2026 compliance deadlines
78 data, privacy, AI and cybersecurity deadlines fall in 2026, across 55 regulations.
Add to calendar
January 202625 deadlines
Ransomware reporting moves to compliance phase
The education-first phase (30 May-31 Dec 2025) ends; Home Affairs moves to a compliance and education approach for missed reports.
Training-data documentation due
Documentation must be posted for GenAI systems released since January 1, 2022, and before each later release or substantial modification.
Original operative date (superseded)
Original SB 942 date; delayed to August 2, 2026 by AB 853.
DROP opens to consumers
Consumers can submit a single deletion request to all registered data brokers through DROP.
Chatbot safeguards apply
AI disclosure, suicide and self-harm protocols, and minor protections apply.
Frontier developer obligations apply
Frontier AI frameworks, transparency reports, critical safety incident reporting (15 days, or 24 hours for imminent risk of death or serious injury) and whistleblower protections apply.
New CCPA regulations take effect
ADMT, risk assessment, cybersecurity audit and updated CCPA regulations become effective; risk assessments required for new high-risk processing.
2025 amendments take effect
Higher fines, first-violation fines, AI governance provisions and PIPL-alignment duties apply under the 28 Oct 2025 NPCSC Decision.
Opt-out preference signals must be honored
Controllers must allow opt-out of targeted advertising and sale via opt-out preference signals (12D-106).
PCICSO comes into operation
Commissioner's Office is established and designation of CIOs begins; obligations apply to designated operators.
AI anti-discrimination and notice duties apply
Prohibition on discriminatory AI use and the employee notice requirement take effect.
ICDPA takes effect
Consumer rights and controller/processor obligations apply; assessments required for processing activities created on or after this date.
KCDPA takes effect
Consumer rights and controller/processor obligations apply (HB 15 section 12).
- New Hampshire Privacy ActNew Hampshire
Mandatory 60-day cure period expires
The AG's obligation to issue a cure notice ended Dec 31, 2025; from Jan 1, 2026 cure opportunities are discretionary (RSA 507-H:11 II-III).
Cure period sunsets
The AG's 30-day notice-and-cure requirement expires; enforcement can proceed without a cure opportunity.
Universal opt-out signals must be honored
Controllers must honor opt-out preference signals such as Global Privacy Control.
Sale ban on precise geolocation and under-16 data (HB 2008)
Selling precise geolocation (1,750-ft radius) and the personal data of consumers the controller knows or willfully disregards are under 16 is prohibited.
RIDTPPA takes effect
All provisions of R.I. Gen. Laws ch. 6-48.1 apply (P.L. 2024, ch. 430/453, effective Jan 1, 2026).
PDPL and Decree 356/2025 take effect
Personal data protection obligations, DPIA/TIA filing and penalty framework apply; Decree 13/2023 replaced.
Under-16 social media time limit (SB 854) takes effect
Social media platforms must use commercially reasonable age determination and cap users under 16 at 1 hour/day unless a parent consents. A preliminary injunction issued Feb 27, 2026 bars enforcement.
AI Basic Act and Enforcement Decree take effect
Transparency, labeling, high-impact AI, and domestic representative obligations apply (fines deferred during the grace period).
Annual data broker registration deadline
Data brokers must register with CalPrivacy and pay the annual fee ($6,000 for 2026) by January 31.
30-day cure period expires
The requirement that the AG send a warning letter and allow 30 days to cure before suing expires Jan 31, 2026 (325M.20(a)).
February 20265 deadlines
Original effective date (superseded)
Original SB 24-205 date; postponed by SB 25B-004, so no obligations applied.
Stage 3: main data protection changes commence
Recognised legitimate interests, ADM reforms, DSAR changes, international transfer test, cookie exemptions and PECR fines at UK GDPR levels apply (Commencement No. 6 Regulations 2026, reg. 2).
Notice of Privacy Practices updates (Part 2 alignment)
Covered entities must update Notices of Privacy Practices under 45 CFR 164.520 for the 2024 Part 2 (substance use disorder records) changes; this NPP piece survived the Purl vacatur.
SB 854 preliminarily enjoined (NetChoice v. Jones)
E.D. Va. preliminarily enjoined enforcement of the SB 854 social media time-limit provisions on First Amendment grounds; Virginia has appealed.
March 20264 deadlines
AI Law takes effect
Risk classification, transparency and labeling obligations apply to new AI systems.
2026 PIPA amendment promulgated (Act No. 21445)
Amendment raising fines to 10% of revenue and adding CEO accountability promulgated.
ECA Digital in force
Art. 41-A (as set by Law 15.352/2026, following MP 1.319/2025) fixes entry into force on 17 March 2026.
Chapter amendment S8828 signed
Chapter amendment (ch. 96) finalizes the RAISE Act text.
April 20265 deadlines
Seventh Circuit: amendment applies retroactively
Clay v. Union Pacific (No. 25-2185) holds the damages amendment is remedial and applies to pending cases.
MODPA applies to personal data processing
The act applies to personal data processing activities from April 1, 2026 (Section 2 of ch. 455).
Fee notification window closes (2026/27)
Fee-liable providers must notify Ofcom before the notification window for the first charging year closes.
Annual compliance notification
Annual certification or acknowledgment covering calendar year 2025 due.
Full compliance with amended COPPA Rule
Operators must comply with all amended provisions (separate third-party disclosure consent, written retention policy, written security program, updated notices); excludes Safe Harbor provisions 312.11(d)(1), (d)(4) and (g), which had earlier dates.
May 20265 deadlines
IPP 3A indirect-collection notification applies
Agencies collecting personal information from third parties must take reasonable steps to notify individuals, subject to exceptions.
SB 26-189 signed (repeal and reenact)
SB 26-189 replaces SB 24-205 with a narrower ADMT disclosure framework and moves the effective date to January 1, 2027.
IDHR proposed notice rules published
IDHR publishes proposed Subpart J rules on AI notice in the Illinois Register.
Platform notice-and-removal process required
Covered platforms must have a clear notice-and-removal process and remove valid reported content within 48 hours (Sec. 3, one year after enactment).
- eIDAS 2 / EU Digital Identity WalletEuropean Union
Legacy qualified trust service providers conformity report
QTSPs qualified before 20 May 2024 had to submit a conformity assessment report proving compliance with Art 24(1), (1a) and (1b) by 21 May 2026.
June 20269 deadlines
IDHR withdraws and postpones proposed rules
IDHR withdraws the Subpart J proposal and postpones the June 10, 2026 hearing; no new date announced.
Smaller entities must comply
Smaller covered institutions (24 months after Federal Register publication) must comply with the amended Regulation S-P.
- Cyber Resilience ActEuropean Union
Conformity assessment body provisions apply
Chapter IV (Arts 35-51, notification of conformity assessment bodies) applies (Art 71(2)).
Bill C-36 tabled (first reading)
Government introduces the PPCDA in the House of Commons.
Royal Assent
Bill C-8 receives Royal Assent (S.C. 2026, c. 9); Telecommunications Act amendments take effect.
Passes House of Commons
Report stage and third reading completed in the Commons after carry-over into the new session.
Mandatory data protection complaints procedure
Controllers must have a process for data subject complaints (s.103 and Sch. 10), per Commencement No. 6 Regulations 2026, reg. 3.
Delayed effective date (superseded)
SB 25B-004 date; superseded by SB 26-189 before it arrived, so no obligations applied.
A5328 sensitive data sale ban takes effect
A5328, signed June 30, 2026, prohibits selling sensitive personal data; the ban took effect on signing.
July 20266 deadlines
PA 25-113 (SB 1295) amendments take effect
Thresholds drop to 35,000 consumers or any sensitive-data processing or data sale; expanded sensitive data, minors' protections, and LLM-training disclosure in privacy notices.
Mandatory 30-day cure period expires
The Division's duty to issue a cure notice before enforcement ends on the first day of the 18th month after the effective date (N.J.S.A. 56:8-166.17(b)).
Ban on selling precise geolocation data (SB 338)
Controllers may not sell consumers' precise geolocation data (1,750-ft radius), replacing the prior consent-based treatment.
2026 APPI amendment act promulgated
Amendment enacted by the Diet on 10 July 2026 and promulgated; main provisions take effect by cabinet order within two years of promulgation.
August 20265 deadlines
Data brokers must begin processing DROP deletion requests
Brokers must access DROP at least every 45 days, process verified deletion requests within 45 days, and treat unverified requests as opt-outs of sale/sharing.
Profiling impact assessments apply
Impact assessment requirements apply to profiling activities created or generated on or after Aug 1, 2026 (Conn. Gen. Stat. 42-522 as amended).
Covered provider duties apply
Detection tool, manifest and latent disclosures, and license-revocation duties become operative.
- EU AI ActEuropean Union
General application: transparency obligations, GPAI fines, most other rules
The AI Act's general date of application. Article 50 transparency obligations (chatbot disclosure, deepfake labelling, machine-readable marking of synthetic content) and Commission fines on GPAI providers (Art 101) apply. Not deferred by the Omnibus.
- Digital Services ActEuropean Union
ChatGPT designated as VLOSE; Reddit and Roblox as VLOPs
Commission designated ChatGPT as a very large online search engine and Reddit and Roblox as very large online platforms. They have four months (by January 2027) to meet VLOP/VLOSE obligations.
September 20264 deadlines
- Cyber Resilience ActEuropean Union
Vulnerability and incident reporting obligations apply
Art 14: manufacturers must report actively exploited vulnerabilities and severe incidents (24-hour early warning, 72-hour notification) via the single reporting platform. Also covers products placed on the market before 11 Dec 2027 (Art 69(3)).
2026 PIPA amendments take effect
10%-of-revenue fines, CEO accountability, and notice duties for possible breaches apply.
- EU Data ActEuropean Union
Access-by-design for new connected products
Art 3(1) design obligation (product data and related service data accessible to the user by default) applies to connected products and related services placed on the market after 12 Sep 2026.
ICO abolished; Information Commission takes over
Sections 118-119 commence: office of Information Commissioner abolished and functions transferred to the Information Commission (Commencement No. 9 Regulations 2026).
October 20262 deadlines
PA 26-64 (SB 4) amendments take effect
Prohibits controllers and third parties from selling precise geolocation data and enacts data broker and other consumer protection provisions.
Lords report stage scheduled
House of Lords report stage scheduled (committee stage sat 1, 3 and 7 Sept 2026).
November 20262 deadlines
Consent Manager registration rule in force (12 months)
Rule 4 (registration and obligations of Consent Managers) comes into force one year after publication.
December 20266 deadlines
Law in force
Main obligations apply and the Personal Data Protection Agency begins supervision.
- EU AI ActEuropean Union
New bans on sexual deepfakes and CSAM generation; Art 50(2) grace period ends
New Art 5(1)(ba)/(bb) prohibitions on AI systems that generate non-consensual intimate imagery of identifiable persons or child sexual abuse material apply. Generative AI systems placed on the market before 2 Aug 2026 must comply with the Art 50(2) marking duty by this date (new Art 111(4)).
- Product Liability DirectiveEuropean Union
Transposition deadline; old PLD repealed
Member States must transpose by 9 Dec 2026 (Art 22). Directive 85/374/EEC is repealed from that date but still applies to products placed on the market before it (Art 21).
Children's Online Privacy Code must be registered
OAIC must develop and register the Children's Online Privacy Code within 24 months of Royal Assent.
Automated decision-making transparency applies
Privacy policies must disclose the kinds of personal information used in substantially automated decisions that significantly affect individuals (24 months after assent).
- eIDAS 2 / EU Digital Identity WalletEuropean Union
Member States must provide EU Digital Identity Wallets
Each Member State must provide at least one wallet within 24 months of the entry into force of the implementing acts under Arts 5a(23) and 5c(6) (Art 5a(1)).