United States (Federal): data, AI and cyber laws
12 regulations in United States (Federal) that affect companies handling data: CIRCIA, CMMC 2.0, COPPA Rule, DOJ Bulk Data Rule, FCC CPNI Breach Rule, FTC Health Breach Notification Rule, GLBA Safeguards Rule, HIPAA, PADFA, SEC Cyber Disclosure Rules, SEC Regulation S-P, TAKE IT DOWN Act. Part of US Federal.
12 regulations
Add to calendar
- CMMC 2.0
United States (Federal)
In forceCybersecurityNext: Nov 10, 2026 Phase 2: Level 2 C3PAO certification
- CIRCIA
United States (Federal)
EnactedCybersecurityBreach notification - COPPA Rule
United States (Federal)
AmendedPrivacyChildrenEffective Apr 21, 2000
- DOJ Bulk Data Rule
United States (Federal)
In forcePrivacyData residencyEffective Apr 8, 2025
- FCC CPNI Breach Rule
United States (Federal)
AmendedPrivacyBreach notificationEffective Mar 13, 2024
- FTC Health Breach Notification Rule
United States (Federal)
AmendedHealth dataPrivacyEffective Sep 24, 2009
- GLBA Safeguards Rule
United States (Federal)
AmendedFinancialCybersecurityEffective May 23, 2003
- HIPAA
United States (Federal)
AmendedPrivacyHealth dataEffective Apr 14, 2003
- PADFA
United States (Federal)
In forcePrivacyData residencyEffective Jun 23, 2024
- SEC Cyber Disclosure Rules
United States (Federal)
In forceCybersecurityBreach notificationEffective Sep 5, 2023
- SEC Regulation S-P
United States (Federal)
AmendedFinancialPrivacyEffective Aug 2, 2024
- TAKE IT DOWN Act
United States (Federal)
In forceOnline safetyAIEffective May 19, 2025
Upcoming deadlines
November 20261 deadline
November 20271 deadline
November 20281 deadline
Past deadlines
June 20261 deadline
Smaller entities must comply
Smaller covered institutions (24 months after Federal Register publication) must comply with the amended Regulation S-P.
May 20261 deadline
Platform notice-and-removal process required
Covered platforms must have a clear notice-and-removal process and remove valid reported content within 48 hours (Sec. 3, one year after enactment).
April 20261 deadline
Full compliance with amended COPPA Rule
Operators must comply with all amended provisions (separate third-party disclosure consent, written retention policy, written security program, updated notices); excludes Safe Harbor provisions 312.11(d)(1), (d)(4) and (g), which had earlier dates.
February 20261 deadline
Notice of Privacy Practices updates (Part 2 alignment)
Covered entities must update Notices of Privacy Practices under 45 CFR 164.520 for the 2024 Part 2 (substance use disorder records) changes; this NPP piece survived the Purl vacatur.
December 20251 deadline
Larger entities must comply
Larger covered institutions (18 months after Federal Register publication) must have incident response programs, 30-day customer notification, and service-provider oversight in place.
November 20251 deadline
October 20251 deadline
Due diligence, audit and reporting obligations apply
Subpart J (data compliance program, due diligence and audits for restricted transactions) and reporting requirements in 202.1103 and 202.1104 apply.
June 20251 deadline
Amended COPPA Rule takes effect
The April 2025 amendments to 16 CFR Part 312 became effective; during the transition operators could comply with either the pre-2025 or the amended Rule.
May 20251 deadline
Criminal provisions effective on enactment
Publishing or threatening to publish non-consensual intimate images, including digital forgeries, became a federal crime upon signature.
April 20251 deadline
Prohibitions and restrictions take effect
Core prohibitions on covered data transactions and security requirements for restricted transactions apply.
March 20251 deadline
December 20244 deadlines
Inline XBRL tagging of Item 1.05 disclosures
Form 8-K Item 1.05 and Form 6-K incident disclosures must be tagged in Inline XBRL.
Inline XBRL tagging of annual cybersecurity disclosures
Item 106 / Item 16K disclosures must be tagged in Inline XBRL for fiscal years ending on or after this date.
August 20241 deadline
Amendments effective
The Regulation S-P amendments became effective; compliance tiered by entity size.
July 20242 deadlines
2024 amendments effective
Amendments clarifying health app coverage, unauthorized disclosure as breach, email notice and FTC notice timing took effect.
June 20243 deadlines
Smaller reporting companies: Item 1.05 compliance
Smaller reporting companies must begin complying with Form 8-K Item 1.05 incident disclosure.
May 20241 deadline
FTC breach notification requirement effective
Section 314.4(j) requires notice to the FTC within 30 days of discovering a notification event involving at least 500 consumers.
March 20241 deadline
Order effective except revised notification rules
Definitions and other parts of the order took effect; the revised 64.2011 and 64.5111 notification requirements were delayed pending OMB approval.
December 20232 deadlines
Form 8-K Item 1.05 incident disclosure begins
All registrants other than smaller reporting companies must file material incident disclosures from this date.
Annual cybersecurity disclosures begin (Item 106 / 16K)
Required in annual reports for fiscal years ending on or after this date.
June 20231 deadline
Compliance with expanded security program elements
Applicability of the 314.5 provisions (qualified individual, written risk assessment, encryption, MFA, pen testing, incident response plan, board reporting) was delayed from December 9, 2022 to this date.
January 20221 deadline
2021 Safeguards Rule amendments effective
The amended Safeguards Rule published December 9, 2021 took effect, with the more detailed program elements in 314.5 deferred.
February 20101 deadline
Full compliance with original Rule
Full compliance with the 2009 Health Breach Notification Rule was required.