BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//fru.dev//Rulebook//EN
CALSCALE:GREGORIAN
METHOD:PUBLISH
X-WR-CALNAME:Regulation deadlines (Rulebook)
X-WR-CALDESC:Compliance deadlines tracked at rulebook.fru.dev
REFRESH-INTERVAL;VALUE=DURATION:P1D
X-PUBLISHED-TTL:P1D
BEGIN:VEVENT
UID:deadline-18@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20010101
DTEND;VALUE=DATE:20010102
SUMMARY:PIPEDA: PIPEDA Part 1 in force (phase 1)
DESCRIPTION:Applies to federally regulated organisations.\n\nPersonal Infor
 mation Protection and Electronic Documents Act (Canada)\n\nSource: https:/
 /laws-lois.justice.gc.ca/eng/acts/p-8.6/\n\nhttps://rulebook.fru.dev/regul
 ations/ca-pipeda
URL:https://rulebook.fru.dev/regulations/ca-pipeda
CATEGORIES:Canada,privacy,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-90@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20020731
DTEND;VALUE=DATE:20020801
SUMMARY:ePrivacy Directive (cookie law): ePrivacy Directive enters into for
 ce
DESCRIPTION:Entered into force on the day of publication in the OJ (Art 20)
 .\n\nDirective 2002/58/EC concerning the processing of personal data and t
 he protection of privacy in the electronic communications sector (ePrivacy
  Directive)\, as amended by Directive 2009/136/EC (European Union)\n\nSour
 ce: https://eur-lex.europa.eu/eli/dir/2002/58/oj\n\nhttps://rulebook.fru.d
 ev/regulations/eu-eprivacy
URL:https://rulebook.fru.dev/regulations/eu-eprivacy
CATEGORIES:European Union,privacy,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-91@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20031031
DTEND;VALUE=DATE:20031101
SUMMARY:ePrivacy Directive (cookie law): Original transposition deadline
DESCRIPTION:Member States had to bring national laws into force before 31 O
 ct 2003 (Art 17).\n\nDirective 2002/58/EC concerning the processing of per
 sonal data and the protection of privacy in the electronic communications 
 sector (ePrivacy Directive)\, as amended by Directive 2009/136/EC (Europea
 n Union)\n\nSource: https://eur-lex.europa.eu/eli/dir/2002/58/oj\n\nhttps:
 //rulebook.fru.dev/regulations/eu-eprivacy
URL:https://rulebook.fru.dev/regulations/eu-eprivacy
CATEGORIES:European Union,privacy,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-19@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20040101
DTEND;VALUE=DATE:20040102
SUMMARY:PIPEDA: PIPEDA applies to all commercial activity
DESCRIPTION:Extended to commercial activity in provinces without substantia
 lly similar legislation.\n\nPersonal Information Protection and Electronic
  Documents Act (Canada)\n\nSource: https://laws-lois.justice.gc.ca/eng/act
 s/p-8.6/\n\nhttps://rulebook.fru.dev/regulations/ca-pipeda
URL:https://rulebook.fru.dev/regulations/ca-pipeda
CATEGORIES:Canada,privacy,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-231@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20100222
DTEND;VALUE=DATE:20100223
SUMMARY:FTC Health Breach Notification Rule: Full compliance with original 
 Rule
DESCRIPTION:Full compliance with the 2009 Health Breach Notification Rule w
 as required.\n\nFTC Health Breach Notification Rule (16 CFR Part 318)\, as
  amended 2024 (United States (Federal))\n\nSource: https://www.federalregi
 ster.gov/citation/74-FR-42962\n\nhttps://rulebook.fru.dev/regulations/us-f
 tc-hbnr
URL:https://rulebook.fru.dev/regulations/us-ftc-hbnr
CATEGORIES:United States (Federal),health,privacy,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-92@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20110525
DTEND;VALUE=DATE:20110526
SUMMARY:ePrivacy Directive (cookie law): Cookie consent amendment transposi
 tion deadline
DESCRIPTION:Directive 2009/136/EC\, which changed Art 5(3) to require conse
 nt for cookies\, had to be transposed by 25 May 2011.\n\nDirective 2002/58
 /EC concerning the processing of personal data and the protection of priva
 cy in the electronic communications sector (ePrivacy Directive)\, as amend
 ed by Directive 2009/136/EC (European Union)\n\nSource: https://eur-lex.eu
 ropa.eu/eli/dir/2009/136/oj\n\nhttps://rulebook.fru.dev/regulations/eu-epr
 ivacy
URL:https://rulebook.fru.dev/regulations/eu-eprivacy
CATEGORIES:European Union,privacy,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-139@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20140702
DTEND;VALUE=DATE:20140703
SUMMARY:Singapore PDPA: PDPA data protection obligations take effect
DESCRIPTION:Main data protection provisions come into force.\n\nPersonal Da
 ta Protection Act 2012 (Singapore) (Singapore)\n\nSource: https://sso.agc.
 gov.sg/Act/PDPA2012\n\nhttps://rulebook.fru.dev/regulations/sg-pdpa
URL:https://rulebook.fru.dev/regulations/sg-pdpa
CATEGORIES:Singapore,privacy,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-93@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20160524
DTEND;VALUE=DATE:20160525
SUMMARY:GDPR: GDPR enters into force
DESCRIPTION:Regulation entered into force on the twentieth day after public
 ation in OJ L 119 of 4 May 2016 (Art 99(1)).\n\nRegulation (EU) 2016/679 (
 General Data Protection Regulation) (European Union)\n\nSource: https://eu
 r-lex.europa.eu/eli/reg/2016/679/oj\n\nhttps://rulebook.fru.dev/regulation
 s/eu-gdpr
URL:https://rulebook.fru.dev/regulations/eu-gdpr
CATEGORIES:European Union,privacy,breach-notification,data-access,children,
 biometrics,health
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-269@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20170301
DTEND;VALUE=DATE:20170302
SUMMARY:NYDFS Cybersecurity Regulation (Part 500): Part 500 effective
DESCRIPTION:Original cybersecurity regulation takes effect.\n\nNew York DFS
  Cybersecurity Requirements for Financial Services Companies (23 NYCRR Par
 t 500)\, Second Amendment (New York)\n\nSource: https://www.dfs.ny.gov/cyb
 ersecurity/23-NYCRR-Part-500\n\nhttps://rulebook.fru.dev/regulations/us-ny
 -dfs-500
URL:https://rulebook.fru.dev/regulations/us-ny-dfs-500
CATEGORIES:New York,cybersecurity,breach-notification,financial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-94@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20180525
DTEND;VALUE=DATE:20180526
SUMMARY:GDPR: GDPR applies
DESCRIPTION:All GDPR obligations apply from 25 May 2018 (Art 99(2))\, repla
 cing Directive 95/46/EC.\n\nRegulation (EU) 2016/679 (General Data Protect
 ion Regulation) (European Union)\n\nSource: https://eur-lex.europa.eu/eli/
 reg/2016/679/oj\n\nhttps://rulebook.fru.dev/regulations/eu-gdpr
URL:https://rulebook.fru.dev/regulations/eu-gdpr
CATEGORIES:European Union,privacy,breach-notification,data-access,children,
 biometrics,health
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-153@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20180525
DTEND;VALUE=DATE:20180526
SUMMARY:UK GDPR: Data Protection Act 2018 and GDPR apply
DESCRIPTION:DPA 2018 and EU GDPR began applying in the UK.\n\nUK General Da
 ta Protection Regulation and Data Protection Act 2018 (United Kingdom)\n\n
 Source: https://www.legislation.gov.uk/ukpga/2018/12/contents\n\nhttps://r
 ulebook.fru.dev/regulations/uk-gdpr
URL:https://rulebook.fru.dev/regulations/uk-gdpr
CATEGORIES:United Kingdom,privacy,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-20@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20181101
DTEND;VALUE=DATE:20181102
SUMMARY:PIPEDA: Mandatory breach reporting
DESCRIPTION:Breach of security safeguards reporting\, notification and reco
 rd-keeping obligations take effect.\n\nPersonal Information Protection and
  Electronic Documents Act (Canada)\n\nSource: https://laws-lois.justice.gc
 .ca/eng/acts/p-8.6/\n\nhttps://rulebook.fru.dev/regulations/ca-pipeda
URL:https://rulebook.fru.dev/regulations/ca-pipeda
CATEGORIES:Canada,privacy,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-123@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20191125
DTEND;VALUE=DATE:20191126
SUMMARY:Kenya Data Protection Act: Data Protection Act in force
DESCRIPTION:Act commences.\n\nData Protection Act\, 2019 (No. 24 of 2019) (
 Kenya)\n\nSource: https://www.odpc.go.ke/\n\nhttps://rulebook.fru.dev/regu
 lations/ke-dpa
URL:https://rulebook.fru.dev/regulations/ke-dpa
CATEGORIES:Kenya,privacy,breach-notification,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-325@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20200701
DTEND;VALUE=DATE:20200702
SUMMARY:South Africa POPIA: Main POPIA provisions commence
DESCRIPTION:Most sections commence with a 12-month grace period.\n\nProtect
 ion of Personal Information Act\, 2013 (Act No. 4 of 2013) (South Africa)\
 n\nSource: https://www.gov.za/documents/protection-personal-information-ac
 t\n\nhttps://rulebook.fru.dev/regulations/za-popia
URL:https://rulebook.fru.dev/regulations/za-popia
CATEGORIES:South Africa,privacy,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-11@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20200918
DTEND;VALUE=DATE:20200919
SUMMARY:Brazil LGPD: LGPD in force
DESCRIPTION:Main LGPD provisions take effect.\n\nLei Geral de Proteção de
  Dados Pessoais (Law No. 13.709/2018) (Brazil)\n\nSource: https://www.plan
 alto.gov.br/ccivil_03/_ato2015-2018/2018/lei/l13709.htm\n\nhttps://ruleboo
 k.fru.dev/regulations/br-lgpd
URL:https://rulebook.fru.dev/regulations/br-lgpd
CATEGORIES:Brazil,privacy,breach-notification,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-134@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20201201
DTEND;VALUE=DATE:20201202
SUMMARY:New Zealand Privacy Act: Privacy Act 2020 in force
DESCRIPTION:IPPs\, mandatory breach notification and compliance notices app
 ly.\n\nPrivacy Act 2020 (New Zealand)\, as amended by the Privacy Amendmen
 t Act 2025 (New Zealand)\n\nSource: https://www.justice.govt.nz/justice-se
 ctor-policy/key-initiatives/enhancing-the-privacy-act/\n\nhttps://rulebook
 .fru.dev/regulations/nz-privacy-act
URL:https://rulebook.fru.dev/regulations/nz-privacy-act
CATEGORIES:New Zealand,privacy,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-154@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20210101
DTEND;VALUE=DATE:20210102
SUMMARY:UK GDPR: UK GDPR takes effect after Brexit transition
DESCRIPTION:Retained EU GDPR becomes the UK GDPR at the end of the Brexit i
 mplementation period.\n\nUK General Data Protection Regulation and Data Pr
 otection Act 2018 (United Kingdom)\n\nSource: https://www.legislation.gov.
 uk/eur/2016/679/contents\n\nhttps://rulebook.fru.dev/regulations/uk-gdpr
URL:https://rulebook.fru.dev/regulations/uk-gdpr
CATEGORIES:United Kingdom,privacy,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-140@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20210201
DTEND;VALUE=DATE:20210202
SUMMARY:Singapore PDPA: 2020 amendments largely in force
DESCRIPTION:Mandatory data breach notification and revised consent framewor
 k apply.\n\nPersonal Data Protection Act 2012 (Singapore) (Singapore)\n\nS
 ource: https://sso.agc.gov.sg/Act/PDPA2012\n\nhttps://rulebook.fru.dev/reg
 ulations/sg-pdpa
URL:https://rulebook.fru.dev/regulations/sg-pdpa
CATEGORIES:Singapore,privacy,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-326@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20210701
DTEND;VALUE=DATE:20210702
SUMMARY:South Africa POPIA: Compliance grace period ends
DESCRIPTION:Responsible parties must comply\; Regulator enforcement begins 
 (grace period ended 30 June 2021).\n\nProtection of Personal Information A
 ct\, 2013 (Act No. 4 of 2013) (South Africa)\n\nSource: https://www.gov.za
 /documents/protection-personal-information-act\n\nhttps://rulebook.fru.dev
 /regulations/za-popia
URL:https://rulebook.fru.dev/regulations/za-popia
CATEGORIES:South Africa,privacy,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-12@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20210801
DTEND;VALUE=DATE:20210802
SUMMARY:Brazil LGPD: ANPD sanctions enforceable
DESCRIPTION:Administrative sanctions (Arts. 52-54) become applicable per La
 w 14.010/2020.\n\nLei Geral de Proteção de Dados Pessoais (Law No. 13.70
 9/2018) (Brazil)\n\nSource: https://www.planalto.gov.br/ccivil_03/_ato2015
 -2018/2018/lei/l13709.htm\n\nhttps://rulebook.fru.dev/regulations/br-lgpd
URL:https://rulebook.fru.dev/regulations/br-lgpd
CATEGORIES:Brazil,privacy,breach-notification,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-21@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20210922
DTEND;VALUE=DATE:20210923
SUMMARY:Quebec Law 25: Assent
DESCRIPTION:Bill 64 assented to as S.Q. 2021\, c. 25.\n\nAct to modernize l
 egislative provisions as regards the protection of personal information (L
 aw 25\, formerly Bill 64) (Quebec\, Canada)\n\nSource: https://www.legisqu
 ebec.gouv.qc.ca/en/document/cs/P-39.1\n\nhttps://rulebook.fru.dev/regulati
 ons/ca-qc-law25
URL:https://rulebook.fru.dev/regulations/ca-qc-law25
CATEGORIES:Quebec\, Canada,privacy,breach-notification,biometrics
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-1@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20220102
DTEND;VALUE=DATE:20220103
SUMMARY:UAE PDPL: PDPL enters into force
DESCRIPTION:Decree-law takes effect\; compliance obligations tied to Execut
 ive Regulations.\n\nFederal Decree-Law No. 45 of 2021 on the Protection of
  Personal Data (United Arab Emirates)\n\nSource: https://uaelegislation.go
 v.ae/en/legislations/1972\n\nhttps://rulebook.fru.dev/regulations/ae-pdpl
URL:https://rulebook.fru.dev/regulations/ae-pdpl
CATEGORIES:United Arab Emirates,privacy,breach-notification,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-233@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20220110
DTEND;VALUE=DATE:20220111
SUMMARY:GLBA Safeguards Rule: 2021 Safeguards Rule amendments effective
DESCRIPTION:The amended Safeguards Rule published December 9\, 2021 took ef
 fect\, with the more detailed program elements in 314.5 deferred.\n\nFTC S
 tandards for Safeguarding Customer Information (Safeguards Rule)\, 16 CFR 
 Part 314\, under the Gramm-Leach-Bliley Act (United States (Federal))\n\nS
 ource: https://www.federalregister.gov/documents/2021/12/09/2021-25736/sta
 ndards-for-safeguarding-customer-information\n\nhttps://rulebook.fru.dev/r
 egulations/us-glba-safeguards
URL:https://rulebook.fru.dev/regulations/us-glba-safeguards
CATEGORIES:United States (Federal),financial,cybersecurity,breach-notificat
 ion,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-121@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20220401
DTEND;VALUE=DATE:20220402
SUMMARY:Japan APPI: 2020 amendments in force
DESCRIPTION:Mandatory breach reporting\, pseudonymized information and stri
 cter cross-border rules apply.\n\nAct on the Protection of Personal Inform
 ation (Act No. 57 of 2003)\, as amended including the 2026 amendment act (
 Japan)\n\nSource: https://www.ppc.go.jp/en/legal/\n\nhttps://rulebook.fru.
 dev/regulations/jp-appi
URL:https://rulebook.fru.dev/regulations/jp-appi
CATEGORIES:Japan,privacy,children,biometrics,breach-notification,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-142@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20220601
DTEND;VALUE=DATE:20220602
SUMMARY:Thailand PDPA: PDPA main obligations take effect
DESCRIPTION:Core data protection obligations and penalties apply after post
 ponement Royal Decrees.\n\nPersonal Data Protection Act B.E. 2562 (2019) (
 Thailand)\n\nSource: https://www.ratchakitcha.soc.go.th/DATA/PDF/2562/A/06
 9/T_0052.PDF\n\nhttps://rulebook.fru.dev/regulations/th-pdpa
URL:https://rulebook.fru.dev/regulations/th-pdpa
CATEGORIES:Thailand,privacy,breach-notification,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-22@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20220922
DTEND;VALUE=DATE:20220923
SUMMARY:Quebec Law 25: Phase 1: privacy officer and incident reporting
DESCRIPTION:Person in charge of personal information protection\, confident
 iality incident notification and register apply.\n\nAct to modernize legis
 lative provisions as regards the protection of personal information (Law 2
 5\, formerly Bill 64) (Quebec\, Canada)\n\nSource: https://www.legisquebec
 .gouv.qc.ca/en/document/cs/P-39.1\n\nhttps://rulebook.fru.dev/regulations/
 ca-qc-law25
URL:https://rulebook.fru.dev/regulations/ca-qc-law25
CATEGORIES:Quebec\, Canada,privacy,breach-notification,biometrics
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-141@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20221001
DTEND;VALUE=DATE:20221002
SUMMARY:Singapore PDPA: Higher financial penalty cap applies
DESCRIPTION:Maximum penalty rises to 10% of Singapore turnover for organiza
 tions with turnover above SGD 10 million.\n\nPersonal Data Protection Act 
 2012 (Singapore) (Singapore)\n\nSource: https://sso.agc.gov.sg/Act/PDPA201
 2\n\nhttps://rulebook.fru.dev/regulations/sg-pdpa
URL:https://rulebook.fru.dev/regulations/sg-pdpa
CATEGORIES:Singapore,privacy,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-112@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20221017
DTEND;VALUE=DATE:20221018
SUMMARY:Indonesia PDP Law: PDP Law enacted and in force
DESCRIPTION:Law takes effect on enactment\, starting a 2-year transition.\n
 \nLaw No. 27 of 2022 on Personal Data Protection (Undang-Undang Pelindunga
 n Data Pribadi) (Indonesia)\n\nSource: https://peraturan.bpk.go.id/Details
 /229798/uu-no-27-tahun-2022\n\nhttps://rulebook.fru.dev/regulations/id-pdp
URL:https://rulebook.fru.dev/regulations/id-pdp
CATEGORIES:Indonesia,privacy,breach-notification,data-residency,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-70@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20230116
DTEND;VALUE=DATE:20230117
SUMMARY:DORA: DORA enters into force
DESCRIPTION:Entered into force on the twentieth day after publication in OJ
  L 333 of 27 Dec 2022 (Art 64).\n\nRegulation (EU) 2022/2554 on digital op
 erational resilience for the financial sector (Digital Operational Resilie
 nce Act) (European Union)\n\nSource: https://eur-lex.europa.eu/eli/reg/202
 2/2554/oj\n\nhttps://rulebook.fru.dev/regulations/eu-dora
URL:https://rulebook.fru.dev/regulations/eu-dora
CATEGORIES:European Union,cybersecurity,financial,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-98@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20230116
DTEND;VALUE=DATE:20230117
SUMMARY:NIS2: NIS2 enters into force
DESCRIPTION:Directive entered into force on the twentieth day after publica
 tion in OJ L 333 of 27 Dec 2022.\n\nDirective (EU) 2022/2555 on measures f
 or a high common level of cybersecurity across the Union (NIS2 Directive) 
 (European Union)\n\nSource: https://eur-lex.europa.eu/eli/dir/2022/2555/oj
 \n\nhttps://rulebook.fru.dev/regulations/eu-nis2
URL:https://rulebook.fru.dev/regulations/eu-nis2
CATEGORIES:European Union,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-234@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20230609
DTEND;VALUE=DATE:20230610
SUMMARY:GLBA Safeguards Rule: Compliance with expanded security program ele
 ments
DESCRIPTION:Applicability of the 314.5 provisions (qualified individual\, w
 ritten risk assessment\, encryption\, MFA\, pen testing\, incident respons
 e plan\, board reporting) was delayed from December 9\, 2022 to this date.
 \n\nFTC Standards for Safeguarding Customer Information (Safeguards Rule)\
 , 16 CFR Part 314\, under the Gramm-Leach-Bliley Act (United States (Feder
 al))\n\nSource: https://www.federalregister.gov/documents/2022/11/23/2022-
 25201/standards-for-safeguarding-customer-information\n\nhttps://rulebook.
 fru.dev/regulations/us-glba-safeguards
URL:https://rulebook.fru.dev/regulations/us-glba-safeguards
CATEGORIES:United States (Federal),financial,cybersecurity,breach-notificat
 ion,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-132@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20230612
DTEND;VALUE=DATE:20230613
SUMMARY:Nigeria NDPA: NDPA signed into law
DESCRIPTION:President signs the Nigeria Data Protection Act\, 2023.\n\nNige
 ria Data Protection Act\, 2023 and NDPA General Application and Implementa
 tion Directive (GAID) 2025 (Nigeria)\n\nSource: https://ndpc.gov.ng/resour
 ces/\n\nhttps://rulebook.fru.dev/regulations/ng-ndpa
URL:https://rulebook.fru.dev/regulations/ng-ndpa
CATEGORIES:Nigeria,privacy,breach-notification,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-25@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20230901
DTEND;VALUE=DATE:20230902
SUMMARY:Swiss revised FADP (nFADP): Revised FADP enters into force
DESCRIPTION:Revised FADP and Data Protection Ordinance apply with no transi
 tion period.\n\nFederal Act on Data Protection (revised FADP) of 25 Septem
 ber 2020 (Switzerland)\n\nSource: https://www.fedlex.admin.ch/eli/cc/2022/
 491/en\n\nhttps://rulebook.fru.dev/regulations/ch-fadp
URL:https://rulebook.fru.dev/regulations/ch-fadp
CATEGORIES:Switzerland,privacy,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-137@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20230914
DTEND;VALUE=DATE:20230915
SUMMARY:Saudi PDPL: PDPL in force
DESCRIPTION:PDPL and its implementing regulations take effect.\n\nPersonal 
 Data Protection Law (Royal Decree M/19 of 9/2/1443H\, as amended by Royal 
 Decree M/148 of 5/9/1444H) (Saudi Arabia)\n\nSource: https://sdaia.gov.sa/
 en/SDAIA/about/Documents/Personal%20Data%20English%20V2-23April2023-%20Rev
 iewed-.pdf\n\nhttps://rulebook.fru.dev/regulations/sa-pdpl
URL:https://rulebook.fru.dev/regulations/sa-pdpl
CATEGORIES:Saudi Arabia,privacy,data-residency,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-23@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20230922
DTEND;VALUE=DATE:20230923
SUMMARY:Quebec Law 25: Phase 2: main obligations and penalties
DESCRIPTION:Governance policies\, PIAs\, consent\, transparency\, privacy b
 y default\, ADM notices\, cross-border PIAs and AMP/penal regime apply.\n\
 nAct to modernize legislative provisions as regards the protection of pers
 onal information (Law 25\, formerly Bill 64) (Quebec\, Canada)\n\nSource: 
 https://www.legisquebec.gouv.qc.ca/en/document/cs/P-39.1\n\nhttps://rulebo
 ok.fru.dev/regulations/ca-qc-law25
URL:https://rulebook.fru.dev/regulations/ca-qc-law25
CATEGORIES:Quebec\, Canada,privacy,breach-notification,biometrics
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-270@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20231101
DTEND;VALUE=DATE:20231102
SUMMARY:NYDFS Cybersecurity Regulation (Part 500): Second Amendment effecti
 ve
DESCRIPTION:Second Amendment takes effect\; 500.19(e)-(h)\, 500.20\, 500.21
 \, 500.22 and 500.24 apply immediately.\n\nNew York DFS Cybersecurity Requ
 irements for Financial Services Companies (23 NYCRR Part 500)\, Second Ame
 ndment (New York)\n\nSource: https://www.dfs.ny.gov/cybersecurity/23-NYCRR
 -Part-500\n\nhttps://rulebook.fru.dev/regulations/us-ny-dfs-500
URL:https://rulebook.fru.dev/regulations/us-ny-dfs-500
CATEGORIES:New York,cybersecurity,breach-notification,financial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-271@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20231201
DTEND;VALUE=DATE:20231202
SUMMARY:NYDFS Cybersecurity Regulation (Part 500): Amended notification req
 uirements (500.17)
DESCRIPTION:New 72-hour event notice\, 24-hour extortion payment notice and
  certification changes apply (30 days).\n\nNew York DFS Cybersecurity Requ
 irements for Financial Services Companies (23 NYCRR Part 500)\, Second Ame
 ndment (New York)\n\nSource: https://www.dfs.ny.gov/cybersecurity/23-NYCRR
 -Part-500\n\nhttps://rulebook.fru.dev/regulations/us-ny-dfs-500
URL:https://rulebook.fru.dev/regulations/us-ny-dfs-500
CATEGORIES:New York,cybersecurity,breach-notification,financial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-290@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20231215
DTEND;VALUE=DATE:20231216
SUMMARY:SEC Cyber Disclosure Rules: Annual cybersecurity disclosures begin 
 (Item 106 / 16K)
DESCRIPTION:Required in annual reports for fiscal years ending on or after 
 this date.\n\nSEC Cybersecurity Risk Management\, Strategy\, Governance\, 
 and Incident Disclosure (Release No. 33-11216) (United States (Federal))\n
 \nSource: https://www.federalregister.gov/documents/2023/08/04/2023-16194/
 cybersecurity-risk-management-strategy-governance-and-incident-disclosure\
 n\nhttps://rulebook.fru.dev/regulations/us-sec-cyber
URL:https://rulebook.fru.dev/regulations/us-sec-cyber
CATEGORIES:United States (Federal),cybersecurity,breach-notification,financ
 ial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-291@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20231218
DTEND;VALUE=DATE:20231219
SUMMARY:SEC Cyber Disclosure Rules: Form 8-K Item 1.05 incident disclosure 
 begins
DESCRIPTION:All registrants other than smaller reporting companies must fil
 e material incident disclosures from this date.\n\nSEC Cybersecurity Risk 
 Management\, Strategy\, Governance\, and Incident Disclosure (Release No. 
 33-11216) (United States (Federal))\n\nSource: https://www.federalregister
 .gov/documents/2023/08/04/2023-16194/cybersecurity-risk-management-strateg
 y-governance-and-incident-disclosure\n\nhttps://rulebook.fru.dev/regulatio
 ns/us-sec-cyber
URL:https://rulebook.fru.dev/regulations/us-sec-cyber
CATEGORIES:United States (Federal),cybersecurity,breach-notification,financ
 ial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-229@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20240313
DTEND;VALUE=DATE:20240314
SUMMARY:FCC CPNI Breach Rule: Order effective except revised notification r
 ules
DESCRIPTION:Definitions and other parts of the order took effect\; the revi
 sed 64.2011 and 64.5111 notification requirements were delayed pending OMB
  approval.\n\nFCC Data Breach Reporting Requirements for telecommunication
 s carriers\, interconnected VoIP and TRS providers (47 CFR 64.2011\, 64.51
 11) (United States (Federal))\n\nSource: https://www.federalregister.gov/d
 ocuments/2024/02/12/2024-01667/data-breach-reporting-requirements\n\nhttps
 ://rulebook.fru.dev/regulations/us-fcc-cpni-breach
URL:https://rulebook.fru.dev/regulations/us-fcc-cpni-breach
CATEGORIES:United States (Federal),privacy,breach-notification,cybersecurit
 y
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-272@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20240415
DTEND;VALUE=DATE:20240416
SUMMARY:NYDFS Cybersecurity Regulation (Part 500): Annual compliance notifi
 cation
DESCRIPTION:Certification of compliance or acknowledgment of non-compliance
  due (recurs every April 15).\n\nNew York DFS Cybersecurity Requirements f
 or Financial Services Companies (23 NYCRR Part 500)\, Second Amendment (Ne
 w York)\n\nSource: https://www.dfs.ny.gov/cybersecurity/23-NYCRR-Part-500\
 n\nhttps://rulebook.fru.dev/regulations/us-ny-dfs-500
URL:https://rulebook.fru.dev/regulations/us-ny-dfs-500
CATEGORIES:New York,cybersecurity,breach-notification,financial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-273@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20240429
DTEND;VALUE=DATE:20240430
SUMMARY:NYDFS Cybersecurity Regulation (Part 500): General 180-day transiti
 on ends
DESCRIPTION:Most new Second Amendment requirements apply\, e.g. annual repo
 rting to the board and risk assessment updates.\n\nNew York DFS Cybersecur
 ity Requirements for Financial Services Companies (23 NYCRR Part 500)\, Se
 cond Amendment (New York)\n\nSource: https://www.dfs.ny.gov/cybersecurity/
 23-NYCRR-Part-500\n\nhttps://rulebook.fru.dev/regulations/us-ny-dfs-500
URL:https://rulebook.fru.dev/regulations/us-ny-dfs-500
CATEGORIES:New York,cybersecurity,breach-notification,financial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-235@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20240513
DTEND;VALUE=DATE:20240514
SUMMARY:GLBA Safeguards Rule: FTC breach notification requirement effective
DESCRIPTION:Section 314.4(j) requires notice to the FTC within 30 days of d
 iscovering a notification event involving at least 500 consumers.\n\nFTC S
 tandards for Safeguarding Customer Information (Safeguards Rule)\, 16 CFR 
 Part 314\, under the Gramm-Leach-Bliley Act (United States (Federal))\n\nS
 ource: https://www.federalregister.gov/documents/2023/11/13/2023-24412/sta
 ndards-for-safeguarding-customer-information\n\nhttps://rulebook.fru.dev/r
 egulations/us-glba-safeguards
URL:https://rulebook.fru.dev/regulations/us-glba-safeguards
CATEGORIES:United States (Federal),financial,cybersecurity,breach-notificat
 ion,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-292@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20240615
DTEND;VALUE=DATE:20240616
SUMMARY:SEC Cyber Disclosure Rules: Smaller reporting companies: Item 1.05 
 compliance
DESCRIPTION:Smaller reporting companies must begin complying with Form 8-K 
 Item 1.05 incident disclosure.\n\nSEC Cybersecurity Risk Management\, Stra
 tegy\, Governance\, and Incident Disclosure (Release No. 33-11216) (United
  States (Federal))\n\nSource: https://www.federalregister.gov/documents/20
 23/08/04/2023-16194/cybersecurity-risk-management-strategy-governance-and-
 incident-disclosure\n\nhttps://rulebook.fru.dev/regulations/us-sec-cyber
URL:https://rulebook.fru.dev/regulations/us-sec-cyber
CATEGORIES:United States (Federal),cybersecurity,breach-notification,financ
 ial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-236@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20240625
DTEND;VALUE=DATE:20240626
SUMMARY:HIPAA: Reproductive health care privacy rule effective (later vacat
 ed)
DESCRIPTION:The HIPAA Privacy Rule to Support Reproductive Health Care Priv
 acy (89 FR 32976) took effect\; it was vacated nationwide on June 18\, 202
 5 in Purl v. HHS (N.D. Tex.).\n\nHIPAA Privacy\, Security and Breach Notif
 ication Rules (45 CFR Parts 160 and 164) (United States (Federal))\n\nSour
 ce: https://www.federalregister.gov/documents/2024/04/26/2024-08503/hipaa-
 privacy-rule-to-support-reproductive-health-care-privacy\n\nhttps://rulebo
 ok.fru.dev/regulations/us-hipaa
URL:https://rulebook.fru.dev/regulations/us-hipaa
CATEGORIES:United States (Federal),privacy,health,cybersecurity,breach-noti
 fication
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-193@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20240703
DTEND;VALUE=DATE:20240704
SUMMARY:CIRCIA: NPRM comment period closed
DESCRIPTION:Extended comment period on the CIRCIA proposed rule closed.\n\n
 Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA) 
 and proposed implementing rule (6 CFR Part 226) (United States (Federal))\
 n\nSource: https://www.federalregister.gov/documents/2024/04/04/2024-06526
 /cyber-incident-reporting-for-critical-infrastructure-act-circia-reporting
 -requirements\n\nhttps://rulebook.fru.dev/regulations/us-circia
URL:https://rulebook.fru.dev/regulations/us-circia
CATEGORIES:United States (Federal),cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-232@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20240729
DTEND;VALUE=DATE:20240730
SUMMARY:FTC Health Breach Notification Rule: 2024 amendments effective
DESCRIPTION:Amendments clarifying health app coverage\, unauthorized disclo
 sure as breach\, email notice and FTC notice timing took effect.\n\nFTC He
 alth Breach Notification Rule (16 CFR Part 318)\, as amended 2024 (United 
 States (Federal))\n\nSource: https://www.federalregister.gov/documents/202
 4/05/30/2024-10855/health-breach-notification-rule\n\nhttps://rulebook.fru
 .dev/regulations/us-ftc-hbnr
URL:https://rulebook.fru.dev/regulations/us-ftc-hbnr
CATEGORIES:United States (Federal),health,privacy,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-295@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20240802
DTEND;VALUE=DATE:20240803
SUMMARY:SEC Regulation S-P: Amendments effective
DESCRIPTION:The Regulation S-P amendments became effective\; compliance tie
 red by entity size.\n\nRegulation S-P: Privacy of Consumer Financial Infor
 mation and Safeguarding Customer Information (2024 amendments) (United Sta
 tes (Federal))\n\nSource: https://www.federalregister.gov/documents/2024/0
 6/03/2024-11116/regulation-s-p-privacy-of-consumer-financial-information-a
 nd-safeguarding-customer-information\n\nhttps://rulebook.fru.dev/regulatio
 ns/us-sec-reg-sp
URL:https://rulebook.fru.dev/regulations/us-sec-reg-sp
CATEGORIES:United States (Federal),financial,privacy,cybersecurity,breach-n
 otification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-13@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20240823
DTEND;VALUE=DATE:20240824
SUMMARY:Brazil LGPD: International transfer regulation published
DESCRIPTION:Resolution CD/ANPD 19/2024 on international transfers and stand
 ard contractual clauses published and in force.\n\nLei Geral de Proteção
  de Dados Pessoais (Law No. 13.709/2018) (Brazil)\n\nSource: https://www.i
 n.gov.br/en/web/dou/-/resolucao-cd/anpd-n-19-de-23-de-agosto-de-2024-58009
 5396\n\nhttps://rulebook.fru.dev/regulations/br-lgpd
URL:https://rulebook.fru.dev/regulations/br-lgpd
CATEGORIES:Brazil,privacy,breach-notification,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-138@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20240914
DTEND;VALUE=DATE:20240915
SUMMARY:Saudi PDPL: One-year grace period ends
DESCRIPTION:Grace period for controllers to comply ends\; PDPL fully enforc
 eable.\n\nPersonal Data Protection Law (Royal Decree M/19 of 9/2/1443H\, a
 s amended by Royal Decree M/148 of 5/9/1444H) (Saudi Arabia)\n\nSource: ht
 tps://sdaia.gov.sa/en/SDAIA/about/Documents/Personal%20Data%20English%20V2
 -23April2023-%20Reviewed-.pdf\n\nhttps://rulebook.fru.dev/regulations/sa-p
 dpl
URL:https://rulebook.fru.dev/regulations/sa-pdpl
CATEGORIES:Saudi Arabia,privacy,data-residency,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-24@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20240922
DTEND;VALUE=DATE:20240923
SUMMARY:Quebec Law 25: Phase 3: data portability
DESCRIPTION:Right to data portability in a structured\, commonly used techn
 ological format applies.\n\nAct to modernize legislative provisions as reg
 ards the protection of personal information (Law 25\, formerly Bill 64) (Q
 uebec\, Canada)\n\nSource: https://www.legisquebec.gouv.qc.ca/en/document/
 cs/P-39.1\n\nhttps://rulebook.fru.dev/regulations/ca-qc-law25
URL:https://rulebook.fru.dev/regulations/ca-qc-law25
CATEGORIES:Quebec\, Canada,privacy,breach-notification,biometrics
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-113@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20241017
DTEND;VALUE=DATE:20241018
SUMMARY:Indonesia PDP Law: PDP Law transition ends
DESCRIPTION:Controllers and processors must fully comply (Art. 74 two-year 
 transition).\n\nLaw No. 27 of 2022 on Personal Data Protection (Undang-Und
 ang Pelindungan Data Pribadi) (Indonesia)\n\nSource: https://peraturan.bpk
 .go.id/Details/229798/uu-no-27-tahun-2022\n\nhttps://rulebook.fru.dev/regu
 lations/id-pdp
URL:https://rulebook.fru.dev/regulations/id-pdp
CATEGORIES:Indonesia,privacy,breach-notification,data-residency,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-99@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20241017
DTEND;VALUE=DATE:20241018
SUMMARY:NIS2: Transposition deadline
DESCRIPTION:Member States had to adopt and publish national transposing mea
 sures by 17 Oct 2024 (Art 41(1)).\n\nDirective (EU) 2022/2555 on measures 
 for a high common level of cybersecurity across the Union (NIS2 Directive)
  (European Union)\n\nSource: https://eur-lex.europa.eu/eli/dir/2022/2555/o
 j\n\nhttps://rulebook.fru.dev/regulations/eu-nis2
URL:https://rulebook.fru.dev/regulations/eu-nis2
CATEGORIES:European Union,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-100@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20241018
DTEND;VALUE=DATE:20241019
SUMMARY:NIS2: National NIS2 measures apply\; NIS1 repealed
DESCRIPTION:Member States apply their NIS2 measures from 18 Oct 2024 and Di
 rective (EU) 2016/1148 (NIS1) is repealed (Arts 41(1)\, 44).\n\nDirective 
 (EU) 2022/2555 on measures for a high common level of cybersecurity across
  the Union (NIS2 Directive) (European Union)\n\nSource: https://eur-lex.eu
 ropa.eu/eli/dir/2022/2555/oj\n\nhttps://rulebook.fru.dev/regulations/eu-ni
 s2
URL:https://rulebook.fru.dev/regulations/eu-nis2
CATEGORIES:European Union,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-274@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20241101
DTEND;VALUE=DATE:20241102
SUMMARY:NYDFS Cybersecurity Regulation (Part 500): Governance\, encryption\
 , IR/BCDR\, exemptions
DESCRIPTION:500.4 governance\, 500.15 encryption\, 500.16 incident response
  and business continuity plans\, and 500.19(a) revised exemptions apply.\n
 \nNew York DFS Cybersecurity Requirements for Financial Services Companies
  (23 NYCRR Part 500)\, Second Amendment (New York)\n\nSource: https://www.
 dfs.ny.gov/cybersecurity/23-NYCRR-Part-500\n\nhttps://rulebook.fru.dev/reg
 ulations/us-ny-dfs-500
URL:https://rulebook.fru.dev/regulations/us-ny-dfs-500
CATEGORIES:New York,cybersecurity,breach-notification,financial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-101@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20241107
DTEND;VALUE=DATE:20241108
SUMMARY:NIS2: Implementing Regulation 2024/2690 enters into force
DESCRIPTION:Commission Implementing Regulation (EU) 2024/2690 (published 18
  Oct 2024) sets technical risk-management measures and significant-inciden
 t thresholds for DNS\, TLD\, cloud\, data centre\, CDN\, managed (security
 ) service providers\, online marketplaces\, search engines\, social networ
 ks and trust service providers.\n\nDirective (EU) 2022/2555 on measures fo
 r a high common level of cybersecurity across the Union (NIS2 Directive) (
 European Union)\n\nSource: https://eur-lex.europa.eu/eli/reg_impl/2024/269
 0/oj\n\nhttps://rulebook.fru.dev/regulations/eu-nis2
URL:https://rulebook.fru.dev/regulations/eu-nis2
CATEGORIES:European Union,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-48@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20241210
DTEND;VALUE=DATE:20241211
SUMMARY:Cyber Resilience Act: CRA enters into force
DESCRIPTION:Entered into force on the twentieth day after publication in th
 e OJ on 20 Nov 2024 (Art 71(1)).\n\nRegulation (EU) 2024/2847 on horizonta
 l cybersecurity requirements for products with digital elements (Cyber Res
 ilience Act) (European Union)\n\nSource: https://eur-lex.europa.eu/eli/reg
 /2024/2847/oj\n\nhttps://rulebook.fru.dev/regulations/eu-cra
URL:https://rulebook.fru.dev/regulations/eu-cra
CATEGORIES:European Union,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-4@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20241211
DTEND;VALUE=DATE:20241212
SUMMARY:Australia Privacy Act: Most POLA Act 2024 amendments commence
DESCRIPTION:Tiered penalties\, infringement notices\, OAIC powers\, securit
 y and overseas-transfer clarifications and doxxing offences commence the d
 ay after Royal Assent.\n\nPrivacy Act 1988 (Cth)\, as amended by the Priva
 cy and Other Legislation Amendment Act 2024 (Australia)\n\nSource: https:/
 /www.legislation.gov.au/C2024A00128/asmade\n\nhttps://rulebook.fru.dev/reg
 ulations/au-privacy-act
URL:https://rulebook.fru.dev/regulations/au-privacy-act
CATEGORIES:Australia,privacy,children,breach-notification,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-26@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20241213
DTEND;VALUE=DATE:20241214
SUMMARY:Chile Personal Data Protection Law (Ley 21.719): Published in Diari
 o Oficial
DESCRIPTION:Law 21.719 published\; 24-month vacatio legis begins.\n\nLey N
 º 21.719 que regula la protección y el tratamiento de los datos personal
 es y crea la Agencia de Protección de Datos Personales (Chile)\n\nSource:
  https://www.bcn.cl/leychile/navegar?idNorma=1209272\n\nhttps://rulebook.f
 ru.dev/regulations/cl-pdpl
URL:https://rulebook.fru.dev/regulations/cl-pdpl
CATEGORIES:Chile,privacy,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-293@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20241215
DTEND;VALUE=DATE:20241216
SUMMARY:SEC Cyber Disclosure Rules: Inline XBRL tagging of annual cybersecu
 rity disclosures
DESCRIPTION:Item 106 / Item 16K disclosures must be tagged in Inline XBRL f
 or fiscal years ending on or after this date.\n\nSEC Cybersecurity Risk Ma
 nagement\, Strategy\, Governance\, and Incident Disclosure (Release No. 33
 -11216) (United States (Federal))\n\nSource: https://www.federalregister.g
 ov/documents/2023/08/04/2023-16194/cybersecurity-risk-management-strategy-
 governance-and-incident-disclosure\n\nhttps://rulebook.fru.dev/regulations
 /us-sec-cyber
URL:https://rulebook.fru.dev/regulations/us-sec-cyber
CATEGORIES:United States (Federal),cybersecurity,breach-notification,financ
 ial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-294@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20241218
DTEND;VALUE=DATE:20241219
SUMMARY:SEC Cyber Disclosure Rules: Inline XBRL tagging of Item 1.05 disclo
 sures
DESCRIPTION:Form 8-K Item 1.05 and Form 6-K incident disclosures must be ta
 gged in Inline XBRL.\n\nSEC Cybersecurity Risk Management\, Strategy\, Gov
 ernance\, and Incident Disclosure (Release No. 33-11216) (United States (F
 ederal))\n\nSource: https://www.federalregister.gov/documents/2023/08/04/2
 023-16194/cybersecurity-risk-management-strategy-governance-and-incident-d
 isclosure\n\nhttps://rulebook.fru.dev/regulations/us-sec-cyber
URL:https://rulebook.fru.dev/regulations/us-sec-cyber
CATEGORIES:United States (Federal),cybersecurity,breach-notification,financ
 ial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-237@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20241223
DTEND;VALUE=DATE:20241224
SUMMARY:HIPAA: Reproductive health privacy compliance date (vacated)
DESCRIPTION:Original compliance date for the reproductive health care priva
 cy provisions\, including the attestation requirement\; these provisions n
 o longer apply after the June 2025 vacatur.\n\nHIPAA Privacy\, Security an
 d Breach Notification Rules (45 CFR Parts 160 and 164) (United States (Fed
 eral))\n\nSource: https://www.federalregister.gov/documents/2024/04/26/202
 4-08503/hipaa-privacy-rule-to-support-reproductive-health-care-privacy\n\n
 https://rulebook.fru.dev/regulations/us-hipaa
URL:https://rulebook.fru.dev/regulations/us-hipaa
CATEGORIES:United States (Federal),privacy,health,cybersecurity,breach-noti
 fication
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-129@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20250101
DTEND;VALUE=DATE:20250102
SUMMARY:Malaysia PDPA: PDPA amendments phase 1
DESCRIPTION:Miscellaneous provisions commence (e.g. electronic service of n
 otices).\n\nPersonal Data Protection Act 2010 (Act 709)\, as amended by th
 e Personal Data Protection (Amendment) Act 2024 (Act A1727) (Malaysia)\n\n
 Source: https://www.pdp.gov.my/ppdpv1/en/personal-data-protection-amendmen
 t-act-2024-commencement-date-determination/\n\nhttps://rulebook.fru.dev/re
 gulations/my-pdpa
URL:https://rulebook.fru.dev/regulations/my-pdpa
CATEGORIES:Malaysia,privacy,breach-notification,biometrics,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-71@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20250117
DTEND;VALUE=DATE:20250118
SUMMARY:DORA: DORA applies
DESCRIPTION:All DORA obligations (ICT risk management\, incident reporting\
 , testing\, third-party risk\, register of information) apply from 17 Jan 
 2025 (Art 64).\n\nRegulation (EU) 2022/2554 on digital operational resilie
 nce for the financial sector (Digital Operational Resilience Act) (Europea
 n Union)\n\nSource: https://eur-lex.europa.eu/eli/reg/2022/2554/oj\n\nhttp
 s://rulebook.fru.dev/regulations/eu-dora
URL:https://rulebook.fru.dev/regulations/eu-dora
CATEGORIES:European Union,cybersecurity,financial,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-102@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20250117
DTEND;VALUE=DATE:20250118
SUMMARY:NIS2: Digital infrastructure entities submit registration data
DESCRIPTION:DNS providers\, TLD registries\, domain registration services\,
  cloud\, data centre\, CDN\, managed (security) service providers\, market
 places\, search engines and social networks had to submit registration det
 ails to competent authorities (Art 27(2)).\n\nDirective (EU) 2022/2555 on 
 measures for a high common level of cybersecurity across the Union (NIS2 D
 irective) (European Union)\n\nSource: https://eur-lex.europa.eu/eli/dir/20
 22/2555/oj\n\nhttps://rulebook.fru.dev/regulations/eu-nis2
URL:https://rulebook.fru.dev/regulations/eu-nis2
CATEGORIES:European Union,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-238@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20250307
DTEND;VALUE=DATE:20250308
SUMMARY:HIPAA: Security Rule NPRM comment period closed
DESCRIPTION:Comments closed on the proposed HIPAA Security Rule update (90 
 FR 898)\; OCR has not issued a final rule.\n\nHIPAA Privacy\, Security and
  Breach Notification Rules (45 CFR Parts 160 and 164) (United States (Fede
 ral))\n\nSource: https://www.federalregister.gov/documents/2025/01/06/2024
 -30983/hipaa-security-rule-to-strengthen-the-cybersecurity-of-electronic-p
 rotected-health-information\n\nhttps://rulebook.fru.dev/regulations/us-hip
 aa
URL:https://rulebook.fru.dev/regulations/us-hipaa
CATEGORIES:United States (Federal),privacy,health,cybersecurity,breach-noti
 fication
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-130@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20250401
DTEND;VALUE=DATE:20250402
SUMMARY:Malaysia PDPA: PDPA amendments phase 2
DESCRIPTION:'Data controller' terminology\, biometric data as sensitive dat
 a\, higher penalties\, Security Principle for processors\, and removal of 
 the cross-border whitelist take effect.\n\nPersonal Data Protection Act 20
 10 (Act 709)\, as amended by the Personal Data Protection (Amendment) Act 
 2024 (Act A1727) (Malaysia)\n\nSource: https://www.pdp.gov.my/ppdpv1/en/pe
 rsonal-data-protection-amendment-act-2024-commencement-date-determination/
 \n\nhttps://rulebook.fru.dev/regulations/my-pdpa
URL:https://rulebook.fru.dev/regulations/my-pdpa
CATEGORIES:Malaysia,privacy,breach-notification,biometrics,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-103@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20250417
DTEND;VALUE=DATE:20250418
SUMMARY:NIS2: Member States establish entity lists
DESCRIPTION:Member States had to establish lists of essential and important
  entities and notify the Commission of entity numbers (Art 3(3) and (5)). 
 Repeated every two years.\n\nDirective (EU) 2022/2555 on measures for a hi
 gh common level of cybersecurity across the Union (NIS2 Directive) (Europe
 an Union)\n\nSource: https://eur-lex.europa.eu/eli/dir/2022/2555/oj\n\nhtt
 ps://rulebook.fru.dev/regulations/eu-nis2
URL:https://rulebook.fru.dev/regulations/eu-nis2
CATEGORIES:European Union,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-72@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20250430
DTEND;VALUE=DATE:20250501
SUMMARY:DORA: First registers of information submitted to the ESAs
DESCRIPTION:Competent authorities had to submit financial entities' registe
 rs of ICT third-party contractual arrangements (reference date 31 Mar 2025
 ) to the ESAs by 30 Apr 2025. National authorities set earlier deadlines f
 or entities.\n\nRegulation (EU) 2022/2554 on digital operational resilienc
 e for the financial sector (Digital Operational Resilience Act) (European 
 Union)\n\nSource: https://www.eba.europa.eu/publications-and-media/press-r
 eleases/esas-announce-timeline-collect-information-designation-critical-ic
 t-third-party-service-providers\n\nhttps://rulebook.fru.dev/regulations/eu
 -dora
URL:https://rulebook.fru.dev/regulations/eu-dora
CATEGORIES:European Union,cybersecurity,financial,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-275@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20250501
DTEND;VALUE=DATE:20250502
SUMMARY:NYDFS Cybersecurity Regulation (Part 500): Vulnerability scans\, ac
 cess privileges\, malware controls\, Class A monitoring
DESCRIPTION:500.5(a)(2) automated scans\, 500.7 access privilege restrictio
 ns\, 500.14(a)(2) malicious code protection\, and 500.14(b) Class A endpoi
 nt detection and centralized logging apply.\n\nNew York DFS Cybersecurity 
 Requirements for Financial Services Companies (23 NYCRR Part 500)\, Second
  Amendment (New York)\n\nSource: https://www.dfs.ny.gov/cybersecurity/23-N
 YCRR-Part-500\n\nhttps://rulebook.fru.dev/regulations/us-ny-dfs-500
URL:https://rulebook.fru.dev/regulations/us-ny-dfs-500
CATEGORIES:New York,cybersecurity,breach-notification,financial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-2@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20250530
DTEND;VALUE=DATE:20250531
SUMMARY:Australia Cyber Security Act (ransomware reporting): Ransomware pay
 ment reporting starts
DESCRIPTION:Reporting business entities must report ransomware/cyber-extort
 ion payments to ASD within 72 hours of payment.\n\nCyber Security Act 2024
  (Cth) and Cyber Security (Ransomware Payment Reporting) Rules 2025 (Austr
 alia)\n\nSource: https://www.homeaffairs.gov.au/cyber-security-subsite/fil
 es/factsheet-ransomware-payment-reporting.pdf\n\nhttps://rulebook.fru.dev/
 regulations/au-cyber-security-act
URL:https://rulebook.fru.dev/regulations/au-cyber-security-act
CATEGORIES:Australia,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-131@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20250601
DTEND;VALUE=DATE:20250602
SUMMARY:Malaysia PDPA: PDPA amendments phase 3
DESCRIPTION:Mandatory DPO appointment\, data breach notification\, and data
  portability take effect.\n\nPersonal Data Protection Act 2010 (Act 709)\,
  as amended by the Personal Data Protection (Amendment) Act 2024 (Act A172
 7) (Malaysia)\n\nSource: https://www.pdp.gov.my/ppdpv1/en/personal-data-pr
 otection-amendment-act-2024-commencement-date-determination/\n\nhttps://ru
 lebook.fru.dev/regulations/my-pdpa
URL:https://rulebook.fru.dev/regulations/my-pdpa
CATEGORIES:Malaysia,privacy,breach-notification,biometrics,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-5@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20250610
DTEND;VALUE=DATE:20250611
SUMMARY:Australia Privacy Act: Statutory tort for serious invasions of priv
 acy commences
DESCRIPTION:Individuals can sue for serious invasions of privacy (Schedule 
 2)\, 6 months after Royal Assent.\n\nPrivacy Act 1988 (Cth)\, as amended b
 y the Privacy and Other Legislation Amendment Act 2024 (Australia)\n\nSour
 ce: https://www.legislation.gov.au/C2024A00128/asmade\n\nhttps://rulebook.
 fru.dev/regulations/au-privacy-act
URL:https://rulebook.fru.dev/regulations/au-privacy-act
CATEGORIES:Australia,privacy,children,breach-notification,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-16@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20250618
DTEND;VALUE=DATE:20250619
SUMMARY:Canada Bill C-8 / CCSPA: Bill C-8 introduced
DESCRIPTION:First reading in the House of Commons.\n\nCritical Cyber System
 s Protection Act (enacted by Bill C-8\, An Act respecting cyber security) 
 (Canada)\n\nSource: https://www.parl.ca/legisinfo/en/bill/45-1/c-8\n\nhttp
 s://rulebook.fru.dev/regulations/ca-ccspa
URL:https://rulebook.fru.dev/regulations/ca-ccspa
CATEGORIES:Canada,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-73@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20250708
DTEND;VALUE=DATE:20250709
SUMMARY:DORA: TLPT regulatory technical standards enter into force
DESCRIPTION:Commission Delegated Regulation (EU) 2025/1190 (published 18 Ju
 ne 2025) sets criteria for which financial entities must run threat-led pe
 netration testing\, plus methodology and tester requirements.\n\nRegulatio
 n (EU) 2022/2554 on digital operational resilience for the financial secto
 r (Digital Operational Resilience Act) (European Union)\n\nSource: https:/
 /eur-lex.europa.eu/eli/reg_del/2025/1190/oj\n\nhttps://rulebook.fru.dev/re
 gulations/eu-dora
URL:https://rulebook.fru.dev/regulations/eu-dora
CATEGORIES:European Union,cybersecurity,financial,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-115@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20250814
DTEND;VALUE=DATE:20250815
SUMMARY:Israel Privacy Protection Law Amendment 13: Amendment 13 in force
DESCRIPTION:Amended Privacy Protection Law\, PPA enforcement powers and sta
 tutory damages take effect.\n\nPrivacy Protection Law\, 5741-1981 (Amendme
 nt No. 13) (Israel)\n\nSource: https://www.gov.il/en/departments/the_priva
 cy_protection_authority/govil-landing-page\n\nhttps://rulebook.fru.dev/reg
 ulations/il-ppl-amendment-13
URL:https://rulebook.fru.dev/regulations/il-ppl-amendment-13
CATEGORIES:Israel,privacy,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-14@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20250823
DTEND;VALUE=DATE:20250824
SUMMARY:Brazil LGPD: Deadline to adopt ANPD standard contractual clauses
DESCRIPTION:Agents relying on contractual clauses for international transfe
 rs must incorporate the ANPD-approved SCCs into their contracts within 12 
 months of publication.\n\nLei Geral de Proteção de Dados Pessoais (Law N
 o. 13.709/2018) (Brazil)\n\nSource: https://www.in.gov.br/en/web/dou/-/res
 olucao-cd/anpd-n-19-de-23-de-agosto-de-2024-580095396\n\nhttps://rulebook.
 fru.dev/regulations/br-lgpd
URL:https://rulebook.fru.dev/regulations/br-lgpd
CATEGORIES:Brazil,privacy,breach-notification,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-133@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20250919
DTEND;VALUE=DATE:20250920
SUMMARY:Nigeria NDPA: GAID 2025 takes effect
DESCRIPTION:General Application and Implementation Directive becomes effect
 ive\, replacing the NDPR 2019 and NDPR Implementation Framework.\n\nNigeri
 a Data Protection Act\, 2023 and NDPA General Application and Implementati
 on Directive (GAID) 2025 (Nigeria)\n\nSource: https://ndpc.gov.ng/resource
 s/\n\nhttps://rulebook.fru.dev/regulations/ng-ndpa
URL:https://rulebook.fru.dev/regulations/ng-ndpa
CATEGORIES:Nigeria,privacy,breach-notification,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-135@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20250924
DTEND;VALUE=DATE:20250925
SUMMARY:New Zealand Privacy Act: Privacy Amendment Act 2025 technical chang
 es commence
DESCRIPTION:Technical amendments commence the day after Royal Assent (23 Se
 p 2025).\n\nPrivacy Act 2020 (New Zealand)\, as amended by the Privacy Ame
 ndment Act 2025 (New Zealand)\n\nSource: https://www.justice.govt.nz/justi
 ce-sector-policy/key-initiatives/enhancing-the-privacy-act/\n\nhttps://rul
 ebook.fru.dev/regulations/nz-privacy-act
URL:https://rulebook.fru.dev/regulations/nz-privacy-act
CATEGORIES:New Zealand,privacy,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-276@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20251101
DTEND;VALUE=DATE:20251102
SUMMARY:NYDFS Cybersecurity Regulation (Part 500): Universal MFA and asset 
 inventory
DESCRIPTION:500.12 multi-factor authentication for all users and 500.13(a) 
 asset inventory requirements apply.\n\nNew York DFS Cybersecurity Requirem
 ents for Financial Services Companies (23 NYCRR Part 500)\, Second Amendme
 nt (New York)\n\nSource: https://www.dfs.ny.gov/cybersecurity/23-NYCRR-Par
 t-500\n\nhttps://rulebook.fru.dev/regulations/us-ny-dfs-500
URL:https://rulebook.fru.dev/regulations/us-ny-dfs-500
CATEGORIES:New York,cybersecurity,breach-notification,financial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-145@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20251112
DTEND;VALUE=DATE:20251113
SUMMARY:UK Cyber Security and Resilience Bill: Introduced (Commons first re
 ading)
DESCRIPTION:Bill introduced in the House of Commons.\n\nCyber Security and 
 Resilience (Network and Information Systems) Bill (United Kingdom)\n\nSour
 ce: https://bills.parliament.uk/bills/4035\n\nhttps://rulebook.fru.dev/reg
 ulations/uk-csr-bill
URL:https://rulebook.fru.dev/regulations/uk-csr-bill
CATEGORIES:United Kingdom,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-116@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20251113
DTEND;VALUE=DATE:20251114
SUMMARY:India DPDP Act: DPDP Rules published\; Board and procedural rules i
 n force
DESCRIPTION:Rules 1\, 2 and 17-21 (Data Protection Board constitution and f
 unctioning) take effect on publication in the Official Gazette.\n\nDigital
  Personal Data Protection Act\, 2023 and Digital Personal Data Protection 
 Rules\, 2025 (India)\n\nSource: https://egazette.gov.in/WriteReadData/2025
 /267650.pdf\n\nhttps://rulebook.fru.dev/regulations/in-dpdp
URL:https://rulebook.fru.dev/regulations/in-dpdp
CATEGORIES:India,privacy,children,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-74@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20251118
DTEND;VALUE=DATE:20251119
SUMMARY:DORA: First critical ICT third-party providers designated
DESCRIPTION:The ESAs published the first list of 19 critical ICT third-part
 y providers (including AWS\, Google Cloud and Microsoft)\, which now come 
 under direct EU oversight.\n\nRegulation (EU) 2022/2554 on digital operati
 onal resilience for the financial sector (Digital Operational Resilience A
 ct) (European Union)\n\nSource: https://www.eba.europa.eu/publications-and
 -media/press-releases/european-supervisory-authorities-designate-critical-
 ict-third-party-providers-under-digital\n\nhttps://rulebook.fru.dev/regula
 tions/eu-dora
URL:https://rulebook.fru.dev/regulations/eu-dora
CATEGORIES:European Union,cybersecurity,financial,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-95@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20251126
DTEND;VALUE=DATE:20251127
SUMMARY:GDPR: GDPR Procedural Regulation adopted
DESCRIPTION:Regulation (EU) 2025/2518 laying down additional procedural rul
 es for cross-border GDPR enforcement signed by Parliament and Council.\n\n
 Regulation (EU) 2016/679 (General Data Protection Regulation) (European Un
 ion)\n\nSource: https://eur-lex.europa.eu/eli/reg/2025/2518/oj\n\nhttps://
 rulebook.fru.dev/regulations/eu-gdpr
URL:https://rulebook.fru.dev/regulations/eu-gdpr
CATEGORIES:European Union,privacy,breach-notification,data-access,children,
 biometrics,health
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-296@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20251203
DTEND;VALUE=DATE:20251204
SUMMARY:SEC Regulation S-P: Larger entities must comply
DESCRIPTION:Larger covered institutions (18 months after Federal Register p
 ublication) must have incident response programs\, 30-day customer notific
 ation\, and service-provider oversight in place.\n\nRegulation S-P: Privac
 y of Consumer Financial Information and Safeguarding Customer Information 
 (2024 amendments) (United States (Federal))\n\nSource: https://www.federal
 register.gov/documents/2024/06/03/2024-11116/regulation-s-p-privacy-of-con
 sumer-financial-information-and-safeguarding-customer-information\n\nhttps
 ://rulebook.fru.dev/regulations/us-sec-reg-sp
URL:https://rulebook.fru.dev/regulations/us-sec-reg-sp
CATEGORIES:United States (Federal),financial,privacy,cybersecurity,breach-n
 otification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-3@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20260101
DTEND;VALUE=DATE:20260102
SUMMARY:Australia Cyber Security Act (ransomware reporting): Ransomware rep
 orting moves to compliance phase
DESCRIPTION:The education-first phase (30 May-31 Dec 2025) ends\; Home Affa
 irs moves to a compliance and education approach for missed reports.\n\nCy
 ber Security Act 2024 (Cth) and Cyber Security (Ransomware Payment Reporti
 ng) Rules 2025 (Australia)\n\nSource: https://www.homeaffairs.gov.au/cyber
 -security-subsite/files/factsheet-ransomware-payment-reporting.pdf\n\nhttp
 s://rulebook.fru.dev/regulations/au-cyber-security-act
URL:https://rulebook.fru.dev/regulations/au-cyber-security-act
CATEGORIES:Australia,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-96@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20260101
DTEND;VALUE=DATE:20260102
SUMMARY:GDPR: GDPR Procedural Regulation enters into force
DESCRIPTION:Regulation (EU) 2025/2518\, published in the OJ on 12 December 
 2025\, enters into force on the twentieth day after publication.\n\nRegula
 tion (EU) 2016/679 (General Data Protection Regulation) (European Union)\n
 \nSource: https://eur-lex.europa.eu/eli/reg/2025/2518/oj\n\nhttps://rulebo
 ok.fru.dev/regulations/eu-gdpr
URL:https://rulebook.fru.dev/regulations/eu-gdpr
CATEGORIES:European Union,privacy,breach-notification,data-access,children,
 biometrics,health
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-111@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20260101
DTEND;VALUE=DATE:20260102
SUMMARY:Hong Kong Critical Infrastructure Cyber Ordinance: PCICSO comes int
 o operation
DESCRIPTION:Commissioner's Office is established and designation of CIOs be
 gins\; obligations apply to designated operators.\n\nProtection of Critica
 l Infrastructures (Computer Systems) Ordinance (Cap. 653) (Hong Kong)\n\nS
 ource: https://www.info.gov.hk/gia/general/202506/27/P2025062700238.htm\n\
 nhttps://rulebook.fru.dev/regulations/hk-pcico
URL:https://rulebook.fru.dev/regulations/hk-pcico
CATEGORIES:Hong Kong,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-324@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20260101
DTEND;VALUE=DATE:20260102
SUMMARY:Vietnam PDPL: PDPL and Decree 356/2025 take effect
DESCRIPTION:Personal data protection obligations\, DPIA/TIA filing and pena
 lty framework apply\; Decree 13/2023 replaced.\n\nLaw on Personal Data Pro
 tection (Law No. 91/2025/QH15) (Vietnam)\n\nSource: https://vanban.chinhph
 u.vn/?pageid=27160&docid=214590\n\nhttps://rulebook.fru.dev/regulations/vn
 -pdpl
URL:https://rulebook.fru.dev/regulations/vn-pdpl
CATEGORIES:Vietnam,privacy,data-residency,children,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-155@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20260205
DTEND;VALUE=DATE:20260206
SUMMARY:UK GDPR: DUAA amendments to UK GDPR commence
DESCRIPTION:Main Data (Use and Access) Act 2025 Part 5 amendments (recognis
 ed legitimate interests\, ADM\, DSAR\, transfers\, cookies\, PECR fines) a
 pply.\n\nUK General Data Protection Regulation and Data Protection Act 201
 8 (United Kingdom)\n\nSource: https://www.legislation.gov.uk/uksi/2026/82/
 contents/made\n\nhttps://rulebook.fru.dev/regulations/uk-gdpr
URL:https://rulebook.fru.dev/regulations/uk-gdpr
CATEGORIES:United Kingdom,privacy,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-239@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20260216
DTEND;VALUE=DATE:20260217
SUMMARY:HIPAA: Notice of Privacy Practices updates (Part 2 alignment)
DESCRIPTION:Covered entities must update Notices of Privacy Practices under
  45 CFR 164.520 for the 2024 Part 2 (substance use disorder records) chang
 es\; this NPP piece survived the Purl vacatur.\n\nHIPAA Privacy\, Security
  and Breach Notification Rules (45 CFR Parts 160 and 164) (United States (
 Federal))\n\nSource: https://www.federalregister.gov/documents/2024/04/26/
 2024-08503/hipaa-privacy-rule-to-support-reproductive-health-care-privacy\
 n\nhttps://rulebook.fru.dev/regulations/us-hipaa
URL:https://rulebook.fru.dev/regulations/us-hipaa
CATEGORIES:United States (Federal),privacy,health,cybersecurity,breach-noti
 fication
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-125@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20260310
DTEND;VALUE=DATE:20260311
SUMMARY:South Korea PIPA: 2026 PIPA amendment promulgated (Act No. 21445)
DESCRIPTION:Amendment raising fines to 10% of revenue and adding CEO accoun
 tability promulgated.\n\nPersonal Information Protection Act (as amended b
 y Act No. 21445\, 2026) (South Korea)\n\nSource: https://www.law.go.kr/법
 령/개인정보보호법\n\nhttps://rulebook.fru.dev/regulations/kr-pipa
URL:https://rulebook.fru.dev/regulations/kr-pipa
CATEGORIES:South Korea,privacy,breach-notification,biometrics,data-residenc
 y
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-277@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20260415
DTEND;VALUE=DATE:20260416
SUMMARY:NYDFS Cybersecurity Regulation (Part 500): Annual compliance notifi
 cation
DESCRIPTION:Annual certification or acknowledgment covering calendar year 2
 025 due.\n\nNew York DFS Cybersecurity Requirements for Financial Services
  Companies (23 NYCRR Part 500)\, Second Amendment (New York)\n\nSource: ht
 tps://www.dfs.ny.gov/cybersecurity/23-NYCRR-Part-500\n\nhttps://rulebook.f
 ru.dev/regulations/us-ny-dfs-500
URL:https://rulebook.fru.dev/regulations/us-ny-dfs-500
CATEGORIES:New York,cybersecurity,breach-notification,financial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-136@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20260501
DTEND;VALUE=DATE:20260502
SUMMARY:New Zealand Privacy Act: IPP 3A indirect-collection notification ap
 plies
DESCRIPTION:Agencies collecting personal information from third parties mus
 t take reasonable steps to notify individuals\, subject to exceptions.\n\n
 Privacy Act 2020 (New Zealand)\, as amended by the Privacy Amendment Act 2
 025 (New Zealand)\n\nSource: https://www.justice.govt.nz/justice-sector-po
 licy/key-initiatives/enhancing-the-privacy-act/\n\nhttps://rulebook.fru.de
 v/regulations/nz-privacy-act
URL:https://rulebook.fru.dev/regulations/nz-privacy-act
CATEGORIES:New Zealand,privacy,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-297@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20260603
DTEND;VALUE=DATE:20260604
SUMMARY:SEC Regulation S-P: Smaller entities must comply
DESCRIPTION:Smaller covered institutions (24 months after Federal Register 
 publication) must comply with the amended Regulation S-P.\n\nRegulation S-
 P: Privacy of Consumer Financial Information and Safeguarding Customer Inf
 ormation (2024 amendments) (United States (Federal))\n\nSource: https://ww
 w.federalregister.gov/documents/2024/06/03/2024-11116/regulation-s-p-priva
 cy-of-consumer-financial-information-and-safeguarding-customer-information
 \n\nhttps://rulebook.fru.dev/regulations/us-sec-reg-sp
URL:https://rulebook.fru.dev/regulations/us-sec-reg-sp
CATEGORIES:United States (Federal),financial,privacy,cybersecurity,breach-n
 otification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-49@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20260611
DTEND;VALUE=DATE:20260612
SUMMARY:Cyber Resilience Act: Conformity assessment body provisions apply
DESCRIPTION:Chapter IV (Arts 35-51\, notification of conformity assessment 
 bodies) applies (Art 71(2)).\n\nRegulation (EU) 2024/2847 on horizontal cy
 bersecurity requirements for products with digital elements (Cyber Resilie
 nce Act) (European Union)\n\nSource: https://eur-lex.europa.eu/eli/reg/202
 4/2847/oj\n\nhttps://rulebook.fru.dev/regulations/eu-cra
URL:https://rulebook.fru.dev/regulations/eu-cra
CATEGORIES:European Union,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-15@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20260615
DTEND;VALUE=DATE:20260616
SUMMARY:Canada Bill C-36 (PPCDA): Bill C-36 tabled (first reading)
DESCRIPTION:Government introduces the PPCDA in the House of Commons.\n\nBil
 l C-36\, An Act to enact the Protecting Privacy and Consumer Data Act (Can
 ada)\n\nSource: https://www.parl.ca/DocumentViewer/en/45-1/bill/C-36/first
 -reading\n\nhttps://rulebook.fru.dev/regulations/ca-c36-ppcda
URL:https://rulebook.fru.dev/regulations/ca-c36-ppcda
CATEGORIES:Canada,privacy,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-17@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20260615
DTEND;VALUE=DATE:20260616
SUMMARY:Canada Bill C-8 / CCSPA: Royal Assent
DESCRIPTION:Bill C-8 receives Royal Assent (S.C. 2026\, c. 9)\; Telecommuni
 cations Act amendments take effect.\n\nCritical Cyber Systems Protection A
 ct (enacted by Bill C-8\, An Act respecting cyber security) (Canada)\n\nSo
 urce: https://www.parl.ca/legisinfo/en/bill/45-1/c-8\n\nhttps://rulebook.f
 ru.dev/regulations/ca-ccspa
URL:https://rulebook.fru.dev/regulations/ca-ccspa
CATEGORIES:Canada,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-146@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20260616
DTEND;VALUE=DATE:20260617
SUMMARY:UK Cyber Security and Resilience Bill: Passes House of Commons
DESCRIPTION:Report stage and third reading completed in the Commons after c
 arry-over into the new session.\n\nCyber Security and Resilience (Network 
 and Information Systems) Bill (United Kingdom)\n\nSource: https://bills.pa
 rliament.uk/bills/4035\n\nhttps://rulebook.fru.dev/regulations/uk-csr-bill
URL:https://rulebook.fru.dev/regulations/uk-csr-bill
CATEGORIES:United Kingdom,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-122@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20260717
DTEND;VALUE=DATE:20260718
SUMMARY:Japan APPI: 2026 APPI amendment act promulgated
DESCRIPTION:Amendment enacted by the Diet on 10 July 2026 and promulgated\;
  main provisions take effect by cabinet order within two years of promulga
 tion.\n\nAct on the Protection of Personal Information (Act No. 57 of 2003
 )\, as amended including the 2026 amendment act (Japan)\n\nSource: https:/
 /www.ppc.go.jp/files/pdf/260731_shiryou-1.pdf\n\nhttps://rulebook.fru.dev/
 regulations/jp-appi
URL:https://rulebook.fru.dev/regulations/jp-appi
CATEGORIES:Japan,privacy,children,biometrics,breach-notification,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-50@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20260911
DTEND;VALUE=DATE:20260912
SUMMARY:Cyber Resilience Act: Vulnerability and incident reporting obligati
 ons apply
DESCRIPTION:Art 14: manufacturers must report actively exploited vulnerabil
 ities and severe incidents (24-hour early warning\, 72-hour notification) 
 via the single reporting platform. Also covers products placed on the mark
 et before 11 Dec 2027 (Art 69(3)).\n\nRegulation (EU) 2024/2847 on horizon
 tal cybersecurity requirements for products with digital elements (Cyber R
 esilience Act) (European Union)\n\nSource: https://eur-lex.europa.eu/eli/r
 eg/2024/2847/oj\n\nhttps://rulebook.fru.dev/regulations/eu-cra
URL:https://rulebook.fru.dev/regulations/eu-cra
CATEGORIES:European Union,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-126@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20260911
DTEND;VALUE=DATE:20260912
SUMMARY:South Korea PIPA: 2026 PIPA amendments take effect
DESCRIPTION:10%-of-revenue fines\, CEO accountability\, and notice duties f
 or possible breaches apply.\n\nPersonal Information Protection Act (as ame
 nded by Act No. 21445\, 2026) (South Korea)\n\nSource: https://www.law.go.
 kr/법령/개인정보보호법\n\nhttps://rulebook.fru.dev/regulations/kr
 -pipa
URL:https://rulebook.fru.dev/regulations/kr-pipa
CATEGORIES:South Korea,privacy,breach-notification,biometrics,data-residenc
 y
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-147@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20261026
DTEND;VALUE=DATE:20261027
SUMMARY:UK Cyber Security and Resilience Bill: Lords report stage scheduled
DESCRIPTION:House of Lords report stage scheduled (committee stage sat 1\, 
 3 and 7 Sept 2026).\n\nTentative: depends on a proposal not yet adopted.\n
 \nCyber Security and Resilience (Network and Information Systems) Bill (Un
 ited Kingdom)\n\nSource: https://bills.parliament.uk/bills/4035\n\nhttps:/
 /rulebook.fru.dev/regulations/uk-csr-bill
URL:https://rulebook.fru.dev/regulations/uk-csr-bill
CATEGORIES:United Kingdom,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-117@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20261113
DTEND;VALUE=DATE:20261114
SUMMARY:India DPDP Act: Consent Manager registration rule in force (12 mont
 hs)
DESCRIPTION:Rule 4 (registration and obligations of Consent Managers) comes
  into force one year after publication.\n\nDigital Personal Data Protectio
 n Act\, 2023 and Digital Personal Data Protection Rules\, 2025 (India)\n\n
 Source: https://egazette.gov.in/WriteReadData/2025/267650.pdf\n\nhttps://r
 ulebook.fru.dev/regulations/in-dpdp
URL:https://rulebook.fru.dev/regulations/in-dpdp
CATEGORIES:India,privacy,children,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-27@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20261201
DTEND;VALUE=DATE:20261202
SUMMARY:Chile Personal Data Protection Law (Ley 21.719): Law in force
DESCRIPTION:Main obligations apply and the Personal Data Protection Agency 
 begins supervision.\n\nLey Nº 21.719 que regula la protección y el trata
 miento de los datos personales y crea la Agencia de Protección de Datos P
 ersonales (Chile)\n\nSource: https://www.bcn.cl/leychile/navegar?idNorma=1
 209272\n\nhttps://rulebook.fru.dev/regulations/cl-pdpl
URL:https://rulebook.fru.dev/regulations/cl-pdpl
CATEGORIES:Chile,privacy,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20261210
DTEND;VALUE=DATE:20261211
SUMMARY:Australia Privacy Act: Children's Online Privacy Code must be regis
 tered
DESCRIPTION:OAIC must develop and register the Children's Online Privacy Co
 de within 24 months of Royal Assent.\n\nPrivacy Act 1988 (Cth)\, as amende
 d by the Privacy and Other Legislation Amendment Act 2024 (Australia)\n\nS
 ource: https://www.oaic.gov.au/privacy/privacy-registers/privacy-codes/chi
 ldrens-online-privacy-code\n\nhttps://rulebook.fru.dev/regulations/au-priv
 acy-act
URL:https://rulebook.fru.dev/regulations/au-privacy-act
CATEGORIES:Australia,privacy,children,breach-notification,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-7@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20261210
DTEND;VALUE=DATE:20261211
SUMMARY:Australia Privacy Act: Automated decision-making transparency appli
 es
DESCRIPTION:Privacy policies must disclose the kinds of personal informatio
 n used in substantially automated decisions that significantly affect indi
 viduals (24 months after assent).\n\nPrivacy Act 1988 (Cth)\, as amended b
 y the Privacy and Other Legislation Amendment Act 2024 (Australia)\n\nSour
 ce: https://www.legislation.gov.au/C2024A00128/asmade\n\nhttps://rulebook.
 fru.dev/regulations/au-privacy-act
URL:https://rulebook.fru.dev/regulations/au-privacy-act
CATEGORIES:Australia,privacy,children,breach-notification,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-114@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20270116
DTEND;VALUE=DATE:20270117
SUMMARY:Indonesia PDP Law: Implementing regulation GR 33/2026 takes effect
DESCRIPTION:Detailed PDP implementing rules (DPIA\, cross-border\, children
 's consent) apply\, 6 months after the 16 Jul 2026 enactment.\n\nLaw No. 2
 7 of 2022 on Personal Data Protection (Undang-Undang Pelindungan Data Prib
 adi) (Indonesia)\n\nSource: https://www.kk-advocates.com/news/read/indones
 ia-gr-pdp-personal-data-protection-compliance-regime-new-phase\n\nhttps://
 rulebook.fru.dev/regulations/id-pdp
URL:https://rulebook.fru.dev/regulations/id-pdp
CATEGORIES:Indonesia,privacy,breach-notification,data-residency,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-97@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20270402
DTEND;VALUE=DATE:20270403
SUMMARY:GDPR: GDPR Procedural Regulation applies
DESCRIPTION:Harmonised rules for cross-border complaint admissibility\, rig
 hts to be heard and access to preliminary findings\, and investigation tim
 elines apply to DPAs from 2 April 2027 (Regulation (EU) 2025/2518\, final 
 article).\n\nRegulation (EU) 2016/679 (General Data Protection Regulation)
  (European Union)\n\nSource: https://eur-lex.europa.eu/eli/reg/2025/2518/o
 j\n\nhttps://rulebook.fru.dev/regulations/eu-gdpr
URL:https://rulebook.fru.dev/regulations/eu-gdpr
CATEGORIES:European Union,privacy,breach-notification,data-access,children,
 biometrics,health
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-104@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20270417
DTEND;VALUE=DATE:20270418
SUMMARY:NIS2: Next biennial entity notification
DESCRIPTION:Competent authorities notify the Commission and Cooperation Gro
 up of the number of essential and important entities\, repeated every two 
 years after 17 Apr 2025 (Art 3(5)).\n\nDirective (EU) 2022/2555 on measure
 s for a high common level of cybersecurity across the Union (NIS2 Directiv
 e) (European Union)\n\nSource: https://eur-lex.europa.eu/eli/dir/2022/2555
 /oj\n\nhttps://rulebook.fru.dev/regulations/eu-nis2
URL:https://rulebook.fru.dev/regulations/eu-nis2
CATEGORIES:European Union,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-118@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20270513
DTEND;VALUE=DATE:20270514
SUMMARY:India DPDP Act: Main data fiduciary obligations apply (18 months)
DESCRIPTION:Rules 3\, 5-16\, 22 and 23 (notice\, security safeguards\, brea
 ch notification\, retention\, children's consent\, SDF duties\, cross-bord
 er) come into force 18 months after publication.\n\nDigital Personal Data 
 Protection Act\, 2023 and Digital Personal Data Protection Rules\, 2025 (I
 ndia)\n\nSource: https://egazette.gov.in/WriteReadData/2025/267650.pdf\n\n
 https://rulebook.fru.dev/regulations/in-dpdp
URL:https://rulebook.fru.dev/regulations/in-dpdp
CATEGORIES:India,privacy,children,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-127@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20270701
DTEND;VALUE=DATE:20270702
SUMMARY:South Korea PIPA: Mandatory ISMS-P certification
DESCRIPTION:ISMS-P certification becomes mandatory for private entities mee
 ting the statutory criteria.\n\nPersonal Information Protection Act (as am
 ended by Act No. 21445\, 2026) (South Korea)\n\nSource: https://www.law.go
 .kr/법령/개인정보보호법\n\nhttps://rulebook.fru.dev/regulations/k
 r-pipa
URL:https://rulebook.fru.dev/regulations/kr-pipa
CATEGORIES:South Korea,privacy,breach-notification,biometrics,data-residenc
 y
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-105@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20271017
DTEND;VALUE=DATE:20271018
SUMMARY:NIS2: Commission review of NIS2
DESCRIPTION:Commission must review the functioning of NIS2 and report to Pa
 rliament and Council\, then every 36 months (Art 40).\n\nDirective (EU) 20
 22/2555 on measures for a high common level of cybersecurity across the Un
 ion (NIS2 Directive) (European Union)\n\nSource: https://eur-lex.europa.eu
 /eli/dir/2022/2555/oj\n\nhttps://rulebook.fru.dev/regulations/eu-nis2
URL:https://rulebook.fru.dev/regulations/eu-nis2
CATEGORIES:European Union,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-28@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20271201
DTEND;VALUE=DATE:20271202
SUMMARY:Chile Personal Data Protection Law (Ley 21.719): Proposed postponem
 ent of entry into force
DESCRIPTION:Government bill Boletin 18623-07 (filed 1 Sep 2026\, 'suma' urg
 ency) would replace the 24-month vacatio legis in transitional Art 1 with 
 a fixed date of 1 Dec 2027\; in first committee stage in the Senate\, not 
 law.\n\nTentative: depends on a proposal not yet adopted.\n\nLey Nº 21.71
 9 que regula la protección y el tratamiento de los datos personales y cre
 a la Agencia de Protección de Datos Personales (Chile)\n\nSource: https:/
 /tramitacion.senado.cl/appsenado/templates/tramitacion/index.php?boletin_i
 ni=18623-07\n\nhttps://rulebook.fru.dev/regulations/cl-pdpl
URL:https://rulebook.fru.dev/regulations/cl-pdpl
CATEGORIES:Chile,privacy,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-51@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20271211
DTEND;VALUE=DATE:20271212
SUMMARY:Cyber Resilience Act: CRA fully applies
DESCRIPTION:All remaining obligations\, including essential cybersecurity r
 equirements\, conformity assessment and CE marking\, apply (Art 71(2)). Pr
 oducts placed on the market earlier are covered only if substantially modi
 fied (Art 69(2)).\n\nRegulation (EU) 2024/2847 on horizontal cybersecurity
  requirements for products with digital elements (Cyber Resilience Act) (E
 uropean Union)\n\nSource: https://eur-lex.europa.eu/eli/reg/2024/2847/oj\n
 \nhttps://rulebook.fru.dev/regulations/eu-cra
URL:https://rulebook.fru.dev/regulations/eu-cra
CATEGORIES:European Union,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-52@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20280611
DTEND;VALUE=DATE:20280612
SUMMARY:Cyber Resilience Act: Legacy type-examination certificates expire
DESCRIPTION:EU type-examination certificates and approval decisions on cybe
 rsecurity requirements under other harmonisation legislation remain valid 
 until this date unless they expire earlier (Art 69(1)).\n\nRegulation (EU)
  2024/2847 on horizontal cybersecurity requirements for products with digi
 tal elements (Cyber Resilience Act) (European Union)\n\nSource: https://eu
 r-lex.europa.eu/eli/reg/2024/2847/oj\n\nhttps://rulebook.fru.dev/regulatio
 ns/eu-cra
URL:https://rulebook.fru.dev/regulations/eu-cra
CATEGORIES:European Union,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-53@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20280911
DTEND;VALUE=DATE:20280912
SUMMARY:Cyber Resilience Act: Report on single reporting platform
DESCRIPTION:Commission report assessing the single reporting platform's eff
 ectiveness (Art 70(2)).\n\nRegulation (EU) 2024/2847 on horizontal cyberse
 curity requirements for products with digital elements (Cyber Resilience A
 ct) (European Union)\n\nSource: https://eur-lex.europa.eu/eli/reg/2024/284
 7/oj\n\nhttps://rulebook.fru.dev/regulations/eu-cra
URL:https://rulebook.fru.dev/regulations/eu-cra
CATEGORIES:European Union,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-54@regulations.fru.dev
DTSTAMP:20260924T112542Z
DTSTART;VALUE=DATE:20301211
DTEND;VALUE=DATE:20301212
SUMMARY:Cyber Resilience Act: First CRA evaluation
DESCRIPTION:Commission evaluation and review report\, then every four years
  (Art 70(1)).\n\nRegulation (EU) 2024/2847 on horizontal cybersecurity req
 uirements for products with digital elements (Cyber Resilience Act) (Europ
 ean Union)\n\nSource: https://eur-lex.europa.eu/eli/reg/2024/2847/oj\n\nht
 tps://rulebook.fru.dev/regulations/eu-cra
URL:https://rulebook.fru.dev/regulations/eu-cra
CATEGORIES:European Union,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
END:VCALENDAR
