BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//fru.dev//Rulebook//EN
CALSCALE:GREGORIAN
METHOD:PUBLISH
X-WR-CALNAME:Regulation deadlines (Rulebook)
X-WR-CALDESC:Compliance deadlines tracked at rulebook.fru.dev
REFRESH-INTERVAL;VALUE=DURATION:P1D
X-PUBLISHED-TTL:P1D
BEGIN:VEVENT
UID:deadline-165@regulations.fru.dev
DTSTAMP:20260924T132329Z
DTSTART;VALUE=DATE:20230101
DTEND;VALUE=DATE:20230102
SUMMARY:CCPA / CPRA: CPRA amendments operative
DESCRIPTION:CPRA amendments (correction right\, sensitive PI limits\, shari
 ng opt-out\, employee/B2B data coverage) become operative.\n\nCalifornia C
 onsumer Privacy Act of 2018\, as amended by the California Privacy Rights 
 Act of 2020 (Cal. Civ. Code 1798.100 et seq.) and CPPA regulations (Cal. C
 ode Regs. tit. 11\, 7000 et seq.) (California)\n\nSource: https://cppa.ca.
 gov/regulations/pdf/ccpa_statute_eff_20260101.pdf\n\nhttps://rulebook.fru.
 dev/regulations/us-ca-ccpa
URL:https://rulebook.fru.dev/regulations/us-ca-ccpa
CATEGORIES:California,privacy,ai,cybersecurity,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-311@regulations.fru.dev
DTSTAMP:20260924T132329Z
DTSTART;VALUE=DATE:20230101
DTEND;VALUE=DATE:20230102
SUMMARY:Virginia VCDPA: VCDPA takes effect
DESCRIPTION:VCDPA obligations and consumer rights apply.\n\nVirginia Consum
 er Data Protection Act (SB 1392 / HB 2307\, 2021) (Virginia)\n\nSource: ht
 tps://law.lis.virginia.gov/vacode/title59.1/chapter53/\n\nhttps://rulebook
 .fru.dev/regulations/us-va-vcdpa
URL:https://rulebook.fru.dev/regulations/us-va-vcdpa
CATEGORIES:Virginia,privacy,children,online-safety
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-70@regulations.fru.dev
DTSTAMP:20260924T132329Z
DTSTART;VALUE=DATE:20230116
DTEND;VALUE=DATE:20230117
SUMMARY:DORA: DORA enters into force
DESCRIPTION:Entered into force on the twentieth day after publication in OJ
  L 333 of 27 Dec 2022 (Art 64).\n\nRegulation (EU) 2022/2554 on digital op
 erational resilience for the financial sector (Digital Operational Resilie
 nce Act) (European Union)\n\nSource: https://eur-lex.europa.eu/eli/reg/202
 2/2554/oj\n\nhttps://rulebook.fru.dev/regulations/eu-dora
URL:https://rulebook.fru.dev/regulations/eu-dora
CATEGORIES:European Union,cybersecurity,financial,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-98@regulations.fru.dev
DTSTAMP:20260924T132329Z
DTSTART;VALUE=DATE:20230116
DTEND;VALUE=DATE:20230117
SUMMARY:NIS2: NIS2 enters into force
DESCRIPTION:Directive entered into force on the twentieth day after publica
 tion in OJ L 333 of 27 Dec 2022.\n\nDirective (EU) 2022/2555 on measures f
 or a high common level of cybersecurity across the Union (NIS2 Directive) 
 (European Union)\n\nSource: https://eur-lex.europa.eu/eli/dir/2022/2555/oj
 \n\nhttps://rulebook.fru.dev/regulations/eu-nis2
URL:https://rulebook.fru.dev/regulations/eu-nis2
CATEGORIES:European Union,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-76@regulations.fru.dev
DTSTAMP:20260924T132329Z
DTSTART;VALUE=DATE:20230217
DTEND;VALUE=DATE:20230218
SUMMARY:Digital Services Act: Platforms publish EU user numbers
DESCRIPTION:Online platforms and search engines had to publish average mont
 hly active EU recipients\, and must update them at least every six months 
 (Art 24(2)).\n\nRegulation (EU) 2022/2065 on a Single Market for Digital S
 ervices (Digital Services Act) (European Union)\n\nSource: https://eur-lex
 .europa.eu/eli/reg/2022/2065/oj\n\nhttps://rulebook.fru.dev/regulations/eu
 -dsa
URL:https://rulebook.fru.dev/regulations/eu-dsa
CATEGORIES:European Union,online-safety,children,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-77@regulations.fru.dev
DTSTAMP:20260924T132329Z
DTSTART;VALUE=DATE:20230425
DTEND;VALUE=DATE:20230426
SUMMARY:Digital Services Act: First VLOP/VLOSE designations
DESCRIPTION:Commission designated the first 19 very large online platforms 
 and search engines (e.g. Amazon Store\, Facebook\, Google Search\, TikTok\
 , X). Obligations apply four months after notification.\n\nRegulation (EU)
  2022/2065 on a Single Market for Digital Services (Digital Services Act) 
 (European Union)\n\nSource: https://digital-strategy.ec.europa.eu/en/polic
 ies/list-designated-vlops-and-vloses\n\nhttps://rulebook.fru.dev/regulatio
 ns/eu-dsa
URL:https://rulebook.fru.dev/regulations/eu-dsa
CATEGORIES:European Union,online-safety,children,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-317@regulations.fru.dev
DTSTAMP:20260924T132329Z
DTSTART;VALUE=DATE:20230427
DTEND;VALUE=DATE:20230428
SUMMARY:Washington My Health My Data Act: HB 1155 signed
DESCRIPTION:Governor signs My Health My Data Act.\n\nWashington My Health M
 y Data Act (HB 1155\, Laws of 2023\, ch. 191\; RCW 19.373) (Washington)\n\
 nSource: https://app.leg.wa.gov/billsummary?BillNumber=1155&Year=2023\n\nh
 ttps://rulebook.fru.dev/regulations/us-wa-mhmda
URL:https://rulebook.fru.dev/regulations/us-wa-mhmda
CATEGORIES:Washington,health,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-67@regulations.fru.dev
DTSTAMP:20260924T132329Z
DTSTART;VALUE=DATE:20230502
DTEND;VALUE=DATE:20230503
SUMMARY:Digital Markets Act: DMA applies
DESCRIPTION:DMA becomes applicable\; undertakings meeting thresholds must n
 otify the Commission within two months (Arts 3(3)\, 54).\n\nRegulation (EU
 ) 2022/1925 on contestable and fair markets in the digital sector (Digital
  Markets Act) (European Union)\n\nSource: https://eur-lex.europa.eu/eli/re
 g/2022/1925/oj\n\nhttps://rulebook.fru.dev/regulations/eu-dma
URL:https://rulebook.fru.dev/regulations/eu-dma
CATEGORIES:European Union,data-access,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-234@regulations.fru.dev
DTSTAMP:20260924T132329Z
DTSTART;VALUE=DATE:20230609
DTEND;VALUE=DATE:20230610
SUMMARY:GLBA Safeguards Rule: Compliance with expanded security program ele
 ments
DESCRIPTION:Applicability of the 314.5 provisions (qualified individual\, w
 ritten risk assessment\, encryption\, MFA\, pen testing\, incident respons
 e plan\, board reporting) was delayed from December 9\, 2022 to this date.
 \n\nFTC Standards for Safeguarding Customer Information (Safeguards Rule)\
 , 16 CFR Part 314\, under the Gramm-Leach-Bliley Act (United States (Feder
 al))\n\nSource: https://www.federalregister.gov/documents/2022/11/23/2022-
 25201/standards-for-safeguarding-customer-information\n\nhttps://rulebook.
 fru.dev/regulations/us-glba-safeguards
URL:https://rulebook.fru.dev/regulations/us-glba-safeguards
CATEGORIES:United States (Federal),financial,cybersecurity,breach-notificat
 ion,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-132@regulations.fru.dev
DTSTAMP:20260924T132329Z
DTSTART;VALUE=DATE:20230612
DTEND;VALUE=DATE:20230613
SUMMARY:Nigeria NDPA: NDPA signed into law
DESCRIPTION:President signs the Nigeria Data Protection Act\, 2023.\n\nNige
 ria Data Protection Act\, 2023 and NDPA General Application and Implementa
 tion Directive (GAID) 2025 (Nigeria)\n\nSource: https://ndpc.gov.ng/resour
 ces/\n\nhttps://rulebook.fru.dev/regulations/ng-ndpa
URL:https://rulebook.fru.dev/regulations/ng-ndpa
CATEGORIES:Nigeria,privacy,breach-notification,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-207@regulations.fru.dev
DTSTAMP:20260924T132329Z
DTSTART;VALUE=DATE:20230701
DTEND;VALUE=DATE:20230702
SUMMARY:Colorado Privacy Act (CPA): CPA takes effect
DESCRIPTION:Core consumer rights and controller duties apply.\n\nColorado P
 rivacy Act (SB 21-190)\, C.R.S. 6-1-1301 et seq.\, as amended by HB 24-113
 0\, SB 24-041 and SB 25-276 (Colorado)\n\nSource: https://leg.colorado.gov
 /bills/sb21-190\n\nhttps://rulebook.fru.dev/regulations/us-co-cpa
URL:https://rulebook.fru.dev/regulations/us-co-cpa
CATEGORIES:Colorado,privacy,children,biometrics
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-215@regulations.fru.dev
DTSTAMP:20260924T132329Z
DTSTART;VALUE=DATE:20230701
DTEND;VALUE=DATE:20230702
SUMMARY:Connecticut Data Privacy Act (CTDPA): CTDPA takes effect
DESCRIPTION:Core consumer rights and controller obligations apply.\n\nConne
 cticut Data Privacy Act (Public Act 22-15)\, Conn. Gen. Stat. 42-515 et se
 q.\, as amended by Public Act 25-113 (SB 1295) and Public Act 26-64 (SB 4)
  (Connecticut)\n\nSource: https://www.cga.ct.gov/asp/cgabillstatus/cgabill
 status.asp?selBillType=Bill&which_year=2022&bill_num=6\n\nhttps://rulebook
 .fru.dev/regulations/us-ct-ctdpa
URL:https://rulebook.fru.dev/regulations/us-ct-ctdpa
CATEGORIES:Connecticut,privacy,children,ai,health
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-281@regulations.fru.dev
DTSTAMP:20260924T132329Z
DTSTART;VALUE=DATE:20230705
DTEND;VALUE=DATE:20230706
SUMMARY:NYC Local Law 144 (AEDT): DCWP enforcement begins
DESCRIPTION:Bias audit\, results publication and candidate notice requireme
 nts are enforced.\n\nNew York City Local Law 144 of 2021\, Automated Emplo
 yment Decision Tools (NYC Admin. Code 20-870 et seq.) (New York City\, New
  York)\n\nSource: https://www.nyc.gov/site/dca/about/automated-employment-
 decision-tools.page\n\nhttps://rulebook.fru.dev/regulations/us-nyc-ll144
URL:https://rulebook.fru.dev/regulations/us-nyc-ll144
CATEGORIES:New York City\, New York,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-108@regulations.fru.dev
DTSTAMP:20260924T132329Z
DTSTART;VALUE=DATE:20230710
DTEND;VALUE=DATE:20230711
SUMMARY:EU-US Data Privacy Framework: DPF adequacy decision adopted and eff
 ective
DESCRIPTION:Commission adopted Implementing Decision (EU) 2023/1795\, effec
 tive on notification to Member States\; EU-US transfers to DPF-certified o
 rganisations may proceed without additional safeguards.\n\nCommission Impl
 ementing Decision (EU) 2023/1795 on the adequate level of protection of pe
 rsonal data under the EU-US Data Privacy Framework (European Union)\n\nSou
 rce: https://eur-lex.europa.eu/eli/dec_impl/2023/1795/oj\n\nhttps://rulebo
 ok.fru.dev/regulations/eu-us-dpf
URL:https://rulebook.fru.dev/regulations/eu-us-dpf
CATEGORIES:European Union,privacy,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-318@regulations.fru.dev
DTSTAMP:20260924T132329Z
DTSTART;VALUE=DATE:20230723
DTEND;VALUE=DATE:20230724
SUMMARY:Washington My Health My Data Act: Geofencing ban (Section 10) effec
 tive
DESCRIPTION:Ban on geofencing around health care facilities applies to all 
 persons.\n\nWashington My Health My Data Act (HB 1155\, Laws of 2023\, ch.
  191\; RCW 19.373) (Washington)\n\nSource: https://www.atg.wa.gov/protecti
 ng-washingtonians-personal-health-data-and-privacy\n\nhttps://rulebook.fru
 .dev/regulations/us-wa-mhmda
URL:https://rulebook.fru.dev/regulations/us-wa-mhmda
CATEGORIES:Washington,health,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-25@regulations.fru.dev
DTSTAMP:20260924T132329Z
DTSTART;VALUE=DATE:20230901
DTEND;VALUE=DATE:20230902
SUMMARY:Swiss revised FADP (nFADP): Revised FADP enters into force
DESCRIPTION:Revised FADP and Data Protection Ordinance apply with no transi
 tion period.\n\nFederal Act on Data Protection (revised FADP) of 25 Septem
 ber 2020 (Switzerland)\n\nSource: https://www.fedlex.admin.ch/eli/cc/2022/
 491/en\n\nhttps://rulebook.fru.dev/regulations/ch-fadp
URL:https://rulebook.fru.dev/regulations/ch-fadp
CATEGORIES:Switzerland,privacy,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-68@regulations.fru.dev
DTSTAMP:20260924T132329Z
DTSTART;VALUE=DATE:20230906
DTEND;VALUE=DATE:20230907
SUMMARY:Digital Markets Act: First six gatekeepers designated
DESCRIPTION:Commission designated Alphabet\, Amazon\, Apple\, ByteDance\, M
 eta and Microsoft (22 core platform services). They had six months to full
 y comply.\n\nRegulation (EU) 2022/1925 on contestable and fair markets in 
 the digital sector (Digital Markets Act) (European Union)\n\nSource: https
 ://digital-markets-act.ec.europa.eu/gatekeepers_en\n\nhttps://rulebook.fru
 .dev/regulations/eu-dma
URL:https://rulebook.fru.dev/regulations/eu-dma
CATEGORIES:European Union,data-access,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-137@regulations.fru.dev
DTSTAMP:20260924T132329Z
DTSTART;VALUE=DATE:20230914
DTEND;VALUE=DATE:20230915
SUMMARY:Saudi PDPL: PDPL in force
DESCRIPTION:PDPL and its implementing regulations take effect.\n\nPersonal 
 Data Protection Law (Royal Decree M/19 of 9/2/1443H\, as amended by Royal 
 Decree M/148 of 5/9/1444H) (Saudi Arabia)\n\nSource: https://sdaia.gov.sa/
 en/SDAIA/about/Documents/Personal%20Data%20English%20V2-23April2023-%20Rev
 iewed-.pdf\n\nhttps://rulebook.fru.dev/regulations/sa-pdpl
URL:https://rulebook.fru.dev/regulations/sa-pdpl
CATEGORIES:Saudi Arabia,privacy,data-residency,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-23@regulations.fru.dev
DTSTAMP:20260924T132329Z
DTSTART;VALUE=DATE:20230922
DTEND;VALUE=DATE:20230923
SUMMARY:Quebec Law 25: Phase 2: main obligations and penalties
DESCRIPTION:Governance policies\, PIAs\, consent\, transparency\, privacy b
 y default\, ADM notices\, cross-border PIAs and AMP/penal regime apply.\n\
 nAct to modernize legislative provisions as regards the protection of pers
 onal information (Law 25\, formerly Bill 64) (Quebec\, Canada)\n\nSource: 
 https://www.legisquebec.gouv.qc.ca/en/document/cs/P-39.1\n\nhttps://rulebo
 ok.fru.dev/regulations/ca-qc-law25
URL:https://rulebook.fru.dev/regulations/ca-qc-law25
CATEGORIES:Quebec\, Canada,privacy,breach-notification,biometrics
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-64@regulations.fru.dev
DTSTAMP:20260924T132329Z
DTSTART;VALUE=DATE:20230924
DTEND;VALUE=DATE:20230925
SUMMARY:Data Governance Act: DGA applies
DESCRIPTION:All DGA rules apply (Art 38).\n\nRegulation (EU) 2022/868 on Eu
 ropean data governance (Data Governance Act) (European Union)\n\nSource: h
 ttps://eur-lex.europa.eu/eli/reg/2022/868/oj\n\nhttps://rulebook.fru.dev/r
 egulations/eu-dga
URL:https://rulebook.fru.dev/regulations/eu-dga
CATEGORIES:European Union,data-access,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-156@regulations.fru.dev
DTSTAMP:20260924T132329Z
DTSTART;VALUE=DATE:20231026
DTEND;VALUE=DATE:20231027
SUMMARY:UK Online Safety Act: Royal Assent
DESCRIPTION:The Online Safety Act receives Royal Assent.\n\nOnline Safety A
 ct 2023 (United Kingdom)\n\nSource: https://www.legislation.gov.uk/ukpga/2
 023/50/contents\n\nhttps://rulebook.fru.dev/regulations/uk-osa
URL:https://rulebook.fru.dev/regulations/uk-osa
CATEGORIES:United Kingdom,online-safety,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-270@regulations.fru.dev
DTSTAMP:20260924T132329Z
DTSTART;VALUE=DATE:20231101
DTEND;VALUE=DATE:20231102
SUMMARY:NYDFS Cybersecurity Regulation (Part 500): Second Amendment effecti
 ve
DESCRIPTION:Second Amendment takes effect\; 500.19(e)-(h)\, 500.20\, 500.21
 \, 500.22 and 500.24 apply immediately.\n\nNew York DFS Cybersecurity Requ
 irements for Financial Services Companies (23 NYCRR Part 500)\, Second Ame
 ndment (New York)\n\nSource: https://www.dfs.ny.gov/cybersecurity/23-NYCRR
 -Part-500\n\nhttps://rulebook.fru.dev/regulations/us-ny-dfs-500
URL:https://rulebook.fru.dev/regulations/us-ny-dfs-500
CATEGORIES:New York,cybersecurity,breach-notification,financial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-271@regulations.fru.dev
DTSTAMP:20260924T132329Z
DTSTART;VALUE=DATE:20231201
DTEND;VALUE=DATE:20231202
SUMMARY:NYDFS Cybersecurity Regulation (Part 500): Amended notification req
 uirements (500.17)
DESCRIPTION:New 72-hour event notice\, 24-hour extortion payment notice and
  certification changes apply (30 days).\n\nNew York DFS Cybersecurity Requ
 irements for Financial Services Companies (23 NYCRR Part 500)\, Second Ame
 ndment (New York)\n\nSource: https://www.dfs.ny.gov/cybersecurity/23-NYCRR
 -Part-500\n\nhttps://rulebook.fru.dev/regulations/us-ny-dfs-500
URL:https://rulebook.fru.dev/regulations/us-ny-dfs-500
CATEGORIES:New York,cybersecurity,breach-notification,financial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-290@regulations.fru.dev
DTSTAMP:20260924T132329Z
DTSTART;VALUE=DATE:20231215
DTEND;VALUE=DATE:20231216
SUMMARY:SEC Cyber Disclosure Rules: Annual cybersecurity disclosures begin 
 (Item 106 / 16K)
DESCRIPTION:Required in annual reports for fiscal years ending on or after 
 this date.\n\nSEC Cybersecurity Risk Management\, Strategy\, Governance\, 
 and Incident Disclosure (Release No. 33-11216) (United States (Federal))\n
 \nSource: https://www.federalregister.gov/documents/2023/08/04/2023-16194/
 cybersecurity-risk-management-strategy-governance-and-incident-disclosure\
 n\nhttps://rulebook.fru.dev/regulations/us-sec-cyber
URL:https://rulebook.fru.dev/regulations/us-sec-cyber
CATEGORIES:United States (Federal),cybersecurity,breach-notification,financ
 ial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-291@regulations.fru.dev
DTSTAMP:20260924T132329Z
DTSTART;VALUE=DATE:20231218
DTEND;VALUE=DATE:20231219
SUMMARY:SEC Cyber Disclosure Rules: Form 8-K Item 1.05 incident disclosure 
 begins
DESCRIPTION:All registrants other than smaller reporting companies must fil
 e material incident disclosures from this date.\n\nSEC Cybersecurity Risk 
 Management\, Strategy\, Governance\, and Incident Disclosure (Release No. 
 33-11216) (United States (Federal))\n\nSource: https://www.federalregister
 .gov/documents/2023/08/04/2023-16194/cybersecurity-risk-management-strateg
 y-governance-and-incident-disclosure\n\nhttps://rulebook.fru.dev/regulatio
 ns/us-sec-cyber
URL:https://rulebook.fru.dev/regulations/us-sec-cyber
CATEGORIES:United States (Federal),cybersecurity,breach-notification,financ
 ial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-308@regulations.fru.dev
DTSTAMP:20260924T132329Z
DTSTART;VALUE=DATE:20231231
DTEND;VALUE=DATE:20240101
SUMMARY:Utah UCPA: UCPA takes effect
DESCRIPTION:Utah Consumer Privacy Act obligations and consumer rights apply
 .\n\nUtah Consumer Privacy Act (SB 227\, 2022) (Utah)\n\nSource: https://l
 e.utah.gov/xcode/Title13/Chapter61/13-61-S402.html\n\nhttps://rulebook.fru
 .dev/regulations/us-ut-ucpa
URL:https://rulebook.fru.dev/regulations/us-ut-ucpa
CATEGORIES:Utah,privacy
TRANSP:TRANSPARENT
END:VEVENT
END:VCALENDAR
