Skip to content

2024 compliance deadlines

51 data, privacy, AI and cybersecurity deadlines fall in 2024, across 40 regulations.

January 20242 deadlines

  1. EU Data Act

    Data Act enters into force

    Entered into force on the twentieth day after publication in the OJ on 22 Dec 2023 (Art 50).

    Takes effect2.7 years agoSource
  2. EU Data Act

    Reduced switching charges period begins

    From 11 Jan 2024 to 12 Jan 2027, data processing providers may charge only reduced switching fees, capped at costs directly linked to switching (Art 29(2)-(3)).

    Transition2.7 years agoSource

February 20241 deadline

  1. Digital Services Act

    DSA applies to all intermediary services

    Full application to all providers of intermediary services (Art 93(2)).

    Takes effect2.6 years agoSource

March 20244 deadlines

  1. Digital Markets Act

    Gatekeeper compliance deadline (first designations)

    First-wave gatekeepers had to comply with Arts 5-7 obligations and submit compliance reports six months after the 6 Sep 2023 designation.

    Compliance deadline2.5 years agoSource
  2. FCC CPNI Breach Rule

    Order effective except revised notification rules

    Definitions and other parts of the order took effect; the revised 64.2011 and 64.5111 notification requirements were delayed pending OMB approval.

    Takes effect2.5 years agoSource
  3. Cross-border data flow provisions take effect

    Exemptions and volume thresholds apply from publication (Art. 14); security assessment results are valid for 3 years (Art. 9).

    Takes effect2.5 years agoSource
  4. Regulated entities must comply

    Sections 4-9 (privacy policy, consent, consumer rights, sale authorization) apply to regulated entities.

    Compliance deadline2.5 years agoSource

April 20242 deadlines

  1. Annual compliance notification

    Certification of compliance or acknowledgment of non-compliance due (recurs every April 15).

    Reporting2.4 years agoSource
  2. General 180-day transition ends

    Most new Second Amendment requirements apply, e.g. annual reporting to the board and risk assessment updates.

    Compliance deadline2.4 years agoSource

May 20244 deadlines

  1. AI Policy Act effective

    Generative AI disclosure duties and the Office of AI Policy take effect.

    Takes effect2.4 years agoSource
  2. GLBA Safeguards Rule

    FTC breach notification requirement effective

    Section 314.4(j) requires notice to the FTC within 30 days of discovering a notification event involving at least 500 consumers.

    Takes effect2.4 years agoSource
  3. SB 24-205 signed

    Governor Polis signs the original Colorado AI Act with a February 1, 2026 effective date.

    Takes effect2.4 years agoSource
  4. eIDAS 2 enters into force

    Regulation (EU) 2024/1183 entered into force on the twentieth day after publication on 30 Apr 2024 (Art 2).

    Takes effect2.3 years agoSource

June 20245 deadlines

  1. Law 7499 amendments take effect

    New sensitive data and cross-border transfer rules (Arts. 6 and 9) apply.

    Takes effect2.3 years agoSource
  2. SEC Cyber Disclosure Rules

    Smaller reporting companies: Item 1.05 compliance

    Smaller reporting companies must begin complying with Form 8-K Item 1.05 incident disclosure.

    Compliance deadline2.3 years agoSource
  3. PADFA

    PADFA takes effect

    The prohibition takes effect 60 days after enactment (April 24, 2024).

    Takes effect2.3 years agoSource
  4. HIPAA

    Reproductive health care privacy rule effective (later vacated)

    The HIPAA Privacy Rule to Support Reproductive Health Care Privacy (89 FR 32976) took effect; it was vacated nationwide on June 18, 2025 in Purl v. HHS (N.D. Tex.).

    Takes effect2.2 years agoSource
  5. Small businesses must comply

    Sections 4-9 apply to small businesses.

    Compliance deadline2.2 years agoSource

July 20246 deadlines

  1. Universal opt-out mechanism recognition required

    Controllers must honor AG-recognized universal opt-out mechanisms (e.g. Global Privacy Control).

    Compliance deadline2.2 years agoSource
  2. Florida Digital Bill of Rights takes effect

    SB 262 obligations under Fla. Stat. 501.701-501.722 apply.

    Takes effect2.2 years agoSource
  3. OCPA takes effect for most controllers

    OCPA obligations apply to for-profit controllers meeting the thresholds.

    Takes effect2.2 years agoSource
  4. TDPSA takes effect

    Most TDPSA obligations and consumer rights apply.

    Takes effect2.2 years agoSource
  5. CIRCIA

    NPRM comment period closed

    Extended comment period on the CIRCIA proposed rule closed.

    Transition2.2 years agoSource
  6. 2024 amendments effective

    Amendments clarifying health app coverage, unauthorized disclosure as breach, email notice and FTC notice timing took effect.

    Takes effect2.2 years agoSource

August 20245 deadlines

  1. EU AI Act

    AI Act enters into force

    Regulation (EU) 2024/1689 enters into force twenty days after publication on 12 July 2024 (Art 113).

    Takes effect2.1 years agoSource
  2. SB 2979 amendment effective

    Public Act 103-0769 signed and effective immediately: single recovery per person and electronic signatures allowed for consent.

    Takes effect2.1 years agoSource
  3. SEC Regulation S-P

    Amendments effective

    The Regulation S-P amendments became effective; compliance tiered by entity size.

    Takes effect2.1 years agoSource
  4. HB 3773 signed

    Governor Pritzker signs Public Act 103-0804.

    Transition2.1 years agoSource
  5. International transfer regulation published

    Resolution CD/ANPD 19/2024 on international transfers and standard contractual clauses published and in force.

    Takes effect2.1 years agoSource

September 20245 deadlines

  1. Old transfer regime ends

    Transitional period ends in which the former Article 9 explicit-consent transfer basis could still be relied on.

    Transition2.1 years agoSource
  2. Saudi PDPL

    One-year grace period ends

    Grace period for controllers to comply ends; PDPL fully enforceable.

    Enforcement2 years agoSource
  3. SB 942 signed

    SB 942 chaptered (ch. 291) with an original operative date of January 1, 2026.

    Transition2 years agoSource
  4. Quebec Law 25

    Phase 3: data portability

    Right to data portability in a structured, commonly used technological format applies.

    Compliance deadline2 years agoSource
  5. AB 2013 signed

    AB 2013 chaptered (ch. 817).

    Transition24 months agoSource

October 20244 deadlines

  1. MCDPA takes effect

    Consumer rights, controller duties and opt-out preference signal support apply.

    Takes effect24 months agoSource
  2. PDP Law transition ends

    Controllers and processors must fully comply (Art. 74 two-year transition).

    Compliance deadline23 months agoSource
  3. NIS2

    Transposition deadline

    Member States had to adopt and publish national transposing measures by 17 Oct 2024 (Art 41(1)).

    Transition23 months agoSource
  4. NIS2

    National NIS2 measures apply; NIS1 repealed

    Member States apply their NIS2 measures from 18 Oct 2024 and Directive (EU) 2016/1148 (NIS1) is repealed (Arts 41(1), 44).

    Takes effect23 months agoSource

November 20242 deadlines

  1. Governance, encryption, IR/BCDR, exemptions

    500.4 governance, 500.15 encryption, 500.16 incident response and business continuity plans, and 500.19(a) revised exemptions apply.

    Compliance deadline23 months agoSource
  2. NIS2

    Implementing Regulation 2024/2690 enters into force

    Commission Implementing Regulation (EU) 2024/2690 (published 18 Oct 2024) sets technical risk-management measures and significant-incident thresholds for DNS, TLD, cloud, data centre, CDN, managed (security) service providers, online marketplaces, search engines, social networks and trust service providers.

    Takes effect23 months agoSource

December 202411 deadlines

  1. New PLD enters into force

    Directive entered into force on the twentieth day after publication in the OJ on 18 Nov 2024 (Art 23).

    Takes effect22 months agoSource
  2. Approved by the Federal Senate

    Senate approves the consolidated text and sends it to the Chamber of Deputies.

    Takes effect21 months agoSource
  3. Cyber Resilience Act

    CRA enters into force

    Entered into force on the twentieth day after publication in the OJ on 20 Nov 2024 (Art 71(1)).

    Takes effect21 months agoSource
  4. Most POLA Act 2024 amendments commence

    Tiered penalties, infringement notices, OAIC powers, security and overseas-transfer clarifications and doxxing offences commence the day after Royal Assent.

    Takes effect21 months agoSource
  5. Published in Diario Oficial

    Law 21.719 published; 24-month vacatio legis begins.

    Takes effect21 months agoSource
  6. SEC Cyber Disclosure Rules

    Inline XBRL tagging of annual cybersecurity disclosures

    Item 106 / Item 16K disclosures must be tagged in Inline XBRL for fiscal years ending on or after this date.

    Compliance deadline21 months agoSource
  7. CMMC 2.0

    CMMC Program rule (32 CFR Part 170) effective

    The program rule establishing CMMC levels and assessment processes took effect; contract enforcement awaited the DFARS rule.

    Takes effect21 months agoSource
  8. SEC Cyber Disclosure Rules

    Inline XBRL tagging of Item 1.05 disclosures

    Form 8-K Item 1.05 and Form 6-K incident disclosures must be tagged in Inline XBRL.

    Compliance deadline21 months agoSource
  9. HIPAA

    Reproductive health privacy compliance date (vacated)

    Original compliance date for the reproductive health care privacy provisions, including the attestation requirement; these provisions no longer apply after the June 2025 vacatur.

    Compliance deadline21 months agoSource
  10. First wallet implementing acts enter into force

    Commission Implementing Regulations (EU) 2024/2977, 2024/2979, 2024/2980, 2024/2981 and 2024/2982 (adopted 28 Nov 2024, published 4 Dec 2024) enter into force. This starts the wallet deadline clocks in Arts 5a and 5f.

    Takes effect21 months agoSource
  11. Mandatory 60-day cure period expires

    After Dec 31, 2024, the AG is no longer required to offer a 60-day cure before enforcement; cure becomes discretionary.

    Enforcement21 months agoSource

When the rules change: new data, privacy and AI laws and deadlines, the next morning.