Skip to content

2027 compliance deadlines

37 data, privacy, AI and cybersecurity deadlines fall in 2027, across 29 regulations.

January 202716 deadlines

  1. Large online platform and hosting platform duties

    Large online platforms and GenAI hosting platforms must meet the provenance duties added by AB 853.

    Compliance deadlinein 3 monthsSource
  2. First OES anonymized incident report and CDT definition review

    OES begins publishing annual anonymized incident summaries and the Department of Technology begins annual review of the act's definitions; the CalCompute framework report is due to the Legislature.

    Reportingin 3 monthsSource
  3. CCPA / CPRA

    ADMT requirements compliance date

    Businesses using ADMT for significant decisions must comply with Article 11 (pre-use notice, opt-out, access rights) by this date (11 CCR 7200(b)).

    Compliance deadlinein 3 monthsSource
  4. CCPA / CPRA

    Browsers must support opt-out preference signal (AB 566)

    Businesses that develop or maintain a browser must include consumer-configurable functionality to send an opt-out preference signal (Civ. Code 1798.136, operative Jan 1, 2027).

    Compliance deadlinein 3 monthsSource
  5. ADMT obligations apply

    Developer documentation, consumer notices, post-adverse-outcome disclosure, correction and human-review rights take effect.

    Takes effectin 3 monthsSource
  6. AG rules due

    Attorney General must adopt rules clarifying the post-adverse-outcome disclosure requirements.

    Compliance deadlinein 3 monthsSource
  7. Data broker registration required

    Data brokers may not sell or license brokered personal data in Connecticut unless registered with the Department of Consumer Protection ($2,500 initial fee).

    Compliance deadlinein 3 monthsSource
  8. Amended thresholds and third-party duties take effect

    Applicability drops to 10,000 consumers (or 5,000 + 20% revenue from sale) and new third-party duties (12D-107A) apply.

    Takes effectin 3 monthsSource
  9. Louisiana Data Privacy Act takes effect

    Consumer rights and controller duties apply (Act 502, Section 2); data protection assessment requirements apply to processing from this date.

    Takes effectin 3 monthsSource
  10. Ban on selling personal data of children under 13 (HB 1460)

    HB 1460 (2026, ch. 168) prohibits controllers from selling the personal data of a child under 13.

    Takes effectin 3 monthsSource
  11. NY RAISE Act

    RAISE Act takes effect

    Transparency reports, frontier AI frameworks, incident reporting and DFS disclosure filings apply.

    Takes effectin 3 monthsSource
  12. Oklahoma OKCDPA

    Oklahoma Consumer Data Privacy Act takes effect

    All OKCDPA obligations and consumer rights apply.

    Takes effectin 3 monthsSource
  13. UCPA extends to motor vehicle manufacturers

    Motor vehicle manufacturers whose vehicles are sold or leased in Utah and that collect personal data through vehicle data systems are covered regardless of the revenue and consumer thresholds (13-61-102, as amended by Laws 2026, ch. 193).

    Takes effectin 3 monthsSource
  14. EU Data Act

    Cloud switching charges abolished

    Providers of data processing services may no longer impose any switching charges on customers (Art 29(1)).

    Compliance deadlinein 4 monthsSource
  15. Implementing regulation GR 33/2026 takes effect

    Detailed PDP implementing rules (DPIA, cross-border, children's consent) apply, 6 months after the 16 Jul 2026 enactment.

    Compliance deadlinein 4 monthsSource
  16. Annual data broker registration deadline

    Data brokers must renew registration with CalPrivacy by January 31 following each year they meet the definition.

    Reportingin 4 monthsSource

March 20272 deadlines

  1. Transition ends for existing AI systems (general)

    Existing AI systems in most sectors must comply (12-month transition).

    Transitionin 5 monthsSource
  2. EHDS general application date

    The regulation applies generally from 26 Mar 2027, subject to the phased exceptions below (final article).

    Takes effectin 6 monthsSource

April 20273 deadlines

  1. Discretionary 60-day cure period ends

    The Division's discretionary notice-and-cure (at least 60 days) applies only to violations occurring on or before April 1, 2027 (Com. Law 14-4614).

    Enforcementin 6 monthsSource
  2. GDPR

    GDPR Procedural Regulation applies

    Harmonised rules for cross-border complaint admissibility, rights to be heard and access to preliminary findings, and investigation timelines apply to DPAs from 2 April 2027 (Regulation (EU) 2025/2518, final article).

    Enforcementin 6 monthsSource
  3. NIS2

    Next biennial entity notification

    Competent authorities notify the Commission and Cooperation Group of the number of essential and important entities, repeated every two years after 17 Apr 2025 (Art 3(5)).

    Reportingin 7 monthsSource

May 20272 deadlines

  1. APDPA takes effect

    Consumer rights and controller/processor obligations apply (HB 351 section 12).

    Takes effectin 7 monthsSource
  2. Main data fiduciary obligations apply (18 months)

    Rules 3, 5-16, 22 and 23 (notice, security safeguards, breach notification, retention, children's consent, SDF duties, cross-border) come into force 18 months after publication.

    Compliance deadlinein 8 monthsSource

July 20274 deadlines

  1. First annual report to Office of Suicide Prevention

    Operators begin annual reporting on crisis referrals and detection protocols.

    Reportingin 9 monthsSource
  2. South Korea PIPA

    Mandatory ISMS-P certification

    ISMS-P certification becomes mandatory for private entities meeting the statutory criteria.

    Compliance deadlinein 9 monthsSource
  3. Scheduled repeal of Title 13, Ch. 72

    SB 332 extends the AI Policy Act repeal date from May 1, 2025 to July 1, 2027.

    Sunsetin 9 monthsSource
  4. 30-day cure period expires

    AG's obligation to give 30-day notice and allow cure before investigating applies only from Jan 1 through July 31, 2027 (R.S. 51:1780.5(D)).

    Enforcementin 10 monthsSource

August 20271 deadline

  1. EU AI Act

    Legacy GPAI models must comply; national AI sandboxes operational

    Providers of GPAI models placed on the market before 2 Aug 2025 must comply (Art 111(3)). Each Member State must have at least one national AI regulatory sandbox operational (Art 57(1) as amended by the Omnibus).

    Compliance deadlinein 10 monthsSource

September 20272 deadlines

  1. Transition ends for existing AI systems in health, education and finance

    Existing AI systems in healthcare, education and finance must comply (18-month transition).

    Transitionin 11 monthsSource
  2. EU Data Act

    Unfair-terms rules extend to older long-term contracts

    Chapter IV (unfair contractual terms) applies to contracts concluded on or before 12 Sep 2025 that are of indefinite duration or expire at least 10 years from 11 Jan 2024 (Art 50).

    Compliance deadlinein 12 monthsSource

October 20271 deadline

  1. NIS2

    Commission review of NIS2

    Commission must review the functioning of NIS2 and report to Parliament and Council, then every 36 months (Art 40).

    Reportingin 13 monthsSource

November 20271 deadline

  1. CMMC 2.0

    Phase 3: Level 3 certification

    Phase 3 begins one year after Phase 2; Level 3 (DIBCAC) requirements added to applicable solicitations (32 CFR 170.3(e)(3)).

    Compliance deadlinein 14 monthsSource

December 20275 deadlines

  1. Proposed postponement of entry into force

    Government bill Boletin 18623-07 (filed 1 Sep 2026, 'suma' urgency) would replace the 24-month vacatio legis in transitional Art 1 with a fixed date of 1 Dec 2027; in first committee stage in the Senate, not law.

    Takes effectTentativein 14 monthsSource
  2. EU AI Act

    High-risk obligations apply to Annex III systems

    Chapter III Sections 1-3 (high-risk requirements and provider/deployer obligations) apply to AI systems classified high-risk under Art 6(2) and Annex III (employment, credit scoring, education, biometrics, essential services and similar). Deferred from 2 Aug 2026 by Regulation (EU) 2026/1744.

    Compliance deadlinein 14 monthsSource
  3. Cyber Resilience Act

    CRA fully applies

    All remaining obligations, including essential cybersecurity requirements, conformity assessment and CE marking, apply (Art 71(2)). Products placed on the market earlier are covered only if substantially modified (Art 69(2)).

    Compliance deadlinein 15 monthsSource
  4. Private relying parties must accept wallets

    Private relying parties required by law or contract to use strong user authentication must accept wallets on user request within 36 months of the implementing acts' entry into force (Art 5f(2)).

    Compliance deadlinein 15 monthsSource
  5. CCPA / CPRA

    Risk assessments for pre-existing processing due

    Risk assessments must be completed and documented for high-risk processing that began before Jan 1, 2026 and continues after (11 CCR 7155(b)).

    Compliance deadlinein 15 monthsSource

When the rules change: new data, privacy and AI laws and deadlines, the next morning.