BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//fru.dev//Rulebook//EN
CALSCALE:GREGORIAN
METHOD:PUBLISH
X-WR-CALNAME:Regulation deadlines (Rulebook)
X-WR-CALDESC:Compliance deadlines tracked at rulebook.fru.dev
REFRESH-INTERVAL;VALUE=DURATION:P1D
X-PUBLISHED-TTL:P1D
BEGIN:VEVENT
UID:deadline-82@regulations.fru.dev
DTSTAMP:20260924T103004Z
DTSTART;VALUE=DATE:20290326
DTEND;VALUE=DATE:20290327
SUMMARY:European Health Data Space (EHDS): Primary use for first data categ
 ories\; secondary use framework applies
DESCRIPTION:Patient rights and EHR rules apply to patient summaries\, ePres
 criptions and eDispensations (Art 14(1)(a)-(c)). Chapter IV secondary-use 
 rules (data permits\, Health Data Access Bodies) apply.\n\nRegulation (EU)
  2025/327 on the European Health Data Space (European Union)\n\nSource: ht
 tps://eur-lex.europa.eu/eli/reg/2025/327/oj\n\nhttps://rulebook.fru.dev/re
 gulations/eu-ehds
URL:https://rulebook.fru.dev/regulations/eu-ehds
CATEGORIES:European Union,health,privacy,data-access
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-174@regulations.fru.dev
DTSTAMP:20260924T103004Z
DTSTART;VALUE=DATE:20290401
DTEND;VALUE=DATE:20290402
SUMMARY:CCPA / CPRA: Cybersecurity audit due: revenue $50M-$100M
DESCRIPTION:First cybersecurity audit report (covering 2028) due for busine
 sses with 2027 annual gross revenue between $50M and $100M (11 CCR 7121(a)
 (2)).\n\nCalifornia Consumer Privacy Act of 2018\, as amended by the Calif
 ornia Privacy Rights Act of 2020 (Cal. Civ. Code 1798.100 et seq.) and CPP
 A regulations (Cal. Code Regs. tit. 11\, 7000 et seq.) (California)\n\nSou
 rce: https://cppa.ca.gov/regulations/pdf/ccpa_updates_cyber_risk_admt_appr
 _text.pdf\n\nhttps://rulebook.fru.dev/regulations/us-ca-ccpa
URL:https://rulebook.fru.dev/regulations/us-ca-ccpa
CATEGORIES:California,privacy,ai,cybersecurity,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-316@regulations.fru.dev
DTSTAMP:20260924T103004Z
DTSTART;VALUE=DATE:20290630
DTEND;VALUE=DATE:20290701
SUMMARY:Vermont VDPOSA: Mandatory 60-day cure period expires
DESCRIPTION:The AG's duty to issue a cure notice before enforcement ends Ju
 ne 30\, 2029 (Act 145 sec. 3).\n\nVermont Data Privacy and Online Surveill
 ance Act (S.71\, Act 145 of 2026) (Vermont)\n\nSource: https://legislature
 .vermont.gov/Documents/2026/Docs/ACTS/ACT145/ACT145%20As%20Enacted.pdf\n\n
 https://rulebook.fru.dev/regulations/us-vt-vdposa
URL:https://rulebook.fru.dev/regulations/us-vt-vdposa
CATEGORIES:Vermont,privacy,health,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-257@regulations.fru.dev
DTSTAMP:20260924T103004Z
DTSTART;VALUE=DATE:20290731
DTEND;VALUE=DATE:20290801
SUMMARY:Minnesota Consumer Data Privacy Act (MCDPA): Postsecondary institut
 ions must comply
DESCRIPTION:Postsecondary institutions regulated by the Office of Higher Ed
 ucation must comply by July 31\, 2029.\n\nMinnesota Consumer Data Privacy 
 Act (HF 4757\, 2024 Minn. Laws ch. 121\, art. 5)\, Minn. Stat. 325M.10-325
 M.21 (Minnesota)\n\nSource: https://www.revisor.mn.gov/statutes/cite/325M.
 20\n\nhttps://rulebook.fru.dev/regulations/us-mn-mcdpa
URL:https://rulebook.fru.dev/regulations/us-mn-mcdpa
CATEGORIES:Minnesota,privacy
TRANSP:TRANSPARENT
END:VEVENT
END:VCALENDAR
