in-employment/\n\nhttps://rulebook.fr
 u.dev/regulations/us-il-hb3773
URL:https://rulebook.fru.dev/regulations/us-il-hb3773
CATEGORIES:Illinois,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-247@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20260602
DTEND;VALUE=DATE:20260603
SUMMARY:Illinois AI in Employment Law (HB 3773): IDHR withdraws and postpon
 es proposed rules
DESCRIPTION:IDHR withdraws the Subpart J proposal and postpones the June 10
 \, 2026 hearing\; no new date announced.\n\nIllinois HB 3773 (Public Act 1
 03-0804)\, amending the Illinois Human Rights Act on artificial intelligen
 ce in employment (Illinois)\n\nSource: https://ogletree.com/insights-resou
 rces/blog-posts/illinois-postpones-proposed-regulations-on-ai-in-employmen
 t/\n\nhttps://rulebook.fru.dev/regulations/us-il-hb3773
URL:https://rulebook.fru.dev/regulations/us-il-hb3773
CATEGORIES:Illinois,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-203@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20260630
DTEND;VALUE=DATE:20260701
SUMMARY:Colorado AI Act: Delayed effective date (superseded)
DESCRIPTION:SB 25B-004 date\; superseded by SB 26-189 before it arrived\, s
 o no obligations applied.\n\nColorado SB 24-205 (Consumer Protections for 
 Artificial Intelligence)\, as delayed by SB 25B-004 and repealed and reena
 cted by SB 26-189 (Automated Decision-Making Technology) (Colorado)\n\nSou
 rce: https://leg.colorado.gov/bills/sb25b-004\n\nhttps://rulebook.fru.dev/
 regulations/us-co-ai-act
URL:https://rulebook.fru.dev/regulations/us-co-ai-act
CATEGORIES:Colorado,ai,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-267@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20260630
DTEND;VALUE=DATE:20260701
SUMMARY:New Jersey NJDPA: A5328 sensitive data sale ban takes effect
DESCRIPTION:A5328\, signed June 30\, 2026\, prohibits selling sensitive per
 sonal data\; the ban took effect on signing.\n\nNew Jersey Data Privacy Ac
 t (P.L.2023\, c.266\; S332) (New Jersey)\n\nSource: https://www.njleg.stat
 e.nj.us/bill-search/2026/A5328\n\nhttps://rulebook.fru.dev/regulations/us-
 nj-njdpa
URL:https://rulebook.fru.dev/regulations/us-nj-njdpa
CATEGORIES:New Jersey,privacy,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-218@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20260701
DTEND;VALUE=DATE:20260702
SUMMARY:Connecticut Data Privacy Act (CTDPA): PA 25-113 (SB 1295) amendment
 s take effect
DESCRIPTION:Thresholds drop to 35\,000 consumers or any sensitive-data proc
 essing or data sale\; expanded sensitive data\, minors' protections\, and 
 LLM-training disclosure in privacy notices.\n\nConnecticut Data Privacy Ac
 t (Public Act 22-15)\, Conn. Gen. Stat. 42-515 et seq.\, as amended by Pub
 lic Act 25-113 (SB 1295) and Public Act 26-64 (SB 4) (Connecticut)\n\nSour
 ce: https://www.cga.ct.gov/2025/ACT/PA/PDF/2025PA-00113-R00SB-01295-PA.PDF
 \n\nhttps://rulebook.fru.dev/regulations/us-ct-ctdpa
URL:https://rulebook.fru.dev/regulations/us-ct-ctdpa
CATEGORIES:Connecticut,privacy,children,ai,health
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-268@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20260701
DTEND;VALUE=DATE:20260702
SUMMARY:New Jersey NJDPA: Mandatory 30-day cure period expires
DESCRIPTION:The Division's duty to issue a cure notice before enforcement e
 nds on the first day of the 18th month after the effective date (N.J.S.A. 
 56:8-166.17(b)).\n\nNew Jersey Data Privacy Act (P.L.2023\, c.266\; S332) 
 (New Jersey)\n\nSource: https://pub.njleg.state.nj.us/Bills/2022/PL23/266_
 .PDF\n\nhttps://rulebook.fru.dev/regulations/us-nj-njdpa
URL:https://rulebook.fru.dev/regulations/us-nj-njdpa
CATEGORIES:New Jersey,privacy,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-309@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20260701
DTEND;VALUE=DATE:20260702
SUMMARY:Utah UCPA: Right to correct takes effect
DESCRIPTION:Consumers may ask controllers to correct inaccurate personal da
 ta (13-61-201(4)\, as amended by Laws 2025\, ch. 468).\n\nUtah Consumer Pr
 ivacy Act (SB 227\, 2022) (Utah)\n\nSource: https://le.utah.gov/xcode/Titl
 e13/Chapter61/13-61-S201.html\n\nhttps://rulebook.fru.dev/regulations/us-u
 t-ucpa
URL:https://rulebook.fru.dev/regulations/us-ut-ucpa
CATEGORIES:Utah,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-314@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20260701
DTEND;VALUE=DATE:20260702
SUMMARY:Virginia VCDPA: Ban on selling precise geolocation data (SB 338)
DESCRIPTION:Controllers may not sell consumers' precise geolocation data (1
 \,750-ft radius)\, replacing the prior consent-based treatment.\n\nVirgini
 a Consumer Data Protection Act (SB 1392 / HB 2307\, 2021) (Virginia)\n\nSo
 urce: https://lis.virginia.gov/bill-details/20261/SB338\n\nhttps://ruleboo
 k.fru.dev/regulations/us-va-vcdpa
URL:https://rulebook.fru.dev/regulations/us-va-vcdpa
CATEGORIES:Virginia,privacy,children,online-safety
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-178@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20260801
DTEND;VALUE=DATE:20260802
SUMMARY:California Delete Act / DROP: Data brokers must begin processing DR
 OP deletion requests
DESCRIPTION:Brokers must access DROP at least every 45 days\, process verif
 ied deletion requests within 45 days\, and treat unverified requests as op
 t-outs of sale/sharing.\n\nCalifornia Delete Act (SB 362\, 2023)\, Cal. Ci
 v. Code 1798.99.80 et seq.\, and DROP regulations (California)\n\nSource: 
 https://www.cppa.ca.gov/data_brokers/\n\nhttps://rulebook.fru.dev/regulati
 ons/us-ca-delete-act
URL:https://rulebook.fru.dev/regulations/us-ca-delete-act
CATEGORIES:California,privacy,data-access
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-219@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20260801
DTEND;VALUE=DATE:20260802
SUMMARY:Connecticut Data Privacy Act (CTDPA): Profiling impact assessments 
 apply
DESCRIPTION:Impact assessment requirements apply to profiling activities cr
 eated or generated on or after Aug 1\, 2026 (Conn. Gen. Stat. 42-522 as am
 ended).\n\nConnecticut Data Privacy Act (Public Act 22-15)\, Conn. Gen. St
 at. 42-515 et seq.\, as amended by Public Act 25-113 (SB 1295) and Public 
 Act 26-64 (SB 4) (Connecticut)\n\nSource: https://www.cga.ct.gov/2025/ACT/
 PA/PDF/2025PA-00113-R00SB-01295-PA.PDF\n\nhttps://rulebook.fru.dev/regulat
 ions/us-ct-ctdpa
URL:https://rulebook.fru.dev/regulations/us-ct-ctdpa
CATEGORIES:Connecticut,privacy,children,ai,health
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-190@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20260802
DTEND;VALUE=DATE:20260803
SUMMARY:California AI Transparency Act (SB 942): Covered provider duties ap
 ply
DESCRIPTION:Detection tool\, manifest and latent disclosures\, and license-
 revocation duties become operative.\n\nCalifornia AI Transparency Act (SB 
 942\, Stats. 2024\, ch. 291)\, as amended by AB 853 (Stats. 2025\, ch. 674
 ) (California)\n\nSource: https://leginfo.legislature.ca.gov/faces/billNav
 Client.xhtml?bill_id=202520260AB853\n\nhttps://rulebook.fru.dev/regulation
 s/us-ca-sb942
URL:https://rulebook.fru.dev/regulations/us-ca-sb942
CATEGORIES:California,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-220@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20261001
DTEND;VALUE=DATE:20261002
SUMMARY:Connecticut Data Privacy Act (CTDPA): PA 26-64 (SB 4) amendments ta
 ke effect
DESCRIPTION:Prohibits controllers and third parties from selling precise ge
 olocation data and enacts data broker and other consumer protection provis
 ions.\n\nConnecticut Data Privacy Act (Public Act 22-15)\, Conn. Gen. Stat
 . 42-515 et seq.\, as amended by Public Act 25-113 (SB 1295) and Public Ac
 t 26-64 (SB 4) (Connecticut)\n\nSource: https://www.cga.ct.gov/2026/ACT/PA
 /PDF/2026PA-00064-R00SB-00004-PA.PDF\n\nhttps://rulebook.fru.dev/regulatio
 ns/us-ct-ctdpa
URL:https://rulebook.fru.dev/regulations/us-ct-ctdpa
CATEGORIES:Connecticut,privacy,children,ai,health
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-191@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20270101
DTEND;VALUE=DATE:20270102
SUMMARY:California AI Transparency Act (SB 942): Large online platform and 
 hosting platform duties
DESCRIPTION:Large online platforms and GenAI hosting platforms must meet th
 e provenance duties added by AB 853.\n\nCalifornia AI Transparency Act (SB
  942\, Stats. 2024\, ch. 291)\, as amended by AB 853 (Stats. 2025\, ch. 67
 4) (California)\n\nSource: https://leginfo.legislature.ca.gov/faces/billNa
 vClient.xhtml?bill_id=202520260AB853\n\nhttps://rulebook.fru.dev/regulatio
 ns/us-ca-sb942
URL:https://rulebook.fru.dev/regulations/us-ca-sb942
CATEGORIES:California,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-186@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20270101
DTEND;VALUE=DATE:20270102
SUMMARY:California SB 53 (TFAIA): First OES anonymized incident report and 
 CDT definition review
DESCRIPTION:OES begins publishing annual anonymized incident summaries and 
 the Department of Technology begins annual review of the act's definitions
 \; the CalCompute framework report is due to the Legislature.\n\nCaliforni
 a SB 53\, Transparency in Frontier Artificial Intelligence Act (Stats. 202
 5\, ch. 138) (California)\n\nSource: https://leginfo.legislature.ca.gov/fa
 ces/billNavClient.xhtml?bill_id=202520260SB53\n\nhttps://rulebook.fru.dev/
 regulations/us-ca-sb53
URL:https://rulebook.fru.dev/regulations/us-ca-sb53
CATEGORIES:California,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-169@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20270101
DTEND;VALUE=DATE:20270102
SUMMARY:CCPA / CPRA: ADMT requirements compliance date
DESCRIPTION:Businesses using ADMT for significant decisions must comply wit
 h Article 11 (pre-use notice\, opt-out\, access rights) by this date (11 C
 CR 7200(b)).\n\nCalifornia Consumer Privacy Act of 2018\, as amended by th
 e California Privacy Rights Act of 2020 (Cal. Civ. Code 1798.100 et seq.) 
 and CPPA regulations (Cal. Code Regs. tit. 11\, 7000 et seq.) (California)
 \n\nSource: https://cppa.ca.gov/regulations/pdf/ccpa_updates_cyber_risk_ad
 mt_appr_text.pdf\n\nhttps://rulebook.fru.dev/regulations/us-ca-ccpa
URL:https://rulebook.fru.dev/regulations/us-ca-ccpa
CATEGORIES:California,privacy,ai,cybersecurity,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-170@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20270101
DTEND;VALUE=DATE:20270102
SUMMARY:CCPA / CPRA: Browsers must support opt-out preference signal (AB 56
 6)
DESCRIPTION:Businesses that develop or maintain a browser must include cons
 umer-configurable functionality to send an opt-out preference signal (Civ.
  Code 1798.136\, operative Jan 1\, 2027).\n\nCalifornia Consumer Privacy A
 ct of 2018\, as amended by the California Privacy Rights Act of 2020 (Cal.
  Civ. Code 1798.100 et seq.) and CPPA regulations (Cal. Code Regs. tit. 11
 \, 7000 et seq.) (California)\n\nSource: https://leginfo.legislature.ca.go
 v/faces/billStatusClient.xhtml?bill_id=202520260AB566\n\nhttps://rulebook.
 fru.dev/regulations/us-ca-ccpa
URL:https://rulebook.fru.dev/regulations/us-ca-ccpa
CATEGORIES:California,privacy,ai,cybersecurity,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-204@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20270101
DTEND;VALUE=DATE:20270102
SUMMARY:Colorado AI Act: ADMT obligations apply
DESCRIPTION:Developer documentation\, consumer notices\, post-adverse-outco
 me disclosure\, correction and human-review rights take effect.\n\nColorad
 o SB 24-205 (Consumer Protections for Artificial Intelligence)\, as delaye
 d by SB 25B-004 and repealed and reenacted by SB 26-189 (Automated Decisio
 n-Making Technology) (Colorado)\n\nSource: https://leg.colorado.gov/bills/
 sb26-189\n\nhttps://rulebook.fru.dev/regulations/us-co-ai-act
URL:https://rulebook.fru.dev/regulations/us-co-ai-act
CATEGORIES:Colorado,ai,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-205@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20270101
DTEND;VALUE=DATE:20270102
SUMMARY:Colorado AI Act: AG rules due
DESCRIPTION:Attorney General must adopt rules clarifying the post-adverse-o
 utcome disclosure requirements.\n\nColorado SB 24-205 (Consumer Protection
 s for Artificial Intelligence)\, as delayed by SB 25B-004 and repealed and
  reenacted by SB 26-189 (Automated Decision-Making Technology) (Colorado)\
 n\nSource: https://leg.colorado.gov/bills/sb26-189\n\nhttps://rulebook.fru
 .dev/regulations/us-co-ai-act
URL:https://rulebook.fru.dev/regulations/us-co-ai-act
CATEGORIES:Colorado,ai,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-221@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20270101
DTEND;VALUE=DATE:20270102
SUMMARY:Connecticut Data Privacy Act (CTDPA): Data broker registration requ
 ired
DESCRIPTION:Data brokers may not sell or license brokered personal data in 
 Connecticut unless registered with the Department of Consumer Protection (
 $2\,500 initial fee).\n\nConnecticut Data Privacy Act (Public Act 22-15)\,
  Conn. Gen. Stat. 42-515 et seq.\, as amended by Public Act 25-113 (SB 129
 5) and Public Act 26-64 (SB 4) (Connecticut)\n\nSource: https://www.cga.ct
 .gov/2026/ACT/PA/PDF/2026PA-00064-R00SB-00004-PA.PDF\n\nhttps://rulebook.f
 ru.dev/regulations/us-ct-ctdpa
URL:https://rulebook.fru.dev/regulations/us-ct-ctdpa
CATEGORIES:Connecticut,privacy,children,ai,health
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-226@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20270101
DTEND;VALUE=DATE:20270102
SUMMARY:Delaware Personal Data Privacy Act (DPDPA): Amended thresholds and 
 third-party duties take effect
DESCRIPTION:Applicability drops to 10\,000 consumers (or 5\,000 + 20% reven
 ue from sale) and new third-party duties (12D-107A) apply.\n\nDelaware Per
 sonal Data Privacy Act (HB 154)\, 6 Del. C. ch. 12D (Delaware)\n\nSource: 
 https://delcode.delaware.gov/title6/c012d/index.html\n\nhttps://rulebook.f
 ru.dev/regulations/us-de-dpdpa
URL:https://rulebook.fru.dev/regulations/us-de-dpdpa
CATEGORIES:Delaware,privacy,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-250@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20270101
DTEND;VALUE=DATE:20270102
SUMMARY:Louisiana Data Privacy Act: Louisiana Data Privacy Act takes effect
DESCRIPTION:Consumer rights and controller duties apply (Act 502\, Section 
 2)\; data protection assessment requirements apply to processing from this
  date.\n\nLouisiana Data Privacy Act (SB 386\, 2026 Regular Session\, Act 
 No. 502)\, La. R.S. 51:1780.1-1780.5 (Louisiana)\n\nSource: https://legis.
 la.gov/legis/ViewDocument.aspx?d=1480202\n\nhttps://rulebook.fru.dev/regul
 ations/us-la-ldpa
URL:https://rulebook.fru.dev/regulations/us-la-ldpa
CATEGORIES:Louisiana,privacy,biometrics
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-263@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20270101
DTEND;VALUE=DATE:20270102
SUMMARY:New Hampshire Privacy Act: Ban on selling personal data of children
  under 13 (HB 1460)
DESCRIPTION:HB 1460 (2026\, ch. 168) prohibits controllers from selling the
  personal data of a child under 13.\n\nNew Hampshire Privacy Act (SB 255\,
  2024)\, RSA chapter 507-H (New Hampshire)\n\nSource: https://gc.nh.gov/bi
 ll_status/billinfo.aspx?id=2443&inflect=2\n\nhttps://rulebook.fru.dev/regu
 lations/us-nh-privacy
URL:https://rulebook.fru.dev/regulations/us-nh-privacy
CATEGORIES:New Hampshire,privacy,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-280@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20270101
DTEND;VALUE=DATE:20270102
SUMMARY:NY RAISE Act: RAISE Act takes effect
DESCRIPTION:Transparency reports\, frontier AI frameworks\, incident report
 ing and DFS disclosure filings apply.\n\nNew York Responsible AI Safety an
 d Education (RAISE) Act (S6953-B/A6453-B of 2025)\, as amended by chapter 
 amendment S8828 of 2026 (New York)\n\nSource: https://www.nysenate.gov/leg
 islation/bills/2025/S8828\n\nhttps://rulebook.fru.dev/regulations/us-ny-ra
 ise
URL:https://rulebook.fru.dev/regulations/us-ny-raise
CATEGORIES:New York,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-282@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20270101
DTEND;VALUE=DATE:20270102
SUMMARY:Oklahoma OKCDPA: Oklahoma Consumer Data Privacy Act takes effect
DESCRIPTION:All OKCDPA obligations and consumer rights apply.\n\nOklahoma C
 onsumer Data Privacy Act (SB 546\, 2026) (Oklahoma)\n\nSource: https://www
 .okhouse.gov/posts/news-20260323_2\n\nhttps://rulebook.fru.dev/regulations
 /us-ok-okcdpa
URL:https://rulebook.fru.dev/regulations/us-ok-okcdpa
CATEGORIES:Oklahoma,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-310@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20270101
DTEND;VALUE=DATE:20270102
SUMMARY:Utah UCPA: UCPA extends to motor vehicle manufacturers
DESCRIPTION:Motor vehicle manufacturers whose vehicles are sold or leased i
 n Utah and that collect personal data through vehicle data systems are cov
 ered regardless of the revenue and consumer thresholds (13-61-102\, as ame
 nded by Laws 2026\, ch. 193).\n\nUtah Consumer Privacy Act (SB 227\, 2022)
  (Utah)\n\nSource: https://le.utah.gov/xcode/Title13/Chapter61/13-61-S102.
 html\n\nhttps://rulebook.fru.dev/regulations/us-ut-ucpa
URL:https://rulebook.fru.dev/regulations/us-ut-ucpa
CATEGORIES:Utah,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-179@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20270131
DTEND;VALUE=DATE:20270201
SUMMARY:California Delete Act / DROP: Annual data broker registration deadl
 ine
DESCRIPTION:Data brokers must renew registration with CalPrivacy by January
  31 following each year they meet the definition.\n\nCalifornia Delete Act
  (SB 362\, 2023)\, Cal. Civ. Code 1798.99.80 et seq.\, and DROP regulation
 s (California)\n\nSource: https://leginfo.legislature.ca.gov/faces/codes_d
 isplaySection.xhtml?lawCode=CIV&sectionNum=1798.99.82\n\nhttps://rulebook.
 fru.dev/regulations/us-ca-delete-act
URL:https://rulebook.fru.dev/regulations/us-ca-delete-act
CATEGORIES:California,privacy,data-access
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-254@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20270401
DTEND;VALUE=DATE:20270402
SUMMARY:Maryland Online Data Privacy Act (MODPA): Discretionary 60-day cure
  period ends
DESCRIPTION:The Division's discretionary notice-and-cure (at least 60 days)
  applies only to violations occurring on or before April 1\, 2027 (Com. La
 w 14-4614).\n\nMaryland Online Data Privacy Act of 2024 (SB 541 / HB 567)\
 , Md. Code\, Com. Law 14-4601 et seq. (Maryland)\n\nSource: https://mgaleg
 .maryland.gov/2024RS/Chapters_noln/CH_455_sb0541e.pdf\n\nhttps://rulebook.
 fru.dev/regulations/us-md-modpa
URL:https://rulebook.fru.dev/regulations/us-md-modpa
CATEGORIES:Maryland,privacy,children,health,biometrics
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-161@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20270501
DTEND;VALUE=DATE:20270502
SUMMARY:Alabama Personal Data Protection Act (APDPA): APDPA takes effect
DESCRIPTION:Consumer rights and controller/processor obligations apply (HB 
 351 section 12).\n\nAlabama Personal Data Protection Act (HB 351\, 2026 Re
 gular Session) (Alabama)\n\nSource: https://alison.legislature.state.al.us
 /files/pdf/SearchableInstruments/2026RS/HB351-enr.pdf\n\nhttps://rulebook.
 fru.dev/regulations/us-al-apdpa
URL:https://rulebook.fru.dev/regulations/us-al-apdpa
CATEGORIES:Alabama,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-183@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20270701
DTEND;VALUE=DATE:20270702
SUMMARY:California SB 243 (companion chatbots): First annual report to Offi
 ce of Suicide Prevention
DESCRIPTION:Operators begin annual reporting on crisis referrals and detect
 ion protocols.\n\nCalifornia SB 243\, Companion Chatbots (Stats. 2025\, ch
 . 677) (California)\n\nSource: https://leginfo.legislature.ca.gov/faces/bi
 llNavClient.xhtml?bill_id=202520260SB243\n\nhttps://rulebook.fru.dev/regul
 ations/us-ca-sb243
URL:https://rulebook.fru.dev/regulations/us-ca-sb243
CATEGORIES:California,ai,children,online-safety
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-307@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20270701
DTEND;VALUE=DATE:20270702
SUMMARY:Utah AI Policy Act: Scheduled repeal of Title 13\, Ch. 72
DESCRIPTION:SB 332 extends the AI Policy Act repeal date from May 1\, 2025 
 to July 1\, 2027.\n\nUtah Artificial Intelligence Policy Act (SB 149\, 202
 4)\, as amended by SB 226 and SB 332 (2025) (Utah)\n\nSource: https://le.u
 tah.gov/~2025/bills/static/SB0332.html\n\nhttps://rulebook.fru.dev/regulat
 ions/us-ut-aipa
URL:https://rulebook.fru.dev/regulations/us-ut-aipa
CATEGORIES:Utah,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-251@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20270731
DTEND;VALUE=DATE:20270801
SUMMARY:Louisiana Data Privacy Act: 30-day cure period expires
DESCRIPTION:AG's obligation to give 30-day notice and allow cure before inv
 estigating applies only from Jan 1 through July 31\, 2027 (R.S. 51:1780.5(
 D)).\n\nLouisiana Data Privacy Act (SB 386\, 2026 Regular Session\, Act No
 . 502)\, La. R.S. 51:1780.1-1780.5 (Louisiana)\n\nSource: https://legis.la
 .gov/legis/ViewDocument.aspx?d=1480202\n\nhttps://rulebook.fru.dev/regulat
 ions/us-la-ldpa
URL:https://rulebook.fru.dev/regulations/us-la-ldpa
CATEGORIES:Louisiana,privacy,biometrics
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-171@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20271231
DTEND;VALUE=DATE:20280101
SUMMARY:CCPA / CPRA: Risk assessments for pre-existing processing due
DESCRIPTION:Risk assessments must be completed and documented for high-risk
  processing that began before Jan 1\, 2026 and continues after (11 CCR 715
 5(b)).\n\nCalifornia Consumer Privacy Act of 2018\, as amended by the Cali
 fornia Privacy Rights Act of 2020 (Cal. Civ. Code 1798.100 et seq.) and CP
 PA regulations (Cal. Code Regs. tit. 11\, 7000 et seq.) (California)\n\nSo
 urce: https://cppa.ca.gov/regulations/pdf/ccpa_updates_cyber_risk_admt_app
 r_text.pdf\n\nhttps://rulebook.fru.dev/regulations/us-ca-ccpa
URL:https://rulebook.fru.dev/regulations/us-ca-ccpa
CATEGORIES:California,privacy,ai,cybersecurity,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-192@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20280101
DTEND;VALUE=DATE:20280102
SUMMARY:California AI Transparency Act (SB 942): Capture device manufacture
 r duties
DESCRIPTION:Capture device manufacturer provenance requirements become oper
 ative.\n\nCalifornia AI Transparency Act (SB 942\, Stats. 2024\, ch. 291)\
 , as amended by AB 853 (Stats. 2025\, ch. 674) (California)\n\nSource: htt
 ps://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=20252026
 0AB853\n\nhttps://rulebook.fru.dev/regulations/us-ca-sb942
URL:https://rulebook.fru.dev/regulations/us-ca-sb942
CATEGORIES:California,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-180@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20280101
DTEND;VALUE=DATE:20280102
SUMMARY:California Delete Act / DROP: Independent third-party audits begin
DESCRIPTION:Beginning Jan 1\, 2028 and every 3 years thereafter\, data brok
 ers must undergo an independent audit of Delete Act compliance.\n\nCalifor
 nia Delete Act (SB 362\, 2023)\, Cal. Civ. Code 1798.99.80 et seq.\, and D
 ROP regulations (California)\n\nSource: https://www.cppa.ca.gov/data_broke
 rs/\n\nhttps://rulebook.fru.dev/regulations/us-ca-delete-act
URL:https://rulebook.fru.dev/regulations/us-ca-delete-act
CATEGORIES:California,privacy,data-access
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-315@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20280101
DTEND;VALUE=DATE:20280102
SUMMARY:Vermont VDPOSA: Vermont Data Privacy and Online Surveillance Act ta
 kes effect
DESCRIPTION:All obligations under Act 145 apply (sec. 4).\n\nVermont Data P
 rivacy and Online Surveillance Act (S.71\, Act 145 of 2026) (Vermont)\n\nS
 ource: https://legislature.vermont.gov/Documents/2026/Docs/ACTS/ACT145/ACT
 145%20As%20Enacted.pdf\n\nhttps://rulebook.fru.dev/regulations/us-vt-vdpos
 a
URL:https://rulebook.fru.dev/regulations/us-vt-vdposa
CATEGORIES:Vermont,privacy,health,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-172@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20280401
DTEND;VALUE=DATE:20280402
SUMMARY:CCPA / CPRA: First risk assessment submission to CPPA
DESCRIPTION:Businesses must submit required risk assessment information and
  attestation for assessments conducted in 2026 and 2027 (11 CCR 7157(a)(1)
 )\; annually by April 1 thereafter.\n\nCalifornia Consumer Privacy Act of 
 2018\, as amended by the California Privacy Rights Act of 2020 (Cal. Civ. 
 Code 1798.100 et seq.) and CPPA regulations (Cal. Code Regs. tit. 11\, 700
 0 et seq.) (California)\n\nSource: https://cppa.ca.gov/regulations/pdf/ccp
 a_updates_cyber_risk_admt_appr_text.pdf\n\nhttps://rulebook.fru.dev/regula
 tions/us-ca-ccpa
URL:https://rulebook.fru.dev/regulations/us-ca-ccpa
CATEGORIES:California,privacy,ai,cybersecurity,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-173@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20280401
DTEND;VALUE=DATE:20280402
SUMMARY:CCPA / CPRA: Cybersecurity audit due: revenue over $100M
DESCRIPTION:First cybersecurity audit report (covering Jan 1\, 2027 - Jan 1
 \, 2028) and certification due for businesses with 2026 annual gross reven
 ue over $100M (11 CCR 7121(a)(1)).\n\nCalifornia Consumer Privacy Act of 2
 018\, as amended by the California Privacy Rights Act of 2020 (Cal. Civ. C
 ode 1798.100 et seq.) and CPPA regulations (Cal. Code Regs. tit. 11\, 7000
  et seq.) (California)\n\nSource: https://cppa.ca.gov/regulations/pdf/ccpa
 _updates_cyber_risk_admt_appr_text.pdf\n\nhttps://rulebook.fru.dev/regulat
 ions/us-ca-ccpa
URL:https://rulebook.fru.dev/regulations/us-ca-ccpa
CATEGORIES:California,privacy,ai,cybersecurity,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-222@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20281001
DTEND;VALUE=DATE:20281002
SUMMARY:Connecticut Data Privacy Act (CTDPA): Data brokers must process sta
 te deletion mechanism requests
DESCRIPTION:Registered data brokers must access the DCP accessible deletion
  mechanism at least every 45 days and process deletion requests.\n\nConnec
 ticut Data Privacy Act (Public Act 22-15)\, Conn. Gen. Stat. 42-515 et seq
 .\, as amended by Public Act 25-113 (SB 1295) and Public Act 26-64 (SB 4) 
 (Connecticut)\n\nSource: https://www.cga.ct.gov/2026/ACT/PA/PDF/2026PA-000
 64-R00SB-00004-PA.PDF\n\nhttps://rulebook.fru.dev/regulations/us-ct-ctdpa
URL:https://rulebook.fru.dev/regulations/us-ct-ctdpa
CATEGORIES:Connecticut,privacy,children,ai,health
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-174@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20290401
DTEND;VALUE=DATE:20290402
SUMMARY:CCPA / CPRA: Cybersecurity audit due: revenue $50M-$100M
DESCRIPTION:First cybersecurity audit report (covering 2028) due for busine
 sses with 2027 annual gross revenue between $50M and $100M (11 CCR 7121(a)
 (2)).\n\nCalifornia Consumer Privacy Act of 2018\, as amended by the Calif
 ornia Privacy Rights Act of 2020 (Cal. Civ. Code 1798.100 et seq.) and CPP
 A regulations (Cal. Code Regs. tit. 11\, 7000 et seq.) (California)\n\nSou
 rce: https://cppa.ca.gov/regulations/pdf/ccpa_updates_cyber_risk_admt_appr
 _text.pdf\n\nhttps://rulebook.fru.dev/regulations/us-ca-ccpa
URL:https://rulebook.fru.dev/regulations/us-ca-ccpa
CATEGORIES:California,privacy,ai,cybersecurity,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-316@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20290630
DTEND;VALUE=DATE:20290701
SUMMARY:Vermont VDPOSA: Mandatory 60-day cure period expires
DESCRIPTION:The AG's duty to issue a cure notice before enforcement ends Ju
 ne 30\, 2029 (Act 145 sec. 3).\n\nVermont Data Privacy and Online Surveill
 ance Act (S.71\, Act 145 of 2026) (Vermont)\n\nSource: https://legislature
 .vermont.gov/Documents/2026/Docs/ACTS/ACT145/ACT145%20As%20Enacted.pdf\n\n
 https://rulebook.fru.dev/regulations/us-vt-vdposa
URL:https://rulebook.fru.dev/regulations/us-vt-vdposa
CATEGORIES:Vermont,privacy,health,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-257@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20290731
DTEND;VALUE=DATE:20290801
SUMMARY:Minnesota Consumer Data Privacy Act (MCDPA): Postsecondary institut
 ions must comply
DESCRIPTION:Postsecondary institutions regulated by the Office of Higher Ed
 ucation must comply by July 31\, 2029.\n\nMinnesota Consumer Data Privacy 
 Act (HF 4757\, 2024 Minn. Laws ch. 121\, art. 5)\, Minn. Stat. 325M.10-325
 M.21 (Minnesota)\n\nSource: https://www.revisor.mn.gov/statutes/cite/325M.
 20\n\nhttps://rulebook.fru.dev/regulations/us-mn-mcdpa
URL:https://rulebook.fru.dev/regulations/us-mn-mcdpa
CATEGORIES:Minnesota,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-206@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20300101
DTEND;VALUE=DATE:20300102
SUMMARY:Colorado AI Act: Mandatory cure period ends
DESCRIPTION:The AG's obligation to offer a 60-day notice-and-cure period ex
 pires.\n\nColorado SB 24-205 (Consumer Protections for Artificial Intellig
 ence)\, as delayed by SB 25B-004 and repealed and reenacted by SB 26-189 (
 Automated Decision-Making Technology) (Colorado)\n\nSource: https://leg.co
 lorado.gov/bills/sb26-189\n\nhttps://rulebook.fru.dev/regulations/us-co-ai
 -act
URL:https://rulebook.fru.dev/regulations/us-co-ai-act
CATEGORIES:Colorado,ai,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-175@regulations.fru.dev
DTSTAMP:20260924T151141Z
DTSTART;VALUE=DATE:20300401
DTEND;VALUE=DATE:20300402
SUMMARY:CCPA / CPRA: Cybersecurity audit due: revenue under $50M
DESCRIPTION:First cybersecurity audit report (covering 2029) due for covere
 d businesses with 2028 annual gross revenue under $50M (11 CCR 7121(a)(3))
 \; annual by April 1 thereafter.\n\nCalifornia Consumer Privacy Act of 201
 8\, as amended by the California Privacy Rights Act of 2020 (Cal. Civ. Cod
 e 1798.100 et seq.) and CPPA regulations (Cal. Code Regs. tit. 11\, 7000 e
 t seq.) (California)\n\nSource: https://cppa.ca.gov/regulations/pdf/ccpa_u
 pdates_cyber_risk_admt_appr_text.pdf\n\nhttps://rulebook.fru.dev/regulatio
 ns/us-ca-ccpa
URL:https://rulebook.fru.dev/regulations/us-ca-ccpa
CATEGORIES:California,privacy,ai,cybersecurity,children
TRANSP:TRANSPARENT
END:VEVENT
END:VCALENDAR
