Skip to content

2025 compliance deadlines

76 data, privacy, AI and cybersecurity deadlines fall in 2025, across 54 regulations.

January 202513 deadlines

  1. CCPA / CPRA

    CPI adjustment of thresholds and fines

    Revenue threshold rises to $26,625,000 and fines to $2,663 / $7,988 per violation.

    Transition21 months agoSource
  2. Network Data Regulations take effect

    All provisions, including the 10-million-person threshold duties and annual important-data risk assessments, apply.

    Takes effect21 months agoSource
  3. 60-day cure period expires

    Mandatory 60-day notice-and-cure before AG enforcement ends; enforcement may proceed without cure.

    Enforcement21 months agoSource
  4. Universal opt-out preference signals required

    Controllers must honor opt-out preference signals for targeted advertising and sale (effective Jan 1, 2025).

    Compliance deadline21 months agoSource
  5. DPDPA takes effect

    Consumer rights and controller duties apply; 60-day mandatory cure period begins.

    Takes effect21 months agoSource
  6. ICDPA takes effect

    Consumer rights and controller/processor obligations apply.

    Takes effect21 months agoSource
  7. PDPA amendments phase 1

    Miscellaneous provisions commence (e.g. electronic service of notices).

    Takes effect21 months agoSource
  8. Nebraska Data Privacy Act takes effect

    Controller and processor obligations and consumer rights under Neb. Rev. Stat. 87-1101 et seq. apply.

    Takes effect21 months agoSource
  9. New Hampshire Privacy Act takes effect

    RSA 507-H obligations and consumer rights apply (Laws 2024, 5:1, eff. Jan. 1, 2025).

    Takes effect21 months agoSource
  10. Universal opt-out mechanism requirement applies

    Controllers must honor global privacy control / universal opt-out signals (Bus. & Com. Code 541.055(e)).

    Compliance deadline21 months agoSource
  11. NJDPA takes effect

    The act takes effect on the 365th day after enactment on Jan 16, 2024 (sec. 17).

    Takes effect20 months agoSource
  12. DORA

    DORA applies

    All DORA obligations (ICT risk management, incident reporting, testing, third-party risk, register of information) apply from 17 Jan 2025 (Art 64).

    Takes effect20 months agoSource
  13. NIS2

    Digital infrastructure entities submit registration data

    DNS providers, TLD registries, domain registration services, cloud, data centre, CDN, managed (security) service providers, marketplaces, search engines and social networks had to submit registration details to competent authorities (Art 27(2)).

    Reporting20 months agoSource

February 20251 deadline

  1. EU AI Act

    Prohibited practices and AI literacy apply

    Chapters I and II apply, including the Article 5 bans on prohibited AI practices and the Article 4 AI literacy duty (Art 113(a)).

    Takes effect20 months agoSource

March 20254 deadlines

  1. HIPAA

    Security Rule NPRM comment period closed

    Comments closed on the proposed HIPAA Security Rule update (90 FR 898); OCR has not issued a final rule.

    Transition19 months agoSource
  2. UK Online Safety Act

    Illegal harms duties enforceable

    Illegal content safety duties apply; illegal content risk assessments had to be completed by 16 March 2025.

    Takes effect18 months agoSource
  3. New LFPDPPP in force

    Law published 20 March 2025 enters into force the following day, repealing the 2010 law.

    Takes effect18 months agoSource
  4. EHDS enters into force

    Regulation (EU) 2025/327, published 5 Mar 2025, enters into force on the twentieth day following publication.

    Takes effect18 months agoSource

April 20255 deadlines

  1. PDPA amendments phase 2

    'Data controller' terminology, biometric data as sensitive data, higher penalties, Security Principle for processors, and removal of the cross-border whitelist take effect.

    Takes effect18 months agoSource
  2. DOJ Bulk Data Rule

    Prohibitions and restrictions take effect

    Core prohibitions on covered data transactions and security requirements for restricted transactions apply.

    Takes effect18 months agoSource
  3. UK Online Safety Act

    Children's access assessments due

    Services had to complete children's access assessments to determine whether children are likely to access them.

    Compliance deadline17 months agoSource
  4. NIS2

    Member States establish entity lists

    Member States had to establish lists of essential and important entities and notify the Commission of entity numbers (Art 3(3) and (5)). Repeated every two years.

    Reporting17 months agoSource
  5. DORA

    First registers of information submitted to the ESAs

    Competent authorities had to submit financial entities' registers of ICT third-party contractual arrangements (reference date 31 Mar 2025) to the ESAs by 30 Apr 2025. National authorities set earlier deadlines for entities.

    Reporting17 months agoSource

May 20256 deadlines

  1. PI compliance audit measures take effect

    Self-audit and regulator-ordered audit regime applies; 10M+ processors must audit at least every two years.

    Takes effect17 months agoSource
  2. Vulnerability scans, access privileges, malware controls, Class A monitoring

    500.5(a)(2) automated scans, 500.7 access privilege restrictions, 500.14(a)(2) malicious code protection, and 500.14(b) Class A endpoint detection and centralized logging apply.

    Compliance deadline17 months agoSource
  3. SB 226 amendments effective

    Disclosure duties narrowed (on clear request or high-risk interactions), safe harbor added, provisions recodified in Title 13, Ch. 75.

    Takes effect17 months agoSource
  4. TAKE IT DOWN Act

    Criminal provisions effective on enactment

    Publishing or threatening to publish non-consensual intimate images, including digital forgeries, became a federal crime upon signature.

    Takes effect16 months agoSource
  5. SB 25-276 geolocation and sensitive-data sale amendment effective

    Adds precise geolocation data definitions and prohibits selling sensitive data without consent (effective on signature).

    Takes effect16 months agoSource
  6. Ransomware payment reporting starts

    Reporting business entities must report ransomware/cyber-extortion payments to ASD within 72 hours of payment.

    Takes effect16 months agoSource

June 20258 deadlines

  1. PDPA amendments phase 3

    Mandatory DPO appointment, data breach notification, and data portability take effect.

    Compliance deadline16 months agoSource
  2. Division of Consumer Affairs proposes NJDPA rules (N.J.A.C. 13:45L)

    Proposed rules published at 57 N.J.R. 1101(a); comments were due Aug 1, 2025.

    Transition16 months agoSource
  3. AI Promotion Act promulgated and partly in force

    Most provisions, including basic principles and stakeholder duties, take effect on promulgation.

    Takes effect16 months agoSource
  4. Statutory tort for serious invasions of privacy commences

    Individuals can sue for serious invasions of privacy (Schedule 2), 6 months after Royal Assent.

    Takes effect15 months agoSource
  5. Bill C-8 introduced

    First reading in the House of Commons.

    Transition15 months agoSource
  6. Royal Assent

    The Act receives Royal Assent; commencement staged by regulations.

    Takes effect15 months agoSource
  7. TRAIGA

    HB 149 signed

    Governor Abbott signs TRAIGA.

    Transition15 months agoSource
  8. COPPA Rule

    Amended COPPA Rule takes effect

    The April 2025 amendments to 16 CFR Part 312 became effective; during the transition operators could comply with either the pre-2025 or the amended Rule.

    Takes effect15 months agoSource

July 20257 deadlines

  1. Biometric identifier amendment (HB 24-1130) effective

    Any controller processing biometric identifiers must adopt a written biometric policy, give notice, obtain consent and follow retention/deletion rules.

    Takes effect15 months agoSource
  2. OCPA applies to nonprofits

    Nonprofit organizations meeting the thresholds become subject to OCPA.

    Takes effect15 months agoSource
  3. TIPA takes effect

    Controller and processor obligations and consumer rights under Tenn. Code Ann. 47-18-3301 et seq. apply.

    Takes effect15 months agoSource
  4. DORA

    TLPT regulatory technical standards enter into force

    Commission Delegated Regulation (EU) 2025/1190 (published 18 June 2025) sets criteria for which financial entities must run threat-led penetration testing, plus methodology and tester requirements.

    Takes effect15 months agoSource
  5. Universal opt-out mechanism must be honored

    Controllers that sell personal data or process it for targeted advertising must honor user-selected universal opt-out signals within six months of the effective date (N.J.S.A. 56:8-166.11).

    Compliance deadline14 months agoSource
  6. UK Online Safety Act

    Protection of children duties apply

    Children's safety duties and Protection of Children Codes take effect, including highly effective age assurance; children's risk assessments due by 24 July 2025.

    Takes effect14 months agoSource
  7. MCDPA takes effect

    Consumer rights and controller/processor obligations apply (postsecondary institutions excepted).

    Takes effect14 months agoSource

August 20255 deadlines

  1. EU AI Act

    GPAI, governance, notified bodies and penalties apply

    Chapter III Section 4 (notifying authorities), Chapter V (general-purpose AI model obligations), Chapter VII (governance), Chapter XII (penalties, except Art 101) and Art 78 apply (Art 113(b)).

    Takes effect14 months agoSource
  2. Amendment 13 in force

    Amended Privacy Protection Law, PPA enforcement powers and statutory damages take effect.

    Takes effect13 months agoSource
  3. Stage 1 commencement

    Technical data protection provisions, ICO statutory objects, Smart Data framework (Part 1) and AI/copyright reporting duties commence (Commencement No. 1 Regulations 2025).

    Takes effect13 months agoSource
  4. Deadline to adopt ANPD standard contractual clauses

    Agents relying on contractual clauses for international transfers must incorporate the ANPD-approved SCCs into their contracts within 12 months of publication.

    Compliance deadline13 months agoSource
  5. SB 25B-004 delays the act

    Special-session bill pushes the SB 24-205 effective date from February 1, 2026 to June 30, 2026.

    Transition13 months agoSource

September 202510 deadlines

  1. AI content labeling measures and GB 45438-2025 take effect

    Explicit and implicit labeling duties for AI-generated content and platform detection duties apply.

    Takes effect13 months agoSource
  2. AI Promotion Act fully in force

    Provisions establishing the AI Strategy Headquarters and AI Basic Plan take effect.

    Takes effect13 months agoSource
  3. General Court upholds DPF (Latombe v Commission)

    General Court dismissed Philippe Latombe's action for annulment (Case T-553/23) and confirmed the US offered adequate protection when the decision was adopted.

    Enforcement13 months agoSource
  4. EU Data Act

    Data Act applies

    Most obligations apply, including user data access and sharing (Chapters II-III), cloud switching (Chapter VI) and interoperability; Chapter IV unfair terms apply to contracts concluded after this date (Art 50).

    Takes effect12 months agoSource
  5. EU Data Act

    Member States notify penalty rules

    Member States had to notify the Commission of their penalty rules (Art 40(2)).

    Reporting12 months agoSource
  6. GAID 2025 takes effect

    General Application and Implementation Directive becomes effective, replacing the NDPR 2019 and NDPR Implementation Framework.

    Takes effect12 months agoSource
  7. CCPA / CPRA

    ADMT, risk assessment and cybersecurity audit regulations approved

    OAL approves the CCPA Updates, Cybersecurity Audit, Risk Assessment, ADMT and Insurance regulations and files them with the Secretary of State.

    Transition12 months agoSource
  8. Data Governance Act

    Legacy data intermediaries must comply

    Entities that were already providing data intermediation services on 23 June 2022 had to comply with Chapter III by 24 Sep 2025 (Art 37).

    Compliance deadline12 months agoSource
  9. Privacy Amendment Act 2025 technical changes commence

    Technical amendments commence the day after Royal Assent (23 Sep 2025).

    Takes effect12 months agoSource
  10. SB 53 signed

    Governor Newsom signs SB 53 (chapter 138).

    Transition12 months agoSource

October 20257 deadlines

  1. Minors' data amendment (SB 24-041) effective

    Controllers offering online services to minors must use reasonable care, conduct assessments, and obtain consent for targeted ads, sale and certain profiling of minors.

    Takes effect12 months agoSource
  2. MODPA takes effect

    Act takes effect; data protection assessments apply to processing activities on or after Oct 1, 2025.

    Takes effect12 months agoSource
  3. SB 297 amendments take effect; cure period eliminated

    Lower thresholds (25,000 / 15,000 + 25%), minors' data protections, AG assessment demands; the 60-day cure period is removed.

    Enforcement12 months agoSource
  4. DOJ Bulk Data Rule

    Due diligence, audit and reporting obligations apply

    Subpart J (data compliance program, due diligence and audits for restricted transactions) and reporting requirements in 202.1103 and 202.1104 apply.

    Compliance deadline12 months agoSource
  5. AB 853 signed

    AB 853 (ch. 674) delays the operative date and adds platform and device duties.

    Transition11 months agoSource
  6. SB 243 signed

    SB 243 chaptered (ch. 677).

    Transition11 months agoSource
  7. Latombe appeal lodged at the Court of Justice

    Latombe appealed the General Court judgment to the Court of Justice on points of law (reported as Case C-703/25 P); the DPF stays valid while it is pending.

    Enforcement11 months agoSource

November 20256 deadlines

  1. Universal MFA and asset inventory

    500.12 multi-factor authentication for all users and 500.13(a) asset inventory requirements apply.

    Compliance deadline11 months agoSource
  2. CMMC 2.0

    DFARS rule effective; Phase 1 begins

    CMMC Level 1 and Level 2 self-assessment requirements begin appearing in applicable DoD solicitations and contracts (32 CFR 170.3(e)(1)).

    Takes effect10 months agoSource
  3. Introduced (Commons first reading)

    Bill introduced in the House of Commons.

    Takes effect10 months agoSource
  4. DPDP Rules published; Board and procedural rules in force

    Rules 1, 2 and 17-21 (Data Protection Board constitution and functioning) take effect on publication in the Official Gazette.

    Takes effect10 months agoSource
  5. DORA

    First critical ICT third-party providers designated

    The ESAs published the first list of 19 critical ICT third-party providers (including AWS, Google Cloud and Microsoft), which now come under direct EU oversight.

    Enforcement10 months agoSource
  6. GDPR

    GDPR Procedural Regulation adopted

    Regulation (EU) 2025/2518 laying down additional procedural rules for cross-border GDPR enforcement signed by Parliament and Council.

    Transition10 months agoSource

December 20254 deadlines

  1. SEC Regulation S-P

    Larger entities must comply

    Larger covered institutions (18 months after Federal Register publication) must have incident response programs, 30-day customer notification, and service-provider oversight in place.

    Compliance deadline10 months agoSource
  2. Social media minimum age obligation applies

    Age-restricted platforms must take reasonable steps to prevent under-16s from holding accounts.

    Takes effect9 months agoSource
  3. NY RAISE Act

    RAISE Act signed

    Governor Hochul signs the RAISE Act with an agreed chapter amendment.

    Transition9 months agoSource
  4. Mandatory 60-day cure period expires

    Mandatory notice-and-cure ends Dec 31, 2025; from Jan 1, 2026 DOJ decides whether to offer a cure using statutory factors.

    Enforcement9 months agoSource

When the rules change: new data, privacy and AI laws and deadlines, the next morning.