Skip to content

2026 compliance deadlines

78 data, privacy, AI and cybersecurity deadlines fall in 2026, across 55 regulations.

January 202625 deadlines

  1. Ransomware reporting moves to compliance phase

    The education-first phase (30 May-31 Dec 2025) ends; Home Affairs moves to a compliance and education approach for missed reports.

    Enforcement9 months agoSource
  2. Training-data documentation due

    Documentation must be posted for GenAI systems released since January 1, 2022, and before each later release or substantial modification.

    Compliance deadline9 months agoSource
  3. Original operative date (superseded)

    Original SB 942 date; delayed to August 2, 2026 by AB 853.

    Transition9 months agoSource
  4. DROP opens to consumers

    Consumers can submit a single deletion request to all registered data brokers through DROP.

    Takes effect9 months agoSource
  5. Chatbot safeguards apply

    AI disclosure, suicide and self-harm protocols, and minor protections apply.

    Takes effect9 months agoSource
  6. Frontier developer obligations apply

    Frontier AI frameworks, transparency reports, critical safety incident reporting (15 days, or 24 hours for imminent risk of death or serious injury) and whistleblower protections apply.

    Takes effect9 months agoSource
  7. CCPA / CPRA

    New CCPA regulations take effect

    ADMT, risk assessment, cybersecurity audit and updated CCPA regulations become effective; risk assessments required for new high-risk processing.

    Takes effect9 months agoSource
  8. 2025 amendments take effect

    Higher fines, first-violation fines, AI governance provisions and PIPL-alignment duties apply under the 28 Oct 2025 NPCSC Decision.

    Takes effect9 months agoSource
  9. Opt-out preference signals must be honored

    Controllers must allow opt-out of targeted advertising and sale via opt-out preference signals (12D-106).

    Compliance deadline9 months agoSource
  10. GDPR

    GDPR Procedural Regulation enters into force

    Regulation (EU) 2025/2518, published in the OJ on 12 December 2025, enters into force on the twentieth day after publication.

    Transition9 months agoSource
  11. PCICSO comes into operation

    Commissioner's Office is established and designation of CIOs begins; obligations apply to designated operators.

    Takes effect9 months agoSource
  12. AI anti-discrimination and notice duties apply

    Prohibition on discriminatory AI use and the employee notice requirement take effect.

    Takes effect9 months agoSource
  13. ICDPA takes effect

    Consumer rights and controller/processor obligations apply; assessments required for processing activities created on or after this date.

    Takes effect9 months agoSource
  14. KCDPA takes effect

    Consumer rights and controller/processor obligations apply (HB 15 section 12).

    Takes effect9 months agoSource
  15. Mandatory 60-day cure period expires

    The AG's obligation to issue a cure notice ended Dec 31, 2025; from Jan 1, 2026 cure opportunities are discretionary (RSA 507-H:11 II-III).

    Enforcement9 months agoSource
  16. Cure period sunsets

    The AG's 30-day notice-and-cure requirement expires; enforcement can proceed without a cure opportunity.

    Enforcement9 months agoSource
  17. Universal opt-out signals must be honored

    Controllers must honor opt-out preference signals such as Global Privacy Control.

    Compliance deadline9 months agoSource
  18. Sale ban on precise geolocation and under-16 data (HB 2008)

    Selling precise geolocation (1,750-ft radius) and the personal data of consumers the controller knows or willfully disregards are under 16 is prohibited.

    Takes effect9 months agoSource
  19. RIDTPPA takes effect

    All provisions of R.I. Gen. Laws ch. 6-48.1 apply (P.L. 2024, ch. 430/453, effective Jan 1, 2026).

    Takes effect9 months agoSource
  20. TRAIGA

    TRAIGA takes effect

    Prohibited-practice rules, AG enforcement, sandbox program and government AI disclosure duties apply.

    Takes effect9 months agoSource
  21. PDPL and Decree 356/2025 take effect

    Personal data protection obligations, DPIA/TIA filing and penalty framework apply; Decree 13/2023 replaced.

    Takes effect9 months agoSource
  22. Under-16 social media time limit (SB 854) takes effect

    Social media platforms must use commercially reasonable age determination and cap users under 16 at 1 hour/day unless a parent consents. A preliminary injunction issued Feb 27, 2026 bars enforcement.

    Takes effect9 months agoSource
  23. AI Basic Act and Enforcement Decree take effect

    Transparency, labeling, high-impact AI, and domestic representative obligations apply (fines deferred during the grace period).

    Takes effect8 months agoSource
  24. Annual data broker registration deadline

    Data brokers must register with CalPrivacy and pay the annual fee ($6,000 for 2026) by January 31.

    Reporting8 months agoSource
  25. 30-day cure period expires

    The requirement that the AG send a warning letter and allow 30 days to cure before suing expires Jan 31, 2026 (325M.20(a)).

    Enforcement8 months agoSource

February 20265 deadlines

  1. Original effective date (superseded)

    Original SB 24-205 date; postponed by SB 25B-004, so no obligations applied.

    Transition8 months agoSource
  2. Stage 3: main data protection changes commence

    Recognised legitimate interests, ADM reforms, DSAR changes, international transfer test, cookie exemptions and PECR fines at UK GDPR levels apply (Commencement No. 6 Regulations 2026, reg. 2).

    Takes effect8 months agoSource
  3. UK GDPR

    DUAA amendments to UK GDPR commence

    Main Data (Use and Access) Act 2025 Part 5 amendments (recognised legitimate interests, ADM, DSAR, transfers, cookies, PECR fines) apply.

    Takes effect8 months agoSource
  4. HIPAA

    Notice of Privacy Practices updates (Part 2 alignment)

    Covered entities must update Notices of Privacy Practices under 45 CFR 164.520 for the 2024 Part 2 (substance use disorder records) changes; this NPP piece survived the Purl vacatur.

    Compliance deadline7 months agoSource
  5. SB 854 preliminarily enjoined (NetChoice v. Jones)

    E.D. Va. preliminarily enjoined enforcement of the SB 854 social media time-limit provisions on First Amendment grounds; Virginia has appealed.

    Enforcement7 months agoSource

March 20264 deadlines

  1. AI Law takes effect

    Risk classification, transparency and labeling obligations apply to new AI systems.

    Takes effect7 months agoSource
  2. South Korea PIPA

    2026 PIPA amendment promulgated (Act No. 21445)

    Amendment raising fines to 10% of revenue and adding CEO accountability promulgated.

    Transition7 months agoSource
  3. ECA Digital in force

    Art. 41-A (as set by Law 15.352/2026, following MP 1.319/2025) fixes entry into force on 17 March 2026.

    Takes effect6 months agoSource
  4. NY RAISE Act

    Chapter amendment S8828 signed

    Chapter amendment (ch. 96) finalizes the RAISE Act text.

    Transition6 months agoSource

April 20265 deadlines

  1. Seventh Circuit: amendment applies retroactively

    Clay v. Union Pacific (No. 25-2185) holds the damages amendment is remedial and applies to pending cases.

    Transition6 months agoSource
  2. MODPA applies to personal data processing

    The act applies to personal data processing activities from April 1, 2026 (Section 2 of ch. 455).

    Compliance deadline6 months agoSource
  3. UK Online Safety Act

    Fee notification window closes (2026/27)

    Fee-liable providers must notify Ofcom before the notification window for the first charging year closes.

    Reporting5 months agoSource
  4. Annual compliance notification

    Annual certification or acknowledgment covering calendar year 2025 due.

    Reporting5 months agoSource
  5. COPPA Rule

    Full compliance with amended COPPA Rule

    Operators must comply with all amended provisions (separate third-party disclosure consent, written retention policy, written security program, updated notices); excludes Safe Harbor provisions 312.11(d)(1), (d)(4) and (g), which had earlier dates.

    Compliance deadline5 months agoSource

May 20265 deadlines

  1. IPP 3A indirect-collection notification applies

    Agencies collecting personal information from third parties must take reasonable steps to notify individuals, subject to exceptions.

    Compliance deadline5 months agoSource
  2. SB 26-189 signed (repeal and reenact)

    SB 26-189 replaces SB 24-205 with a narrower ADMT disclosure framework and moves the effective date to January 1, 2027.

    Transition4 months agoSource
  3. IDHR proposed notice rules published

    IDHR publishes proposed Subpart J rules on AI notice in the Illinois Register.

    Transition4 months agoSource
  4. TAKE IT DOWN Act

    Platform notice-and-removal process required

    Covered platforms must have a clear notice-and-removal process and remove valid reported content within 48 hours (Sec. 3, one year after enactment).

    Compliance deadline4 months agoSource
  5. Legacy qualified trust service providers conformity report

    QTSPs qualified before 20 May 2024 had to submit a conformity assessment report proving compliance with Art 24(1), (1a) and (1b) by 21 May 2026.

    Compliance deadline4 months agoSource

June 20269 deadlines

  1. IDHR withdraws and postpones proposed rules

    IDHR withdraws the Subpart J proposal and postpones the June 10, 2026 hearing; no new date announced.

    Transition4 months agoSource
  2. SEC Regulation S-P

    Smaller entities must comply

    Smaller covered institutions (24 months after Federal Register publication) must comply with the amended Regulation S-P.

    Compliance deadline4 months agoSource
  3. Cyber Resilience Act

    Conformity assessment body provisions apply

    Chapter IV (Arts 35-51, notification of conformity assessment bodies) applies (Art 71(2)).

    Takes effect3 months agoSource
  4. Bill C-36 tabled (first reading)

    Government introduces the PPCDA in the House of Commons.

    Takes effect3 months agoSource
  5. Royal Assent

    Bill C-8 receives Royal Assent (S.C. 2026, c. 9); Telecommunications Act amendments take effect.

    Takes effect3 months agoSource
  6. Passes House of Commons

    Report stage and third reading completed in the Commons after carry-over into the new session.

    Takes effect3 months agoSource
  7. Mandatory data protection complaints procedure

    Controllers must have a process for data subject complaints (s.103 and Sch. 10), per Commencement No. 6 Regulations 2026, reg. 3.

    Compliance deadline3 months agoSource
  8. Delayed effective date (superseded)

    SB 25B-004 date; superseded by SB 26-189 before it arrived, so no obligations applied.

    Transition3 months agoSource
  9. A5328 sensitive data sale ban takes effect

    A5328, signed June 30, 2026, prohibits selling sensitive personal data; the ban took effect on signing.

    Takes effect3 months agoSource

July 20266 deadlines

  1. PA 25-113 (SB 1295) amendments take effect

    Thresholds drop to 35,000 consumers or any sensitive-data processing or data sale; expanded sensitive data, minors' protections, and LLM-training disclosure in privacy notices.

    Takes effect3 months agoSource
  2. Mandatory 30-day cure period expires

    The Division's duty to issue a cure notice before enforcement ends on the first day of the 18th month after the effective date (N.J.S.A. 56:8-166.17(b)).

    Enforcement3 months agoSource
  3. Right to correct takes effect

    Consumers may ask controllers to correct inaccurate personal data (13-61-201(4), as amended by Laws 2025, ch. 468).

    Takes effect3 months agoSource
  4. Ban on selling precise geolocation data (SB 338)

    Controllers may not sell consumers' precise geolocation data (1,750-ft radius), replacing the prior consent-based treatment.

    Takes effect3 months agoSource
  5. 2026 APPI amendment act promulgated

    Amendment enacted by the Diet on 10 July 2026 and promulgated; main provisions take effect by cabinet order within two years of promulgation.

    Transition2 months agoSource
  6. EU AI Act

    Digital Omnibus on AI enters into force

    Regulation (EU) 2026/1744 (adopted 8 July 2026, OJ 24 July 2026) enters into force on the third day after publication. Amended Articles 102 to 110 apply from this date (new Art 113(d)).

    Transition59 days agoSource

August 20265 deadlines

  1. Data brokers must begin processing DROP deletion requests

    Brokers must access DROP at least every 45 days, process verified deletion requests within 45 days, and treat unverified requests as opt-outs of sale/sharing.

    Compliance deadline54 days agoSource
  2. Profiling impact assessments apply

    Impact assessment requirements apply to profiling activities created or generated on or after Aug 1, 2026 (Conn. Gen. Stat. 42-522 as amended).

    Compliance deadline54 days agoSource
  3. Covered provider duties apply

    Detection tool, manifest and latent disclosures, and license-revocation duties become operative.

    Takes effect53 days agoSource
  4. EU AI Act

    General application: transparency obligations, GPAI fines, most other rules

    The AI Act's general date of application. Article 50 transparency obligations (chatbot disclosure, deepfake labelling, machine-readable marking of synthetic content) and Commission fines on GPAI providers (Art 101) apply. Not deferred by the Omnibus.

    Takes effect53 days agoSource
  5. Digital Services Act

    ChatGPT designated as VLOSE; Reddit and Roblox as VLOPs

    Commission designated ChatGPT as a very large online search engine and Reddit and Roblox as very large online platforms. They have four months (by January 2027) to meet VLOP/VLOSE obligations.

    Enforcement24 days agoSource

September 20264 deadlines

  1. Cyber Resilience Act

    Vulnerability and incident reporting obligations apply

    Art 14: manufacturers must report actively exploited vulnerabilities and severe incidents (24-hour early warning, 72-hour notification) via the single reporting platform. Also covers products placed on the market before 11 Dec 2027 (Art 69(3)).

    Reporting13 days agoSource
  2. South Korea PIPA

    2026 PIPA amendments take effect

    10%-of-revenue fines, CEO accountability, and notice duties for possible breaches apply.

    Takes effect13 days agoSource
  3. EU Data Act

    Access-by-design for new connected products

    Art 3(1) design obligation (product data and related service data accessible to the user by default) applies to connected products and related services placed on the market after 12 Sep 2026.

    Compliance deadline12 days agoSource
  4. ICO abolished; Information Commission takes over

    Sections 118-119 commence: office of Information Commissioner abolished and functions transferred to the Information Commission (Commencement No. 9 Regulations 2026).

    Takes effectin 6 daysSource

October 20262 deadlines

  1. PA 26-64 (SB 4) amendments take effect

    Prohibits controllers and third parties from selling precise geolocation data and enacts data broker and other consumer protection provisions.

    Takes effectin 7 daysSource
  2. Lords report stage scheduled

    House of Lords report stage scheduled (committee stage sat 1, 3 and 7 Sept 2026).

    Takes effectTentativein 32 daysSource

November 20262 deadlines

  1. CMMC 2.0

    Phase 2: Level 2 C3PAO certification

    Phase 2 begins one calendar year after Phase 1; applicable solicitations require CMMC Level 2 third-party (C3PAO) certification (32 CFR 170.3(e)(2)).

    Compliance deadlinein 47 daysSource
  2. Consent Manager registration rule in force (12 months)

    Rule 4 (registration and obligations of Consent Managers) comes into force one year after publication.

    Transitionin 50 daysSource

December 20266 deadlines

  1. Law in force

    Main obligations apply and the Personal Data Protection Agency begins supervision.

    Takes effectin 2 monthsSource
  2. EU AI Act

    New bans on sexual deepfakes and CSAM generation; Art 50(2) grace period ends

    New Art 5(1)(ba)/(bb) prohibitions on AI systems that generate non-consensual intimate imagery of identifiable persons or child sexual abuse material apply. Generative AI systems placed on the market before 2 Aug 2026 must comply with the Art 50(2) marking duty by this date (new Art 111(4)).

    Compliance deadlinein 2 monthsSource
  3. Transposition deadline; old PLD repealed

    Member States must transpose by 9 Dec 2026 (Art 22). Directive 85/374/EEC is repealed from that date but still applies to products placed on the market before it (Art 21).

    Transitionin 3 monthsSource
  4. Children's Online Privacy Code must be registered

    OAIC must develop and register the Children's Online Privacy Code within 24 months of Royal Assent.

    Compliance deadlinein 3 monthsSource
  5. Automated decision-making transparency applies

    Privacy policies must disclose the kinds of personal information used in substantially automated decisions that significantly affect individuals (24 months after assent).

    Compliance deadlinein 3 monthsSource
  6. Member States must provide EU Digital Identity Wallets

    Each Member State must provide at least one wallet within 24 months of the entry into force of the implementing acts under Arts 5a(23) and 5c(6) (Art 5a(1)).

    Compliance deadlinein 3 monthsSource

When the rules change: new data, privacy and AI laws and deadlines, the next morning.