2027 compliance deadlines
37 data, privacy, AI and cybersecurity deadlines fall in 2027, across 29 regulations.
Add to calendar
January 202716 deadlines
Large online platform and hosting platform duties
Large online platforms and GenAI hosting platforms must meet the provenance duties added by AB 853.
First OES anonymized incident report and CDT definition review
OES begins publishing annual anonymized incident summaries and the Department of Technology begins annual review of the act's definitions; the CalCompute framework report is due to the Legislature.
ADMT requirements compliance date
Businesses using ADMT for significant decisions must comply with Article 11 (pre-use notice, opt-out, access rights) by this date (11 CCR 7200(b)).
Browsers must support opt-out preference signal (AB 566)
Businesses that develop or maintain a browser must include consumer-configurable functionality to send an opt-out preference signal (Civ. Code 1798.136, operative Jan 1, 2027).
ADMT obligations apply
Developer documentation, consumer notices, post-adverse-outcome disclosure, correction and human-review rights take effect.
AG rules due
Attorney General must adopt rules clarifying the post-adverse-outcome disclosure requirements.
Data broker registration required
Data brokers may not sell or license brokered personal data in Connecticut unless registered with the Department of Consumer Protection ($2,500 initial fee).
Amended thresholds and third-party duties take effect
Applicability drops to 10,000 consumers (or 5,000 + 20% revenue from sale) and new third-party duties (12D-107A) apply.
- Louisiana Data Privacy ActLouisiana
Louisiana Data Privacy Act takes effect
Consumer rights and controller duties apply (Act 502, Section 2); data protection assessment requirements apply to processing from this date.
- New Hampshire Privacy ActNew Hampshire
Ban on selling personal data of children under 13 (HB 1460)
HB 1460 (2026, ch. 168) prohibits controllers from selling the personal data of a child under 13.
RAISE Act takes effect
Transparency reports, frontier AI frameworks, incident reporting and DFS disclosure filings apply.
- Oklahoma OKCDPAOklahoma
Oklahoma Consumer Data Privacy Act takes effect
All OKCDPA obligations and consumer rights apply.
UCPA extends to motor vehicle manufacturers
Motor vehicle manufacturers whose vehicles are sold or leased in Utah and that collect personal data through vehicle data systems are covered regardless of the revenue and consumer thresholds (13-61-102, as amended by Laws 2026, ch. 193).
- EU Data ActEuropean Union
Cloud switching charges abolished
Providers of data processing services may no longer impose any switching charges on customers (Art 29(1)).
Implementing regulation GR 33/2026 takes effect
Detailed PDP implementing rules (DPIA, cross-border, children's consent) apply, 6 months after the 16 Jul 2026 enactment.
Annual data broker registration deadline
Data brokers must renew registration with CalPrivacy by January 31 following each year they meet the definition.
March 20272 deadlines
Transition ends for existing AI systems (general)
Existing AI systems in most sectors must comply (12-month transition).
- European Health Data Space (EHDS)European Union
EHDS general application date
The regulation applies generally from 26 Mar 2027, subject to the phased exceptions below (final article).
April 20273 deadlines
Discretionary 60-day cure period ends
The Division's discretionary notice-and-cure (at least 60 days) applies only to violations occurring on or before April 1, 2027 (Com. Law 14-4614).
May 20272 deadlines
APDPA takes effect
Consumer rights and controller/processor obligations apply (HB 351 section 12).
Main data fiduciary obligations apply (18 months)
Rules 3, 5-16, 22 and 23 (notice, security safeguards, breach notification, retention, children's consent, SDF duties, cross-border) come into force 18 months after publication.
July 20274 deadlines
First annual report to Office of Suicide Prevention
Operators begin annual reporting on crisis referrals and detection protocols.
Mandatory ISMS-P certification
ISMS-P certification becomes mandatory for private entities meeting the statutory criteria.
Scheduled repeal of Title 13, Ch. 72
SB 332 extends the AI Policy Act repeal date from May 1, 2025 to July 1, 2027.
- Louisiana Data Privacy ActLouisiana
30-day cure period expires
AG's obligation to give 30-day notice and allow cure before investigating applies only from Jan 1 through July 31, 2027 (R.S. 51:1780.5(D)).
August 20271 deadline
- EU AI ActEuropean Union
Legacy GPAI models must comply; national AI sandboxes operational
Providers of GPAI models placed on the market before 2 Aug 2025 must comply (Art 111(3)). Each Member State must have at least one national AI regulatory sandbox operational (Art 57(1) as amended by the Omnibus).
September 20272 deadlines
Transition ends for existing AI systems in health, education and finance
Existing AI systems in healthcare, education and finance must comply (18-month transition).
- EU Data ActEuropean Union
Unfair-terms rules extend to older long-term contracts
Chapter IV (unfair contractual terms) applies to contracts concluded on or before 12 Sep 2025 that are of indefinite duration or expire at least 10 years from 11 Jan 2024 (Art 50).
October 20271 deadline
November 20271 deadline
December 20275 deadlines
Proposed postponement of entry into force
Government bill Boletin 18623-07 (filed 1 Sep 2026, 'suma' urgency) would replace the 24-month vacatio legis in transitional Art 1 with a fixed date of 1 Dec 2027; in first committee stage in the Senate, not law.
- EU AI ActEuropean Union
High-risk obligations apply to Annex III systems
Chapter III Sections 1-3 (high-risk requirements and provider/deployer obligations) apply to AI systems classified high-risk under Art 6(2) and Annex III (employment, credit scoring, education, biometrics, essential services and similar). Deferred from 2 Aug 2026 by Regulation (EU) 2026/1744.
- Cyber Resilience ActEuropean Union
CRA fully applies
All remaining obligations, including essential cybersecurity requirements, conformity assessment and CE marking, apply (Art 71(2)). Products placed on the market earlier are covered only if substantially modified (Art 69(2)).
- eIDAS 2 / EU Digital Identity WalletEuropean Union
Private relying parties must accept wallets
Private relying parties required by law or contract to use strong user authentication must accept wallets on user request within 36 months of the implementing acts' entry into force (Art 5f(2)).
Risk assessments for pre-existing processing due
Risk assessments must be completed and documented for high-risk processing that began before Jan 1, 2026 and continues after (11 CCR 7155(b)).