Compliance deadlines: what is due next
Every phased date in order. Filter it, then subscribe to exactly that list.
Add to calendar
70 deadlines from today on
September 20261 deadline
ICO abolished; Information Commission takes over
Sections 118-119 commence: office of Information Commissioner abolished and functions transferred to the Information Commission (Commencement No. 9 Regulations 2026).
October 20262 deadlines
PA 26-64 (SB 4) amendments take effect
Prohibits controllers and third parties from selling precise geolocation data and enacts data broker and other consumer protection provisions.
Lords report stage scheduled
House of Lords report stage scheduled (committee stage sat 1, 3 and 7 Sept 2026).
November 20262 deadlines
Consent Manager registration rule in force (12 months)
Rule 4 (registration and obligations of Consent Managers) comes into force one year after publication.
December 20266 deadlines
Law in force
Main obligations apply and the Personal Data Protection Agency begins supervision.
- EU AI ActEuropean Union
New bans on sexual deepfakes and CSAM generation; Art 50(2) grace period ends
New Art 5(1)(ba)/(bb) prohibitions on AI systems that generate non-consensual intimate imagery of identifiable persons or child sexual abuse material apply. Generative AI systems placed on the market before 2 Aug 2026 must comply with the Art 50(2) marking duty by this date (new Art 111(4)).
- Product Liability DirectiveEuropean Union
Transposition deadline; old PLD repealed
Member States must transpose by 9 Dec 2026 (Art 22). Directive 85/374/EEC is repealed from that date but still applies to products placed on the market before it (Art 21).
Children's Online Privacy Code must be registered
OAIC must develop and register the Children's Online Privacy Code within 24 months of Royal Assent.
Automated decision-making transparency applies
Privacy policies must disclose the kinds of personal information used in substantially automated decisions that significantly affect individuals (24 months after assent).
- eIDAS 2 / EU Digital Identity WalletEuropean Union
Member States must provide EU Digital Identity Wallets
Each Member State must provide at least one wallet within 24 months of the entry into force of the implementing acts under Arts 5a(23) and 5c(6) (Art 5a(1)).
January 202716 deadlines
Large online platform and hosting platform duties
Large online platforms and GenAI hosting platforms must meet the provenance duties added by AB 853.
First OES anonymized incident report and CDT definition review
OES begins publishing annual anonymized incident summaries and the Department of Technology begins annual review of the act's definitions; the CalCompute framework report is due to the Legislature.
ADMT requirements compliance date
Businesses using ADMT for significant decisions must comply with Article 11 (pre-use notice, opt-out, access rights) by this date (11 CCR 7200(b)).
Browsers must support opt-out preference signal (AB 566)
Businesses that develop or maintain a browser must include consumer-configurable functionality to send an opt-out preference signal (Civ. Code 1798.136, operative Jan 1, 2027).
ADMT obligations apply
Developer documentation, consumer notices, post-adverse-outcome disclosure, correction and human-review rights take effect.
AG rules due
Attorney General must adopt rules clarifying the post-adverse-outcome disclosure requirements.
Data broker registration required
Data brokers may not sell or license brokered personal data in Connecticut unless registered with the Department of Consumer Protection ($2,500 initial fee).
Amended thresholds and third-party duties take effect
Applicability drops to 10,000 consumers (or 5,000 + 20% revenue from sale) and new third-party duties (12D-107A) apply.
- Louisiana Data Privacy ActLouisiana
Louisiana Data Privacy Act takes effect
Consumer rights and controller duties apply (Act 502, Section 2); data protection assessment requirements apply to processing from this date.
- New Hampshire Privacy ActNew Hampshire
Ban on selling personal data of children under 13 (HB 1460)
HB 1460 (2026, ch. 168) prohibits controllers from selling the personal data of a child under 13.
RAISE Act takes effect
Transparency reports, frontier AI frameworks, incident reporting and DFS disclosure filings apply.
- Oklahoma OKCDPAOklahoma
Oklahoma Consumer Data Privacy Act takes effect
All OKCDPA obligations and consumer rights apply.
UCPA extends to motor vehicle manufacturers
Motor vehicle manufacturers whose vehicles are sold or leased in Utah and that collect personal data through vehicle data systems are covered regardless of the revenue and consumer thresholds (13-61-102, as amended by Laws 2026, ch. 193).
- EU Data ActEuropean Union
Cloud switching charges abolished
Providers of data processing services may no longer impose any switching charges on customers (Art 29(1)).
Implementing regulation GR 33/2026 takes effect
Detailed PDP implementing rules (DPIA, cross-border, children's consent) apply, 6 months after the 16 Jul 2026 enactment.
Annual data broker registration deadline
Data brokers must renew registration with CalPrivacy by January 31 following each year they meet the definition.
March 20272 deadlines
Transition ends for existing AI systems (general)
Existing AI systems in most sectors must comply (12-month transition).
- European Health Data Space (EHDS)European Union
EHDS general application date
The regulation applies generally from 26 Mar 2027, subject to the phased exceptions below (final article).
April 20273 deadlines
Discretionary 60-day cure period ends
The Division's discretionary notice-and-cure (at least 60 days) applies only to violations occurring on or before April 1, 2027 (Com. Law 14-4614).
May 20272 deadlines
APDPA takes effect
Consumer rights and controller/processor obligations apply (HB 351 section 12).
Main data fiduciary obligations apply (18 months)
Rules 3, 5-16, 22 and 23 (notice, security safeguards, breach notification, retention, children's consent, SDF duties, cross-border) come into force 18 months after publication.
July 20274 deadlines
First annual report to Office of Suicide Prevention
Operators begin annual reporting on crisis referrals and detection protocols.
Mandatory ISMS-P certification
ISMS-P certification becomes mandatory for private entities meeting the statutory criteria.
Scheduled repeal of Title 13, Ch. 72
SB 332 extends the AI Policy Act repeal date from May 1, 2025 to July 1, 2027.
- Louisiana Data Privacy ActLouisiana
30-day cure period expires
AG's obligation to give 30-day notice and allow cure before investigating applies only from Jan 1 through July 31, 2027 (R.S. 51:1780.5(D)).
August 20271 deadline
- EU AI ActEuropean Union
Legacy GPAI models must comply; national AI sandboxes operational
Providers of GPAI models placed on the market before 2 Aug 2025 must comply (Art 111(3)). Each Member State must have at least one national AI regulatory sandbox operational (Art 57(1) as amended by the Omnibus).
September 20272 deadlines
Transition ends for existing AI systems in health, education and finance
Existing AI systems in healthcare, education and finance must comply (18-month transition).
- EU Data ActEuropean Union
Unfair-terms rules extend to older long-term contracts
Chapter IV (unfair contractual terms) applies to contracts concluded on or before 12 Sep 2025 that are of indefinite duration or expire at least 10 years from 11 Jan 2024 (Art 50).
October 20271 deadline
November 20271 deadline
December 20275 deadlines
Proposed postponement of entry into force
Government bill Boletin 18623-07 (filed 1 Sep 2026, 'suma' urgency) would replace the 24-month vacatio legis in transitional Art 1 with a fixed date of 1 Dec 2027; in first committee stage in the Senate, not law.
- EU AI ActEuropean Union
High-risk obligations apply to Annex III systems
Chapter III Sections 1-3 (high-risk requirements and provider/deployer obligations) apply to AI systems classified high-risk under Art 6(2) and Annex III (employment, credit scoring, education, biometrics, essential services and similar). Deferred from 2 Aug 2026 by Regulation (EU) 2026/1744.
- Cyber Resilience ActEuropean Union
CRA fully applies
All remaining obligations, including essential cybersecurity requirements, conformity assessment and CE marking, apply (Art 71(2)). Products placed on the market earlier are covered only if substantially modified (Art 69(2)).
- eIDAS 2 / EU Digital Identity WalletEuropean Union
Private relying parties must accept wallets
Private relying parties required by law or contract to use strong user authentication must accept wallets on user request within 36 months of the implementing acts' entry into force (Art 5f(2)).
Risk assessments for pre-existing processing due
Risk assessments must be completed and documented for high-risk processing that began before Jan 1, 2026 and continues after (11 CCR 7155(b)).
January 20283 deadlines
Capture device manufacturer duties
Capture device manufacturer provenance requirements become operative.
Independent third-party audits begin
Beginning Jan 1, 2028 and every 3 years thereafter, data brokers must undergo an independent audit of Delete Act compliance.
Vermont Data Privacy and Online Surveillance Act takes effect
All obligations under Act 145 apply (sec. 4).
April 20282 deadlines
First risk assessment submission to CPPA
Businesses must submit required risk assessment information and attestation for assessments conducted in 2026 and 2027 (11 CCR 7157(a)(1)); annually by April 1 thereafter.
Cybersecurity audit due: revenue over $100M
First cybersecurity audit report (covering Jan 1, 2027 - Jan 1, 2028) and certification due for businesses with 2026 annual gross revenue over $100M (11 CCR 7121(a)(1)).
June 20281 deadline
- Cyber Resilience ActEuropean Union
Legacy type-examination certificates expire
EU type-examination certificates and approval decisions on cybersecurity requirements under other harmonisation legislation remain valid until this date unless they expire earlier (Art 69(1)).
August 20281 deadline
- EU AI ActEuropean Union
High-risk obligations apply to Annex I product-embedded systems
Chapter III Sections 1-3 apply to AI systems classified high-risk under Art 6(1) and Annex I (safety components of products covered by EU harmonisation legislation). Deferred from 2 Aug 2027 by Regulation (EU) 2026/1744.
September 20282 deadlines
- Cyber Resilience ActEuropean Union
Report on single reporting platform
Commission report assessing the single reporting platform's effectiveness (Art 70(2)).
- EU Data ActEuropean Union
Commission evaluation
Commission evaluation report due, including the impact of cloud switching rules (Arts 23-31) (Art 49(2)).
October 20281 deadline
Data brokers must process state deletion mechanism requests
Registered data brokers must access the DCP accessible deletion mechanism at least every 45 days and process deletion requests.
November 20281 deadline
March 20291 deadline
- European Health Data Space (EHDS)European Union
Primary use for first data categories; secondary use framework applies
Patient rights and EHR rules apply to patient summaries, ePrescriptions and eDispensations (Art 14(1)(a)-(c)). Chapter IV secondary-use rules (data permits, Health Data Access Bodies) apply.
April 20291 deadline
Cybersecurity audit due: revenue $50M-$100M
First cybersecurity audit report (covering 2028) due for businesses with 2027 annual gross revenue between $50M and $100M (11 CCR 7121(a)(2)).
June 20291 deadline
Mandatory 60-day cure period expires
The AG's duty to issue a cure notice before enforcement ends June 30, 2029 (Act 145 sec. 3).
July 20291 deadline
Postsecondary institutions must comply
Postsecondary institutions regulated by the Office of Higher Education must comply by July 31, 2029.
January 20301 deadline
Mandatory cure period ends
The AG's obligation to offer a 60-day notice-and-cure period expires.
April 20301 deadline
Cybersecurity audit due: revenue under $50M
First cybersecurity audit report (covering 2029) due for covered businesses with 2028 annual gross revenue under $50M (11 CCR 7121(a)(3)); annual by April 1 thereafter.
August 20301 deadline
- EU AI ActEuropean Union
Public-authority high-risk systems must comply
Providers and deployers of high-risk AI systems intended for use by public authorities that were placed on the market before the Chapter III application date must comply (Art 111(2), as replaced by the Omnibus).
December 20302 deadlines
- Cyber Resilience ActEuropean Union
First CRA evaluation
Commission evaluation and review report, then every four years (Art 70(1)).
March 20311 deadline
- European Health Data Space (EHDS)European Union
Primary use for second data categories; EHR systems in service; extra secondary-use categories
Primary-use rules extend to medical images, lab results and discharge reports (Art 14(1)(d)-(f)). Chapter III applies to EHR systems put into service under Art 26(2). Additional secondary-use categories in Art 51(1)(b),(f),(g),(m),(p) apply.
March 20351 deadline
- European Health Data Space (EHDS)European Union
Third-country participation in secondary use
Art 75(5) applies from 26 Mar 2035.
Summaries for reference, not legal advice. Check the official text.