Data privacy laws
80 regulations worldwide that deal with privacy, with every phased deadline and the official source for each.
80 regulations
Add to calendar
- Data (Use and Access) Act
United Kingdom
In forcePrivacyData access and sharingNext: Sep 30, 2026 ICO abolished; Information Commission takes over
- Connecticut Data Privacy Act (CTDPA)
Connecticut
AmendedPrivacyChildrenNext: Oct 1, 2026 PA 26-64 (SB 4) amendments take effect
- India DPDP Act
India
EnactedPrivacyChildrenNext: Nov 13, 2026 Consent Manager registration rule in force (12 months)
- EnactedPrivacyBreach notification
Next: Dec 1, 2026 Law in force
- Australia Privacy Act
Australia
AmendedPrivacyChildrenNext: Dec 10, 2026 Children's Online Privacy Code must be registered
- eIDAS 2 / EU Digital Identity Wallet
European Union
EnactedPrivacyData access and sharingNext: Dec 24, 2026 Member States must provide EU Digital Identity Wallets
- CCPA / CPRA
California
AmendedPrivacyAINext: Jan 1, 2027 ADMT requirements compliance date
- Colorado AI Act
Colorado
EnactedAIPrivacyNext: Jan 1, 2027 ADMT obligations apply
- AmendedPrivacyChildren
Next: Jan 1, 2027 Amended thresholds and third-party duties take effect
- Louisiana Data Privacy Act
Louisiana
EnactedPrivacyBiometricsNext: Jan 1, 2027 Louisiana Data Privacy Act takes effect
- New Hampshire Privacy Act
New Hampshire
AmendedPrivacyChildrenNext: Jan 1, 2027 Ban on selling personal data of children under 13 (HB 1460)
- Oklahoma OKCDPA
Oklahoma
EnactedPrivacyNext: Jan 1, 2027 Oklahoma Consumer Data Privacy Act takes effect
- Utah UCPA
Utah
AmendedPrivacyNext: Jan 1, 2027 UCPA extends to motor vehicle manufacturers
- EU Data Act
European Union
In forceData access and sharingPrivacyNext: Jan 12, 2027 Cloud switching charges abolished
- Indonesia PDP Law
Indonesia
AmendedPrivacyBreach notificationNext: Jan 16, 2027 Implementing regulation GR 33/2026 takes effect
- California Delete Act / DROP
California
In forcePrivacyData access and sharingNext: Jan 31, 2027 Annual data broker registration deadline
- European Health Data Space (EHDS)
European Union
EnactedHealth dataPrivacyNext: Mar 26, 2027 EHDS general application date
- AmendedPrivacyChildren
Next: Apr 1, 2027 Discretionary 60-day cure period ends
- GDPR
European Union
AmendedPrivacyBreach notificationNext: Apr 2, 2027 GDPR Procedural Regulation applies
- EnactedPrivacy
Next: May 1, 2027 APDPA takes effect
- South Korea PIPA
South Korea
AmendedPrivacyBreach notificationNext: Jul 1, 2027 Mandatory ISMS-P certification
- Vermont VDPOSA
Vermont
EnactedPrivacyHealth dataNext: Jan 1, 2028 Vermont Data Privacy and Online Surveillance Act takes effect
- In forcePrivacy
Next: Jul 31, 2029 Postsecondary institutions must comply
- Brazil ECA Digital
Brazil
In forceChildrenOnline safetyEffective Mar 17, 2026
- Brazil LGPD
Brazil
In forcePrivacyBreach notificationEffective Sep 18, 2020
- In forceAIPrivacy
Effective Jan 1, 2026
- Canada Bill C-36 (PPCDA)
Canada
ProposedPrivacyBreach notification - In forceData residencyPrivacy
Effective Mar 22, 2024
- AmendedCybersecurityData residency
Effective Jun 1, 2017
- In forcePrivacyCybersecurity
Effective Jan 1, 2025
- In forcePrivacy
Effective May 1, 2025
- China PIPL
China
In forcePrivacyData residencyEffective Nov 1, 2021
- Colorado Privacy Act (CPA)
Colorado
AmendedPrivacyChildrenEffective Jul 1, 2023
- COPPA Rule
United States (Federal)
AmendedPrivacyChildrenEffective Apr 21, 2000
- Data Governance Act
European Union
AmendedData access and sharingPrivacyEffective Jun 23, 2022
- Digital Markets Act
European Union
In forceData access and sharingPrivacyEffective Nov 1, 2022
- Digital Omnibus (data/GDPR)
European Union
ProposedPrivacyData access and sharing - Digital Services Act
European Union
In forceOnline safetyChildrenEffective Nov 16, 2022
- DOJ Bulk Data Rule
United States (Federal)
In forcePrivacyData residencyEffective Apr 8, 2025
- ePrivacy Directive (cookie law)
European Union
AmendedPrivacyBreach notificationEffective Jul 31, 2002
- EU-US Data Privacy Framework
European Union
In forcePrivacyData residencyEffective Jul 10, 2023
- FCC CPNI Breach Rule
United States (Federal)
AmendedPrivacyBreach notificationEffective Mar 13, 2024
- In forcePrivacyChildren
Effective Jul 1, 2024
- FTC Health Breach Notification Rule
United States (Federal)
AmendedHealth dataPrivacyEffective Sep 24, 2009
- GLBA Safeguards Rule
United States (Federal)
AmendedFinancialCybersecurityEffective May 23, 2003
- HIPAA
United States (Federal)
AmendedPrivacyHealth dataEffective Apr 14, 2003
- Illinois BIPA
Illinois
AmendedBiometricsPrivacyEffective Oct 3, 2008
- In forcePrivacy
Effective Jan 1, 2026
- In forcePrivacy
Effective Jan 1, 2025
- AmendedPrivacyBreach notification
Effective Aug 14, 2025
- Japan APPI
Japan
AmendedPrivacyChildrenEffective Apr 1, 2005
- In forcePrivacy
Effective Jan 1, 2026
- In forcePrivacyBreach notification
Effective Nov 25, 2019
- Malaysia PDPA
Malaysia
AmendedPrivacyBreach notificationEffective Nov 15, 2013
- Mexico LFPDPPP 2025
Mexico
In forcePrivacyEffective Mar 21, 2025
- AmendedPrivacyChildren
Effective Oct 1, 2024
- Nebraska NDPA
Nebraska
In forcePrivacyEffective Jan 1, 2025
- New Jersey NJDPA
New Jersey
AmendedPrivacyChildrenEffective Jan 15, 2025
- New Zealand Privacy Act
New Zealand
AmendedPrivacyBreach notificationEffective Dec 1, 2020
- Nigeria NDPA
Nigeria
AmendedPrivacyBreach notificationEffective Jun 12, 2023
- Oregon OCPA
Oregon
AmendedPrivacyChildrenEffective Jul 1, 2024
- PADFA
United States (Federal)
In forcePrivacyData residencyEffective Jun 23, 2024
- PIPEDA
Canada
In forcePrivacyBreach notificationEffective Jan 1, 2001
- Quebec Law 25
Quebec, Canada
In forcePrivacyBreach notificationEffective Sep 22, 2022
- Rhode Island RIDTPPA
Rhode Island
In forcePrivacyEffective Jan 1, 2026
- Saudi PDPL
Saudi Arabia
In forcePrivacyData residencyEffective Sep 14, 2023
- SEC Regulation S-P
United States (Federal)
AmendedFinancialPrivacyEffective Aug 2, 2024
- Singapore PDPA
Singapore
In forcePrivacyBreach notificationEffective Jul 2, 2014
- South Africa POPIA
South Africa
In forcePrivacyBreach notificationEffective Jul 1, 2020
- Swiss revised FADP (nFADP)
Switzerland
In forcePrivacyBreach notificationEffective Sep 1, 2023
- TAKE IT DOWN Act
United States (Federal)
In forceOnline safetyAIEffective May 19, 2025
- Tennessee TIPA
Tennessee
In forcePrivacyEffective Jul 1, 2025
- Texas TDPSA
Texas
In forcePrivacyEffective Jul 1, 2024
- Thailand PDPA
Thailand
In forcePrivacyBreach notificationEffective Jun 1, 2022
- Turkey KVKK
Turkey
AmendedPrivacyData residencyEffective Apr 7, 2016
- UAE PDPL
United Arab Emirates
In forcePrivacyBreach notificationEffective Jan 2, 2022
- UK GDPR
United Kingdom
AmendedPrivacyBreach notificationEffective May 25, 2018
- Vietnam PDPL
Vietnam
In forcePrivacyData residencyEffective Jan 1, 2026
- Virginia VCDPA
Virginia
AmendedPrivacyChildrenEffective Jan 1, 2023
- Washington My Health My Data Act
Washington
In forceHealth dataPrivacyEffective Mar 31, 2024
Upcoming deadlines
September 20261 deadline
ICO abolished; Information Commission takes over
Sections 118-119 commence: office of Information Commissioner abolished and functions transferred to the Information Commission (Commencement No. 9 Regulations 2026).
October 20261 deadline
PA 26-64 (SB 4) amendments take effect
Prohibits controllers and third parties from selling precise geolocation data and enacts data broker and other consumer protection provisions.
November 20261 deadline
Consent Manager registration rule in force (12 months)
Rule 4 (registration and obligations of Consent Managers) comes into force one year after publication.
December 20264 deadlines
Law in force
Main obligations apply and the Personal Data Protection Agency begins supervision.
Children's Online Privacy Code must be registered
OAIC must develop and register the Children's Online Privacy Code within 24 months of Royal Assent.
Automated decision-making transparency applies
Privacy policies must disclose the kinds of personal information used in substantially automated decisions that significantly affect individuals (24 months after assent).
- eIDAS 2 / EU Digital Identity WalletEuropean Union
Member States must provide EU Digital Identity Wallets
Each Member State must provide at least one wallet within 24 months of the entry into force of the implementing acts under Arts 5a(23) and 5c(6) (Art 5a(1)).
January 202713 deadlines
ADMT requirements compliance date
Businesses using ADMT for significant decisions must comply with Article 11 (pre-use notice, opt-out, access rights) by this date (11 CCR 7200(b)).
Browsers must support opt-out preference signal (AB 566)
Businesses that develop or maintain a browser must include consumer-configurable functionality to send an opt-out preference signal (Civ. Code 1798.136, operative Jan 1, 2027).
ADMT obligations apply
Developer documentation, consumer notices, post-adverse-outcome disclosure, correction and human-review rights take effect.
AG rules due
Attorney General must adopt rules clarifying the post-adverse-outcome disclosure requirements.
Data broker registration required
Data brokers may not sell or license brokered personal data in Connecticut unless registered with the Department of Consumer Protection ($2,500 initial fee).
Amended thresholds and third-party duties take effect
Applicability drops to 10,000 consumers (or 5,000 + 20% revenue from sale) and new third-party duties (12D-107A) apply.
- Louisiana Data Privacy ActLouisiana
Louisiana Data Privacy Act takes effect
Consumer rights and controller duties apply (Act 502, Section 2); data protection assessment requirements apply to processing from this date.
- New Hampshire Privacy ActNew Hampshire
Ban on selling personal data of children under 13 (HB 1460)
HB 1460 (2026, ch. 168) prohibits controllers from selling the personal data of a child under 13.
- Oklahoma OKCDPAOklahoma
Oklahoma Consumer Data Privacy Act takes effect
All OKCDPA obligations and consumer rights apply.
UCPA extends to motor vehicle manufacturers
Motor vehicle manufacturers whose vehicles are sold or leased in Utah and that collect personal data through vehicle data systems are covered regardless of the revenue and consumer thresholds (13-61-102, as amended by Laws 2026, ch. 193).
- EU Data ActEuropean Union
Cloud switching charges abolished
Providers of data processing services may no longer impose any switching charges on customers (Art 29(1)).
Implementing regulation GR 33/2026 takes effect
Detailed PDP implementing rules (DPIA, cross-border, children's consent) apply, 6 months after the 16 Jul 2026 enactment.
Annual data broker registration deadline
Data brokers must renew registration with CalPrivacy by January 31 following each year they meet the definition.
March 20271 deadline
- European Health Data Space (EHDS)European Union
EHDS general application date
The regulation applies generally from 26 Mar 2027, subject to the phased exceptions below (final article).
April 20272 deadlines
Discretionary 60-day cure period ends
The Division's discretionary notice-and-cure (at least 60 days) applies only to violations occurring on or before April 1, 2027 (Com. Law 14-4614).
May 20272 deadlines
APDPA takes effect
Consumer rights and controller/processor obligations apply (HB 351 section 12).
Main data fiduciary obligations apply (18 months)
Rules 3, 5-16, 22 and 23 (notice, security safeguards, breach notification, retention, children's consent, SDF duties, cross-border) come into force 18 months after publication.
July 20272 deadlines
Mandatory ISMS-P certification
ISMS-P certification becomes mandatory for private entities meeting the statutory criteria.
- Louisiana Data Privacy ActLouisiana
30-day cure period expires
AG's obligation to give 30-day notice and allow cure before investigating applies only from Jan 1 through July 31, 2027 (R.S. 51:1780.5(D)).
September 20271 deadline
- EU Data ActEuropean Union
Unfair-terms rules extend to older long-term contracts
Chapter IV (unfair contractual terms) applies to contracts concluded on or before 12 Sep 2025 that are of indefinite duration or expire at least 10 years from 11 Jan 2024 (Art 50).
December 20273 deadlines
Proposed postponement of entry into force
Government bill Boletin 18623-07 (filed 1 Sep 2026, 'suma' urgency) would replace the 24-month vacatio legis in transitional Art 1 with a fixed date of 1 Dec 2027; in first committee stage in the Senate, not law.
- eIDAS 2 / EU Digital Identity WalletEuropean Union
Private relying parties must accept wallets
Private relying parties required by law or contract to use strong user authentication must accept wallets on user request within 36 months of the implementing acts' entry into force (Art 5f(2)).
Risk assessments for pre-existing processing due
Risk assessments must be completed and documented for high-risk processing that began before Jan 1, 2026 and continues after (11 CCR 7155(b)).
January 20282 deadlines
Independent third-party audits begin
Beginning Jan 1, 2028 and every 3 years thereafter, data brokers must undergo an independent audit of Delete Act compliance.
Vermont Data Privacy and Online Surveillance Act takes effect
All obligations under Act 145 apply (sec. 4).
April 20282 deadlines
First risk assessment submission to CPPA
Businesses must submit required risk assessment information and attestation for assessments conducted in 2026 and 2027 (11 CCR 7157(a)(1)); annually by April 1 thereafter.
Cybersecurity audit due: revenue over $100M
First cybersecurity audit report (covering Jan 1, 2027 - Jan 1, 2028) and certification due for businesses with 2026 annual gross revenue over $100M (11 CCR 7121(a)(1)).
September 20281 deadline
- EU Data ActEuropean Union
Commission evaluation
Commission evaluation report due, including the impact of cloud switching rules (Arts 23-31) (Art 49(2)).
October 20281 deadline
Data brokers must process state deletion mechanism requests
Registered data brokers must access the DCP accessible deletion mechanism at least every 45 days and process deletion requests.
March 20291 deadline
- European Health Data Space (EHDS)European Union
Primary use for first data categories; secondary use framework applies
Patient rights and EHR rules apply to patient summaries, ePrescriptions and eDispensations (Art 14(1)(a)-(c)). Chapter IV secondary-use rules (data permits, Health Data Access Bodies) apply.
April 20291 deadline
Cybersecurity audit due: revenue $50M-$100M
First cybersecurity audit report (covering 2028) due for businesses with 2027 annual gross revenue between $50M and $100M (11 CCR 7121(a)(2)).
June 20291 deadline
Mandatory 60-day cure period expires
The AG's duty to issue a cure notice before enforcement ends June 30, 2029 (Act 145 sec. 3).
July 20291 deadline
Postsecondary institutions must comply
Postsecondary institutions regulated by the Office of Higher Education must comply by July 31, 2029.
January 20301 deadline
Mandatory cure period ends
The AG's obligation to offer a 60-day notice-and-cure period expires.
April 20301 deadline
Cybersecurity audit due: revenue under $50M
First cybersecurity audit report (covering 2029) due for covered businesses with 2028 annual gross revenue under $50M (11 CCR 7121(a)(3)); annual by April 1 thereafter.
March 20311 deadline
- European Health Data Space (EHDS)European Union
Primary use for second data categories; EHR systems in service; extra secondary-use categories
Primary-use rules extend to medical images, lab results and discharge reports (Art 14(1)(d)-(f)). Chapter III applies to EHR systems put into service under Art 26(2). Additional secondary-use categories in Art 51(1)(b),(f),(g),(m),(p) apply.
March 20351 deadline
- European Health Data Space (EHDS)European Union
Third-country participation in secondary use
Art 75(5) applies from 26 Mar 2035.
Past deadlines
September 20262 deadlines
- EU Data ActEuropean Union
Access-by-design for new connected products
Art 3(1) design obligation (product data and related service data accessible to the user by default) applies to connected products and related services placed on the market after 12 Sep 2026.
2026 PIPA amendments take effect
10%-of-revenue fines, CEO accountability, and notice duties for possible breaches apply.
August 20263 deadlines
- Digital Services ActEuropean Union
ChatGPT designated as VLOSE; Reddit and Roblox as VLOPs
Commission designated ChatGPT as a very large online search engine and Reddit and Roblox as very large online platforms. They have four months (by January 2027) to meet VLOP/VLOSE obligations.
Profiling impact assessments apply
Impact assessment requirements apply to profiling activities created or generated on or after Aug 1, 2026 (Conn. Gen. Stat. 42-522 as amended).
Data brokers must begin processing DROP deletion requests
Brokers must access DROP at least every 45 days, process verified deletion requests within 45 days, and treat unverified requests as opt-outs of sale/sharing.
July 20265 deadlines
2026 APPI amendment act promulgated
Amendment enacted by the Diet on 10 July 2026 and promulgated; main provisions take effect by cabinet order within two years of promulgation.
Ban on selling precise geolocation data (SB 338)
Controllers may not sell consumers' precise geolocation data (1,750-ft radius), replacing the prior consent-based treatment.
Mandatory 30-day cure period expires
The Division's duty to issue a cure notice before enforcement ends on the first day of the 18th month after the effective date (N.J.S.A. 56:8-166.17(b)).
PA 25-113 (SB 1295) amendments take effect
Thresholds drop to 35,000 consumers or any sensitive-data processing or data sale; expanded sensitive data, minors' protections, and LLM-training disclosure in privacy notices.
June 20265 deadlines
A5328 sensitive data sale ban takes effect
A5328, signed June 30, 2026, prohibits selling sensitive personal data; the ban took effect on signing.
Delayed effective date (superseded)
SB 25B-004 date; superseded by SB 26-189 before it arrived, so no obligations applied.
Mandatory data protection complaints procedure
Controllers must have a process for data subject complaints (s.103 and Sch. 10), per Commencement No. 6 Regulations 2026, reg. 3.
Bill C-36 tabled (first reading)
Government introduces the PPCDA in the House of Commons.
Smaller entities must comply
Smaller covered institutions (24 months after Federal Register publication) must comply with the amended Regulation S-P.
May 20264 deadlines
- eIDAS 2 / EU Digital Identity WalletEuropean Union
Legacy qualified trust service providers conformity report
QTSPs qualified before 20 May 2024 had to submit a conformity assessment report proving compliance with Art 24(1), (1a) and (1b) by 21 May 2026.
Platform notice-and-removal process required
Covered platforms must have a clear notice-and-removal process and remove valid reported content within 48 hours (Sec. 3, one year after enactment).
SB 26-189 signed (repeal and reenact)
SB 26-189 replaces SB 24-205 with a narrower ADMT disclosure framework and moves the effective date to January 1, 2027.
IPP 3A indirect-collection notification applies
Agencies collecting personal information from third parties must take reasonable steps to notify individuals, subject to exceptions.
April 20263 deadlines
Full compliance with amended COPPA Rule
Operators must comply with all amended provisions (separate third-party disclosure consent, written retention policy, written security program, updated notices); excludes Safe Harbor provisions 312.11(d)(1), (d)(4) and (g), which had earlier dates.
MODPA applies to personal data processing
The act applies to personal data processing activities from April 1, 2026 (Section 2 of ch. 455).
Seventh Circuit: amendment applies retroactively
Clay v. Union Pacific (No. 25-2185) holds the damages amendment is remedial and applies to pending cases.
March 20262 deadlines
ECA Digital in force
Art. 41-A (as set by Law 15.352/2026, following MP 1.319/2025) fixes entry into force on 17 March 2026.
2026 PIPA amendment promulgated (Act No. 21445)
Amendment raising fines to 10% of revenue and adding CEO accountability promulgated.
February 20265 deadlines
SB 854 preliminarily enjoined (NetChoice v. Jones)
E.D. Va. preliminarily enjoined enforcement of the SB 854 social media time-limit provisions on First Amendment grounds; Virginia has appealed.
Notice of Privacy Practices updates (Part 2 alignment)
Covered entities must update Notices of Privacy Practices under 45 CFR 164.520 for the 2024 Part 2 (substance use disorder records) changes; this NPP piece survived the Purl vacatur.
Stage 3: main data protection changes commence
Recognised legitimate interests, ADM reforms, DSAR changes, international transfer test, cookie exemptions and PECR fines at UK GDPR levels apply (Commencement No. 6 Regulations 2026, reg. 2).
Original effective date (superseded)
Original SB 24-205 date; postponed by SB 25B-004, so no obligations applied.
January 202611 deadlines
30-day cure period expires
The requirement that the AG send a warning letter and allow 30 days to cure before suing expires Jan 31, 2026 (325M.20(a)).
Annual data broker registration deadline
Data brokers must register with CalPrivacy and pay the annual fee ($6,000 for 2026) by January 31.
Under-16 social media time limit (SB 854) takes effect
Social media platforms must use commercially reasonable age determination and cap users under 16 at 1 hour/day unless a parent consents. A preliminary injunction issued Feb 27, 2026 bars enforcement.
PDPL and Decree 356/2025 take effect
Personal data protection obligations, DPIA/TIA filing and penalty framework apply; Decree 13/2023 replaced.
RIDTPPA takes effect
All provisions of R.I. Gen. Laws ch. 6-48.1 apply (P.L. 2024, ch. 430/453, effective Jan 1, 2026).
Sale ban on precise geolocation and under-16 data (HB 2008)
Selling precise geolocation (1,750-ft radius) and the personal data of consumers the controller knows or willfully disregards are under 16 is prohibited.
Universal opt-out signals must be honored
Controllers must honor opt-out preference signals such as Global Privacy Control.
Cure period sunsets
The AG's 30-day notice-and-cure requirement expires; enforcement can proceed without a cure opportunity.
- New Hampshire Privacy ActNew Hampshire
Mandatory 60-day cure period expires
The AG's obligation to issue a cure notice ended Dec 31, 2025; from Jan 1, 2026 cure opportunities are discretionary (RSA 507-H:11 II-III).
KCDPA takes effect
Consumer rights and controller/processor obligations apply (HB 15 section 12).
ICDPA takes effect
Consumer rights and controller/processor obligations apply; assessments required for processing activities created on or after this date.