Skip to content

2030 compliance deadlines

5 data, privacy, AI and cybersecurity deadlines fall in 2030, across 4 regulations.

January 20301 deadline

  1. Mandatory cure period ends

    The AG's obligation to offer a 60-day notice-and-cure period expires.

    Sunsetin 3.3 yearsSource

April 20301 deadline

  1. CCPA / CPRA

    Cybersecurity audit due: revenue under $50M

    First cybersecurity audit report (covering 2029) due for covered businesses with 2028 annual gross revenue under $50M (11 CCR 7121(a)(3)); annual by April 1 thereafter.

    Reportingin 3.5 yearsSource

August 20301 deadline

  1. EU AI Act

    Public-authority high-risk systems must comply

    Providers and deployers of high-risk AI systems intended for use by public authorities that were placed on the market before the Chapter III application date must comply (Art 111(2), as replaced by the Omnibus).

    Compliance deadlinein 3.9 yearsSource

December 20302 deadlines

  1. Cyber Resilience Act

    First CRA evaluation

    Commission evaluation and review report, then every four years (Art 70(1)).

    Reportingin 4.2 yearsSource
  2. EU AI Act

    Large-scale EU IT systems must comply

    AI systems that are components of the large-scale IT systems in Annex X (e.g. SIS, VIS, Eurodac, EES, ETIAS) placed on the market before 2 Aug 2027 must be brought into compliance (Art 111(1)).

    Compliance deadlinein 4.3 yearsSource

When the rules change: new data, privacy and AI laws and deadlines, the next morning.