BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//fru.dev//Rulebook//EN
CALSCALE:GREGORIAN
METHOD:PUBLISH
X-WR-CALNAME:Regulation deadlines (Rulebook)
X-WR-CALDESC:Compliance deadlines tracked at rulebook.fru.dev
REFRESH-INTERVAL;VALUE=DURATION:P1D
X-PUBLISHED-TTL:P1D
BEGIN:VEVENT
UID:deadline-231@regulations.fru.dev
DTSTAMP:20260924T150819Z
DTSTART;VALUE=DATE:20100222
DTEND;VALUE=DATE:20100223
SUMMARY:FTC Health Breach Notification Rule: Full compliance with original 
 Rule
DESCRIPTION:Full compliance with the 2009 Health Breach Notification Rule w
 as required.\n\nFTC Health Breach Notification Rule (16 CFR Part 318)\, as
  amended 2024 (United States (Federal))\n\nSource: https://www.federalregi
 ster.gov/citation/74-FR-42962\n\nhttps://rulebook.fru.dev/regulations/us-f
 tc-hbnr
URL:https://rulebook.fru.dev/regulations/us-ftc-hbnr
CATEGORIES:United States (Federal),health,privacy,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-93@regulations.fru.dev
DTSTAMP:20260924T150819Z
DTSTART;VALUE=DATE:20160524
DTEND;VALUE=DATE:20160525
SUMMARY:GDPR: GDPR enters into force
DESCRIPTION:Regulation entered into force on the twentieth day after public
 ation in OJ L 119 of 4 May 2016 (Art 99(1)).\n\nRegulation (EU) 2016/679 (
 General Data Protection Regulation) (European Union)\n\nSource: https://eu
 r-lex.europa.eu/eli/reg/2016/679/oj\n\nhttps://rulebook.fru.dev/regulation
 s/eu-gdpr
URL:https://rulebook.fru.dev/regulations/eu-gdpr
CATEGORIES:European Union,privacy,breach-notification,data-access,children,
 biometrics,health
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-94@regulations.fru.dev
DTSTAMP:20260924T150819Z
DTSTART;VALUE=DATE:20180525
DTEND;VALUE=DATE:20180526
SUMMARY:GDPR: GDPR applies
DESCRIPTION:All GDPR obligations apply from 25 May 2018 (Art 99(2))\, repla
 cing Directive 95/46/EC.\n\nRegulation (EU) 2016/679 (General Data Protect
 ion Regulation) (European Union)\n\nSource: https://eur-lex.europa.eu/eli/
 reg/2016/679/oj\n\nhttps://rulebook.fru.dev/regulations/eu-gdpr
URL:https://rulebook.fru.dev/regulations/eu-gdpr
CATEGORIES:European Union,privacy,breach-notification,data-access,children,
 biometrics,health
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-317@regulations.fru.dev
DTSTAMP:20260924T150819Z
DTSTART;VALUE=DATE:20230427
DTEND;VALUE=DATE:20230428
SUMMARY:Washington My Health My Data Act: HB 1155 signed
DESCRIPTION:Governor signs My Health My Data Act.\n\nWashington My Health M
 y Data Act (HB 1155\, Laws of 2023\, ch. 191\; RCW 19.373) (Washington)\n\
 nSource: https://app.leg.wa.gov/billsummary?BillNumber=1155&Year=2023\n\nh
 ttps://rulebook.fru.dev/regulations/us-wa-mhmda
URL:https://rulebook.fru.dev/regulations/us-wa-mhmda
CATEGORIES:Washington,health,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-215@regulations.fru.dev
DTSTAMP:20260924T150819Z
DTSTART;VALUE=DATE:20230701
DTEND;VALUE=DATE:20230702
SUMMARY:Connecticut Data Privacy Act (CTDPA): CTDPA takes effect
DESCRIPTION:Core consumer rights and controller obligations apply.\n\nConne
 cticut Data Privacy Act (Public Act 22-15)\, Conn. Gen. Stat. 42-515 et se
 q.\, as amended by Public Act 25-113 (SB 1295) and Public Act 26-64 (SB 4)
  (Connecticut)\n\nSource: https://www.cga.ct.gov/asp/cgabillstatus/cgabill
 status.asp?selBillType=Bill&which_year=2022&bill_num=6\n\nhttps://rulebook
 .fru.dev/regulations/us-ct-ctdpa
URL:https://rulebook.fru.dev/regulations/us-ct-ctdpa
CATEGORIES:Connecticut,privacy,children,ai,health
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-318@regulations.fru.dev
DTSTAMP:20260924T150819Z
DTSTART;VALUE=DATE:20230723
DTEND;VALUE=DATE:20230724
SUMMARY:Washington My Health My Data Act: Geofencing ban (Section 10) effec
 tive
DESCRIPTION:Ban on geofencing around health care facilities applies to all 
 persons.\n\nWashington My Health My Data Act (HB 1155\, Laws of 2023\, ch.
  191\; RCW 19.373) (Washington)\n\nSource: https://www.atg.wa.gov/protecti
 ng-washingtonians-personal-health-data-and-privacy\n\nhttps://rulebook.fru
 .dev/regulations/us-wa-mhmda
URL:https://rulebook.fru.dev/regulations/us-wa-mhmda
CATEGORIES:Washington,health,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-319@regulations.fru.dev
DTSTAMP:20260924T150819Z
DTSTART;VALUE=DATE:20240331
DTEND;VALUE=DATE:20240401
SUMMARY:Washington My Health My Data Act: Regulated entities must comply
DESCRIPTION:Sections 4-9 (privacy policy\, consent\, consumer rights\, sale
  authorization) apply to regulated entities.\n\nWashington My Health My Da
 ta Act (HB 1155\, Laws of 2023\, ch. 191\; RCW 19.373) (Washington)\n\nSou
 rce: https://www.atg.wa.gov/protecting-washingtonians-personal-health-data
 -and-privacy\n\nhttps://rulebook.fru.dev/regulations/us-wa-mhmda
URL:https://rulebook.fru.dev/regulations/us-wa-mhmda
CATEGORIES:Washington,health,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-236@regulations.fru.dev
DTSTAMP:20260924T150819Z
DTSTART;VALUE=DATE:20240625
DTEND;VALUE=DATE:20240626
SUMMARY:HIPAA: Reproductive health care privacy rule effective (later vacat
 ed)
DESCRIPTION:The HIPAA Privacy Rule to Support Reproductive Health Care Priv
 acy (89 FR 32976) took effect\; it was vacated nationwide on June 18\, 202
 5 in Purl v. HHS (N.D. Tex.).\n\nHIPAA Privacy\, Security and Breach Notif
 ication Rules (45 CFR Parts 160 and 164) (United States (Federal))\n\nSour
 ce: https://www.federalregister.gov/documents/2024/04/26/2024-08503/hipaa-
 privacy-rule-to-support-reproductive-health-care-privacy\n\nhttps://rulebo
 ok.fru.dev/regulations/us-hipaa
URL:https://rulebook.fru.dev/regulations/us-hipaa
CATEGORIES:United States (Federal),privacy,health,cybersecurity,breach-noti
 fication
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-320@regulations.fru.dev
DTSTAMP:20260924T150819Z
DTSTART;VALUE=DATE:20240630
DTEND;VALUE=DATE:20240701
SUMMARY:Washington My Health My Data Act: Small businesses must comply
DESCRIPTION:Sections 4-9 apply to small businesses.\n\nWashington My Health
  My Data Act (HB 1155\, Laws of 2023\, ch. 191\; RCW 19.373) (Washington)\
 n\nSource: https://www.atg.wa.gov/protecting-washingtonians-personal-healt
 h-data-and-privacy\n\nhttps://rulebook.fru.dev/regulations/us-wa-mhmda
URL:https://rulebook.fru.dev/regulations/us-wa-mhmda
CATEGORIES:Washington,health,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-232@regulations.fru.dev
DTSTAMP:20260924T150819Z
DTSTART;VALUE=DATE:20240729
DTEND;VALUE=DATE:20240730
SUMMARY:FTC Health Breach Notification Rule: 2024 amendments effective
DESCRIPTION:Amendments clarifying health app coverage\, unauthorized disclo
 sure as breach\, email notice and FTC notice timing took effect.\n\nFTC He
 alth Breach Notification Rule (16 CFR Part 318)\, as amended 2024 (United 
 States (Federal))\n\nSource: https://www.federalregister.gov/documents/202
 4/05/30/2024-10855/health-breach-notification-rule\n\nhttps://rulebook.fru
 .dev/regulations/us-ftc-hbnr
URL:https://rulebook.fru.dev/regulations/us-ftc-hbnr
CATEGORIES:United States (Federal),health,privacy,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-237@regulations.fru.dev
DTSTAMP:20260924T150819Z
DTSTART;VALUE=DATE:20241223
DTEND;VALUE=DATE:20241224
SUMMARY:HIPAA: Reproductive health privacy compliance date (vacated)
DESCRIPTION:Original compliance date for the reproductive health care priva
 cy provisions\, including the attestation requirement\; these provisions n
 o longer apply after the June 2025 vacatur.\n\nHIPAA Privacy\, Security an
 d Breach Notification Rules (45 CFR Parts 160 and 164) (United States (Fed
 eral))\n\nSource: https://www.federalregister.gov/documents/2024/04/26/202
 4-08503/hipaa-privacy-rule-to-support-reproductive-health-care-privacy\n\n
 https://rulebook.fru.dev/regulations/us-hipaa
URL:https://rulebook.fru.dev/regulations/us-hipaa
CATEGORIES:United States (Federal),privacy,health,cybersecurity,breach-noti
 fication
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-216@regulations.fru.dev
DTSTAMP:20260924T150819Z
DTSTART;VALUE=DATE:20241231
DTEND;VALUE=DATE:20250101
SUMMARY:Connecticut Data Privacy Act (CTDPA): Mandatory 60-day cure period 
 expires
DESCRIPTION:After Dec 31\, 2024\, the AG is no longer required to offer a 6
 0-day cure before enforcement\; cure becomes discretionary.\n\nConnecticut
  Data Privacy Act (Public Act 22-15)\, Conn. Gen. Stat. 42-515 et seq.\, a
 s amended by Public Act 25-113 (SB 1295) and Public Act 26-64 (SB 4) (Conn
 ecticut)\n\nSource: https://www.cga.ct.gov/asp/cgabillstatus/cgabillstatus
 .asp?selBillType=Bill&which_year=2022&bill_num=6\n\nhttps://rulebook.fru.d
 ev/regulations/us-ct-ctdpa
URL:https://rulebook.fru.dev/regulations/us-ct-ctdpa
CATEGORIES:Connecticut,privacy,children,ai,health
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-217@regulations.fru.dev
DTSTAMP:20260924T150819Z
DTSTART;VALUE=DATE:20250101
DTEND;VALUE=DATE:20250102
SUMMARY:Connecticut Data Privacy Act (CTDPA): Universal opt-out preference 
 signals required
DESCRIPTION:Controllers must honor opt-out preference signals for targeted 
 advertising and sale (effective Jan 1\, 2025).\n\nConnecticut Data Privacy
  Act (Public Act 22-15)\, Conn. Gen. Stat. 42-515 et seq.\, as amended by 
 Public Act 25-113 (SB 1295) and Public Act 26-64 (SB 4) (Connecticut)\n\nS
 ource: https://www.cga.ct.gov/asp/cgabillstatus/cgabillstatus.asp?selBillT
 ype=Bill&which_year=2022&bill_num=6\n\nhttps://rulebook.fru.dev/regulation
 s/us-ct-ctdpa
URL:https://rulebook.fru.dev/regulations/us-ct-ctdpa
CATEGORIES:Connecticut,privacy,children,ai,health
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-238@regulations.fru.dev
DTSTAMP:20260924T150819Z
DTSTART;VALUE=DATE:20250307
DTEND;VALUE=DATE:20250308
SUMMARY:HIPAA: Security Rule NPRM comment period closed
DESCRIPTION:Comments closed on the proposed HIPAA Security Rule update (90 
 FR 898)\; OCR has not issued a final rule.\n\nHIPAA Privacy\, Security and
  Breach Notification Rules (45 CFR Parts 160 and 164) (United States (Fede
 ral))\n\nSource: https://www.federalregister.gov/documents/2025/01/06/2024
 -30983/hipaa-security-rule-to-strengthen-the-cybersecurity-of-electronic-p
 rotected-health-information\n\nhttps://rulebook.fru.dev/regulations/us-hip
 aa
URL:https://rulebook.fru.dev/regulations/us-hipaa
CATEGORIES:United States (Federal),privacy,health,cybersecurity,breach-noti
 fication
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-80@regulations.fru.dev
DTSTAMP:20260924T150819Z
DTSTART;VALUE=DATE:20250325
DTEND;VALUE=DATE:20250326
SUMMARY:European Health Data Space (EHDS): EHDS enters into force
DESCRIPTION:Regulation (EU) 2025/327\, published 5 Mar 2025\, enters into f
 orce on the twentieth day following publication.\n\nRegulation (EU) 2025/3
 27 on the European Health Data Space (European Union)\n\nSource: https://e
 ur-lex.europa.eu/eli/reg/2025/327/oj\n\nhttps://rulebook.fru.dev/regulatio
 ns/eu-ehds
URL:https://rulebook.fru.dev/regulations/eu-ehds
CATEGORIES:European Union,health,privacy,data-access
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-227@regulations.fru.dev
DTSTAMP:20260924T150819Z
DTSTART;VALUE=DATE:20250408
DTEND;VALUE=DATE:20250409
SUMMARY:DOJ Bulk Data Rule: Prohibitions and restrictions take effect
DESCRIPTION:Core prohibitions on covered data transactions and security req
 uirements for restricted transactions apply.\n\nPreventing Access to U.S. 
 Sensitive Personal Data and Government-Related Data by Countries of Concer
 n or Covered Persons (28 CFR Part 202) - DOJ Data Security Program (United
  States (Federal))\n\nSource: https://www.federalregister.gov/documents/20
 25/01/08/2024-31486/preventing-access-to-us-sensitive-personal-data-and-go
 vernment-related-data-by-countries-of-concern\n\nhttps://rulebook.fru.dev/
 regulations/us-doj-bulk-data
URL:https://rulebook.fru.dev/regulations/us-doj-bulk-data
CATEGORIES:United States (Federal),privacy,data-residency,cybersecurity,bio
 metrics,health,financial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-252@regulations.fru.dev
DTSTAMP:20260924T150819Z
DTSTART;VALUE=DATE:20251001
DTEND;VALUE=DATE:20251002
SUMMARY:Maryland Online Data Privacy Act (MODPA): MODPA takes effect
DESCRIPTION:Act takes effect\; data protection assessments apply to process
 ing activities on or after Oct 1\, 2025.\n\nMaryland Online Data Privacy A
 ct of 2024 (SB 541 / HB 567)\, Md. Code\, Com. Law 14-4601 et seq. (Maryla
 nd)\n\nSource: https://mgaleg.maryland.gov/2024RS/Chapters_noln/CH_455_sb0
 541e.pdf\n\nhttps://rulebook.fru.dev/regulations/us-md-modpa
URL:https://rulebook.fru.dev/regulations/us-md-modpa
CATEGORIES:Maryland,privacy,children,health,biometrics
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-228@regulations.fru.dev
DTSTAMP:20260924T150819Z
DTSTART;VALUE=DATE:20251006
DTEND;VALUE=DATE:20251007
SUMMARY:DOJ Bulk Data Rule: Due diligence\, audit and reporting obligations
  apply
DESCRIPTION:Subpart J (data compliance program\, due diligence and audits f
 or restricted transactions) and reporting requirements in 202.1103 and 202
 .1104 apply.\n\nPreventing Access to U.S. Sensitive Personal Data and Gove
 rnment-Related Data by Countries of Concern or Covered Persons (28 CFR Par
 t 202) - DOJ Data Security Program (United States (Federal))\n\nSource: ht
 tps://www.federalregister.gov/documents/2025/01/08/2024-31486/preventing-a
 ccess-to-us-sensitive-personal-data-and-government-related-data-by-countri
 es-of-concern\n\nhttps://rulebook.fru.dev/regulations/us-doj-bulk-data
URL:https://rulebook.fru.dev/regulations/us-doj-bulk-data
CATEGORIES:United States (Federal),privacy,data-residency,cybersecurity,bio
 metrics,health,financial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-95@regulations.fru.dev
DTSTAMP:20260924T150819Z
DTSTART;VALUE=DATE:20251126
DTEND;VALUE=DATE:20251127
SUMMARY:GDPR: GDPR Procedural Regulation adopted
DESCRIPTION:Regulation (EU) 2025/2518 laying down additional procedural rul
 es for cross-border GDPR enforcement signed by Parliament and Council.\n\n
 Regulation (EU) 2016/679 (General Data Protection Regulation) (European Un
 ion)\n\nSource: https://eur-lex.europa.eu/eli/reg/2025/2518/oj\n\nhttps://
 rulebook.fru.dev/regulations/eu-gdpr
URL:https://rulebook.fru.dev/regulations/eu-gdpr
CATEGORIES:European Union,privacy,breach-notification,data-access,children,
 biometrics,health
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-96@regulations.fru.dev
DTSTAMP:20260924T150819Z
DTSTART;VALUE=DATE:20260101
DTEND;VALUE=DATE:20260102
SUMMARY:GDPR: GDPR Procedural Regulation enters into force
DESCRIPTION:Regulation (EU) 2025/2518\, published in the OJ on 12 December 
 2025\, enters into force on the twentieth day after publication.\n\nRegula
 tion (EU) 2016/679 (General Data Protection Regulation) (European Union)\n
 \nSource: https://eur-lex.europa.eu/eli/reg/2025/2518/oj\n\nhttps://rulebo
 ok.fru.dev/regulations/eu-gdpr
URL:https://rulebook.fru.dev/regulations/eu-gdpr
CATEGORIES:European Union,privacy,breach-notification,data-access,children,
 biometrics,health
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-239@regulations.fru.dev
DTSTAMP:20260924T150819Z
DTSTART;VALUE=DATE:20260216
DTEND;VALUE=DATE:20260217
SUMMARY:HIPAA: Notice of Privacy Practices updates (Part 2 alignment)
DESCRIPTION:Covered entities must update Notices of Privacy Practices under
  45 CFR 164.520 for the 2024 Part 2 (substance use disorder records) chang
 es\; this NPP piece survived the Purl vacatur.\n\nHIPAA Privacy\, Security
  and Breach Notification Rules (45 CFR Parts 160 and 164) (United States (
 Federal))\n\nSource: https://www.federalregister.gov/documents/2024/04/26/
 2024-08503/hipaa-privacy-rule-to-support-reproductive-health-care-privacy\
 n\nhttps://rulebook.fru.dev/regulations/us-hipaa
URL:https://rulebook.fru.dev/regulations/us-hipaa
CATEGORIES:United States (Federal),privacy,health,cybersecurity,breach-noti
 fication
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-253@regulations.fru.dev
DTSTAMP:20260924T150819Z
DTSTART;VALUE=DATE:20260401
DTEND;VALUE=DATE:20260402
SUMMARY:Maryland Online Data Privacy Act (MODPA): MODPA applies to personal
  data processing
DESCRIPTION:The act applies to personal data processing activities from Apr
 il 1\, 2026 (Section 2 of ch. 455).\n\nMaryland Online Data Privacy Act of
  2024 (SB 541 / HB 567)\, Md. Code\, Com. Law 14-4601 et seq. (Maryland)\n
 \nSource: https://mgaleg.maryland.gov/2024RS/Chapters_noln/CH_455_sb0541e.
 pdf\n\nhttps://rulebook.fru.dev/regulations/us-md-modpa
URL:https://rulebook.fru.dev/regulations/us-md-modpa
CATEGORIES:Maryland,privacy,children,health,biometrics
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-218@regulations.fru.dev
DTSTAMP:20260924T150819Z
DTSTART;VALUE=DATE:20260701
DTEND;VALUE=DATE:20260702
SUMMARY:Connecticut Data Privacy Act (CTDPA): PA 25-113 (SB 1295) amendment
 s take effect
DESCRIPTION:Thresholds drop to 35\,000 consumers or any sensitive-data proc
 essing or data sale\; expanded sensitive data\, minors' protections\, and 
 LLM-training disclosure in privacy notices.\n\nConnecticut Data Privacy Ac
 t (Public Act 22-15)\, Conn. Gen. Stat. 42-515 et seq.\, as amended by Pub
 lic Act 25-113 (SB 1295) and Public Act 26-64 (SB 4) (Connecticut)\n\nSour
 ce: https://www.cga.ct.gov/2025/ACT/PA/PDF/2025PA-00113-R00SB-01295-PA.PDF
 \n\nhttps://rulebook.fru.dev/regulations/us-ct-ctdpa
URL:https://rulebook.fru.dev/regulations/us-ct-ctdpa
CATEGORIES:Connecticut,privacy,children,ai,health
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-219@regulations.fru.dev
DTSTAMP:20260924T150819Z
DTSTART;VALUE=DATE:20260801
DTEND;VALUE=DATE:20260802
SUMMARY:Connecticut Data Privacy Act (CTDPA): Profiling impact assessments 
 apply
DESCRIPTION:Impact assessment requirements apply to profiling activities cr
 eated or generated on or after Aug 1\, 2026 (Conn. Gen. Stat. 42-522 as am
 ended).\n\nConnecticut Data Privacy Act (Public Act 22-15)\, Conn. Gen. St
 at. 42-515 et seq.\, as amended by Public Act 25-113 (SB 1295) and Public 
 Act 26-64 (SB 4) (Connecticut)\n\nSource: https://www.cga.ct.gov/2025/ACT/
 PA/PDF/2025PA-00113-R00SB-01295-PA.PDF\n\nhttps://rulebook.fru.dev/regulat
 ions/us-ct-ctdpa
URL:https://rulebook.fru.dev/regulations/us-ct-ctdpa
CATEGORIES:Connecticut,privacy,children,ai,health
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-220@regulations.fru.dev
DTSTAMP:20260924T150819Z
DTSTART;VALUE=DATE:20261001
DTEND;VALUE=DATE:20261002
SUMMARY:Connecticut Data Privacy Act (CTDPA): PA 26-64 (SB 4) amendments ta
 ke effect
DESCRIPTION:Prohibits controllers and third parties from selling precise ge
 olocation data and enacts data broker and other consumer protection provis
 ions.\n\nConnecticut Data Privacy Act (Public Act 22-15)\, Conn. Gen. Stat
 . 42-515 et seq.\, as amended by Public Act 25-113 (SB 1295) and Public Ac
 t 26-64 (SB 4) (Connecticut)\n\nSource: https://www.cga.ct.gov/2026/ACT/PA
 /PDF/2026PA-00064-R00SB-00004-PA.PDF\n\nhttps://rulebook.fru.dev/regulatio
 ns/us-ct-ctdpa
URL:https://rulebook.fru.dev/regulations/us-ct-ctdpa
CATEGORIES:Connecticut,privacy,children,ai,health
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-221@regulations.fru.dev
DTSTAMP:20260924T150819Z
DTSTART;VALUE=DATE:20270101
DTEND;VALUE=DATE:20270102
SUMMARY:Connecticut Data Privacy Act (CTDPA): Data broker registration requ
 ired
DESCRIPTION:Data brokers may not sell or license brokered personal data in 
 Connecticut unless registered with the Department of Consumer Protection (
 $2\,500 initial fee).\n\nConnecticut Data Privacy Act (Public Act 22-15)\,
  Conn. Gen. Stat. 42-515 et seq.\, as amended by Public Act 25-113 (SB 129
 5) and Public Act 26-64 (SB 4) (Connecticut)\n\nSource: https://www.cga.ct
 .gov/2026/ACT/PA/PDF/2026PA-00064-R00SB-00004-PA.PDF\n\nhttps://rulebook.f
 ru.dev/regulations/us-ct-ctdpa
URL:https://rulebook.fru.dev/regulations/us-ct-ctdpa
CATEGORIES:Connecticut,privacy,children,ai,health
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-81@regulations.fru.dev
DTSTAMP:20260924T150819Z
DTSTART;VALUE=DATE:20270326
DTEND;VALUE=DATE:20270327
SUMMARY:European Health Data Space (EHDS): EHDS general application date
DESCRIPTION:The regulation applies generally from 26 Mar 2027\, subject to 
 the phased exceptions below (final article).\n\nRegulation (EU) 2025/327 o
 n the European Health Data Space (European Union)\n\nSource: https://eur-l
 ex.europa.eu/eli/reg/2025/327/oj\n\nhttps://rulebook.fru.dev/regulations/e
 u-ehds
URL:https://rulebook.fru.dev/regulations/eu-ehds
CATEGORIES:European Union,health,privacy,data-access
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-254@regulations.fru.dev
DTSTAMP:20260924T150819Z
DTSTART;VALUE=DATE:20270401
DTEND;VALUE=DATE:20270402
SUMMARY:Maryland Online Data Privacy Act (MODPA): Discretionary 60-day cure
  period ends
DESCRIPTION:The Division's discretionary notice-and-cure (at least 60 days)
  applies only to violations occurring on or before April 1\, 2027 (Com. La
 w 14-4614).\n\nMaryland Online Data Privacy Act of 2024 (SB 541 / HB 567)\
 , Md. Code\, Com. Law 14-4601 et seq. (Maryland)\n\nSource: https://mgaleg
 .maryland.gov/2024RS/Chapters_noln/CH_455_sb0541e.pdf\n\nhttps://rulebook.
 fru.dev/regulations/us-md-modpa
URL:https://rulebook.fru.dev/regulations/us-md-modpa
CATEGORIES:Maryland,privacy,children,health,biometrics
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-97@regulations.fru.dev
DTSTAMP:20260924T150819Z
DTSTART;VALUE=DATE:20270402
DTEND;VALUE=DATE:20270403
SUMMARY:GDPR: GDPR Procedural Regulation applies
DESCRIPTION:Harmonised rules for cross-border complaint admissibility\, rig
 hts to be heard and access to preliminary findings\, and investigation tim
 elines apply to DPAs from 2 April 2027 (Regulation (EU) 2025/2518\, final 
 article).\n\nRegulation (EU) 2016/679 (General Data Protection Regulation)
  (European Union)\n\nSource: https://eur-lex.europa.eu/eli/reg/2025/2518/o
 j\n\nhttps://rulebook.fru.dev/regulations/eu-gdpr
URL:https://rulebook.fru.dev/regulations/eu-gdpr
CATEGORIES:European Union,privacy,breach-notification,data-access,children,
 biometrics,health
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-315@regulations.fru.dev
DTSTAMP:20260924T150819Z
DTSTART;VALUE=DATE:20280101
DTEND;VALUE=DATE:20280102
SUMMARY:Vermont VDPOSA: Vermont Data Privacy and Online Surveillance Act ta
 kes effect
DESCRIPTION:All obligations under Act 145 apply (sec. 4).\n\nVermont Data P
 rivacy and Online Surveillance Act (S.71\, Act 145 of 2026) (Vermont)\n\nS
 ource: https://legislature.vermont.gov/Documents/2026/Docs/ACTS/ACT145/ACT
 145%20As%20Enacted.pdf\n\nhttps://rulebook.fru.dev/regulations/us-vt-vdpos
 a
URL:https://rulebook.fru.dev/regulations/us-vt-vdposa
CATEGORIES:Vermont,privacy,health,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-222@regulations.fru.dev
DTSTAMP:20260924T150819Z
DTSTART;VALUE=DATE:20281001
DTEND;VALUE=DATE:20281002
SUMMARY:Connecticut Data Privacy Act (CTDPA): Data brokers must process sta
 te deletion mechanism requests
DESCRIPTION:Registered data brokers must access the DCP accessible deletion
  mechanism at least every 45 days and process deletion requests.\n\nConnec
 ticut Data Privacy Act (Public Act 22-15)\, Conn. Gen. Stat. 42-515 et seq
 .\, as amended by Public Act 25-113 (SB 1295) and Public Act 26-64 (SB 4) 
 (Connecticut)\n\nSource: https://www.cga.ct.gov/2026/ACT/PA/PDF/2026PA-000
 64-R00SB-00004-PA.PDF\n\nhttps://rulebook.fru.dev/regulations/us-ct-ctdpa
URL:https://rulebook.fru.dev/regulations/us-ct-ctdpa
CATEGORIES:Connecticut,privacy,children,ai,health
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-82@regulations.fru.dev
DTSTAMP:20260924T150819Z
DTSTART;VALUE=DATE:20290326
DTEND;VALUE=DATE:20290327
SUMMARY:European Health Data Space (EHDS): Primary use for first data categ
 ories\; secondary use framework applies
DESCRIPTION:Patient rights and EHR rules apply to patient summaries\, ePres
 criptions and eDispensations (Art 14(1)(a)-(c)). Chapter IV secondary-use 
 rules (data permits\, Health Data Access Bodies) apply.\n\nRegulation (EU)
  2025/327 on the European Health Data Space (European Union)\n\nSource: ht
 tps://eur-lex.europa.eu/eli/reg/2025/327/oj\n\nhttps://rulebook.fru.dev/re
 gulations/eu-ehds
URL:https://rulebook.fru.dev/regulations/eu-ehds
CATEGORIES:European Union,health,privacy,data-access
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-316@regulations.fru.dev
DTSTAMP:20260924T150819Z
DTSTART;VALUE=DATE:20290630
DTEND;VALUE=DATE:20290701
SUMMARY:Vermont VDPOSA: Mandatory 60-day cure period expires
DESCRIPTION:The AG's duty to issue a cure notice before enforcement ends Ju
 ne 30\, 2029 (Act 145 sec. 3).\n\nVermont Data Privacy and Online Surveill
 ance Act (S.71\, Act 145 of 2026) (Vermont)\n\nSource: https://legislature
 .vermont.gov/Documents/2026/Docs/ACTS/ACT145/ACT145%20As%20Enacted.pdf\n\n
 https://rulebook.fru.dev/regulations/us-vt-vdposa
URL:https://rulebook.fru.dev/regulations/us-vt-vdposa
CATEGORIES:Vermont,privacy,health,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-83@regulations.fru.dev
DTSTAMP:20260924T150819Z
DTSTART;VALUE=DATE:20310326
DTEND;VALUE=DATE:20310327
SUMMARY:European Health Data Space (EHDS): Primary use for second data cate
 gories\; EHR systems in service\; extra secondary-use categories
DESCRIPTION:Primary-use rules extend to medical images\, lab results and di
 scharge reports (Art 14(1)(d)-(f)). Chapter III applies to EHR systems put
  into service under Art 26(2). Additional secondary-use categories in Art 
 51(1)(b)\,(f)\,(g)\,(m)\,(p) apply.\n\nRegulation (EU) 2025/327 on the Eur
 opean Health Data Space (European Union)\n\nSource: https://eur-lex.europa
 .eu/eli/reg/2025/327/oj\n\nhttps://rulebook.fru.dev/regulations/eu-ehds
URL:https://rulebook.fru.dev/regulations/eu-ehds
CATEGORIES:European Union,health,privacy,data-access
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-84@regulations.fru.dev
DTSTAMP:20260924T150819Z
DTSTART;VALUE=DATE:20350326
DTEND;VALUE=DATE:20350327
SUMMARY:European Health Data Space (EHDS): Third-country participation in s
 econdary use
DESCRIPTION:Art 75(5) applies from 26 Mar 2035.\n\nRegulation (EU) 2025/327
  on the European Health Data Space (European Union)\n\nSource: https://eur
 -lex.europa.eu/eli/reg/2025/327/oj\n\nhttps://rulebook.fru.dev/regulations
 /eu-ehds
URL:https://rulebook.fru.dev/regulations/eu-ehds
CATEGORIES:European Union,health,privacy,data-access
TRANSP:TRANSPARENT
END:VEVENT
END:VCALENDAR
