BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//fru.dev//Rulebook//EN
CALSCALE:GREGORIAN
METHOD:PUBLISH
X-WR-CALNAME:Regulation deadlines (Rulebook)
X-WR-CALDESC:Compliance deadlines tracked at rulebook.fru.dev
REFRESH-INTERVAL;VALUE=DURATION:P1D
X-PUBLISHED-TTL:P1D
BEGIN:VEVENT
UID:deadline-93@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20160524
DTEND;VALUE=DATE:20160525
SUMMARY:GDPR: GDPR enters into force
DESCRIPTION:Regulation entered into force on the twentieth day after public
 ation in OJ L 119 of 4 May 2016 (Art 99(1)).\n\nRegulation (EU) 2016/679 (
 General Data Protection Regulation) (European Union)\n\nSource: https://eu
 r-lex.europa.eu/eli/reg/2016/679/oj\n\nhttps://rulebook.fru.dev/regulation
 s/eu-gdpr
URL:https://rulebook.fru.dev/regulations/eu-gdpr
CATEGORIES:European Union,privacy,breach-notification,data-access,children,
 biometrics,health
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-94@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20180525
DTEND;VALUE=DATE:20180526
SUMMARY:GDPR: GDPR applies
DESCRIPTION:All GDPR obligations apply from 25 May 2018 (Art 99(2))\, repla
 cing Directive 95/46/EC.\n\nRegulation (EU) 2016/679 (General Data Protect
 ion Regulation) (European Union)\n\nSource: https://eur-lex.europa.eu/eli/
 reg/2016/679/oj\n\nhttps://rulebook.fru.dev/regulations/eu-gdpr
URL:https://rulebook.fru.dev/regulations/eu-gdpr
CATEGORIES:European Union,privacy,breach-notification,data-access,children,
 biometrics,health
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-164@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20200101
DTEND;VALUE=DATE:20200102
SUMMARY:CCPA / CPRA: CCPA takes effect
DESCRIPTION:Original CCPA consumer rights and business obligations take eff
 ect.\n\nCalifornia Consumer Privacy Act of 2018\, as amended by the Califo
 rnia Privacy Rights Act of 2020 (Cal. Civ. Code 1798.100 et seq.) and CPPA
  regulations (Cal. Code Regs. tit. 11\, 7000 et seq.) (California)\n\nSour
 ce: https://cppa.ca.gov/regulations/pdf/ccpa_statute_eff_20260101.pdf\n\nh
 ttps://rulebook.fru.dev/regulations/us-ca-ccpa
URL:https://rulebook.fru.dev/regulations/us-ca-ccpa
CATEGORIES:California,privacy,ai,cybersecurity,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-36@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20211101
DTEND;VALUE=DATE:20211102
SUMMARY:China PIPL: PIPL takes effect
DESCRIPTION:All PIPL obligations (legal bases\, consent\, cross-border rule
 s\, data subject rights) apply (Art. 74).\n\nPersonal Information Protecti
 on Law of the People's Republic of China (China)\n\nSource: http://www.cac
 .gov.cn/2021-08/20/c_1631050028355286.htm\n\nhttps://rulebook.fru.dev/regu
 lations/cn-pipl
URL:https://rulebook.fru.dev/regulations/cn-pipl
CATEGORIES:China,privacy,data-residency,biometrics,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-121@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20220401
DTEND;VALUE=DATE:20220402
SUMMARY:Japan APPI: 2020 amendments in force
DESCRIPTION:Mandatory breach reporting\, pseudonymized information and stri
 cter cross-border rules apply.\n\nAct on the Protection of Personal Inform
 ation (Act No. 57 of 2003)\, as amended including the 2026 amendment act (
 Japan)\n\nSource: https://www.ppc.go.jp/en/legal/\n\nhttps://rulebook.fru.
 dev/regulations/jp-appi
URL:https://rulebook.fru.dev/regulations/jp-appi
CATEGORIES:Japan,privacy,children,biometrics,breach-notification,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-112@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20221017
DTEND;VALUE=DATE:20221018
SUMMARY:Indonesia PDP Law: PDP Law enacted and in force
DESCRIPTION:Law takes effect on enactment\, starting a 2-year transition.\n
 \nLaw No. 27 of 2022 on Personal Data Protection (Undang-Undang Pelindunga
 n Data Pribadi) (Indonesia)\n\nSource: https://peraturan.bpk.go.id/Details
 /229798/uu-no-27-tahun-2022\n\nhttps://rulebook.fru.dev/regulations/id-pdp
URL:https://rulebook.fru.dev/regulations/id-pdp
CATEGORIES:Indonesia,privacy,breach-notification,data-residency,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-75@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20221116
DTEND;VALUE=DATE:20221117
SUMMARY:Digital Services Act: DSA enters into force
DESCRIPTION:Entered into force twenty days after publication\; VLOP designa
 tion provisions (Art 33(3)-(6)) and Commission enforcement sections apply 
 from this date (Art 93).\n\nRegulation (EU) 2022/2065 on a Single Market f
 or Digital Services (Digital Services Act) (European Union)\n\nSource: htt
 ps://eur-lex.europa.eu/eli/reg/2022/2065/oj\n\nhttps://rulebook.fru.dev/re
 gulations/eu-dsa
URL:https://rulebook.fru.dev/regulations/eu-dsa
CATEGORIES:European Union,online-safety,children,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-165@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20230101
DTEND;VALUE=DATE:20230102
SUMMARY:CCPA / CPRA: CPRA amendments operative
DESCRIPTION:CPRA amendments (correction right\, sensitive PI limits\, shari
 ng opt-out\, employee/B2B data coverage) become operative.\n\nCalifornia C
 onsumer Privacy Act of 2018\, as amended by the California Privacy Rights 
 Act of 2020 (Cal. Civ. Code 1798.100 et seq.) and CPPA regulations (Cal. C
 ode Regs. tit. 11\, 7000 et seq.) (California)\n\nSource: https://cppa.ca.
 gov/regulations/pdf/ccpa_statute_eff_20260101.pdf\n\nhttps://rulebook.fru.
 dev/regulations/us-ca-ccpa
URL:https://rulebook.fru.dev/regulations/us-ca-ccpa
CATEGORIES:California,privacy,ai,cybersecurity,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-311@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20230101
DTEND;VALUE=DATE:20230102
SUMMARY:Virginia VCDPA: VCDPA takes effect
DESCRIPTION:VCDPA obligations and consumer rights apply.\n\nVirginia Consum
 er Data Protection Act (SB 1392 / HB 2307\, 2021) (Virginia)\n\nSource: ht
 tps://law.lis.virginia.gov/vacode/title59.1/chapter53/\n\nhttps://rulebook
 .fru.dev/regulations/us-va-vcdpa
URL:https://rulebook.fru.dev/regulations/us-va-vcdpa
CATEGORIES:Virginia,privacy,children,online-safety
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-76@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20230217
DTEND;VALUE=DATE:20230218
SUMMARY:Digital Services Act: Platforms publish EU user numbers
DESCRIPTION:Online platforms and search engines had to publish average mont
 hly active EU recipients\, and must update them at least every six months 
 (Art 24(2)).\n\nRegulation (EU) 2022/2065 on a Single Market for Digital S
 ervices (Digital Services Act) (European Union)\n\nSource: https://eur-lex
 .europa.eu/eli/reg/2022/2065/oj\n\nhttps://rulebook.fru.dev/regulations/eu
 -dsa
URL:https://rulebook.fru.dev/regulations/eu-dsa
CATEGORIES:European Union,online-safety,children,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-77@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20230425
DTEND;VALUE=DATE:20230426
SUMMARY:Digital Services Act: First VLOP/VLOSE designations
DESCRIPTION:Commission designated the first 19 very large online platforms 
 and search engines (e.g. Amazon Store\, Facebook\, Google Search\, TikTok\
 , X). Obligations apply four months after notification.\n\nRegulation (EU)
  2022/2065 on a Single Market for Digital Services (Digital Services Act) 
 (European Union)\n\nSource: https://digital-strategy.ec.europa.eu/en/polic
 ies/list-designated-vlops-and-vloses\n\nhttps://rulebook.fru.dev/regulatio
 ns/eu-dsa
URL:https://rulebook.fru.dev/regulations/eu-dsa
CATEGORIES:European Union,online-safety,children,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-207@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20230701
DTEND;VALUE=DATE:20230702
SUMMARY:Colorado Privacy Act (CPA): CPA takes effect
DESCRIPTION:Core consumer rights and controller duties apply.\n\nColorado P
 rivacy Act (SB 21-190)\, C.R.S. 6-1-1301 et seq.\, as amended by HB 24-113
 0\, SB 24-041 and SB 25-276 (Colorado)\n\nSource: https://leg.colorado.gov
 /bills/sb21-190\n\nhttps://rulebook.fru.dev/regulations/us-co-cpa
URL:https://rulebook.fru.dev/regulations/us-co-cpa
CATEGORIES:Colorado,privacy,children,biometrics
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-215@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20230701
DTEND;VALUE=DATE:20230702
SUMMARY:Connecticut Data Privacy Act (CTDPA): CTDPA takes effect
DESCRIPTION:Core consumer rights and controller obligations apply.\n\nConne
 cticut Data Privacy Act (Public Act 22-15)\, Conn. Gen. Stat. 42-515 et se
 q.\, as amended by Public Act 25-113 (SB 1295) and Public Act 26-64 (SB 4)
  (Connecticut)\n\nSource: https://www.cga.ct.gov/asp/cgabillstatus/cgabill
 status.asp?selBillType=Bill&which_year=2022&bill_num=6\n\nhttps://rulebook
 .fru.dev/regulations/us-ct-ctdpa
URL:https://rulebook.fru.dev/regulations/us-ct-ctdpa
CATEGORIES:Connecticut,privacy,children,ai,health
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-156@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20231026
DTEND;VALUE=DATE:20231027
SUMMARY:UK Online Safety Act: Royal Assent
DESCRIPTION:The Online Safety Act receives Royal Assent.\n\nOnline Safety A
 ct 2023 (United Kingdom)\n\nSource: https://www.legislation.gov.uk/ukpga/2
 023/50/contents\n\nhttps://rulebook.fru.dev/regulations/uk-osa
URL:https://rulebook.fru.dev/regulations/uk-osa
CATEGORIES:United Kingdom,online-safety,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-78@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20240217
DTEND;VALUE=DATE:20240218
SUMMARY:Digital Services Act: DSA applies to all intermediary services
DESCRIPTION:Full application to all providers of intermediary services (Art
  93(2)).\n\nRegulation (EU) 2022/2065 on a Single Market for Digital Servi
 ces (Digital Services Act) (European Union)\n\nSource: https://eur-lex.eur
 opa.eu/eli/reg/2022/2065/oj\n\nhttps://rulebook.fru.dev/regulations/eu-dsa
URL:https://rulebook.fru.dev/regulations/eu-dsa
CATEGORIES:European Union,online-safety,children,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-208@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20240701
DTEND;VALUE=DATE:20240702
SUMMARY:Colorado Privacy Act (CPA): Universal opt-out mechanism recognition
  required
DESCRIPTION:Controllers must honor AG-recognized universal opt-out mechanis
 ms (e.g. Global Privacy Control).\n\nColorado Privacy Act (SB 21-190)\, C.
 R.S. 6-1-1301 et seq.\, as amended by HB 24-1130\, SB 24-041 and SB 25-276
  (Colorado)\n\nSource: https://leg.colorado.gov/bills/sb21-190\n\nhttps://
 rulebook.fru.dev/regulations/us-co-cpa
URL:https://rulebook.fru.dev/regulations/us-co-cpa
CATEGORIES:Colorado,privacy,children,biometrics
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-230@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20240701
DTEND;VALUE=DATE:20240702
SUMMARY:Florida Digital Bill of Rights: Florida Digital Bill of Rights take
 s effect
DESCRIPTION:SB 262 obligations under Fla. Stat. 501.701-501.722 apply.\n\nF
 lorida Digital Bill of Rights (CS/CS/SB 262\, 2023) (Florida)\n\nSource: h
 ttps://www.flsenate.gov/Session/Bill/2023/262\n\nhttps://rulebook.fru.dev/
 regulations/us-fl-fdbr
URL:https://rulebook.fru.dev/regulations/us-fl-fdbr
CATEGORIES:Florida,privacy,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-283@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20240701
DTEND;VALUE=DATE:20240702
SUMMARY:Oregon OCPA: OCPA takes effect for most controllers
DESCRIPTION:OCPA obligations apply to for-profit controllers meeting the th
 resholds.\n\nOregon Consumer Privacy Act (SB 619\, 2023) (Oregon)\n\nSourc
 e: https://www.doj.state.or.us/consumer-protection/id-theft-data-breaches/
 privacy/\n\nhttps://rulebook.fru.dev/regulations/us-or-ocpa
URL:https://rulebook.fru.dev/regulations/us-or-ocpa
CATEGORIES:Oregon,privacy,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-37@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20240801
DTEND;VALUE=DATE:20240802
SUMMARY:EU AI Act: AI Act enters into force
DESCRIPTION:Regulation (EU) 2024/1689 enters into force twenty days after p
 ublication on 12 July 2024 (Art 113).\n\nRegulation (EU) 2024/1689 laying 
 down harmonised rules on artificial intelligence (Artificial Intelligence 
 Act)\, as amended by Regulation (EU) 2026/1744 (Digital Omnibus on AI) (Eu
 ropean Union)\n\nSource: https://eur-lex.europa.eu/eli/reg/2024/1689/oj\n\
 nhttps://rulebook.fru.dev/regulations/eu-ai-act
URL:https://rulebook.fru.dev/regulations/eu-ai-act
CATEGORIES:European Union,ai,biometrics,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-258@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20241001
DTEND;VALUE=DATE:20241002
SUMMARY:Montana Consumer Data Privacy Act (MCDPA): MCDPA takes effect
DESCRIPTION:Consumer rights\, controller duties and opt-out preference sign
 al support apply.\n\nMontana Consumer Data Privacy Act (SB 384\, 2023)\, M
 ont. Code Ann. 30-14-2801 et seq.\, as amended by SB 297 (2025) (Montana)\
 n\nSource: https://archive.legmt.gov/bills/mca/title_0300/chapter_0140/par
 t_0280/section_0030/0300-0140-0280-0030.html\n\nhttps://rulebook.fru.dev/r
 egulations/us-mt-mcdpa
URL:https://rulebook.fru.dev/regulations/us-mt-mcdpa
CATEGORIES:Montana,privacy,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-113@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20241017
DTEND;VALUE=DATE:20241018
SUMMARY:Indonesia PDP Law: PDP Law transition ends
DESCRIPTION:Controllers and processors must fully comply (Art. 74 two-year 
 transition).\n\nLaw No. 27 of 2022 on Personal Data Protection (Undang-Und
 ang Pelindungan Data Pribadi) (Indonesia)\n\nSource: https://peraturan.bpk
 .go.id/Details/229798/uu-no-27-tahun-2022\n\nhttps://rulebook.fru.dev/regu
 lations/id-pdp
URL:https://rulebook.fru.dev/regulations/id-pdp
CATEGORIES:Indonesia,privacy,breach-notification,data-residency,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-4@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20241211
DTEND;VALUE=DATE:20241212
SUMMARY:Australia Privacy Act: Most POLA Act 2024 amendments commence
DESCRIPTION:Tiered penalties\, infringement notices\, OAIC powers\, securit
 y and overseas-transfer clarifications and doxxing offences commence the d
 ay after Royal Assent.\n\nPrivacy Act 1988 (Cth)\, as amended by the Priva
 cy and Other Legislation Amendment Act 2024 (Australia)\n\nSource: https:/
 /www.legislation.gov.au/C2024A00128/asmade\n\nhttps://rulebook.fru.dev/reg
 ulations/au-privacy-act
URL:https://rulebook.fru.dev/regulations/au-privacy-act
CATEGORIES:Australia,privacy,children,breach-notification,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-216@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20241231
DTEND;VALUE=DATE:20250101
SUMMARY:Connecticut Data Privacy Act (CTDPA): Mandatory 60-day cure period 
 expires
DESCRIPTION:After Dec 31\, 2024\, the AG is no longer required to offer a 6
 0-day cure before enforcement\; cure becomes discretionary.\n\nConnecticut
  Data Privacy Act (Public Act 22-15)\, Conn. Gen. Stat. 42-515 et seq.\, a
 s amended by Public Act 25-113 (SB 1295) and Public Act 26-64 (SB 4) (Conn
 ecticut)\n\nSource: https://www.cga.ct.gov/asp/cgabillstatus/cgabillstatus
 .asp?selBillType=Bill&which_year=2022&bill_num=6\n\nhttps://rulebook.fru.d
 ev/regulations/us-ct-ctdpa
URL:https://rulebook.fru.dev/regulations/us-ct-ctdpa
CATEGORIES:Connecticut,privacy,children,ai,health
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-166@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20250101
DTEND;VALUE=DATE:20250102
SUMMARY:CCPA / CPRA: CPI adjustment of thresholds and fines
DESCRIPTION:Revenue threshold rises to $26\,625\,000 and fines to $2\,663 /
  $7\,988 per violation.\n\nCalifornia Consumer Privacy Act of 2018\, as am
 ended by the California Privacy Rights Act of 2020 (Cal. Civ. Code 1798.10
 0 et seq.) and CPPA regulations (Cal. Code Regs. tit. 11\, 7000 et seq.) (
 California)\n\nSource: https://cppa.ca.gov/regulations/cpi_adjustment.html
 \n\nhttps://rulebook.fru.dev/regulations/us-ca-ccpa
URL:https://rulebook.fru.dev/regulations/us-ca-ccpa
CATEGORIES:California,privacy,ai,cybersecurity,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-209@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20250101
DTEND;VALUE=DATE:20250102
SUMMARY:Colorado Privacy Act (CPA): 60-day cure period expires
DESCRIPTION:Mandatory 60-day notice-and-cure before AG enforcement ends\; e
 nforcement may proceed without cure.\n\nColorado Privacy Act (SB 21-190)\,
  C.R.S. 6-1-1301 et seq.\, as amended by HB 24-1130\, SB 24-041 and SB 25-
 276 (Colorado)\n\nSource: https://leg.colorado.gov/bills/sb21-190\n\nhttps
 ://rulebook.fru.dev/regulations/us-co-cpa
URL:https://rulebook.fru.dev/regulations/us-co-cpa
CATEGORIES:Colorado,privacy,children,biometrics
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-217@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20250101
DTEND;VALUE=DATE:20250102
SUMMARY:Connecticut Data Privacy Act (CTDPA): Universal opt-out preference 
 signals required
DESCRIPTION:Controllers must honor opt-out preference signals for targeted 
 advertising and sale (effective Jan 1\, 2025).\n\nConnecticut Data Privacy
  Act (Public Act 22-15)\, Conn. Gen. Stat. 42-515 et seq.\, as amended by 
 Public Act 25-113 (SB 1295) and Public Act 26-64 (SB 4) (Connecticut)\n\nS
 ource: https://www.cga.ct.gov/asp/cgabillstatus/cgabillstatus.asp?selBillT
 ype=Bill&which_year=2022&bill_num=6\n\nhttps://rulebook.fru.dev/regulation
 s/us-ct-ctdpa
URL:https://rulebook.fru.dev/regulations/us-ct-ctdpa
CATEGORIES:Connecticut,privacy,children,ai,health
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-223@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20250101
DTEND;VALUE=DATE:20250102
SUMMARY:Delaware Personal Data Privacy Act (DPDPA): DPDPA takes effect
DESCRIPTION:Consumer rights and controller duties apply\; 60-day mandatory 
 cure period begins.\n\nDelaware Personal Data Privacy Act (HB 154)\, 6 Del
 . C. ch. 12D (Delaware)\n\nSource: https://delcode.delaware.gov/title6/c01
 2d/index.html\n\nhttps://rulebook.fru.dev/regulations/us-de-dpdpa
URL:https://rulebook.fru.dev/regulations/us-de-dpdpa
CATEGORIES:Delaware,privacy,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-261@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20250101
DTEND;VALUE=DATE:20250102
SUMMARY:New Hampshire Privacy Act: New Hampshire Privacy Act takes effect
DESCRIPTION:RSA 507-H obligations and consumer rights apply (Laws 2024\, 5:
 1\, eff. Jan. 1\, 2025).\n\nNew Hampshire Privacy Act (SB 255\, 2024)\, RS
 A chapter 507-H (New Hampshire)\n\nSource: https://gc.nh.gov/rsa/html/LII/
 507-H/507-H-2.htm\n\nhttps://rulebook.fru.dev/regulations/us-nh-privacy
URL:https://rulebook.fru.dev/regulations/us-nh-privacy
CATEGORIES:New Hampshire,privacy,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-264@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20250115
DTEND;VALUE=DATE:20250116
SUMMARY:New Jersey NJDPA: NJDPA takes effect
DESCRIPTION:The act takes effect on the 365th day after enactment on Jan 16
 \, 2024 (sec. 17).\n\nNew Jersey Data Privacy Act (P.L.2023\, c.266\; S332
 ) (New Jersey)\n\nSource: https://pub.njleg.state.nj.us/Bills/2022/PL23/26
 6_.PDF\n\nhttps://rulebook.fru.dev/regulations/us-nj-njdpa
URL:https://rulebook.fru.dev/regulations/us-nj-njdpa
CATEGORIES:New Jersey,privacy,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-38@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20250202
DTEND;VALUE=DATE:20250203
SUMMARY:EU AI Act: Prohibited practices and AI literacy apply
DESCRIPTION:Chapters I and II apply\, including the Article 5 bans on prohi
 bited AI practices and the Article 4 AI literacy duty (Art 113(a)).\n\nReg
 ulation (EU) 2024/1689 laying down harmonised rules on artificial intellig
 ence (Artificial Intelligence Act)\, as amended by Regulation (EU) 2026/17
 44 (Digital Omnibus on AI) (European Union)\n\nSource: https://eur-lex.eur
 opa.eu/eli/reg/2024/1689/oj\n\nhttps://rulebook.fru.dev/regulations/eu-ai-
 act
URL:https://rulebook.fru.dev/regulations/eu-ai-act
CATEGORIES:European Union,ai,biometrics,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-157@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20250317
DTEND;VALUE=DATE:20250318
SUMMARY:UK Online Safety Act: Illegal harms duties enforceable
DESCRIPTION:Illegal content safety duties apply\; illegal content risk asse
 ssments had to be completed by 16 March 2025.\n\nOnline Safety Act 2023 (U
 nited Kingdom)\n\nSource: https://www.ofcom.org.uk/online-safety/illegal-a
 nd-harmful-content\n\nhttps://rulebook.fru.dev/regulations/uk-osa
URL:https://rulebook.fru.dev/regulations/uk-osa
CATEGORIES:United Kingdom,online-safety,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-158@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20250416
DTEND;VALUE=DATE:20250417
SUMMARY:UK Online Safety Act: Children's access assessments due
DESCRIPTION:Services had to complete children's access assessments to deter
 mine whether children are likely to access them.\n\nOnline Safety Act 2023
  (United Kingdom)\n\nSource: https://www.ofcom.org.uk/online-safety/protec
 ting-children/protection-of-children-duties-under-the-online-safety-act\n\
 nhttps://rulebook.fru.dev/regulations/uk-osa
URL:https://rulebook.fru.dev/regulations/uk-osa
CATEGORIES:United Kingdom,online-safety,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-298@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20250519
DTEND;VALUE=DATE:20250520
SUMMARY:TAKE IT DOWN Act: Criminal provisions effective on enactment
DESCRIPTION:Publishing or threatening to publish non-consensual intimate im
 ages\, including digital forgeries\, became a federal crime upon signature
 .\n\nTools to Address Known Exploitation by Immobilizing Technological Dee
 pfakes on Websites and Networks Act (TAKE IT DOWN Act) (United States (Fed
 eral))\n\nSource: https://www.govinfo.gov/content/pkg/PLAW-119publ12/html/
 PLAW-119publ12.htm\n\nhttps://rulebook.fru.dev/regulations/us-take-it-down
URL:https://rulebook.fru.dev/regulations/us-take-it-down
CATEGORIES:United States (Federal),online-safety,ai,children,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-210@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20250523
DTEND;VALUE=DATE:20250524
SUMMARY:Colorado Privacy Act (CPA): SB 25-276 geolocation and sensitive-dat
 a sale amendment effective
DESCRIPTION:Adds precise geolocation data definitions and prohibits selling
  sensitive data without consent (effective on signature).\n\nColorado Priv
 acy Act (SB 21-190)\, C.R.S. 6-1-1301 et seq.\, as amended by HB 24-1130\,
  SB 24-041 and SB 25-276 (Colorado)\n\nSource: https://leg.colorado.gov/bi
 lls/sb25-276\n\nhttps://rulebook.fru.dev/regulations/us-co-cpa
URL:https://rulebook.fru.dev/regulations/us-co-cpa
CATEGORIES:Colorado,privacy,children,biometrics
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-265@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20250602
DTEND;VALUE=DATE:20250603
SUMMARY:New Jersey NJDPA: Division of Consumer Affairs proposes NJDPA rules
  (N.J.A.C. 13:45L)
DESCRIPTION:Proposed rules published at 57 N.J.R. 1101(a)\; comments were d
 ue Aug 1\, 2025.\n\nNew Jersey Data Privacy Act (P.L.2023\, c.266\; S332) 
 (New Jersey)\n\nSource: https://www.njoag.gov/murphy-administration-announ
 ces-proposed-rules-establishing-comprehensive-consumer-data-privacy-protec
 tions/\n\nhttps://rulebook.fru.dev/regulations/us-nj-njdpa
URL:https://rulebook.fru.dev/regulations/us-nj-njdpa
CATEGORIES:New Jersey,privacy,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-5@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20250610
DTEND;VALUE=DATE:20250611
SUMMARY:Australia Privacy Act: Statutory tort for serious invasions of priv
 acy commences
DESCRIPTION:Individuals can sue for serious invasions of privacy (Schedule 
 2)\, 6 months after Royal Assent.\n\nPrivacy Act 1988 (Cth)\, as amended b
 y the Privacy and Other Legislation Amendment Act 2024 (Australia)\n\nSour
 ce: https://www.legislation.gov.au/C2024A00128/asmade\n\nhttps://rulebook.
 fru.dev/regulations/au-privacy-act
URL:https://rulebook.fru.dev/regulations/au-privacy-act
CATEGORIES:Australia,privacy,children,breach-notification,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-213@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20250623
DTEND;VALUE=DATE:20250624
SUMMARY:COPPA Rule: Amended COPPA Rule takes effect
DESCRIPTION:The April 2025 amendments to 16 CFR Part 312 became effective\;
  during the transition operators could comply with either the pre-2025 or 
 the amended Rule.\n\nChildren's Online Privacy Protection Rule (16 CFR Par
 t 312)\, as amended April 2025 (United States (Federal))\n\nSource: https:
 //www.federalregister.gov/documents/2025/04/22/2025-05904/childrens-online
 -privacy-protection-rule\n\nhttps://rulebook.fru.dev/regulations/us-coppa
URL:https://rulebook.fru.dev/regulations/us-coppa
CATEGORIES:United States (Federal),privacy,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-211@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20250701
DTEND;VALUE=DATE:20250702
SUMMARY:Colorado Privacy Act (CPA): Biometric identifier amendment (HB 24-1
 130) effective
DESCRIPTION:Any controller processing biometric identifiers must adopt a wr
 itten biometric policy\, give notice\, obtain consent and follow retention
 /deletion rules.\n\nColorado Privacy Act (SB 21-190)\, C.R.S. 6-1-1301 et 
 seq.\, as amended by HB 24-1130\, SB 24-041 and SB 25-276 (Colorado)\n\nSo
 urce: https://leg.colorado.gov/bills/hb24-1130\n\nhttps://rulebook.fru.dev
 /regulations/us-co-cpa
URL:https://rulebook.fru.dev/regulations/us-co-cpa
CATEGORIES:Colorado,privacy,children,biometrics
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-284@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20250701
DTEND;VALUE=DATE:20250702
SUMMARY:Oregon OCPA: OCPA applies to nonprofits
DESCRIPTION:Nonprofit organizations meeting the thresholds become subject t
 o OCPA.\n\nOregon Consumer Privacy Act (SB 619\, 2023) (Oregon)\n\nSource:
  https://www.doj.state.or.us/consumer-protection/for-businesses/privacy-la
 w-faqs-for-nonprofits/\n\nhttps://rulebook.fru.dev/regulations/us-or-ocpa
URL:https://rulebook.fru.dev/regulations/us-or-ocpa
CATEGORIES:Oregon,privacy,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-266@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20250715
DTEND;VALUE=DATE:20250716
SUMMARY:New Jersey NJDPA: Universal opt-out mechanism must be honored
DESCRIPTION:Controllers that sell personal data or process it for targeted 
 advertising must honor user-selected universal opt-out signals within six 
 months of the effective date (N.J.S.A. 56:8-166.11).\n\nNew Jersey Data Pr
 ivacy Act (P.L.2023\, c.266\; S332) (New Jersey)\n\nSource: https://pub.nj
 leg.state.nj.us/Bills/2022/PL23/266_.PDF\n\nhttps://rulebook.fru.dev/regul
 ations/us-nj-njdpa
URL:https://rulebook.fru.dev/regulations/us-nj-njdpa
CATEGORIES:New Jersey,privacy,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-159@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20250725
DTEND;VALUE=DATE:20250726
SUMMARY:UK Online Safety Act: Protection of children duties apply
DESCRIPTION:Children's safety duties and Protection of Children Codes take 
 effect\, including highly effective age assurance\; children's risk assess
 ments due by 24 July 2025.\n\nOnline Safety Act 2023 (United Kingdom)\n\nS
 ource: https://www.ofcom.org.uk/online-safety/protecting-children/protecti
 on-of-children-duties-under-the-online-safety-act\n\nhttps://rulebook.fru.
 dev/regulations/uk-osa
URL:https://rulebook.fru.dev/regulations/uk-osa
CATEGORIES:United Kingdom,online-safety,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-39@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20250802
DTEND;VALUE=DATE:20250803
SUMMARY:EU AI Act: GPAI\, governance\, notified bodies and penalties apply
DESCRIPTION:Chapter III Section 4 (notifying authorities)\, Chapter V (gene
 ral-purpose AI model obligations)\, Chapter VII (governance)\, Chapter XII
  (penalties\, except Art 101) and Art 78 apply (Art 113(b)).\n\nRegulation
  (EU) 2024/1689 laying down harmonised rules on artificial intelligence (A
 rtificial Intelligence Act)\, as amended by Regulation (EU) 2026/1744 (Dig
 ital Omnibus on AI) (European Union)\n\nSource: https://eur-lex.europa.eu/
 eli/reg/2024/1689/oj\n\nhttps://rulebook.fru.dev/regulations/eu-ai-act
URL:https://rulebook.fru.dev/regulations/eu-ai-act
CATEGORIES:European Union,ai,biometrics,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-167@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20250922
DTEND;VALUE=DATE:20250923
SUMMARY:CCPA / CPRA: ADMT\, risk assessment and cybersecurity audit regulat
 ions approved
DESCRIPTION:OAL approves the CCPA Updates\, Cybersecurity Audit\, Risk Asse
 ssment\, ADMT and Insurance regulations and files them with the Secretary 
 of State.\n\nCalifornia Consumer Privacy Act of 2018\, as amended by the C
 alifornia Privacy Rights Act of 2020 (Cal. Civ. Code 1798.100 et seq.) and
  CPPA regulations (Cal. Code Regs. tit. 11\, 7000 et seq.) (California)\n\
 nSource: https://cppa.ca.gov/regulations/ccpa_updates.html\n\nhttps://rule
 book.fru.dev/regulations/us-ca-ccpa
URL:https://rulebook.fru.dev/regulations/us-ca-ccpa
CATEGORIES:California,privacy,ai,cybersecurity,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-212@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20251001
DTEND;VALUE=DATE:20251002
SUMMARY:Colorado Privacy Act (CPA): Minors' data amendment (SB 24-041) effe
 ctive
DESCRIPTION:Controllers offering online services to minors must use reasona
 ble care\, conduct assessments\, and obtain consent for targeted ads\, sal
 e and certain profiling of minors.\n\nColorado Privacy Act (SB 21-190)\, C
 .R.S. 6-1-1301 et seq.\, as amended by HB 24-1130\, SB 24-041 and SB 25-27
 6 (Colorado)\n\nSource: https://leg.colorado.gov/bills/sb24-041\n\nhttps:/
 /rulebook.fru.dev/regulations/us-co-cpa
URL:https://rulebook.fru.dev/regulations/us-co-cpa
CATEGORIES:Colorado,privacy,children,biometrics
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-252@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20251001
DTEND;VALUE=DATE:20251002
SUMMARY:Maryland Online Data Privacy Act (MODPA): MODPA takes effect
DESCRIPTION:Act takes effect\; data protection assessments apply to process
 ing activities on or after Oct 1\, 2025.\n\nMaryland Online Data Privacy A
 ct of 2024 (SB 541 / HB 567)\, Md. Code\, Com. Law 14-4601 et seq. (Maryla
 nd)\n\nSource: https://mgaleg.maryland.gov/2024RS/Chapters_noln/CH_455_sb0
 541e.pdf\n\nhttps://rulebook.fru.dev/regulations/us-md-modpa
URL:https://rulebook.fru.dev/regulations/us-md-modpa
CATEGORIES:Maryland,privacy,children,health,biometrics
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-259@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20251001
DTEND;VALUE=DATE:20251002
SUMMARY:Montana Consumer Data Privacy Act (MCDPA): SB 297 amendments take e
 ffect\; cure period eliminated
DESCRIPTION:Lower thresholds (25\,000 / 15\,000 + 25%)\, minors' data prote
 ctions\, AG assessment demands\; the 60-day cure period is removed.\n\nMon
 tana Consumer Data Privacy Act (SB 384\, 2023)\, Mont. Code Ann. 30-14-280
 1 et seq.\, as amended by SB 297 (2025) (Montana)\n\nSource: https://archi
 ve.legmt.gov/bills/mca/title_0300/chapter_0140/part_0280/section_0170/0300
 -0140-0280-0170.html\n\nhttps://rulebook.fru.dev/regulations/us-mt-mcdpa
URL:https://rulebook.fru.dev/regulations/us-mt-mcdpa
CATEGORIES:Montana,privacy,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-181@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20251013
DTEND;VALUE=DATE:20251014
SUMMARY:California SB 243 (companion chatbots): SB 243 signed
DESCRIPTION:SB 243 chaptered (ch. 677).\n\nCalifornia SB 243\, Companion Ch
 atbots (Stats. 2025\, ch. 677) (California)\n\nSource: https://leginfo.leg
 islature.ca.gov/faces/billNavClient.xhtml?bill_id=202520260SB243\n\nhttps:
 //rulebook.fru.dev/regulations/us-ca-sb243
URL:https://rulebook.fru.dev/regulations/us-ca-sb243
CATEGORIES:California,ai,children,online-safety
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-116@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20251113
DTEND;VALUE=DATE:20251114
SUMMARY:India DPDP Act: DPDP Rules published\; Board and procedural rules i
 n force
DESCRIPTION:Rules 1\, 2 and 17-21 (Data Protection Board constitution and f
 unctioning) take effect on publication in the Official Gazette.\n\nDigital
  Personal Data Protection Act\, 2023 and Digital Personal Data Protection 
 Rules\, 2025 (India)\n\nSource: https://egazette.gov.in/WriteReadData/2025
 /267650.pdf\n\nhttps://rulebook.fru.dev/regulations/in-dpdp
URL:https://rulebook.fru.dev/regulations/in-dpdp
CATEGORIES:India,privacy,children,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-95@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20251126
DTEND;VALUE=DATE:20251127
SUMMARY:GDPR: GDPR Procedural Regulation adopted
DESCRIPTION:Regulation (EU) 2025/2518 laying down additional procedural rul
 es for cross-border GDPR enforcement signed by Parliament and Council.\n\n
 Regulation (EU) 2016/679 (General Data Protection Regulation) (European Un
 ion)\n\nSource: https://eur-lex.europa.eu/eli/reg/2025/2518/oj\n\nhttps://
 rulebook.fru.dev/regulations/eu-gdpr
URL:https://rulebook.fru.dev/regulations/eu-gdpr
CATEGORIES:European Union,privacy,breach-notification,data-access,children,
 biometrics,health
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-8@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20251210
DTEND;VALUE=DATE:20251211
SUMMARY:Australia Social Media Minimum Age: Social media minimum age obliga
 tion applies
DESCRIPTION:Age-restricted platforms must take reasonable steps to prevent 
 under-16s from holding accounts.\n\nOnline Safety Amendment (Social Media 
 Minimum Age) Act 2024 (Australia)\n\nSource: https://www.legislation.gov.a
 u/C2024A00127/asmade\n\nhttps://rulebook.fru.dev/regulations/au-social-med
 ia-min-age
URL:https://rulebook.fru.dev/regulations/au-social-media-min-age
CATEGORIES:Australia,children,online-safety
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-224@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20251231
DTEND;VALUE=DATE:20260101
SUMMARY:Delaware Personal Data Privacy Act (DPDPA): Mandatory 60-day cure p
 eriod expires
DESCRIPTION:Mandatory notice-and-cure ends Dec 31\, 2025\; from Jan 1\, 202
 6 DOJ decides whether to offer a cure using statutory factors.\n\nDelaware
  Personal Data Privacy Act (HB 154)\, 6 Del. C. ch. 12D (Delaware)\n\nSour
 ce: https://delcode.delaware.gov/title6/c012d/index.html\n\nhttps://rulebo
 ok.fru.dev/regulations/us-de-dpdpa
URL:https://rulebook.fru.dev/regulations/us-de-dpdpa
CATEGORIES:Delaware,privacy,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-182@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20260101
DTEND;VALUE=DATE:20260102
SUMMARY:California SB 243 (companion chatbots): Chatbot safeguards apply
DESCRIPTION:AI disclosure\, suicide and self-harm protocols\, and minor pro
 tections apply.\n\nCalifornia SB 243\, Companion Chatbots (Stats. 2025\, c
 h. 677) (California)\n\nSource: https://leginfo.legislature.ca.gov/faces/b
 illNavClient.xhtml?bill_id=202520260SB243\n\nhttps://rulebook.fru.dev/regu
 lations/us-ca-sb243
URL:https://rulebook.fru.dev/regulations/us-ca-sb243
CATEGORIES:California,ai,children,online-safety
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-168@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20260101
DTEND;VALUE=DATE:20260102
SUMMARY:CCPA / CPRA: New CCPA regulations take effect
DESCRIPTION:ADMT\, risk assessment\, cybersecurity audit and updated CCPA r
 egulations become effective\; risk assessments required for new high-risk 
 processing.\n\nCalifornia Consumer Privacy Act of 2018\, as amended by the
  California Privacy Rights Act of 2020 (Cal. Civ. Code 1798.100 et seq.) a
 nd CPPA regulations (Cal. Code Regs. tit. 11\, 7000 et seq.) (California)\
 n\nSource: https://cppa.ca.gov/regulations/ccpa_updates.html\n\nhttps://ru
 lebook.fru.dev/regulations/us-ca-ccpa
URL:https://rulebook.fru.dev/regulations/us-ca-ccpa
CATEGORIES:California,privacy,ai,cybersecurity,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-225@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20260101
DTEND;VALUE=DATE:20260102
SUMMARY:Delaware Personal Data Privacy Act (DPDPA): Opt-out preference sign
 als must be honored
DESCRIPTION:Controllers must allow opt-out of targeted advertising and sale
  via opt-out preference signals (12D-106).\n\nDelaware Personal Data Priva
 cy Act (HB 154)\, 6 Del. C. ch. 12D (Delaware)\n\nSource: https://delcode.
 delaware.gov/title6/c012d/index.html\n\nhttps://rulebook.fru.dev/regulatio
 ns/us-de-dpdpa
URL:https://rulebook.fru.dev/regulations/us-de-dpdpa
CATEGORIES:Delaware,privacy,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-96@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20260101
DTEND;VALUE=DATE:20260102
SUMMARY:GDPR: GDPR Procedural Regulation enters into force
DESCRIPTION:Regulation (EU) 2025/2518\, published in the OJ on 12 December 
 2025\, enters into force on the twentieth day after publication.\n\nRegula
 tion (EU) 2016/679 (General Data Protection Regulation) (European Union)\n
 \nSource: https://eur-lex.europa.eu/eli/reg/2025/2518/oj\n\nhttps://rulebo
 ok.fru.dev/regulations/eu-gdpr
URL:https://rulebook.fru.dev/regulations/eu-gdpr
CATEGORIES:European Union,privacy,breach-notification,data-access,children,
 biometrics,health
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-262@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20260101
DTEND;VALUE=DATE:20260102
SUMMARY:New Hampshire Privacy Act: Mandatory 60-day cure period expires
DESCRIPTION:The AG's obligation to issue a cure notice ended Dec 31\, 2025\
 ; from Jan 1\, 2026 cure opportunities are discretionary (RSA 507-H:11 II-
 III).\n\nNew Hampshire Privacy Act (SB 255\, 2024)\, RSA chapter 507-H (Ne
 w Hampshire)\n\nSource: https://gc.nh.gov/rsa/html/LII/507-H/507-H-11.htm\
 n\nhttps://rulebook.fru.dev/regulations/us-nh-privacy
URL:https://rulebook.fru.dev/regulations/us-nh-privacy
CATEGORIES:New Hampshire,privacy,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-285@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20260101
DTEND;VALUE=DATE:20260102
SUMMARY:Oregon OCPA: Cure period sunsets
DESCRIPTION:The AG's 30-day notice-and-cure requirement expires\; enforceme
 nt can proceed without a cure opportunity.\n\nOregon Consumer Privacy Act 
 (SB 619\, 2023) (Oregon)\n\nSource: https://www.oregonlegislature.gov/bill
 s_laws/ors/ors646A.html\n\nhttps://rulebook.fru.dev/regulations/us-or-ocpa
URL:https://rulebook.fru.dev/regulations/us-or-ocpa
CATEGORIES:Oregon,privacy,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-286@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20260101
DTEND;VALUE=DATE:20260102
SUMMARY:Oregon OCPA: Universal opt-out signals must be honored
DESCRIPTION:Controllers must honor opt-out preference signals such as Globa
 l Privacy Control.\n\nOregon Consumer Privacy Act (SB 619\, 2023) (Oregon)
 \n\nSource: https://www.doj.state.or.us/consumer-protection/id-theft-data-
 breaches/privacy/\n\nhttps://rulebook.fru.dev/regulations/us-or-ocpa
URL:https://rulebook.fru.dev/regulations/us-or-ocpa
CATEGORIES:Oregon,privacy,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-287@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20260101
DTEND;VALUE=DATE:20260102
SUMMARY:Oregon OCPA: Sale ban on precise geolocation and under-16 data (HB 
 2008)
DESCRIPTION:Selling precise geolocation (1\,750-ft radius) and the personal
  data of consumers the controller knows or willfully disregards are under 
 16 is prohibited.\n\nOregon Consumer Privacy Act (SB 619\, 2023) (Oregon)\
 n\nSource: https://www.doj.state.or.us/consumer-protection/id-theft-data-b
 reaches/privacy/\n\nhttps://rulebook.fru.dev/regulations/us-or-ocpa
URL:https://rulebook.fru.dev/regulations/us-or-ocpa
CATEGORIES:Oregon,privacy,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-324@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20260101
DTEND;VALUE=DATE:20260102
SUMMARY:Vietnam PDPL: PDPL and Decree 356/2025 take effect
DESCRIPTION:Personal data protection obligations\, DPIA/TIA filing and pena
 lty framework apply\; Decree 13/2023 replaced.\n\nLaw on Personal Data Pro
 tection (Law No. 91/2025/QH15) (Vietnam)\n\nSource: https://vanban.chinhph
 u.vn/?pageid=27160&docid=214590\n\nhttps://rulebook.fru.dev/regulations/vn
 -pdpl
URL:https://rulebook.fru.dev/regulations/vn-pdpl
CATEGORIES:Vietnam,privacy,data-residency,children,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-312@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20260101
DTEND;VALUE=DATE:20260102
SUMMARY:Virginia VCDPA: Under-16 social media time limit (SB 854) takes eff
 ect
DESCRIPTION:Social media platforms must use commercially reasonable age det
 ermination and cap users under 16 at 1 hour/day unless a parent consents. 
 A preliminary injunction issued Feb 27\, 2026 bars enforcement.\n\nVirgini
 a Consumer Data Protection Act (SB 1392 / HB 2307\, 2021) (Virginia)\n\nSo
 urce: https://netchoice.org/wp-content/uploads/2026/02/Virginia-PI-Opinion
 _Granted.pdf\n\nhttps://rulebook.fru.dev/regulations/us-va-vcdpa
URL:https://rulebook.fru.dev/regulations/us-va-vcdpa
CATEGORIES:Virginia,privacy,children,online-safety
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-313@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20260227
DTEND;VALUE=DATE:20260228
SUMMARY:Virginia VCDPA: SB 854 preliminarily enjoined (NetChoice v. Jones)
DESCRIPTION:E.D. Va. preliminarily enjoined enforcement of the SB 854 socia
 l media time-limit provisions on First Amendment grounds\; Virginia has ap
 pealed.\n\nVirginia Consumer Data Protection Act (SB 1392 / HB 2307\, 2021
 ) (Virginia)\n\nSource: https://netchoice.org/wp-content/uploads/2026/02/V
 irginia-PI-Opinion_Granted.pdf\n\nhttps://rulebook.fru.dev/regulations/us-
 va-vcdpa
URL:https://rulebook.fru.dev/regulations/us-va-vcdpa
CATEGORIES:Virginia,privacy,children,online-safety
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-10@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20260317
DTEND;VALUE=DATE:20260318
SUMMARY:Brazil ECA Digital: ECA Digital in force
DESCRIPTION:Art. 41-A (as set by Law 15.352/2026\, following MP 1.319/2025)
  fixes entry into force on 17 March 2026.\n\nEstatuto Digital da Criança 
 e do Adolescente (Law No. 15.211/2025) (Brazil)\n\nSource: https://www.pla
 nalto.gov.br/ccivil_03/_ato2023-2026/2025/lei/L15211.htm\n\nhttps://rulebo
 ok.fru.dev/regulations/br-eca-digital
URL:https://rulebook.fru.dev/regulations/br-eca-digital
CATEGORIES:Brazil,children,online-safety,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-253@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20260401
DTEND;VALUE=DATE:20260402
SUMMARY:Maryland Online Data Privacy Act (MODPA): MODPA applies to personal
  data processing
DESCRIPTION:The act applies to personal data processing activities from Apr
 il 1\, 2026 (Section 2 of ch. 455).\n\nMaryland Online Data Privacy Act of
  2024 (SB 541 / HB 567)\, Md. Code\, Com. Law 14-4601 et seq. (Maryland)\n
 \nSource: https://mgaleg.maryland.gov/2024RS/Chapters_noln/CH_455_sb0541e.
 pdf\n\nhttps://rulebook.fru.dev/regulations/us-md-modpa
URL:https://rulebook.fru.dev/regulations/us-md-modpa
CATEGORIES:Maryland,privacy,children,health,biometrics
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-160@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20260411
DTEND;VALUE=DATE:20260412
SUMMARY:UK Online Safety Act: Fee notification window closes (2026/27)
DESCRIPTION:Fee-liable providers must notify Ofcom before the notification 
 window for the first charging year closes.\n\nOnline Safety Act 2023 (Unit
 ed Kingdom)\n\nSource: https://www.ofcom.org.uk/online-safety/illegal-and-
 harmful-content/online-safety-fees-and-penalties\n\nhttps://rulebook.fru.d
 ev/regulations/uk-osa
URL:https://rulebook.fru.dev/regulations/uk-osa
CATEGORIES:United Kingdom,online-safety,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-214@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20260422
DTEND;VALUE=DATE:20260423
SUMMARY:COPPA Rule: Full compliance with amended COPPA Rule
DESCRIPTION:Operators must comply with all amended provisions (separate thi
 rd-party disclosure consent\, written retention policy\, written security 
 program\, updated notices)\; excludes Safe Harbor provisions 312.11(d)(1)\
 , (d)(4) and (g)\, which had earlier dates.\n\nChildren's Online Privacy P
 rotection Rule (16 CFR Part 312)\, as amended April 2025 (United States (F
 ederal))\n\nSource: https://www.federalregister.gov/documents/2025/04/22/2
 025-05904/childrens-online-privacy-protection-rule\n\nhttps://rulebook.fru
 .dev/regulations/us-coppa
URL:https://rulebook.fru.dev/regulations/us-coppa
CATEGORIES:United States (Federal),privacy,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-299@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20260519
DTEND;VALUE=DATE:20260520
SUMMARY:TAKE IT DOWN Act: Platform notice-and-removal process required
DESCRIPTION:Covered platforms must have a clear notice-and-removal process 
 and remove valid reported content within 48 hours (Sec. 3\, one year after
  enactment).\n\nTools to Address Known Exploitation by Immobilizing Techno
 logical Deepfakes on Websites and Networks Act (TAKE IT DOWN Act) (United 
 States (Federal))\n\nSource: https://www.govinfo.gov/content/pkg/PLAW-119p
 ubl12/html/PLAW-119publ12.htm\n\nhttps://rulebook.fru.dev/regulations/us-t
 ake-it-down
URL:https://rulebook.fru.dev/regulations/us-take-it-down
CATEGORIES:United States (Federal),online-safety,ai,children,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-267@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20260630
DTEND;VALUE=DATE:20260701
SUMMARY:New Jersey NJDPA: A5328 sensitive data sale ban takes effect
DESCRIPTION:A5328\, signed June 30\, 2026\, prohibits selling sensitive per
 sonal data\; the ban took effect on signing.\n\nNew Jersey Data Privacy Ac
 t (P.L.2023\, c.266\; S332) (New Jersey)\n\nSource: https://www.njleg.stat
 e.nj.us/bill-search/2026/A5328\n\nhttps://rulebook.fru.dev/regulations/us-
 nj-njdpa
URL:https://rulebook.fru.dev/regulations/us-nj-njdpa
CATEGORIES:New Jersey,privacy,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-218@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20260701
DTEND;VALUE=DATE:20260702
SUMMARY:Connecticut Data Privacy Act (CTDPA): PA 25-113 (SB 1295) amendment
 s take effect
DESCRIPTION:Thresholds drop to 35\,000 consumers or any sensitive-data proc
 essing or data sale\; expanded sensitive data\, minors' protections\, and 
 LLM-training disclosure in privacy notices.\n\nConnecticut Data Privacy Ac
 t (Public Act 22-15)\, Conn. Gen. Stat. 42-515 et seq.\, as amended by Pub
 lic Act 25-113 (SB 1295) and Public Act 26-64 (SB 4) (Connecticut)\n\nSour
 ce: https://www.cga.ct.gov/2025/ACT/PA/PDF/2025PA-00113-R00SB-01295-PA.PDF
 \n\nhttps://rulebook.fru.dev/regulations/us-ct-ctdpa
URL:https://rulebook.fru.dev/regulations/us-ct-ctdpa
CATEGORIES:Connecticut,privacy,children,ai,health
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-268@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20260701
DTEND;VALUE=DATE:20260702
SUMMARY:New Jersey NJDPA: Mandatory 30-day cure period expires
DESCRIPTION:The Division's duty to issue a cure notice before enforcement e
 nds on the first day of the 18th month after the effective date (N.J.S.A. 
 56:8-166.17(b)).\n\nNew Jersey Data Privacy Act (P.L.2023\, c.266\; S332) 
 (New Jersey)\n\nSource: https://pub.njleg.state.nj.us/Bills/2022/PL23/266_
 .PDF\n\nhttps://rulebook.fru.dev/regulations/us-nj-njdpa
URL:https://rulebook.fru.dev/regulations/us-nj-njdpa
CATEGORIES:New Jersey,privacy,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-314@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20260701
DTEND;VALUE=DATE:20260702
SUMMARY:Virginia VCDPA: Ban on selling precise geolocation data (SB 338)
DESCRIPTION:Controllers may not sell consumers' precise geolocation data (1
 \,750-ft radius)\, replacing the prior consent-based treatment.\n\nVirgini
 a Consumer Data Protection Act (SB 1392 / HB 2307\, 2021) (Virginia)\n\nSo
 urce: https://lis.virginia.gov/bill-details/20261/SB338\n\nhttps://ruleboo
 k.fru.dev/regulations/us-va-vcdpa
URL:https://rulebook.fru.dev/regulations/us-va-vcdpa
CATEGORIES:Virginia,privacy,children,online-safety
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-122@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20260717
DTEND;VALUE=DATE:20260718
SUMMARY:Japan APPI: 2026 APPI amendment act promulgated
DESCRIPTION:Amendment enacted by the Diet on 10 July 2026 and promulgated\;
  main provisions take effect by cabinet order within two years of promulga
 tion.\n\nAct on the Protection of Personal Information (Act No. 57 of 2003
 )\, as amended including the 2026 amendment act (Japan)\n\nSource: https:/
 /www.ppc.go.jp/files/pdf/260731_shiryou-1.pdf\n\nhttps://rulebook.fru.dev/
 regulations/jp-appi
URL:https://rulebook.fru.dev/regulations/jp-appi
CATEGORIES:Japan,privacy,children,biometrics,breach-notification,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-40@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20260727
DTEND;VALUE=DATE:20260728
SUMMARY:EU AI Act: Digital Omnibus on AI enters into force
DESCRIPTION:Regulation (EU) 2026/1744 (adopted 8 July 2026\, OJ 24 July 202
 6) enters into force on the third day after publication. Amended Articles 
 102 to 110 apply from this date (new Art 113(d)).\n\nRegulation (EU) 2024/
 1689 laying down harmonised rules on artificial intelligence (Artificial I
 ntelligence Act)\, as amended by Regulation (EU) 2026/1744 (Digital Omnibu
 s on AI) (European Union)\n\nSource: https://eur-lex.europa.eu/eli/reg/202
 6/1744/oj\n\nhttps://rulebook.fru.dev/regulations/eu-ai-act
URL:https://rulebook.fru.dev/regulations/eu-ai-act
CATEGORIES:European Union,ai,biometrics,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-219@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20260801
DTEND;VALUE=DATE:20260802
SUMMARY:Connecticut Data Privacy Act (CTDPA): Profiling impact assessments 
 apply
DESCRIPTION:Impact assessment requirements apply to profiling activities cr
 eated or generated on or after Aug 1\, 2026 (Conn. Gen. Stat. 42-522 as am
 ended).\n\nConnecticut Data Privacy Act (Public Act 22-15)\, Conn. Gen. St
 at. 42-515 et seq.\, as amended by Public Act 25-113 (SB 1295) and Public 
 Act 26-64 (SB 4) (Connecticut)\n\nSource: https://www.cga.ct.gov/2025/ACT/
 PA/PDF/2025PA-00113-R00SB-01295-PA.PDF\n\nhttps://rulebook.fru.dev/regulat
 ions/us-ct-ctdpa
URL:https://rulebook.fru.dev/regulations/us-ct-ctdpa
CATEGORIES:Connecticut,privacy,children,ai,health
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-41@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20260802
DTEND;VALUE=DATE:20260803
SUMMARY:EU AI Act: General application: transparency obligations\, GPAI fin
 es\, most other rules
DESCRIPTION:The AI Act's general date of application. Article 50 transparen
 cy obligations (chatbot disclosure\, deepfake labelling\, machine-readable
  marking of synthetic content) and Commission fines on GPAI providers (Art
  101) apply. Not deferred by the Omnibus.\n\nRegulation (EU) 2024/1689 lay
 ing down harmonised rules on artificial intelligence (Artificial Intellige
 nce Act)\, as amended by Regulation (EU) 2026/1744 (Digital Omnibus on AI)
  (European Union)\n\nSource: https://eur-lex.europa.eu/eli/reg/2024/1689/o
 j\n\nhttps://rulebook.fru.dev/regulations/eu-ai-act
URL:https://rulebook.fru.dev/regulations/eu-ai-act
CATEGORIES:European Union,ai,biometrics,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-79@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20260831
DTEND;VALUE=DATE:20260901
SUMMARY:Digital Services Act: ChatGPT designated as VLOSE\; Reddit and Robl
 ox as VLOPs
DESCRIPTION:Commission designated ChatGPT as a very large online search eng
 ine and Reddit and Roblox as very large online platforms. They have four m
 onths (by January 2027) to meet VLOP/VLOSE obligations.\n\nRegulation (EU)
  2022/2065 on a Single Market for Digital Services (Digital Services Act) 
 (European Union)\n\nSource: https://digital-strategy.ec.europa.eu/en/news/
 commission-designates-chatgpt-reddit-roblox-under-digital-services-act\n\n
 https://rulebook.fru.dev/regulations/eu-dsa
URL:https://rulebook.fru.dev/regulations/eu-dsa
CATEGORIES:European Union,online-safety,children,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-220@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20261001
DTEND;VALUE=DATE:20261002
SUMMARY:Connecticut Data Privacy Act (CTDPA): PA 26-64 (SB 4) amendments ta
 ke effect
DESCRIPTION:Prohibits controllers and third parties from selling precise ge
 olocation data and enacts data broker and other consumer protection provis
 ions.\n\nConnecticut Data Privacy Act (Public Act 22-15)\, Conn. Gen. Stat
 . 42-515 et seq.\, as amended by Public Act 25-113 (SB 1295) and Public Ac
 t 26-64 (SB 4) (Connecticut)\n\nSource: https://www.cga.ct.gov/2026/ACT/PA
 /PDF/2026PA-00064-R00SB-00004-PA.PDF\n\nhttps://rulebook.fru.dev/regulatio
 ns/us-ct-ctdpa
URL:https://rulebook.fru.dev/regulations/us-ct-ctdpa
CATEGORIES:Connecticut,privacy,children,ai,health
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-117@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20261113
DTEND;VALUE=DATE:20261114
SUMMARY:India DPDP Act: Consent Manager registration rule in force (12 mont
 hs)
DESCRIPTION:Rule 4 (registration and obligations of Consent Managers) comes
  into force one year after publication.\n\nDigital Personal Data Protectio
 n Act\, 2023 and Digital Personal Data Protection Rules\, 2025 (India)\n\n
 Source: https://egazette.gov.in/WriteReadData/2025/267650.pdf\n\nhttps://r
 ulebook.fru.dev/regulations/in-dpdp
URL:https://rulebook.fru.dev/regulations/in-dpdp
CATEGORIES:India,privacy,children,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-42@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20261202
DTEND;VALUE=DATE:20261203
SUMMARY:EU AI Act: New bans on sexual deepfakes and CSAM generation\; Art 5
 0(2) grace period ends
DESCRIPTION:New Art 5(1)(ba)/(bb) prohibitions on AI systems that generate 
 non-consensual intimate imagery of identifiable persons or child sexual ab
 use material apply. Generative AI systems placed on the market before 2 Au
 g 2026 must comply with the Art 50(2) marking duty by this date (new Art 1
 11(4)).\n\nRegulation (EU) 2024/1689 laying down harmonised rules on artif
 icial intelligence (Artificial Intelligence Act)\, as amended by Regulatio
 n (EU) 2026/1744 (Digital Omnibus on AI) (European Union)\n\nSource: https
 ://eur-lex.europa.eu/eli/reg/2026/1744/oj\n\nhttps://rulebook.fru.dev/regu
 lations/eu-ai-act
URL:https://rulebook.fru.dev/regulations/eu-ai-act
CATEGORIES:European Union,ai,biometrics,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20261210
DTEND;VALUE=DATE:20261211
SUMMARY:Australia Privacy Act: Children's Online Privacy Code must be regis
 tered
DESCRIPTION:OAIC must develop and register the Children's Online Privacy Co
 de within 24 months of Royal Assent.\n\nPrivacy Act 1988 (Cth)\, as amende
 d by the Privacy and Other Legislation Amendment Act 2024 (Australia)\n\nS
 ource: https://www.oaic.gov.au/privacy/privacy-registers/privacy-codes/chi
 ldrens-online-privacy-code\n\nhttps://rulebook.fru.dev/regulations/au-priv
 acy-act
URL:https://rulebook.fru.dev/regulations/au-privacy-act
CATEGORIES:Australia,privacy,children,breach-notification,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-7@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20261210
DTEND;VALUE=DATE:20261211
SUMMARY:Australia Privacy Act: Automated decision-making transparency appli
 es
DESCRIPTION:Privacy policies must disclose the kinds of personal informatio
 n used in substantially automated decisions that significantly affect indi
 viduals (24 months after assent).\n\nPrivacy Act 1988 (Cth)\, as amended b
 y the Privacy and Other Legislation Amendment Act 2024 (Australia)\n\nSour
 ce: https://www.legislation.gov.au/C2024A00128/asmade\n\nhttps://rulebook.
 fru.dev/regulations/au-privacy-act
URL:https://rulebook.fru.dev/regulations/au-privacy-act
CATEGORIES:Australia,privacy,children,breach-notification,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-169@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20270101
DTEND;VALUE=DATE:20270102
SUMMARY:CCPA / CPRA: ADMT requirements compliance date
DESCRIPTION:Businesses using ADMT for significant decisions must comply wit
 h Article 11 (pre-use notice\, opt-out\, access rights) by this date (11 C
 CR 7200(b)).\n\nCalifornia Consumer Privacy Act of 2018\, as amended by th
 e California Privacy Rights Act of 2020 (Cal. Civ. Code 1798.100 et seq.) 
 and CPPA regulations (Cal. Code Regs. tit. 11\, 7000 et seq.) (California)
 \n\nSource: https://cppa.ca.gov/regulations/pdf/ccpa_updates_cyber_risk_ad
 mt_appr_text.pdf\n\nhttps://rulebook.fru.dev/regulations/us-ca-ccpa
URL:https://rulebook.fru.dev/regulations/us-ca-ccpa
CATEGORIES:California,privacy,ai,cybersecurity,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-170@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20270101
DTEND;VALUE=DATE:20270102
SUMMARY:CCPA / CPRA: Browsers must support opt-out preference signal (AB 56
 6)
DESCRIPTION:Businesses that develop or maintain a browser must include cons
 umer-configurable functionality to send an opt-out preference signal (Civ.
  Code 1798.136\, operative Jan 1\, 2027).\n\nCalifornia Consumer Privacy A
 ct of 2018\, as amended by the California Privacy Rights Act of 2020 (Cal.
  Civ. Code 1798.100 et seq.) and CPPA regulations (Cal. Code Regs. tit. 11
 \, 7000 et seq.) (California)\n\nSource: https://leginfo.legislature.ca.go
 v/faces/billStatusClient.xhtml?bill_id=202520260AB566\n\nhttps://rulebook.
 fru.dev/regulations/us-ca-ccpa
URL:https://rulebook.fru.dev/regulations/us-ca-ccpa
CATEGORIES:California,privacy,ai,cybersecurity,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-221@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20270101
DTEND;VALUE=DATE:20270102
SUMMARY:Connecticut Data Privacy Act (CTDPA): Data broker registration requ
 ired
DESCRIPTION:Data brokers may not sell or license brokered personal data in 
 Connecticut unless registered with the Department of Consumer Protection (
 $2\,500 initial fee).\n\nConnecticut Data Privacy Act (Public Act 22-15)\,
  Conn. Gen. Stat. 42-515 et seq.\, as amended by Public Act 25-113 (SB 129
 5) and Public Act 26-64 (SB 4) (Connecticut)\n\nSource: https://www.cga.ct
 .gov/2026/ACT/PA/PDF/2026PA-00064-R00SB-00004-PA.PDF\n\nhttps://rulebook.f
 ru.dev/regulations/us-ct-ctdpa
URL:https://rulebook.fru.dev/regulations/us-ct-ctdpa
CATEGORIES:Connecticut,privacy,children,ai,health
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-226@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20270101
DTEND;VALUE=DATE:20270102
SUMMARY:Delaware Personal Data Privacy Act (DPDPA): Amended thresholds and 
 third-party duties take effect
DESCRIPTION:Applicability drops to 10\,000 consumers (or 5\,000 + 20% reven
 ue from sale) and new third-party duties (12D-107A) apply.\n\nDelaware Per
 sonal Data Privacy Act (HB 154)\, 6 Del. C. ch. 12D (Delaware)\n\nSource: 
 https://delcode.delaware.gov/title6/c012d/index.html\n\nhttps://rulebook.f
 ru.dev/regulations/us-de-dpdpa
URL:https://rulebook.fru.dev/regulations/us-de-dpdpa
CATEGORIES:Delaware,privacy,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-263@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20270101
DTEND;VALUE=DATE:20270102
SUMMARY:New Hampshire Privacy Act: Ban on selling personal data of children
  under 13 (HB 1460)
DESCRIPTION:HB 1460 (2026\, ch. 168) prohibits controllers from selling the
  personal data of a child under 13.\n\nNew Hampshire Privacy Act (SB 255\,
  2024)\, RSA chapter 507-H (New Hampshire)\n\nSource: https://gc.nh.gov/bi
 ll_status/billinfo.aspx?id=2443&inflect=2\n\nhttps://rulebook.fru.dev/regu
 lations/us-nh-privacy
URL:https://rulebook.fru.dev/regulations/us-nh-privacy
CATEGORIES:New Hampshire,privacy,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-114@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20270116
DTEND;VALUE=DATE:20270117
SUMMARY:Indonesia PDP Law: Implementing regulation GR 33/2026 takes effect
DESCRIPTION:Detailed PDP implementing rules (DPIA\, cross-border\, children
 's consent) apply\, 6 months after the 16 Jul 2026 enactment.\n\nLaw No. 2
 7 of 2022 on Personal Data Protection (Undang-Undang Pelindungan Data Prib
 adi) (Indonesia)\n\nSource: https://www.kk-advocates.com/news/read/indones
 ia-gr-pdp-personal-data-protection-compliance-regime-new-phase\n\nhttps://
 rulebook.fru.dev/regulations/id-pdp
URL:https://rulebook.fru.dev/regulations/id-pdp
CATEGORIES:Indonesia,privacy,breach-notification,data-residency,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-254@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20270401
DTEND;VALUE=DATE:20270402
SUMMARY:Maryland Online Data Privacy Act (MODPA): Discretionary 60-day cure
  period ends
DESCRIPTION:The Division's discretionary notice-and-cure (at least 60 days)
  applies only to violations occurring on or before April 1\, 2027 (Com. La
 w 14-4614).\n\nMaryland Online Data Privacy Act of 2024 (SB 541 / HB 567)\
 , Md. Code\, Com. Law 14-4601 et seq. (Maryland)\n\nSource: https://mgaleg
 .maryland.gov/2024RS/Chapters_noln/CH_455_sb0541e.pdf\n\nhttps://rulebook.
 fru.dev/regulations/us-md-modpa
URL:https://rulebook.fru.dev/regulations/us-md-modpa
CATEGORIES:Maryland,privacy,children,health,biometrics
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-97@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20270402
DTEND;VALUE=DATE:20270403
SUMMARY:GDPR: GDPR Procedural Regulation applies
DESCRIPTION:Harmonised rules for cross-border complaint admissibility\, rig
 hts to be heard and access to preliminary findings\, and investigation tim
 elines apply to DPAs from 2 April 2027 (Regulation (EU) 2025/2518\, final 
 article).\n\nRegulation (EU) 2016/679 (General Data Protection Regulation)
  (European Union)\n\nSource: https://eur-lex.europa.eu/eli/reg/2025/2518/o
 j\n\nhttps://rulebook.fru.dev/regulations/eu-gdpr
URL:https://rulebook.fru.dev/regulations/eu-gdpr
CATEGORIES:European Union,privacy,breach-notification,data-access,children,
 biometrics,health
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-118@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20270513
DTEND;VALUE=DATE:20270514
SUMMARY:India DPDP Act: Main data fiduciary obligations apply (18 months)
DESCRIPTION:Rules 3\, 5-16\, 22 and 23 (notice\, security safeguards\, brea
 ch notification\, retention\, children's consent\, SDF duties\, cross-bord
 er) come into force 18 months after publication.\n\nDigital Personal Data 
 Protection Act\, 2023 and Digital Personal Data Protection Rules\, 2025 (I
 ndia)\n\nSource: https://egazette.gov.in/WriteReadData/2025/267650.pdf\n\n
 https://rulebook.fru.dev/regulations/in-dpdp
URL:https://rulebook.fru.dev/regulations/in-dpdp
CATEGORIES:India,privacy,children,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-183@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20270701
DTEND;VALUE=DATE:20270702
SUMMARY:California SB 243 (companion chatbots): First annual report to Offi
 ce of Suicide Prevention
DESCRIPTION:Operators begin annual reporting on crisis referrals and detect
 ion protocols.\n\nCalifornia SB 243\, Companion Chatbots (Stats. 2025\, ch
 . 677) (California)\n\nSource: https://leginfo.legislature.ca.gov/faces/bi
 llNavClient.xhtml?bill_id=202520260SB243\n\nhttps://rulebook.fru.dev/regul
 ations/us-ca-sb243
URL:https://rulebook.fru.dev/regulations/us-ca-sb243
CATEGORIES:California,ai,children,online-safety
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-43@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20270802
DTEND;VALUE=DATE:20270803
SUMMARY:EU AI Act: Legacy GPAI models must comply\; national AI sandboxes o
 perational
DESCRIPTION:Providers of GPAI models placed on the market before 2 Aug 2025
  must comply (Art 111(3)). Each Member State must have at least one nation
 al AI regulatory sandbox operational (Art 57(1) as amended by the Omnibus)
 .\n\nRegulation (EU) 2024/1689 laying down harmonised rules on artificial 
 intelligence (Artificial Intelligence Act)\, as amended by Regulation (EU)
  2026/1744 (Digital Omnibus on AI) (European Union)\n\nSource: https://eur
 -lex.europa.eu/eli/reg/2024/1689/oj\n\nhttps://rulebook.fru.dev/regulation
 s/eu-ai-act
URL:https://rulebook.fru.dev/regulations/eu-ai-act
CATEGORIES:European Union,ai,biometrics,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-44@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20271202
DTEND;VALUE=DATE:20271203
SUMMARY:EU AI Act: High-risk obligations apply to Annex III systems
DESCRIPTION:Chapter III Sections 1-3 (high-risk requirements and provider/d
 eployer obligations) apply to AI systems classified high-risk under Art 6(
 2) and Annex III (employment\, credit scoring\, education\, biometrics\, e
 ssential services and similar). Deferred from 2 Aug 2026 by Regulation (EU
 ) 2026/1744.\n\nRegulation (EU) 2024/1689 laying down harmonised rules on 
 artificial intelligence (Artificial Intelligence Act)\, as amended by Regu
 lation (EU) 2026/1744 (Digital Omnibus on AI) (European Union)\n\nSource: 
 https://eur-lex.europa.eu/eli/reg/2026/1744/oj\n\nhttps://rulebook.fru.dev
 /regulations/eu-ai-act
URL:https://rulebook.fru.dev/regulations/eu-ai-act
CATEGORIES:European Union,ai,biometrics,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-171@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20271231
DTEND;VALUE=DATE:20280101
SUMMARY:CCPA / CPRA: Risk assessments for pre-existing processing due
DESCRIPTION:Risk assessments must be completed and documented for high-risk
  processing that began before Jan 1\, 2026 and continues after (11 CCR 715
 5(b)).\n\nCalifornia Consumer Privacy Act of 2018\, as amended by the Cali
 fornia Privacy Rights Act of 2020 (Cal. Civ. Code 1798.100 et seq.) and CP
 PA regulations (Cal. Code Regs. tit. 11\, 7000 et seq.) (California)\n\nSo
 urce: https://cppa.ca.gov/regulations/pdf/ccpa_updates_cyber_risk_admt_app
 r_text.pdf\n\nhttps://rulebook.fru.dev/regulations/us-ca-ccpa
URL:https://rulebook.fru.dev/regulations/us-ca-ccpa
CATEGORIES:California,privacy,ai,cybersecurity,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-172@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20280401
DTEND;VALUE=DATE:20280402
SUMMARY:CCPA / CPRA: First risk assessment submission to CPPA
DESCRIPTION:Businesses must submit required risk assessment information and
  attestation for assessments conducted in 2026 and 2027 (11 CCR 7157(a)(1)
 )\; annually by April 1 thereafter.\n\nCalifornia Consumer Privacy Act of 
 2018\, as amended by the California Privacy Rights Act of 2020 (Cal. Civ. 
 Code 1798.100 et seq.) and CPPA regulations (Cal. Code Regs. tit. 11\, 700
 0 et seq.) (California)\n\nSource: https://cppa.ca.gov/regulations/pdf/ccp
 a_updates_cyber_risk_admt_appr_text.pdf\n\nhttps://rulebook.fru.dev/regula
 tions/us-ca-ccpa
URL:https://rulebook.fru.dev/regulations/us-ca-ccpa
CATEGORIES:California,privacy,ai,cybersecurity,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-173@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20280401
DTEND;VALUE=DATE:20280402
SUMMARY:CCPA / CPRA: Cybersecurity audit due: revenue over $100M
DESCRIPTION:First cybersecurity audit report (covering Jan 1\, 2027 - Jan 1
 \, 2028) and certification due for businesses with 2026 annual gross reven
 ue over $100M (11 CCR 7121(a)(1)).\n\nCalifornia Consumer Privacy Act of 2
 018\, as amended by the California Privacy Rights Act of 2020 (Cal. Civ. C
 ode 1798.100 et seq.) and CPPA regulations (Cal. Code Regs. tit. 11\, 7000
  et seq.) (California)\n\nSource: https://cppa.ca.gov/regulations/pdf/ccpa
 _updates_cyber_risk_admt_appr_text.pdf\n\nhttps://rulebook.fru.dev/regulat
 ions/us-ca-ccpa
URL:https://rulebook.fru.dev/regulations/us-ca-ccpa
CATEGORIES:California,privacy,ai,cybersecurity,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-45@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20280802
DTEND;VALUE=DATE:20280803
SUMMARY:EU AI Act: High-risk obligations apply to Annex I product-embedded 
 systems
DESCRIPTION:Chapter III Sections 1-3 apply to AI systems classified high-ri
 sk under Art 6(1) and Annex I (safety components of products covered by EU
  harmonisation legislation). Deferred from 2 Aug 2027 by Regulation (EU) 2
 026/1744.\n\nRegulation (EU) 2024/1689 laying down harmonised rules on art
 ificial intelligence (Artificial Intelligence Act)\, as amended by Regulat
 ion (EU) 2026/1744 (Digital Omnibus on AI) (European Union)\n\nSource: htt
 ps://eur-lex.europa.eu/eli/reg/2026/1744/oj\n\nhttps://rulebook.fru.dev/re
 gulations/eu-ai-act
URL:https://rulebook.fru.dev/regulations/eu-ai-act
CATEGORIES:European Union,ai,biometrics,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-222@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20281001
DTEND;VALUE=DATE:20281002
SUMMARY:Connecticut Data Privacy Act (CTDPA): Data brokers must process sta
 te deletion mechanism requests
DESCRIPTION:Registered data brokers must access the DCP accessible deletion
  mechanism at least every 45 days and process deletion requests.\n\nConnec
 ticut Data Privacy Act (Public Act 22-15)\, Conn. Gen. Stat. 42-515 et seq
 .\, as amended by Public Act 25-113 (SB 1295) and Public Act 26-64 (SB 4) 
 (Connecticut)\n\nSource: https://www.cga.ct.gov/2026/ACT/PA/PDF/2026PA-000
 64-R00SB-00004-PA.PDF\n\nhttps://rulebook.fru.dev/regulations/us-ct-ctdpa
URL:https://rulebook.fru.dev/regulations/us-ct-ctdpa
CATEGORIES:Connecticut,privacy,children,ai,health
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-174@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20290401
DTEND;VALUE=DATE:20290402
SUMMARY:CCPA / CPRA: Cybersecurity audit due: revenue $50M-$100M
DESCRIPTION:First cybersecurity audit report (covering 2028) due for busine
 sses with 2027 annual gross revenue between $50M and $100M (11 CCR 7121(a)
 (2)).\n\nCalifornia Consumer Privacy Act of 2018\, as amended by the Calif
 ornia Privacy Rights Act of 2020 (Cal. Civ. Code 1798.100 et seq.) and CPP
 A regulations (Cal. Code Regs. tit. 11\, 7000 et seq.) (California)\n\nSou
 rce: https://cppa.ca.gov/regulations/pdf/ccpa_updates_cyber_risk_admt_appr
 _text.pdf\n\nhttps://rulebook.fru.dev/regulations/us-ca-ccpa
URL:https://rulebook.fru.dev/regulations/us-ca-ccpa
CATEGORIES:California,privacy,ai,cybersecurity,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-175@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20300401
DTEND;VALUE=DATE:20300402
SUMMARY:CCPA / CPRA: Cybersecurity audit due: revenue under $50M
DESCRIPTION:First cybersecurity audit report (covering 2029) due for covere
 d businesses with 2028 annual gross revenue under $50M (11 CCR 7121(a)(3))
 \; annual by April 1 thereafter.\n\nCalifornia Consumer Privacy Act of 201
 8\, as amended by the California Privacy Rights Act of 2020 (Cal. Civ. Cod
 e 1798.100 et seq.) and CPPA regulations (Cal. Code Regs. tit. 11\, 7000 e
 t seq.) (California)\n\nSource: https://cppa.ca.gov/regulations/pdf/ccpa_u
 pdates_cyber_risk_admt_appr_text.pdf\n\nhttps://rulebook.fru.dev/regulatio
 ns/us-ca-ccpa
URL:https://rulebook.fru.dev/regulations/us-ca-ccpa
CATEGORIES:California,privacy,ai,cybersecurity,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-46@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20300802
DTEND;VALUE=DATE:20300803
SUMMARY:EU AI Act: Public-authority high-risk systems must comply
DESCRIPTION:Providers and deployers of high-risk AI systems intended for us
 e by public authorities that were placed on the market before the Chapter 
 III application date must comply (Art 111(2)\, as replaced by the Omnibus)
 .\n\nRegulation (EU) 2024/1689 laying down harmonised rules on artificial 
 intelligence (Artificial Intelligence Act)\, as amended by Regulation (EU)
  2026/1744 (Digital Omnibus on AI) (European Union)\n\nSource: https://eur
 -lex.europa.eu/eli/reg/2026/1744/oj\n\nhttps://rulebook.fru.dev/regulation
 s/eu-ai-act
URL:https://rulebook.fru.dev/regulations/eu-ai-act
CATEGORIES:European Union,ai,biometrics,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-47@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20301231
DTEND;VALUE=DATE:20310101
SUMMARY:EU AI Act: Large-scale EU IT systems must comply
DESCRIPTION:AI systems that are components of the large-scale IT systems in
  Annex X (e.g. SIS\, VIS\, Eurodac\, EES\, ETIAS) placed on the market bef
 ore 2 Aug 2027 must be brought into compliance (Art 111(1)).\n\nRegulation
  (EU) 2024/1689 laying down harmonised rules on artificial intelligence (A
 rtificial Intelligence Act)\, as amended by Regulation (EU) 2026/1744 (Dig
 ital Omnibus on AI) (European Union)\n\nSource: https://eur-lex.europa.eu/
 eli/reg/2024/1689/oj\n\nhttps://rulebook.fru.dev/regulations/eu-ai-act
URL:https://rulebook.fru.dev/regulations/eu-ai-act
CATEGORIES:European Union,ai,biometrics,children
TRANSP:TRANSPARENT
END:VEVENT
END:VCALENDAR
