Skip to content

Asia-Pacific data protection and AI laws

China, India, Japan, Korea, Australia, Singapore, Vietnam, Indonesia and more.

FewerMore laws

12 jurisdictions with tracked laws. Tap one to open it.

Upcoming deadlines

November 20261 deadline

  1. Consent Manager registration rule in force (12 months)

    Rule 4 (registration and obligations of Consent Managers) comes into force one year after publication.

    Transitionin 50 daysSource

December 20262 deadlines

  1. Children's Online Privacy Code must be registered

    OAIC must develop and register the Children's Online Privacy Code within 24 months of Royal Assent.

    Compliance deadlinein 3 monthsSource
  2. Automated decision-making transparency applies

    Privacy policies must disclose the kinds of personal information used in substantially automated decisions that significantly affect individuals (24 months after assent).

    Compliance deadlinein 3 monthsSource

January 20271 deadline

  1. Implementing regulation GR 33/2026 takes effect

    Detailed PDP implementing rules (DPIA, cross-border, children's consent) apply, 6 months after the 16 Jul 2026 enactment.

    Compliance deadlinein 4 monthsSource

March 20271 deadline

  1. Transition ends for existing AI systems (general)

    Existing AI systems in most sectors must comply (12-month transition).

    Transitionin 5 monthsSource

May 20271 deadline

  1. Main data fiduciary obligations apply (18 months)

    Rules 3, 5-16, 22 and 23 (notice, security safeguards, breach notification, retention, children's consent, SDF duties, cross-border) come into force 18 months after publication.

    Compliance deadlinein 8 monthsSource

July 20271 deadline

  1. South Korea PIPA

    Mandatory ISMS-P certification

    ISMS-P certification becomes mandatory for private entities meeting the statutory criteria.

    Compliance deadlinein 9 monthsSource

September 20271 deadline

  1. Transition ends for existing AI systems in health, education and finance

    Existing AI systems in healthcare, education and finance must comply (18-month transition).

    Transitionin 11 monthsSource

Past deadlines

September 20261 deadline

  1. South Korea PIPA

    2026 PIPA amendments take effect

    10%-of-revenue fines, CEO accountability, and notice duties for possible breaches apply.

    Takes effect13 days agoSource

July 20261 deadline

  1. 2026 APPI amendment act promulgated

    Amendment enacted by the Diet on 10 July 2026 and promulgated; main provisions take effect by cabinet order within two years of promulgation.

    Transition2 months agoSource

May 20261 deadline

  1. IPP 3A indirect-collection notification applies

    Agencies collecting personal information from third parties must take reasonable steps to notify individuals, subject to exceptions.

    Compliance deadline5 months agoSource

March 20262 deadlines

  1. South Korea PIPA

    2026 PIPA amendment promulgated (Act No. 21445)

    Amendment raising fines to 10% of revenue and adding CEO accountability promulgated.

    Transition7 months agoSource
  2. AI Law takes effect

    Risk classification, transparency and labeling obligations apply to new AI systems.

    Takes effect7 months agoSource

January 20265 deadlines

  1. AI Basic Act and Enforcement Decree take effect

    Transparency, labeling, high-impact AI, and domestic representative obligations apply (fines deferred during the grace period).

    Takes effect8 months agoSource
  2. PDPL and Decree 356/2025 take effect

    Personal data protection obligations, DPIA/TIA filing and penalty framework apply; Decree 13/2023 replaced.

    Takes effect9 months agoSource
  3. PCICSO comes into operation

    Commissioner's Office is established and designation of CIOs begins; obligations apply to designated operators.

    Takes effect9 months agoSource
  4. 2025 amendments take effect

    Higher fines, first-violation fines, AI governance provisions and PIPL-alignment duties apply under the 28 Oct 2025 NPCSC Decision.

    Takes effect9 months agoSource
  5. Ransomware reporting moves to compliance phase

    The education-first phase (30 May-31 Dec 2025) ends; Home Affairs moves to a compliance and education approach for missed reports.

    Enforcement9 months agoSource

December 20251 deadline

  1. Social media minimum age obligation applies

    Age-restricted platforms must take reasonable steps to prevent under-16s from holding accounts.

    Takes effect9 months agoSource

November 20251 deadline

  1. DPDP Rules published; Board and procedural rules in force

    Rules 1, 2 and 17-21 (Data Protection Board constitution and functioning) take effect on publication in the Official Gazette.

    Takes effect10 months agoSource

September 20253 deadlines

  1. Privacy Amendment Act 2025 technical changes commence

    Technical amendments commence the day after Royal Assent (23 Sep 2025).

    Takes effect12 months agoSource
  2. AI Promotion Act fully in force

    Provisions establishing the AI Strategy Headquarters and AI Basic Plan take effect.

    Takes effect13 months agoSource
  3. AI content labeling measures and GB 45438-2025 take effect

    Explicit and implicit labeling duties for AI-generated content and platform detection duties apply.

    Takes effect13 months agoSource

June 20253 deadlines

  1. Statutory tort for serious invasions of privacy commences

    Individuals can sue for serious invasions of privacy (Schedule 2), 6 months after Royal Assent.

    Takes effect15 months agoSource
  2. AI Promotion Act promulgated and partly in force

    Most provisions, including basic principles and stakeholder duties, take effect on promulgation.

    Takes effect16 months agoSource
  3. PDPA amendments phase 3

    Mandatory DPO appointment, data breach notification, and data portability take effect.

    Compliance deadline16 months agoSource

May 20252 deadlines

  1. Ransomware payment reporting starts

    Reporting business entities must report ransomware/cyber-extortion payments to ASD within 72 hours of payment.

    Takes effect16 months agoSource
  2. PI compliance audit measures take effect

    Self-audit and regulator-ordered audit regime applies; 10M+ processors must audit at least every two years.

    Takes effect17 months agoSource

April 20251 deadline

  1. PDPA amendments phase 2

    'Data controller' terminology, biometric data as sensitive data, higher penalties, Security Principle for processors, and removal of the cross-border whitelist take effect.

    Takes effect18 months agoSource

January 20252 deadlines

  1. PDPA amendments phase 1

    Miscellaneous provisions commence (e.g. electronic service of notices).

    Takes effect21 months agoSource
  2. Network Data Regulations take effect

    All provisions, including the 10-million-person threshold duties and annual important-data risk assessments, apply.

    Takes effect21 months agoSource

December 20241 deadline

  1. Most POLA Act 2024 amendments commence

    Tiered penalties, infringement notices, OAIC powers, security and overseas-transfer clarifications and doxxing offences commence the day after Royal Assent.

    Takes effect21 months agoSource

October 20241 deadline

  1. PDP Law transition ends

    Controllers and processors must fully comply (Art. 74 two-year transition).

    Compliance deadline23 months agoSource

March 20241 deadline

  1. Cross-border data flow provisions take effect

    Exemptions and volume thresholds apply from publication (Art. 14); security assessment results are valid for 3 years (Art. 9).

    Takes effect2.5 years agoSource

October 20222 deadlines

  1. PDP Law enacted and in force

    Law takes effect on enactment, starting a 2-year transition.

    Takes effect3.9 years agoSource
  2. Singapore PDPA

    Higher financial penalty cap applies

    Maximum penalty rises to 10% of Singapore turnover for organizations with turnover above SGD 10 million.

    Enforcement4 years agoSource

June 20221 deadline

  1. Thailand PDPA

    PDPA main obligations take effect

    Core data protection obligations and penalties apply after postponement Royal Decrees.

    Takes effect4.3 years agoSource

April 20221 deadline

  1. 2020 amendments in force

    Mandatory breach reporting, pseudonymized information and stricter cross-border rules apply.

    Takes effect4.5 years agoSource

November 20211 deadline

  1. China PIPL

    PIPL takes effect

    All PIPL obligations (legal bases, consent, cross-border rules, data subject rights) apply (Art. 74).

    Takes effect4.9 years agoSource

September 20211 deadline

  1. Data Security Law takes effect

    Data classification, important-data protection and data export restrictions apply (Art. 55).

    Takes effect5.1 years agoSource

February 20211 deadline

  1. Singapore PDPA

    2020 amendments largely in force

    Mandatory data breach notification and revised consent framework apply.

    Takes effect5.6 years agoSource

December 20201 deadline

  1. Privacy Act 2020 in force

    IPPs, mandatory breach notification and compliance notices apply.

    Takes effect5.8 years agoSource

June 20171 deadline

  1. Cybersecurity Law takes effect

    Original CSL obligations for network operators and CII operators apply.

    Takes effect9.3 years agoSource

July 20141 deadline

  1. Singapore PDPA

    PDPA data protection obligations take effect

    Main data protection provisions come into force.

    Takes effect12.2 years agoSource

When the rules change: new data, privacy and AI laws and deadlines, the next morning.