Skip to content

Children and teen online privacy laws

26 regulations worldwide that deal with children, with every phased deadline and the official source for each.

Upcoming deadlines

October 20261 deadline

  1. PA 26-64 (SB 4) amendments take effect

    Prohibits controllers and third parties from selling precise geolocation data and enacts data broker and other consumer protection provisions.

    Takes effectin 7 daysSource

November 20261 deadline

  1. Consent Manager registration rule in force (12 months)

    Rule 4 (registration and obligations of Consent Managers) comes into force one year after publication.

    Transitionin 50 daysSource

December 20263 deadlines

  1. EU AI Act

    New bans on sexual deepfakes and CSAM generation; Art 50(2) grace period ends

    New Art 5(1)(ba)/(bb) prohibitions on AI systems that generate non-consensual intimate imagery of identifiable persons or child sexual abuse material apply. Generative AI systems placed on the market before 2 Aug 2026 must comply with the Art 50(2) marking duty by this date (new Art 111(4)).

    Compliance deadlinein 2 monthsSource
  2. Children's Online Privacy Code must be registered

    OAIC must develop and register the Children's Online Privacy Code within 24 months of Royal Assent.

    Compliance deadlinein 3 monthsSource
  3. Automated decision-making transparency applies

    Privacy policies must disclose the kinds of personal information used in substantially automated decisions that significantly affect individuals (24 months after assent).

    Compliance deadlinein 3 monthsSource

January 20276 deadlines

  1. CCPA / CPRA

    ADMT requirements compliance date

    Businesses using ADMT for significant decisions must comply with Article 11 (pre-use notice, opt-out, access rights) by this date (11 CCR 7200(b)).

    Compliance deadlinein 3 monthsSource
  2. CCPA / CPRA

    Browsers must support opt-out preference signal (AB 566)

    Businesses that develop or maintain a browser must include consumer-configurable functionality to send an opt-out preference signal (Civ. Code 1798.136, operative Jan 1, 2027).

    Compliance deadlinein 3 monthsSource
  3. Data broker registration required

    Data brokers may not sell or license brokered personal data in Connecticut unless registered with the Department of Consumer Protection ($2,500 initial fee).

    Compliance deadlinein 3 monthsSource
  4. Amended thresholds and third-party duties take effect

    Applicability drops to 10,000 consumers (or 5,000 + 20% revenue from sale) and new third-party duties (12D-107A) apply.

    Takes effectin 3 monthsSource
  5. Ban on selling personal data of children under 13 (HB 1460)

    HB 1460 (2026, ch. 168) prohibits controllers from selling the personal data of a child under 13.

    Takes effectin 3 monthsSource
  6. Implementing regulation GR 33/2026 takes effect

    Detailed PDP implementing rules (DPIA, cross-border, children's consent) apply, 6 months after the 16 Jul 2026 enactment.

    Compliance deadlinein 4 monthsSource

April 20272 deadlines

  1. Discretionary 60-day cure period ends

    The Division's discretionary notice-and-cure (at least 60 days) applies only to violations occurring on or before April 1, 2027 (Com. Law 14-4614).

    Enforcementin 6 monthsSource
  2. GDPR

    GDPR Procedural Regulation applies

    Harmonised rules for cross-border complaint admissibility, rights to be heard and access to preliminary findings, and investigation timelines apply to DPAs from 2 April 2027 (Regulation (EU) 2025/2518, final article).

    Enforcementin 6 monthsSource

May 20271 deadline

  1. Main data fiduciary obligations apply (18 months)

    Rules 3, 5-16, 22 and 23 (notice, security safeguards, breach notification, retention, children's consent, SDF duties, cross-border) come into force 18 months after publication.

    Compliance deadlinein 8 monthsSource

July 20271 deadline

  1. First annual report to Office of Suicide Prevention

    Operators begin annual reporting on crisis referrals and detection protocols.

    Reportingin 9 monthsSource

August 20271 deadline

  1. EU AI Act

    Legacy GPAI models must comply; national AI sandboxes operational

    Providers of GPAI models placed on the market before 2 Aug 2025 must comply (Art 111(3)). Each Member State must have at least one national AI regulatory sandbox operational (Art 57(1) as amended by the Omnibus).

    Compliance deadlinein 10 monthsSource

December 20272 deadlines

  1. EU AI Act

    High-risk obligations apply to Annex III systems

    Chapter III Sections 1-3 (high-risk requirements and provider/deployer obligations) apply to AI systems classified high-risk under Art 6(2) and Annex III (employment, credit scoring, education, biometrics, essential services and similar). Deferred from 2 Aug 2026 by Regulation (EU) 2026/1744.

    Compliance deadlinein 14 monthsSource
  2. CCPA / CPRA

    Risk assessments for pre-existing processing due

    Risk assessments must be completed and documented for high-risk processing that began before Jan 1, 2026 and continues after (11 CCR 7155(b)).

    Compliance deadlinein 15 monthsSource

April 20282 deadlines

  1. CCPA / CPRA

    First risk assessment submission to CPPA

    Businesses must submit required risk assessment information and attestation for assessments conducted in 2026 and 2027 (11 CCR 7157(a)(1)); annually by April 1 thereafter.

    Reportingin 18 monthsSource
  2. CCPA / CPRA

    Cybersecurity audit due: revenue over $100M

    First cybersecurity audit report (covering Jan 1, 2027 - Jan 1, 2028) and certification due for businesses with 2026 annual gross revenue over $100M (11 CCR 7121(a)(1)).

    Reportingin 18 monthsSource

August 20281 deadline

  1. EU AI Act

    High-risk obligations apply to Annex I product-embedded systems

    Chapter III Sections 1-3 apply to AI systems classified high-risk under Art 6(1) and Annex I (safety components of products covered by EU harmonisation legislation). Deferred from 2 Aug 2027 by Regulation (EU) 2026/1744.

    Compliance deadlinein 22 monthsSource

October 20281 deadline

  1. Data brokers must process state deletion mechanism requests

    Registered data brokers must access the DCP accessible deletion mechanism at least every 45 days and process deletion requests.

    Compliance deadlinein 2 yearsSource

April 20291 deadline

  1. CCPA / CPRA

    Cybersecurity audit due: revenue $50M-$100M

    First cybersecurity audit report (covering 2028) due for businesses with 2027 annual gross revenue between $50M and $100M (11 CCR 7121(a)(2)).

    Reportingin 2.5 yearsSource

April 20301 deadline

  1. CCPA / CPRA

    Cybersecurity audit due: revenue under $50M

    First cybersecurity audit report (covering 2029) due for covered businesses with 2028 annual gross revenue under $50M (11 CCR 7121(a)(3)); annual by April 1 thereafter.

    Reportingin 3.5 yearsSource

August 20301 deadline

  1. EU AI Act

    Public-authority high-risk systems must comply

    Providers and deployers of high-risk AI systems intended for use by public authorities that were placed on the market before the Chapter III application date must comply (Art 111(2), as replaced by the Omnibus).

    Compliance deadlinein 3.9 yearsSource

December 20301 deadline

  1. EU AI Act

    Large-scale EU IT systems must comply

    AI systems that are components of the large-scale IT systems in Annex X (e.g. SIS, VIS, Eurodac, EES, ETIAS) placed on the market before 2 Aug 2027 must be brought into compliance (Art 111(1)).

    Compliance deadlinein 4.3 yearsSource

Past deadlines

August 20263 deadlines

  1. Digital Services Act

    ChatGPT designated as VLOSE; Reddit and Roblox as VLOPs

    Commission designated ChatGPT as a very large online search engine and Reddit and Roblox as very large online platforms. They have four months (by January 2027) to meet VLOP/VLOSE obligations.

    Enforcement24 days agoSource
  2. EU AI Act

    General application: transparency obligations, GPAI fines, most other rules

    The AI Act's general date of application. Article 50 transparency obligations (chatbot disclosure, deepfake labelling, machine-readable marking of synthetic content) and Commission fines on GPAI providers (Art 101) apply. Not deferred by the Omnibus.

    Takes effect53 days agoSource
  3. Profiling impact assessments apply

    Impact assessment requirements apply to profiling activities created or generated on or after Aug 1, 2026 (Conn. Gen. Stat. 42-522 as amended).

    Compliance deadline54 days agoSource

July 20265 deadlines

  1. EU AI Act

    Digital Omnibus on AI enters into force

    Regulation (EU) 2026/1744 (adopted 8 July 2026, OJ 24 July 2026) enters into force on the third day after publication. Amended Articles 102 to 110 apply from this date (new Art 113(d)).

    Transition59 days agoSource
  2. 2026 APPI amendment act promulgated

    Amendment enacted by the Diet on 10 July 2026 and promulgated; main provisions take effect by cabinet order within two years of promulgation.

    Transition2 months agoSource
  3. Ban on selling precise geolocation data (SB 338)

    Controllers may not sell consumers' precise geolocation data (1,750-ft radius), replacing the prior consent-based treatment.

    Takes effect3 months agoSource
  4. Mandatory 30-day cure period expires

    The Division's duty to issue a cure notice before enforcement ends on the first day of the 18th month after the effective date (N.J.S.A. 56:8-166.17(b)).

    Enforcement3 months agoSource
  5. PA 25-113 (SB 1295) amendments take effect

    Thresholds drop to 35,000 consumers or any sensitive-data processing or data sale; expanded sensitive data, minors' protections, and LLM-training disclosure in privacy notices.

    Takes effect3 months agoSource

June 20261 deadline

  1. A5328 sensitive data sale ban takes effect

    A5328, signed June 30, 2026, prohibits selling sensitive personal data; the ban took effect on signing.

    Takes effect3 months agoSource

May 20261 deadline

  1. TAKE IT DOWN Act

    Platform notice-and-removal process required

    Covered platforms must have a clear notice-and-removal process and remove valid reported content within 48 hours (Sec. 3, one year after enactment).

    Compliance deadline4 months agoSource

April 20263 deadlines

  1. COPPA Rule

    Full compliance with amended COPPA Rule

    Operators must comply with all amended provisions (separate third-party disclosure consent, written retention policy, written security program, updated notices); excludes Safe Harbor provisions 312.11(d)(1), (d)(4) and (g), which had earlier dates.

    Compliance deadline5 months agoSource
  2. UK Online Safety Act

    Fee notification window closes (2026/27)

    Fee-liable providers must notify Ofcom before the notification window for the first charging year closes.

    Reporting5 months agoSource
  3. MODPA applies to personal data processing

    The act applies to personal data processing activities from April 1, 2026 (Section 2 of ch. 455).

    Compliance deadline6 months agoSource

March 20261 deadline

  1. ECA Digital in force

    Art. 41-A (as set by Law 15.352/2026, following MP 1.319/2025) fixes entry into force on 17 March 2026.

    Takes effect6 months agoSource

February 20261 deadline

  1. SB 854 preliminarily enjoined (NetChoice v. Jones)

    E.D. Va. preliminarily enjoined enforcement of the SB 854 social media time-limit provisions on First Amendment grounds; Virginia has appealed.

    Enforcement7 months agoSource

January 202610 deadlines

  1. Under-16 social media time limit (SB 854) takes effect

    Social media platforms must use commercially reasonable age determination and cap users under 16 at 1 hour/day unless a parent consents. A preliminary injunction issued Feb 27, 2026 bars enforcement.

    Takes effect9 months agoSource
  2. PDPL and Decree 356/2025 take effect

    Personal data protection obligations, DPIA/TIA filing and penalty framework apply; Decree 13/2023 replaced.

    Takes effect9 months agoSource
  3. Sale ban on precise geolocation and under-16 data (HB 2008)

    Selling precise geolocation (1,750-ft radius) and the personal data of consumers the controller knows or willfully disregards are under 16 is prohibited.

    Takes effect9 months agoSource
  4. Universal opt-out signals must be honored

    Controllers must honor opt-out preference signals such as Global Privacy Control.

    Compliance deadline9 months agoSource
  5. Cure period sunsets

    The AG's 30-day notice-and-cure requirement expires; enforcement can proceed without a cure opportunity.

    Enforcement9 months agoSource
  6. Mandatory 60-day cure period expires

    The AG's obligation to issue a cure notice ended Dec 31, 2025; from Jan 1, 2026 cure opportunities are discretionary (RSA 507-H:11 II-III).

    Enforcement9 months agoSource
  7. GDPR

    GDPR Procedural Regulation enters into force

    Regulation (EU) 2025/2518, published in the OJ on 12 December 2025, enters into force on the twentieth day after publication.

    Transition9 months agoSource
  8. Opt-out preference signals must be honored

    Controllers must allow opt-out of targeted advertising and sale via opt-out preference signals (12D-106).

    Compliance deadline9 months agoSource
  9. CCPA / CPRA

    New CCPA regulations take effect

    ADMT, risk assessment, cybersecurity audit and updated CCPA regulations become effective; risk assessments required for new high-risk processing.

    Takes effect9 months agoSource
  10. Chatbot safeguards apply

    AI disclosure, suicide and self-harm protocols, and minor protections apply.

    Takes effect9 months agoSource

December 20252 deadlines

  1. Mandatory 60-day cure period expires

    Mandatory notice-and-cure ends Dec 31, 2025; from Jan 1, 2026 DOJ decides whether to offer a cure using statutory factors.

    Enforcement9 months agoSource
  2. Social media minimum age obligation applies

    Age-restricted platforms must take reasonable steps to prevent under-16s from holding accounts.

    Takes effect9 months agoSource

November 20252 deadlines

  1. GDPR

    GDPR Procedural Regulation adopted

    Regulation (EU) 2025/2518 laying down additional procedural rules for cross-border GDPR enforcement signed by Parliament and Council.

    Transition10 months agoSource
  2. DPDP Rules published; Board and procedural rules in force

    Rules 1, 2 and 17-21 (Data Protection Board constitution and functioning) take effect on publication in the Official Gazette.

    Takes effect10 months agoSource

October 20254 deadlines

  1. SB 243 signed

    SB 243 chaptered (ch. 677).

    Transition11 months agoSource
  2. SB 297 amendments take effect; cure period eliminated

    Lower thresholds (25,000 / 15,000 + 25%), minors' data protections, AG assessment demands; the 60-day cure period is removed.

    Enforcement12 months agoSource
  3. MODPA takes effect

    Act takes effect; data protection assessments apply to processing activities on or after Oct 1, 2025.

    Takes effect12 months agoSource
  4. Minors' data amendment (SB 24-041) effective

    Controllers offering online services to minors must use reasonable care, conduct assessments, and obtain consent for targeted ads, sale and certain profiling of minors.

    Takes effect12 months agoSource

September 20251 deadline

  1. CCPA / CPRA

    ADMT, risk assessment and cybersecurity audit regulations approved

    OAL approves the CCPA Updates, Cybersecurity Audit, Risk Assessment, ADMT and Insurance regulations and files them with the Secretary of State.

    Transition12 months agoSource

August 20251 deadline

  1. EU AI Act

    GPAI, governance, notified bodies and penalties apply

    Chapter III Section 4 (notifying authorities), Chapter V (general-purpose AI model obligations), Chapter VII (governance), Chapter XII (penalties, except Art 101) and Art 78 apply (Art 113(b)).

    Takes effect14 months agoSource

July 20254 deadlines

  1. UK Online Safety Act

    Protection of children duties apply

    Children's safety duties and Protection of Children Codes take effect, including highly effective age assurance; children's risk assessments due by 24 July 2025.

    Takes effect14 months agoSource
  2. Universal opt-out mechanism must be honored

    Controllers that sell personal data or process it for targeted advertising must honor user-selected universal opt-out signals within six months of the effective date (N.J.S.A. 56:8-166.11).

    Compliance deadline14 months agoSource
  3. OCPA applies to nonprofits

    Nonprofit organizations meeting the thresholds become subject to OCPA.

    Takes effect15 months agoSource
  4. Biometric identifier amendment (HB 24-1130) effective

    Any controller processing biometric identifiers must adopt a written biometric policy, give notice, obtain consent and follow retention/deletion rules.

    Takes effect15 months agoSource

June 20251 deadline

  1. COPPA Rule

    Amended COPPA Rule takes effect

    The April 2025 amendments to 16 CFR Part 312 became effective; during the transition operators could comply with either the pre-2025 or the amended Rule.

    Takes effect15 months agoSource

When the rules change: new data, privacy and AI laws and deadlines, the next morning.