Skip to content

Biometric privacy laws

14 regulations worldwide that deal with biometrics, with every phased deadline and the official source for each.

  • EU AI Act

    European Union

    AmendedAIBiometrics

    Next: Dec 2, 2026 New bans on sexual deepfakes and CSAM generation; Art 50(2) grace period ends

  • EnactedPrivacyData access and sharing

    Next: Dec 24, 2026 Member States must provide EU Digital Identity Wallets

  • EnactedPrivacyBiometrics

    Next: Jan 1, 2027 Louisiana Data Privacy Act takes effect

  • AmendedPrivacyChildren

    Next: Apr 1, 2027 Discretionary 60-day cure period ends

  • GDPR

    European Union

    AmendedPrivacyBreach notification

    Next: Apr 2, 2027 GDPR Procedural Regulation applies

  • South Korea PIPA

    South Korea

    AmendedPrivacyBreach notification

    Next: Jul 1, 2027 Mandatory ISMS-P certification

  • In forcePrivacyData residency

    Effective Nov 1, 2021

  • AmendedPrivacyChildren

    Effective Jul 1, 2023

  • DOJ Bulk Data Rule

    United States (Federal)

    In forcePrivacyData residency

    Effective Apr 8, 2025

  • AmendedBiometricsPrivacy

    Effective Oct 3, 2008

  • AmendedPrivacyChildren

    Effective Apr 1, 2005

  • AmendedPrivacyBreach notification

    Effective Nov 15, 2013

  • Quebec Law 25

    Quebec, Canada

    In forcePrivacyBreach notification

    Effective Sep 22, 2022

  • TRAIGA

    Texas

    In forceAIBiometrics

    Effective Jan 1, 2026

Upcoming deadlines

December 20262 deadlines

  1. EU AI Act

    New bans on sexual deepfakes and CSAM generation; Art 50(2) grace period ends

    New Art 5(1)(ba)/(bb) prohibitions on AI systems that generate non-consensual intimate imagery of identifiable persons or child sexual abuse material apply. Generative AI systems placed on the market before 2 Aug 2026 must comply with the Art 50(2) marking duty by this date (new Art 111(4)).

    Compliance deadlinein 2 monthsSource
  2. Member States must provide EU Digital Identity Wallets

    Each Member State must provide at least one wallet within 24 months of the entry into force of the implementing acts under Arts 5a(23) and 5c(6) (Art 5a(1)).

    Compliance deadlinein 3 monthsSource

January 20271 deadline

  1. Louisiana Data Privacy Act takes effect

    Consumer rights and controller duties apply (Act 502, Section 2); data protection assessment requirements apply to processing from this date.

    Takes effectin 3 monthsSource

April 20272 deadlines

  1. Discretionary 60-day cure period ends

    The Division's discretionary notice-and-cure (at least 60 days) applies only to violations occurring on or before April 1, 2027 (Com. Law 14-4614).

    Enforcementin 6 monthsSource
  2. GDPR

    GDPR Procedural Regulation applies

    Harmonised rules for cross-border complaint admissibility, rights to be heard and access to preliminary findings, and investigation timelines apply to DPAs from 2 April 2027 (Regulation (EU) 2025/2518, final article).

    Enforcementin 6 monthsSource

July 20272 deadlines

  1. South Korea PIPA

    Mandatory ISMS-P certification

    ISMS-P certification becomes mandatory for private entities meeting the statutory criteria.

    Compliance deadlinein 9 monthsSource
  2. 30-day cure period expires

    AG's obligation to give 30-day notice and allow cure before investigating applies only from Jan 1 through July 31, 2027 (R.S. 51:1780.5(D)).

    Enforcementin 10 monthsSource

August 20271 deadline

  1. EU AI Act

    Legacy GPAI models must comply; national AI sandboxes operational

    Providers of GPAI models placed on the market before 2 Aug 2025 must comply (Art 111(3)). Each Member State must have at least one national AI regulatory sandbox operational (Art 57(1) as amended by the Omnibus).

    Compliance deadlinein 10 monthsSource

December 20272 deadlines

  1. EU AI Act

    High-risk obligations apply to Annex III systems

    Chapter III Sections 1-3 (high-risk requirements and provider/deployer obligations) apply to AI systems classified high-risk under Art 6(2) and Annex III (employment, credit scoring, education, biometrics, essential services and similar). Deferred from 2 Aug 2026 by Regulation (EU) 2026/1744.

    Compliance deadlinein 14 monthsSource
  2. Private relying parties must accept wallets

    Private relying parties required by law or contract to use strong user authentication must accept wallets on user request within 36 months of the implementing acts' entry into force (Art 5f(2)).

    Compliance deadlinein 15 monthsSource

August 20281 deadline

  1. EU AI Act

    High-risk obligations apply to Annex I product-embedded systems

    Chapter III Sections 1-3 apply to AI systems classified high-risk under Art 6(1) and Annex I (safety components of products covered by EU harmonisation legislation). Deferred from 2 Aug 2027 by Regulation (EU) 2026/1744.

    Compliance deadlinein 22 monthsSource

August 20301 deadline

  1. EU AI Act

    Public-authority high-risk systems must comply

    Providers and deployers of high-risk AI systems intended for use by public authorities that were placed on the market before the Chapter III application date must comply (Art 111(2), as replaced by the Omnibus).

    Compliance deadlinein 3.9 yearsSource

December 20301 deadline

  1. EU AI Act

    Large-scale EU IT systems must comply

    AI systems that are components of the large-scale IT systems in Annex X (e.g. SIS, VIS, Eurodac, EES, ETIAS) placed on the market before 2 Aug 2027 must be brought into compliance (Art 111(1)).

    Compliance deadlinein 4.3 yearsSource

Past deadlines

September 20261 deadline

  1. South Korea PIPA

    2026 PIPA amendments take effect

    10%-of-revenue fines, CEO accountability, and notice duties for possible breaches apply.

    Takes effect13 days agoSource

August 20261 deadline

  1. EU AI Act

    General application: transparency obligations, GPAI fines, most other rules

    The AI Act's general date of application. Article 50 transparency obligations (chatbot disclosure, deepfake labelling, machine-readable marking of synthetic content) and Commission fines on GPAI providers (Art 101) apply. Not deferred by the Omnibus.

    Takes effect53 days agoSource

July 20262 deadlines

  1. EU AI Act

    Digital Omnibus on AI enters into force

    Regulation (EU) 2026/1744 (adopted 8 July 2026, OJ 24 July 2026) enters into force on the third day after publication. Amended Articles 102 to 110 apply from this date (new Art 113(d)).

    Transition59 days agoSource
  2. 2026 APPI amendment act promulgated

    Amendment enacted by the Diet on 10 July 2026 and promulgated; main provisions take effect by cabinet order within two years of promulgation.

    Transition2 months agoSource

May 20261 deadline

  1. Legacy qualified trust service providers conformity report

    QTSPs qualified before 20 May 2024 had to submit a conformity assessment report proving compliance with Art 24(1), (1a) and (1b) by 21 May 2026.

    Compliance deadline4 months agoSource

April 20262 deadlines

  1. MODPA applies to personal data processing

    The act applies to personal data processing activities from April 1, 2026 (Section 2 of ch. 455).

    Compliance deadline6 months agoSource
  2. Seventh Circuit: amendment applies retroactively

    Clay v. Union Pacific (No. 25-2185) holds the damages amendment is remedial and applies to pending cases.

    Transition6 months agoSource

March 20261 deadline

  1. South Korea PIPA

    2026 PIPA amendment promulgated (Act No. 21445)

    Amendment raising fines to 10% of revenue and adding CEO accountability promulgated.

    Transition7 months agoSource

January 20262 deadlines

  1. TRAIGA

    TRAIGA takes effect

    Prohibited-practice rules, AG enforcement, sandbox program and government AI disclosure duties apply.

    Takes effect9 months agoSource
  2. GDPR

    GDPR Procedural Regulation enters into force

    Regulation (EU) 2025/2518, published in the OJ on 12 December 2025, enters into force on the twentieth day after publication.

    Transition9 months agoSource

November 20251 deadline

  1. GDPR

    GDPR Procedural Regulation adopted

    Regulation (EU) 2025/2518 laying down additional procedural rules for cross-border GDPR enforcement signed by Parliament and Council.

    Transition10 months agoSource

October 20253 deadlines

  1. DOJ Bulk Data Rule

    Due diligence, audit and reporting obligations apply

    Subpart J (data compliance program, due diligence and audits for restricted transactions) and reporting requirements in 202.1103 and 202.1104 apply.

    Compliance deadline12 months agoSource
  2. MODPA takes effect

    Act takes effect; data protection assessments apply to processing activities on or after Oct 1, 2025.

    Takes effect12 months agoSource
  3. Minors' data amendment (SB 24-041) effective

    Controllers offering online services to minors must use reasonable care, conduct assessments, and obtain consent for targeted ads, sale and certain profiling of minors.

    Takes effect12 months agoSource

August 20251 deadline

  1. EU AI Act

    GPAI, governance, notified bodies and penalties apply

    Chapter III Section 4 (notifying authorities), Chapter V (general-purpose AI model obligations), Chapter VII (governance), Chapter XII (penalties, except Art 101) and Art 78 apply (Art 113(b)).

    Takes effect14 months agoSource

July 20251 deadline

  1. Biometric identifier amendment (HB 24-1130) effective

    Any controller processing biometric identifiers must adopt a written biometric policy, give notice, obtain consent and follow retention/deletion rules.

    Takes effect15 months agoSource

June 20252 deadlines

  1. TRAIGA

    HB 149 signed

    Governor Abbott signs TRAIGA.

    Transition15 months agoSource
  2. PDPA amendments phase 3

    Mandatory DPO appointment, data breach notification, and data portability take effect.

    Compliance deadline16 months agoSource

May 20251 deadline

  1. SB 25-276 geolocation and sensitive-data sale amendment effective

    Adds precise geolocation data definitions and prohibits selling sensitive data without consent (effective on signature).

    Takes effect16 months agoSource

April 20252 deadlines

  1. DOJ Bulk Data Rule

    Prohibitions and restrictions take effect

    Core prohibitions on covered data transactions and security requirements for restricted transactions apply.

    Takes effect18 months agoSource
  2. PDPA amendments phase 2

    'Data controller' terminology, biometric data as sensitive data, higher penalties, Security Principle for processors, and removal of the cross-border whitelist take effect.

    Takes effect18 months agoSource

February 20251 deadline

  1. EU AI Act

    Prohibited practices and AI literacy apply

    Chapters I and II apply, including the Article 5 bans on prohibited AI practices and the Article 4 AI literacy duty (Art 113(a)).

    Takes effect20 months agoSource

January 20252 deadlines

  1. PDPA amendments phase 1

    Miscellaneous provisions commence (e.g. electronic service of notices).

    Takes effect21 months agoSource
  2. 60-day cure period expires

    Mandatory 60-day notice-and-cure before AG enforcement ends; enforcement may proceed without cure.

    Enforcement21 months agoSource

December 20241 deadline

  1. First wallet implementing acts enter into force

    Commission Implementing Regulations (EU) 2024/2977, 2024/2979, 2024/2980, 2024/2981 and 2024/2982 (adopted 28 Nov 2024, published 4 Dec 2024) enter into force. This starts the wallet deadline clocks in Arts 5a and 5f.

    Takes effect21 months agoSource

September 20241 deadline

  1. Quebec Law 25

    Phase 3: data portability

    Right to data portability in a structured, commonly used technological format applies.

    Compliance deadline2 years agoSource

August 20242 deadlines

  1. SB 2979 amendment effective

    Public Act 103-0769 signed and effective immediately: single recovery per person and electronic signatures allowed for consent.

    Takes effect2.1 years agoSource
  2. EU AI Act

    AI Act enters into force

    Regulation (EU) 2024/1689 enters into force twenty days after publication on 12 July 2024 (Art 113).

    Takes effect2.1 years agoSource

July 20241 deadline

  1. Universal opt-out mechanism recognition required

    Controllers must honor AG-recognized universal opt-out mechanisms (e.g. Global Privacy Control).

    Compliance deadline2.2 years agoSource

May 20241 deadline

  1. eIDAS 2 enters into force

    Regulation (EU) 2024/1183 entered into force on the twentieth day after publication on 30 Apr 2024 (Art 2).

    Takes effect2.3 years agoSource

September 20231 deadline

  1. Quebec Law 25

    Phase 2: main obligations and penalties

    Governance policies, PIAs, consent, transparency, privacy by default, ADM notices, cross-border PIAs and AMP/penal regime apply.

    Compliance deadline3 years agoSource

July 20231 deadline

  1. CPA takes effect

    Core consumer rights and controller duties apply.

    Takes effect3.2 years agoSource

September 20221 deadline

  1. Quebec Law 25

    Phase 1: privacy officer and incident reporting

    Person in charge of personal information protection, confidentiality incident notification and register apply.

    Compliance deadline4 years agoSource

April 20221 deadline

  1. 2020 amendments in force

    Mandatory breach reporting, pseudonymized information and stricter cross-border rules apply.

    Takes effect4.5 years agoSource

November 20211 deadline

  1. China PIPL

    PIPL takes effect

    All PIPL obligations (legal bases, consent, cross-border rules, data subject rights) apply (Art. 74).

    Takes effect4.9 years agoSource

September 20211 deadline

  1. Quebec Law 25

    Assent

    Bill 64 assented to as S.Q. 2021, c. 25.

    Takes effect5 years agoSource

May 20181 deadline

  1. GDPR

    GDPR applies

    All GDPR obligations apply from 25 May 2018 (Art 99(2)), replacing Directive 95/46/EC.

    Takes effect8.3 years agoSource

May 20161 deadline

  1. GDPR

    GDPR enters into force

    Regulation entered into force on the twentieth day after publication in OJ L 119 of 4 May 2016 (Art 99(1)).

    Takes effect10.3 years agoSource

October 20081 deadline

  1. BIPA effective

    The Biometric Information Privacy Act takes effect.

    Takes effect18 years agoSource

When the rules change: new data, privacy and AI laws and deadlines, the next morning.