2025 compliance deadlines
76 data, privacy, AI and cybersecurity deadlines fall in 2025, across 54 regulations.
Add to calendar
January 202513 deadlines
CPI adjustment of thresholds and fines
Revenue threshold rises to $26,625,000 and fines to $2,663 / $7,988 per violation.
Network Data Regulations take effect
All provisions, including the 10-million-person threshold duties and annual important-data risk assessments, apply.
60-day cure period expires
Mandatory 60-day notice-and-cure before AG enforcement ends; enforcement may proceed without cure.
Universal opt-out preference signals required
Controllers must honor opt-out preference signals for targeted advertising and sale (effective Jan 1, 2025).
DPDPA takes effect
Consumer rights and controller duties apply; 60-day mandatory cure period begins.
ICDPA takes effect
Consumer rights and controller/processor obligations apply.
PDPA amendments phase 1
Miscellaneous provisions commence (e.g. electronic service of notices).
Nebraska Data Privacy Act takes effect
Controller and processor obligations and consumer rights under Neb. Rev. Stat. 87-1101 et seq. apply.
- New Hampshire Privacy ActNew Hampshire
New Hampshire Privacy Act takes effect
RSA 507-H obligations and consumer rights apply (Laws 2024, 5:1, eff. Jan. 1, 2025).
Universal opt-out mechanism requirement applies
Controllers must honor global privacy control / universal opt-out signals (Bus. & Com. Code 541.055(e)).
NJDPA takes effect
The act takes effect on the 365th day after enactment on Jan 16, 2024 (sec. 17).
- NIS2European Union
Digital infrastructure entities submit registration data
DNS providers, TLD registries, domain registration services, cloud, data centre, CDN, managed (security) service providers, marketplaces, search engines and social networks had to submit registration details to competent authorities (Art 27(2)).
February 20251 deadline
March 20254 deadlines
Illegal harms duties enforceable
Illegal content safety duties apply; illegal content risk assessments had to be completed by 16 March 2025.
- Mexico LFPDPPP 2025Mexico
New LFPDPPP in force
Law published 20 March 2025 enters into force the following day, repealing the 2010 law.
- European Health Data Space (EHDS)European Union
EHDS enters into force
Regulation (EU) 2025/327, published 5 Mar 2025, enters into force on the twentieth day following publication.
April 20255 deadlines
PDPA amendments phase 2
'Data controller' terminology, biometric data as sensitive data, higher penalties, Security Principle for processors, and removal of the cross-border whitelist take effect.
Prohibitions and restrictions take effect
Core prohibitions on covered data transactions and security requirements for restricted transactions apply.
Children's access assessments due
Services had to complete children's access assessments to determine whether children are likely to access them.
- DORAEuropean Union
First registers of information submitted to the ESAs
Competent authorities had to submit financial entities' registers of ICT third-party contractual arrangements (reference date 31 Mar 2025) to the ESAs by 30 Apr 2025. National authorities set earlier deadlines for entities.
May 20256 deadlines
PI compliance audit measures take effect
Self-audit and regulator-ordered audit regime applies; 10M+ processors must audit at least every two years.
Vulnerability scans, access privileges, malware controls, Class A monitoring
500.5(a)(2) automated scans, 500.7 access privilege restrictions, 500.14(a)(2) malicious code protection, and 500.14(b) Class A endpoint detection and centralized logging apply.
SB 226 amendments effective
Disclosure duties narrowed (on clear request or high-risk interactions), safe harbor added, provisions recodified in Title 13, Ch. 75.
Criminal provisions effective on enactment
Publishing or threatening to publish non-consensual intimate images, including digital forgeries, became a federal crime upon signature.
SB 25-276 geolocation and sensitive-data sale amendment effective
Adds precise geolocation data definitions and prohibits selling sensitive data without consent (effective on signature).
Ransomware payment reporting starts
Reporting business entities must report ransomware/cyber-extortion payments to ASD within 72 hours of payment.
June 20258 deadlines
PDPA amendments phase 3
Mandatory DPO appointment, data breach notification, and data portability take effect.
Division of Consumer Affairs proposes NJDPA rules (N.J.A.C. 13:45L)
Proposed rules published at 57 N.J.R. 1101(a); comments were due Aug 1, 2025.
AI Promotion Act promulgated and partly in force
Most provisions, including basic principles and stakeholder duties, take effect on promulgation.
Statutory tort for serious invasions of privacy commences
Individuals can sue for serious invasions of privacy (Schedule 2), 6 months after Royal Assent.
Bill C-8 introduced
First reading in the House of Commons.
Royal Assent
The Act receives Royal Assent; commencement staged by regulations.
Amended COPPA Rule takes effect
The April 2025 amendments to 16 CFR Part 312 became effective; during the transition operators could comply with either the pre-2025 or the amended Rule.
July 20257 deadlines
Biometric identifier amendment (HB 24-1130) effective
Any controller processing biometric identifiers must adopt a written biometric policy, give notice, obtain consent and follow retention/deletion rules.
OCPA applies to nonprofits
Nonprofit organizations meeting the thresholds become subject to OCPA.
TIPA takes effect
Controller and processor obligations and consumer rights under Tenn. Code Ann. 47-18-3301 et seq. apply.
Universal opt-out mechanism must be honored
Controllers that sell personal data or process it for targeted advertising must honor user-selected universal opt-out signals within six months of the effective date (N.J.S.A. 56:8-166.11).
Protection of children duties apply
Children's safety duties and Protection of Children Codes take effect, including highly effective age assurance; children's risk assessments due by 24 July 2025.
MCDPA takes effect
Consumer rights and controller/processor obligations apply (postsecondary institutions excepted).
August 20255 deadlines
- EU AI ActEuropean Union
GPAI, governance, notified bodies and penalties apply
Chapter III Section 4 (notifying authorities), Chapter V (general-purpose AI model obligations), Chapter VII (governance), Chapter XII (penalties, except Art 101) and Art 78 apply (Art 113(b)).
Amendment 13 in force
Amended Privacy Protection Law, PPA enforcement powers and statutory damages take effect.
Stage 1 commencement
Technical data protection provisions, ICO statutory objects, Smart Data framework (Part 1) and AI/copyright reporting duties commence (Commencement No. 1 Regulations 2025).
Deadline to adopt ANPD standard contractual clauses
Agents relying on contractual clauses for international transfers must incorporate the ANPD-approved SCCs into their contracts within 12 months of publication.
SB 25B-004 delays the act
Special-session bill pushes the SB 24-205 effective date from February 1, 2026 to June 30, 2026.
September 202510 deadlines
AI content labeling measures and GB 45438-2025 take effect
Explicit and implicit labeling duties for AI-generated content and platform detection duties apply.
AI Promotion Act fully in force
Provisions establishing the AI Strategy Headquarters and AI Basic Plan take effect.
- EU-US Data Privacy FrameworkEuropean Union
General Court upholds DPF (Latombe v Commission)
General Court dismissed Philippe Latombe's action for annulment (Case T-553/23) and confirmed the US offered adequate protection when the decision was adopted.
- EU Data ActEuropean Union
Data Act applies
Most obligations apply, including user data access and sharing (Chapters II-III), cloud switching (Chapter VI) and interoperability; Chapter IV unfair terms apply to contracts concluded after this date (Art 50).
- EU Data ActEuropean Union
Member States notify penalty rules
Member States had to notify the Commission of their penalty rules (Art 40(2)).
GAID 2025 takes effect
General Application and Implementation Directive becomes effective, replacing the NDPR 2019 and NDPR Implementation Framework.
ADMT, risk assessment and cybersecurity audit regulations approved
OAL approves the CCPA Updates, Cybersecurity Audit, Risk Assessment, ADMT and Insurance regulations and files them with the Secretary of State.
- Data Governance ActEuropean Union
Legacy data intermediaries must comply
Entities that were already providing data intermediation services on 23 June 2022 had to comply with Chapter III by 24 Sep 2025 (Art 37).
Privacy Amendment Act 2025 technical changes commence
Technical amendments commence the day after Royal Assent (23 Sep 2025).
SB 53 signed
Governor Newsom signs SB 53 (chapter 138).
October 20257 deadlines
Minors' data amendment (SB 24-041) effective
Controllers offering online services to minors must use reasonable care, conduct assessments, and obtain consent for targeted ads, sale and certain profiling of minors.
MODPA takes effect
Act takes effect; data protection assessments apply to processing activities on or after Oct 1, 2025.
SB 297 amendments take effect; cure period eliminated
Lower thresholds (25,000 / 15,000 + 25%), minors' data protections, AG assessment demands; the 60-day cure period is removed.
Due diligence, audit and reporting obligations apply
Subpart J (data compliance program, due diligence and audits for restricted transactions) and reporting requirements in 202.1103 and 202.1104 apply.
AB 853 signed
AB 853 (ch. 674) delays the operative date and adds platform and device duties.
SB 243 signed
SB 243 chaptered (ch. 677).
- EU-US Data Privacy FrameworkEuropean Union
Latombe appeal lodged at the Court of Justice
Latombe appealed the General Court judgment to the Court of Justice on points of law (reported as Case C-703/25 P); the DPF stays valid while it is pending.
November 20256 deadlines
Universal MFA and asset inventory
500.12 multi-factor authentication for all users and 500.13(a) asset inventory requirements apply.
Introduced (Commons first reading)
Bill introduced in the House of Commons.
DPDP Rules published; Board and procedural rules in force
Rules 1, 2 and 17-21 (Data Protection Board constitution and functioning) take effect on publication in the Official Gazette.
December 20254 deadlines
Larger entities must comply
Larger covered institutions (18 months after Federal Register publication) must have incident response programs, 30-day customer notification, and service-provider oversight in place.
Social media minimum age obligation applies
Age-restricted platforms must take reasonable steps to prevent under-16s from holding accounts.
RAISE Act signed
Governor Hochul signs the RAISE Act with an agreed chapter amendment.
Mandatory 60-day cure period expires
Mandatory notice-and-cure ends Dec 31, 2025; from Jan 1, 2026 DOJ decides whether to offer a cure using statutory factors.