Skip to content

Compliance deadlines: what is due next

Every phased date in order. Filter it, then subscribe to exactly that list.

70 deadlines from today on

September 20261 deadline

  1. ICO abolished; Information Commission takes over

    Sections 118-119 commence: office of Information Commissioner abolished and functions transferred to the Information Commission (Commencement No. 9 Regulations 2026).

    Takes effectin 6 daysSource

October 20262 deadlines

  1. PA 26-64 (SB 4) amendments take effect

    Prohibits controllers and third parties from selling precise geolocation data and enacts data broker and other consumer protection provisions.

    Takes effectin 7 daysSource
  2. Lords report stage scheduled

    House of Lords report stage scheduled (committee stage sat 1, 3 and 7 Sept 2026).

    Takes effectTentativein 32 daysSource

November 20262 deadlines

  1. CMMC 2.0

    Phase 2: Level 2 C3PAO certification

    Phase 2 begins one calendar year after Phase 1; applicable solicitations require CMMC Level 2 third-party (C3PAO) certification (32 CFR 170.3(e)(2)).

    Compliance deadlinein 47 daysSource
  2. Consent Manager registration rule in force (12 months)

    Rule 4 (registration and obligations of Consent Managers) comes into force one year after publication.

    Transitionin 50 daysSource

December 20266 deadlines

  1. Law in force

    Main obligations apply and the Personal Data Protection Agency begins supervision.

    Takes effectin 2 monthsSource
  2. EU AI Act

    New bans on sexual deepfakes and CSAM generation; Art 50(2) grace period ends

    New Art 5(1)(ba)/(bb) prohibitions on AI systems that generate non-consensual intimate imagery of identifiable persons or child sexual abuse material apply. Generative AI systems placed on the market before 2 Aug 2026 must comply with the Art 50(2) marking duty by this date (new Art 111(4)).

    Compliance deadlinein 2 monthsSource
  3. Transposition deadline; old PLD repealed

    Member States must transpose by 9 Dec 2026 (Art 22). Directive 85/374/EEC is repealed from that date but still applies to products placed on the market before it (Art 21).

    Transitionin 3 monthsSource
  4. Children's Online Privacy Code must be registered

    OAIC must develop and register the Children's Online Privacy Code within 24 months of Royal Assent.

    Compliance deadlinein 3 monthsSource
  5. Automated decision-making transparency applies

    Privacy policies must disclose the kinds of personal information used in substantially automated decisions that significantly affect individuals (24 months after assent).

    Compliance deadlinein 3 monthsSource
  6. Member States must provide EU Digital Identity Wallets

    Each Member State must provide at least one wallet within 24 months of the entry into force of the implementing acts under Arts 5a(23) and 5c(6) (Art 5a(1)).

    Compliance deadlinein 3 monthsSource

January 202716 deadlines

  1. Large online platform and hosting platform duties

    Large online platforms and GenAI hosting platforms must meet the provenance duties added by AB 853.

    Compliance deadlinein 3 monthsSource
  2. First OES anonymized incident report and CDT definition review

    OES begins publishing annual anonymized incident summaries and the Department of Technology begins annual review of the act's definitions; the CalCompute framework report is due to the Legislature.

    Reportingin 3 monthsSource
  3. CCPA / CPRA

    ADMT requirements compliance date

    Businesses using ADMT for significant decisions must comply with Article 11 (pre-use notice, opt-out, access rights) by this date (11 CCR 7200(b)).

    Compliance deadlinein 3 monthsSource
  4. CCPA / CPRA

    Browsers must support opt-out preference signal (AB 566)

    Businesses that develop or maintain a browser must include consumer-configurable functionality to send an opt-out preference signal (Civ. Code 1798.136, operative Jan 1, 2027).

    Compliance deadlinein 3 monthsSource
  5. ADMT obligations apply

    Developer documentation, consumer notices, post-adverse-outcome disclosure, correction and human-review rights take effect.

    Takes effectin 3 monthsSource
  6. AG rules due

    Attorney General must adopt rules clarifying the post-adverse-outcome disclosure requirements.

    Compliance deadlinein 3 monthsSource
  7. Data broker registration required

    Data brokers may not sell or license brokered personal data in Connecticut unless registered with the Department of Consumer Protection ($2,500 initial fee).

    Compliance deadlinein 3 monthsSource
  8. Amended thresholds and third-party duties take effect

    Applicability drops to 10,000 consumers (or 5,000 + 20% revenue from sale) and new third-party duties (12D-107A) apply.

    Takes effectin 3 monthsSource
  9. Louisiana Data Privacy Act takes effect

    Consumer rights and controller duties apply (Act 502, Section 2); data protection assessment requirements apply to processing from this date.

    Takes effectin 3 monthsSource
  10. Ban on selling personal data of children under 13 (HB 1460)

    HB 1460 (2026, ch. 168) prohibits controllers from selling the personal data of a child under 13.

    Takes effectin 3 monthsSource
  11. NY RAISE Act

    RAISE Act takes effect

    Transparency reports, frontier AI frameworks, incident reporting and DFS disclosure filings apply.

    Takes effectin 3 monthsSource
  12. Oklahoma OKCDPA

    Oklahoma Consumer Data Privacy Act takes effect

    All OKCDPA obligations and consumer rights apply.

    Takes effectin 3 monthsSource
  13. UCPA extends to motor vehicle manufacturers

    Motor vehicle manufacturers whose vehicles are sold or leased in Utah and that collect personal data through vehicle data systems are covered regardless of the revenue and consumer thresholds (13-61-102, as amended by Laws 2026, ch. 193).

    Takes effectin 3 monthsSource
  14. EU Data Act

    Cloud switching charges abolished

    Providers of data processing services may no longer impose any switching charges on customers (Art 29(1)).

    Compliance deadlinein 4 monthsSource
  15. Implementing regulation GR 33/2026 takes effect

    Detailed PDP implementing rules (DPIA, cross-border, children's consent) apply, 6 months after the 16 Jul 2026 enactment.

    Compliance deadlinein 4 monthsSource
  16. Annual data broker registration deadline

    Data brokers must renew registration with CalPrivacy by January 31 following each year they meet the definition.

    Reportingin 4 monthsSource

March 20272 deadlines

  1. Transition ends for existing AI systems (general)

    Existing AI systems in most sectors must comply (12-month transition).

    Transitionin 5 monthsSource
  2. EHDS general application date

    The regulation applies generally from 26 Mar 2027, subject to the phased exceptions below (final article).

    Takes effectin 6 monthsSource

April 20273 deadlines

  1. Discretionary 60-day cure period ends

    The Division's discretionary notice-and-cure (at least 60 days) applies only to violations occurring on or before April 1, 2027 (Com. Law 14-4614).

    Enforcementin 6 monthsSource
  2. GDPR

    GDPR Procedural Regulation applies

    Harmonised rules for cross-border complaint admissibility, rights to be heard and access to preliminary findings, and investigation timelines apply to DPAs from 2 April 2027 (Regulation (EU) 2025/2518, final article).

    Enforcementin 6 monthsSource
  3. NIS2

    Next biennial entity notification

    Competent authorities notify the Commission and Cooperation Group of the number of essential and important entities, repeated every two years after 17 Apr 2025 (Art 3(5)).

    Reportingin 7 monthsSource

May 20272 deadlines

  1. APDPA takes effect

    Consumer rights and controller/processor obligations apply (HB 351 section 12).

    Takes effectin 7 monthsSource
  2. Main data fiduciary obligations apply (18 months)

    Rules 3, 5-16, 22 and 23 (notice, security safeguards, breach notification, retention, children's consent, SDF duties, cross-border) come into force 18 months after publication.

    Compliance deadlinein 8 monthsSource

July 20274 deadlines

  1. First annual report to Office of Suicide Prevention

    Operators begin annual reporting on crisis referrals and detection protocols.

    Reportingin 9 monthsSource
  2. South Korea PIPA

    Mandatory ISMS-P certification

    ISMS-P certification becomes mandatory for private entities meeting the statutory criteria.

    Compliance deadlinein 9 monthsSource
  3. Scheduled repeal of Title 13, Ch. 72

    SB 332 extends the AI Policy Act repeal date from May 1, 2025 to July 1, 2027.

    Sunsetin 9 monthsSource
  4. 30-day cure period expires

    AG's obligation to give 30-day notice and allow cure before investigating applies only from Jan 1 through July 31, 2027 (R.S. 51:1780.5(D)).

    Enforcementin 10 monthsSource

August 20271 deadline

  1. EU AI Act

    Legacy GPAI models must comply; national AI sandboxes operational

    Providers of GPAI models placed on the market before 2 Aug 2025 must comply (Art 111(3)). Each Member State must have at least one national AI regulatory sandbox operational (Art 57(1) as amended by the Omnibus).

    Compliance deadlinein 10 monthsSource

September 20272 deadlines

  1. Transition ends for existing AI systems in health, education and finance

    Existing AI systems in healthcare, education and finance must comply (18-month transition).

    Transitionin 11 monthsSource
  2. EU Data Act

    Unfair-terms rules extend to older long-term contracts

    Chapter IV (unfair contractual terms) applies to contracts concluded on or before 12 Sep 2025 that are of indefinite duration or expire at least 10 years from 11 Jan 2024 (Art 50).

    Compliance deadlinein 12 monthsSource

October 20271 deadline

  1. NIS2

    Commission review of NIS2

    Commission must review the functioning of NIS2 and report to Parliament and Council, then every 36 months (Art 40).

    Reportingin 13 monthsSource

November 20271 deadline

  1. CMMC 2.0

    Phase 3: Level 3 certification

    Phase 3 begins one year after Phase 2; Level 3 (DIBCAC) requirements added to applicable solicitations (32 CFR 170.3(e)(3)).

    Compliance deadlinein 14 monthsSource

December 20275 deadlines

  1. Proposed postponement of entry into force

    Government bill Boletin 18623-07 (filed 1 Sep 2026, 'suma' urgency) would replace the 24-month vacatio legis in transitional Art 1 with a fixed date of 1 Dec 2027; in first committee stage in the Senate, not law.

    Takes effectTentativein 14 monthsSource
  2. EU AI Act

    High-risk obligations apply to Annex III systems

    Chapter III Sections 1-3 (high-risk requirements and provider/deployer obligations) apply to AI systems classified high-risk under Art 6(2) and Annex III (employment, credit scoring, education, biometrics, essential services and similar). Deferred from 2 Aug 2026 by Regulation (EU) 2026/1744.

    Compliance deadlinein 14 monthsSource
  3. Cyber Resilience Act

    CRA fully applies

    All remaining obligations, including essential cybersecurity requirements, conformity assessment and CE marking, apply (Art 71(2)). Products placed on the market earlier are covered only if substantially modified (Art 69(2)).

    Compliance deadlinein 15 monthsSource
  4. Private relying parties must accept wallets

    Private relying parties required by law or contract to use strong user authentication must accept wallets on user request within 36 months of the implementing acts' entry into force (Art 5f(2)).

    Compliance deadlinein 15 monthsSource
  5. CCPA / CPRA

    Risk assessments for pre-existing processing due

    Risk assessments must be completed and documented for high-risk processing that began before Jan 1, 2026 and continues after (11 CCR 7155(b)).

    Compliance deadlinein 15 monthsSource

January 20283 deadlines

  1. Capture device manufacturer duties

    Capture device manufacturer provenance requirements become operative.

    Compliance deadlinein 15 monthsSource
  2. Independent third-party audits begin

    Beginning Jan 1, 2028 and every 3 years thereafter, data brokers must undergo an independent audit of Delete Act compliance.

    Compliance deadlinein 15 monthsSource
  3. Vermont Data Privacy and Online Surveillance Act takes effect

    All obligations under Act 145 apply (sec. 4).

    Takes effectin 15 monthsSource

April 20282 deadlines

  1. CCPA / CPRA

    First risk assessment submission to CPPA

    Businesses must submit required risk assessment information and attestation for assessments conducted in 2026 and 2027 (11 CCR 7157(a)(1)); annually by April 1 thereafter.

    Reportingin 18 monthsSource
  2. CCPA / CPRA

    Cybersecurity audit due: revenue over $100M

    First cybersecurity audit report (covering Jan 1, 2027 - Jan 1, 2028) and certification due for businesses with 2026 annual gross revenue over $100M (11 CCR 7121(a)(1)).

    Reportingin 18 monthsSource

June 20281 deadline

  1. Cyber Resilience Act

    Legacy type-examination certificates expire

    EU type-examination certificates and approval decisions on cybersecurity requirements under other harmonisation legislation remain valid until this date unless they expire earlier (Art 69(1)).

    Sunsetin 21 monthsSource

August 20281 deadline

  1. EU AI Act

    High-risk obligations apply to Annex I product-embedded systems

    Chapter III Sections 1-3 apply to AI systems classified high-risk under Art 6(1) and Annex I (safety components of products covered by EU harmonisation legislation). Deferred from 2 Aug 2027 by Regulation (EU) 2026/1744.

    Compliance deadlinein 22 monthsSource

September 20282 deadlines

  1. Cyber Resilience Act

    Report on single reporting platform

    Commission report assessing the single reporting platform's effectiveness (Art 70(2)).

    Reportingin 24 monthsSource
  2. EU Data Act

    Commission evaluation

    Commission evaluation report due, including the impact of cloud switching rules (Arts 23-31) (Art 49(2)).

    Reportingin 24 monthsSource

October 20281 deadline

  1. Data brokers must process state deletion mechanism requests

    Registered data brokers must access the DCP accessible deletion mechanism at least every 45 days and process deletion requests.

    Compliance deadlinein 2 yearsSource

November 20281 deadline

  1. CMMC 2.0

    Phase 4: full implementation

    CMMC requirements included in all applicable DoD solicitations and contracts, including option periods (32 CFR 170.3(e)(4)).

    Compliance deadlinein 2.1 yearsSource

March 20291 deadline

  1. Primary use for first data categories; secondary use framework applies

    Patient rights and EHR rules apply to patient summaries, ePrescriptions and eDispensations (Art 14(1)(a)-(c)). Chapter IV secondary-use rules (data permits, Health Data Access Bodies) apply.

    Compliance deadlinein 2.5 yearsSource

April 20291 deadline

  1. CCPA / CPRA

    Cybersecurity audit due: revenue $50M-$100M

    First cybersecurity audit report (covering 2028) due for businesses with 2027 annual gross revenue between $50M and $100M (11 CCR 7121(a)(2)).

    Reportingin 2.5 yearsSource

June 20291 deadline

  1. Mandatory 60-day cure period expires

    The AG's duty to issue a cure notice before enforcement ends June 30, 2029 (Act 145 sec. 3).

    Enforcementin 2.8 yearsSource

July 20291 deadline

  1. Postsecondary institutions must comply

    Postsecondary institutions regulated by the Office of Higher Education must comply by July 31, 2029.

    Compliance deadlinein 2.9 yearsSource

January 20301 deadline

  1. Mandatory cure period ends

    The AG's obligation to offer a 60-day notice-and-cure period expires.

    Sunsetin 3.3 yearsSource

April 20301 deadline

  1. CCPA / CPRA

    Cybersecurity audit due: revenue under $50M

    First cybersecurity audit report (covering 2029) due for covered businesses with 2028 annual gross revenue under $50M (11 CCR 7121(a)(3)); annual by April 1 thereafter.

    Reportingin 3.5 yearsSource

August 20301 deadline

  1. EU AI Act

    Public-authority high-risk systems must comply

    Providers and deployers of high-risk AI systems intended for use by public authorities that were placed on the market before the Chapter III application date must comply (Art 111(2), as replaced by the Omnibus).

    Compliance deadlinein 3.9 yearsSource

December 20302 deadlines

  1. Cyber Resilience Act

    First CRA evaluation

    Commission evaluation and review report, then every four years (Art 70(1)).

    Reportingin 4.2 yearsSource
  2. EU AI Act

    Large-scale EU IT systems must comply

    AI systems that are components of the large-scale IT systems in Annex X (e.g. SIS, VIS, Eurodac, EES, ETIAS) placed on the market before 2 Aug 2027 must be brought into compliance (Art 111(1)).

    Compliance deadlinein 4.3 yearsSource

March 20311 deadline

  1. Primary use for second data categories; EHR systems in service; extra secondary-use categories

    Primary-use rules extend to medical images, lab results and discharge reports (Art 14(1)(d)-(f)). Chapter III applies to EHR systems put into service under Art 26(2). Additional secondary-use categories in Art 51(1)(b),(f),(g),(m),(p) apply.

    Compliance deadlinein 4.5 yearsSource

March 20351 deadline

  1. Third-country participation in secondary use

    Art 75(5) applies from 26 Mar 2035.

    Takes effectin 8.5 yearsSource

Summaries for reference, not legal advice. Check the official text.

When the rules change: new data, privacy and AI laws and deadlines, the next morning.