BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//fru.dev//Rulebook//EN
CALSCALE:GREGORIAN
METHOD:PUBLISH
X-WR-CALNAME:Regulation deadlines (Rulebook)
X-WR-CALDESC:Compliance deadlines tracked at rulebook.fru.dev
REFRESH-INTERVAL;VALUE=DURATION:P1D
X-PUBLISHED-TTL:P1D
BEGIN:VEVENT
UID:deadline-55@regulations.fru.dev
DTSTAMP:20260924T132329Z
DTSTART;VALUE=DATE:20240111
DTEND;VALUE=DATE:20240112
SUMMARY:EU Data Act: Data Act enters into force
DESCRIPTION:Entered into force on the twentieth day after publication in th
 e OJ on 22 Dec 2023 (Art 50).\n\nRegulation (EU) 2023/2854 on harmonised r
 ules on fair access to and use of data (Data Act) (European Union)\n\nSour
 ce: https://eur-lex.europa.eu/eli/reg/2023/2854/oj\n\nhttps://rulebook.fru
 .dev/regulations/eu-data-act
URL:https://rulebook.fru.dev/regulations/eu-data-act
CATEGORIES:European Union,data-access,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-56@regulations.fru.dev
DTSTAMP:20260924T132329Z
DTSTART;VALUE=DATE:20240111
DTEND;VALUE=DATE:20240112
SUMMARY:EU Data Act: Reduced switching charges period begins
DESCRIPTION:From 11 Jan 2024 to 12 Jan 2027\, data processing providers may
  charge only reduced switching fees\, capped at costs directly linked to s
 witching (Art 29(2)-(3)).\n\nRegulation (EU) 2023/2854 on harmonised rules
  on fair access to and use of data (Data Act) (European Union)\n\nSource: 
 https://eur-lex.europa.eu/eli/reg/2023/2854/oj\n\nhttps://rulebook.fru.dev
 /regulations/eu-data-act
URL:https://rulebook.fru.dev/regulations/eu-data-act
CATEGORIES:European Union,data-access,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-78@regulations.fru.dev
DTSTAMP:20260924T132329Z
DTSTART;VALUE=DATE:20240217
DTEND;VALUE=DATE:20240218
SUMMARY:Digital Services Act: DSA applies to all intermediary services
DESCRIPTION:Full application to all providers of intermediary services (Art
  93(2)).\n\nRegulation (EU) 2022/2065 on a Single Market for Digital Servi
 ces (Digital Services Act) (European Union)\n\nSource: https://eur-lex.eur
 opa.eu/eli/reg/2022/2065/oj\n\nhttps://rulebook.fru.dev/regulations/eu-dsa
URL:https://rulebook.fru.dev/regulations/eu-dsa
CATEGORIES:European Union,online-safety,children,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-69@regulations.fru.dev
DTSTAMP:20260924T132329Z
DTSTART;VALUE=DATE:20240307
DTEND;VALUE=DATE:20240308
SUMMARY:Digital Markets Act: Gatekeeper compliance deadline (first designat
 ions)
DESCRIPTION:First-wave gatekeepers had to comply with Arts 5-7 obligations 
 and submit compliance reports six months after the 6 Sep 2023 designation.
 \n\nRegulation (EU) 2022/1925 on contestable and fair markets in the digit
 al sector (Digital Markets Act) (European Union)\n\nSource: https://ec.eur
 opa.eu/commission/presscorner/detail/en/ip_23_4328\n\nhttps://rulebook.fru
 .dev/regulations/eu-dma
URL:https://rulebook.fru.dev/regulations/eu-dma
CATEGORIES:European Union,data-access,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-229@regulations.fru.dev
DTSTAMP:20260924T132329Z
DTSTART;VALUE=DATE:20240313
DTEND;VALUE=DATE:20240314
SUMMARY:FCC CPNI Breach Rule: Order effective except revised notification r
 ules
DESCRIPTION:Definitions and other parts of the order took effect\; the revi
 sed 64.2011 and 64.5111 notification requirements were delayed pending OMB
  approval.\n\nFCC Data Breach Reporting Requirements for telecommunication
 s carriers\, interconnected VoIP and TRS providers (47 CFR 64.2011\, 64.51
 11) (United States (Federal))\n\nSource: https://www.federalregister.gov/d
 ocuments/2024/02/12/2024-01667/data-breach-reporting-requirements\n\nhttps
 ://rulebook.fru.dev/regulations/us-fcc-cpni-breach
URL:https://rulebook.fru.dev/regulations/us-fcc-cpni-breach
CATEGORIES:United States (Federal),privacy,breach-notification,cybersecurit
 y
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-30@regulations.fru.dev
DTSTAMP:20260924T132329Z
DTSTART;VALUE=DATE:20240322
DTEND;VALUE=DATE:20240323
SUMMARY:China Cross-Border Data Flow Provisions: Cross-border data flow pro
 visions take effect
DESCRIPTION:Exemptions and volume thresholds apply from publication (Art. 1
 4)\; security assessment results are valid for 3 years (Art. 9).\n\nProvis
 ions on Promoting and Regulating Cross-Border Data Flows (CAC Order No. 16
 ) (China)\n\nSource: https://www.cac.gov.cn/2024-03/22/c_1712776611775634.
 htm\n\nhttps://rulebook.fru.dev/regulations/cn-cross-border
URL:https://rulebook.fru.dev/regulations/cn-cross-border
CATEGORIES:China,data-residency,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-319@regulations.fru.dev
DTSTAMP:20260924T132329Z
DTSTART;VALUE=DATE:20240331
DTEND;VALUE=DATE:20240401
SUMMARY:Washington My Health My Data Act: Regulated entities must comply
DESCRIPTION:Sections 4-9 (privacy policy\, consent\, consumer rights\, sale
  authorization) apply to regulated entities.\n\nWashington My Health My Da
 ta Act (HB 1155\, Laws of 2023\, ch. 191\; RCW 19.373) (Washington)\n\nSou
 rce: https://www.atg.wa.gov/protecting-washingtonians-personal-health-data
 -and-privacy\n\nhttps://rulebook.fru.dev/regulations/us-wa-mhmda
URL:https://rulebook.fru.dev/regulations/us-wa-mhmda
CATEGORIES:Washington,health,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-272@regulations.fru.dev
DTSTAMP:20260924T132329Z
DTSTART;VALUE=DATE:20240415
DTEND;VALUE=DATE:20240416
SUMMARY:NYDFS Cybersecurity Regulation (Part 500): Annual compliance notifi
 cation
DESCRIPTION:Certification of compliance or acknowledgment of non-compliance
  due (recurs every April 15).\n\nNew York DFS Cybersecurity Requirements f
 or Financial Services Companies (23 NYCRR Part 500)\, Second Amendment (Ne
 w York)\n\nSource: https://www.dfs.ny.gov/cybersecurity/23-NYCRR-Part-500\
 n\nhttps://rulebook.fru.dev/regulations/us-ny-dfs-500
URL:https://rulebook.fru.dev/regulations/us-ny-dfs-500
CATEGORIES:New York,cybersecurity,breach-notification,financial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-273@regulations.fru.dev
DTSTAMP:20260924T132329Z
DTSTART;VALUE=DATE:20240429
DTEND;VALUE=DATE:20240430
SUMMARY:NYDFS Cybersecurity Regulation (Part 500): General 180-day transiti
 on ends
DESCRIPTION:Most new Second Amendment requirements apply\, e.g. annual repo
 rting to the board and risk assessment updates.\n\nNew York DFS Cybersecur
 ity Requirements for Financial Services Companies (23 NYCRR Part 500)\, Se
 cond Amendment (New York)\n\nSource: https://www.dfs.ny.gov/cybersecurity/
 23-NYCRR-Part-500\n\nhttps://rulebook.fru.dev/regulations/us-ny-dfs-500
URL:https://rulebook.fru.dev/regulations/us-ny-dfs-500
CATEGORIES:New York,cybersecurity,breach-notification,financial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-305@regulations.fru.dev
DTSTAMP:20260924T132329Z
DTSTART;VALUE=DATE:20240501
DTEND;VALUE=DATE:20240502
SUMMARY:Utah AI Policy Act: AI Policy Act effective
DESCRIPTION:Generative AI disclosure duties and the Office of AI Policy tak
 e effect.\n\nUtah Artificial Intelligence Policy Act (SB 149\, 2024)\, as 
 amended by SB 226 and SB 332 (2025) (Utah)\n\nSource: https://le.utah.gov/
 ~2024/bills/static/SB0149.html\n\nhttps://rulebook.fru.dev/regulations/us-
 ut-aipa
URL:https://rulebook.fru.dev/regulations/us-ut-aipa
CATEGORIES:Utah,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-235@regulations.fru.dev
DTSTAMP:20260924T132329Z
DTSTART;VALUE=DATE:20240513
DTEND;VALUE=DATE:20240514
SUMMARY:GLBA Safeguards Rule: FTC breach notification requirement effective
DESCRIPTION:Section 314.4(j) requires notice to the FTC within 30 days of d
 iscovering a notification event involving at least 500 consumers.\n\nFTC S
 tandards for Safeguarding Customer Information (Safeguards Rule)\, 16 CFR 
 Part 314\, under the Gramm-Leach-Bliley Act (United States (Federal))\n\nS
 ource: https://www.federalregister.gov/documents/2023/11/13/2023-24412/sta
 ndards-for-safeguarding-customer-information\n\nhttps://rulebook.fru.dev/r
 egulations/us-glba-safeguards
URL:https://rulebook.fru.dev/regulations/us-glba-safeguards
CATEGORIES:United States (Federal),financial,cybersecurity,breach-notificat
 ion,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-199@regulations.fru.dev
DTSTAMP:20260924T132329Z
DTSTART;VALUE=DATE:20240517
DTEND;VALUE=DATE:20240518
SUMMARY:Colorado AI Act: SB 24-205 signed
DESCRIPTION:Governor Polis signs the original Colorado AI Act with a Februa
 ry 1\, 2026 effective date.\n\nColorado SB 24-205 (Consumer Protections fo
 r Artificial Intelligence)\, as delayed by SB 25B-004 and repealed and ree
 nacted by SB 26-189 (Automated Decision-Making Technology) (Colorado)\n\nS
 ource: https://leg.colorado.gov/bills/sb24-205\n\nhttps://rulebook.fru.dev
 /regulations/us-co-ai-act
URL:https://rulebook.fru.dev/regulations/us-co-ai-act
CATEGORIES:Colorado,ai,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-85@regulations.fru.dev
DTSTAMP:20260924T132329Z
DTSTART;VALUE=DATE:20240520
DTEND;VALUE=DATE:20240521
SUMMARY:eIDAS 2 / EU Digital Identity Wallet: eIDAS 2 enters into force
DESCRIPTION:Regulation (EU) 2024/1183 entered into force on the twentieth d
 ay after publication on 30 Apr 2024 (Art 2).\n\nRegulation (EU) 2024/1183 
 amending Regulation (EU) No 910/2014 as regards establishing the European 
 Digital Identity Framework (eIDAS 2) (European Union)\n\nSource: https://e
 ur-lex.europa.eu/eli/reg/2024/1183/oj\n\nhttps://rulebook.fru.dev/regulati
 ons/eu-eidas2
URL:https://rulebook.fru.dev/regulations/eu-eidas2
CATEGORIES:European Union,privacy,data-access,biometrics
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-143@regulations.fru.dev
DTSTAMP:20260924T132329Z
DTSTART;VALUE=DATE:20240601
DTEND;VALUE=DATE:20240602
SUMMARY:Turkey KVKK: Law 7499 amendments take effect
DESCRIPTION:New sensitive data and cross-border transfer rules (Arts. 6 and
  9) apply.\n\nLaw No. 6698 on the Protection of Personal Data (KVKK)\, as 
 amended by Law No. 7499 (Turkey)\n\nSource: https://www.resmigazete.gov.tr
 /eskiler/2024/03/20240312-1.htm\n\nhttps://rulebook.fru.dev/regulations/tr
 -kvkk
URL:https://rulebook.fru.dev/regulations/tr-kvkk
CATEGORIES:Turkey,privacy,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-292@regulations.fru.dev
DTSTAMP:20260924T132329Z
DTSTART;VALUE=DATE:20240615
DTEND;VALUE=DATE:20240616
SUMMARY:SEC Cyber Disclosure Rules: Smaller reporting companies: Item 1.05 
 compliance
DESCRIPTION:Smaller reporting companies must begin complying with Form 8-K 
 Item 1.05 incident disclosure.\n\nSEC Cybersecurity Risk Management\, Stra
 tegy\, Governance\, and Incident Disclosure (Release No. 33-11216) (United
  States (Federal))\n\nSource: https://www.federalregister.gov/documents/20
 23/08/04/2023-16194/cybersecurity-risk-management-strategy-governance-and-
 incident-disclosure\n\nhttps://rulebook.fru.dev/regulations/us-sec-cyber
URL:https://rulebook.fru.dev/regulations/us-sec-cyber
CATEGORIES:United States (Federal),cybersecurity,breach-notification,financ
 ial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-288@regulations.fru.dev
DTSTAMP:20260924T132329Z
DTSTART;VALUE=DATE:20240623
DTEND;VALUE=DATE:20240624
SUMMARY:PADFA: PADFA takes effect
DESCRIPTION:The prohibition takes effect 60 days after enactment (April 24\
 , 2024).\n\nProtecting Americans' Data from Foreign Adversaries Act of 202
 4 (United States (Federal))\n\nSource: https://www.govinfo.gov/content/pkg
 /PLAW-118publ50/html/PLAW-118publ50.htm\n\nhttps://rulebook.fru.dev/regula
 tions/us-padfa
URL:https://rulebook.fru.dev/regulations/us-padfa
CATEGORIES:United States (Federal),privacy,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-236@regulations.fru.dev
DTSTAMP:20260924T132329Z
DTSTART;VALUE=DATE:20240625
DTEND;VALUE=DATE:20240626
SUMMARY:HIPAA: Reproductive health care privacy rule effective (later vacat
 ed)
DESCRIPTION:The HIPAA Privacy Rule to Support Reproductive Health Care Priv
 acy (89 FR 32976) took effect\; it was vacated nationwide on June 18\, 202
 5 in Purl v. HHS (N.D. Tex.).\n\nHIPAA Privacy\, Security and Breach Notif
 ication Rules (45 CFR Parts 160 and 164) (United States (Federal))\n\nSour
 ce: https://www.federalregister.gov/documents/2024/04/26/2024-08503/hipaa-
 privacy-rule-to-support-reproductive-health-care-privacy\n\nhttps://rulebo
 ok.fru.dev/regulations/us-hipaa
URL:https://rulebook.fru.dev/regulations/us-hipaa
CATEGORIES:United States (Federal),privacy,health,cybersecurity,breach-noti
 fication
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-320@regulations.fru.dev
DTSTAMP:20260924T132329Z
DTSTART;VALUE=DATE:20240630
DTEND;VALUE=DATE:20240701
SUMMARY:Washington My Health My Data Act: Small businesses must comply
DESCRIPTION:Sections 4-9 apply to small businesses.\n\nWashington My Health
  My Data Act (HB 1155\, Laws of 2023\, ch. 191\; RCW 19.373) (Washington)\
 n\nSource: https://www.atg.wa.gov/protecting-washingtonians-personal-healt
 h-data-and-privacy\n\nhttps://rulebook.fru.dev/regulations/us-wa-mhmda
URL:https://rulebook.fru.dev/regulations/us-wa-mhmda
CATEGORIES:Washington,health,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-208@regulations.fru.dev
DTSTAMP:20260924T132329Z
DTSTART;VALUE=DATE:20240701
DTEND;VALUE=DATE:20240702
SUMMARY:Colorado Privacy Act (CPA): Universal opt-out mechanism recognition
  required
DESCRIPTION:Controllers must honor AG-recognized universal opt-out mechanis
 ms (e.g. Global Privacy Control).\n\nColorado Privacy Act (SB 21-190)\, C.
 R.S. 6-1-1301 et seq.\, as amended by HB 24-1130\, SB 24-041 and SB 25-276
  (Colorado)\n\nSource: https://leg.colorado.gov/bills/sb21-190\n\nhttps://
 rulebook.fru.dev/regulations/us-co-cpa
URL:https://rulebook.fru.dev/regulations/us-co-cpa
CATEGORIES:Colorado,privacy,children,biometrics
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-230@regulations.fru.dev
DTSTAMP:20260924T132329Z
DTSTART;VALUE=DATE:20240701
DTEND;VALUE=DATE:20240702
SUMMARY:Florida Digital Bill of Rights: Florida Digital Bill of Rights take
 s effect
DESCRIPTION:SB 262 obligations under Fla. Stat. 501.701-501.722 apply.\n\nF
 lorida Digital Bill of Rights (CS/CS/SB 262\, 2023) (Florida)\n\nSource: h
 ttps://www.flsenate.gov/Session/Bill/2023/262\n\nhttps://rulebook.fru.dev/
 regulations/us-fl-fdbr
URL:https://rulebook.fru.dev/regulations/us-fl-fdbr
CATEGORIES:Florida,privacy,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-283@regulations.fru.dev
DTSTAMP:20260924T132329Z
DTSTART;VALUE=DATE:20240701
DTEND;VALUE=DATE:20240702
SUMMARY:Oregon OCPA: OCPA takes effect for most controllers
DESCRIPTION:OCPA obligations apply to for-profit controllers meeting the th
 resholds.\n\nOregon Consumer Privacy Act (SB 619\, 2023) (Oregon)\n\nSourc
 e: https://www.doj.state.or.us/consumer-protection/id-theft-data-breaches/
 privacy/\n\nhttps://rulebook.fru.dev/regulations/us-or-ocpa
URL:https://rulebook.fru.dev/regulations/us-or-ocpa
CATEGORIES:Oregon,privacy,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-301@regulations.fru.dev
DTSTAMP:20260924T132329Z
DTSTART;VALUE=DATE:20240701
DTEND;VALUE=DATE:20240702
SUMMARY:Texas TDPSA: TDPSA takes effect
DESCRIPTION:Most TDPSA obligations and consumer rights apply.\n\nTexas Data
  Privacy and Security Act (HB 4\, 2023) (Texas)\n\nSource: https://capitol
 .texas.gov/BillLookup/History.aspx?LegSess=88R&Bill=HB4\n\nhttps://ruleboo
 k.fru.dev/regulations/us-tx-tdpsa
URL:https://rulebook.fru.dev/regulations/us-tx-tdpsa
CATEGORIES:Texas,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-193@regulations.fru.dev
DTSTAMP:20260924T132329Z
DTSTART;VALUE=DATE:20240703
DTEND;VALUE=DATE:20240704
SUMMARY:CIRCIA: NPRM comment period closed
DESCRIPTION:Extended comment period on the CIRCIA proposed rule closed.\n\n
 Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA) 
 and proposed implementing rule (6 CFR Part 226) (United States (Federal))\
 n\nSource: https://www.federalregister.gov/documents/2024/04/04/2024-06526
 /cyber-incident-reporting-for-critical-infrastructure-act-circia-reporting
 -requirements\n\nhttps://rulebook.fru.dev/regulations/us-circia
URL:https://rulebook.fru.dev/regulations/us-circia
CATEGORIES:United States (Federal),cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-232@regulations.fru.dev
DTSTAMP:20260924T132329Z
DTSTART;VALUE=DATE:20240729
DTEND;VALUE=DATE:20240730
SUMMARY:FTC Health Breach Notification Rule: 2024 amendments effective
DESCRIPTION:Amendments clarifying health app coverage\, unauthorized disclo
 sure as breach\, email notice and FTC notice timing took effect.\n\nFTC He
 alth Breach Notification Rule (16 CFR Part 318)\, as amended 2024 (United 
 States (Federal))\n\nSource: https://www.federalregister.gov/documents/202
 4/05/30/2024-10855/health-breach-notification-rule\n\nhttps://rulebook.fru
 .dev/regulations/us-ftc-hbnr
URL:https://rulebook.fru.dev/regulations/us-ftc-hbnr
CATEGORIES:United States (Federal),health,privacy,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-37@regulations.fru.dev
DTSTAMP:20260924T132329Z
DTSTART;VALUE=DATE:20240801
DTEND;VALUE=DATE:20240802
SUMMARY:EU AI Act: AI Act enters into force
DESCRIPTION:Regulation (EU) 2024/1689 enters into force twenty days after p
 ublication on 12 July 2024 (Art 113).\n\nRegulation (EU) 2024/1689 laying 
 down harmonised rules on artificial intelligence (Artificial Intelligence 
 Act)\, as amended by Regulation (EU) 2026/1744 (Digital Omnibus on AI) (Eu
 ropean Union)\n\nSource: https://eur-lex.europa.eu/eli/reg/2024/1689/oj\n\
 nhttps://rulebook.fru.dev/regulations/eu-ai-act
URL:https://rulebook.fru.dev/regulations/eu-ai-act
CATEGORIES:European Union,ai,biometrics,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-242@regulations.fru.dev
DTSTAMP:20260924T132329Z
DTSTART;VALUE=DATE:20240802
DTEND;VALUE=DATE:20240803
SUMMARY:Illinois BIPA: SB 2979 amendment effective
DESCRIPTION:Public Act 103-0769 signed and effective immediately: single re
 covery per person and electronic signatures allowed for consent.\n\nIllino
 is Biometric Information Privacy Act (740 ILCS 14)\, as amended by SB 2979
  (Public Act 103-0769) (Illinois)\n\nSource: https://www.ilga.gov/Legislat
 ion/publicacts/view/103-0769\n\nhttps://rulebook.fru.dev/regulations/us-il
 -bipa
URL:https://rulebook.fru.dev/regulations/us-il-bipa
CATEGORIES:Illinois,biometrics,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-295@regulations.fru.dev
DTSTAMP:20260924T132329Z
DTSTART;VALUE=DATE:20240802
DTEND;VALUE=DATE:20240803
SUMMARY:SEC Regulation S-P: Amendments effective
DESCRIPTION:The Regulation S-P amendments became effective\; compliance tie
 red by entity size.\n\nRegulation S-P: Privacy of Consumer Financial Infor
 mation and Safeguarding Customer Information (2024 amendments) (United Sta
 tes (Federal))\n\nSource: https://www.federalregister.gov/documents/2024/0
 6/03/2024-11116/regulation-s-p-privacy-of-consumer-financial-information-a
 nd-safeguarding-customer-information\n\nhttps://rulebook.fru.dev/regulatio
 ns/us-sec-reg-sp
URL:https://rulebook.fru.dev/regulations/us-sec-reg-sp
CATEGORIES:United States (Federal),financial,privacy,cybersecurity,breach-n
 otification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-244@regulations.fru.dev
DTSTAMP:20260924T132329Z
DTSTART;VALUE=DATE:20240809
DTEND;VALUE=DATE:20240810
SUMMARY:Illinois AI in Employment Law (HB 3773): HB 3773 signed
DESCRIPTION:Governor Pritzker signs Public Act 103-0804.\n\nIllinois HB 377
 3 (Public Act 103-0804)\, amending the Illinois Human Rights Act on artifi
 cial intelligence in employment (Illinois)\n\nSource: https://www.ilga.gov
 /ftp/legislation/103/BillStatus/HTML/10300HB3773.html\n\nhttps://rulebook.
 fru.dev/regulations/us-il-hb3773
URL:https://rulebook.fru.dev/regulations/us-il-hb3773
CATEGORIES:Illinois,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-13@regulations.fru.dev
DTSTAMP:20260924T132329Z
DTSTART;VALUE=DATE:20240823
DTEND;VALUE=DATE:20240824
SUMMARY:Brazil LGPD: International transfer regulation published
DESCRIPTION:Resolution CD/ANPD 19/2024 on international transfers and stand
 ard contractual clauses published and in force.\n\nLei Geral de Proteção
  de Dados Pessoais (Law No. 13.709/2018) (Brazil)\n\nSource: https://www.i
 n.gov.br/en/web/dou/-/resolucao-cd/anpd-n-19-de-23-de-agosto-de-2024-58009
 5396\n\nhttps://rulebook.fru.dev/regulations/br-lgpd
URL:https://rulebook.fru.dev/regulations/br-lgpd
CATEGORIES:Brazil,privacy,breach-notification,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-144@regulations.fru.dev
DTSTAMP:20260924T132329Z
DTSTART;VALUE=DATE:20240901
DTEND;VALUE=DATE:20240902
SUMMARY:Turkey KVKK: Old transfer regime ends
DESCRIPTION:Transitional period ends in which the former Article 9 explicit
 -consent transfer basis could still be relied on.\n\nLaw No. 6698 on the P
 rotection of Personal Data (KVKK)\, as amended by Law No. 7499 (Turkey)\n\
 nSource: https://www.resmigazete.gov.tr/eskiler/2024/03/20240312-1.htm\n\n
 https://rulebook.fru.dev/regulations/tr-kvkk
URL:https://rulebook.fru.dev/regulations/tr-kvkk
CATEGORIES:Turkey,privacy,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-138@regulations.fru.dev
DTSTAMP:20260924T132329Z
DTSTART;VALUE=DATE:20240914
DTEND;VALUE=DATE:20240915
SUMMARY:Saudi PDPL: One-year grace period ends
DESCRIPTION:Grace period for controllers to comply ends\; PDPL fully enforc
 eable.\n\nPersonal Data Protection Law (Royal Decree M/19 of 9/2/1443H\, a
 s amended by Royal Decree M/148 of 5/9/1444H) (Saudi Arabia)\n\nSource: ht
 tps://sdaia.gov.sa/en/SDAIA/about/Documents/Personal%20Data%20English%20V2
 -23April2023-%20Reviewed-.pdf\n\nhttps://rulebook.fru.dev/regulations/sa-p
 dpl
URL:https://rulebook.fru.dev/regulations/sa-pdpl
CATEGORIES:Saudi Arabia,privacy,data-residency,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-187@regulations.fru.dev
DTSTAMP:20260924T132329Z
DTSTART;VALUE=DATE:20240919
DTEND;VALUE=DATE:20240920
SUMMARY:California AI Transparency Act (SB 942): SB 942 signed
DESCRIPTION:SB 942 chaptered (ch. 291) with an original operative date of J
 anuary 1\, 2026.\n\nCalifornia AI Transparency Act (SB 942\, Stats. 2024\,
  ch. 291)\, as amended by AB 853 (Stats. 2025\, ch. 674) (California)\n\nS
 ource: https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_i
 d=202320240SB942\n\nhttps://rulebook.fru.dev/regulations/us-ca-sb942
URL:https://rulebook.fru.dev/regulations/us-ca-sb942
CATEGORIES:California,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-24@regulations.fru.dev
DTSTAMP:20260924T132329Z
DTSTART;VALUE=DATE:20240922
DTEND;VALUE=DATE:20240923
SUMMARY:Quebec Law 25: Phase 3: data portability
DESCRIPTION:Right to data portability in a structured\, commonly used techn
 ological format applies.\n\nAct to modernize legislative provisions as reg
 ards the protection of personal information (Law 25\, formerly Bill 64) (Q
 uebec\, Canada)\n\nSource: https://www.legisquebec.gouv.qc.ca/en/document/
 cs/P-39.1\n\nhttps://rulebook.fru.dev/regulations/ca-qc-law25
URL:https://rulebook.fru.dev/regulations/ca-qc-law25
CATEGORIES:Quebec\, Canada,privacy,breach-notification,biometrics
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-162@regulations.fru.dev
DTSTAMP:20260924T132329Z
DTSTART;VALUE=DATE:20240928
DTEND;VALUE=DATE:20240929
SUMMARY:California AB 2013 (AI training data transparency): AB 2013 signed
DESCRIPTION:AB 2013 chaptered (ch. 817).\n\nCalifornia AB 2013\, Generative
  Artificial Intelligence: Training Data Transparency (Stats. 2024\, ch. 81
 7) (California)\n\nSource: https://leginfo.legislature.ca.gov/faces/billNa
 vClient.xhtml?bill_id=202320240AB2013\n\nhttps://rulebook.fru.dev/regulati
 ons/us-ca-ab2013
URL:https://rulebook.fru.dev/regulations/us-ca-ab2013
CATEGORIES:California,ai,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-258@regulations.fru.dev
DTSTAMP:20260924T132329Z
DTSTART;VALUE=DATE:20241001
DTEND;VALUE=DATE:20241002
SUMMARY:Montana Consumer Data Privacy Act (MCDPA): MCDPA takes effect
DESCRIPTION:Consumer rights\, controller duties and opt-out preference sign
 al support apply.\n\nMontana Consumer Data Privacy Act (SB 384\, 2023)\, M
 ont. Code Ann. 30-14-2801 et seq.\, as amended by SB 297 (2025) (Montana)\
 n\nSource: https://archive.legmt.gov/bills/mca/title_0300/chapter_0140/par
 t_0280/section_0030/0300-0140-0280-0030.html\n\nhttps://rulebook.fru.dev/r
 egulations/us-mt-mcdpa
URL:https://rulebook.fru.dev/regulations/us-mt-mcdpa
CATEGORIES:Montana,privacy,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-113@regulations.fru.dev
DTSTAMP:20260924T132329Z
DTSTART;VALUE=DATE:20241017
DTEND;VALUE=DATE:20241018
SUMMARY:Indonesia PDP Law: PDP Law transition ends
DESCRIPTION:Controllers and processors must fully comply (Art. 74 two-year 
 transition).\n\nLaw No. 27 of 2022 on Personal Data Protection (Undang-Und
 ang Pelindungan Data Pribadi) (Indonesia)\n\nSource: https://peraturan.bpk
 .go.id/Details/229798/uu-no-27-tahun-2022\n\nhttps://rulebook.fru.dev/regu
 lations/id-pdp
URL:https://rulebook.fru.dev/regulations/id-pdp
CATEGORIES:Indonesia,privacy,breach-notification,data-residency,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-99@regulations.fru.dev
DTSTAMP:20260924T132329Z
DTSTART;VALUE=DATE:20241017
DTEND;VALUE=DATE:20241018
SUMMARY:NIS2: Transposition deadline
DESCRIPTION:Member States had to adopt and publish national transposing mea
 sures by 17 Oct 2024 (Art 41(1)).\n\nDirective (EU) 2022/2555 on measures 
 for a high common level of cybersecurity across the Union (NIS2 Directive)
  (European Union)\n\nSource: https://eur-lex.europa.eu/eli/dir/2022/2555/o
 j\n\nhttps://rulebook.fru.dev/regulations/eu-nis2
URL:https://rulebook.fru.dev/regulations/eu-nis2
CATEGORIES:European Union,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-100@regulations.fru.dev
DTSTAMP:20260924T132329Z
DTSTART;VALUE=DATE:20241018
DTEND;VALUE=DATE:20241019
SUMMARY:NIS2: National NIS2 measures apply\; NIS1 repealed
DESCRIPTION:Member States apply their NIS2 measures from 18 Oct 2024 and Di
 rective (EU) 2016/1148 (NIS1) is repealed (Arts 41(1)\, 44).\n\nDirective 
 (EU) 2022/2555 on measures for a high common level of cybersecurity across
  the Union (NIS2 Directive) (European Union)\n\nSource: https://eur-lex.eu
 ropa.eu/eli/dir/2022/2555/oj\n\nhttps://rulebook.fru.dev/regulations/eu-ni
 s2
URL:https://rulebook.fru.dev/regulations/eu-nis2
CATEGORIES:European Union,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-274@regulations.fru.dev
DTSTAMP:20260924T132329Z
DTSTART;VALUE=DATE:20241101
DTEND;VALUE=DATE:20241102
SUMMARY:NYDFS Cybersecurity Regulation (Part 500): Governance\, encryption\
 , IR/BCDR\, exemptions
DESCRIPTION:500.4 governance\, 500.15 encryption\, 500.16 incident response
  and business continuity plans\, and 500.19(a) revised exemptions apply.\n
 \nNew York DFS Cybersecurity Requirements for Financial Services Companies
  (23 NYCRR Part 500)\, Second Amendment (New York)\n\nSource: https://www.
 dfs.ny.gov/cybersecurity/23-NYCRR-Part-500\n\nhttps://rulebook.fru.dev/reg
 ulations/us-ny-dfs-500
URL:https://rulebook.fru.dev/regulations/us-ny-dfs-500
CATEGORIES:New York,cybersecurity,breach-notification,financial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-101@regulations.fru.dev
DTSTAMP:20260924T132329Z
DTSTART;VALUE=DATE:20241107
DTEND;VALUE=DATE:20241108
SUMMARY:NIS2: Implementing Regulation 2024/2690 enters into force
DESCRIPTION:Commission Implementing Regulation (EU) 2024/2690 (published 18
  Oct 2024) sets technical risk-management measures and significant-inciden
 t thresholds for DNS\, TLD\, cloud\, data centre\, CDN\, managed (security
 ) service providers\, online marketplaces\, search engines\, social networ
 ks and trust service providers.\n\nDirective (EU) 2022/2555 on measures fo
 r a high common level of cybersecurity across the Union (NIS2 Directive) (
 European Union)\n\nSource: https://eur-lex.europa.eu/eli/reg_impl/2024/269
 0/oj\n\nhttps://rulebook.fru.dev/regulations/eu-nis2
URL:https://rulebook.fru.dev/regulations/eu-nis2
CATEGORIES:European Union,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-106@regulations.fru.dev
DTSTAMP:20260924T132329Z
DTSTART;VALUE=DATE:20241208
DTEND;VALUE=DATE:20241209
SUMMARY:Product Liability Directive: New PLD enters into force
DESCRIPTION:Directive entered into force on the twentieth day after publica
 tion in the OJ on 18 Nov 2024 (Art 23).\n\nDirective (EU) 2024/2853 on lia
 bility for defective products (new Product Liability Directive) (European 
 Union)\n\nSource: https://eur-lex.europa.eu/eli/dir/2024/2853/oj\n\nhttps:
 //rulebook.fru.dev/regulations/eu-pld
URL:https://rulebook.fru.dev/regulations/eu-pld
CATEGORIES:European Union,ai,cybersecurity
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-9@regulations.fru.dev
DTSTAMP:20260924T132329Z
DTSTART;VALUE=DATE:20241210
DTEND;VALUE=DATE:20241211
SUMMARY:Brazil AI Bill (PL 2338/2023): Approved by the Federal Senate
DESCRIPTION:Senate approves the consolidated text and sends it to the Chamb
 er of Deputies.\n\nProjeto de Lei nº 2338/2023 (Brazilian AI Legal Framew
 ork) (Brazil)\n\nSource: https://www25.senado.leg.br/web/atividade/materia
 s/-/materia/157233\n\nhttps://rulebook.fru.dev/regulations/br-ai-bill
URL:https://rulebook.fru.dev/regulations/br-ai-bill
CATEGORIES:Brazil,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-48@regulations.fru.dev
DTSTAMP:20260924T132329Z
DTSTART;VALUE=DATE:20241210
DTEND;VALUE=DATE:20241211
SUMMARY:Cyber Resilience Act: CRA enters into force
DESCRIPTION:Entered into force on the twentieth day after publication in th
 e OJ on 20 Nov 2024 (Art 71(1)).\n\nRegulation (EU) 2024/2847 on horizonta
 l cybersecurity requirements for products with digital elements (Cyber Res
 ilience Act) (European Union)\n\nSource: https://eur-lex.europa.eu/eli/reg
 /2024/2847/oj\n\nhttps://rulebook.fru.dev/regulations/eu-cra
URL:https://rulebook.fru.dev/regulations/eu-cra
CATEGORIES:European Union,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-4@regulations.fru.dev
DTSTAMP:20260924T132329Z
DTSTART;VALUE=DATE:20241211
DTEND;VALUE=DATE:20241212
SUMMARY:Australia Privacy Act: Most POLA Act 2024 amendments commence
DESCRIPTION:Tiered penalties\, infringement notices\, OAIC powers\, securit
 y and overseas-transfer clarifications and doxxing offences commence the d
 ay after Royal Assent.\n\nPrivacy Act 1988 (Cth)\, as amended by the Priva
 cy and Other Legislation Amendment Act 2024 (Australia)\n\nSource: https:/
 /www.legislation.gov.au/C2024A00128/asmade\n\nhttps://rulebook.fru.dev/reg
 ulations/au-privacy-act
URL:https://rulebook.fru.dev/regulations/au-privacy-act
CATEGORIES:Australia,privacy,children,breach-notification,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-26@regulations.fru.dev
DTSTAMP:20260924T132329Z
DTSTART;VALUE=DATE:20241213
DTEND;VALUE=DATE:20241214
SUMMARY:Chile Personal Data Protection Law (Ley 21.719): Published in Diari
 o Oficial
DESCRIPTION:Law 21.719 published\; 24-month vacatio legis begins.\n\nLey N
 º 21.719 que regula la protección y el tratamiento de los datos personal
 es y crea la Agencia de Protección de Datos Personales (Chile)\n\nSource:
  https://www.bcn.cl/leychile/navegar?idNorma=1209272\n\nhttps://rulebook.f
 ru.dev/regulations/cl-pdpl
URL:https://rulebook.fru.dev/regulations/cl-pdpl
CATEGORIES:Chile,privacy,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-293@regulations.fru.dev
DTSTAMP:20260924T132329Z
DTSTART;VALUE=DATE:20241215
DTEND;VALUE=DATE:20241216
SUMMARY:SEC Cyber Disclosure Rules: Inline XBRL tagging of annual cybersecu
 rity disclosures
DESCRIPTION:Item 106 / Item 16K disclosures must be tagged in Inline XBRL f
 or fiscal years ending on or after this date.\n\nSEC Cybersecurity Risk Ma
 nagement\, Strategy\, Governance\, and Incident Disclosure (Release No. 33
 -11216) (United States (Federal))\n\nSource: https://www.federalregister.g
 ov/documents/2023/08/04/2023-16194/cybersecurity-risk-management-strategy-
 governance-and-incident-disclosure\n\nhttps://rulebook.fru.dev/regulations
 /us-sec-cyber
URL:https://rulebook.fru.dev/regulations/us-sec-cyber
CATEGORIES:United States (Federal),cybersecurity,breach-notification,financ
 ial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-194@regulations.fru.dev
DTSTAMP:20260924T132329Z
DTSTART;VALUE=DATE:20241216
DTEND;VALUE=DATE:20241217
SUMMARY:CMMC 2.0: CMMC Program rule (32 CFR Part 170) effective
DESCRIPTION:The program rule establishing CMMC levels and assessment proces
 ses took effect\; contract enforcement awaited the DFARS rule.\n\nCybersec
 urity Maturity Model Certification (CMMC) Program (32 CFR Part 170) and DF
 ARS acquisition rule (48 CFR Parts 204\, 212\, 217\, 252) (United States (
 Federal))\n\nSource: https://www.federalregister.gov/documents/2024/10/15/
 2024-22905/cybersecurity-maturity-model-certification-cmmc-program\n\nhttp
 s://rulebook.fru.dev/regulations/us-cmmc
URL:https://rulebook.fru.dev/regulations/us-cmmc
CATEGORIES:United States (Federal),cybersecurity
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-294@regulations.fru.dev
DTSTAMP:20260924T132329Z
DTSTART;VALUE=DATE:20241218
DTEND;VALUE=DATE:20241219
SUMMARY:SEC Cyber Disclosure Rules: Inline XBRL tagging of Item 1.05 disclo
 sures
DESCRIPTION:Form 8-K Item 1.05 and Form 6-K incident disclosures must be ta
 gged in Inline XBRL.\n\nSEC Cybersecurity Risk Management\, Strategy\, Gov
 ernance\, and Incident Disclosure (Release No. 33-11216) (United States (F
 ederal))\n\nSource: https://www.federalregister.gov/documents/2023/08/04/2
 023-16194/cybersecurity-risk-management-strategy-governance-and-incident-d
 isclosure\n\nhttps://rulebook.fru.dev/regulations/us-sec-cyber
URL:https://rulebook.fru.dev/regulations/us-sec-cyber
CATEGORIES:United States (Federal),cybersecurity,breach-notification,financ
 ial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-237@regulations.fru.dev
DTSTAMP:20260924T132329Z
DTSTART;VALUE=DATE:20241223
DTEND;VALUE=DATE:20241224
SUMMARY:HIPAA: Reproductive health privacy compliance date (vacated)
DESCRIPTION:Original compliance date for the reproductive health care priva
 cy provisions\, including the attestation requirement\; these provisions n
 o longer apply after the June 2025 vacatur.\n\nHIPAA Privacy\, Security an
 d Breach Notification Rules (45 CFR Parts 160 and 164) (United States (Fed
 eral))\n\nSource: https://www.federalregister.gov/documents/2024/04/26/202
 4-08503/hipaa-privacy-rule-to-support-reproductive-health-care-privacy\n\n
 https://rulebook.fru.dev/regulations/us-hipaa
URL:https://rulebook.fru.dev/regulations/us-hipaa
CATEGORIES:United States (Federal),privacy,health,cybersecurity,breach-noti
 fication
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-86@regulations.fru.dev
DTSTAMP:20260924T132329Z
DTSTART;VALUE=DATE:20241224
DTEND;VALUE=DATE:20241225
SUMMARY:eIDAS 2 / EU Digital Identity Wallet: First wallet implementing act
 s enter into force
DESCRIPTION:Commission Implementing Regulations (EU) 2024/2977\, 2024/2979\
 , 2024/2980\, 2024/2981 and 2024/2982 (adopted 28 Nov 2024\, published 4 D
 ec 2024) enter into force. This starts the wallet deadline clocks in Arts 
 5a and 5f.\n\nRegulation (EU) 2024/1183 amending Regulation (EU) No 910/20
 14 as regards establishing the European Digital Identity Framework (eIDAS 
 2) (European Union)\n\nSource: https://eur-lex.europa.eu/eli/reg_impl/2024
 /2977/oj\n\nhttps://rulebook.fru.dev/regulations/eu-eidas2
URL:https://rulebook.fru.dev/regulations/eu-eidas2
CATEGORIES:European Union,privacy,data-access,biometrics
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-216@regulations.fru.dev
DTSTAMP:20260924T132329Z
DTSTART;VALUE=DATE:20241231
DTEND;VALUE=DATE:20250101
SUMMARY:Connecticut Data Privacy Act (CTDPA): Mandatory 60-day cure period 
 expires
DESCRIPTION:After Dec 31\, 2024\, the AG is no longer required to offer a 6
 0-day cure before enforcement\; cure becomes discretionary.\n\nConnecticut
  Data Privacy Act (Public Act 22-15)\, Conn. Gen. Stat. 42-515 et seq.\, a
 s amended by Public Act 25-113 (SB 1295) and Public Act 26-64 (SB 4) (Conn
 ecticut)\n\nSource: https://www.cga.ct.gov/asp/cgabillstatus/cgabillstatus
 .asp?selBillType=Bill&which_year=2022&bill_num=6\n\nhttps://rulebook.fru.d
 ev/regulations/us-ct-ctdpa
URL:https://rulebook.fru.dev/regulations/us-ct-ctdpa
CATEGORIES:Connecticut,privacy,children,ai,health
TRANSP:TRANSPARENT
END:VEVENT
END:VCALENDAR
