Skip to content

Data privacy laws

80 regulations worldwide that deal with privacy, with every phased deadline and the official source for each.

Upcoming deadlines

September 20261 deadline

  1. ICO abolished; Information Commission takes over

    Sections 118-119 commence: office of Information Commissioner abolished and functions transferred to the Information Commission (Commencement No. 9 Regulations 2026).

    Takes effectin 6 daysSource

October 20261 deadline

  1. PA 26-64 (SB 4) amendments take effect

    Prohibits controllers and third parties from selling precise geolocation data and enacts data broker and other consumer protection provisions.

    Takes effectin 7 daysSource

November 20261 deadline

  1. Consent Manager registration rule in force (12 months)

    Rule 4 (registration and obligations of Consent Managers) comes into force one year after publication.

    Transitionin 50 daysSource

December 20264 deadlines

  1. Law in force

    Main obligations apply and the Personal Data Protection Agency begins supervision.

    Takes effectin 2 monthsSource
  2. Children's Online Privacy Code must be registered

    OAIC must develop and register the Children's Online Privacy Code within 24 months of Royal Assent.

    Compliance deadlinein 3 monthsSource
  3. Automated decision-making transparency applies

    Privacy policies must disclose the kinds of personal information used in substantially automated decisions that significantly affect individuals (24 months after assent).

    Compliance deadlinein 3 monthsSource
  4. Member States must provide EU Digital Identity Wallets

    Each Member State must provide at least one wallet within 24 months of the entry into force of the implementing acts under Arts 5a(23) and 5c(6) (Art 5a(1)).

    Compliance deadlinein 3 monthsSource

January 202713 deadlines

  1. CCPA / CPRA

    ADMT requirements compliance date

    Businesses using ADMT for significant decisions must comply with Article 11 (pre-use notice, opt-out, access rights) by this date (11 CCR 7200(b)).

    Compliance deadlinein 3 monthsSource
  2. CCPA / CPRA

    Browsers must support opt-out preference signal (AB 566)

    Businesses that develop or maintain a browser must include consumer-configurable functionality to send an opt-out preference signal (Civ. Code 1798.136, operative Jan 1, 2027).

    Compliance deadlinein 3 monthsSource
  3. ADMT obligations apply

    Developer documentation, consumer notices, post-adverse-outcome disclosure, correction and human-review rights take effect.

    Takes effectin 3 monthsSource
  4. AG rules due

    Attorney General must adopt rules clarifying the post-adverse-outcome disclosure requirements.

    Compliance deadlinein 3 monthsSource
  5. Data broker registration required

    Data brokers may not sell or license brokered personal data in Connecticut unless registered with the Department of Consumer Protection ($2,500 initial fee).

    Compliance deadlinein 3 monthsSource
  6. Amended thresholds and third-party duties take effect

    Applicability drops to 10,000 consumers (or 5,000 + 20% revenue from sale) and new third-party duties (12D-107A) apply.

    Takes effectin 3 monthsSource
  7. Louisiana Data Privacy Act takes effect

    Consumer rights and controller duties apply (Act 502, Section 2); data protection assessment requirements apply to processing from this date.

    Takes effectin 3 monthsSource
  8. Ban on selling personal data of children under 13 (HB 1460)

    HB 1460 (2026, ch. 168) prohibits controllers from selling the personal data of a child under 13.

    Takes effectin 3 monthsSource
  9. Oklahoma OKCDPA

    Oklahoma Consumer Data Privacy Act takes effect

    All OKCDPA obligations and consumer rights apply.

    Takes effectin 3 monthsSource
  10. UCPA extends to motor vehicle manufacturers

    Motor vehicle manufacturers whose vehicles are sold or leased in Utah and that collect personal data through vehicle data systems are covered regardless of the revenue and consumer thresholds (13-61-102, as amended by Laws 2026, ch. 193).

    Takes effectin 3 monthsSource
  11. EU Data Act

    Cloud switching charges abolished

    Providers of data processing services may no longer impose any switching charges on customers (Art 29(1)).

    Compliance deadlinein 4 monthsSource
  12. Implementing regulation GR 33/2026 takes effect

    Detailed PDP implementing rules (DPIA, cross-border, children's consent) apply, 6 months after the 16 Jul 2026 enactment.

    Compliance deadlinein 4 monthsSource
  13. Annual data broker registration deadline

    Data brokers must renew registration with CalPrivacy by January 31 following each year they meet the definition.

    Reportingin 4 monthsSource

March 20271 deadline

  1. EHDS general application date

    The regulation applies generally from 26 Mar 2027, subject to the phased exceptions below (final article).

    Takes effectin 6 monthsSource

April 20272 deadlines

  1. Discretionary 60-day cure period ends

    The Division's discretionary notice-and-cure (at least 60 days) applies only to violations occurring on or before April 1, 2027 (Com. Law 14-4614).

    Enforcementin 6 monthsSource
  2. GDPR

    GDPR Procedural Regulation applies

    Harmonised rules for cross-border complaint admissibility, rights to be heard and access to preliminary findings, and investigation timelines apply to DPAs from 2 April 2027 (Regulation (EU) 2025/2518, final article).

    Enforcementin 6 monthsSource

May 20272 deadlines

  1. APDPA takes effect

    Consumer rights and controller/processor obligations apply (HB 351 section 12).

    Takes effectin 7 monthsSource
  2. Main data fiduciary obligations apply (18 months)

    Rules 3, 5-16, 22 and 23 (notice, security safeguards, breach notification, retention, children's consent, SDF duties, cross-border) come into force 18 months after publication.

    Compliance deadlinein 8 monthsSource

July 20272 deadlines

  1. South Korea PIPA

    Mandatory ISMS-P certification

    ISMS-P certification becomes mandatory for private entities meeting the statutory criteria.

    Compliance deadlinein 9 monthsSource
  2. 30-day cure period expires

    AG's obligation to give 30-day notice and allow cure before investigating applies only from Jan 1 through July 31, 2027 (R.S. 51:1780.5(D)).

    Enforcementin 10 monthsSource

September 20271 deadline

  1. EU Data Act

    Unfair-terms rules extend to older long-term contracts

    Chapter IV (unfair contractual terms) applies to contracts concluded on or before 12 Sep 2025 that are of indefinite duration or expire at least 10 years from 11 Jan 2024 (Art 50).

    Compliance deadlinein 12 monthsSource

December 20273 deadlines

  1. Proposed postponement of entry into force

    Government bill Boletin 18623-07 (filed 1 Sep 2026, 'suma' urgency) would replace the 24-month vacatio legis in transitional Art 1 with a fixed date of 1 Dec 2027; in first committee stage in the Senate, not law.

    Takes effectTentativein 14 monthsSource
  2. Private relying parties must accept wallets

    Private relying parties required by law or contract to use strong user authentication must accept wallets on user request within 36 months of the implementing acts' entry into force (Art 5f(2)).

    Compliance deadlinein 15 monthsSource
  3. CCPA / CPRA

    Risk assessments for pre-existing processing due

    Risk assessments must be completed and documented for high-risk processing that began before Jan 1, 2026 and continues after (11 CCR 7155(b)).

    Compliance deadlinein 15 monthsSource

January 20282 deadlines

  1. Independent third-party audits begin

    Beginning Jan 1, 2028 and every 3 years thereafter, data brokers must undergo an independent audit of Delete Act compliance.

    Compliance deadlinein 15 monthsSource
  2. Vermont Data Privacy and Online Surveillance Act takes effect

    All obligations under Act 145 apply (sec. 4).

    Takes effectin 15 monthsSource

April 20282 deadlines

  1. CCPA / CPRA

    First risk assessment submission to CPPA

    Businesses must submit required risk assessment information and attestation for assessments conducted in 2026 and 2027 (11 CCR 7157(a)(1)); annually by April 1 thereafter.

    Reportingin 18 monthsSource
  2. CCPA / CPRA

    Cybersecurity audit due: revenue over $100M

    First cybersecurity audit report (covering Jan 1, 2027 - Jan 1, 2028) and certification due for businesses with 2026 annual gross revenue over $100M (11 CCR 7121(a)(1)).

    Reportingin 18 monthsSource

September 20281 deadline

  1. EU Data Act

    Commission evaluation

    Commission evaluation report due, including the impact of cloud switching rules (Arts 23-31) (Art 49(2)).

    Reportingin 24 monthsSource

October 20281 deadline

  1. Data brokers must process state deletion mechanism requests

    Registered data brokers must access the DCP accessible deletion mechanism at least every 45 days and process deletion requests.

    Compliance deadlinein 2 yearsSource

March 20291 deadline

  1. Primary use for first data categories; secondary use framework applies

    Patient rights and EHR rules apply to patient summaries, ePrescriptions and eDispensations (Art 14(1)(a)-(c)). Chapter IV secondary-use rules (data permits, Health Data Access Bodies) apply.

    Compliance deadlinein 2.5 yearsSource

April 20291 deadline

  1. CCPA / CPRA

    Cybersecurity audit due: revenue $50M-$100M

    First cybersecurity audit report (covering 2028) due for businesses with 2027 annual gross revenue between $50M and $100M (11 CCR 7121(a)(2)).

    Reportingin 2.5 yearsSource

June 20291 deadline

  1. Mandatory 60-day cure period expires

    The AG's duty to issue a cure notice before enforcement ends June 30, 2029 (Act 145 sec. 3).

    Enforcementin 2.8 yearsSource

July 20291 deadline

  1. Postsecondary institutions must comply

    Postsecondary institutions regulated by the Office of Higher Education must comply by July 31, 2029.

    Compliance deadlinein 2.9 yearsSource

January 20301 deadline

  1. Mandatory cure period ends

    The AG's obligation to offer a 60-day notice-and-cure period expires.

    Sunsetin 3.3 yearsSource

April 20301 deadline

  1. CCPA / CPRA

    Cybersecurity audit due: revenue under $50M

    First cybersecurity audit report (covering 2029) due for covered businesses with 2028 annual gross revenue under $50M (11 CCR 7121(a)(3)); annual by April 1 thereafter.

    Reportingin 3.5 yearsSource

March 20311 deadline

  1. Primary use for second data categories; EHR systems in service; extra secondary-use categories

    Primary-use rules extend to medical images, lab results and discharge reports (Art 14(1)(d)-(f)). Chapter III applies to EHR systems put into service under Art 26(2). Additional secondary-use categories in Art 51(1)(b),(f),(g),(m),(p) apply.

    Compliance deadlinein 4.5 yearsSource

March 20351 deadline

  1. Third-country participation in secondary use

    Art 75(5) applies from 26 Mar 2035.

    Takes effectin 8.5 yearsSource

Past deadlines

September 20262 deadlines

  1. EU Data Act

    Access-by-design for new connected products

    Art 3(1) design obligation (product data and related service data accessible to the user by default) applies to connected products and related services placed on the market after 12 Sep 2026.

    Compliance deadline12 days agoSource
  2. South Korea PIPA

    2026 PIPA amendments take effect

    10%-of-revenue fines, CEO accountability, and notice duties for possible breaches apply.

    Takes effect13 days agoSource

August 20263 deadlines

  1. Digital Services Act

    ChatGPT designated as VLOSE; Reddit and Roblox as VLOPs

    Commission designated ChatGPT as a very large online search engine and Reddit and Roblox as very large online platforms. They have four months (by January 2027) to meet VLOP/VLOSE obligations.

    Enforcement24 days agoSource
  2. Profiling impact assessments apply

    Impact assessment requirements apply to profiling activities created or generated on or after Aug 1, 2026 (Conn. Gen. Stat. 42-522 as amended).

    Compliance deadline54 days agoSource
  3. Data brokers must begin processing DROP deletion requests

    Brokers must access DROP at least every 45 days, process verified deletion requests within 45 days, and treat unverified requests as opt-outs of sale/sharing.

    Compliance deadline54 days agoSource

July 20265 deadlines

  1. 2026 APPI amendment act promulgated

    Amendment enacted by the Diet on 10 July 2026 and promulgated; main provisions take effect by cabinet order within two years of promulgation.

    Transition2 months agoSource
  2. Ban on selling precise geolocation data (SB 338)

    Controllers may not sell consumers' precise geolocation data (1,750-ft radius), replacing the prior consent-based treatment.

    Takes effect3 months agoSource
  3. Right to correct takes effect

    Consumers may ask controllers to correct inaccurate personal data (13-61-201(4), as amended by Laws 2025, ch. 468).

    Takes effect3 months agoSource
  4. Mandatory 30-day cure period expires

    The Division's duty to issue a cure notice before enforcement ends on the first day of the 18th month after the effective date (N.J.S.A. 56:8-166.17(b)).

    Enforcement3 months agoSource
  5. PA 25-113 (SB 1295) amendments take effect

    Thresholds drop to 35,000 consumers or any sensitive-data processing or data sale; expanded sensitive data, minors' protections, and LLM-training disclosure in privacy notices.

    Takes effect3 months agoSource

June 20265 deadlines

  1. A5328 sensitive data sale ban takes effect

    A5328, signed June 30, 2026, prohibits selling sensitive personal data; the ban took effect on signing.

    Takes effect3 months agoSource
  2. Delayed effective date (superseded)

    SB 25B-004 date; superseded by SB 26-189 before it arrived, so no obligations applied.

    Transition3 months agoSource
  3. Mandatory data protection complaints procedure

    Controllers must have a process for data subject complaints (s.103 and Sch. 10), per Commencement No. 6 Regulations 2026, reg. 3.

    Compliance deadline3 months agoSource
  4. Bill C-36 tabled (first reading)

    Government introduces the PPCDA in the House of Commons.

    Takes effect3 months agoSource
  5. SEC Regulation S-P

    Smaller entities must comply

    Smaller covered institutions (24 months after Federal Register publication) must comply with the amended Regulation S-P.

    Compliance deadline4 months agoSource

May 20264 deadlines

  1. Legacy qualified trust service providers conformity report

    QTSPs qualified before 20 May 2024 had to submit a conformity assessment report proving compliance with Art 24(1), (1a) and (1b) by 21 May 2026.

    Compliance deadline4 months agoSource
  2. TAKE IT DOWN Act

    Platform notice-and-removal process required

    Covered platforms must have a clear notice-and-removal process and remove valid reported content within 48 hours (Sec. 3, one year after enactment).

    Compliance deadline4 months agoSource
  3. SB 26-189 signed (repeal and reenact)

    SB 26-189 replaces SB 24-205 with a narrower ADMT disclosure framework and moves the effective date to January 1, 2027.

    Transition4 months agoSource
  4. IPP 3A indirect-collection notification applies

    Agencies collecting personal information from third parties must take reasonable steps to notify individuals, subject to exceptions.

    Compliance deadline5 months agoSource

April 20263 deadlines

  1. COPPA Rule

    Full compliance with amended COPPA Rule

    Operators must comply with all amended provisions (separate third-party disclosure consent, written retention policy, written security program, updated notices); excludes Safe Harbor provisions 312.11(d)(1), (d)(4) and (g), which had earlier dates.

    Compliance deadline5 months agoSource
  2. MODPA applies to personal data processing

    The act applies to personal data processing activities from April 1, 2026 (Section 2 of ch. 455).

    Compliance deadline6 months agoSource
  3. Seventh Circuit: amendment applies retroactively

    Clay v. Union Pacific (No. 25-2185) holds the damages amendment is remedial and applies to pending cases.

    Transition6 months agoSource

March 20262 deadlines

  1. ECA Digital in force

    Art. 41-A (as set by Law 15.352/2026, following MP 1.319/2025) fixes entry into force on 17 March 2026.

    Takes effect6 months agoSource
  2. South Korea PIPA

    2026 PIPA amendment promulgated (Act No. 21445)

    Amendment raising fines to 10% of revenue and adding CEO accountability promulgated.

    Transition7 months agoSource

February 20265 deadlines

  1. SB 854 preliminarily enjoined (NetChoice v. Jones)

    E.D. Va. preliminarily enjoined enforcement of the SB 854 social media time-limit provisions on First Amendment grounds; Virginia has appealed.

    Enforcement7 months agoSource
  2. HIPAA

    Notice of Privacy Practices updates (Part 2 alignment)

    Covered entities must update Notices of Privacy Practices under 45 CFR 164.520 for the 2024 Part 2 (substance use disorder records) changes; this NPP piece survived the Purl vacatur.

    Compliance deadline7 months agoSource
  3. UK GDPR

    DUAA amendments to UK GDPR commence

    Main Data (Use and Access) Act 2025 Part 5 amendments (recognised legitimate interests, ADM, DSAR, transfers, cookies, PECR fines) apply.

    Takes effect8 months agoSource
  4. Stage 3: main data protection changes commence

    Recognised legitimate interests, ADM reforms, DSAR changes, international transfer test, cookie exemptions and PECR fines at UK GDPR levels apply (Commencement No. 6 Regulations 2026, reg. 2).

    Takes effect8 months agoSource
  5. Original effective date (superseded)

    Original SB 24-205 date; postponed by SB 25B-004, so no obligations applied.

    Transition8 months agoSource

January 202611 deadlines

  1. 30-day cure period expires

    The requirement that the AG send a warning letter and allow 30 days to cure before suing expires Jan 31, 2026 (325M.20(a)).

    Enforcement8 months agoSource
  2. Annual data broker registration deadline

    Data brokers must register with CalPrivacy and pay the annual fee ($6,000 for 2026) by January 31.

    Reporting8 months agoSource
  3. Under-16 social media time limit (SB 854) takes effect

    Social media platforms must use commercially reasonable age determination and cap users under 16 at 1 hour/day unless a parent consents. A preliminary injunction issued Feb 27, 2026 bars enforcement.

    Takes effect9 months agoSource
  4. PDPL and Decree 356/2025 take effect

    Personal data protection obligations, DPIA/TIA filing and penalty framework apply; Decree 13/2023 replaced.

    Takes effect9 months agoSource
  5. RIDTPPA takes effect

    All provisions of R.I. Gen. Laws ch. 6-48.1 apply (P.L. 2024, ch. 430/453, effective Jan 1, 2026).

    Takes effect9 months agoSource
  6. Sale ban on precise geolocation and under-16 data (HB 2008)

    Selling precise geolocation (1,750-ft radius) and the personal data of consumers the controller knows or willfully disregards are under 16 is prohibited.

    Takes effect9 months agoSource
  7. Universal opt-out signals must be honored

    Controllers must honor opt-out preference signals such as Global Privacy Control.

    Compliance deadline9 months agoSource
  8. Cure period sunsets

    The AG's 30-day notice-and-cure requirement expires; enforcement can proceed without a cure opportunity.

    Enforcement9 months agoSource
  9. Mandatory 60-day cure period expires

    The AG's obligation to issue a cure notice ended Dec 31, 2025; from Jan 1, 2026 cure opportunities are discretionary (RSA 507-H:11 II-III).

    Enforcement9 months agoSource
  10. KCDPA takes effect

    Consumer rights and controller/processor obligations apply (HB 15 section 12).

    Takes effect9 months agoSource
  11. ICDPA takes effect

    Consumer rights and controller/processor obligations apply; assessments required for processing activities created on or after this date.

    Takes effect9 months agoSource

When the rules change: new data, privacy and AI laws and deadlines, the next morning.