BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//fru.dev//Rulebook//EN
CALSCALE:GREGORIAN
METHOD:PUBLISH
X-WR-CALNAME:Regulation deadlines (Rulebook)
X-WR-CALDESC:Compliance deadlines tracked at rulebook.fru.dev
REFRESH-INTERVAL;VALUE=DURATION:P1D
X-PUBLISHED-TTL:P1D
BEGIN:VEVENT
UID:deadline-166@regulations.fru.dev
DTSTAMP:20260924T142439Z
DTSTART;VALUE=DATE:20250101
DTEND;VALUE=DATE:20250102
SUMMARY:CCPA / CPRA: CPI adjustment of thresholds and fines
DESCRIPTION:Revenue threshold rises to $26\,625\,000 and fines to $2\,663 /
  $7\,988 per violation.\n\nCalifornia Consumer Privacy Act of 2018\, as am
 ended by the California Privacy Rights Act of 2020 (Cal. Civ. Code 1798.10
 0 et seq.) and CPPA regulations (Cal. Code Regs. tit. 11\, 7000 et seq.) (
 California)\n\nSource: https://cppa.ca.gov/regulations/cpi_adjustment.html
 \n\nhttps://rulebook.fru.dev/regulations/us-ca-ccpa
URL:https://rulebook.fru.dev/regulations/us-ca-ccpa
CATEGORIES:California,privacy,ai,cybersecurity,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-34@regulations.fru.dev
DTSTAMP:20260924T142439Z
DTSTART;VALUE=DATE:20250101
DTEND;VALUE=DATE:20250102
SUMMARY:China Network Data Security Regulations: Network Data Regulations t
 ake effect
DESCRIPTION:All provisions\, including the 10-million-person threshold duti
 es and annual important-data risk assessments\, apply.\n\nRegulations on N
 etwork Data Security Management (State Council Order No. 790) (China)\n\nS
 ource: https://www.gov.cn/zhengce/content/202409/content_6977766.htm\n\nht
 tps://rulebook.fru.dev/regulations/cn-network-data-regs
URL:https://rulebook.fru.dev/regulations/cn-network-data-regs
CATEGORIES:China,privacy,cybersecurity,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-209@regulations.fru.dev
DTSTAMP:20260924T142439Z
DTSTART;VALUE=DATE:20250101
DTEND;VALUE=DATE:20250102
SUMMARY:Colorado Privacy Act (CPA): 60-day cure period expires
DESCRIPTION:Mandatory 60-day notice-and-cure before AG enforcement ends\; e
 nforcement may proceed without cure.\n\nColorado Privacy Act (SB 21-190)\,
  C.R.S. 6-1-1301 et seq.\, as amended by HB 24-1130\, SB 24-041 and SB 25-
 276 (Colorado)\n\nSource: https://leg.colorado.gov/bills/sb21-190\n\nhttps
 ://rulebook.fru.dev/regulations/us-co-cpa
URL:https://rulebook.fru.dev/regulations/us-co-cpa
CATEGORIES:Colorado,privacy,children,biometrics
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-217@regulations.fru.dev
DTSTAMP:20260924T142439Z
DTSTART;VALUE=DATE:20250101
DTEND;VALUE=DATE:20250102
SUMMARY:Connecticut Data Privacy Act (CTDPA): Universal opt-out preference 
 signals required
DESCRIPTION:Controllers must honor opt-out preference signals for targeted 
 advertising and sale (effective Jan 1\, 2025).\n\nConnecticut Data Privacy
  Act (Public Act 22-15)\, Conn. Gen. Stat. 42-515 et seq.\, as amended by 
 Public Act 25-113 (SB 1295) and Public Act 26-64 (SB 4) (Connecticut)\n\nS
 ource: https://www.cga.ct.gov/asp/cgabillstatus/cgabillstatus.asp?selBillT
 ype=Bill&which_year=2022&bill_num=6\n\nhttps://rulebook.fru.dev/regulation
 s/us-ct-ctdpa
URL:https://rulebook.fru.dev/regulations/us-ct-ctdpa
CATEGORIES:Connecticut,privacy,children,ai,health
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-223@regulations.fru.dev
DTSTAMP:20260924T142439Z
DTSTART;VALUE=DATE:20250101
DTEND;VALUE=DATE:20250102
SUMMARY:Delaware Personal Data Privacy Act (DPDPA): DPDPA takes effect
DESCRIPTION:Consumer rights and controller duties apply\; 60-day mandatory 
 cure period begins.\n\nDelaware Personal Data Privacy Act (HB 154)\, 6 Del
 . C. ch. 12D (Delaware)\n\nSource: https://delcode.delaware.gov/title6/c01
 2d/index.html\n\nhttps://rulebook.fru.dev/regulations/us-de-dpdpa
URL:https://rulebook.fru.dev/regulations/us-de-dpdpa
CATEGORIES:Delaware,privacy,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-240@regulations.fru.dev
DTSTAMP:20260924T142439Z
DTSTART;VALUE=DATE:20250101
DTEND;VALUE=DATE:20250102
SUMMARY:Iowa Consumer Data Protection Act (ICDPA): ICDPA takes effect
DESCRIPTION:Consumer rights and controller/processor obligations apply.\n\n
 Iowa Consumer Data Protection Act (SF 262\, 2023)\, Iowa Code ch. 715D (Io
 wa)\n\nSource: https://www.legis.iowa.gov/docs/code/715D.pdf\n\nhttps://ru
 lebook.fru.dev/regulations/us-ia-icdpa
URL:https://rulebook.fru.dev/regulations/us-ia-icdpa
CATEGORIES:Iowa,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-129@regulations.fru.dev
DTSTAMP:20260924T142439Z
DTSTART;VALUE=DATE:20250101
DTEND;VALUE=DATE:20250102
SUMMARY:Malaysia PDPA: PDPA amendments phase 1
DESCRIPTION:Miscellaneous provisions commence (e.g. electronic service of n
 otices).\n\nPersonal Data Protection Act 2010 (Act 709)\, as amended by th
 e Personal Data Protection (Amendment) Act 2024 (Act A1727) (Malaysia)\n\n
 Source: https://www.pdp.gov.my/ppdpv1/en/personal-data-protection-amendmen
 t-act-2024-commencement-date-determination/\n\nhttps://rulebook.fru.dev/re
 gulations/my-pdpa
URL:https://rulebook.fru.dev/regulations/my-pdpa
CATEGORIES:Malaysia,privacy,breach-notification,biometrics,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-260@regulations.fru.dev
DTSTAMP:20260924T142439Z
DTSTART;VALUE=DATE:20250101
DTEND;VALUE=DATE:20250102
SUMMARY:Nebraska NDPA: Nebraska Data Privacy Act takes effect
DESCRIPTION:Controller and processor obligations and consumer rights under 
 Neb. Rev. Stat. 87-1101 et seq. apply.\n\nNebraska Data Privacy Act (LB 10
 74\, 2024) (Nebraska)\n\nSource: https://nebraskalegislature.gov/bills/vie
 w_bill.php?DocumentID=54904\n\nhttps://rulebook.fru.dev/regulations/us-ne-
 ndpa
URL:https://rulebook.fru.dev/regulations/us-ne-ndpa
CATEGORIES:Nebraska,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-261@regulations.fru.dev
DTSTAMP:20260924T142439Z
DTSTART;VALUE=DATE:20250101
DTEND;VALUE=DATE:20250102
SUMMARY:New Hampshire Privacy Act: New Hampshire Privacy Act takes effect
DESCRIPTION:RSA 507-H obligations and consumer rights apply (Laws 2024\, 5:
 1\, eff. Jan. 1\, 2025).\n\nNew Hampshire Privacy Act (SB 255\, 2024)\, RS
 A chapter 507-H (New Hampshire)\n\nSource: https://gc.nh.gov/rsa/html/LII/
 507-H/507-H-2.htm\n\nhttps://rulebook.fru.dev/regulations/us-nh-privacy
URL:https://rulebook.fru.dev/regulations/us-nh-privacy
CATEGORIES:New Hampshire,privacy,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-302@regulations.fru.dev
DTSTAMP:20260924T142439Z
DTSTART;VALUE=DATE:20250101
DTEND;VALUE=DATE:20250102
SUMMARY:Texas TDPSA: Universal opt-out mechanism requirement applies
DESCRIPTION:Controllers must honor global privacy control / universal opt-o
 ut signals (Bus. & Com. Code 541.055(e)).\n\nTexas Data Privacy and Securi
 ty Act (HB 4\, 2023) (Texas)\n\nSource: https://capitol.texas.gov/BillLook
 up/History.aspx?LegSess=88R&Bill=HB4\n\nhttps://rulebook.fru.dev/regulatio
 ns/us-tx-tdpsa
URL:https://rulebook.fru.dev/regulations/us-tx-tdpsa
CATEGORIES:Texas,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-264@regulations.fru.dev
DTSTAMP:20260924T142439Z
DTSTART;VALUE=DATE:20250115
DTEND;VALUE=DATE:20250116
SUMMARY:New Jersey NJDPA: NJDPA takes effect
DESCRIPTION:The act takes effect on the 365th day after enactment on Jan 16
 \, 2024 (sec. 17).\n\nNew Jersey Data Privacy Act (P.L.2023\, c.266\; S332
 ) (New Jersey)\n\nSource: https://pub.njleg.state.nj.us/Bills/2022/PL23/26
 6_.PDF\n\nhttps://rulebook.fru.dev/regulations/us-nj-njdpa
URL:https://rulebook.fru.dev/regulations/us-nj-njdpa
CATEGORIES:New Jersey,privacy,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-71@regulations.fru.dev
DTSTAMP:20260924T142439Z
DTSTART;VALUE=DATE:20250117
DTEND;VALUE=DATE:20250118
SUMMARY:DORA: DORA applies
DESCRIPTION:All DORA obligations (ICT risk management\, incident reporting\
 , testing\, third-party risk\, register of information) apply from 17 Jan 
 2025 (Art 64).\n\nRegulation (EU) 2022/2554 on digital operational resilie
 nce for the financial sector (Digital Operational Resilience Act) (Europea
 n Union)\n\nSource: https://eur-lex.europa.eu/eli/reg/2022/2554/oj\n\nhttp
 s://rulebook.fru.dev/regulations/eu-dora
URL:https://rulebook.fru.dev/regulations/eu-dora
CATEGORIES:European Union,cybersecurity,financial,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-102@regulations.fru.dev
DTSTAMP:20260924T142439Z
DTSTART;VALUE=DATE:20250117
DTEND;VALUE=DATE:20250118
SUMMARY:NIS2: Digital infrastructure entities submit registration data
DESCRIPTION:DNS providers\, TLD registries\, domain registration services\,
  cloud\, data centre\, CDN\, managed (security) service providers\, market
 places\, search engines and social networks had to submit registration det
 ails to competent authorities (Art 27(2)).\n\nDirective (EU) 2022/2555 on 
 measures for a high common level of cybersecurity across the Union (NIS2 D
 irective) (European Union)\n\nSource: https://eur-lex.europa.eu/eli/dir/20
 22/2555/oj\n\nhttps://rulebook.fru.dev/regulations/eu-nis2
URL:https://rulebook.fru.dev/regulations/eu-nis2
CATEGORIES:European Union,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-38@regulations.fru.dev
DTSTAMP:20260924T142439Z
DTSTART;VALUE=DATE:20250202
DTEND;VALUE=DATE:20250203
SUMMARY:EU AI Act: Prohibited practices and AI literacy apply
DESCRIPTION:Chapters I and II apply\, including the Article 5 bans on prohi
 bited AI practices and the Article 4 AI literacy duty (Art 113(a)).\n\nReg
 ulation (EU) 2024/1689 laying down harmonised rules on artificial intellig
 ence (Artificial Intelligence Act)\, as amended by Regulation (EU) 2026/17
 44 (Digital Omnibus on AI) (European Union)\n\nSource: https://eur-lex.eur
 opa.eu/eli/reg/2024/1689/oj\n\nhttps://rulebook.fru.dev/regulations/eu-ai-
 act
URL:https://rulebook.fru.dev/regulations/eu-ai-act
CATEGORIES:European Union,ai,biometrics,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-238@regulations.fru.dev
DTSTAMP:20260924T142439Z
DTSTART;VALUE=DATE:20250307
DTEND;VALUE=DATE:20250308
SUMMARY:HIPAA: Security Rule NPRM comment period closed
DESCRIPTION:Comments closed on the proposed HIPAA Security Rule update (90 
 FR 898)\; OCR has not issued a final rule.\n\nHIPAA Privacy\, Security and
  Breach Notification Rules (45 CFR Parts 160 and 164) (United States (Fede
 ral))\n\nSource: https://www.federalregister.gov/documents/2025/01/06/2024
 -30983/hipaa-security-rule-to-strengthen-the-cybersecurity-of-electronic-p
 rotected-health-information\n\nhttps://rulebook.fru.dev/regulations/us-hip
 aa
URL:https://rulebook.fru.dev/regulations/us-hipaa
CATEGORIES:United States (Federal),privacy,health,cybersecurity,breach-noti
 fication
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-157@regulations.fru.dev
DTSTAMP:20260924T142439Z
DTSTART;VALUE=DATE:20250317
DTEND;VALUE=DATE:20250318
SUMMARY:UK Online Safety Act: Illegal harms duties enforceable
DESCRIPTION:Illegal content safety duties apply\; illegal content risk asse
 ssments had to be completed by 16 March 2025.\n\nOnline Safety Act 2023 (U
 nited Kingdom)\n\nSource: https://www.ofcom.org.uk/online-safety/illegal-a
 nd-harmful-content\n\nhttps://rulebook.fru.dev/regulations/uk-osa
URL:https://rulebook.fru.dev/regulations/uk-osa
CATEGORIES:United Kingdom,online-safety,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-128@regulations.fru.dev
DTSTAMP:20260924T142439Z
DTSTART;VALUE=DATE:20250321
DTEND;VALUE=DATE:20250322
SUMMARY:Mexico LFPDPPP 2025: New LFPDPPP in force
DESCRIPTION:Law published 20 March 2025 enters into force the following day
 \, repealing the 2010 law.\n\nLey Federal de Protección de Datos Personal
 es en Posesión de los Particulares (2025) (Mexico)\n\nSource: https://www
 .diputados.gob.mx/LeyesBiblio/pdf/LFPDPPP.pdf\n\nhttps://rulebook.fru.dev/
 regulations/mx-lfpdppp
URL:https://rulebook.fru.dev/regulations/mx-lfpdppp
CATEGORIES:Mexico,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-80@regulations.fru.dev
DTSTAMP:20260924T142439Z
DTSTART;VALUE=DATE:20250325
DTEND;VALUE=DATE:20250326
SUMMARY:European Health Data Space (EHDS): EHDS enters into force
DESCRIPTION:Regulation (EU) 2025/327\, published 5 Mar 2025\, enters into f
 orce on the twentieth day following publication.\n\nRegulation (EU) 2025/3
 27 on the European Health Data Space (European Union)\n\nSource: https://e
 ur-lex.europa.eu/eli/reg/2025/327/oj\n\nhttps://rulebook.fru.dev/regulatio
 ns/eu-ehds
URL:https://rulebook.fru.dev/regulations/eu-ehds
CATEGORIES:European Union,health,privacy,data-access
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-130@regulations.fru.dev
DTSTAMP:20260924T142439Z
DTSTART;VALUE=DATE:20250401
DTEND;VALUE=DATE:20250402
SUMMARY:Malaysia PDPA: PDPA amendments phase 2
DESCRIPTION:'Data controller' terminology\, biometric data as sensitive dat
 a\, higher penalties\, Security Principle for processors\, and removal of 
 the cross-border whitelist take effect.\n\nPersonal Data Protection Act 20
 10 (Act 709)\, as amended by the Personal Data Protection (Amendment) Act 
 2024 (Act A1727) (Malaysia)\n\nSource: https://www.pdp.gov.my/ppdpv1/en/pe
 rsonal-data-protection-amendment-act-2024-commencement-date-determination/
 \n\nhttps://rulebook.fru.dev/regulations/my-pdpa
URL:https://rulebook.fru.dev/regulations/my-pdpa
CATEGORIES:Malaysia,privacy,breach-notification,biometrics,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-227@regulations.fru.dev
DTSTAMP:20260924T142439Z
DTSTART;VALUE=DATE:20250408
DTEND;VALUE=DATE:20250409
SUMMARY:DOJ Bulk Data Rule: Prohibitions and restrictions take effect
DESCRIPTION:Core prohibitions on covered data transactions and security req
 uirements for restricted transactions apply.\n\nPreventing Access to U.S. 
 Sensitive Personal Data and Government-Related Data by Countries of Concer
 n or Covered Persons (28 CFR Part 202) - DOJ Data Security Program (United
  States (Federal))\n\nSource: https://www.federalregister.gov/documents/20
 25/01/08/2024-31486/preventing-access-to-us-sensitive-personal-data-and-go
 vernment-related-data-by-countries-of-concern\n\nhttps://rulebook.fru.dev/
 regulations/us-doj-bulk-data
URL:https://rulebook.fru.dev/regulations/us-doj-bulk-data
CATEGORIES:United States (Federal),privacy,data-residency,cybersecurity,bio
 metrics,health,financial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-158@regulations.fru.dev
DTSTAMP:20260924T142439Z
DTSTART;VALUE=DATE:20250416
DTEND;VALUE=DATE:20250417
SUMMARY:UK Online Safety Act: Children's access assessments due
DESCRIPTION:Services had to complete children's access assessments to deter
 mine whether children are likely to access them.\n\nOnline Safety Act 2023
  (United Kingdom)\n\nSource: https://www.ofcom.org.uk/online-safety/protec
 ting-children/protection-of-children-duties-under-the-online-safety-act\n\
 nhttps://rulebook.fru.dev/regulations/uk-osa
URL:https://rulebook.fru.dev/regulations/uk-osa
CATEGORIES:United Kingdom,online-safety,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-103@regulations.fru.dev
DTSTAMP:20260924T142439Z
DTSTART;VALUE=DATE:20250417
DTEND;VALUE=DATE:20250418
SUMMARY:NIS2: Member States establish entity lists
DESCRIPTION:Member States had to establish lists of essential and important
  entities and notify the Commission of entity numbers (Art 3(3) and (5)). 
 Repeated every two years.\n\nDirective (EU) 2022/2555 on measures for a hi
 gh common level of cybersecurity across the Union (NIS2 Directive) (Europe
 an Union)\n\nSource: https://eur-lex.europa.eu/eli/dir/2022/2555/oj\n\nhtt
 ps://rulebook.fru.dev/regulations/eu-nis2
URL:https://rulebook.fru.dev/regulations/eu-nis2
CATEGORIES:European Union,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-72@regulations.fru.dev
DTSTAMP:20260924T142439Z
DTSTART;VALUE=DATE:20250430
DTEND;VALUE=DATE:20250501
SUMMARY:DORA: First registers of information submitted to the ESAs
DESCRIPTION:Competent authorities had to submit financial entities' registe
 rs of ICT third-party contractual arrangements (reference date 31 Mar 2025
 ) to the ESAs by 30 Apr 2025. National authorities set earlier deadlines f
 or entities.\n\nRegulation (EU) 2022/2554 on digital operational resilienc
 e for the financial sector (Digital Operational Resilience Act) (European 
 Union)\n\nSource: https://www.eba.europa.eu/publications-and-media/press-r
 eleases/esas-announce-timeline-collect-information-designation-critical-ic
 t-third-party-service-providers\n\nhttps://rulebook.fru.dev/regulations/eu
 -dora
URL:https://rulebook.fru.dev/regulations/eu-dora
CATEGORIES:European Union,cybersecurity,financial,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-35@regulations.fru.dev
DTSTAMP:20260924T142439Z
DTSTART;VALUE=DATE:20250501
DTEND;VALUE=DATE:20250502
SUMMARY:China PI Compliance Audit Measures: PI compliance audit measures ta
 ke effect
DESCRIPTION:Self-audit and regulator-ordered audit regime applies\; 10M+ pr
 ocessors must audit at least every two years.\n\nAdministrative Measures f
 or Personal Information Protection Compliance Audits (CAC Order No. 18) (C
 hina)\n\nSource: https://www.cac.gov.cn/2025-02/14/c_1741233507681519.htm\
 n\nhttps://rulebook.fru.dev/regulations/cn-pi-compliance-audit
URL:https://rulebook.fru.dev/regulations/cn-pi-compliance-audit
CATEGORIES:China,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-275@regulations.fru.dev
DTSTAMP:20260924T142439Z
DTSTART;VALUE=DATE:20250501
DTEND;VALUE=DATE:20250502
SUMMARY:NYDFS Cybersecurity Regulation (Part 500): Vulnerability scans\, ac
 cess privileges\, malware controls\, Class A monitoring
DESCRIPTION:500.5(a)(2) automated scans\, 500.7 access privilege restrictio
 ns\, 500.14(a)(2) malicious code protection\, and 500.14(b) Class A endpoi
 nt detection and centralized logging apply.\n\nNew York DFS Cybersecurity 
 Requirements for Financial Services Companies (23 NYCRR Part 500)\, Second
  Amendment (New York)\n\nSource: https://www.dfs.ny.gov/cybersecurity/23-N
 YCRR-Part-500\n\nhttps://rulebook.fru.dev/regulations/us-ny-dfs-500
URL:https://rulebook.fru.dev/regulations/us-ny-dfs-500
CATEGORIES:New York,cybersecurity,breach-notification,financial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-306@regulations.fru.dev
DTSTAMP:20260924T142439Z
DTSTART;VALUE=DATE:20250507
DTEND;VALUE=DATE:20250508
SUMMARY:Utah AI Policy Act: SB 226 amendments effective
DESCRIPTION:Disclosure duties narrowed (on clear request or high-risk inter
 actions)\, safe harbor added\, provisions recodified in Title 13\, Ch. 75.
 \n\nUtah Artificial Intelligence Policy Act (SB 149\, 2024)\, as amended b
 y SB 226 and SB 332 (2025) (Utah)\n\nSource: https://le.utah.gov/~2025/bil
 ls/static/SB0226.html\n\nhttps://rulebook.fru.dev/regulations/us-ut-aipa
URL:https://rulebook.fru.dev/regulations/us-ut-aipa
CATEGORIES:Utah,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-298@regulations.fru.dev
DTSTAMP:20260924T142439Z
DTSTART;VALUE=DATE:20250519
DTEND;VALUE=DATE:20250520
SUMMARY:TAKE IT DOWN Act: Criminal provisions effective on enactment
DESCRIPTION:Publishing or threatening to publish non-consensual intimate im
 ages\, including digital forgeries\, became a federal crime upon signature
 .\n\nTools to Address Known Exploitation by Immobilizing Technological Dee
 pfakes on Websites and Networks Act (TAKE IT DOWN Act) (United States (Fed
 eral))\n\nSource: https://www.govinfo.gov/content/pkg/PLAW-119publ12/html/
 PLAW-119publ12.htm\n\nhttps://rulebook.fru.dev/regulations/us-take-it-down
URL:https://rulebook.fru.dev/regulations/us-take-it-down
CATEGORIES:United States (Federal),online-safety,ai,children,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-210@regulations.fru.dev
DTSTAMP:20260924T142439Z
DTSTART;VALUE=DATE:20250523
DTEND;VALUE=DATE:20250524
SUMMARY:Colorado Privacy Act (CPA): SB 25-276 geolocation and sensitive-dat
 a sale amendment effective
DESCRIPTION:Adds precise geolocation data definitions and prohibits selling
  sensitive data without consent (effective on signature).\n\nColorado Priv
 acy Act (SB 21-190)\, C.R.S. 6-1-1301 et seq.\, as amended by HB 24-1130\,
  SB 24-041 and SB 25-276 (Colorado)\n\nSource: https://leg.colorado.gov/bi
 lls/sb25-276\n\nhttps://rulebook.fru.dev/regulations/us-co-cpa
URL:https://rulebook.fru.dev/regulations/us-co-cpa
CATEGORIES:Colorado,privacy,children,biometrics
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-2@regulations.fru.dev
DTSTAMP:20260924T142439Z
DTSTART;VALUE=DATE:20250530
DTEND;VALUE=DATE:20250531
SUMMARY:Australia Cyber Security Act (ransomware reporting): Ransomware pay
 ment reporting starts
DESCRIPTION:Reporting business entities must report ransomware/cyber-extort
 ion payments to ASD within 72 hours of payment.\n\nCyber Security Act 2024
  (Cth) and Cyber Security (Ransomware Payment Reporting) Rules 2025 (Austr
 alia)\n\nSource: https://www.homeaffairs.gov.au/cyber-security-subsite/fil
 es/factsheet-ransomware-payment-reporting.pdf\n\nhttps://rulebook.fru.dev/
 regulations/au-cyber-security-act
URL:https://rulebook.fru.dev/regulations/au-cyber-security-act
CATEGORIES:Australia,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-131@regulations.fru.dev
DTSTAMP:20260924T142439Z
DTSTART;VALUE=DATE:20250601
DTEND;VALUE=DATE:20250602
SUMMARY:Malaysia PDPA: PDPA amendments phase 3
DESCRIPTION:Mandatory DPO appointment\, data breach notification\, and data
  portability take effect.\n\nPersonal Data Protection Act 2010 (Act 709)\,
  as amended by the Personal Data Protection (Amendment) Act 2024 (Act A172
 7) (Malaysia)\n\nSource: https://www.pdp.gov.my/ppdpv1/en/personal-data-pr
 otection-amendment-act-2024-commencement-date-determination/\n\nhttps://ru
 lebook.fru.dev/regulations/my-pdpa
URL:https://rulebook.fru.dev/regulations/my-pdpa
CATEGORIES:Malaysia,privacy,breach-notification,biometrics,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-265@regulations.fru.dev
DTSTAMP:20260924T142439Z
DTSTART;VALUE=DATE:20250602
DTEND;VALUE=DATE:20250603
SUMMARY:New Jersey NJDPA: Division of Consumer Affairs proposes NJDPA rules
  (N.J.A.C. 13:45L)
DESCRIPTION:Proposed rules published at 57 N.J.R. 1101(a)\; comments were d
 ue Aug 1\, 2025.\n\nNew Jersey Data Privacy Act (P.L.2023\, c.266\; S332) 
 (New Jersey)\n\nSource: https://www.njoag.gov/murphy-administration-announ
 ces-proposed-rules-establishing-comprehensive-consumer-data-privacy-protec
 tions/\n\nhttps://rulebook.fru.dev/regulations/us-nj-njdpa
URL:https://rulebook.fru.dev/regulations/us-nj-njdpa
CATEGORIES:New Jersey,privacy,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-119@regulations.fru.dev
DTSTAMP:20260924T142439Z
DTSTART;VALUE=DATE:20250604
DTEND;VALUE=DATE:20250605
SUMMARY:Japan AI Promotion Act: AI Promotion Act promulgated and partly in 
 force
DESCRIPTION:Most provisions\, including basic principles and stakeholder du
 ties\, take effect on promulgation.\n\nAct on Promotion of Research and De
 velopment\, and Utilization of Artificial Intelligence-Related Technology 
 (Japan)\n\nSource: https://www8.cao.go.jp/cstp/ai/ai_act/ai_act.html\n\nht
 tps://rulebook.fru.dev/regulations/jp-ai-act
URL:https://rulebook.fru.dev/regulations/jp-ai-act
CATEGORIES:Japan,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-5@regulations.fru.dev
DTSTAMP:20260924T142439Z
DTSTART;VALUE=DATE:20250610
DTEND;VALUE=DATE:20250611
SUMMARY:Australia Privacy Act: Statutory tort for serious invasions of priv
 acy commences
DESCRIPTION:Individuals can sue for serious invasions of privacy (Schedule 
 2)\, 6 months after Royal Assent.\n\nPrivacy Act 1988 (Cth)\, as amended b
 y the Privacy and Other Legislation Amendment Act 2024 (Australia)\n\nSour
 ce: https://www.legislation.gov.au/C2024A00128/asmade\n\nhttps://rulebook.
 fru.dev/regulations/au-privacy-act
URL:https://rulebook.fru.dev/regulations/au-privacy-act
CATEGORIES:Australia,privacy,children,breach-notification,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-16@regulations.fru.dev
DTSTAMP:20260924T142439Z
DTSTART;VALUE=DATE:20250618
DTEND;VALUE=DATE:20250619
SUMMARY:Canada Bill C-8 / CCSPA: Bill C-8 introduced
DESCRIPTION:First reading in the House of Commons.\n\nCritical Cyber System
 s Protection Act (enacted by Bill C-8\, An Act respecting cyber security) 
 (Canada)\n\nSource: https://www.parl.ca/legisinfo/en/bill/45-1/c-8\n\nhttp
 s://rulebook.fru.dev/regulations/ca-ccspa
URL:https://rulebook.fru.dev/regulations/ca-ccspa
CATEGORIES:Canada,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-148@regulations.fru.dev
DTSTAMP:20260924T142439Z
DTSTART;VALUE=DATE:20250619
DTEND;VALUE=DATE:20250620
SUMMARY:Data (Use and Access) Act: Royal Assent
DESCRIPTION:The Act receives Royal Assent\; commencement staged by regulati
 ons.\n\nData (Use and Access) Act 2025 (United Kingdom)\n\nSource: https:/
 /www.legislation.gov.uk/ukpga/2025/18/contents\n\nhttps://rulebook.fru.dev
 /regulations/uk-duaa
URL:https://rulebook.fru.dev/regulations/uk-duaa
CATEGORIES:United Kingdom,privacy,data-access,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-303@regulations.fru.dev
DTSTAMP:20260924T142439Z
DTSTART;VALUE=DATE:20250622
DTEND;VALUE=DATE:20250623
SUMMARY:TRAIGA: HB 149 signed
DESCRIPTION:Governor Abbott signs TRAIGA.\n\nTexas Responsible Artificial I
 ntelligence Governance Act (HB 149\, 89th Legislature) (Texas)\n\nSource: 
 https://capitol.texas.gov/BillLookup/History.aspx?LegSess=89R&Bill=HB149\n
 \nhttps://rulebook.fru.dev/regulations/us-tx-traiga
URL:https://rulebook.fru.dev/regulations/us-tx-traiga
CATEGORIES:Texas,ai,biometrics
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-213@regulations.fru.dev
DTSTAMP:20260924T142439Z
DTSTART;VALUE=DATE:20250623
DTEND;VALUE=DATE:20250624
SUMMARY:COPPA Rule: Amended COPPA Rule takes effect
DESCRIPTION:The April 2025 amendments to 16 CFR Part 312 became effective\;
  during the transition operators could comply with either the pre-2025 or 
 the amended Rule.\n\nChildren's Online Privacy Protection Rule (16 CFR Par
 t 312)\, as amended April 2025 (United States (Federal))\n\nSource: https:
 //www.federalregister.gov/documents/2025/04/22/2025-05904/childrens-online
 -privacy-protection-rule\n\nhttps://rulebook.fru.dev/regulations/us-coppa
URL:https://rulebook.fru.dev/regulations/us-coppa
CATEGORIES:United States (Federal),privacy,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-211@regulations.fru.dev
DTSTAMP:20260924T142439Z
DTSTART;VALUE=DATE:20250701
DTEND;VALUE=DATE:20250702
SUMMARY:Colorado Privacy Act (CPA): Biometric identifier amendment (HB 24-1
 130) effective
DESCRIPTION:Any controller processing biometric identifiers must adopt a wr
 itten biometric policy\, give notice\, obtain consent and follow retention
 /deletion rules.\n\nColorado Privacy Act (SB 21-190)\, C.R.S. 6-1-1301 et 
 seq.\, as amended by HB 24-1130\, SB 24-041 and SB 25-276 (Colorado)\n\nSo
 urce: https://leg.colorado.gov/bills/hb24-1130\n\nhttps://rulebook.fru.dev
 /regulations/us-co-cpa
URL:https://rulebook.fru.dev/regulations/us-co-cpa
CATEGORIES:Colorado,privacy,children,biometrics
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-284@regulations.fru.dev
DTSTAMP:20260924T142439Z
DTSTART;VALUE=DATE:20250701
DTEND;VALUE=DATE:20250702
SUMMARY:Oregon OCPA: OCPA applies to nonprofits
DESCRIPTION:Nonprofit organizations meeting the thresholds become subject t
 o OCPA.\n\nOregon Consumer Privacy Act (SB 619\, 2023) (Oregon)\n\nSource:
  https://www.doj.state.or.us/consumer-protection/for-businesses/privacy-la
 w-faqs-for-nonprofits/\n\nhttps://rulebook.fru.dev/regulations/us-or-ocpa
URL:https://rulebook.fru.dev/regulations/us-or-ocpa
CATEGORIES:Oregon,privacy,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-300@regulations.fru.dev
DTSTAMP:20260924T142439Z
DTSTART;VALUE=DATE:20250701
DTEND;VALUE=DATE:20250702
SUMMARY:Tennessee TIPA: TIPA takes effect
DESCRIPTION:Controller and processor obligations and consumer rights under 
 Tenn. Code Ann. 47-18-3301 et seq. apply.\n\nTennessee Information Protect
 ion Act (HB 1181 / SB 73\, 2023) (Tennessee)\n\nSource: https://wapp.capit
 ol.tn.gov/apps/BillInfo/Default.aspx?BillNumber=HB1181&GA=113\n\nhttps://r
 ulebook.fru.dev/regulations/us-tn-tipa
URL:https://rulebook.fru.dev/regulations/us-tn-tipa
CATEGORIES:Tennessee,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-73@regulations.fru.dev
DTSTAMP:20260924T142439Z
DTSTART;VALUE=DATE:20250708
DTEND;VALUE=DATE:20250709
SUMMARY:DORA: TLPT regulatory technical standards enter into force
DESCRIPTION:Commission Delegated Regulation (EU) 2025/1190 (published 18 Ju
 ne 2025) sets criteria for which financial entities must run threat-led pe
 netration testing\, plus methodology and tester requirements.\n\nRegulatio
 n (EU) 2022/2554 on digital operational resilience for the financial secto
 r (Digital Operational Resilience Act) (European Union)\n\nSource: https:/
 /eur-lex.europa.eu/eli/reg_del/2025/1190/oj\n\nhttps://rulebook.fru.dev/re
 gulations/eu-dora
URL:https://rulebook.fru.dev/regulations/eu-dora
CATEGORIES:European Union,cybersecurity,financial,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-266@regulations.fru.dev
DTSTAMP:20260924T142439Z
DTSTART;VALUE=DATE:20250715
DTEND;VALUE=DATE:20250716
SUMMARY:New Jersey NJDPA: Universal opt-out mechanism must be honored
DESCRIPTION:Controllers that sell personal data or process it for targeted 
 advertising must honor user-selected universal opt-out signals within six 
 months of the effective date (N.J.S.A. 56:8-166.11).\n\nNew Jersey Data Pr
 ivacy Act (P.L.2023\, c.266\; S332) (New Jersey)\n\nSource: https://pub.nj
 leg.state.nj.us/Bills/2022/PL23/266_.PDF\n\nhttps://rulebook.fru.dev/regul
 ations/us-nj-njdpa
URL:https://rulebook.fru.dev/regulations/us-nj-njdpa
CATEGORIES:New Jersey,privacy,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-159@regulations.fru.dev
DTSTAMP:20260924T142439Z
DTSTART;VALUE=DATE:20250725
DTEND;VALUE=DATE:20250726
SUMMARY:UK Online Safety Act: Protection of children duties apply
DESCRIPTION:Children's safety duties and Protection of Children Codes take 
 effect\, including highly effective age assurance\; children's risk assess
 ments due by 24 July 2025.\n\nOnline Safety Act 2023 (United Kingdom)\n\nS
 ource: https://www.ofcom.org.uk/online-safety/protecting-children/protecti
 on-of-children-duties-under-the-online-safety-act\n\nhttps://rulebook.fru.
 dev/regulations/uk-osa
URL:https://rulebook.fru.dev/regulations/uk-osa
CATEGORIES:United Kingdom,online-safety,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-255@regulations.fru.dev
DTSTAMP:20260924T142439Z
DTSTART;VALUE=DATE:20250731
DTEND;VALUE=DATE:20250801
SUMMARY:Minnesota Consumer Data Privacy Act (MCDPA): MCDPA takes effect
DESCRIPTION:Consumer rights and controller/processor obligations apply (pos
 tsecondary institutions excepted).\n\nMinnesota Consumer Data Privacy Act 
 (HF 4757\, 2024 Minn. Laws ch. 121\, art. 5)\, Minn. Stat. 325M.10-325M.21
  (Minnesota)\n\nSource: https://www.revisor.mn.gov/statutes/cite/325M.20\n
 \nhttps://rulebook.fru.dev/regulations/us-mn-mcdpa
URL:https://rulebook.fru.dev/regulations/us-mn-mcdpa
CATEGORIES:Minnesota,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-39@regulations.fru.dev
DTSTAMP:20260924T142439Z
DTSTART;VALUE=DATE:20250802
DTEND;VALUE=DATE:20250803
SUMMARY:EU AI Act: GPAI\, governance\, notified bodies and penalties apply
DESCRIPTION:Chapter III Section 4 (notifying authorities)\, Chapter V (gene
 ral-purpose AI model obligations)\, Chapter VII (governance)\, Chapter XII
  (penalties\, except Art 101) and Art 78 apply (Art 113(b)).\n\nRegulation
  (EU) 2024/1689 laying down harmonised rules on artificial intelligence (A
 rtificial Intelligence Act)\, as amended by Regulation (EU) 2026/1744 (Dig
 ital Omnibus on AI) (European Union)\n\nSource: https://eur-lex.europa.eu/
 eli/reg/2024/1689/oj\n\nhttps://rulebook.fru.dev/regulations/eu-ai-act
URL:https://rulebook.fru.dev/regulations/eu-ai-act
CATEGORIES:European Union,ai,biometrics,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-115@regulations.fru.dev
DTSTAMP:20260924T142439Z
DTSTART;VALUE=DATE:20250814
DTEND;VALUE=DATE:20250815
SUMMARY:Israel Privacy Protection Law Amendment 13: Amendment 13 in force
DESCRIPTION:Amended Privacy Protection Law\, PPA enforcement powers and sta
 tutory damages take effect.\n\nPrivacy Protection Law\, 5741-1981 (Amendme
 nt No. 13) (Israel)\n\nSource: https://www.gov.il/en/departments/the_priva
 cy_protection_authority/govil-landing-page\n\nhttps://rulebook.fru.dev/reg
 ulations/il-ppl-amendment-13
URL:https://rulebook.fru.dev/regulations/il-ppl-amendment-13
CATEGORIES:Israel,privacy,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-149@regulations.fru.dev
DTSTAMP:20260924T142439Z
DTSTART;VALUE=DATE:20250820
DTEND;VALUE=DATE:20250821
SUMMARY:Data (Use and Access) Act: Stage 1 commencement
DESCRIPTION:Technical data protection provisions\, ICO statutory objects\, 
 Smart Data framework (Part 1) and AI/copyright reporting duties commence (
 Commencement No. 1 Regulations 2025).\n\nData (Use and Access) Act 2025 (U
 nited Kingdom)\n\nSource: https://www.legislation.gov.uk/ukpga/2025/18/con
 tents\n\nhttps://rulebook.fru.dev/regulations/uk-duaa
URL:https://rulebook.fru.dev/regulations/uk-duaa
CATEGORIES:United Kingdom,privacy,data-access,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-14@regulations.fru.dev
DTSTAMP:20260924T142439Z
DTSTART;VALUE=DATE:20250823
DTEND;VALUE=DATE:20250824
SUMMARY:Brazil LGPD: Deadline to adopt ANPD standard contractual clauses
DESCRIPTION:Agents relying on contractual clauses for international transfe
 rs must incorporate the ANPD-approved SCCs into their contracts within 12 
 months of publication.\n\nLei Geral de Proteção de Dados Pessoais (Law N
 o. 13.709/2018) (Brazil)\n\nSource: https://www.in.gov.br/en/web/dou/-/res
 olucao-cd/anpd-n-19-de-23-de-agosto-de-2024-580095396\n\nhttps://rulebook.
 fru.dev/regulations/br-lgpd
URL:https://rulebook.fru.dev/regulations/br-lgpd
CATEGORIES:Brazil,privacy,breach-notification,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-200@regulations.fru.dev
DTSTAMP:20260924T142439Z
DTSTART;VALUE=DATE:20250828
DTEND;VALUE=DATE:20250829
SUMMARY:Colorado AI Act: SB 25B-004 delays the act
DESCRIPTION:Special-session bill pushes the SB 24-205 effective date from F
 ebruary 1\, 2026 to June 30\, 2026.\n\nColorado SB 24-205 (Consumer Protec
 tions for Artificial Intelligence)\, as delayed by SB 25B-004 and repealed
  and reenacted by SB 26-189 (Automated Decision-Making Technology) (Colora
 do)\n\nSource: https://leg.colorado.gov/bills/sb25b-004\n\nhttps://ruleboo
 k.fru.dev/regulations/us-co-ai-act
URL:https://rulebook.fru.dev/regulations/us-co-ai-act
CATEGORIES:Colorado,ai,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-29@regulations.fru.dev
DTSTAMP:20260924T142439Z
DTSTART;VALUE=DATE:20250901
DTEND;VALUE=DATE:20250902
SUMMARY:China AI Content Labeling Measures: AI content labeling measures an
 d GB 45438-2025 take effect
DESCRIPTION:Explicit and implicit labeling duties for AI-generated content 
 and platform detection duties apply.\n\nMeasures for Labeling AI-Generated
  Synthetic Content (China)\n\nSource: https://www.cac.gov.cn/2025-03/14/c_
 1743654684782215.htm\n\nhttps://rulebook.fru.dev/regulations/cn-ai-labelin
 g
URL:https://rulebook.fru.dev/regulations/cn-ai-labeling
CATEGORIES:China,ai,online-safety
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-120@regulations.fru.dev
DTSTAMP:20260924T142439Z
DTSTART;VALUE=DATE:20250901
DTEND;VALUE=DATE:20250902
SUMMARY:Japan AI Promotion Act: AI Promotion Act fully in force
DESCRIPTION:Provisions establishing the AI Strategy Headquarters and AI Bas
 ic Plan take effect.\n\nAct on Promotion of Research and Development\, and
  Utilization of Artificial Intelligence-Related Technology (Japan)\n\nSour
 ce: https://www8.cao.go.jp/cstp/ai/ai_act/ai_act.html\n\nhttps://rulebook.
 fru.dev/regulations/jp-ai-act
URL:https://rulebook.fru.dev/regulations/jp-ai-act
CATEGORIES:Japan,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-109@regulations.fru.dev
DTSTAMP:20260924T142439Z
DTSTART;VALUE=DATE:20250903
DTEND;VALUE=DATE:20250904
SUMMARY:EU-US Data Privacy Framework: General Court upholds DPF (Latombe v 
 Commission)
DESCRIPTION:General Court dismissed Philippe Latombe's action for annulment
  (Case T-553/23) and confirmed the US offered adequate protection when the
  decision was adopted.\n\nCommission Implementing Decision (EU) 2023/1795 
 on the adequate level of protection of personal data under the EU-US Data 
 Privacy Framework (European Union)\n\nSource: https://curia.europa.eu/jcms
 /upload/docs/application/pdf/2025-09/cp250106en.pdf\n\nhttps://rulebook.fr
 u.dev/regulations/eu-us-dpf
URL:https://rulebook.fru.dev/regulations/eu-us-dpf
CATEGORIES:European Union,privacy,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-57@regulations.fru.dev
DTSTAMP:20260924T142439Z
DTSTART;VALUE=DATE:20250912
DTEND;VALUE=DATE:20250913
SUMMARY:EU Data Act: Data Act applies
DESCRIPTION:Most obligations apply\, including user data access and sharing
  (Chapters II-III)\, cloud switching (Chapter VI) and interoperability\; C
 hapter IV unfair terms apply to contracts concluded after this date (Art 5
 0).\n\nRegulation (EU) 2023/2854 on harmonised rules on fair access to and
  use of data (Data Act) (European Union)\n\nSource: https://eur-lex.europa
 .eu/eli/reg/2023/2854/oj\n\nhttps://rulebook.fru.dev/regulations/eu-data-a
 ct
URL:https://rulebook.fru.dev/regulations/eu-data-act
CATEGORIES:European Union,data-access,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-58@regulations.fru.dev
DTSTAMP:20260924T142439Z
DTSTART;VALUE=DATE:20250912
DTEND;VALUE=DATE:20250913
SUMMARY:EU Data Act: Member States notify penalty rules
DESCRIPTION:Member States had to notify the Commission of their penalty rul
 es (Art 40(2)).\n\nRegulation (EU) 2023/2854 on harmonised rules on fair a
 ccess to and use of data (Data Act) (European Union)\n\nSource: https://eu
 r-lex.europa.eu/eli/reg/2023/2854/oj\n\nhttps://rulebook.fru.dev/regulatio
 ns/eu-data-act
URL:https://rulebook.fru.dev/regulations/eu-data-act
CATEGORIES:European Union,data-access,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-133@regulations.fru.dev
DTSTAMP:20260924T142439Z
DTSTART;VALUE=DATE:20250919
DTEND;VALUE=DATE:20250920
SUMMARY:Nigeria NDPA: GAID 2025 takes effect
DESCRIPTION:General Application and Implementation Directive becomes effect
 ive\, replacing the NDPR 2019 and NDPR Implementation Framework.\n\nNigeri
 a Data Protection Act\, 2023 and NDPA General Application and Implementati
 on Directive (GAID) 2025 (Nigeria)\n\nSource: https://ndpc.gov.ng/resource
 s/\n\nhttps://rulebook.fru.dev/regulations/ng-ndpa
URL:https://rulebook.fru.dev/regulations/ng-ndpa
CATEGORIES:Nigeria,privacy,breach-notification,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-167@regulations.fru.dev
DTSTAMP:20260924T142439Z
DTSTART;VALUE=DATE:20250922
DTEND;VALUE=DATE:20250923
SUMMARY:CCPA / CPRA: ADMT\, risk assessment and cybersecurity audit regulat
 ions approved
DESCRIPTION:OAL approves the CCPA Updates\, Cybersecurity Audit\, Risk Asse
 ssment\, ADMT and Insurance regulations and files them with the Secretary 
 of State.\n\nCalifornia Consumer Privacy Act of 2018\, as amended by the C
 alifornia Privacy Rights Act of 2020 (Cal. Civ. Code 1798.100 et seq.) and
  CPPA regulations (Cal. Code Regs. tit. 11\, 7000 et seq.) (California)\n\
 nSource: https://cppa.ca.gov/regulations/ccpa_updates.html\n\nhttps://rule
 book.fru.dev/regulations/us-ca-ccpa
URL:https://rulebook.fru.dev/regulations/us-ca-ccpa
CATEGORIES:California,privacy,ai,cybersecurity,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-65@regulations.fru.dev
DTSTAMP:20260924T142439Z
DTSTART;VALUE=DATE:20250924
DTEND;VALUE=DATE:20250925
SUMMARY:Data Governance Act: Legacy data intermediaries must comply
DESCRIPTION:Entities that were already providing data intermediation servic
 es on 23 June 2022 had to comply with Chapter III by 24 Sep 2025 (Art 37).
 \n\nRegulation (EU) 2022/868 on European data governance (Data Governance 
 Act) (European Union)\n\nSource: https://eur-lex.europa.eu/eli/reg/2022/86
 8/oj\n\nhttps://rulebook.fru.dev/regulations/eu-dga
URL:https://rulebook.fru.dev/regulations/eu-dga
CATEGORIES:European Union,data-access,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-135@regulations.fru.dev
DTSTAMP:20260924T142439Z
DTSTART;VALUE=DATE:20250924
DTEND;VALUE=DATE:20250925
SUMMARY:New Zealand Privacy Act: Privacy Amendment Act 2025 technical chang
 es commence
DESCRIPTION:Technical amendments commence the day after Royal Assent (23 Se
 p 2025).\n\nPrivacy Act 2020 (New Zealand)\, as amended by the Privacy Ame
 ndment Act 2025 (New Zealand)\n\nSource: https://www.justice.govt.nz/justi
 ce-sector-policy/key-initiatives/enhancing-the-privacy-act/\n\nhttps://rul
 ebook.fru.dev/regulations/nz-privacy-act
URL:https://rulebook.fru.dev/regulations/nz-privacy-act
CATEGORIES:New Zealand,privacy,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-184@regulations.fru.dev
DTSTAMP:20260924T142439Z
DTSTART;VALUE=DATE:20250929
DTEND;VALUE=DATE:20250930
SUMMARY:California SB 53 (TFAIA): SB 53 signed
DESCRIPTION:Governor Newsom signs SB 53 (chapter 138).\n\nCalifornia SB 53\
 , Transparency in Frontier Artificial Intelligence Act (Stats. 2025\, ch. 
 138) (California)\n\nSource: https://leginfo.legislature.ca.gov/faces/bill
 NavClient.xhtml?bill_id=202520260SB53\n\nhttps://rulebook.fru.dev/regulati
 ons/us-ca-sb53
URL:https://rulebook.fru.dev/regulations/us-ca-sb53
CATEGORIES:California,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-212@regulations.fru.dev
DTSTAMP:20260924T142439Z
DTSTART;VALUE=DATE:20251001
DTEND;VALUE=DATE:20251002
SUMMARY:Colorado Privacy Act (CPA): Minors' data amendment (SB 24-041) effe
 ctive
DESCRIPTION:Controllers offering online services to minors must use reasona
 ble care\, conduct assessments\, and obtain consent for targeted ads\, sal
 e and certain profiling of minors.\n\nColorado Privacy Act (SB 21-190)\, C
 .R.S. 6-1-1301 et seq.\, as amended by HB 24-1130\, SB 24-041 and SB 25-27
 6 (Colorado)\n\nSource: https://leg.colorado.gov/bills/sb24-041\n\nhttps:/
 /rulebook.fru.dev/regulations/us-co-cpa
URL:https://rulebook.fru.dev/regulations/us-co-cpa
CATEGORIES:Colorado,privacy,children,biometrics
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-252@regulations.fru.dev
DTSTAMP:20260924T142439Z
DTSTART;VALUE=DATE:20251001
DTEND;VALUE=DATE:20251002
SUMMARY:Maryland Online Data Privacy Act (MODPA): MODPA takes effect
DESCRIPTION:Act takes effect\; data protection assessments apply to process
 ing activities on or after Oct 1\, 2025.\n\nMaryland Online Data Privacy A
 ct of 2024 (SB 541 / HB 567)\, Md. Code\, Com. Law 14-4601 et seq. (Maryla
 nd)\n\nSource: https://mgaleg.maryland.gov/2024RS/Chapters_noln/CH_455_sb0
 541e.pdf\n\nhttps://rulebook.fru.dev/regulations/us-md-modpa
URL:https://rulebook.fru.dev/regulations/us-md-modpa
CATEGORIES:Maryland,privacy,children,health,biometrics
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-259@regulations.fru.dev
DTSTAMP:20260924T142439Z
DTSTART;VALUE=DATE:20251001
DTEND;VALUE=DATE:20251002
SUMMARY:Montana Consumer Data Privacy Act (MCDPA): SB 297 amendments take e
 ffect\; cure period eliminated
DESCRIPTION:Lower thresholds (25\,000 / 15\,000 + 25%)\, minors' data prote
 ctions\, AG assessment demands\; the 60-day cure period is removed.\n\nMon
 tana Consumer Data Privacy Act (SB 384\, 2023)\, Mont. Code Ann. 30-14-280
 1 et seq.\, as amended by SB 297 (2025) (Montana)\n\nSource: https://archi
 ve.legmt.gov/bills/mca/title_0300/chapter_0140/part_0280/section_0170/0300
 -0140-0280-0170.html\n\nhttps://rulebook.fru.dev/regulations/us-mt-mcdpa
URL:https://rulebook.fru.dev/regulations/us-mt-mcdpa
CATEGORIES:Montana,privacy,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-228@regulations.fru.dev
DTSTAMP:20260924T142439Z
DTSTART;VALUE=DATE:20251006
DTEND;VALUE=DATE:20251007
SUMMARY:DOJ Bulk Data Rule: Due diligence\, audit and reporting obligations
  apply
DESCRIPTION:Subpart J (data compliance program\, due diligence and audits f
 or restricted transactions) and reporting requirements in 202.1103 and 202
 .1104 apply.\n\nPreventing Access to U.S. Sensitive Personal Data and Gove
 rnment-Related Data by Countries of Concern or Covered Persons (28 CFR Par
 t 202) - DOJ Data Security Program (United States (Federal))\n\nSource: ht
 tps://www.federalregister.gov/documents/2025/01/08/2024-31486/preventing-a
 ccess-to-us-sensitive-personal-data-and-government-related-data-by-countri
 es-of-concern\n\nhttps://rulebook.fru.dev/regulations/us-doj-bulk-data
URL:https://rulebook.fru.dev/regulations/us-doj-bulk-data
CATEGORIES:United States (Federal),privacy,data-residency,cybersecurity,bio
 metrics,health,financial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-188@regulations.fru.dev
DTSTAMP:20260924T142439Z
DTSTART;VALUE=DATE:20251013
DTEND;VALUE=DATE:20251014
SUMMARY:California AI Transparency Act (SB 942): AB 853 signed
DESCRIPTION:AB 853 (ch. 674) delays the operative date and adds platform an
 d device duties.\n\nCalifornia AI Transparency Act (SB 942\, Stats. 2024\,
  ch. 291)\, as amended by AB 853 (Stats. 2025\, ch. 674) (California)\n\nS
 ource: https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_i
 d=202520260AB853\n\nhttps://rulebook.fru.dev/regulations/us-ca-sb942
URL:https://rulebook.fru.dev/regulations/us-ca-sb942
CATEGORIES:California,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-181@regulations.fru.dev
DTSTAMP:20260924T142439Z
DTSTART;VALUE=DATE:20251013
DTEND;VALUE=DATE:20251014
SUMMARY:California SB 243 (companion chatbots): SB 243 signed
DESCRIPTION:SB 243 chaptered (ch. 677).\n\nCalifornia SB 243\, Companion Ch
 atbots (Stats. 2025\, ch. 677) (California)\n\nSource: https://leginfo.leg
 islature.ca.gov/faces/billNavClient.xhtml?bill_id=202520260SB243\n\nhttps:
 //rulebook.fru.dev/regulations/us-ca-sb243
URL:https://rulebook.fru.dev/regulations/us-ca-sb243
CATEGORIES:California,ai,children,online-safety
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-110@regulations.fru.dev
DTSTAMP:20260924T142439Z
DTSTART;VALUE=DATE:20251031
DTEND;VALUE=DATE:20251101
SUMMARY:EU-US Data Privacy Framework: Latombe appeal lodged at the Court of
  Justice
DESCRIPTION:Latombe appealed the General Court judgment to the Court of Jus
 tice on points of law (reported as Case C-703/25 P)\; the DPF stays valid 
 while it is pending.\n\nCommission Implementing Decision (EU) 2023/1795 on
  the adequate level of protection of personal data under the EU-US Data Pr
 ivacy Framework (European Union)\n\nSource: https://www.wilmerhale.com/en/
 insights/blogs/wilmerhale-privacy-and-cybersecurity-law/20251201-european-
 court-of-justice-to-review-challenge-to-eu-us-data-privacy-framework\n\nht
 tps://rulebook.fru.dev/regulations/eu-us-dpf
URL:https://rulebook.fru.dev/regulations/eu-us-dpf
CATEGORIES:European Union,privacy,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-276@regulations.fru.dev
DTSTAMP:20260924T142439Z
DTSTART;VALUE=DATE:20251101
DTEND;VALUE=DATE:20251102
SUMMARY:NYDFS Cybersecurity Regulation (Part 500): Universal MFA and asset 
 inventory
DESCRIPTION:500.12 multi-factor authentication for all users and 500.13(a) 
 asset inventory requirements apply.\n\nNew York DFS Cybersecurity Requirem
 ents for Financial Services Companies (23 NYCRR Part 500)\, Second Amendme
 nt (New York)\n\nSource: https://www.dfs.ny.gov/cybersecurity/23-NYCRR-Par
 t-500\n\nhttps://rulebook.fru.dev/regulations/us-ny-dfs-500
URL:https://rulebook.fru.dev/regulations/us-ny-dfs-500
CATEGORIES:New York,cybersecurity,breach-notification,financial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-195@regulations.fru.dev
DTSTAMP:20260924T142439Z
DTSTART;VALUE=DATE:20251110
DTEND;VALUE=DATE:20251111
SUMMARY:CMMC 2.0: DFARS rule effective\; Phase 1 begins
DESCRIPTION:CMMC Level 1 and Level 2 self-assessment requirements begin app
 earing in applicable DoD solicitations and contracts (32 CFR 170.3(e)(1)).
 \n\nCybersecurity Maturity Model Certification (CMMC) Program (32 CFR Part
  170) and DFARS acquisition rule (48 CFR Parts 204\, 212\, 217\, 252) (Uni
 ted States (Federal))\n\nSource: https://www.federalregister.gov/documents
 /2025/09/10/2025-17359/defense-federal-acquisition-regulation-supplement-a
 ssessing-contractor-implementation-of\n\nhttps://rulebook.fru.dev/regulati
 ons/us-cmmc
URL:https://rulebook.fru.dev/regulations/us-cmmc
CATEGORIES:United States (Federal),cybersecurity
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-145@regulations.fru.dev
DTSTAMP:20260924T142439Z
DTSTART;VALUE=DATE:20251112
DTEND;VALUE=DATE:20251113
SUMMARY:UK Cyber Security and Resilience Bill: Introduced (Commons first re
 ading)
DESCRIPTION:Bill introduced in the House of Commons.\n\nCyber Security and 
 Resilience (Network and Information Systems) Bill (United Kingdom)\n\nSour
 ce: https://bills.parliament.uk/bills/4035\n\nhttps://rulebook.fru.dev/reg
 ulations/uk-csr-bill
URL:https://rulebook.fru.dev/regulations/uk-csr-bill
CATEGORIES:United Kingdom,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-116@regulations.fru.dev
DTSTAMP:20260924T142439Z
DTSTART;VALUE=DATE:20251113
DTEND;VALUE=DATE:20251114
SUMMARY:India DPDP Act: DPDP Rules published\; Board and procedural rules i
 n force
DESCRIPTION:Rules 1\, 2 and 17-21 (Data Protection Board constitution and f
 unctioning) take effect on publication in the Official Gazette.\n\nDigital
  Personal Data Protection Act\, 2023 and Digital Personal Data Protection 
 Rules\, 2025 (India)\n\nSource: https://egazette.gov.in/WriteReadData/2025
 /267650.pdf\n\nhttps://rulebook.fru.dev/regulations/in-dpdp
URL:https://rulebook.fru.dev/regulations/in-dpdp
CATEGORIES:India,privacy,children,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-74@regulations.fru.dev
DTSTAMP:20260924T142439Z
DTSTART;VALUE=DATE:20251118
DTEND;VALUE=DATE:20251119
SUMMARY:DORA: First critical ICT third-party providers designated
DESCRIPTION:The ESAs published the first list of 19 critical ICT third-part
 y providers (including AWS\, Google Cloud and Microsoft)\, which now come 
 under direct EU oversight.\n\nRegulation (EU) 2022/2554 on digital operati
 onal resilience for the financial sector (Digital Operational Resilience A
 ct) (European Union)\n\nSource: https://www.eba.europa.eu/publications-and
 -media/press-releases/european-supervisory-authorities-designate-critical-
 ict-third-party-providers-under-digital\n\nhttps://rulebook.fru.dev/regula
 tions/eu-dora
URL:https://rulebook.fru.dev/regulations/eu-dora
CATEGORIES:European Union,cybersecurity,financial,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-95@regulations.fru.dev
DTSTAMP:20260924T142439Z
DTSTART;VALUE=DATE:20251126
DTEND;VALUE=DATE:20251127
SUMMARY:GDPR: GDPR Procedural Regulation adopted
DESCRIPTION:Regulation (EU) 2025/2518 laying down additional procedural rul
 es for cross-border GDPR enforcement signed by Parliament and Council.\n\n
 Regulation (EU) 2016/679 (General Data Protection Regulation) (European Un
 ion)\n\nSource: https://eur-lex.europa.eu/eli/reg/2025/2518/oj\n\nhttps://
 rulebook.fru.dev/regulations/eu-gdpr
URL:https://rulebook.fru.dev/regulations/eu-gdpr
CATEGORIES:European Union,privacy,breach-notification,data-access,children,
 biometrics,health
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-296@regulations.fru.dev
DTSTAMP:20260924T142439Z
DTSTART;VALUE=DATE:20251203
DTEND;VALUE=DATE:20251204
SUMMARY:SEC Regulation S-P: Larger entities must comply
DESCRIPTION:Larger covered institutions (18 months after Federal Register p
 ublication) must have incident response programs\, 30-day customer notific
 ation\, and service-provider oversight in place.\n\nRegulation S-P: Privac
 y of Consumer Financial Information and Safeguarding Customer Information 
 (2024 amendments) (United States (Federal))\n\nSource: https://www.federal
 register.gov/documents/2024/06/03/2024-11116/regulation-s-p-privacy-of-con
 sumer-financial-information-and-safeguarding-customer-information\n\nhttps
 ://rulebook.fru.dev/regulations/us-sec-reg-sp
URL:https://rulebook.fru.dev/regulations/us-sec-reg-sp
CATEGORIES:United States (Federal),financial,privacy,cybersecurity,breach-n
 otification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-8@regulations.fru.dev
DTSTAMP:20260924T142439Z
DTSTART;VALUE=DATE:20251210
DTEND;VALUE=DATE:20251211
SUMMARY:Australia Social Media Minimum Age: Social media minimum age obliga
 tion applies
DESCRIPTION:Age-restricted platforms must take reasonable steps to prevent 
 under-16s from holding accounts.\n\nOnline Safety Amendment (Social Media 
 Minimum Age) Act 2024 (Australia)\n\nSource: https://www.legislation.gov.a
 u/C2024A00127/asmade\n\nhttps://rulebook.fru.dev/regulations/au-social-med
 ia-min-age
URL:https://rulebook.fru.dev/regulations/au-social-media-min-age
CATEGORIES:Australia,children,online-safety
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-278@regulations.fru.dev
DTSTAMP:20260924T142439Z
DTSTART;VALUE=DATE:20251219
DTEND;VALUE=DATE:20251220
SUMMARY:NY RAISE Act: RAISE Act signed
DESCRIPTION:Governor Hochul signs the RAISE Act with an agreed chapter amen
 dment.\n\nNew York Responsible AI Safety and Education (RAISE) Act (S6953-
 B/A6453-B of 2025)\, as amended by chapter amendment S8828 of 2026 (New Yo
 rk)\n\nSource: https://www.governor.ny.gov/news/governor-hochul-signs-nati
 on-leading-legislation-require-ai-frameworks-ai-frontier-models\n\nhttps:/
 /rulebook.fru.dev/regulations/us-ny-raise
URL:https://rulebook.fru.dev/regulations/us-ny-raise
CATEGORIES:New York,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-224@regulations.fru.dev
DTSTAMP:20260924T142439Z
DTSTART;VALUE=DATE:20251231
DTEND;VALUE=DATE:20260101
SUMMARY:Delaware Personal Data Privacy Act (DPDPA): Mandatory 60-day cure p
 eriod expires
DESCRIPTION:Mandatory notice-and-cure ends Dec 31\, 2025\; from Jan 1\, 202
 6 DOJ decides whether to offer a cure using statutory factors.\n\nDelaware
  Personal Data Privacy Act (HB 154)\, 6 Del. C. ch. 12D (Delaware)\n\nSour
 ce: https://delcode.delaware.gov/title6/c012d/index.html\n\nhttps://rulebo
 ok.fru.dev/regulations/us-de-dpdpa
URL:https://rulebook.fru.dev/regulations/us-de-dpdpa
CATEGORIES:Delaware,privacy,children
TRANSP:TRANSPARENT
END:VEVENT
END:VCALENDAR
