Asia-Pacific data protection and AI laws
China, India, Japan, Korea, Australia, Singapore, Vietnam, Indonesia and more.
12 jurisdictions with tracked laws. Tap one to open it.
23 regulations
Add to calendar
- India DPDP Act
India
EnactedPrivacyChildrenNext: Nov 13, 2026 Consent Manager registration rule in force (12 months)
- Australia Privacy Act
Australia
AmendedPrivacyChildrenNext: Dec 10, 2026 Children's Online Privacy Code must be registered
- Indonesia PDP Law
Indonesia
AmendedPrivacyBreach notificationNext: Jan 16, 2027 Implementing regulation GR 33/2026 takes effect
- Vietnam AI Law
Vietnam
In forceAINext: Mar 1, 2027 Transition ends for existing AI systems (general)
- South Korea PIPA
South Korea
AmendedPrivacyBreach notificationNext: Jul 1, 2027 Mandatory ISMS-P certification
- In forceCybersecurityBreach notification
Effective Nov 30, 2024
- Australia Social Media Minimum Age
Australia
In forceChildrenOnline safetyEffective Dec 10, 2025
- In forceAIOnline safety
Effective Sep 1, 2025
- In forceData residencyPrivacy
Effective Mar 22, 2024
- AmendedCybersecurityData residency
Effective Jun 1, 2017
- In forceCybersecurityData residency
Effective Sep 1, 2021
- In forcePrivacyCybersecurity
Effective Jan 1, 2025
- In forcePrivacy
Effective May 1, 2025
- China PIPL
China
In forcePrivacyData residencyEffective Nov 1, 2021
- In forceCybersecurityBreach notification
Effective Jan 1, 2026
- In forceAI
Effective Jun 4, 2025
- Japan APPI
Japan
AmendedPrivacyChildrenEffective Apr 1, 2005
- Malaysia PDPA
Malaysia
AmendedPrivacyBreach notificationEffective Nov 15, 2013
- New Zealand Privacy Act
New Zealand
AmendedPrivacyBreach notificationEffective Dec 1, 2020
- Singapore PDPA
Singapore
In forcePrivacyBreach notificationEffective Jul 2, 2014
- South Korea AI Basic Act
South Korea
In forceAIEffective Jan 22, 2026
- Thailand PDPA
Thailand
In forcePrivacyBreach notificationEffective Jun 1, 2022
- Vietnam PDPL
Vietnam
In forcePrivacyData residencyEffective Jan 1, 2026
Upcoming deadlines
November 20261 deadline
Consent Manager registration rule in force (12 months)
Rule 4 (registration and obligations of Consent Managers) comes into force one year after publication.
December 20262 deadlines
Children's Online Privacy Code must be registered
OAIC must develop and register the Children's Online Privacy Code within 24 months of Royal Assent.
Automated decision-making transparency applies
Privacy policies must disclose the kinds of personal information used in substantially automated decisions that significantly affect individuals (24 months after assent).
January 20271 deadline
Implementing regulation GR 33/2026 takes effect
Detailed PDP implementing rules (DPIA, cross-border, children's consent) apply, 6 months after the 16 Jul 2026 enactment.
March 20271 deadline
Transition ends for existing AI systems (general)
Existing AI systems in most sectors must comply (12-month transition).
May 20271 deadline
Main data fiduciary obligations apply (18 months)
Rules 3, 5-16, 22 and 23 (notice, security safeguards, breach notification, retention, children's consent, SDF duties, cross-border) come into force 18 months after publication.
July 20271 deadline
Mandatory ISMS-P certification
ISMS-P certification becomes mandatory for private entities meeting the statutory criteria.
September 20271 deadline
Transition ends for existing AI systems in health, education and finance
Existing AI systems in healthcare, education and finance must comply (18-month transition).
Past deadlines
September 20261 deadline
2026 PIPA amendments take effect
10%-of-revenue fines, CEO accountability, and notice duties for possible breaches apply.
July 20261 deadline
2026 APPI amendment act promulgated
Amendment enacted by the Diet on 10 July 2026 and promulgated; main provisions take effect by cabinet order within two years of promulgation.
May 20261 deadline
IPP 3A indirect-collection notification applies
Agencies collecting personal information from third parties must take reasonable steps to notify individuals, subject to exceptions.
March 20262 deadlines
2026 PIPA amendment promulgated (Act No. 21445)
Amendment raising fines to 10% of revenue and adding CEO accountability promulgated.
AI Law takes effect
Risk classification, transparency and labeling obligations apply to new AI systems.
January 20265 deadlines
AI Basic Act and Enforcement Decree take effect
Transparency, labeling, high-impact AI, and domestic representative obligations apply (fines deferred during the grace period).
PDPL and Decree 356/2025 take effect
Personal data protection obligations, DPIA/TIA filing and penalty framework apply; Decree 13/2023 replaced.
PCICSO comes into operation
Commissioner's Office is established and designation of CIOs begins; obligations apply to designated operators.
2025 amendments take effect
Higher fines, first-violation fines, AI governance provisions and PIPL-alignment duties apply under the 28 Oct 2025 NPCSC Decision.
Ransomware reporting moves to compliance phase
The education-first phase (30 May-31 Dec 2025) ends; Home Affairs moves to a compliance and education approach for missed reports.
December 20251 deadline
Social media minimum age obligation applies
Age-restricted platforms must take reasonable steps to prevent under-16s from holding accounts.
November 20251 deadline
DPDP Rules published; Board and procedural rules in force
Rules 1, 2 and 17-21 (Data Protection Board constitution and functioning) take effect on publication in the Official Gazette.
September 20253 deadlines
Privacy Amendment Act 2025 technical changes commence
Technical amendments commence the day after Royal Assent (23 Sep 2025).
AI Promotion Act fully in force
Provisions establishing the AI Strategy Headquarters and AI Basic Plan take effect.
AI content labeling measures and GB 45438-2025 take effect
Explicit and implicit labeling duties for AI-generated content and platform detection duties apply.
June 20253 deadlines
Statutory tort for serious invasions of privacy commences
Individuals can sue for serious invasions of privacy (Schedule 2), 6 months after Royal Assent.
AI Promotion Act promulgated and partly in force
Most provisions, including basic principles and stakeholder duties, take effect on promulgation.
PDPA amendments phase 3
Mandatory DPO appointment, data breach notification, and data portability take effect.
May 20252 deadlines
Ransomware payment reporting starts
Reporting business entities must report ransomware/cyber-extortion payments to ASD within 72 hours of payment.
PI compliance audit measures take effect
Self-audit and regulator-ordered audit regime applies; 10M+ processors must audit at least every two years.
April 20251 deadline
PDPA amendments phase 2
'Data controller' terminology, biometric data as sensitive data, higher penalties, Security Principle for processors, and removal of the cross-border whitelist take effect.
January 20252 deadlines
PDPA amendments phase 1
Miscellaneous provisions commence (e.g. electronic service of notices).
Network Data Regulations take effect
All provisions, including the 10-million-person threshold duties and annual important-data risk assessments, apply.
December 20241 deadline
Most POLA Act 2024 amendments commence
Tiered penalties, infringement notices, OAIC powers, security and overseas-transfer clarifications and doxxing offences commence the day after Royal Assent.
October 20241 deadline
PDP Law transition ends
Controllers and processors must fully comply (Art. 74 two-year transition).
March 20241 deadline
Cross-border data flow provisions take effect
Exemptions and volume thresholds apply from publication (Art. 14); security assessment results are valid for 3 years (Art. 9).
October 20222 deadlines
PDP Law enacted and in force
Law takes effect on enactment, starting a 2-year transition.
- Singapore PDPASingapore
Higher financial penalty cap applies
Maximum penalty rises to 10% of Singapore turnover for organizations with turnover above SGD 10 million.
June 20221 deadline
- Thailand PDPAThailand
PDPA main obligations take effect
Core data protection obligations and penalties apply after postponement Royal Decrees.
April 20221 deadline
2020 amendments in force
Mandatory breach reporting, pseudonymized information and stricter cross-border rules apply.
November 20211 deadline
- China PIPLChina
PIPL takes effect
All PIPL obligations (legal bases, consent, cross-border rules, data subject rights) apply (Art. 74).
September 20211 deadline
Data Security Law takes effect
Data classification, important-data protection and data export restrictions apply (Art. 55).
February 20211 deadline
- Singapore PDPASingapore
2020 amendments largely in force
Mandatory data breach notification and revised consent framework apply.
December 20201 deadline
Privacy Act 2020 in force
IPPs, mandatory breach notification and compliance notices apply.
June 20171 deadline
Cybersecurity Law takes effect
Original CSL obligations for network operators and CII operators apply.
July 20141 deadline
- Singapore PDPASingapore
PDPA data protection obligations take effect
Main data protection provisions come into force.