Biometric privacy laws
14 regulations worldwide that deal with biometrics, with every phased deadline and the official source for each.
14 regulations
Add to calendar
- EU AI Act
European Union
AmendedAIBiometricsNext: Dec 2, 2026 New bans on sexual deepfakes and CSAM generation; Art 50(2) grace period ends
- eIDAS 2 / EU Digital Identity Wallet
European Union
EnactedPrivacyData access and sharingNext: Dec 24, 2026 Member States must provide EU Digital Identity Wallets
- Louisiana Data Privacy Act
Louisiana
EnactedPrivacyBiometricsNext: Jan 1, 2027 Louisiana Data Privacy Act takes effect
- AmendedPrivacyChildren
Next: Apr 1, 2027 Discretionary 60-day cure period ends
- GDPR
European Union
AmendedPrivacyBreach notificationNext: Apr 2, 2027 GDPR Procedural Regulation applies
- South Korea PIPA
South Korea
AmendedPrivacyBreach notificationNext: Jul 1, 2027 Mandatory ISMS-P certification
- China PIPL
China
In forcePrivacyData residencyEffective Nov 1, 2021
- Colorado Privacy Act (CPA)
Colorado
AmendedPrivacyChildrenEffective Jul 1, 2023
- DOJ Bulk Data Rule
United States (Federal)
In forcePrivacyData residencyEffective Apr 8, 2025
- Illinois BIPA
Illinois
AmendedBiometricsPrivacyEffective Oct 3, 2008
- Japan APPI
Japan
AmendedPrivacyChildrenEffective Apr 1, 2005
- Malaysia PDPA
Malaysia
AmendedPrivacyBreach notificationEffective Nov 15, 2013
- Quebec Law 25
Quebec, Canada
In forcePrivacyBreach notificationEffective Sep 22, 2022
- TRAIGA
Texas
In forceAIBiometricsEffective Jan 1, 2026
Upcoming deadlines
December 20262 deadlines
- EU AI ActEuropean Union
New bans on sexual deepfakes and CSAM generation; Art 50(2) grace period ends
New Art 5(1)(ba)/(bb) prohibitions on AI systems that generate non-consensual intimate imagery of identifiable persons or child sexual abuse material apply. Generative AI systems placed on the market before 2 Aug 2026 must comply with the Art 50(2) marking duty by this date (new Art 111(4)).
- eIDAS 2 / EU Digital Identity WalletEuropean Union
Member States must provide EU Digital Identity Wallets
Each Member State must provide at least one wallet within 24 months of the entry into force of the implementing acts under Arts 5a(23) and 5c(6) (Art 5a(1)).
January 20271 deadline
- Louisiana Data Privacy ActLouisiana
Louisiana Data Privacy Act takes effect
Consumer rights and controller duties apply (Act 502, Section 2); data protection assessment requirements apply to processing from this date.
April 20272 deadlines
Discretionary 60-day cure period ends
The Division's discretionary notice-and-cure (at least 60 days) applies only to violations occurring on or before April 1, 2027 (Com. Law 14-4614).
July 20272 deadlines
Mandatory ISMS-P certification
ISMS-P certification becomes mandatory for private entities meeting the statutory criteria.
- Louisiana Data Privacy ActLouisiana
30-day cure period expires
AG's obligation to give 30-day notice and allow cure before investigating applies only from Jan 1 through July 31, 2027 (R.S. 51:1780.5(D)).
August 20271 deadline
- EU AI ActEuropean Union
Legacy GPAI models must comply; national AI sandboxes operational
Providers of GPAI models placed on the market before 2 Aug 2025 must comply (Art 111(3)). Each Member State must have at least one national AI regulatory sandbox operational (Art 57(1) as amended by the Omnibus).
December 20272 deadlines
- EU AI ActEuropean Union
High-risk obligations apply to Annex III systems
Chapter III Sections 1-3 (high-risk requirements and provider/deployer obligations) apply to AI systems classified high-risk under Art 6(2) and Annex III (employment, credit scoring, education, biometrics, essential services and similar). Deferred from 2 Aug 2026 by Regulation (EU) 2026/1744.
- eIDAS 2 / EU Digital Identity WalletEuropean Union
Private relying parties must accept wallets
Private relying parties required by law or contract to use strong user authentication must accept wallets on user request within 36 months of the implementing acts' entry into force (Art 5f(2)).
August 20281 deadline
- EU AI ActEuropean Union
High-risk obligations apply to Annex I product-embedded systems
Chapter III Sections 1-3 apply to AI systems classified high-risk under Art 6(1) and Annex I (safety components of products covered by EU harmonisation legislation). Deferred from 2 Aug 2027 by Regulation (EU) 2026/1744.
August 20301 deadline
- EU AI ActEuropean Union
Public-authority high-risk systems must comply
Providers and deployers of high-risk AI systems intended for use by public authorities that were placed on the market before the Chapter III application date must comply (Art 111(2), as replaced by the Omnibus).
December 20301 deadline
Past deadlines
September 20261 deadline
2026 PIPA amendments take effect
10%-of-revenue fines, CEO accountability, and notice duties for possible breaches apply.
August 20261 deadline
- EU AI ActEuropean Union
General application: transparency obligations, GPAI fines, most other rules
The AI Act's general date of application. Article 50 transparency obligations (chatbot disclosure, deepfake labelling, machine-readable marking of synthetic content) and Commission fines on GPAI providers (Art 101) apply. Not deferred by the Omnibus.
July 20262 deadlines
2026 APPI amendment act promulgated
Amendment enacted by the Diet on 10 July 2026 and promulgated; main provisions take effect by cabinet order within two years of promulgation.
May 20261 deadline
- eIDAS 2 / EU Digital Identity WalletEuropean Union
Legacy qualified trust service providers conformity report
QTSPs qualified before 20 May 2024 had to submit a conformity assessment report proving compliance with Art 24(1), (1a) and (1b) by 21 May 2026.
April 20262 deadlines
MODPA applies to personal data processing
The act applies to personal data processing activities from April 1, 2026 (Section 2 of ch. 455).
Seventh Circuit: amendment applies retroactively
Clay v. Union Pacific (No. 25-2185) holds the damages amendment is remedial and applies to pending cases.
March 20261 deadline
2026 PIPA amendment promulgated (Act No. 21445)
Amendment raising fines to 10% of revenue and adding CEO accountability promulgated.
January 20262 deadlines
November 20251 deadline
October 20253 deadlines
Due diligence, audit and reporting obligations apply
Subpart J (data compliance program, due diligence and audits for restricted transactions) and reporting requirements in 202.1103 and 202.1104 apply.
MODPA takes effect
Act takes effect; data protection assessments apply to processing activities on or after Oct 1, 2025.
Minors' data amendment (SB 24-041) effective
Controllers offering online services to minors must use reasonable care, conduct assessments, and obtain consent for targeted ads, sale and certain profiling of minors.
August 20251 deadline
- EU AI ActEuropean Union
GPAI, governance, notified bodies and penalties apply
Chapter III Section 4 (notifying authorities), Chapter V (general-purpose AI model obligations), Chapter VII (governance), Chapter XII (penalties, except Art 101) and Art 78 apply (Art 113(b)).
July 20251 deadline
Biometric identifier amendment (HB 24-1130) effective
Any controller processing biometric identifiers must adopt a written biometric policy, give notice, obtain consent and follow retention/deletion rules.
June 20252 deadlines
PDPA amendments phase 3
Mandatory DPO appointment, data breach notification, and data portability take effect.
May 20251 deadline
SB 25-276 geolocation and sensitive-data sale amendment effective
Adds precise geolocation data definitions and prohibits selling sensitive data without consent (effective on signature).
April 20252 deadlines
Prohibitions and restrictions take effect
Core prohibitions on covered data transactions and security requirements for restricted transactions apply.
PDPA amendments phase 2
'Data controller' terminology, biometric data as sensitive data, higher penalties, Security Principle for processors, and removal of the cross-border whitelist take effect.
February 20251 deadline
January 20252 deadlines
PDPA amendments phase 1
Miscellaneous provisions commence (e.g. electronic service of notices).
60-day cure period expires
Mandatory 60-day notice-and-cure before AG enforcement ends; enforcement may proceed without cure.
December 20241 deadline
- eIDAS 2 / EU Digital Identity WalletEuropean Union
First wallet implementing acts enter into force
Commission Implementing Regulations (EU) 2024/2977, 2024/2979, 2024/2980, 2024/2981 and 2024/2982 (adopted 28 Nov 2024, published 4 Dec 2024) enter into force. This starts the wallet deadline clocks in Arts 5a and 5f.
September 20241 deadline
Phase 3: data portability
Right to data portability in a structured, commonly used technological format applies.
August 20242 deadlines
SB 2979 amendment effective
Public Act 103-0769 signed and effective immediately: single recovery per person and electronic signatures allowed for consent.
July 20241 deadline
Universal opt-out mechanism recognition required
Controllers must honor AG-recognized universal opt-out mechanisms (e.g. Global Privacy Control).
May 20241 deadline
- eIDAS 2 / EU Digital Identity WalletEuropean Union
eIDAS 2 enters into force
Regulation (EU) 2024/1183 entered into force on the twentieth day after publication on 30 Apr 2024 (Art 2).
September 20231 deadline
Phase 2: main obligations and penalties
Governance policies, PIAs, consent, transparency, privacy by default, ADM notices, cross-border PIAs and AMP/penal regime apply.
July 20231 deadline
CPA takes effect
Core consumer rights and controller duties apply.
September 20221 deadline
Phase 1: privacy officer and incident reporting
Person in charge of personal information protection, confidentiality incident notification and register apply.
April 20221 deadline
2020 amendments in force
Mandatory breach reporting, pseudonymized information and stricter cross-border rules apply.
November 20211 deadline
- China PIPLChina
PIPL takes effect
All PIPL obligations (legal bases, consent, cross-border rules, data subject rights) apply (Art. 74).
September 20211 deadline
Assent
Bill 64 assented to as S.Q. 2021, c. 25.
May 20181 deadline
May 20161 deadline
October 20081 deadline
BIPA effective
The Biometric Information Privacy Act takes effect.