BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//fru.dev//Rulebook//EN
CALSCALE:GREGORIAN
METHOD:PUBLISH
X-WR-CALNAME:Regulation deadlines (Rulebook)
X-WR-CALDESC:Compliance deadlines tracked at rulebook.fru.dev
REFRESH-INTERVAL;VALUE=DURATION:P1D
X-PUBLISHED-TTL:P1D
BEGIN:VEVENT
UID:deadline-31@regulations.fru.dev
DTSTAMP:20260924T142203Z
DTSTART;VALUE=DATE:20170601
DTEND;VALUE=DATE:20170602
SUMMARY:China Cybersecurity Law: Cybersecurity Law takes effect
DESCRIPTION:Original CSL obligations for network operators and CII operator
 s apply.\n\nCybersecurity Law of the People's Republic of China (as amende
 d by the NPC Standing Committee Decision of 28 October 2025) (China)\n\nSo
 urce: https://www.gov.cn/yaowen/liebiao/202510/content_7046194.htm\n\nhttp
 s://rulebook.fru.dev/regulations/cn-csl
URL:https://rulebook.fru.dev/regulations/cn-csl
CATEGORIES:China,cybersecurity,data-residency,ai,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-123@regulations.fru.dev
DTSTAMP:20260924T142203Z
DTSTART;VALUE=DATE:20191125
DTEND;VALUE=DATE:20191126
SUMMARY:Kenya Data Protection Act: Data Protection Act in force
DESCRIPTION:Act commences.\n\nData Protection Act\, 2019 (No. 24 of 2019) (
 Kenya)\n\nSource: https://www.odpc.go.ke/\n\nhttps://rulebook.fru.dev/regu
 lations/ke-dpa
URL:https://rulebook.fru.dev/regulations/ke-dpa
CATEGORIES:Kenya,privacy,breach-notification,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-11@regulations.fru.dev
DTSTAMP:20260924T142203Z
DTSTART;VALUE=DATE:20200918
DTEND;VALUE=DATE:20200919
SUMMARY:Brazil LGPD: LGPD in force
DESCRIPTION:Main LGPD provisions take effect.\n\nLei Geral de Proteção de
  Dados Pessoais (Law No. 13.709/2018) (Brazil)\n\nSource: https://www.plan
 alto.gov.br/ccivil_03/_ato2015-2018/2018/lei/l13709.htm\n\nhttps://ruleboo
 k.fru.dev/regulations/br-lgpd
URL:https://rulebook.fru.dev/regulations/br-lgpd
CATEGORIES:Brazil,privacy,breach-notification,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-12@regulations.fru.dev
DTSTAMP:20260924T142203Z
DTSTART;VALUE=DATE:20210801
DTEND;VALUE=DATE:20210802
SUMMARY:Brazil LGPD: ANPD sanctions enforceable
DESCRIPTION:Administrative sanctions (Arts. 52-54) become applicable per La
 w 14.010/2020.\n\nLei Geral de Proteção de Dados Pessoais (Law No. 13.70
 9/2018) (Brazil)\n\nSource: https://www.planalto.gov.br/ccivil_03/_ato2015
 -2018/2018/lei/l13709.htm\n\nhttps://rulebook.fru.dev/regulations/br-lgpd
URL:https://rulebook.fru.dev/regulations/br-lgpd
CATEGORIES:Brazil,privacy,breach-notification,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-33@regulations.fru.dev
DTSTAMP:20260924T142203Z
DTSTART;VALUE=DATE:20210901
DTEND;VALUE=DATE:20210902
SUMMARY:China Data Security Law: Data Security Law takes effect
DESCRIPTION:Data classification\, important-data protection and data export
  restrictions apply (Art. 55).\n\nData Security Law of the People's Republ
 ic of China (China)\n\nSource: http://www.cac.gov.cn/2021-06/11/c_16249945
 66919140.htm\n\nhttps://rulebook.fru.dev/regulations/cn-dsl
URL:https://rulebook.fru.dev/regulations/cn-dsl
CATEGORIES:China,cybersecurity,data-residency,data-access
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-36@regulations.fru.dev
DTSTAMP:20260924T142203Z
DTSTART;VALUE=DATE:20211101
DTEND;VALUE=DATE:20211102
SUMMARY:China PIPL: PIPL takes effect
DESCRIPTION:All PIPL obligations (legal bases\, consent\, cross-border rule
 s\, data subject rights) apply (Art. 74).\n\nPersonal Information Protecti
 on Law of the People's Republic of China (China)\n\nSource: http://www.cac
 .gov.cn/2021-08/20/c_1631050028355286.htm\n\nhttps://rulebook.fru.dev/regu
 lations/cn-pipl
URL:https://rulebook.fru.dev/regulations/cn-pipl
CATEGORIES:China,privacy,data-residency,biometrics,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-1@regulations.fru.dev
DTSTAMP:20260924T142203Z
DTSTART;VALUE=DATE:20220102
DTEND;VALUE=DATE:20220103
SUMMARY:UAE PDPL: PDPL enters into force
DESCRIPTION:Decree-law takes effect\; compliance obligations tied to Execut
 ive Regulations.\n\nFederal Decree-Law No. 45 of 2021 on the Protection of
  Personal Data (United Arab Emirates)\n\nSource: https://uaelegislation.go
 v.ae/en/legislations/1972\n\nhttps://rulebook.fru.dev/regulations/ae-pdpl
URL:https://rulebook.fru.dev/regulations/ae-pdpl
CATEGORIES:United Arab Emirates,privacy,breach-notification,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-142@regulations.fru.dev
DTSTAMP:20260924T142203Z
DTSTART;VALUE=DATE:20220601
DTEND;VALUE=DATE:20220602
SUMMARY:Thailand PDPA: PDPA main obligations take effect
DESCRIPTION:Core data protection obligations and penalties apply after post
 ponement Royal Decrees.\n\nPersonal Data Protection Act B.E. 2562 (2019) (
 Thailand)\n\nSource: https://www.ratchakitcha.soc.go.th/DATA/PDF/2562/A/06
 9/T_0052.PDF\n\nhttps://rulebook.fru.dev/regulations/th-pdpa
URL:https://rulebook.fru.dev/regulations/th-pdpa
CATEGORIES:Thailand,privacy,breach-notification,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-112@regulations.fru.dev
DTSTAMP:20260924T142203Z
DTSTART;VALUE=DATE:20221017
DTEND;VALUE=DATE:20221018
SUMMARY:Indonesia PDP Law: PDP Law enacted and in force
DESCRIPTION:Law takes effect on enactment\, starting a 2-year transition.\n
 \nLaw No. 27 of 2022 on Personal Data Protection (Undang-Undang Pelindunga
 n Data Pribadi) (Indonesia)\n\nSource: https://peraturan.bpk.go.id/Details
 /229798/uu-no-27-tahun-2022\n\nhttps://rulebook.fru.dev/regulations/id-pdp
URL:https://rulebook.fru.dev/regulations/id-pdp
CATEGORIES:Indonesia,privacy,breach-notification,data-residency,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-132@regulations.fru.dev
DTSTAMP:20260924T142203Z
DTSTART;VALUE=DATE:20230612
DTEND;VALUE=DATE:20230613
SUMMARY:Nigeria NDPA: NDPA signed into law
DESCRIPTION:President signs the Nigeria Data Protection Act\, 2023.\n\nNige
 ria Data Protection Act\, 2023 and NDPA General Application and Implementa
 tion Directive (GAID) 2025 (Nigeria)\n\nSource: https://ndpc.gov.ng/resour
 ces/\n\nhttps://rulebook.fru.dev/regulations/ng-ndpa
URL:https://rulebook.fru.dev/regulations/ng-ndpa
CATEGORIES:Nigeria,privacy,breach-notification,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-108@regulations.fru.dev
DTSTAMP:20260924T142203Z
DTSTART;VALUE=DATE:20230710
DTEND;VALUE=DATE:20230711
SUMMARY:EU-US Data Privacy Framework: DPF adequacy decision adopted and eff
 ective
DESCRIPTION:Commission adopted Implementing Decision (EU) 2023/1795\, effec
 tive on notification to Member States\; EU-US transfers to DPF-certified o
 rganisations may proceed without additional safeguards.\n\nCommission Impl
 ementing Decision (EU) 2023/1795 on the adequate level of protection of pe
 rsonal data under the EU-US Data Privacy Framework (European Union)\n\nSou
 rce: https://eur-lex.europa.eu/eli/dec_impl/2023/1795/oj\n\nhttps://rulebo
 ok.fru.dev/regulations/eu-us-dpf
URL:https://rulebook.fru.dev/regulations/eu-us-dpf
CATEGORIES:European Union,privacy,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-137@regulations.fru.dev
DTSTAMP:20260924T142203Z
DTSTART;VALUE=DATE:20230914
DTEND;VALUE=DATE:20230915
SUMMARY:Saudi PDPL: PDPL in force
DESCRIPTION:PDPL and its implementing regulations take effect.\n\nPersonal 
 Data Protection Law (Royal Decree M/19 of 9/2/1443H\, as amended by Royal 
 Decree M/148 of 5/9/1444H) (Saudi Arabia)\n\nSource: https://sdaia.gov.sa/
 en/SDAIA/about/Documents/Personal%20Data%20English%20V2-23April2023-%20Rev
 iewed-.pdf\n\nhttps://rulebook.fru.dev/regulations/sa-pdpl
URL:https://rulebook.fru.dev/regulations/sa-pdpl
CATEGORIES:Saudi Arabia,privacy,data-residency,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-30@regulations.fru.dev
DTSTAMP:20260924T142203Z
DTSTART;VALUE=DATE:20240322
DTEND;VALUE=DATE:20240323
SUMMARY:China Cross-Border Data Flow Provisions: Cross-border data flow pro
 visions take effect
DESCRIPTION:Exemptions and volume thresholds apply from publication (Art. 1
 4)\; security assessment results are valid for 3 years (Art. 9).\n\nProvis
 ions on Promoting and Regulating Cross-Border Data Flows (CAC Order No. 16
 ) (China)\n\nSource: https://www.cac.gov.cn/2024-03/22/c_1712776611775634.
 htm\n\nhttps://rulebook.fru.dev/regulations/cn-cross-border
URL:https://rulebook.fru.dev/regulations/cn-cross-border
CATEGORIES:China,data-residency,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-143@regulations.fru.dev
DTSTAMP:20260924T142203Z
DTSTART;VALUE=DATE:20240601
DTEND;VALUE=DATE:20240602
SUMMARY:Turkey KVKK: Law 7499 amendments take effect
DESCRIPTION:New sensitive data and cross-border transfer rules (Arts. 6 and
  9) apply.\n\nLaw No. 6698 on the Protection of Personal Data (KVKK)\, as 
 amended by Law No. 7499 (Turkey)\n\nSource: https://www.resmigazete.gov.tr
 /eskiler/2024/03/20240312-1.htm\n\nhttps://rulebook.fru.dev/regulations/tr
 -kvkk
URL:https://rulebook.fru.dev/regulations/tr-kvkk
CATEGORIES:Turkey,privacy,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-288@regulations.fru.dev
DTSTAMP:20260924T142203Z
DTSTART;VALUE=DATE:20240623
DTEND;VALUE=DATE:20240624
SUMMARY:PADFA: PADFA takes effect
DESCRIPTION:The prohibition takes effect 60 days after enactment (April 24\
 , 2024).\n\nProtecting Americans' Data from Foreign Adversaries Act of 202
 4 (United States (Federal))\n\nSource: https://www.govinfo.gov/content/pkg
 /PLAW-118publ50/html/PLAW-118publ50.htm\n\nhttps://rulebook.fru.dev/regula
 tions/us-padfa
URL:https://rulebook.fru.dev/regulations/us-padfa
CATEGORIES:United States (Federal),privacy,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-13@regulations.fru.dev
DTSTAMP:20260924T142203Z
DTSTART;VALUE=DATE:20240823
DTEND;VALUE=DATE:20240824
SUMMARY:Brazil LGPD: International transfer regulation published
DESCRIPTION:Resolution CD/ANPD 19/2024 on international transfers and stand
 ard contractual clauses published and in force.\n\nLei Geral de Proteção
  de Dados Pessoais (Law No. 13.709/2018) (Brazil)\n\nSource: https://www.i
 n.gov.br/en/web/dou/-/resolucao-cd/anpd-n-19-de-23-de-agosto-de-2024-58009
 5396\n\nhttps://rulebook.fru.dev/regulations/br-lgpd
URL:https://rulebook.fru.dev/regulations/br-lgpd
CATEGORIES:Brazil,privacy,breach-notification,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-144@regulations.fru.dev
DTSTAMP:20260924T142203Z
DTSTART;VALUE=DATE:20240901
DTEND;VALUE=DATE:20240902
SUMMARY:Turkey KVKK: Old transfer regime ends
DESCRIPTION:Transitional period ends in which the former Article 9 explicit
 -consent transfer basis could still be relied on.\n\nLaw No. 6698 on the P
 rotection of Personal Data (KVKK)\, as amended by Law No. 7499 (Turkey)\n\
 nSource: https://www.resmigazete.gov.tr/eskiler/2024/03/20240312-1.htm\n\n
 https://rulebook.fru.dev/regulations/tr-kvkk
URL:https://rulebook.fru.dev/regulations/tr-kvkk
CATEGORIES:Turkey,privacy,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-138@regulations.fru.dev
DTSTAMP:20260924T142203Z
DTSTART;VALUE=DATE:20240914
DTEND;VALUE=DATE:20240915
SUMMARY:Saudi PDPL: One-year grace period ends
DESCRIPTION:Grace period for controllers to comply ends\; PDPL fully enforc
 eable.\n\nPersonal Data Protection Law (Royal Decree M/19 of 9/2/1443H\, a
 s amended by Royal Decree M/148 of 5/9/1444H) (Saudi Arabia)\n\nSource: ht
 tps://sdaia.gov.sa/en/SDAIA/about/Documents/Personal%20Data%20English%20V2
 -23April2023-%20Reviewed-.pdf\n\nhttps://rulebook.fru.dev/regulations/sa-p
 dpl
URL:https://rulebook.fru.dev/regulations/sa-pdpl
CATEGORIES:Saudi Arabia,privacy,data-residency,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-113@regulations.fru.dev
DTSTAMP:20260924T142203Z
DTSTART;VALUE=DATE:20241017
DTEND;VALUE=DATE:20241018
SUMMARY:Indonesia PDP Law: PDP Law transition ends
DESCRIPTION:Controllers and processors must fully comply (Art. 74 two-year 
 transition).\n\nLaw No. 27 of 2022 on Personal Data Protection (Undang-Und
 ang Pelindungan Data Pribadi) (Indonesia)\n\nSource: https://peraturan.bpk
 .go.id/Details/229798/uu-no-27-tahun-2022\n\nhttps://rulebook.fru.dev/regu
 lations/id-pdp
URL:https://rulebook.fru.dev/regulations/id-pdp
CATEGORIES:Indonesia,privacy,breach-notification,data-residency,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-34@regulations.fru.dev
DTSTAMP:20260924T142203Z
DTSTART;VALUE=DATE:20250101
DTEND;VALUE=DATE:20250102
SUMMARY:China Network Data Security Regulations: Network Data Regulations t
 ake effect
DESCRIPTION:All provisions\, including the 10-million-person threshold duti
 es and annual important-data risk assessments\, apply.\n\nRegulations on N
 etwork Data Security Management (State Council Order No. 790) (China)\n\nS
 ource: https://www.gov.cn/zhengce/content/202409/content_6977766.htm\n\nht
 tps://rulebook.fru.dev/regulations/cn-network-data-regs
URL:https://rulebook.fru.dev/regulations/cn-network-data-regs
CATEGORIES:China,privacy,cybersecurity,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-129@regulations.fru.dev
DTSTAMP:20260924T142203Z
DTSTART;VALUE=DATE:20250101
DTEND;VALUE=DATE:20250102
SUMMARY:Malaysia PDPA: PDPA amendments phase 1
DESCRIPTION:Miscellaneous provisions commence (e.g. electronic service of n
 otices).\n\nPersonal Data Protection Act 2010 (Act 709)\, as amended by th
 e Personal Data Protection (Amendment) Act 2024 (Act A1727) (Malaysia)\n\n
 Source: https://www.pdp.gov.my/ppdpv1/en/personal-data-protection-amendmen
 t-act-2024-commencement-date-determination/\n\nhttps://rulebook.fru.dev/re
 gulations/my-pdpa
URL:https://rulebook.fru.dev/regulations/my-pdpa
CATEGORIES:Malaysia,privacy,breach-notification,biometrics,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-130@regulations.fru.dev
DTSTAMP:20260924T142203Z
DTSTART;VALUE=DATE:20250401
DTEND;VALUE=DATE:20250402
SUMMARY:Malaysia PDPA: PDPA amendments phase 2
DESCRIPTION:'Data controller' terminology\, biometric data as sensitive dat
 a\, higher penalties\, Security Principle for processors\, and removal of 
 the cross-border whitelist take effect.\n\nPersonal Data Protection Act 20
 10 (Act 709)\, as amended by the Personal Data Protection (Amendment) Act 
 2024 (Act A1727) (Malaysia)\n\nSource: https://www.pdp.gov.my/ppdpv1/en/pe
 rsonal-data-protection-amendment-act-2024-commencement-date-determination/
 \n\nhttps://rulebook.fru.dev/regulations/my-pdpa
URL:https://rulebook.fru.dev/regulations/my-pdpa
CATEGORIES:Malaysia,privacy,breach-notification,biometrics,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-227@regulations.fru.dev
DTSTAMP:20260924T142203Z
DTSTART;VALUE=DATE:20250408
DTEND;VALUE=DATE:20250409
SUMMARY:DOJ Bulk Data Rule: Prohibitions and restrictions take effect
DESCRIPTION:Core prohibitions on covered data transactions and security req
 uirements for restricted transactions apply.\n\nPreventing Access to U.S. 
 Sensitive Personal Data and Government-Related Data by Countries of Concer
 n or Covered Persons (28 CFR Part 202) - DOJ Data Security Program (United
  States (Federal))\n\nSource: https://www.federalregister.gov/documents/20
 25/01/08/2024-31486/preventing-access-to-us-sensitive-personal-data-and-go
 vernment-related-data-by-countries-of-concern\n\nhttps://rulebook.fru.dev/
 regulations/us-doj-bulk-data
URL:https://rulebook.fru.dev/regulations/us-doj-bulk-data
CATEGORIES:United States (Federal),privacy,data-residency,cybersecurity,bio
 metrics,health,financial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-131@regulations.fru.dev
DTSTAMP:20260924T142203Z
DTSTART;VALUE=DATE:20250601
DTEND;VALUE=DATE:20250602
SUMMARY:Malaysia PDPA: PDPA amendments phase 3
DESCRIPTION:Mandatory DPO appointment\, data breach notification\, and data
  portability take effect.\n\nPersonal Data Protection Act 2010 (Act 709)\,
  as amended by the Personal Data Protection (Amendment) Act 2024 (Act A172
 7) (Malaysia)\n\nSource: https://www.pdp.gov.my/ppdpv1/en/personal-data-pr
 otection-amendment-act-2024-commencement-date-determination/\n\nhttps://ru
 lebook.fru.dev/regulations/my-pdpa
URL:https://rulebook.fru.dev/regulations/my-pdpa
CATEGORIES:Malaysia,privacy,breach-notification,biometrics,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-14@regulations.fru.dev
DTSTAMP:20260924T142203Z
DTSTART;VALUE=DATE:20250823
DTEND;VALUE=DATE:20250824
SUMMARY:Brazil LGPD: Deadline to adopt ANPD standard contractual clauses
DESCRIPTION:Agents relying on contractual clauses for international transfe
 rs must incorporate the ANPD-approved SCCs into their contracts within 12 
 months of publication.\n\nLei Geral de Proteção de Dados Pessoais (Law N
 o. 13.709/2018) (Brazil)\n\nSource: https://www.in.gov.br/en/web/dou/-/res
 olucao-cd/anpd-n-19-de-23-de-agosto-de-2024-580095396\n\nhttps://rulebook.
 fru.dev/regulations/br-lgpd
URL:https://rulebook.fru.dev/regulations/br-lgpd
CATEGORIES:Brazil,privacy,breach-notification,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-109@regulations.fru.dev
DTSTAMP:20260924T142203Z
DTSTART;VALUE=DATE:20250903
DTEND;VALUE=DATE:20250904
SUMMARY:EU-US Data Privacy Framework: General Court upholds DPF (Latombe v 
 Commission)
DESCRIPTION:General Court dismissed Philippe Latombe's action for annulment
  (Case T-553/23) and confirmed the US offered adequate protection when the
  decision was adopted.\n\nCommission Implementing Decision (EU) 2023/1795 
 on the adequate level of protection of personal data under the EU-US Data 
 Privacy Framework (European Union)\n\nSource: https://curia.europa.eu/jcms
 /upload/docs/application/pdf/2025-09/cp250106en.pdf\n\nhttps://rulebook.fr
 u.dev/regulations/eu-us-dpf
URL:https://rulebook.fru.dev/regulations/eu-us-dpf
CATEGORIES:European Union,privacy,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-133@regulations.fru.dev
DTSTAMP:20260924T142203Z
DTSTART;VALUE=DATE:20250919
DTEND;VALUE=DATE:20250920
SUMMARY:Nigeria NDPA: GAID 2025 takes effect
DESCRIPTION:General Application and Implementation Directive becomes effect
 ive\, replacing the NDPR 2019 and NDPR Implementation Framework.\n\nNigeri
 a Data Protection Act\, 2023 and NDPA General Application and Implementati
 on Directive (GAID) 2025 (Nigeria)\n\nSource: https://ndpc.gov.ng/resource
 s/\n\nhttps://rulebook.fru.dev/regulations/ng-ndpa
URL:https://rulebook.fru.dev/regulations/ng-ndpa
CATEGORIES:Nigeria,privacy,breach-notification,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-228@regulations.fru.dev
DTSTAMP:20260924T142203Z
DTSTART;VALUE=DATE:20251006
DTEND;VALUE=DATE:20251007
SUMMARY:DOJ Bulk Data Rule: Due diligence\, audit and reporting obligations
  apply
DESCRIPTION:Subpart J (data compliance program\, due diligence and audits f
 or restricted transactions) and reporting requirements in 202.1103 and 202
 .1104 apply.\n\nPreventing Access to U.S. Sensitive Personal Data and Gove
 rnment-Related Data by Countries of Concern or Covered Persons (28 CFR Par
 t 202) - DOJ Data Security Program (United States (Federal))\n\nSource: ht
 tps://www.federalregister.gov/documents/2025/01/08/2024-31486/preventing-a
 ccess-to-us-sensitive-personal-data-and-government-related-data-by-countri
 es-of-concern\n\nhttps://rulebook.fru.dev/regulations/us-doj-bulk-data
URL:https://rulebook.fru.dev/regulations/us-doj-bulk-data
CATEGORIES:United States (Federal),privacy,data-residency,cybersecurity,bio
 metrics,health,financial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-110@regulations.fru.dev
DTSTAMP:20260924T142203Z
DTSTART;VALUE=DATE:20251031
DTEND;VALUE=DATE:20251101
SUMMARY:EU-US Data Privacy Framework: Latombe appeal lodged at the Court of
  Justice
DESCRIPTION:Latombe appealed the General Court judgment to the Court of Jus
 tice on points of law (reported as Case C-703/25 P)\; the DPF stays valid 
 while it is pending.\n\nCommission Implementing Decision (EU) 2023/1795 on
  the adequate level of protection of personal data under the EU-US Data Pr
 ivacy Framework (European Union)\n\nSource: https://www.wilmerhale.com/en/
 insights/blogs/wilmerhale-privacy-and-cybersecurity-law/20251201-european-
 court-of-justice-to-review-challenge-to-eu-us-data-privacy-framework\n\nht
 tps://rulebook.fru.dev/regulations/eu-us-dpf
URL:https://rulebook.fru.dev/regulations/eu-us-dpf
CATEGORIES:European Union,privacy,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-32@regulations.fru.dev
DTSTAMP:20260924T142203Z
DTSTART;VALUE=DATE:20260101
DTEND;VALUE=DATE:20260102
SUMMARY:China Cybersecurity Law: 2025 amendments take effect
DESCRIPTION:Higher fines\, first-violation fines\, AI governance provisions
  and PIPL-alignment duties apply under the 28 Oct 2025 NPCSC Decision.\n\n
 Cybersecurity Law of the People's Republic of China (as amended by the NPC
  Standing Committee Decision of 28 October 2025) (China)\n\nSource: https:
 //www.gov.cn/yaowen/liebiao/202510/content_7046194.htm\n\nhttps://rulebook
 .fru.dev/regulations/cn-csl
URL:https://rulebook.fru.dev/regulations/cn-csl
CATEGORIES:China,cybersecurity,data-residency,ai,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-324@regulations.fru.dev
DTSTAMP:20260924T142203Z
DTSTART;VALUE=DATE:20260101
DTEND;VALUE=DATE:20260102
SUMMARY:Vietnam PDPL: PDPL and Decree 356/2025 take effect
DESCRIPTION:Personal data protection obligations\, DPIA/TIA filing and pena
 lty framework apply\; Decree 13/2023 replaced.\n\nLaw on Personal Data Pro
 tection (Law No. 91/2025/QH15) (Vietnam)\n\nSource: https://vanban.chinhph
 u.vn/?pageid=27160&docid=214590\n\nhttps://rulebook.fru.dev/regulations/vn
 -pdpl
URL:https://rulebook.fru.dev/regulations/vn-pdpl
CATEGORIES:Vietnam,privacy,data-residency,children,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-125@regulations.fru.dev
DTSTAMP:20260924T142203Z
DTSTART;VALUE=DATE:20260310
DTEND;VALUE=DATE:20260311
SUMMARY:South Korea PIPA: 2026 PIPA amendment promulgated (Act No. 21445)
DESCRIPTION:Amendment raising fines to 10% of revenue and adding CEO accoun
 tability promulgated.\n\nPersonal Information Protection Act (as amended b
 y Act No. 21445\, 2026) (South Korea)\n\nSource: https://www.law.go.kr/법
 령/개인정보보호법\n\nhttps://rulebook.fru.dev/regulations/kr-pipa
URL:https://rulebook.fru.dev/regulations/kr-pipa
CATEGORIES:South Korea,privacy,breach-notification,biometrics,data-residenc
 y
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-126@regulations.fru.dev
DTSTAMP:20260924T142203Z
DTSTART;VALUE=DATE:20260911
DTEND;VALUE=DATE:20260912
SUMMARY:South Korea PIPA: 2026 PIPA amendments take effect
DESCRIPTION:10%-of-revenue fines\, CEO accountability\, and notice duties f
 or possible breaches apply.\n\nPersonal Information Protection Act (as ame
 nded by Act No. 21445\, 2026) (South Korea)\n\nSource: https://www.law.go.
 kr/법령/개인정보보호법\n\nhttps://rulebook.fru.dev/regulations/kr
 -pipa
URL:https://rulebook.fru.dev/regulations/kr-pipa
CATEGORIES:South Korea,privacy,breach-notification,biometrics,data-residenc
 y
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-114@regulations.fru.dev
DTSTAMP:20260924T142203Z
DTSTART;VALUE=DATE:20270116
DTEND;VALUE=DATE:20270117
SUMMARY:Indonesia PDP Law: Implementing regulation GR 33/2026 takes effect
DESCRIPTION:Detailed PDP implementing rules (DPIA\, cross-border\, children
 's consent) apply\, 6 months after the 16 Jul 2026 enactment.\n\nLaw No. 2
 7 of 2022 on Personal Data Protection (Undang-Undang Pelindungan Data Prib
 adi) (Indonesia)\n\nSource: https://www.kk-advocates.com/news/read/indones
 ia-gr-pdp-personal-data-protection-compliance-regime-new-phase\n\nhttps://
 rulebook.fru.dev/regulations/id-pdp
URL:https://rulebook.fru.dev/regulations/id-pdp
CATEGORIES:Indonesia,privacy,breach-notification,data-residency,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-127@regulations.fru.dev
DTSTAMP:20260924T142203Z
DTSTART;VALUE=DATE:20270701
DTEND;VALUE=DATE:20270702
SUMMARY:South Korea PIPA: Mandatory ISMS-P certification
DESCRIPTION:ISMS-P certification becomes mandatory for private entities mee
 ting the statutory criteria.\n\nPersonal Information Protection Act (as am
 ended by Act No. 21445\, 2026) (South Korea)\n\nSource: https://www.law.go
 .kr/법령/개인정보보호법\n\nhttps://rulebook.fru.dev/regulations/k
 r-pipa
URL:https://rulebook.fru.dev/regulations/kr-pipa
CATEGORIES:South Korea,privacy,breach-notification,biometrics,data-residenc
 y
TRANSP:TRANSPARENT
END:VEVENT
END:VCALENDAR
