BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//fru.dev//Rulebook//EN
CALSCALE:GREGORIAN
METHOD:PUBLISH
X-WR-CALNAME:Regulation deadlines (Rulebook)
X-WR-CALDESC:Compliance deadlines tracked at rulebook.fru.dev
REFRESH-INTERVAL;VALUE=DURATION:P1D
X-PUBLISHED-TTL:P1D
BEGIN:VEVENT
UID:deadline-191@regulations.fru.dev
DTSTAMP:20260924T132330Z
DTSTART;VALUE=DATE:20270101
DTEND;VALUE=DATE:20270102
SUMMARY:California AI Transparency Act (SB 942): Large online platform and 
 hosting platform duties
DESCRIPTION:Large online platforms and GenAI hosting platforms must meet th
 e provenance duties added by AB 853.\n\nCalifornia AI Transparency Act (SB
  942\, Stats. 2024\, ch. 291)\, as amended by AB 853 (Stats. 2025\, ch. 67
 4) (California)\n\nSource: https://leginfo.legislature.ca.gov/faces/billNa
 vClient.xhtml?bill_id=202520260AB853\n\nhttps://rulebook.fru.dev/regulatio
 ns/us-ca-sb942
URL:https://rulebook.fru.dev/regulations/us-ca-sb942
CATEGORIES:California,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-186@regulations.fru.dev
DTSTAMP:20260924T132330Z
DTSTART;VALUE=DATE:20270101
DTEND;VALUE=DATE:20270102
SUMMARY:California SB 53 (TFAIA): First OES anonymized incident report and 
 CDT definition review
DESCRIPTION:OES begins publishing annual anonymized incident summaries and 
 the Department of Technology begins annual review of the act's definitions
 \; the CalCompute framework report is due to the Legislature.\n\nCaliforni
 a SB 53\, Transparency in Frontier Artificial Intelligence Act (Stats. 202
 5\, ch. 138) (California)\n\nSource: https://leginfo.legislature.ca.gov/fa
 ces/billNavClient.xhtml?bill_id=202520260SB53\n\nhttps://rulebook.fru.dev/
 regulations/us-ca-sb53
URL:https://rulebook.fru.dev/regulations/us-ca-sb53
CATEGORIES:California,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-169@regulations.fru.dev
DTSTAMP:20260924T132330Z
DTSTART;VALUE=DATE:20270101
DTEND;VALUE=DATE:20270102
SUMMARY:CCPA / CPRA: ADMT requirements compliance date
DESCRIPTION:Businesses using ADMT for significant decisions must comply wit
 h Article 11 (pre-use notice\, opt-out\, access rights) by this date (11 C
 CR 7200(b)).\n\nCalifornia Consumer Privacy Act of 2018\, as amended by th
 e California Privacy Rights Act of 2020 (Cal. Civ. Code 1798.100 et seq.) 
 and CPPA regulations (Cal. Code Regs. tit. 11\, 7000 et seq.) (California)
 \n\nSource: https://cppa.ca.gov/regulations/pdf/ccpa_updates_cyber_risk_ad
 mt_appr_text.pdf\n\nhttps://rulebook.fru.dev/regulations/us-ca-ccpa
URL:https://rulebook.fru.dev/regulations/us-ca-ccpa
CATEGORIES:California,privacy,ai,cybersecurity,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-170@regulations.fru.dev
DTSTAMP:20260924T132330Z
DTSTART;VALUE=DATE:20270101
DTEND;VALUE=DATE:20270102
SUMMARY:CCPA / CPRA: Browsers must support opt-out preference signal (AB 56
 6)
DESCRIPTION:Businesses that develop or maintain a browser must include cons
 umer-configurable functionality to send an opt-out preference signal (Civ.
  Code 1798.136\, operative Jan 1\, 2027).\n\nCalifornia Consumer Privacy A
 ct of 2018\, as amended by the California Privacy Rights Act of 2020 (Cal.
  Civ. Code 1798.100 et seq.) and CPPA regulations (Cal. Code Regs. tit. 11
 \, 7000 et seq.) (California)\n\nSource: https://leginfo.legislature.ca.go
 v/faces/billStatusClient.xhtml?bill_id=202520260AB566\n\nhttps://rulebook.
 fru.dev/regulations/us-ca-ccpa
URL:https://rulebook.fru.dev/regulations/us-ca-ccpa
CATEGORIES:California,privacy,ai,cybersecurity,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-204@regulations.fru.dev
DTSTAMP:20260924T132330Z
DTSTART;VALUE=DATE:20270101
DTEND;VALUE=DATE:20270102
SUMMARY:Colorado AI Act: ADMT obligations apply
DESCRIPTION:Developer documentation\, consumer notices\, post-adverse-outco
 me disclosure\, correction and human-review rights take effect.\n\nColorad
 o SB 24-205 (Consumer Protections for Artificial Intelligence)\, as delaye
 d by SB 25B-004 and repealed and reenacted by SB 26-189 (Automated Decisio
 n-Making Technology) (Colorado)\n\nSource: https://leg.colorado.gov/bills/
 sb26-189\n\nhttps://rulebook.fru.dev/regulations/us-co-ai-act
URL:https://rulebook.fru.dev/regulations/us-co-ai-act
CATEGORIES:Colorado,ai,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-205@regulations.fru.dev
DTSTAMP:20260924T132330Z
DTSTART;VALUE=DATE:20270101
DTEND;VALUE=DATE:20270102
SUMMARY:Colorado AI Act: AG rules due
DESCRIPTION:Attorney General must adopt rules clarifying the post-adverse-o
 utcome disclosure requirements.\n\nColorado SB 24-205 (Consumer Protection
 s for Artificial Intelligence)\, as delayed by SB 25B-004 and repealed and
  reenacted by SB 26-189 (Automated Decision-Making Technology) (Colorado)\
 n\nSource: https://leg.colorado.gov/bills/sb26-189\n\nhttps://rulebook.fru
 .dev/regulations/us-co-ai-act
URL:https://rulebook.fru.dev/regulations/us-co-ai-act
CATEGORIES:Colorado,ai,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-221@regulations.fru.dev
DTSTAMP:20260924T132330Z
DTSTART;VALUE=DATE:20270101
DTEND;VALUE=DATE:20270102
SUMMARY:Connecticut Data Privacy Act (CTDPA): Data broker registration requ
 ired
DESCRIPTION:Data brokers may not sell or license brokered personal data in 
 Connecticut unless registered with the Department of Consumer Protection (
 $2\,500 initial fee).\n\nConnecticut Data Privacy Act (Public Act 22-15)\,
  Conn. Gen. Stat. 42-515 et seq.\, as amended by Public Act 25-113 (SB 129
 5) and Public Act 26-64 (SB 4) (Connecticut)\n\nSource: https://www.cga.ct
 .gov/2026/ACT/PA/PDF/2026PA-00064-R00SB-00004-PA.PDF\n\nhttps://rulebook.f
 ru.dev/regulations/us-ct-ctdpa
URL:https://rulebook.fru.dev/regulations/us-ct-ctdpa
CATEGORIES:Connecticut,privacy,children,ai,health
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-226@regulations.fru.dev
DTSTAMP:20260924T132330Z
DTSTART;VALUE=DATE:20270101
DTEND;VALUE=DATE:20270102
SUMMARY:Delaware Personal Data Privacy Act (DPDPA): Amended thresholds and 
 third-party duties take effect
DESCRIPTION:Applicability drops to 10\,000 consumers (or 5\,000 + 20% reven
 ue from sale) and new third-party duties (12D-107A) apply.\n\nDelaware Per
 sonal Data Privacy Act (HB 154)\, 6 Del. C. ch. 12D (Delaware)\n\nSource: 
 https://delcode.delaware.gov/title6/c012d/index.html\n\nhttps://rulebook.f
 ru.dev/regulations/us-de-dpdpa
URL:https://rulebook.fru.dev/regulations/us-de-dpdpa
CATEGORIES:Delaware,privacy,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-250@regulations.fru.dev
DTSTAMP:20260924T132330Z
DTSTART;VALUE=DATE:20270101
DTEND;VALUE=DATE:20270102
SUMMARY:Louisiana Data Privacy Act: Louisiana Data Privacy Act takes effect
DESCRIPTION:Consumer rights and controller duties apply (Act 502\, Section 
 2)\; data protection assessment requirements apply to processing from this
  date.\n\nLouisiana Data Privacy Act (SB 386\, 2026 Regular Session\, Act 
 No. 502)\, La. R.S. 51:1780.1-1780.5 (Louisiana)\n\nSource: https://legis.
 la.gov/legis/ViewDocument.aspx?d=1480202\n\nhttps://rulebook.fru.dev/regul
 ations/us-la-ldpa
URL:https://rulebook.fru.dev/regulations/us-la-ldpa
CATEGORIES:Louisiana,privacy,biometrics
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-263@regulations.fru.dev
DTSTAMP:20260924T132330Z
DTSTART;VALUE=DATE:20270101
DTEND;VALUE=DATE:20270102
SUMMARY:New Hampshire Privacy Act: Ban on selling personal data of children
  under 13 (HB 1460)
DESCRIPTION:HB 1460 (2026\, ch. 168) prohibits controllers from selling the
  personal data of a child under 13.\n\nNew Hampshire Privacy Act (SB 255\,
  2024)\, RSA chapter 507-H (New Hampshire)\n\nSource: https://gc.nh.gov/bi
 ll_status/billinfo.aspx?id=2443&inflect=2\n\nhttps://rulebook.fru.dev/regu
 lations/us-nh-privacy
URL:https://rulebook.fru.dev/regulations/us-nh-privacy
CATEGORIES:New Hampshire,privacy,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-280@regulations.fru.dev
DTSTAMP:20260924T132330Z
DTSTART;VALUE=DATE:20270101
DTEND;VALUE=DATE:20270102
SUMMARY:NY RAISE Act: RAISE Act takes effect
DESCRIPTION:Transparency reports\, frontier AI frameworks\, incident report
 ing and DFS disclosure filings apply.\n\nNew York Responsible AI Safety an
 d Education (RAISE) Act (S6953-B/A6453-B of 2025)\, as amended by chapter 
 amendment S8828 of 2026 (New York)\n\nSource: https://www.nysenate.gov/leg
 islation/bills/2025/S8828\n\nhttps://rulebook.fru.dev/regulations/us-ny-ra
 ise
URL:https://rulebook.fru.dev/regulations/us-ny-raise
CATEGORIES:New York,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-282@regulations.fru.dev
DTSTAMP:20260924T132330Z
DTSTART;VALUE=DATE:20270101
DTEND;VALUE=DATE:20270102
SUMMARY:Oklahoma OKCDPA: Oklahoma Consumer Data Privacy Act takes effect
DESCRIPTION:All OKCDPA obligations and consumer rights apply.\n\nOklahoma C
 onsumer Data Privacy Act (SB 546\, 2026) (Oklahoma)\n\nSource: https://www
 .okhouse.gov/posts/news-20260323_2\n\nhttps://rulebook.fru.dev/regulations
 /us-ok-okcdpa
URL:https://rulebook.fru.dev/regulations/us-ok-okcdpa
CATEGORIES:Oklahoma,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-310@regulations.fru.dev
DTSTAMP:20260924T132330Z
DTSTART;VALUE=DATE:20270101
DTEND;VALUE=DATE:20270102
SUMMARY:Utah UCPA: UCPA extends to motor vehicle manufacturers
DESCRIPTION:Motor vehicle manufacturers whose vehicles are sold or leased i
 n Utah and that collect personal data through vehicle data systems are cov
 ered regardless of the revenue and consumer thresholds (13-61-102\, as ame
 nded by Laws 2026\, ch. 193).\n\nUtah Consumer Privacy Act (SB 227\, 2022)
  (Utah)\n\nSource: https://le.utah.gov/xcode/Title13/Chapter61/13-61-S102.
 html\n\nhttps://rulebook.fru.dev/regulations/us-ut-ucpa
URL:https://rulebook.fru.dev/regulations/us-ut-ucpa
CATEGORIES:Utah,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-60@regulations.fru.dev
DTSTAMP:20260924T132330Z
DTSTART;VALUE=DATE:20270112
DTEND;VALUE=DATE:20270113
SUMMARY:EU Data Act: Cloud switching charges abolished
DESCRIPTION:Providers of data processing services may no longer impose any 
 switching charges on customers (Art 29(1)).\n\nRegulation (EU) 2023/2854 o
 n harmonised rules on fair access to and use of data (Data Act) (European 
 Union)\n\nSource: https://eur-lex.europa.eu/eli/reg/2023/2854/oj\n\nhttps:
 //rulebook.fru.dev/regulations/eu-data-act
URL:https://rulebook.fru.dev/regulations/eu-data-act
CATEGORIES:European Union,data-access,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-114@regulations.fru.dev
DTSTAMP:20260924T132330Z
DTSTART;VALUE=DATE:20270116
DTEND;VALUE=DATE:20270117
SUMMARY:Indonesia PDP Law: Implementing regulation GR 33/2026 takes effect
DESCRIPTION:Detailed PDP implementing rules (DPIA\, cross-border\, children
 's consent) apply\, 6 months after the 16 Jul 2026 enactment.\n\nLaw No. 2
 7 of 2022 on Personal Data Protection (Undang-Undang Pelindungan Data Prib
 adi) (Indonesia)\n\nSource: https://www.kk-advocates.com/news/read/indones
 ia-gr-pdp-personal-data-protection-compliance-regime-new-phase\n\nhttps://
 rulebook.fru.dev/regulations/id-pdp
URL:https://rulebook.fru.dev/regulations/id-pdp
CATEGORIES:Indonesia,privacy,breach-notification,data-residency,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-179@regulations.fru.dev
DTSTAMP:20260924T132330Z
DTSTART;VALUE=DATE:20270131
DTEND;VALUE=DATE:20270201
SUMMARY:California Delete Act / DROP: Annual data broker registration deadl
 ine
DESCRIPTION:Data brokers must renew registration with CalPrivacy by January
  31 following each year they meet the definition.\n\nCalifornia Delete Act
  (SB 362\, 2023)\, Cal. Civ. Code 1798.99.80 et seq.\, and DROP regulation
 s (California)\n\nSource: https://leginfo.legislature.ca.gov/faces/codes_d
 isplaySection.xhtml?lawCode=CIV&sectionNum=1798.99.82\n\nhttps://rulebook.
 fru.dev/regulations/us-ca-delete-act
URL:https://rulebook.fru.dev/regulations/us-ca-delete-act
CATEGORIES:California,privacy,data-access
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-322@regulations.fru.dev
DTSTAMP:20260924T132330Z
DTSTART;VALUE=DATE:20270301
DTEND;VALUE=DATE:20270302
SUMMARY:Vietnam AI Law: Transition ends for existing AI systems (general)
DESCRIPTION:Existing AI systems in most sectors must comply (12-month trans
 ition).\n\nLaw on Artificial Intelligence (Law No. 134/2025/QH15) (Vietnam
 )\n\nSource: https://www.vilaf.com.vn/blog/vietnam-enacts-its-first-law-on
 -artificial-intelligence-key-regulatory-obligations-from-1-march-2026/\n\n
 https://rulebook.fru.dev/regulations/vn-ai-law
URL:https://rulebook.fru.dev/regulations/vn-ai-law
CATEGORIES:Vietnam,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-81@regulations.fru.dev
DTSTAMP:20260924T132330Z
DTSTART;VALUE=DATE:20270326
DTEND;VALUE=DATE:20270327
SUMMARY:European Health Data Space (EHDS): EHDS general application date
DESCRIPTION:The regulation applies generally from 26 Mar 2027\, subject to 
 the phased exceptions below (final article).\n\nRegulation (EU) 2025/327 o
 n the European Health Data Space (European Union)\n\nSource: https://eur-l
 ex.europa.eu/eli/reg/2025/327/oj\n\nhttps://rulebook.fru.dev/regulations/e
 u-ehds
URL:https://rulebook.fru.dev/regulations/eu-ehds
CATEGORIES:European Union,health,privacy,data-access
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-254@regulations.fru.dev
DTSTAMP:20260924T132330Z
DTSTART;VALUE=DATE:20270401
DTEND;VALUE=DATE:20270402
SUMMARY:Maryland Online Data Privacy Act (MODPA): Discretionary 60-day cure
  period ends
DESCRIPTION:The Division's discretionary notice-and-cure (at least 60 days)
  applies only to violations occurring on or before April 1\, 2027 (Com. La
 w 14-4614).\n\nMaryland Online Data Privacy Act of 2024 (SB 541 / HB 567)\
 , Md. Code\, Com. Law 14-4601 et seq. (Maryland)\n\nSource: https://mgaleg
 .maryland.gov/2024RS/Chapters_noln/CH_455_sb0541e.pdf\n\nhttps://rulebook.
 fru.dev/regulations/us-md-modpa
URL:https://rulebook.fru.dev/regulations/us-md-modpa
CATEGORIES:Maryland,privacy,children,health,biometrics
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-97@regulations.fru.dev
DTSTAMP:20260924T132330Z
DTSTART;VALUE=DATE:20270402
DTEND;VALUE=DATE:20270403
SUMMARY:GDPR: GDPR Procedural Regulation applies
DESCRIPTION:Harmonised rules for cross-border complaint admissibility\, rig
 hts to be heard and access to preliminary findings\, and investigation tim
 elines apply to DPAs from 2 April 2027 (Regulation (EU) 2025/2518\, final 
 article).\n\nRegulation (EU) 2016/679 (General Data Protection Regulation)
  (European Union)\n\nSource: https://eur-lex.europa.eu/eli/reg/2025/2518/o
 j\n\nhttps://rulebook.fru.dev/regulations/eu-gdpr
URL:https://rulebook.fru.dev/regulations/eu-gdpr
CATEGORIES:European Union,privacy,breach-notification,data-access,children,
 biometrics,health
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-104@regulations.fru.dev
DTSTAMP:20260924T132330Z
DTSTART;VALUE=DATE:20270417
DTEND;VALUE=DATE:20270418
SUMMARY:NIS2: Next biennial entity notification
DESCRIPTION:Competent authorities notify the Commission and Cooperation Gro
 up of the number of essential and important entities\, repeated every two 
 years after 17 Apr 2025 (Art 3(5)).\n\nDirective (EU) 2022/2555 on measure
 s for a high common level of cybersecurity across the Union (NIS2 Directiv
 e) (European Union)\n\nSource: https://eur-lex.europa.eu/eli/dir/2022/2555
 /oj\n\nhttps://rulebook.fru.dev/regulations/eu-nis2
URL:https://rulebook.fru.dev/regulations/eu-nis2
CATEGORIES:European Union,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-161@regulations.fru.dev
DTSTAMP:20260924T132330Z
DTSTART;VALUE=DATE:20270501
DTEND;VALUE=DATE:20270502
SUMMARY:Alabama Personal Data Protection Act (APDPA): APDPA takes effect
DESCRIPTION:Consumer rights and controller/processor obligations apply (HB 
 351 section 12).\n\nAlabama Personal Data Protection Act (HB 351\, 2026 Re
 gular Session) (Alabama)\n\nSource: https://alison.legislature.state.al.us
 /files/pdf/SearchableInstruments/2026RS/HB351-enr.pdf\n\nhttps://rulebook.
 fru.dev/regulations/us-al-apdpa
URL:https://rulebook.fru.dev/regulations/us-al-apdpa
CATEGORIES:Alabama,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-118@regulations.fru.dev
DTSTAMP:20260924T132330Z
DTSTART;VALUE=DATE:20270513
DTEND;VALUE=DATE:20270514
SUMMARY:India DPDP Act: Main data fiduciary obligations apply (18 months)
DESCRIPTION:Rules 3\, 5-16\, 22 and 23 (notice\, security safeguards\, brea
 ch notification\, retention\, children's consent\, SDF duties\, cross-bord
 er) come into force 18 months after publication.\n\nDigital Personal Data 
 Protection Act\, 2023 and Digital Personal Data Protection Rules\, 2025 (I
 ndia)\n\nSource: https://egazette.gov.in/WriteReadData/2025/267650.pdf\n\n
 https://rulebook.fru.dev/regulations/in-dpdp
URL:https://rulebook.fru.dev/regulations/in-dpdp
CATEGORIES:India,privacy,children,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-183@regulations.fru.dev
DTSTAMP:20260924T132330Z
DTSTART;VALUE=DATE:20270701
DTEND;VALUE=DATE:20270702
SUMMARY:California SB 243 (companion chatbots): First annual report to Offi
 ce of Suicide Prevention
DESCRIPTION:Operators begin annual reporting on crisis referrals and detect
 ion protocols.\n\nCalifornia SB 243\, Companion Chatbots (Stats. 2025\, ch
 . 677) (California)\n\nSource: https://leginfo.legislature.ca.gov/faces/bi
 llNavClient.xhtml?bill_id=202520260SB243\n\nhttps://rulebook.fru.dev/regul
 ations/us-ca-sb243
URL:https://rulebook.fru.dev/regulations/us-ca-sb243
CATEGORIES:California,ai,children,online-safety
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-127@regulations.fru.dev
DTSTAMP:20260924T132330Z
DTSTART;VALUE=DATE:20270701
DTEND;VALUE=DATE:20270702
SUMMARY:South Korea PIPA: Mandatory ISMS-P certification
DESCRIPTION:ISMS-P certification becomes mandatory for private entities mee
 ting the statutory criteria.\n\nPersonal Information Protection Act (as am
 ended by Act No. 21445\, 2026) (South Korea)\n\nSource: https://www.law.go
 .kr/법령/개인정보보호법\n\nhttps://rulebook.fru.dev/regulations/k
 r-pipa
URL:https://rulebook.fru.dev/regulations/kr-pipa
CATEGORIES:South Korea,privacy,breach-notification,biometrics,data-residenc
 y
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-307@regulations.fru.dev
DTSTAMP:20260924T132330Z
DTSTART;VALUE=DATE:20270701
DTEND;VALUE=DATE:20270702
SUMMARY:Utah AI Policy Act: Scheduled repeal of Title 13\, Ch. 72
DESCRIPTION:SB 332 extends the AI Policy Act repeal date from May 1\, 2025 
 to July 1\, 2027.\n\nUtah Artificial Intelligence Policy Act (SB 149\, 202
 4)\, as amended by SB 226 and SB 332 (2025) (Utah)\n\nSource: https://le.u
 tah.gov/~2025/bills/static/SB0332.html\n\nhttps://rulebook.fru.dev/regulat
 ions/us-ut-aipa
URL:https://rulebook.fru.dev/regulations/us-ut-aipa
CATEGORIES:Utah,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-251@regulations.fru.dev
DTSTAMP:20260924T132330Z
DTSTART;VALUE=DATE:20270731
DTEND;VALUE=DATE:20270801
SUMMARY:Louisiana Data Privacy Act: 30-day cure period expires
DESCRIPTION:AG's obligation to give 30-day notice and allow cure before inv
 estigating applies only from Jan 1 through July 31\, 2027 (R.S. 51:1780.5(
 D)).\n\nLouisiana Data Privacy Act (SB 386\, 2026 Regular Session\, Act No
 . 502)\, La. R.S. 51:1780.1-1780.5 (Louisiana)\n\nSource: https://legis.la
 .gov/legis/ViewDocument.aspx?d=1480202\n\nhttps://rulebook.fru.dev/regulat
 ions/us-la-ldpa
URL:https://rulebook.fru.dev/regulations/us-la-ldpa
CATEGORIES:Louisiana,privacy,biometrics
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-43@regulations.fru.dev
DTSTAMP:20260924T132330Z
DTSTART;VALUE=DATE:20270802
DTEND;VALUE=DATE:20270803
SUMMARY:EU AI Act: Legacy GPAI models must comply\; national AI sandboxes o
 perational
DESCRIPTION:Providers of GPAI models placed on the market before 2 Aug 2025
  must comply (Art 111(3)). Each Member State must have at least one nation
 al AI regulatory sandbox operational (Art 57(1) as amended by the Omnibus)
 .\n\nRegulation (EU) 2024/1689 laying down harmonised rules on artificial 
 intelligence (Artificial Intelligence Act)\, as amended by Regulation (EU)
  2026/1744 (Digital Omnibus on AI) (European Union)\n\nSource: https://eur
 -lex.europa.eu/eli/reg/2024/1689/oj\n\nhttps://rulebook.fru.dev/regulation
 s/eu-ai-act
URL:https://rulebook.fru.dev/regulations/eu-ai-act
CATEGORIES:European Union,ai,biometrics,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-323@regulations.fru.dev
DTSTAMP:20260924T132330Z
DTSTART;VALUE=DATE:20270901
DTEND;VALUE=DATE:20270902
SUMMARY:Vietnam AI Law: Transition ends for existing AI systems in health\,
  education and finance
DESCRIPTION:Existing AI systems in healthcare\, education and finance must 
 comply (18-month transition).\n\nLaw on Artificial Intelligence (Law No. 1
 34/2025/QH15) (Vietnam)\n\nSource: https://www.vilaf.com.vn/blog/vietnam-e
 nacts-its-first-law-on-artificial-intelligence-key-regulatory-obligations-
 from-1-march-2026/\n\nhttps://rulebook.fru.dev/regulations/vn-ai-law
URL:https://rulebook.fru.dev/regulations/vn-ai-law
CATEGORIES:Vietnam,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-61@regulations.fru.dev
DTSTAMP:20260924T132330Z
DTSTART;VALUE=DATE:20270912
DTEND;VALUE=DATE:20270913
SUMMARY:EU Data Act: Unfair-terms rules extend to older long-term contracts
DESCRIPTION:Chapter IV (unfair contractual terms) applies to contracts conc
 luded on or before 12 Sep 2025 that are of indefinite duration or expire a
 t least 10 years from 11 Jan 2024 (Art 50).\n\nRegulation (EU) 2023/2854 o
 n harmonised rules on fair access to and use of data (Data Act) (European 
 Union)\n\nSource: https://eur-lex.europa.eu/eli/reg/2023/2854/oj\n\nhttps:
 //rulebook.fru.dev/regulations/eu-data-act
URL:https://rulebook.fru.dev/regulations/eu-data-act
CATEGORIES:European Union,data-access,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-105@regulations.fru.dev
DTSTAMP:20260924T132330Z
DTSTART;VALUE=DATE:20271017
DTEND;VALUE=DATE:20271018
SUMMARY:NIS2: Commission review of NIS2
DESCRIPTION:Commission must review the functioning of NIS2 and report to Pa
 rliament and Council\, then every 36 months (Art 40).\n\nDirective (EU) 20
 22/2555 on measures for a high common level of cybersecurity across the Un
 ion (NIS2 Directive) (European Union)\n\nSource: https://eur-lex.europa.eu
 /eli/dir/2022/2555/oj\n\nhttps://rulebook.fru.dev/regulations/eu-nis2
URL:https://rulebook.fru.dev/regulations/eu-nis2
CATEGORIES:European Union,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-197@regulations.fru.dev
DTSTAMP:20260924T132330Z
DTSTART;VALUE=DATE:20271110
DTEND;VALUE=DATE:20271111
SUMMARY:CMMC 2.0: Phase 3: Level 3 certification
DESCRIPTION:Phase 3 begins one year after Phase 2\; Level 3 (DIBCAC) requir
 ements added to applicable solicitations (32 CFR 170.3(e)(3)).\n\nCybersec
 urity Maturity Model Certification (CMMC) Program (32 CFR Part 170) and DF
 ARS acquisition rule (48 CFR Parts 204\, 212\, 217\, 252) (United States (
 Federal))\n\nSource: https://www.federalregister.gov/documents/2024/10/15/
 2024-22905/cybersecurity-maturity-model-certification-cmmc-program\n\nhttp
 s://rulebook.fru.dev/regulations/us-cmmc
URL:https://rulebook.fru.dev/regulations/us-cmmc
CATEGORIES:United States (Federal),cybersecurity
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-28@regulations.fru.dev
DTSTAMP:20260924T132330Z
DTSTART;VALUE=DATE:20271201
DTEND;VALUE=DATE:20271202
SUMMARY:Chile Personal Data Protection Law (Ley 21.719): Proposed postponem
 ent of entry into force
DESCRIPTION:Government bill Boletin 18623-07 (filed 1 Sep 2026\, 'suma' urg
 ency) would replace the 24-month vacatio legis in transitional Art 1 with 
 a fixed date of 1 Dec 2027\; in first committee stage in the Senate\, not 
 law.\n\nTentative: depends on a proposal not yet adopted.\n\nLey Nº 21.71
 9 que regula la protección y el tratamiento de los datos personales y cre
 a la Agencia de Protección de Datos Personales (Chile)\n\nSource: https:/
 /tramitacion.senado.cl/appsenado/templates/tramitacion/index.php?boletin_i
 ni=18623-07\n\nhttps://rulebook.fru.dev/regulations/cl-pdpl
URL:https://rulebook.fru.dev/regulations/cl-pdpl
CATEGORIES:Chile,privacy,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-44@regulations.fru.dev
DTSTAMP:20260924T132330Z
DTSTART;VALUE=DATE:20271202
DTEND;VALUE=DATE:20271203
SUMMARY:EU AI Act: High-risk obligations apply to Annex III systems
DESCRIPTION:Chapter III Sections 1-3 (high-risk requirements and provider/d
 eployer obligations) apply to AI systems classified high-risk under Art 6(
 2) and Annex III (employment\, credit scoring\, education\, biometrics\, e
 ssential services and similar). Deferred from 2 Aug 2026 by Regulation (EU
 ) 2026/1744.\n\nRegulation (EU) 2024/1689 laying down harmonised rules on 
 artificial intelligence (Artificial Intelligence Act)\, as amended by Regu
 lation (EU) 2026/1744 (Digital Omnibus on AI) (European Union)\n\nSource: 
 https://eur-lex.europa.eu/eli/reg/2026/1744/oj\n\nhttps://rulebook.fru.dev
 /regulations/eu-ai-act
URL:https://rulebook.fru.dev/regulations/eu-ai-act
CATEGORIES:European Union,ai,biometrics,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-51@regulations.fru.dev
DTSTAMP:20260924T132330Z
DTSTART;VALUE=DATE:20271211
DTEND;VALUE=DATE:20271212
SUMMARY:Cyber Resilience Act: CRA fully applies
DESCRIPTION:All remaining obligations\, including essential cybersecurity r
 equirements\, conformity assessment and CE marking\, apply (Art 71(2)). Pr
 oducts placed on the market earlier are covered only if substantially modi
 fied (Art 69(2)).\n\nRegulation (EU) 2024/2847 on horizontal cybersecurity
  requirements for products with digital elements (Cyber Resilience Act) (E
 uropean Union)\n\nSource: https://eur-lex.europa.eu/eli/reg/2024/2847/oj\n
 \nhttps://rulebook.fru.dev/regulations/eu-cra
URL:https://rulebook.fru.dev/regulations/eu-cra
CATEGORIES:European Union,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-89@regulations.fru.dev
DTSTAMP:20260924T132330Z
DTSTART;VALUE=DATE:20271224
DTEND;VALUE=DATE:20271225
SUMMARY:eIDAS 2 / EU Digital Identity Wallet: Private relying parties must 
 accept wallets
DESCRIPTION:Private relying parties required by law or contract to use stro
 ng user authentication must accept wallets on user request within 36 month
 s of the implementing acts' entry into force (Art 5f(2)).\n\nRegulation (E
 U) 2024/1183 amending Regulation (EU) No 910/2014 as regards establishing 
 the European Digital Identity Framework (eIDAS 2) (European Union)\n\nSour
 ce: https://eur-lex.europa.eu/eli/reg_impl/2024/2977/oj\n\nhttps://ruleboo
 k.fru.dev/regulations/eu-eidas2
URL:https://rulebook.fru.dev/regulations/eu-eidas2
CATEGORIES:European Union,privacy,data-access,biometrics
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-171@regulations.fru.dev
DTSTAMP:20260924T132330Z
DTSTART;VALUE=DATE:20271231
DTEND;VALUE=DATE:20280101
SUMMARY:CCPA / CPRA: Risk assessments for pre-existing processing due
DESCRIPTION:Risk assessments must be completed and documented for high-risk
  processing that began before Jan 1\, 2026 and continues after (11 CCR 715
 5(b)).\n\nCalifornia Consumer Privacy Act of 2018\, as amended by the Cali
 fornia Privacy Rights Act of 2020 (Cal. Civ. Code 1798.100 et seq.) and CP
 PA regulations (Cal. Code Regs. tit. 11\, 7000 et seq.) (California)\n\nSo
 urce: https://cppa.ca.gov/regulations/pdf/ccpa_updates_cyber_risk_admt_app
 r_text.pdf\n\nhttps://rulebook.fru.dev/regulations/us-ca-ccpa
URL:https://rulebook.fru.dev/regulations/us-ca-ccpa
CATEGORIES:California,privacy,ai,cybersecurity,children
TRANSP:TRANSPARENT
END:VEVENT
END:VCALENDAR
