{"regulations":[{"id":"us-eo-14365-ai-preemption","name":"Executive Order 14365: Ensuring a National Policy Framework for Artificial Intelligence","shortName":"AI state-law preemption EO","jurisdiction":"us","jurisdictionName":"United States","region":"us-federal","topics":["ai"],"status":"in_force","citation":"Executive Order 14365, 90 FR 58499","enactedDate":"2025-12-11","effectiveDate":"2025-12-11","summary":"Directs federal agencies to push back on state AI laws seen as onerous. It orders a DOJ AI Litigation Task Force, a Commerce list of conflicting state laws, BEAD and grant funding conditions, an FCC disclosure-standard proceeding and an FTC policy statement on AI outputs. It does not itself preempt any state law; that needs Congress or court rulings.","appliesTo":"Federal agencies. Indirectly affects states with AI laws (for example Colorado) and companies subject to them.","penalties":"None directly. Tools are litigation and conditions on federal funding.","enforcer":"DOJ, Department of Commerce (NTIA), FCC, FTC","sourceUrl":"https://www.federalregister.gov/documents/2025/12/16/2025-23092/ensuring-a-national-policy-framework-for-artificial-intelligence","extraSources":["https://www.federalregister.gov/documents/2026/07/07/2026-13628/policy-statement-concerning-the-suppression-of-accuracy-in-artificial-intelligence-systems"],"notes":"The FCC proceeding is due within 90 days after Commerce publishes its evaluation; that publication date was not confirmed from an official source, so no FCC date is listed. Carve-outs in the legislative recommendation cover child safety, data center infrastructure and state procurement.","lastVerified":"2026-09-25","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-25 10:55:47","sourceType":"official","verifiedBy":"research from official sources (2026-09-25)","deadlines":[{"id":6892,"regulationId":"us-eo-14365-ai-preemption","date":"2025-12-16","title":"EO published in Federal Register","description":"Signed 2025-12-11 and published at 90 FR 58499.","kind":"effective","sourceUrl":"https://www.federalregister.gov/documents/2025/12/16/2025-23092/ensuring-a-national-policy-framework-for-artificial-intelligence","tentative":false,"review":"verified"},{"id":6893,"regulationId":"us-eo-14365-ai-preemption","date":"2026-01-10","title":"AI Litigation Task Force due","description":"Attorney General to set up a task force to challenge state AI laws within 30 days of the order (date computed from signing).","kind":"compliance","sourceUrl":"https://www.federalregister.gov/documents/2025/12/16/2025-23092/ensuring-a-national-policy-framework-for-artificial-intelligence","tentative":false,"review":"verified"},{"id":6894,"regulationId":"us-eo-14365-ai-preemption","date":"2026-03-11","title":"Commerce state-law evaluation, BEAD notice and FTC statement due","description":"Within 90 days of the order: Commerce publishes its list of onerous state AI laws, NTIA issues the BEAD policy notice, and the FTC issues a policy statement (date computed from signing).","kind":"compliance","sourceUrl":"https://www.federalregister.gov/documents/2025/12/16/2025-23092/ensuring-a-national-policy-framework-for-artificial-intelligence","tentative":false,"review":"verified"},{"id":6895,"regulationId":"us-eo-14365-ai-preemption","date":"2026-07-07","title":"FTC proposes AI accuracy policy statement","description":"FTC publishes a proposed policy statement on deceptive suppression of accuracy in AI systems (91 FR 41638), linked to Section 7 of the EO.","kind":"transition","sourceUrl":"https://www.federalregister.gov/documents/2026/07/07/2026-13628/policy-statement-concerning-the-suppression-of-accuracy-in-artificial-intelligence-systems","tentative":false,"review":"verified"},{"id":6896,"regulationId":"us-eo-14365-ai-preemption","date":"2026-07-31","title":"FTC policy statement comments close","description":"Comment deadline on the proposed FTC AI policy statement.","kind":"reporting","sourceUrl":"https://www.federalregister.gov/documents/2026/07/07/2026-13628/policy-statement-concerning-the-suppression-of-accuracy-in-artificial-intelligence-systems","tentative":false,"review":"verified"}]},{"id":"us-al-apdpa","name":"Alabama Personal Data Protection Act (HB 351, 2026 Regular Session)","shortName":"Alabama Personal Data Protection Act (APDPA)","jurisdiction":"us-al","jurisdictionName":"Alabama","region":"us-states","topics":["privacy"],"status":"enacted","citation":"HB 351 (2026 RS), Act 2026-552","enactedDate":"2026-04-17","effectiveDate":"2027-05-01","summary":"Alabama's comprehensive privacy law, enacted April 2026, grants rights to confirm, correct, delete, port and opt out of targeted advertising, sale and profiling. Unusually, it does not require data protection assessments, generally excludes analytics and certain marketing disclosures from 'sale', and broadly exempts small businesses that don't sell data.","appliesTo":"Persons doing business in Alabama or targeting residents that control or process personal data of more than 25,000 consumers (excluding payment-only data), or derive more than 25% of gross revenue from the sale of personal data regardless of volume. Exempts businesses with fewer than 500 employees and nonprofits with fewer than 100 employees that do not sell personal data.","penalties":"Civil penalty up to $15,000 per violation, only after the controller fails to correct within the permanent 45-day notice-and-cure period; injunctive relief. No private right of action.","enforcer":"Alabama Attorney General (exclusive)","sourceUrl":"https://alison.legislature.state.al.us/files/pdf/SearchableInstruments/2026RS/HB351-enr.pdf","extraSources":["https://www.wilmerhale.com/en/insights/blogs/wilmerhale-privacy-and-cybersecurity-law/20260422-alabama-enacts-nations-twenty-first-state-comprehensive-privacy-law","https://www.venable.com/insights/publications/2026/07/2026-mid-year-state-privacy-law-update"],"notes":"Fact-check 2026-09-22: the official ALISON record lists HB 351 as Act 2026-552, delivered to the Governor 8 Apr 2026 and 'Enacted' 17 Apr 2026; enacted_date uses the official 17 Apr 2026 date (WilmerHale and Privacy Daily reported signing on 16 Apr 2026). Enrolled text Section 12: effective 1 May 2027. The 45-day cure period is permanent, so no cure-expiry deadline.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-22 20:04:22","sourceType":"official","verifiedBy":"research from official sources","deadlines":[{"id":161,"regulationId":"us-al-apdpa","date":"2027-05-01","title":"APDPA takes effect","description":"Consumer rights and controller/processor obligations apply (HB 351 section 12).","kind":"effective","sourceUrl":"https://alison.legislature.state.al.us/files/pdf/SearchableInstruments/2026RS/HB351-enr.pdf","tentative":false,"review":"verified"}]},{"id":"ca-ab-popa","name":"Protection of Privacy Act","shortName":"Alberta POPA","jurisdiction":"ca-ab","jurisdictionName":"Alberta, Canada","region":"americas","topics":["privacy","breach-notification","ai"],"status":"in_force","citation":"SA 2024, c P-28.5","enactedDate":"","effectiveDate":"2025-06-11","summary":"Replaces the privacy part of Alberta's FOIP Act for public bodies. It adds mandatory breach notification where there is a real risk of significant harm, privacy management programs, privacy impact assessments, rules for creating and using non-personal data, and notice when personal information will be fed into automated systems. It also bans selling personal information and adds large offence fines.","appliesTo":"Alberta public bodies (ministries, agencies, municipalities, school boards, post-secondary and health bodies covered by the Act). Private sector stays under PIPA.","penalties":"Offence fines up to $125,000 for individuals and $750,000 for other persons, and up to $200,000 and $1,000,000 for the most serious contraventions (s. 57).","enforcer":"Information and Privacy Commissioner of Alberta","sourceUrl":"https://kings-printer.alberta.ca/1266.cfm?page=p28p5.cfm&leg_type=Acts&isbncln=9780779861309&display=html","extraSources":["https://www.alberta.ca/protection-of-privacy-act","https://open.alberta.ca/publications/p28p5"],"notes":"Assent date not confirmed on an official page, so enacted_date is left blank. Alberta PIPA (private sector) reform was not confirmed as enacted and is not included.","lastVerified":"2026-09-25","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-25 10:55:47","sourceType":"official","verifiedBy":"research from official sources (2026-09-25)","deadlines":[{"id":6946,"regulationId":"ca-ab-popa","date":"2025-06-11","title":"POPA in force","description":"Act comes into force with the Access to Information Act, proclaimed in force June 11, 2025.","kind":"effective","sourceUrl":"https://kings-printer.alberta.ca/1266.cfm?page=p28p5.cfm&leg_type=Acts&isbncln=9780779861309&display=html","tentative":false,"review":"verified"},{"id":6947,"regulationId":"ca-ab-popa","date":"2026-06-11","title":"Privacy management programs required","description":"Public bodies must establish and implement a privacy management program one year after the section comes into force (s. 25(5)).","kind":"compliance","sourceUrl":"https://kings-printer.alberta.ca/1266.cfm?page=p28p5.cfm&leg_type=Acts&isbncln=9780779861309&display=html","tentative":false,"review":"verified"}]},{"id":"ar-pdpl","name":"Ley 25.326 de Protección de los Datos Personales","shortName":"Argentina Law 25.326","jurisdiction":"ar","jurisdictionName":"Argentina","region":"americas","topics":["privacy","data-residency"],"status":"in_force","citation":"Ley 25.326","enactedDate":"2000-10-04","effectiveDate":"","summary":"Argentina's habeas data and personal data protection law. It covers consent, data quality, sensitive data, security and confidentiality, international transfers to countries with adequate protection, and access, rectification and deletion rights. Argentina holds EU adequacy status based on this law.","appliesTo":"Public and private files, registers, databases and data banks holding personal data in Argentina.","penalties":"Warning, suspension, fines of ARS 1,000 to ARS 100,000 in the statute (updated by later regulation), and closure or cancellation of the database; criminal penalties under Art. 32.","enforcer":"Agencia de Acceso a la Información Pública (AAIP)","sourceUrl":"https://servicios.infoleg.gob.ar/infolegInternet/anexos/60000-64999/64790/norma.htm","extraSources":["https://servicios.infoleg.gob.ar/infolegInternet/verNorma.do?id=64790"],"notes":"Partially promulgated on 2000-10-30. Several reform bills to modernize the law have been introduced but none confirmed as enacted. Effective date not stated in the law; left blank.","lastVerified":"2026-09-25","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-25 10:55:47","sourceType":"official","verifiedBy":"research from official sources (2026-09-25)","deadlines":[{"id":6948,"regulationId":"ar-pdpl","date":"2000-10-04","title":"Law sanctioned","description":"Congress sanctions Law 25.326.","kind":"effective","sourceUrl":"https://servicios.infoleg.gob.ar/infolegInternet/anexos/60000-64999/64790/norma.htm","tentative":false,"review":"verified"},{"id":6949,"regulationId":"ar-pdpl","date":"2000-11-02","title":"Published in Boletín Oficial","description":"Published in Boletín Oficial No. 29517.","kind":"effective","sourceUrl":"https://servicios.infoleg.gob.ar/infolegInternet/verNorma.do?id=64790","tentative":false,"review":"verified"}]},{"id":"us-ar-cttoppa","name":"Arkansas Children and Teens' Online Privacy Protection Act (Act 952 of 2025, HB 1717)","shortName":"Arkansas COPPA 2.0","jurisdiction":"us-ar","jurisdictionName":"Arkansas","region":"us-states","topics":["children","privacy"],"status":"in_force","citation":"2025 Ark. Acts 952; Ark. Code section 4-88-1501 et seq.","enactedDate":"2025-04-21","effectiveDate":"2026-07-01","summary":"State COPPA-style law that extends protections to teens. Operators of sites and apps directed to children or teens, or with knowledge of their age, face limits on collecting and using their personal information and on targeted advertising.","appliesTo":"Operators of websites, online services and apps directed to, or with knowledge of, Arkansas children and teens.","penalties":"Unfair or deceptive practice under the Arkansas Deceptive Trade Practices Act; AG civil actions for injunctions and relief.","enforcer":"Arkansas Attorney General","sourceUrl":"https://arkleg.state.ar.us/Bills/Detail?id=HB1717&ddBienniumSession=2025%2F2025R","extraSources":["https://arkleg.state.ar.us/Acts/FTPDocument?path=%2FACTS%2F2025R%2FPublic%2F&file=952.pdf&ddBienniumSession=2025%2F2025R"],"notes":"Exact age range and thresholds should be checked against the act text.","lastVerified":"2026-09-25","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-25 10:55:47","sourceType":"official","verifiedBy":"research from official sources (2026-09-25)","deadlines":[{"id":6941,"regulationId":"us-ar-cttoppa","date":"2025-04-21","title":"Approved by Governor","description":"Became Act 952.","kind":"transition","sourceUrl":"https://arkleg.state.ar.us/Bills/Detail?id=HB1717&ddBienniumSession=2025%2F2025R","tentative":false,"review":"verified"},{"id":6942,"regulationId":"us-ar-cttoppa","date":"2026-07-01","title":"Takes effect","description":"Section 3: effective on and after July 1, 2026.","kind":"effective","sourceUrl":"https://arkleg.state.ar.us/Bills/Detail?id=HB1717&ddBienniumSession=2025%2F2025R","tentative":false,"review":"verified"}]},{"id":"au-cyber-security-act","name":"Cyber Security Act 2024 (Cth) and Cyber Security (Ransomware Payment Reporting) Rules 2025","shortName":"Australia Cyber Security Act (ransomware reporting)","jurisdiction":"au","jurisdictionName":"Australia","region":"apac","topics":["cybersecurity","breach-notification"],"status":"in_force","citation":"Act No. 98, 2024","enactedDate":"2024-11-29","effectiveDate":"2024-11-30","summary":"Australia's first standalone cyber law: mandatory reporting of ransomware or cyber-extortion payments within 72 hours, security standards for consumer smart devices, 'limited use' protections for information shared with ASD and the National Cyber Security Coordinator, and a Cyber Incident Review Board. Ransomware payment reporting has applied since 30 May 2025.","appliesTo":"Ransomware reporting: entities carrying on business in Australia with annual turnover above AUD 3 million in the previous financial year (pro-rated for part years), plus responsible entities for critical infrastructure assets regardless of turnover, that make or have a ransomware payment made on their behalf.","penalties":"Failure to report a ransomware payment: civil penalty of 60 penalty units (AUD 19,800 at the rate cited by commentators).","enforcer":"Department of Home Affairs; reports go to the Australian Signals Directorate (ASD)","sourceUrl":"https://www.legislation.gov.au/C2024A00098/asmade","extraSources":["https://www.homeaffairs.gov.au/cyber-security-subsite/files/factsheet-ransomware-payment-reporting.pdf"],"notes":"Royal Assent was 29 Nov 2024 (from secondary sources); Part 1 commenced the next day. Commencement dates for the smart-device security standards were not verified here. Penalty unit values are indexed, and the AUD 19,800 figure uses the rate at commencement.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-22 20:04:22","sourceType":"official","verifiedBy":"research from official sources","deadlines":[{"id":2,"regulationId":"au-cyber-security-act","date":"2025-05-30","title":"Ransomware payment reporting starts","description":"Reporting business entities must report ransomware/cyber-extortion payments to ASD within 72 hours of payment.","kind":"effective","sourceUrl":"https://www.homeaffairs.gov.au/cyber-security-subsite/files/factsheet-ransomware-payment-reporting.pdf","tentative":false,"review":"verified"},{"id":3,"regulationId":"au-cyber-security-act","date":"2026-01-01","title":"Ransomware reporting moves to compliance phase","description":"The education-first phase (30 May-31 Dec 2025) ends; Home Affairs moves to a compliance and education approach for missed reports.","kind":"enforcement","sourceUrl":"https://www.homeaffairs.gov.au/cyber-security-subsite/files/factsheet-ransomware-payment-reporting.pdf","tentative":false,"review":"verified"},{"id":7043,"regulationId":"au-cyber-security-act","date":"2026-03-04","title":"Smart device security standard applies","description":"Part 2 and Schedule 1 of the Cyber Security (Security Standards for Smart Devices) Rules 2025 commence. Manufacturers and suppliers of relevant connectable products must meet the security standard.","kind":"compliance","sourceUrl":"https://www.legislation.gov.au/F2025L00276/asmade","tentative":false,"review":"verified"}]},{"id":"au-online-safety-act","name":"Online Safety Act 2021","shortName":"Australia Online Safety Act","jurisdiction":"au","jurisdictionName":"Australia","region":"apac","topics":["online-safety","children"],"status":"amended","citation":"Act No. 76, 2021","enactedDate":"2021-07-23","effectiveDate":"2022-01-23","summary":"Sets up the eSafety Commissioner and removal schemes for cyber-bullying of children, adult cyber-abuse, non-consensual intimate images and abhorrent violent material. It also sets Basic Online Safety Expectations with reporting duties, and binding industry codes and standards. The Unlawful Material codes and standards cover class 1A and 1B material such as child sexual exploitation and pro-terror content. The Age-Restricted Material codes cover class 1C and class 2 material such as online pornography, and require age assurance and other measures to protect children.","appliesTo":"Social media services, relevant electronic services (messaging, email, gaming), designated internet services (websites and apps), search engines, app stores, hosting services, internet carriage services and equipment providers that serve Australian end-users.","penalties":"Most civil penalty provisions carry up to 500 penalty units for individuals, with higher amounts for bodies corporate. The social media minimum age provisions carry far higher penalties (see au-social-media-min-age). eSafety can issue formal warnings, infringement notices and directions to comply with codes.","enforcer":"eSafety Commissioner","sourceUrl":"https://www.legislation.gov.au/C2021A00076/asmade","extraSources":["https://www.legislation.gov.au/C2021A00076/asmade/2021-07-23/text/original/pdf","https://www.esafety.gov.au/industry/codes/register-online-industry-codes-standards","https://www.esafety.gov.au/industry/codes","https://www.legislation.gov.au/F2024L00711/asmade","https://www.legislation.gov.au/F2024L00710/asmade"],"notes":"Assented 2021-07-23. The register says some Age-Restricted Material Code measures start later than the headline dates; those later dates are not listed here. In September 2026 eSafety updated its regulatory guidance after a Federal Court judgment ([2026] FCA 1123) on which Unlawful Material Standard or Code applies.","lastVerified":"2026-09-25","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-25 11:14:17","sourceType":"official","verifiedBy":"research from official sources (2026-09-25)","deadlines":[{"id":7023,"regulationId":"au-online-safety-act","date":"2022-01-23","title":"Online Safety Act commences","description":"The whole Act commences by Proclamation.","kind":"effective","sourceUrl":"https://www.legislation.gov.au/C2021A00076/asmade","tentative":false,"review":"verified"}]},{"id":"au-privacy-act","name":"Privacy Act 1988 (Cth), as amended by the Privacy and Other Legislation Amendment Act 2024","shortName":"Australia Privacy Act","jurisdiction":"au","jurisdictionName":"Australia","region":"apac","topics":["privacy","children","breach-notification","ai"],"status":"amended","citation":"Privacy Act 1988 (Cth); Privacy and Other Legislation Amendment Act 2024 (No. 128, 2024)","enactedDate":"2024-12-10","effectiveDate":"2024-12-11","summary":"Australia's federal privacy law (13 Australian Privacy Principles, Notifiable Data Breaches scheme). The 2024 amendment adds a statutory tort for serious invasions of privacy, tiered civil penalties and infringement notices, a mandate for a Children's Online Privacy Code, clearer security duties, and privacy-policy transparency for substantially automated decisions from 10 December 2026. It also adds criminal doxxing offences.","appliesTo":"APP entities: Australian Government agencies and organizations with annual turnover above AUD 3 million, plus some smaller businesses (e.g. health service providers, data traders). The statutory tort applies to anyone, not only APP entities. The Children's Online Privacy Code will cover social media, relevant electronic and designated internet services likely to be accessed by children.","penalties":"Serious interference with privacy: for bodies corporate, the greater of AUD 50 million, 3x the benefit obtained, or 30% of adjusted turnover. New mid-tier civil penalty for interferences with privacy (up to AUD 3.3 million for bodies corporate) and infringement notices for administrative breaches. Statutory tort: court-awarded damages, with a cap on damages for non-economic loss.","enforcer":"Office of the Australian Information Commissioner (OAIC); courts (statutory tort)","sourceUrl":"https://www.legislation.gov.au/C2024A00128/asmade","extraSources":["https://www.oaic.gov.au/privacy/privacy-registers/privacy-codes/childrens-online-privacy-code","https://www.legislation.gov.au/C2024A00128/asmade/2024-12-10/text/original/pdf","https://ministers.ag.gov.au/media-centre/draft-childrens-online-privacy-code-released-31-03-2026"],"notes":"The OAIC released an exposure draft Privacy (Children's Online Privacy) Code 2026 for consultation from 31 Mar to 5 Jun 2026; it was not registered as of Aug 2026, and its commencement date for regulated entities is not yet set. 'Tranche 2' reforms (e.g. removing the small business exemption, a fair and reasonable test) are not yet legislated. The mid-tier and tort cap figures come from the Act and secondary summaries; check against the current indexed penalty unit value.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-22 20:04:22","sourceType":"official","verifiedBy":"research from official sources","deadlines":[{"id":4,"regulationId":"au-privacy-act","date":"2024-12-11","title":"Most POLA Act 2024 amendments commence","description":"Tiered penalties, infringement notices, OAIC powers, security and overseas-transfer clarifications and doxxing offences commence the day after Royal Assent.","kind":"effective","sourceUrl":"https://www.legislation.gov.au/C2024A00128/asmade","tentative":false,"review":"verified"},{"id":5,"regulationId":"au-privacy-act","date":"2025-06-10","title":"Statutory tort for serious invasions of privacy commences","description":"Individuals can sue for serious invasions of privacy (Schedule 2), 6 months after Royal Assent.","kind":"effective","sourceUrl":"https://www.legislation.gov.au/C2024A00128/asmade","tentative":false,"review":"verified"},{"id":6,"regulationId":"au-privacy-act","date":"2026-12-10","title":"Children's Online Privacy Code must be registered","description":"OAIC must develop and register the Children's Online Privacy Code within 24 months of Royal Assent.","kind":"compliance","sourceUrl":"https://www.oaic.gov.au/privacy/privacy-registers/privacy-codes/childrens-online-privacy-code","tentative":false,"review":"verified"},{"id":7,"regulationId":"au-privacy-act","date":"2026-12-10","title":"Automated decision-making transparency applies","description":"Privacy policies must disclose the kinds of personal information used in substantially automated decisions that significantly affect individuals (24 months after assent).","kind":"compliance","sourceUrl":"https://www.legislation.gov.au/C2024A00128/asmade","tentative":false,"review":"verified"}]},{"id":"au-soci-act","name":"Security of Critical Infrastructure Act 2018","shortName":"Australia SOCI Act","jurisdiction":"au","jurisdictionName":"Australia","region":"apac","topics":["cybersecurity","breach-notification"],"status":"amended","citation":"Act No. 29, 2018; amended by Acts of 2021, 2022 and 2024","enactedDate":"2018-04-11","effectiveDate":"2018-07-11","summary":"Australia's critical infrastructure security law. Owners and operators of critical infrastructure assets must register ownership and operational information, and many must report cyber security incidents to the Australian Signals Directorate. Responsible entities for many asset classes must also keep a critical infrastructure risk management program. Systems of national significance face enhanced cyber security obligations, and the government has step-in and assistance powers.","appliesTo":"Responsible entities and direct interest holders for critical infrastructure assets across 11 sectors, including energy, water, communications, data storage and processing, financial services, health, transport and food.","penalties":"Civil penalties for failing to register, report incidents or keep a risk management program. Amounts are set in penalty units in the Act and are not captured here.","enforcer":"Department of Home Affairs (Cyber and Infrastructure Security Centre); Australian Signals Directorate receives incident reports","sourceUrl":"https://www.legislation.gov.au/C2018A00029/asmade","extraSources":["https://www.legislation.gov.au/C2021A00124/asmade","https://www.legislation.gov.au/C2022A00033/asmade","https://www.legislation.gov.au/C2024A00100/asmade","https://www.legislation.gov.au/F2022L00562/asmade"],"notes":"The 2021 (SLACI), 2022 (SLACIP) and 2024 (Enhanced Response and Prevention) amending Acts are on the Federal Register. The incident reporting start date is calculated, not stated, so it is marked tentative. Risk management program dates are not captured here.","lastVerified":"2026-09-25","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-25 11:14:17","sourceType":"official","verifiedBy":"research from official sources (2026-09-25)","deadlines":[{"id":7024,"regulationId":"au-soci-act","date":"2018-07-11","title":"SOCI Act commences","description":"The whole Act commences by Proclamation.","kind":"effective","sourceUrl":"https://www.legislation.gov.au/C2018A00029/asmade","tentative":false,"review":"verified"},{"id":7025,"regulationId":"au-soci-act","date":"2022-07-08","title":"Mandatory cyber incident reporting starts for most assets","description":"The Application Rules registered on 7 April 2022 gave most asset classes a 3-month grace period before Part 2B incident reporting applied. The date is worked out from that grace period.","kind":"compliance","sourceUrl":"https://www.legislation.gov.au/F2022L00562/asmade","tentative":true,"review":"verified"}]},{"id":"au-social-media-min-age","name":"Online Safety Amendment (Social Media Minimum Age) Act 2024","shortName":"Australia Social Media Minimum Age","jurisdiction":"au","jurisdictionName":"Australia","region":"apac","topics":["children","online-safety"],"status":"in_force","citation":"Act No. 127, 2024 (amending the Online Safety Act 2021)","enactedDate":"2024-12-10","effectiveDate":"2025-12-10","summary":"Requires providers of age-restricted social media platforms to take reasonable steps to stop Australians under 16 from having accounts. Platforms may not rely only on government ID for age assurance, and must protect data collected for age checks and destroy it after use. eSafety has named platforms including Facebook, Instagram, Snapchat, TikTok, X, YouTube, Reddit, Threads, Twitch and Kick.","appliesTo":"Providers of 'age-restricted social media platforms' (services whose significant purpose is online social interaction, allowing users to link and post), subject to exclusions (e.g. messaging, gaming, education and health services).","penalties":"Up to 150,000 penalty units (AUD 49.5 million) for corporations failing to take reasonable steps. Separate penalties apply for misusing age-assurance data under the Privacy Act.","enforcer":"eSafety Commissioner (minimum age obligation); OAIC (privacy of age-assurance data)","sourceUrl":"https://www.legislation.gov.au/C2024A00127/asmade","extraSources":["https://www.esafety.gov.au/about-us/industry-regulation/social-media-age-restrictions","https://www.pm.gov.au/media/stronger-powers-and-double-penalties-world-leading-social-media-law"],"notes":"On 28 June 2026 the Government announced legislation to double the maximum penalty for systemic breaches to AUD 99 million and give eSafety stronger information-gathering powers; it is not yet enacted as of verification. eSafety is investigating five platforms.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-22 20:04:22","sourceType":"official","verifiedBy":"research from official sources","deadlines":[{"id":8,"regulationId":"au-social-media-min-age","date":"2025-12-10","title":"Social media minimum age obligation applies","description":"Age-restricted platforms must take reasonable steps to prevent under-16s from holding accounts.","kind":"effective","sourceUrl":"https://www.legislation.gov.au/C2024A00127/asmade","tentative":false,"review":"verified"},{"id":7044,"regulationId":"au-social-media-min-age","date":"2026-09-12","title":"Strengthened enforcement amendments commence","description":"The Online Safety Amendment (Strengthening Enforcement for the Social Media Minimum Age) Act 2026 (No. 83, 2026) commences. The maximum civil penalty for platforms doubles from 30,000 to 60,000 penalty units, and eSafety gains new information-gathering powers.","kind":"enforcement","sourceUrl":"https://www.legislation.gov.au/C2026A00083/asmade","tentative":false,"review":"verified"}]},{"id":"bh-pdpl","name":"Law No. 30 of 2018 on the Protection of Personal Data","shortName":"Bahrain PDPL","jurisdiction":"bh","jurisdictionName":"Bahrain","region":"mea","topics":["privacy"],"status":"in_force","citation":"Law No. (30) of 2018","enactedDate":"2018-07-12","effectiveDate":"2019-08-01","summary":"Bahrain's general data protection law. It sets lawful bases for processing, stricter rules for sensitive data, individual rights, transfer limits and registration duties, and creates the Personal Data Protection Authority. It carries both administrative and criminal penalties.","appliesTo":"Individuals and entities that process personal data in Bahrain, and those outside Bahrain that process data using means in Bahrain.","penalties":"Administrative fines up to BHD 20,000 and daily fines up to BHD 1,000 (BHD 2,000 for repeats). Criminal penalties of up to one year in prison and fines of BHD 1,000 to 20,000 for offences such as unlawful sensitive data processing or unlawful transfers (Art. 58).","enforcer":"Personal Data Protection Authority (Art. 27)","sourceUrl":"https://www.lloc.gov.bh/Legislation/HTM/K3018","extraSources":[],"notes":"Issue date 12 July 2018 is on the LLOC text. The Gazette publication date is not shown on that page; 2019-08-01 assumes publication in July 2018, so the deadline is marked tentative.","lastVerified":"2026-09-25","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-25 11:14:17","sourceType":"official","verifiedBy":"research from official sources (2026-09-25)","deadlines":[{"id":7030,"regulationId":"bh-pdpl","date":"2019-08-01","title":"PDPL takes effect","description":"Article 4 of the issuing law says the law applies from the first day of the month after one year from Gazette publication.","kind":"effective","sourceUrl":"https://www.lloc.gov.bh/Legislation/HTM/K3018","tentative":true,"review":"verified"}]},{"id":"br-ai-bill","name":"Projeto de Lei nº 2338/2023 (Brazilian AI Legal Framework)","shortName":"Brazil AI Bill (PL 2338/2023)","jurisdiction":"br","jurisdictionName":"Brazil","region":"americas","topics":["ai"],"status":"proposed","citation":"PL 2338/2023","enactedDate":"","effectiveDate":"","summary":"Risk-based AI framework inspired by the EU AI Act: prohibited (excessive-risk) uses, high-risk system obligations, algorithmic impact assessments, rights for affected persons and copyright remuneration provisions, coordinated by a national AI regulation system (SIA) led by the ANPD.","appliesTo":"Developers, distributors and deployers of AI systems in Brazil (per Senate text).","penalties":"Senate text: fines up to BRL 50 million per infraction or up to 2% of group revenue in Brazil; suspension of development or supply.","enforcer":"ANPD as coordinator of the National AI Regulation and Governance System (SIA) (proposed)","sourceUrl":"https://www25.senado.leg.br/web/atividade/materias/-/materia/157233","extraSources":["https://www.camara.leg.br/proposicoesWeb/fichadetramitacao?idProposicao=2487262"],"notes":"As of September 2026 the Chamber's tramitação page shows the bill still awaiting the rapporteur's opinion in the Special Commission; a plenary vote reported for late May 2026 did not occur. If the Chamber amends it, the bill returns to the Senate. Penalty figures are from the Senate-approved text as reported, not re-verified.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-22 20:04:22","sourceType":"official","verifiedBy":"research from official sources","deadlines":[{"id":9,"regulationId":"br-ai-bill","date":"2024-12-10","title":"Approved by the Federal Senate","description":"Senate approves the consolidated text and sends it to the Chamber of Deputies.","kind":"effective","sourceUrl":"https://www25.senado.leg.br/web/atividade/materias/-/materia/157233","tentative":false,"review":"verified"}]},{"id":"br-eca-digital","name":"Estatuto Digital da Criança e do Adolescente (Law No. 15.211/2025)","shortName":"Brazil ECA Digital","jurisdiction":"br","jurisdictionName":"Brazil","region":"americas","topics":["children","online-safety","privacy"],"status":"in_force","citation":"Lei nº 15.211/2025","enactedDate":"2025-09-17","effectiveDate":"2026-03-17","summary":"Requires digital products and services likely to be accessed by children and adolescents to apply protection by design and default, reliable age verification, parental supervision tools, links between under-16 accounts and guardians, and swift removal of harmful content; bans profiling-based advertising to children and loot boxes in games for minors.","appliesTo":"Providers of information technology products or services directed at, or likely to be accessed by, children and adolescents in Brazil: social networks, games, app stores, operating systems, streaming and similar services, regardless of location.","penalties":"Warning; simple fine up to 10% of the economic group's revenue in Brazil in the last fiscal year or, absent revenue, BRL 10 to BRL 1,000 per registered user, capped at BRL 50 million per infraction; temporary suspension or prohibition of activities (judicial).","enforcer":"Autonomous administrative authority for children's digital rights (ANPD designated); courts for suspension/prohibition","sourceUrl":"https://www.planalto.gov.br/ccivil_03/_ato2023-2026/2025/lei/L15211.htm","extraSources":["https://www.machadomeyer.com.br/pt/inteligencia-juridica/publicacoes-ij/direito-digital/estatuto-digital-da-crianca-e-do-adolescente-lei-n-15-211-2025-entra-em-vigor-em-17-de-marco-de-2026"],"notes":"Published 18 Sept 2025. Designation of ANPD as the enforcing authority is from secondary reporting.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-22 20:04:22","sourceType":"official","verifiedBy":"research from official sources","deadlines":[{"id":10,"regulationId":"br-eca-digital","date":"2026-03-17","title":"ECA Digital in force","description":"Art. 41-A (as set by Law 15.352/2026, following MP 1.319/2025) fixes entry into force on 17 March 2026.","kind":"effective","sourceUrl":"https://www.planalto.gov.br/ccivil_03/_ato2023-2026/2025/lei/L15211.htm","tentative":false,"review":"verified"}]},{"id":"br-lgpd","name":"Lei Geral de Proteção de Dados Pessoais (Law No. 13.709/2018)","shortName":"Brazil LGPD","jurisdiction":"br","jurisdictionName":"Brazil","region":"americas","topics":["privacy","breach-notification","data-residency"],"status":"in_force","citation":"Lei nº 13.709, de 14 de agosto de 2018","enactedDate":"2018-08-14","effectiveDate":"2020-09-18","summary":"Brazil's GDPR-style general data protection law: ten legal bases, data subject rights, DPO (encarregado), incident reporting and international transfer rules. ANPD's Resolution CD/ANPD 19/2024 set the international transfer regime and mandatory standard contractual clauses.","appliesTo":"Any processing carried out in Brazil, targeting individuals in Brazil, or of data collected in Brazil, regardless of the controller's location. Simplified rules for small-scale agents (Resolution CD/ANPD 2/2022).","penalties":"Fines up to 2% of the company's/group's revenue in Brazil in the prior fiscal year, capped at BRL 50 million per infraction; daily fines; publicisation; blocking or deletion of data; suspension of processing.","enforcer":"Autoridade Nacional de Proteção de Dados (ANPD)","sourceUrl":"https://www.planalto.gov.br/ccivil_03/_ato2015-2018/2018/lei/l13709.htm","extraSources":["https://www.in.gov.br/en/web/dou/-/resolucao-cd/anpd-n-19-de-23-de-agosto-de-2024-580095396","https://www.gov.br/anpd/"],"notes":"In 2025 the ANPD was restructured into a regulatory agency (MP 1.317/2025); not separately verified.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-22 20:04:22","sourceType":"official","verifiedBy":"research from official sources","deadlines":[{"id":11,"regulationId":"br-lgpd","date":"2020-09-18","title":"LGPD in force","description":"Main LGPD provisions take effect.","kind":"effective","sourceUrl":"https://www.planalto.gov.br/ccivil_03/_ato2015-2018/2018/lei/l13709.htm","tentative":false,"review":"verified"},{"id":12,"regulationId":"br-lgpd","date":"2021-08-01","title":"ANPD sanctions enforceable","description":"Administrative sanctions (Arts. 52-54) become applicable per Law 14.010/2020.","kind":"enforcement","sourceUrl":"https://www.planalto.gov.br/ccivil_03/_ato2015-2018/2018/lei/l13709.htm","tentative":false,"review":"verified"},{"id":13,"regulationId":"br-lgpd","date":"2024-08-23","title":"International transfer regulation published","description":"Resolution CD/ANPD 19/2024 on international transfers and standard contractual clauses published and in force.","kind":"effective","sourceUrl":"https://www.in.gov.br/en/web/dou/-/resolucao-cd/anpd-n-19-de-23-de-agosto-de-2024-580095396","tentative":false,"review":"verified"},{"id":14,"regulationId":"br-lgpd","date":"2025-08-23","title":"Deadline to adopt ANPD standard contractual clauses","description":"Agents relying on contractual clauses for international transfers must incorporate the ANPD-approved SCCs into their contracts within 12 months of publication.","kind":"compliance","sourceUrl":"https://www.in.gov.br/en/web/dou/-/resolucao-cd/anpd-n-19-de-23-de-agosto-de-2024-580095396","tentative":false,"review":"verified"}]},{"id":"us-ca-ccpa","name":"California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 (Cal. Civ. Code 1798.100 et seq.) and CPPA regulations (Cal. Code Regs. tit. 11, 7000 et seq.)","shortName":"CCPA / CPRA","jurisdiction":"us-ca","jurisdictionName":"California","region":"us-states","topics":["privacy","ai","cybersecurity","children"],"status":"amended","citation":"Cal. Civ. Code 1798.100-1798.199.100 (AB 375, Stats. 2018 ch. 55; Proposition 24 (2020)); 11 CCR 7000 et seq.","enactedDate":"2018-06-28","effectiveDate":"2020-01-01","summary":"Gives California residents (including employees and B2B contacts) rights to know, delete, correct, and opt out of sale/sharing of personal information and to limit use of sensitive personal information. CPPA regulations approved Sept 22, 2025 (effective Jan 1, 2026) add automated decisionmaking technology (ADMT) rights, mandatory risk assessments with submissions to the agency, and annual independent cybersecurity audits. AB 566 (2025) requires browsers to offer an opt-out preference signal from Jan 1, 2027.","appliesTo":"For-profit businesses doing business in California that meet any of: annual gross revenue over $25M as CPI-adjusted ($26,625,000 from Jan 1, 2025); buy, sell or share personal information of 100,000+ consumers or households; or derive 50%+ of annual revenue from selling or sharing personal information. Cybersecurity audits apply to businesses deriving 50%+ revenue from selling/sharing PI, or over the revenue threshold and processing PI of 250,000+ consumers/households or sensitive PI of 50,000+ consumers.","penalties":"Administrative fines/civil penalties up to $2,663 per violation and $7,988 per intentional violation or violation involving minors under 16 (CPI-adjusted from Jan 1, 2025; statutory base $2,500/$7,500). Private right of action for data breaches: $107-$799 per consumer per incident or actual damages. No statutory cure period (the 30-day cure was removed by the CPRA; CPPA may consider cure discretionarily).","enforcer":"California Privacy Protection Agency (CalPrivacy) and California Attorney General","sourceUrl":"https://cppa.ca.gov/regulations/ccpa_updates.html","extraSources":["https://cppa.ca.gov/regulations/pdf/ccpa_updates_cyber_risk_admt_appr_text.pdf","https://cppa.ca.gov/regulations/cpi_adjustment.html","https://leginfo.legislature.ca.gov/faces/billStatusClient.xhtml?bill_id=202520260AB566","https://cppa.ca.gov/regulations/pdf/ccpa_statute_eff_20260101.pdf","https://www.alston.com/en/insights/publications/2026/08/california-privacy-opt-out-signals-data-brokers"],"notes":"Monetary thresholds are CPI-adjusted every odd year; a January 2027 adjustment is expected but not yet published as of verification. CPPA rebranded as CalPrivacy. Additional 2025 bills (e.g. SB 361 data broker disclosures) and further CPPA rulemaking (reported for late 2026/2027 on notices and employee data) are not captured as deadlines. Risk assessment submission deadline is April 1, 2028 per 11 CCR 7157 (not April 21).","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-22 20:04:22","sourceType":"official","verifiedBy":"research from official sources","deadlines":[{"id":164,"regulationId":"us-ca-ccpa","date":"2020-01-01","title":"CCPA takes effect","description":"Original CCPA consumer rights and business obligations take effect.","kind":"effective","sourceUrl":"https://cppa.ca.gov/regulations/pdf/ccpa_statute_eff_20260101.pdf","tentative":false,"review":"verified"},{"id":165,"regulationId":"us-ca-ccpa","date":"2023-01-01","title":"CPRA amendments operative","description":"CPRA amendments (correction right, sensitive PI limits, sharing opt-out, employee/B2B data coverage) become operative.","kind":"effective","sourceUrl":"https://cppa.ca.gov/regulations/pdf/ccpa_statute_eff_20260101.pdf","tentative":false,"review":"verified"},{"id":166,"regulationId":"us-ca-ccpa","date":"2025-01-01","title":"CPI adjustment of thresholds and fines","description":"Revenue threshold rises to $26,625,000 and fines to $2,663 / $7,988 per violation.","kind":"transition","sourceUrl":"https://cppa.ca.gov/regulations/cpi_adjustment.html","tentative":false,"review":"verified"},{"id":167,"regulationId":"us-ca-ccpa","date":"2025-09-22","title":"ADMT, risk assessment and cybersecurity audit regulations approved","description":"OAL approves the CCPA Updates, Cybersecurity Audit, Risk Assessment, ADMT and Insurance regulations and files them with the Secretary of State.","kind":"transition","sourceUrl":"https://cppa.ca.gov/regulations/ccpa_updates.html","tentative":false,"review":"verified"},{"id":168,"regulationId":"us-ca-ccpa","date":"2026-01-01","title":"New CCPA regulations take effect","description":"ADMT, risk assessment, cybersecurity audit and updated CCPA regulations become effective; risk assessments required for new high-risk processing.","kind":"effective","sourceUrl":"https://cppa.ca.gov/regulations/ccpa_updates.html","tentative":false,"review":"verified"},{"id":169,"regulationId":"us-ca-ccpa","date":"2027-01-01","title":"ADMT requirements compliance date","description":"Businesses using ADMT for significant decisions must comply with Article 11 (pre-use notice, opt-out, access rights) by this date (11 CCR 7200(b)).","kind":"compliance","sourceUrl":"https://cppa.ca.gov/regulations/pdf/ccpa_updates_cyber_risk_admt_appr_text.pdf","tentative":false,"review":"verified"},{"id":170,"regulationId":"us-ca-ccpa","date":"2027-01-01","title":"Browsers must support opt-out preference signal (AB 566)","description":"Businesses that develop or maintain a browser must include consumer-configurable functionality to send an opt-out preference signal (Civ. Code 1798.136, operative Jan 1, 2027).","kind":"compliance","sourceUrl":"https://leginfo.legislature.ca.gov/faces/billStatusClient.xhtml?bill_id=202520260AB566","tentative":false,"review":"verified"},{"id":171,"regulationId":"us-ca-ccpa","date":"2027-12-31","title":"Risk assessments for pre-existing processing due","description":"Risk assessments must be completed and documented for high-risk processing that began before Jan 1, 2026 and continues after (11 CCR 7155(b)).","kind":"compliance","sourceUrl":"https://cppa.ca.gov/regulations/pdf/ccpa_updates_cyber_risk_admt_appr_text.pdf","tentative":false,"review":"verified"},{"id":172,"regulationId":"us-ca-ccpa","date":"2028-04-01","title":"First risk assessment submission to CPPA","description":"Businesses must submit required risk assessment information and attestation for assessments conducted in 2026 and 2027 (11 CCR 7157(a)(1)); annually by April 1 thereafter.","kind":"reporting","sourceUrl":"https://cppa.ca.gov/regulations/pdf/ccpa_updates_cyber_risk_admt_appr_text.pdf","tentative":false,"review":"verified"},{"id":173,"regulationId":"us-ca-ccpa","date":"2028-04-01","title":"Cybersecurity audit due: revenue over $100M","description":"First cybersecurity audit report (covering Jan 1, 2027 - Jan 1, 2028) and certification due for businesses with 2026 annual gross revenue over $100M (11 CCR 7121(a)(1)).","kind":"reporting","sourceUrl":"https://cppa.ca.gov/regulations/pdf/ccpa_updates_cyber_risk_admt_appr_text.pdf","tentative":false,"review":"verified"},{"id":174,"regulationId":"us-ca-ccpa","date":"2029-04-01","title":"Cybersecurity audit due: revenue $50M-$100M","description":"First cybersecurity audit report (covering 2028) due for businesses with 2027 annual gross revenue between $50M and $100M (11 CCR 7121(a)(2)).","kind":"reporting","sourceUrl":"https://cppa.ca.gov/regulations/pdf/ccpa_updates_cyber_risk_admt_appr_text.pdf","tentative":false,"review":"verified"},{"id":175,"regulationId":"us-ca-ccpa","date":"2030-04-01","title":"Cybersecurity audit due: revenue under $50M","description":"First cybersecurity audit report (covering 2029) due for covered businesses with 2028 annual gross revenue under $50M (11 CCR 7121(a)(3)); annual by April 1 thereafter.","kind":"reporting","sourceUrl":"https://cppa.ca.gov/regulations/pdf/ccpa_updates_cyber_risk_admt_appr_text.pdf","tentative":false,"review":"verified"}]},{"id":"us-cfpb-1033","name":"Required Rulemaking on Personal Financial Data Rights (12 CFR Part 1033)","shortName":"CFPB Open Banking Rule (Section 1033)","jurisdiction":"us","jurisdictionName":"United States","region":"us-federal","topics":["data-access","financial","privacy","cybersecurity"],"status":"enacted","citation":"89 FR 90838; 12 CFR Part 1033","enactedDate":"2024-11-18","effectiveDate":"2025-01-17","summary":"Requires banks, card issuers and other data providers to give consumers and authorized third parties their transaction and account data through a secure developer interface, free of charge. Third parties must limit collection, use and retention to what the consumer requested. The CFPB is reconsidering the rule and a federal court has barred its enforcement until that reconsideration ends.","appliesTo":"Depository and nondepository data providers holding covered Regulation E accounts or Regulation Z credit cards, and third parties and data aggregators that access consumer data. Depository institutions at or under the SBA size standard are exempt.","penalties":"Enforced under the Consumer Financial Protection Act (civil money penalties and other relief). Enforcement currently enjoined.","enforcer":"Consumer Financial Protection Bureau","sourceUrl":"https://www.federalregister.gov/documents/2024/11/18/2024-25079/required-rulemaking-on-personal-financial-data-rights","extraSources":["https://www.consumerfinance.gov/rules-policy/final-rules/required-rulemaking-on-personal-financial-data-rights/","https://www.federalregister.gov/documents/2025/08/22/2025-16139/personal-financial-data-rights-reconsideration","https://www.govinfo.gov/content/pkg/USCOURTS-kyed-5_24-cv-00304/pdf/USCOURTS-kyed-5_24-cv-00304-1.pdf","https://www.reginfo.gov/public/do/eAgendaViewRule?pubId=202510&RIN=3170-AB39","https://www.ecfr.gov/current/title-12/chapter-X/part-1033"],"notes":"As of 2026-09-25 the eCFR text still shows the original compliance dates and no reconsideration NPRM appears in the Federal Register. The Fall 2025 Unified Agenda targeted an NPRM for July 2026 (RIN 3170-AB39). The ANPR states the CFPB plans to propose extending the compliance dates. Treat all compliance dates as unsettled.","lastVerified":"2026-09-25","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-25 10:55:47","sourceType":"official","verifiedBy":"research from official sources (2026-09-25)","deadlines":[{"id":6880,"regulationId":"us-cfpb-1033","date":"2025-01-17","title":"Final rule effective","description":"Rule published 2024-11-18 takes effect.","kind":"effective","sourceUrl":"https://www.federalregister.gov/documents/2024/11/18/2024-25079/required-rulemaking-on-personal-financial-data-rights","tentative":false,"review":"verified"},{"id":6881,"regulationId":"us-cfpb-1033","date":"2025-07-29","title":"Court stays Forcht Bank litigation","description":"E.D. Ky. stays the industry challenge after the CFPB says it will reconsider the rule; compliance dates stayed by 90 days.","kind":"transition","sourceUrl":"https://www.federalregister.gov/documents/2025/08/22/2025-16139/personal-financial-data-rights-reconsideration","tentative":false,"review":"verified"},{"id":6882,"regulationId":"us-cfpb-1033","date":"2025-08-22","title":"Reconsideration ANPR published","description":"CFPB seeks comment on representatives, fees, data security and privacy, and on extending compliance dates.","kind":"transition","sourceUrl":"https://www.federalregister.gov/documents/2025/08/22/2025-16139/personal-financial-data-rights-reconsideration","tentative":false,"review":"verified"},{"id":6883,"regulationId":"us-cfpb-1033","date":"2025-10-21","title":"Reconsideration comment period closes","description":"Comments on the ANPR due.","kind":"reporting","sourceUrl":"https://www.federalregister.gov/documents/2025/08/22/2025-16139/personal-financial-data-rights-reconsideration","tentative":false,"review":"verified"},{"id":6884,"regulationId":"us-cfpb-1033","date":"2025-10-29","title":"Court enjoins enforcement","description":"E.D. Ky. enjoins the CFPB from enforcing the rule until it completes its reconsideration.","kind":"enforcement","sourceUrl":"https://www.govinfo.gov/content/pkg/USCOURTS-kyed-5_24-cv-00304/pdf/USCOURTS-kyed-5_24-cv-00304-1.pdf","tentative":false,"review":"verified"},{"id":6885,"regulationId":"us-cfpb-1033","date":"2026-06-30","title":"First compliance date (stayed, enjoined)","description":"Largest data providers (banks with $250B or more in assets; nondepositories with $10B or more in receipts). Originally 2026-04-01, moved 90 days by court stay. Not enforceable while the injunction stands.","kind":"compliance","sourceUrl":"https://www.federalregister.gov/documents/2025/08/22/2025-16139/personal-financial-data-rights-reconsideration","tentative":true,"review":"verified"},{"id":6886,"regulationId":"us-cfpb-1033","date":"2027-04-01","title":"Tier 2 compliance date (original)","description":"Banks with $10B to $250B in assets and smaller nondepositories. Original date in 12 CFR 1033.121; subject to the 90-day stay, planned extension and injunction.","kind":"compliance","sourceUrl":"https://www.federalregister.gov/documents/2024/11/18/2024-25079/required-rulemaking-on-personal-financial-data-rights","tentative":true,"review":"verified"},{"id":6887,"regulationId":"us-cfpb-1033","date":"2028-04-01","title":"Tier 3 compliance date (original)","description":"Banks with $3B to $10B in assets. Original date; subject to stay, extension and injunction.","kind":"compliance","sourceUrl":"https://www.federalregister.gov/documents/2024/11/18/2024-25079/required-rulemaking-on-personal-financial-data-rights","tentative":true,"review":"verified"},{"id":6888,"regulationId":"us-cfpb-1033","date":"2029-04-01","title":"Tier 4 compliance date (original)","description":"Banks with $1.5B to $3B in assets. Original date; subject to stay, extension and injunction.","kind":"compliance","sourceUrl":"https://www.federalregister.gov/documents/2024/11/18/2024-25079/required-rulemaking-on-personal-financial-data-rights","tentative":true,"review":"verified"},{"id":6889,"regulationId":"us-cfpb-1033","date":"2030-04-01","title":"Tier 5 compliance date (original)","description":"Banks with $850M to $1.5B in assets. Original date; subject to stay, extension and injunction.","kind":"compliance","sourceUrl":"https://www.federalregister.gov/documents/2024/11/18/2024-25079/required-rulemaking-on-personal-financial-data-rights","tentative":true,"review":"verified"}]},{"id":"us-circia","name":"Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA) and proposed implementing rule (6 CFR Part 226)","shortName":"CIRCIA","jurisdiction":"us","jurisdictionName":"United States (Federal)","region":"us-federal","topics":["cybersecurity","breach-notification"],"status":"enacted","citation":"6 U.S.C. 681-681g; Pub. L. 117-103, div. Y; NPRM 89 FR 23644 (Apr. 4, 2024), RIN 1670-AA04","enactedDate":"2022-03-15","effectiveDate":"","summary":"Directs CISA to require covered critical infrastructure entities to report covered cyber incidents within 72 hours of reasonably believing one occurred and ransom payments within 24 hours of payment, and to preserve related data. Reporting obligations begin only once CISA's final rule takes effect.","appliesTo":"As proposed: entities in any of the 16 critical infrastructure sectors that exceed the SBA small business size standard for their industry, or meet sector-based criteria (e.g. hospitals, certain IT and communications providers, water systems). CISA estimated about 316,244 covered entities.","penalties":"CISA may issue requests for information and subpoenas; failure to comply with a subpoena may be referred to DOJ for a civil action and contempt. False statements are subject to 18 U.S.C. 1001; federal contractors may face procurement actions including suspension or debarment.","enforcer":"Cybersecurity and Infrastructure Security Agency (CISA), DHS; DOJ for civil enforcement of subpoenas","sourceUrl":"https://www.federalregister.gov/documents/2024/04/04/2024-06526/cyber-incident-reporting-for-critical-infrastructure-act-circia-reporting-requirements","extraSources":["https://www.cisa.gov/topics/cyber-threats-and-advisories/information-sharing/circia","https://www.reginfo.gov/public/do/eAgendaViewRule?pubId=202510&RIN=1670-AA04","https://www.federalregister.gov/documents/2026/05/26/2026-10417/town-hall-meetings-to-provide-input-on-cyber-incident-reporting-for-critical-infrastructure-act","https://www.hunton.com/privacy-and-cybersecurity-law-blog/cisa-plans-to-finalize-cyber-incident-reporting-regulations-in-september-2026"],"notes":"Final rule not yet published as of 2026-09-22 (Federal Register search). CISA missed the statutory October 2025 deadline, then targeted May 2026, and the latest Unified Agenda lists the final rule for 09/2026 (month only). CISA held further town halls in 2026 (Federal Register notices of Feb. 13 and May 26, 2026) and has said it intends to streamline scope. Obligations will start on the final rule's effective date, expected to be well after publication.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-22 20:04:22","sourceType":"official","verifiedBy":"research from official sources","deadlines":[{"id":193,"regulationId":"us-circia","date":"2024-07-03","title":"NPRM comment period closed","description":"Extended comment period on the CIRCIA proposed rule closed.","kind":"transition","sourceUrl":"https://www.federalregister.gov/documents/2024/04/04/2024-06526/cyber-incident-reporting-for-critical-infrastructure-act-circia-reporting-requirements","tentative":false,"review":"verified"}]},{"id":"us-cmmc","name":"Cybersecurity Maturity Model Certification (CMMC) Program (32 CFR Part 170) and DFARS acquisition rule (48 CFR Parts 204, 212, 217, 252)","shortName":"CMMC 2.0","jurisdiction":"us","jurisdictionName":"United States (Federal)","region":"us-federal","topics":["cybersecurity"],"status":"in_force","citation":"32 CFR Part 170 (89 FR 83092, Oct. 15, 2024); DFARS Case 2019-D041, 90 FR 43560 (Sept. 10, 2025)","enactedDate":"2024-10-15","effectiveDate":"2024-12-16","summary":"Requires defense contractors and subcontractors that handle Federal Contract Information (FCI) or Controlled Unclassified Information (CUI) to meet a specified CMMC level (Level 1 self-assessment, Level 2 self- or third-party (C3PAO) assessment against NIST SP 800-171, Level 3 DIBCAC assessment against selected NIST SP 800-172 controls) as a condition of contract award. Requirements are phased into DoD solicitations over four years.","appliesTo":"DoD prime contractors and subcontractors at all tiers whose information systems process, store or transmit FCI or CUI in contract performance; excludes contracts solely for commercially available off-the-shelf (COTS) items.","penalties":"Ineligibility for award or option exercise; misrepresented affirmations can create False Claims Act and contractual liability.","enforcer":"U.S. Department of Defense (DoD CIO, contracting officers, DCMA DIBCAC); Cyber AB accredits C3PAOs","sourceUrl":"https://www.federalregister.gov/documents/2025/09/10/2025-17359/defense-federal-acquisition-regulation-supplement-assessing-contractor-implementation-of","extraSources":["https://www.federalregister.gov/documents/2024/10/15/2024-22905/cybersecurity-maturity-model-certification-cmmc-program","https://dodcio.defense.gov/CMMC/"],"notes":"Phase dates computed per 32 CFR 170.3(e): Phase 1 starts on the later of the Part 170 or the 48 CFR rule effective date (November 10, 2025), each later phase one calendar year after the previous; DoD may include higher requirements earlier at its discretion. The DoD CIO site could not be fetched during verification.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-22 20:04:22","sourceType":"official","verifiedBy":"research from official sources","deadlines":[{"id":194,"regulationId":"us-cmmc","date":"2024-12-16","title":"CMMC Program rule (32 CFR Part 170) effective","description":"The program rule establishing CMMC levels and assessment processes took effect; contract enforcement awaited the DFARS rule.","kind":"effective","sourceUrl":"https://www.federalregister.gov/documents/2024/10/15/2024-22905/cybersecurity-maturity-model-certification-cmmc-program","tentative":false,"review":"verified"},{"id":195,"regulationId":"us-cmmc","date":"2025-11-10","title":"DFARS rule effective; Phase 1 begins","description":"CMMC Level 1 and Level 2 self-assessment requirements begin appearing in applicable DoD solicitations and contracts (32 CFR 170.3(e)(1)).","kind":"effective","sourceUrl":"https://www.federalregister.gov/documents/2025/09/10/2025-17359/defense-federal-acquisition-regulation-supplement-assessing-contractor-implementation-of","tentative":false,"review":"verified"},{"id":196,"regulationId":"us-cmmc","date":"2026-11-10","title":"Phase 2: Level 2 C3PAO certification","description":"Phase 2 begins one calendar year after Phase 1; applicable solicitations require CMMC Level 2 third-party (C3PAO) certification (32 CFR 170.3(e)(2)).","kind":"compliance","sourceUrl":"https://www.federalregister.gov/documents/2024/10/15/2024-22905/cybersecurity-maturity-model-certification-cmmc-program","tentative":false,"review":"verified"},{"id":197,"regulationId":"us-cmmc","date":"2027-11-10","title":"Phase 3: Level 3 certification","description":"Phase 3 begins one year after Phase 2; Level 3 (DIBCAC) requirements added to applicable solicitations (32 CFR 170.3(e)(3)).","kind":"compliance","sourceUrl":"https://www.federalregister.gov/documents/2024/10/15/2024-22905/cybersecurity-maturity-model-certification-cmmc-program","tentative":false,"review":"verified"},{"id":198,"regulationId":"us-cmmc","date":"2028-11-10","title":"Phase 4: full implementation","description":"CMMC requirements included in all applicable DoD solicitations and contracts, including option periods (32 CFR 170.3(e)(4)).","kind":"compliance","sourceUrl":"https://www.federalregister.gov/documents/2024/10/15/2024-22905/cybersecurity-maturity-model-certification-cmmc-program","tentative":false,"review":"verified"}]},{"id":"us-coppa","name":"Children's Online Privacy Protection Rule (16 CFR Part 312), as amended April 2025","shortName":"COPPA Rule","jurisdiction":"us","jurisdictionName":"United States (Federal)","region":"us-federal","topics":["privacy","children"],"status":"amended","citation":"15 U.S.C. 6501-6506; 16 CFR Part 312; amendments at 90 FR 16918 (Apr. 22, 2025)","enactedDate":"1998-10-21","effectiveDate":"2000-04-21","summary":"Requires operators of child-directed online services, or those with actual knowledge they collect personal information from children under 13, to give notice and obtain verifiable parental consent before collecting, using or disclosing that data. The 2025 amendments add separate parental consent for disclosures to third parties (including for targeted advertising), require a written data retention policy and a written information security program, expand 'personal information' to include biometric identifiers and government-issued identifiers, and tighten Safe Harbor program oversight.","appliesTo":"Operators of commercial websites, online services and apps directed to children under 13 (including mixed-audience services), and general-audience operators with actual knowledge they collect personal information from a child under 13. No revenue or volume threshold.","penalties":"Violations are treated as violations of an FTC trade regulation rule: civil penalties up to $53,088 per violation (FTC Act 5(m)(1)(A) amount as adjusted January 2025, 90 FR 5580; adjusted annually for inflation). State attorneys general may also sue.","enforcer":"Federal Trade Commission; State Attorneys General","sourceUrl":"https://www.federalregister.gov/documents/2025/04/22/2025-05904/childrens-online-privacy-protection-rule","extraSources":["https://www.ecfr.gov/current/title-16/chapter-I/subchapter-C/part-312","https://www.federalregister.gov/documents/2025/01/17/2025-01361/adjustments-to-civil-penalty-amounts"],"notes":"Safe Harbor program obligations had earlier compliance dates set relative to publication: 90 days after publication for 312.11(d)(4) and six months after publication for 312.11(d)(1) and (g) (i.e. around July 21, 2025 and October 22, 2025); omitted as rows because the rule states them relatively. The FTC civil penalty figure is the January 2025 adjustment; no 2026 FTC adjustment was found in the Federal Register as of verification.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-22 20:04:22","sourceType":"official","verifiedBy":"research from official sources","deadlines":[{"id":213,"regulationId":"us-coppa","date":"2025-06-23","title":"Amended COPPA Rule takes effect","description":"The April 2025 amendments to 16 CFR Part 312 became effective; during the transition operators could comply with either the pre-2025 or the amended Rule.","kind":"effective","sourceUrl":"https://www.federalregister.gov/documents/2025/04/22/2025-05904/childrens-online-privacy-protection-rule","tentative":false,"review":"verified"},{"id":214,"regulationId":"us-coppa","date":"2026-04-22","title":"Full compliance with amended COPPA Rule","description":"Operators must comply with all amended provisions (separate third-party disclosure consent, written retention policy, written security program, updated notices); excludes Safe Harbor provisions 312.11(d)(1), (d)(4) and (g), which had earlier dates.","kind":"compliance","sourceUrl":"https://www.federalregister.gov/documents/2025/04/22/2025-05904/childrens-online-privacy-protection-rule","tentative":false,"review":"verified"}]},{"id":"us-ca-ab2013","name":"California AB 2013, Generative Artificial Intelligence: Training Data Transparency (Stats. 2024, ch. 817)","shortName":"California AB 2013 (AI training data transparency)","jurisdiction":"us-ca","jurisdictionName":"California","region":"us-states","topics":["ai","privacy"],"status":"in_force","citation":"AB 2013 (2024), Stats. 2024, ch. 817; Civ. Code 3110-3111","enactedDate":"2024-09-28","effectiveDate":"2026-01-01","summary":"Developers of generative AI systems made publicly available to Californians must post documentation of the training data on their websites. It must cover a high-level summary of the datasets, their sources and owners, the number of data points, the types of data, whether the data includes copyrighted material or personal information, whether it was licensed or purchased, cleaning and processing steps, collection periods, and whether synthetic data was used.","appliesTo":"Any developer, including those that substantially modify a system, of a generative AI system or service released on or after January 1, 2022 and publicly available to Californians. Exempt: systems whose sole purpose is security and integrity, systems for operating aircraft in national airspace, and systems for federal national security, military or defense purposes. No size threshold.","penalties":"The statute sets no specific penalty. Enforcement would rely on general California law, for example the Unfair Competition Law.","enforcer":"Not specified in statute (California Attorney General under general consumer protection law)","sourceUrl":"https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202320240AB2013","extraSources":[],"notes":"Enforcement route is not explicit in the statute. Constitutional challenges to AB 2013 were reported but not verified for this record.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-22 20:04:22","sourceType":"official","verifiedBy":"research from official sources","deadlines":[{"id":162,"regulationId":"us-ca-ab2013","date":"2024-09-28","title":"AB 2013 signed","description":"AB 2013 chaptered (ch. 817).","kind":"transition","sourceUrl":"https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202320240AB2013","tentative":false,"review":"verified"},{"id":163,"regulationId":"us-ca-ab2013","date":"2026-01-01","title":"Training-data documentation due","description":"Documentation must be posted for GenAI systems released since January 1, 2022, and before each later release or substantial modification.","kind":"compliance","sourceUrl":"https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202320240AB2013","tentative":false,"review":"verified"}]},{"id":"us-ca-ads-regs","name":"Civil Rights Council Regulations on Automated-Decision Systems in Employment (FEHA)","shortName":"California ADS employment regulations","jurisdiction":"us-ca","jurisdictionName":"California","region":"us-states","topics":["ai"],"status":"in_force","citation":"Cal. Code Regs., tit. 2, section 11008 et seq. (amended)","enactedDate":"2025-06-27","effectiveDate":"2025-10-01","summary":"Clarifies that using an automated-decision system in hiring or other employment decisions can violate the Fair Employment and Housing Act if it discriminates on protected traits. Employers must keep automated-decision data and employment records for at least four years. AI assessments that elicit disability information can be unlawful medical inquiries.","appliesTo":"Employers with 5 or more employees, their agents, employment agencies and others covered by FEHA in California.","penalties":"FEHA remedies: damages, back pay, injunctive relief and attorney fees through CRD complaints or civil suits.","enforcer":"California Civil Rights Department","sourceUrl":"https://calcivilrights.ca.gov/2025/06/30/civil-rights-council-secures-approval-for-regulations-to-protect-against-employment-discrimination-related-to-artificial-intelligence/","extraSources":["https://calcivilrights.ca.gov/civilrightscouncil/"],"notes":"Distinct from the CPPA's CCPA ADMT regulations tracked under us-ca-ccpa.","lastVerified":"2026-09-25","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-25 10:55:47","sourceType":"official","verifiedBy":"research from official sources (2026-09-25)","deadlines":[{"id":6897,"regulationId":"us-ca-ads-regs","date":"2025-06-27","title":"OAL approves regulations","description":"Office of Administrative Law approves the Civil Rights Council's ADS rules.","kind":"transition","sourceUrl":"https://calcivilrights.ca.gov/2025/06/30/civil-rights-council-secures-approval-for-regulations-to-protect-against-employment-discrimination-related-to-artificial-intelligence/","tentative":false,"review":"verified"},{"id":6898,"regulationId":"us-ca-ads-regs","date":"2025-10-01","title":"ADS regulations take effect","description":"Rules apply to employment decisions using automated-decision systems.","kind":"effective","sourceUrl":"https://calcivilrights.ca.gov/2025/06/30/civil-rights-council-secures-approval-for-regulations-to-protect-against-employment-discrimination-related-to-artificial-intelligence/","tentative":false,"review":"verified"}]},{"id":"us-ca-ab1405","name":"Artificial Intelligence: Auditors: Registration (AB 1405)","shortName":"California AI Auditor Registry","jurisdiction":"us-ca","jurisdictionName":"California","region":"us-states","topics":["ai"],"status":"enacted","citation":"Stats. 2026, ch. 178; Cal. Gov. Code section 11549.8 et seq.","enactedDate":"2026-09-09","effectiveDate":"2027-01-01","summary":"Creates a state registry for AI auditors run by the Government Operations Agency. From 2029 only registered auditors may offer, sell or conduct covered AI audits, and they must show their registration number in advertising. Registered auditors must file information and follow conduct rules.","appliesTo":"Persons offering or conducting covered AI audits, including audits under California AI laws.","penalties":"Registration can be denied, suspended or revoked; see statute for enforcement.","enforcer":"California Government Operations Agency","sourceUrl":"https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202520260AB1405","extraSources":[],"notes":"2027-01-01 is California's default effective date; the operative duties start 2029-01-01.","lastVerified":"2026-09-25","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-25 10:55:47","sourceType":"official","verifiedBy":"research from official sources (2026-09-25)","deadlines":[{"id":6904,"regulationId":"us-ca-ab1405","date":"2026-09-09","title":"Signed by Governor","description":"Chaptered as Chapter 178, Statutes of 2026.","kind":"transition","sourceUrl":"https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202520260AB1405","tentative":false,"review":"verified"},{"id":6905,"regulationId":"us-ca-ab1405","date":"2027-01-01","title":"Act takes effect","description":"Default effective date for 2026 regular-session statutes.","kind":"effective","sourceUrl":"https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202520260AB1405","tentative":false,"review":"verified"},{"id":6906,"regulationId":"us-ca-ab1405","date":"2029-01-01","title":"Registry opens and registration required","description":"Agency must launch the AI Auditor Registry; unregistered persons may not offer or conduct covered AI audits.","kind":"compliance","sourceUrl":"https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202520260AB1405","tentative":false,"review":"verified"}]},{"id":"us-ca-sb942","name":"California AI Transparency Act (SB 942, Stats. 2024, ch. 291), as amended by AB 853 (Stats. 2025, ch. 674)","shortName":"California AI Transparency Act (SB 942)","jurisdiction":"us-ca","jurisdictionName":"California","region":"us-states","topics":["ai"],"status":"amended","citation":"Bus. & Prof. Code 22757 et seq.; SB 942 (2024) ch. 291; AB 853 (2025) ch. 674","enactedDate":"2024-09-19","effectiveDate":"2026-08-02","summary":"Covered generative AI providers must offer a free AI-content detection tool, give users the option of a visible (manifest) disclosure on AI-generated image, video or audio, and embed a latent, machine-readable provenance disclosure. Licensees must keep those disclosures intact, and providers must revoke a license within 96 hours of learning a licensee disabled them. AB 853 delayed the operative date to August 2, 2026 and extends duties to large online platforms and GenAI hosting platforms from 2027 and to capture-device makers from 2028.","appliesTo":"Covered providers: creators of GenAI systems with over 1,000,000 monthly visitors or users that are publicly accessible in California. From 2027: large online platforms with more than 2,000,000 unique monthly users in the preceding 12 months, and GenAI system hosting platforms. From 2028: capture device manufacturers.","penalties":"Civil penalty of $5,000 per violation, each day a separate violation, plus attorney fees and costs for a prevailing plaintiff. Injunctive relief against licensees.","enforcer":"California Attorney General, city attorneys, county counsel","sourceUrl":"https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202520260AB853","extraSources":["https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202320240SB942","https://www.troutmanprivacy.com/2025/10/california-ai-transparency-act-amendments-signed-into-law/"],"notes":"The August 2, 2026 operative date was set by AB 853. Many trackers still cite January 1, 2026, which is superseded.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-22 20:04:22","sourceType":"official","verifiedBy":"research from official sources","deadlines":[{"id":187,"regulationId":"us-ca-sb942","date":"2024-09-19","title":"SB 942 signed","description":"SB 942 chaptered (ch. 291) with an original operative date of January 1, 2026.","kind":"transition","sourceUrl":"https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202320240SB942","tentative":false,"review":"verified"},{"id":188,"regulationId":"us-ca-sb942","date":"2025-10-13","title":"AB 853 signed","description":"AB 853 (ch. 674) delays the operative date and adds platform and device duties.","kind":"transition","sourceUrl":"https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202520260AB853","tentative":false,"review":"verified"},{"id":189,"regulationId":"us-ca-sb942","date":"2026-01-01","title":"Original operative date (superseded)","description":"Original SB 942 date; delayed to August 2, 2026 by AB 853.","kind":"transition","sourceUrl":"https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202320240SB942","tentative":false,"review":"verified"},{"id":190,"regulationId":"us-ca-sb942","date":"2026-08-02","title":"Covered provider duties apply","description":"Detection tool, manifest and latent disclosures, and license-revocation duties become operative.","kind":"effective","sourceUrl":"https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202520260AB853","tentative":false,"review":"verified"},{"id":191,"regulationId":"us-ca-sb942","date":"2027-01-01","title":"Large online platform and hosting platform duties","description":"Large online platforms and GenAI hosting platforms must meet the provenance duties added by AB 853.","kind":"compliance","sourceUrl":"https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202520260AB853","tentative":false,"review":"verified"},{"id":192,"regulationId":"us-ca-sb942","date":"2028-01-01","title":"Capture device manufacturer duties","description":"Capture device manufacturer provenance requirements become operative.","kind":"compliance","sourceUrl":"https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202520260AB853","tentative":false,"review":"verified"}]},{"id":"us-ca-ab316","name":"Artificial Intelligence: Defenses (AB 316)","shortName":"California AI autonomous-harm defense ban","jurisdiction":"us-ca","jurisdictionName":"California","region":"us-states","topics":["ai"],"status":"in_force","citation":"Stats. 2025, ch. 672; Cal. Civ. Code section 1714.46","enactedDate":"2025-10-13","effectiveDate":"2026-01-01","summary":"A defendant that developed, modified or used AI cannot argue in a civil case that the AI acted autonomously and so caused the harm on its own. Other defenses such as causation and comparative fault remain.","appliesTo":"Any developer, modifier or user of AI who is a defendant in a California civil action.","penalties":"No penalty; shapes civil liability.","enforcer":"Courts (private litigation)","sourceUrl":"https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202520260AB316","extraSources":[],"notes":"Effective date is California's default January 1 rule for non-urgency statutes; the bill has no special date.","lastVerified":"2026-09-25","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-25 10:55:47","sourceType":"official","verifiedBy":"research from official sources (2026-09-25)","deadlines":[{"id":6902,"regulationId":"us-ca-ab316","date":"2025-10-13","title":"Signed by Governor","description":"Chaptered as Chapter 672, Statutes of 2025.","kind":"transition","sourceUrl":"https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202520260AB316","tentative":false,"review":"verified"},{"id":6903,"regulationId":"us-ca-ab316","date":"2026-01-01","title":"Takes effect","description":"Default effective date for 2025 regular-session statutes.","kind":"effective","sourceUrl":"https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202520260AB316","tentative":false,"review":"verified"}]},{"id":"us-ca-delete-act","name":"California Delete Act (SB 362, 2023), Cal. Civ. Code 1798.99.80 et seq., and DROP regulations","shortName":"California Delete Act / DROP","jurisdiction":"us-ca","jurisdictionName":"California","region":"us-states","topics":["privacy","data-access"],"status":"in_force","citation":"SB 362 (Stats. 2023, ch. 709); Cal. Civ. Code 1798.99.80-1798.99.89","enactedDate":"2023-10-10","effectiveDate":"2024-01-01","summary":"Requires data brokers to register annually with the California Privacy Protection Agency and to process consumer deletion requests submitted through the agency's Delete Request and Opt-out Platform (DROP). DROP opened to consumers Jan 1, 2026; from Aug 1, 2026 brokers must pull and process requests at least every 45 days. Brokers face independent compliance audits every three years from 2028.","appliesTo":"Data brokers: businesses that knowingly collect and sell to third parties the personal information of consumers with whom they do not have a direct relationship (Civ. Code 1798.99.80). No revenue or volume threshold.","penalties":"Administrative fines of $200 per day for failure to register, plus unpaid fees; $200 per deletion request per day for failure to delete as required by 1798.99.86; plus reasonable enforcement costs.","enforcer":"California Privacy Protection Agency (CalPrivacy)","sourceUrl":"https://www.cppa.ca.gov/data_brokers/","extraSources":["https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=CIV&sectionNum=1798.99.82","https://cppa.ca.gov/regulations/drop.html","https://www.alston.com/en/insights/publications/2026/08/california-privacy-opt-out-signals-data-brokers"],"notes":"Registration fee reported to rise from $6,000 to $9,500 for 2027 (Alston & Bird, Aug 2026); not verified on cppa.ca.gov. Signing date Oct 10, 2023 per legislative history (chaptered as ch. 709).","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-22 20:04:22","sourceType":"official","verifiedBy":"research from official sources","deadlines":[{"id":176,"regulationId":"us-ca-delete-act","date":"2026-01-01","title":"DROP opens to consumers","description":"Consumers can submit a single deletion request to all registered data brokers through DROP.","kind":"effective","sourceUrl":"https://www.cppa.ca.gov/data_brokers/","tentative":false,"review":"verified"},{"id":177,"regulationId":"us-ca-delete-act","date":"2026-01-31","title":"Annual data broker registration deadline","description":"Data brokers must register with CalPrivacy and pay the annual fee ($6,000 for 2026) by January 31.","kind":"reporting","sourceUrl":"https://www.cppa.ca.gov/data_brokers/","tentative":false,"review":"verified"},{"id":178,"regulationId":"us-ca-delete-act","date":"2026-08-01","title":"Data brokers must begin processing DROP deletion requests","description":"Brokers must access DROP at least every 45 days, process verified deletion requests within 45 days, and treat unverified requests as opt-outs of sale/sharing.","kind":"compliance","sourceUrl":"https://www.cppa.ca.gov/data_brokers/","tentative":false,"review":"verified"},{"id":179,"regulationId":"us-ca-delete-act","date":"2027-01-31","title":"Annual data broker registration deadline","description":"Data brokers must renew registration with CalPrivacy by January 31 following each year they meet the definition.","kind":"reporting","sourceUrl":"https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=CIV&sectionNum=1798.99.82","tentative":false,"review":"verified"},{"id":180,"regulationId":"us-ca-delete-act","date":"2028-01-01","title":"Independent third-party audits begin","description":"Beginning Jan 1, 2028 and every 3 years thereafter, data brokers must undergo an independent audit of Delete Act compliance.","kind":"compliance","sourceUrl":"https://www.cppa.ca.gov/data_brokers/","tentative":false,"review":"verified"}]},{"id":"us-ca-ab1043","name":"Digital Age Assurance Act (AB 1043)","shortName":"California Digital Age Assurance Act","jurisdiction":"us-ca","jurisdictionName":"California","region":"us-states","topics":["children","privacy","online-safety"],"status":"enacted","citation":"Stats. 2025, ch. 675; Cal. Civ. Code section 1798.500 et seq.","enactedDate":"2025-10-13","effectiveDate":"2027-01-01","summary":"Operating system providers must ask for a user's birth date or age at device account setup and send an age-bracket signal to apps through an API. App developers must request that signal when an app is downloaded and launched. The signal may only be used for age compliance and not shared for other purposes.","appliesTo":"Operating system providers, covered application stores and app developers serving users in California.","penalties":"Injunction and civil penalty up to $2,500 per affected child per negligent violation and up to $7,500 per affected child per intentional violation.","enforcer":"California Attorney General","sourceUrl":"https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202520260AB1043","extraSources":[],"notes":"","lastVerified":"2026-09-25","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-25 10:55:47","sourceType":"official","verifiedBy":"research from official sources (2026-09-25)","deadlines":[{"id":6899,"regulationId":"us-ca-ab1043","date":"2025-10-13","title":"Signed by Governor","description":"Chaptered as Chapter 675, Statutes of 2025.","kind":"transition","sourceUrl":"https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202520260AB1043","tentative":false,"review":"verified"},{"id":6900,"regulationId":"us-ca-ab1043","date":"2027-01-01","title":"Age signal duties begin","description":"OS providers must offer the age interface at account setup and developers must request signals.","kind":"effective","sourceUrl":"https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202520260AB1043","tentative":false,"review":"verified"},{"id":6901,"regulationId":"us-ca-ab1043","date":"2027-07-01","title":"Deadline for existing devices and apps","description":"OS providers must offer the age interface for accounts set up before 2027, and developers must request signals for earlier installs.","kind":"compliance","sourceUrl":"https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202520260AB1043","tentative":false,"review":"verified"}]},{"id":"us-ca-sb243","name":"California SB 243, Companion Chatbots (Stats. 2025, ch. 677)","shortName":"California SB 243 (companion chatbots)","jurisdiction":"us-ca","jurisdictionName":"California","region":"us-states","topics":["ai","children","online-safety"],"status":"in_force","citation":"SB 243 (2025), Stats. 2025, ch. 677","enactedDate":"2025-10-13","effectiveDate":"2026-01-01","summary":"Operators of companion chatbot platforms must clearly disclose that the chatbot is AI where a user could reasonably think they are talking to a human. They must keep and publish protocols that prevent suicidal-ideation and self-harm content and refer users to crisis services. For known minors, operators must disclose AI use, remind them every three hours to take a break, and block sexually explicit content. Annual reports to the Office of Suicide Prevention begin July 1, 2027.","appliesTo":"Operators of companion chatbot platforms available to users in California. No size threshold.","penalties":"Private right of action: injunctive relief, the greater of actual damages or $1,000 per violation, and reasonable attorney fees and costs.","enforcer":"Private right of action; Office of Suicide Prevention receives reports","sourceUrl":"https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202520260SB243","extraSources":[],"notes":"Added as a major 2025 California AI law affecting consumer AI products.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-22 20:04:22","sourceType":"official","verifiedBy":"research from official sources","deadlines":[{"id":181,"regulationId":"us-ca-sb243","date":"2025-10-13","title":"SB 243 signed","description":"SB 243 chaptered (ch. 677).","kind":"transition","sourceUrl":"https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202520260SB243","tentative":false,"review":"verified"},{"id":182,"regulationId":"us-ca-sb243","date":"2026-01-01","title":"Chatbot safeguards apply","description":"AI disclosure, suicide and self-harm protocols, and minor protections apply.","kind":"effective","sourceUrl":"https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202520260SB243","tentative":false,"review":"verified"},{"id":183,"regulationId":"us-ca-sb243","date":"2027-07-01","title":"First annual report to Office of Suicide Prevention","description":"Operators begin annual reporting on crisis referrals and detection protocols.","kind":"reporting","sourceUrl":"https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202520260SB243","tentative":false,"review":"verified"}]},{"id":"us-ca-sb53","name":"California SB 53, Transparency in Frontier Artificial Intelligence Act (Stats. 2025, ch. 138)","shortName":"California SB 53 (TFAIA)","jurisdiction":"us-ca","jurisdictionName":"California","region":"us-states","topics":["ai"],"status":"in_force","citation":"SB 53 (2025), Stats. 2025, ch. 138","enactedDate":"2025-09-29","effectiveDate":"2026-01-01","summary":"Frontier AI developers must publish transparency reports when deploying new or substantially modified frontier models and report critical safety incidents to the Office of Emergency Services (OES). Large frontier developers must also write, implement and publish a frontier AI framework for catastrophic risk, update it annually, and send OES quarterly summaries of their catastrophic-risk assessments. The act also adds whistleblower protections and creates the CalCompute public computing consortium.","appliesTo":"Frontier developers: trained or started training a foundation model with more than 10^26 integer or floating-point operations, counting fine-tuning. Large frontier developers: those whose revenue with affiliates exceeded $500,000,000 in annual gross revenue in the preceding calendar year.","penalties":"Civil penalty up to $1,000,000 per violation, recoverable only in a civil action by the Attorney General.","enforcer":"California Attorney General; Office of Emergency Services receives incident reports","sourceUrl":"https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202520260SB53","extraSources":["https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=202520260SB53"],"notes":"CalCompute depends on a budget appropriation. The quarterly catastrophic-risk summary schedule can be set with OES.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-22 20:04:22","sourceType":"official","verifiedBy":"research from official sources","deadlines":[{"id":184,"regulationId":"us-ca-sb53","date":"2025-09-29","title":"SB 53 signed","description":"Governor Newsom signs SB 53 (chapter 138).","kind":"transition","sourceUrl":"https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202520260SB53","tentative":false,"review":"verified"},{"id":185,"regulationId":"us-ca-sb53","date":"2026-01-01","title":"Frontier developer obligations apply","description":"Frontier AI frameworks, transparency reports, critical safety incident reporting (15 days, or 24 hours for imminent risk of death or serious injury) and whistleblower protections apply.","kind":"effective","sourceUrl":"https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202520260SB53","tentative":false,"review":"verified"},{"id":186,"regulationId":"us-ca-sb53","date":"2027-01-01","title":"First OES anonymized incident report and CDT definition review","description":"OES begins publishing annual anonymized incident summaries and the Department of Technology begins annual review of the act's definitions; the CalCompute framework report is due to the Legislature.","kind":"reporting","sourceUrl":"https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202520260SB53","tentative":false,"review":"verified"}]},{"id":"us-ca-sb976","name":"Protecting Our Kids from Social Media Addiction Act (SB 976)","shortName":"California SB 976 addictive feeds","jurisdiction":"us-ca","jurisdictionName":"California","region":"us-states","topics":["children","online-safety"],"status":"in_force","citation":"Stats. 2024, ch. 321; Cal. Health & Safety Code section 27000 et seq.","enactedDate":"2024-09-20","effectiveDate":"2025-01-01","summary":"Bars addictive, personalized feeds for known minors without verifiable parental consent, and limits notifications to minors at night and during school hours. From 2027 operators must reasonably determine a user is not a minor before serving an addictive feed. The Attorney General must adopt age assurance and parental consent rules.","appliesTo":"Operators of addictive internet-based services or applications with California users.","penalties":"Civil actions by the Attorney General; see statute.","enforcer":"California Attorney General","sourceUrl":"https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202320240SB976","extraSources":["https://www.govinfo.gov/content/pkg/USCOURTS-cand-5_25-cv-09795/pdf/USCOURTS-cand-5_25-cv-09795-3.pdf"],"notes":"Litigation ongoing. On 2026-08-21 the N.D. Cal. denied Meta, TikTok and Google motions to enjoin the personalized feed provisions pending appeal.","lastVerified":"2026-09-25","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-25 10:55:47","sourceType":"official","verifiedBy":"research from official sources (2026-09-25)","deadlines":[{"id":6907,"regulationId":"us-ca-sb976","date":"2024-09-20","title":"Signed by Governor","description":"Chaptered as Chapter 321, Statutes of 2024.","kind":"transition","sourceUrl":"https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202320240SB976","tentative":false,"review":"verified"},{"id":6908,"regulationId":"us-ca-sb976","date":"2025-01-01","title":"Takes effect","description":"Actual-knowledge feed and notification limits apply, subject to litigation.","kind":"effective","sourceUrl":"https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202320240SB976","tentative":false,"review":"verified"},{"id":6909,"regulationId":"us-ca-sb976","date":"2027-01-01","title":"Age assurance duty and AG rules","description":"Operators must reasonably determine users are not minors; AG regulations on age assurance and parental consent due.","kind":"compliance","sourceUrl":"https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202320240SB976","tentative":false,"review":"verified"}]},{"id":"us-ca-ab656","name":"Account Cancellation (AB 656)","shortName":"California social media account deletion","jurisdiction":"us-ca","jurisdictionName":"California","region":"us-states","topics":["privacy"],"status":"in_force","citation":"Stats. 2025, ch. 464","enactedDate":"2025-10-08","effectiveDate":"2026-01-01","summary":"Social media platforms must offer a clear and conspicuous button to delete an account and must not obstruct deletion. A request to delete an account counts as a CCPA request to delete the user's personal information.","appliesTo":"Social media platforms with California users.","penalties":"Enforced through the CCPA framework for the deletion request; see statute.","enforcer":"California Attorney General and California Privacy Protection Agency","sourceUrl":"https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202520260AB656","extraSources":[],"notes":"Effective date is California's default January 1 rule; the bill has no special date.","lastVerified":"2026-09-25","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-25 10:55:47","sourceType":"official","verifiedBy":"research from official sources (2026-09-25)","deadlines":[{"id":6910,"regulationId":"us-ca-ab656","date":"2025-10-08","title":"Signed by Governor","description":"Chaptered as Chapter 464, Statutes of 2025.","kind":"transition","sourceUrl":"https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202520260AB656","tentative":false,"review":"verified"},{"id":6911,"regulationId":"us-ca-ab656","date":"2026-01-01","title":"Takes effect","description":"Default effective date for 2025 regular-session statutes.","kind":"effective","sourceUrl":"https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202520260AB656","tentative":false,"review":"verified"}]},{"id":"ca-c36-ppcda","name":"Bill C-36, An Act to enact the Protecting Privacy and Consumer Data Act","shortName":"Canada Bill C-36 (PPCDA)","jurisdiction":"ca","jurisdictionName":"Canada","region":"americas","topics":["privacy","breach-notification"],"status":"proposed","citation":"Bill C-36 (45th Parliament, 1st Session)","enactedDate":"","effectiveDate":"","summary":"Would replace PIPEDA's private-sector rules with a modernised statute (successor to C-27's CPPA) including stronger consent, de-identification and re-identification rules, and administrative penalties, with oversight housed in a new Digital Safety and Data Protection Commission. Does not include an AI act.","appliesTo":"Organisations handling personal information in the course of commercial activity (as under PIPEDA).","penalties":"As tabled: administrative monetary penalties up to the greater of CAD 10 million and 3% of global revenue; criminal fines up to the greater of CAD 25 million and 5% of global revenue on indictment.","enforcer":"Digital Safety and Data Protection Commission of Canada (proposed)","sourceUrl":"https://www.parl.ca/DocumentViewer/en/45-1/bill/C-36/first-reading","extraSources":["https://iapp.org/news/a/canada-s-bill-c-36-introduces-privacy-reforms-enforcement-changes","https://www.osler.com/en/insights/reports/the-protecting-privacy-and-consumer-data-act-bill-c-36-key-obligations-and-enforcement-overview/"],"notes":"Penalty figures are from law-firm/IAPP summaries of the first-reading text. No federal AI successor to AIDA has been tabled as of Aug 2026.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-22 20:04:22","sourceType":"official","verifiedBy":"research from official sources","deadlines":[{"id":15,"regulationId":"ca-c36-ppcda","date":"2026-06-15","title":"Bill C-36 tabled (first reading)","description":"Government introduces the PPCDA in the House of Commons.","kind":"effective","sourceUrl":"https://www.parl.ca/DocumentViewer/en/45-1/bill/C-36/first-reading","tentative":false,"review":"verified"}]},{"id":"ca-ccspa","name":"Critical Cyber Systems Protection Act (enacted by Bill C-8, An Act respecting cyber security)","shortName":"Canada Bill C-8 / CCSPA","jurisdiction":"ca","jurisdictionName":"Canada","region":"americas","topics":["cybersecurity","breach-notification"],"status":"enacted","citation":"S.C. 2026, c. 9 (Bill C-8, 45th Parl., 1st Sess.)","enactedDate":"2026-06-15","effectiveDate":"","summary":"Requires designated operators in federally regulated critical sectors to establish cyber security programs, mitigate supply-chain risks, report cyber incidents and comply with government cyber security directions; also amends the Telecommunications Act to let government order telecom providers to secure their networks.","appliesTo":"Designated operators in classes listed in the Act's schedule for vital federal services and systems: finance/banking, telecommunications, energy (pipelines, nuclear, interprovincial power) and transportation.","penalties":"Administrative monetary penalties and offences under the CCSPA; exact maxima in the final text not verified here.","enforcer":"Sector regulators (e.g. OSFI, CRTC, CER, CNSC, Transport Canada) and the Minister of Public Safety; Communications Security Establishment receives incident reports","sourceUrl":"https://www.parl.ca/legisinfo/en/bill/45-1/c-8","extraSources":["https://www.parl.ca/DocumentViewer/en/45-1/bill/C-8/royal-assent","https://www.canada.ca/en/public-safety-canada/news/2026/06/government-of-canada-strengthens-cyber-security-and-critical-infrastructure-with-royal-assent-of-bill-c8.html"],"notes":"Parliament's LEGISinfo lists Royal Assent on 15 June 2026; the Public Safety Canada news release is dated 16 June 2026. The CCSPA itself comes into force by order in council in phases; no date announced as of late July 2026. Predecessor C-26 proposed 72-hour incident reporting and AMPs up to CAD 15M for organisations; final figures not verified.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-22 20:04:22","sourceType":"official","verifiedBy":"research from official sources","deadlines":[{"id":16,"regulationId":"ca-ccspa","date":"2025-06-18","title":"Bill C-8 introduced","description":"First reading in the House of Commons.","kind":"transition","sourceUrl":"https://www.parl.ca/legisinfo/en/bill/45-1/c-8","tentative":false,"review":"verified"},{"id":17,"regulationId":"ca-ccspa","date":"2026-06-15","title":"Royal Assent","description":"Bill C-8 receives Royal Assent (S.C. 2026, c. 9); Telecommunications Act amendments take effect.","kind":"effective","sourceUrl":"https://www.parl.ca/legisinfo/en/bill/45-1/c-8","tentative":false,"review":"verified"}]},{"id":"cl-pdpl","name":"Ley Nº 21.719 que regula la protección y el tratamiento de los datos personales y crea la Agencia de Protección de Datos Personales","shortName":"Chile Personal Data Protection Law (Ley 21.719)","jurisdiction":"cl","jurisdictionName":"Chile","region":"americas","topics":["privacy","breach-notification"],"status":"enacted","citation":"Ley Nº 21.719 (Diario Oficial 13 Dec 2024)","enactedDate":"2024-11-25","effectiveDate":"2026-12-01","summary":"Replaces Chile's 1999 data law with a GDPR-style regime: legal bases, data subject rights (including portability and objection to automated decisions), security and breach notification, international transfer rules, a voluntary compliance (crime-prevention-style) model, and a new independent Personal Data Protection Agency.","appliesTo":"Controllers and processors established in Chile, and those outside Chile offering goods/services to or monitoring individuals in Chile. No size threshold (graduated fines for small businesses).","penalties":"Fines up to 5,000 UTM (minor), 10,000 UTM (serious) and 20,000 UTM (very serious) infringements; repeat serious/very serious infringements by larger companies can reach a percentage of annual revenue (up to 4%) per secondary sources.","enforcer":"Agencia de Protección de Datos Personales","sourceUrl":"https://www.bcn.cl/leychile/navegar?idNorma=1209272","extraSources":["https://www.senado.cl/appsenado/index.php?mo=tramitacion&ac=getDocto&iddocto=19307&tipodoc=mensaje_mocion","https://lawwwing.com/la-nueva-era-de-la-proteccion-de-datos-en-chile-que-cambia-con-la-ley-21-719/"],"notes":"Fact-check 2026-09-22 against BCN LeyChile metadata: promulgated 25 Nov 2024 ('Santiago, 25 de noviembre de 2024'), published in the Diario Oficial 13 Dec 2024, deferred entry into force 1 Dec 2026 (first day of the 24th month after publication, transitional Art 1). Pending amendment: government bill Boletin 18623-07 (filed 1 Sep 2026 with 'suma' urgency, Senate Constitution Committee first report stage) would postpone entry into force to 1 Dec 2027 and require the Agency's first board appointments at least 12 months before; a separate member's bill 18060-07 (Jan 2026) is also in committee. Until enacted, 1 Dec 2026 remains the legal date.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-22 20:04:22","sourceType":"official","verifiedBy":"research from official sources","deadlines":[{"id":26,"regulationId":"cl-pdpl","date":"2024-12-13","title":"Published in Diario Oficial","description":"Law 21.719 published; 24-month vacatio legis begins.","kind":"effective","sourceUrl":"https://www.bcn.cl/leychile/navegar?idNorma=1209272","tentative":false,"review":"verified"},{"id":27,"regulationId":"cl-pdpl","date":"2026-12-01","title":"Law in force","description":"Main obligations apply and the Personal Data Protection Agency begins supervision.","kind":"effective","sourceUrl":"https://www.bcn.cl/leychile/navegar?idNorma=1209272","tentative":false,"review":"verified"},{"id":28,"regulationId":"cl-pdpl","date":"2027-12-01","title":"Proposed postponement of entry into force","description":"Government bill Boletin 18623-07 (filed 1 Sep 2026, 'suma' urgency) would replace the 24-month vacatio legis in transitional Art 1 with a fixed date of 1 Dec 2027; in first committee stage in the Senate, not law.","kind":"effective","sourceUrl":"https://tramitacion.senado.cl/appsenado/templates/tramitacion/index.php?boletin_ini=18623-07","tentative":true,"review":"verified"}]},{"id":"cn-ai-labeling","name":"Measures for Labeling AI-Generated Synthetic Content","shortName":"China AI Content Labeling Measures","jurisdiction":"cn","jurisdictionName":"China","region":"apac","topics":["ai","online-safety"],"status":"in_force","citation":"Joint notice of CAC, MIIT, Ministry of Public Security and NRTA (14 Mar 2025)","enactedDate":"2025-03-14","effectiveDate":"2025-09-01","summary":"Requires generative AI service providers to add explicit (visible) labels to AI-generated text, images, audio, video and virtual scenes, and implicit labels (metadata) to generated files. Content distribution platforms must detect and label AI-generated content, and app stores must check labeling functions when apps are listed. A mandatory national standard (GB 45438-2025) takes effect on the same date.","appliesTo":"Internet information service providers in China that provide generative AI, deep synthesis, or content distribution services, and app distribution platforms.","penalties":"No standalone fines; violations are handled under existing laws and regulations (CSL, generative AI and deep synthesis rules). CAC ran enforcement actions against non-compliant apps in November 2025.","enforcer":"CAC with MIIT, Ministry of Public Security and National Radio and Television Administration","sourceUrl":"https://www.cac.gov.cn/2025-03/14/c_1743654684782215.htm","extraSources":["https://www.cac.gov.cn/2025-03/14/c_1743654685899683.htm","https://www.cac.gov.cn/2025-11/25/c_1765795550841819.htm"],"notes":"Official notice document number not captured here.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-22 20:04:22","sourceType":"official","verifiedBy":"research from official sources","deadlines":[{"id":29,"regulationId":"cn-ai-labeling","date":"2025-09-01","title":"AI content labeling measures and GB 45438-2025 take effect","description":"Explicit and implicit labeling duties for AI-generated content and platform detection duties apply.","kind":"effective","sourceUrl":"https://www.cac.gov.cn/2025-03/14/c_1743654684782215.htm","tentative":false,"review":"verified"}]},{"id":"cn-algorithm-recommendation","name":"Provisions on the Administration of Algorithmic Recommendation in Internet Information Services","shortName":"China Algorithmic Recommendation Provisions","jurisdiction":"cn","jurisdictionName":"China","region":"apac","topics":["ai","online-safety","privacy"],"status":"in_force","citation":"CAC Order No. 9 (joint with MIIT, MPS, SAMR)","enactedDate":"2021-11-16","effectiveDate":"2022-03-01","summary":"Regulates recommendation, ranking, personalization, generation and dispatch algorithms used in internet services in China. Users must be able to switch off personalized recommendations and manage tags, and providers may not use algorithms for price discrimination or to induce addiction. Providers with public opinion attributes or social mobilization capacity must file their algorithms with the CAC within 10 working days of launching a service.","appliesTo":"Providers using algorithmic recommendation technology to deliver internet information services in China.","penalties":"Warnings, public criticism and rectification orders; for refusal or serious cases, suspension of information updates and fines of RMB 10,000 to 100,000.","enforcer":"CAC with MIIT, MPS and SAMR","sourceUrl":"https://www.cac.gov.cn/2022-01/04/c_1642894606364259.htm","extraSources":["http://www.gov.cn/gongbao/content/2022/content_5682428.htm"],"notes":"Adopted by CAC on 2021-11-16 (used as enacted_date) and published 2022-01-04. The algorithm filing system is also used for generative AI, deep synthesis and anthropomorphic AI services.","lastVerified":"2026-09-25","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-25 11:14:17","sourceType":"official","verifiedBy":"research from official sources (2026-09-25)","deadlines":[{"id":6975,"regulationId":"cn-algorithm-recommendation","date":"2022-03-01","title":"Algorithmic recommendation provisions take effect","description":"User opt-out, transparency and algorithm filing duties apply.","kind":"effective","sourceUrl":"https://www.cac.gov.cn/2022-01/04/c_1642894606364259.htm","tentative":false,"review":"verified"}]},{"id":"cn-anthropomorphic-ai","name":"Interim Measures for the Management of Anthropomorphic AI Interaction Services","shortName":"China Anthropomorphic AI Measures","jurisdiction":"cn","jurisdictionName":"China","region":"apac","topics":["ai","children","online-safety","privacy"],"status":"in_force","citation":"CAC Order No. 21 (joint with NDRC, MIIT, MPS, SAMR)","enactedDate":"2026-04-10","effectiveDate":"2026-07-15","summary":"Regulates AI companion and emotional interaction services that simulate human personality. Providers must tell users they are talking to AI, remind users after every 2 hours of use, intervene in crises such as self-harm, offer easy exit, and may not offer virtual partner or relative services to minors. Users' interaction data may not be shared or used for training on sensitive data without consent, and services with 1 million registered or 100,000 monthly active users need a security assessment filed with the provincial CAC.","appliesTo":"Providers of AI services that offer continuing emotional interaction (companionship, care, support) to the public in China. Customer service, Q&A, work, education and research assistants without continuing emotional interaction are excluded.","penalties":"Where no law applies: warnings, rectification, suspension of registrations; for refusal or serious cases, service shutdown and fines of RMB 10,000 to 100,000, rising to RMB 100,000 to 200,000 where harm to life or health results.","enforcer":"CAC with NDRC, MIIT, MPS and SAMR","sourceUrl":"https://www.cac.gov.cn/2026-04/10/c_1777558395078289.htm","extraSources":["https://www.gov.cn/gongbao/2026/issue_12806/202606/content_7072472.html"],"notes":"Adopted by CAC on 2026-02-02, signed and published 2026-04-10. Algorithm filings under the Algorithmic Recommendation Provisions are verified annually.","lastVerified":"2026-09-25","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-25 11:14:17","sourceType":"official","verifiedBy":"research from official sources (2026-09-25)","deadlines":[{"id":6987,"regulationId":"cn-anthropomorphic-ai","date":"2026-07-15","title":"Anthropomorphic AI measures take effect","description":"AI disclosure, usage reminders, minor protection, data and security assessment duties apply.","kind":"effective","sourceUrl":"https://www.cac.gov.cn/2026-04/10/c_1777558395078289.htm","tentative":false,"review":"verified"}]},{"id":"cn-cross-border","name":"Provisions on Promoting and Regulating Cross-Border Data Flows (CAC Order No. 16)","shortName":"China Cross-Border Data Flow Provisions","jurisdiction":"cn","jurisdictionName":"China","region":"apac","topics":["data-residency","privacy"],"status":"in_force","citation":"CAC Order No. 16","enactedDate":"2024-03-22","effectiveDate":"2024-03-22","summary":"Relaxes China's data export regime by exempting common transfers (contracts with the individual, cross-border HR, emergencies, and non-CII transfers of PI of fewer than 100,000 people a year) and setting volume thresholds for when a CAC security assessment, standard contract or certification is needed. Data is not 'important data' unless regulators have notified or published it as such.","appliesTo":"Data processors exporting data from China. Non-CII processors: fewer than 100,000 individuals' non-sensitive PI per year is exempt (Art. 5); 100,000 to under 1 million non-sensitive PI, or fewer than 10,000 individuals' sensitive PI, needs a standard contract or certification (Art. 8); 1 million+ non-sensitive PI, 10,000+ sensitive PI, or any important data needs a CAC security assessment (Art. 7). CII operators exporting PI or important data always need an assessment.","penalties":"Enforced through PIPL, DSL and CSL penalties (e.g. PIPL up to RMB 50 million or 5% of turnover; DSL up to RMB 10 million for serious unlawful important-data exports).","enforcer":"Cyberspace Administration of China (national and provincial)","sourceUrl":"https://www.cac.gov.cn/2024-03/22/c_1712776611775634.htm","extraSources":["https://www.cac.gov.cn/2024-03/22/c_1712776612187994.htm"],"notes":"Counts are cumulative from 1 January of each year. Free trade zones may issue negative lists. Security assessment approvals last 3 years and may be extended on application.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-22 20:04:22","sourceType":"official","verifiedBy":"research from official sources","deadlines":[{"id":30,"regulationId":"cn-cross-border","date":"2024-03-22","title":"Cross-border data flow provisions take effect","description":"Exemptions and volume thresholds apply from publication (Art. 14); security assessment results are valid for 3 years (Art. 9).","kind":"effective","sourceUrl":"https://www.cac.gov.cn/2024-03/22/c_1712776611775634.htm","tentative":false,"review":"verified"}]},{"id":"cn-incident-reporting","name":"Administrative Measures for National Cybersecurity Incident Reporting","shortName":"China Cyber Incident Reporting Measures","jurisdiction":"cn","jurisdictionName":"China","region":"apac","topics":["cybersecurity","breach-notification"],"status":"in_force","citation":"CAC measures of 11 September 2025","enactedDate":"2025-09-11","effectiveDate":"2025-11-01","summary":"Requires network operators in China to grade cybersecurity incidents using an annexed grading guide and report incidents rated relatively major or above. CII operators must report within 1 hour, central government bodies within 2 hours, and other operators to the provincial CAC within 4 hours. A full post-incident report is due within 30 days after handling ends, and ransom demands must be disclosed.","appliesTo":"Network owners, managers and network service providers that build or operate networks or provide services over networks in China.","penalties":"Penalties under the CSL and other laws for failure to report; heavier penalties for late, missing, false or concealed reports that cause serious harm. Liability may be reduced where operators took reasonable measures and reported on time.","enforcer":"Cyberspace Administration of China (CAC) and provincial CAC offices, with MPS and sector regulators","sourceUrl":"https://www.cac.gov.cn/2025-09/15/c_1759583017717009.htm","extraSources":[],"notes":"Issued by CAC on 2025-09-11 and published 2025-09-15 as a normative document without an order number. Sector rules such as the PBOC incident reporting measures apply in addition.","lastVerified":"2026-09-25","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-25 11:14:17","sourceType":"official","verifiedBy":"research from official sources (2026-09-25)","deadlines":[{"id":6982,"regulationId":"cn-incident-reporting","date":"2025-11-01","title":"Incident reporting measures take effect","description":"1, 2 and 4 hour reporting windows apply to relatively major and higher incidents.","kind":"effective","sourceUrl":"https://www.cac.gov.cn/2025-09/15/c_1759583017717009.htm","tentative":false,"review":"verified"}]},{"id":"cn-csl","name":"Cybersecurity Law of the People's Republic of China (as amended by the NPC Standing Committee Decision of 28 October 2025)","shortName":"China Cybersecurity Law","jurisdiction":"cn","jurisdictionName":"China","region":"apac","topics":["cybersecurity","data-residency","ai","privacy"],"status":"amended","citation":"Order of the President No. 53 (2016); amended by Decision of the 14th NPC Standing Committee, 18th session, 28 Oct 2025","enactedDate":"2016-11-07","effectiveDate":"2017-06-01","summary":"China's base cybersecurity statute: multi-level protection scheme duties for network operators, localization and security review duties for critical information infrastructure (CII) operators, and content controls. The 2025 amendment, in force from 1 January 2026, adds AI governance support, ties PI processing to PIPL, allows fines on first violations and sharply raises maximum fines.","appliesTo":"All network operators in China (owners, managers and service providers of networks); stricter duties for CII operators. Amended Art. 77 allows sanctions such as asset freezes on foreign organizations whose activities endanger China's cybersecurity.","penalties":"Post-amendment (Art. 61): network operators RMB 10,000-50,000 on a first violation, RMB 50,000-500,000 for refusal to correct; CII operators RMB 50,000-100,000 rising to RMB 100,000-1 million. Serious harm (e.g. large data leaks): RMB 500,000-2 million; particularly serious harm: RMB 2-10 million, with responsible individuals fined up to RMB 1 million. Using unreviewed network products in CII: 1-10x the purchase amount.","enforcer":"CAC, Ministry of Public Security, MIIT and sector regulators","sourceUrl":"https://www.gov.cn/yaowen/liebiao/202510/content_7046194.htm","extraSources":[],"notes":"Amendment adopted 2025-10-28 and effective 2026-01-01, per the official Decision text on gov.cn. The original 2016 enactment date comes from the 2016 promulgation, not re-verified here.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-22 20:04:22","sourceType":"official","verifiedBy":"research from official sources","deadlines":[{"id":31,"regulationId":"cn-csl","date":"2017-06-01","title":"Cybersecurity Law takes effect","description":"Original CSL obligations for network operators and CII operators apply.","kind":"effective","sourceUrl":"https://www.gov.cn/yaowen/liebiao/202510/content_7046194.htm","tentative":false,"review":"verified"},{"id":32,"regulationId":"cn-csl","date":"2026-01-01","title":"2025 amendments take effect","description":"Higher fines, first-violation fines, AI governance provisions and PIPL-alignment duties apply under the 28 Oct 2025 NPCSC Decision.","kind":"effective","sourceUrl":"https://www.gov.cn/yaowen/liebiao/202510/content_7046194.htm","tentative":false,"review":"verified"}]},{"id":"cn-sa-measures","name":"Measures for the Security Assessment of Outbound Data Transfers","shortName":"China Data Export Security Assessment Measures","jurisdiction":"cn","jurisdictionName":"China","region":"apac","topics":["data-residency","privacy","cybersecurity"],"status":"in_force","citation":"CAC Order No. 11","enactedDate":"2022-07-07","effectiveDate":"2022-09-01","summary":"Sets the CAC security assessment that must be passed before certain data leaves China, including exports of important data and large-scale personal information exports. Data handlers must run a self-assessment, then apply through the provincial CAC for a national CAC review. Transfers already under way had six months to come into compliance.","appliesTo":"Data handlers exporting important data, CII operators exporting personal information, and handlers exporting personal information above the volume thresholds set by the CAC.","penalties":"Handled under the CSL, DSL and PIPL. PIPL fines reach RMB 50 million or 5% of prior-year turnover for serious violations.","enforcer":"Cyberspace Administration of China (CAC)","sourceUrl":"https://www.cac.gov.cn/2022-07/07/c_1658811536396503.htm","extraSources":["http://www.gov.cn/gongbao/content/2022/content_5707283.htm"],"notes":"The 2024 Provisions on Promoting and Regulating Cross-Border Data Flows (cn-cross-border) raised the thresholds and extended approval validity from 2 to 3 years. Signed 2022-07-07.","lastVerified":"2026-09-25","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-25 11:14:17","sourceType":"official","verifiedBy":"research from official sources (2026-09-25)","deadlines":[{"id":6977,"regulationId":"cn-sa-measures","date":"2022-09-01","title":"Security assessment measures take effect","description":"Covered data exports require a CAC security assessment.","kind":"effective","sourceUrl":"https://www.cac.gov.cn/2022-07/07/c_1658811536396503.htm","tentative":false,"review":"verified"},{"id":6978,"regulationId":"cn-sa-measures","date":"2023-03-01","title":"Remediation window for existing transfers ends","description":"Existing exports had to be remediated within six months of 2022-09-01. The exact end date is computed, not stated.","kind":"transition","sourceUrl":"https://www.cac.gov.cn/2022-07/07/c_1658811536396503.htm","tentative":true,"review":"verified"}]},{"id":"cn-dsl","name":"Data Security Law of the People's Republic of China","shortName":"China Data Security Law","jurisdiction":"cn","jurisdictionName":"China","region":"apac","topics":["cybersecurity","data-residency","data-access"],"status":"in_force","citation":"Order of the President of the PRC No. 84","enactedDate":"2021-06-10","effectiveDate":"2021-09-01","summary":"Sets up China's data classification and grading system, with heightened protection for 'important data' and 'core data'. Requires data processors to run data security management systems, risk monitoring and incident handling, and restricts giving data stored in China to foreign judicial or law-enforcement bodies without approval.","appliesTo":"All organizations and individuals carrying out data processing activities in China, plus offshore activities that harm China's national security or public interest. Important-data processors must appoint a data security officer and submit periodic risk assessments.","penalties":"Failure to meet security duties: up to RMB 500,000, rising to RMB 500,000-2 million for refusal to correct or serious consequences such as large data leaks (Art. 45). Violating the national core data regime: RMB 2-10 million plus suspension or license revocation. Unlawful export of important data: RMB 100,000-1 million, up to RMB 10 million if serious (Art. 46).","enforcer":"Sector regulators, public security and national security authorities; CAC coordinates network data security","sourceUrl":"http://www.cac.gov.cn/2021-06/11/c_1624994566919140.htm","extraSources":[],"notes":"Important-data catalogs are issued by region and sector; the Network Data Security Management Regulations (effective 2025-01-01) detail important-data processor duties such as annual risk assessments.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-22 20:04:22","sourceType":"official","verifiedBy":"research from official sources","deadlines":[{"id":33,"regulationId":"cn-dsl","date":"2021-09-01","title":"Data Security Law takes effect","description":"Data classification, important-data protection and data export restrictions apply (Art. 55).","kind":"effective","sourceUrl":"http://www.cac.gov.cn/2021-06/11/c_1624994566919140.htm","tentative":false,"review":"verified"}]},{"id":"cn-data-risk-assessment","name":"Measures for Network Data Security Risk Assessment","shortName":"China Data Security Risk Assessment Measures","jurisdiction":"cn","jurisdictionName":"China","region":"apac","topics":["cybersecurity","privacy"],"status":"in_force","citation":"CAC Order No. 24 (joint with MIIT, MPS)","enactedDate":"2026-06-18","effectiveDate":"2026-08-20","summary":"Implements the annual risk assessment duty for important data handlers under the DSL and Network Data Security Regulations. Important data handlers must assess risk every year and submit the report to their regulator within 20 working days of finishing; general data handlers are encouraged to assess at least every 3 years. Regulators can order an assessment by a certified third party after serious risks or large leaks.","appliesTo":"Network data handlers in China, with mandatory annual assessments for handlers of important data.","penalties":"Handled under the DSL and Network Data Security Regulations. Regulators may order handlers to stop processing important data if they fail to remediate.","enforcer":"CAC with MIIT, MPS and sector regulators","sourceUrl":"https://www.cac.gov.cn/2026-06/18/c_1783525609815499.htm","extraSources":["https://www.gov.cn/gongbao/2026/issue_12946/202608/content_7079356.html"],"notes":"Adopted 2026-06-01, signed and published 2026-06-18. The same assessor may not run more than 3 consecutive annual assessments for one handler. Reports must be kept at least 3 years.","lastVerified":"2026-09-25","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-25 11:14:17","sourceType":"official","verifiedBy":"research from official sources (2026-09-25)","deadlines":[{"id":6988,"regulationId":"cn-data-risk-assessment","date":"2026-08-20","title":"Risk assessment measures take effect","description":"Annual risk assessment and reporting duties for important data handlers apply.","kind":"effective","sourceUrl":"https://www.cac.gov.cn/2026-06/18/c_1783525609815499.htm","tentative":false,"review":"verified"}]},{"id":"cn-deep-synthesis","name":"Provisions on the Administration of Deep Synthesis in Internet Information Services","shortName":"China Deep Synthesis Provisions","jurisdiction":"cn","jurisdictionName":"China","region":"apac","topics":["ai","online-safety","biometrics"],"status":"in_force","citation":"CAC Order No. 12 (joint with MIIT, MPS)","enactedDate":"2022-11-25","effectiveDate":"2023-01-10","summary":"Regulates deepfakes and other deep synthesis services such as synthetic text, voice cloning, face swapping and immersive scenes. Providers must verify user identity, review content, add technical marks to generated content, and add prominent labels where content could confuse the public. Providers with public opinion attributes must file algorithms, and app stores must check filings and security assessments.","appliesTo":"Deep synthesis service providers, technical supporters, users, and app distribution platforms in China.","penalties":"Handled under existing laws and administrative regulations, with heavier penalties for serious consequences.","enforcer":"CAC with MIIT and MPS","sourceUrl":"https://www.cac.gov.cn/2022-12/11/c_1672221949354811.htm","extraSources":["http://www.gov.cn/gongbao/content/2023/content_5741257.htm"],"notes":"Adopted 2022-11-03, signed 2022-11-25 (used as enacted_date), published 2022-12-11. Labeling duties were further detailed by the 2025 AI content labeling measures (cn-ai-labeling).","lastVerified":"2026-09-25","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-25 11:14:17","sourceType":"official","verifiedBy":"research from official sources (2026-09-25)","deadlines":[{"id":6976,"regulationId":"cn-deep-synthesis","date":"2023-01-10","title":"Deep synthesis provisions take effect","description":"Labeling, identity verification and filing duties apply to deep synthesis services.","kind":"effective","sourceUrl":"https://www.cac.gov.cn/2022-12/11/c_1672221949354811.htm","tentative":false,"review":"verified"}]},{"id":"cn-facial-recognition","name":"Measures for the Security Management of Facial Recognition Technology Applications","shortName":"China Facial Recognition Measures","jurisdiction":"cn","jurisdictionName":"China","region":"apac","topics":["biometrics","privacy"],"status":"in_force","citation":"CAC and MPS Order No. 19","enactedDate":"2025-03-13","effectiveDate":"2025-06-01","summary":"Sets rules for using facial recognition to process face data in China. Handlers need a specific purpose and necessity, separate consent (guardian consent under 14), a prior impact assessment, local storage on the device unless consent or law allows otherwise, and a non-face alternative. Handlers storing face data of 100,000 people or more must file with the provincial CAC within 30 working days.","appliesTo":"Personal information handlers using facial recognition technology in China. Pure R&D and algorithm training are excluded.","penalties":"Handled under the PIPL and other laws; PIPL fines reach RMB 50 million or 5% of prior-year turnover for serious violations.","enforcer":"CAC and Ministry of Public Security","sourceUrl":"https://www.cac.gov.cn/2025-03/21/c_1744174262156096.htm","extraSources":["https://www.gov.cn/zhengce/zhengceku/202503/content_7016075.htm"],"notes":"Adopted by CAC on 2024-09-30, signed 2025-03-13, published 2025-03-21. Face recognition devices may not be installed in private spaces such as hotel rooms and changing rooms.","lastVerified":"2026-09-25","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-25 11:14:17","sourceType":"official","verifiedBy":"research from official sources (2026-09-25)","deadlines":[{"id":6986,"regulationId":"cn-facial-recognition","date":"2025-06-01","title":"Facial recognition measures take effect","description":"Consent, impact assessment, storage and filing duties apply.","kind":"effective","sourceUrl":"https://www.cac.gov.cn/2025-03/21/c_1744174262156096.htm","tentative":false,"review":"verified"}]},{"id":"cn-genai-measures","name":"Interim Measures for the Management of Generative Artificial Intelligence Services","shortName":"China Generative AI Measures","jurisdiction":"cn","jurisdictionName":"China","region":"apac","topics":["ai","online-safety","privacy"],"status":"in_force","citation":"CAC Order No. 15 (joint with NDRC, MOE, MOST, MIIT, MPS, NRTA)","enactedDate":"2023-07-10","effectiveDate":"2023-08-15","summary":"China's main rule for generative AI services offered to the public in China. Providers must use lawfully sourced training data, respect IP and personal information rights, label generated content, handle illegal content, and protect minors. Services with public opinion attributes or social mobilization capacity need a security assessment and algorithm filing.","appliesTo":"Organizations and individuals that provide generative AI services (text, image, audio, video) to the public in China, including via APIs. Internal R&D not offered to the public is excluded.","penalties":"Handled under the CSL, DSL, PIPL and Science and Technology Progress Law. Where no law applies, warnings, public criticism, rectification orders and suspension of service.","enforcer":"CAC with NDRC, MOE, MOST, MIIT, MPS and NRTA","sourceUrl":"https://www.cac.gov.cn/2023-07/13/c_1690898327029107.htm","extraSources":["https://www.gov.cn/gongbao/2023/issue_10666/202308/content_6900864.html"],"notes":"Adopted by CAC on 2023-05-23 and signed 2023-07-10 (the date used as enacted_date); published 2023-07-13. Security assessment and algorithm filing duties link to the Algorithmic Recommendation Provisions.","lastVerified":"2026-09-25","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-25 11:14:17","sourceType":"official","verifiedBy":"research from official sources (2026-09-25)","deadlines":[{"id":6974,"regulationId":"cn-genai-measures","date":"2023-08-15","title":"Generative AI measures take effect","description":"Training data, labeling, content and user protection duties apply to public generative AI services.","kind":"effective","sourceUrl":"https://www.cac.gov.cn/2023-07/13/c_1690898327029107.htm","tentative":false,"review":"verified"}]},{"id":"cn-minors-online-protection","name":"Regulations on the Protection of Minors Online","shortName":"China Minors Online Protection Regulations","jurisdiction":"cn","jurisdictionName":"China","region":"apac","topics":["children","privacy","online-safety"],"status":"in_force","citation":"State Council Decree No. 766","enactedDate":"2023-10-16","effectiveDate":"2024-01-01","summary":"China's State Council regulation on online protection of minors. Platforms with huge numbers of minor users or significant influence on minors must run impact assessments, offer minor modes, set up independent oversight and publish annual reports. Handlers of minors' personal information must run annual compliance audits, and online services must have anti-addiction systems.","appliesTo":"Network product and service providers, personal information handlers, smart device makers and platforms whose services reach minors in China.","penalties":"Fines up to RMB 1 million for platform duties; for serious cases, up to RMB 50 million or 5% of prior-year turnover, business suspension or license revocation, and fines up to RMB 1 million for responsible managers.","enforcer":"CAC with press and publication, telecom, public security, culture and tourism, and broadcasting authorities","sourceUrl":"https://www.cac.gov.cn/2023-10/24/c_1699806932316206.htm","extraSources":["https://www.gov.cn/zhengce/zhengceku/202310/content_6911289.htm","https://www.cac.gov.cn/2026-01/23/c_1770728781060093.htm","https://www.cac.gov.cn/2026-02/28/c_1774010730056867.htm"],"notes":"Passed by the State Council on 2023-09-20, signed 2023-10-16, published 2023-10-24. Implementing measures were issued by CAC and other departments in 2025-12 and 2026-02.","lastVerified":"2026-09-25","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-25 11:14:17","sourceType":"official","verifiedBy":"research from official sources (2026-09-25)","deadlines":[{"id":6983,"regulationId":"cn-minors-online-protection","date":"2024-01-01","title":"Minors online protection regulations take effect","description":"Platform, content, personal information and anti-addiction duties apply.","kind":"effective","sourceUrl":"https://www.cac.gov.cn/2023-10/24/c_1699806932316206.htm","tentative":false,"review":"verified"},{"id":6984,"regulationId":"cn-minors-online-protection","date":"2026-03-01","title":"Classification measures for content harmful to minors take effect","description":"Implementing measures classify online information that may affect minors' physical and mental health.","kind":"effective","sourceUrl":"https://www.cac.gov.cn/2026-01/23/c_1770728781060093.htm","tentative":false,"review":"verified"},{"id":6985,"regulationId":"cn-minors-online-protection","date":"2026-04-01","title":"Measures identifying large or influential platforms for minors take effect","description":"Platforms meeting the thresholds (for example 10 million registered or 1 million monthly active minor users) must apply to be designated.","kind":"effective","sourceUrl":"https://www.cac.gov.cn/2026-02/28/c_1774010730056867.htm","tentative":false,"review":"verified"}]},{"id":"cn-network-data-regs","name":"Regulations on Network Data Security Management (State Council Order No. 790)","shortName":"China Network Data Security Regulations","jurisdiction":"cn","jurisdictionName":"China","region":"apac","topics":["privacy","cybersecurity","data-residency"],"status":"in_force","citation":"State Council Order No. 790","enactedDate":"2024-09-24","effectiveDate":"2025-01-01","summary":"Implementing regulations under the CSL, DSL and PIPL covering personal information, important data, cross-border data and platform duties. Processors of PI of 10 million+ people must also meet important-data processor duties, such as naming a security lead and filing annual risk assessments. Platforms must offer an easy opt-out from personalized recommendations.","appliesTo":"Network data processing activities in China, plus offshore processing of data of people in China that harms national security or public interest. Processors of PI of 10 million or more individuals take on the important-data duties in Arts. 30 and 32 (Art. 28). Important-data processors must file annual risk assessment reports with provincial-level regulators (Art. 33).","penalties":"Violating specified articles (e.g. Arts. 12, 16-20, 22, 40-42): warning and confiscation, and for refusal or serious cases fines up to RMB 1 million plus possible suspension or license revocation; responsible individuals RMB 10,000-100,000 (Art. 55). Other violations are punished under the CSL, DSL and PIPL.","enforcer":"CAC, telecom, public security and other competent departments","sourceUrl":"https://www.gov.cn/zhengce/content/202409/content_6977766.htm","extraSources":["https://www.cac.gov.cn/2024-09/30/c_1729384452307680.htm"],"notes":"Adopted at the State Council executive meeting of 2024-08-30, signed as Order No. 790 on 2024-09-24, published 2024-09-30. Annual risk assessment timing is 'each year' with no fixed calendar date.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-22 20:04:22","sourceType":"official","verifiedBy":"research from official sources","deadlines":[{"id":34,"regulationId":"cn-network-data-regs","date":"2025-01-01","title":"Network Data Regulations take effect","description":"All provisions, including the 10-million-person threshold duties and annual important-data risk assessments, apply.","kind":"effective","sourceUrl":"https://www.gov.cn/zhengce/content/202409/content_6977766.htm","tentative":false,"review":"verified"}]},{"id":"cn-pi-compliance-audit","name":"Administrative Measures for Personal Information Protection Compliance Audits (CAC Order No. 18)","shortName":"China PI Compliance Audit Measures","jurisdiction":"cn","jurisdictionName":"China","region":"apac","topics":["privacy"],"status":"in_force","citation":"CAC Order No. 18","enactedDate":"2025-02-14","effectiveDate":"2025-05-01","summary":"Implements PIPL Arts. 54 and 64: PI processors must audit their own PIPL compliance regularly, and regulators can order an audit by a professional firm when they find high risk or an incident. Processors of PI of more than 10 million people must audit at least once every two years.","appliesTo":"All personal information processors in China; mandatory biennial audits for processors handling PI of more than 10 million individuals. The related CAC Q&A ties the DPO requirement to processors handling PI of 1 million+ individuals.","penalties":"Penalties are imposed under the PIPL (up to RMB 50 million or 5% of prior-year turnover for serious violations).","enforcer":"CAC and departments with PI protection duties","sourceUrl":"https://www.cac.gov.cn/2025-02/14/c_1741233507681519.htm","extraSources":["https://www.cac.gov.cn/2025-02/14/c_1741232791991016.htm"],"notes":"The measures fix no calendar date for the first biennial audit. The 1-million DPO threshold comes from the CAC announcement and law-firm summaries, not re-read in the official text here.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-22 20:04:22","sourceType":"official","verifiedBy":"research from official sources","deadlines":[{"id":35,"regulationId":"cn-pi-compliance-audit","date":"2025-05-01","title":"PI compliance audit measures take effect","description":"Self-audit and regulator-ordered audit regime applies; 10M+ processors must audit at least every two years.","kind":"effective","sourceUrl":"https://www.cac.gov.cn/2025-02/14/c_1741233507681519.htm","tentative":false,"review":"verified"}]},{"id":"cn-pi-certification","name":"Measures for Personal Information Outbound Transfer Certification","shortName":"China PI Export Certification Measures","jurisdiction":"cn","jurisdictionName":"China","region":"apac","topics":["data-residency","privacy"],"status":"in_force","citation":"CAC and SAMR Order No. 20","enactedDate":"2025-10-14","effectiveDate":"2026-01-01","summary":"Sets the third route for exporting personal information from China: certification by an accredited certification body. Available to non-CII handlers exporting personal information of 100,000 to under 1 million people (non-sensitive) or under 10,000 people's sensitive data in a year. Certificates last three years; overseas handlers apply through a local entity or representative.","appliesTo":"Non-CII personal information handlers, including overseas handlers, exporting personal information from China within the certification thresholds.","penalties":"Handled under the PIPL, Network Data Security Regulations and Certification and Accreditation Regulations.","enforcer":"CAC and State Administration for Market Regulation (SAMR)","sourceUrl":"https://www.cac.gov.cn/2025-10/17/c_1762449728720008.htm","extraSources":["https://www.gov.cn/gongbao/2025/issue_12426/202511/content_7049740.html","https://www.gov.cn/zhengce/202510/content_7044902.htm"],"notes":"Adopted by CAC on 2025-07-21, signed 2025-10-14, published 2025-10-17. Renewal applications are due 6 months before a certificate expires.","lastVerified":"2026-09-25","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-25 11:14:17","sourceType":"official","verifiedBy":"research from official sources (2026-09-25)","deadlines":[{"id":6981,"regulationId":"cn-pi-certification","date":"2026-01-01","title":"PI export certification measures take effect","description":"The certification route for personal information exports applies.","kind":"effective","sourceUrl":"https://www.cac.gov.cn/2025-10/17/c_1762449728720008.htm","tentative":false,"review":"verified"}]},{"id":"cn-scc-measures","name":"Measures on the Standard Contract for Outbound Transfer of Personal Information","shortName":"China PI Export Standard Contract Measures","jurisdiction":"cn","jurisdictionName":"China","region":"apac","topics":["data-residency","privacy"],"status":"in_force","citation":"CAC Order No. 13","enactedDate":"2023-02-22","effectiveDate":"2023-06-01","summary":"Lets personal information handlers export personal information by signing China's standard contract with the overseas recipient instead of a security assessment, if volume limits are met. Handlers must do a personal information protection impact assessment and file the signed contract with the provincial CAC. Transfers already under way had six months to comply.","appliesTo":"Non-CII personal information handlers exporting personal information below the security assessment thresholds.","penalties":"Handled under the PIPL and related laws. PIPL fines reach RMB 50 million or 5% of prior-year turnover for serious violations.","enforcer":"Cyberspace Administration of China (CAC)","sourceUrl":"https://www.cac.gov.cn/2023-02/24/c_1678884830036813.htm","extraSources":["http://www.gov.cn/gongbao/content/2023/content_5752224.htm"],"notes":"The original thresholds (under 1 million people processed, under 100,000 exported) were changed by the 2024 cross-border provisions (cn-cross-border). Signed 2023-02-22, published 2023-02-24.","lastVerified":"2026-09-25","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-25 11:14:17","sourceType":"official","verifiedBy":"research from official sources (2026-09-25)","deadlines":[{"id":6979,"regulationId":"cn-scc-measures","date":"2023-06-01","title":"Standard contract measures take effect","description":"The standard contract route and filing duty apply.","kind":"effective","sourceUrl":"https://www.cac.gov.cn/2023-02/24/c_1678884830036813.htm","tentative":false,"review":"verified"},{"id":6980,"regulationId":"cn-scc-measures","date":"2023-12-01","title":"Remediation window for existing transfers ends","description":"Existing exports had to comply within six months of 2023-06-01. The exact end date is computed, not stated.","kind":"transition","sourceUrl":"https://www.cac.gov.cn/2023-02/24/c_1678884830036813.htm","tentative":true,"review":"verified"}]},{"id":"cn-pipl","name":"Personal Information Protection Law of the People's Republic of China","shortName":"China PIPL","jurisdiction":"cn","jurisdictionName":"China","region":"apac","topics":["privacy","data-residency","biometrics","children"],"status":"in_force","citation":"Order of the President of the PRC No. 91 (adopted by the 13th NPC Standing Committee, 30th session)","enactedDate":"2021-08-20","effectiveDate":"2021-11-01","summary":"China's comprehensive personal information law: requires a legal basis (usually consent) for processing, separate consent for sensitive data and cross-border transfers, PI impact assessments, and data subject rights. Applies extraterritorially to processing of data of people in China to provide products/services or analyze their behavior. Cross-border transfers need a CAC security assessment, standard contract, or certification.","appliesTo":"Any personal information processor handling PI of natural persons in China, including offshore processors that target or analyze people in China (must appoint a local representative). CII operators and processors reaching CAC-set volumes must store PI in China (Art. 40).","penalties":"Ordinary violations: rectification, confiscation of illegal gains, fines up to RMB 1 million (individuals responsible RMB 10,000-100,000). Serious violations: fines up to RMB 50 million or 5% of prior-year turnover, suspension of business or license revocation; responsible individuals RMB 100,000-1 million (Art. 66).","enforcer":"Cyberspace Administration of China (CAC) and other departments with PI protection duties at county level and above","sourceUrl":"http://www.cac.gov.cn/2021-08/20/c_1631050028355286.htm","extraSources":["https://www.gov.cn/yaowen/liebiao/202510/content_7046194.htm"],"notes":"Implementing rules layered on PIPL: Network Data Security Management Regulations (2025-01-01), PI Compliance Audit Measures (2025-05-01), cross-border data flow provisions (2024-03-22). The 2025 Cybersecurity Law amendment adds an express duty for network operators to follow PIPL when processing PI. Reports indicate CAC/SAMR measures on PI export certification took effect 2026-01-01; not verified against the official text here.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-22 20:04:22","sourceType":"official","verifiedBy":"research from official sources","deadlines":[{"id":36,"regulationId":"cn-pipl","date":"2021-11-01","title":"PIPL takes effect","description":"All PIPL obligations (legal bases, consent, cross-border rules, data subject rights) apply (Art. 74).","kind":"effective","sourceUrl":"http://www.cac.gov.cn/2021-08/20/c_1631050028355286.htm","tentative":false,"review":"verified"}]},{"id":"cn-small-pi-handlers","name":"Provisions on Simplified Personal Information Protection Measures for Small Personal Information Handlers","shortName":"China Small PI Handler Simplified Measures","jurisdiction":"cn","jurisdictionName":"China","region":"apac","topics":["privacy","data-residency"],"status":"in_force","citation":"CAC and MPS Order No. 25","enactedDate":"2026-07-22","effectiveDate":"2026-09-01","summary":"Eases PIPL compliance for handlers processing personal information of fewer than 100,000 people. They can use short notices, rely on platform privacy rules, run simplified compliance audits at least every five years using a self-check form, and use simplified impact assessments. It also exempts common cross-border transfers from the assessment, contract and certification routes and limits penalties for minor first violations.","appliesTo":"Personal information handlers in China that process personal information of fewer than 100,000 individuals.","penalties":"No penalty for minor, promptly corrected violations without harm; lighter penalties for self-reporting and cooperation. Repeated violations or incidents are handled under the PIPL and Network Data Security Regulations.","enforcer":"CAC and Ministry of Public Security","sourceUrl":"https://www.cac.gov.cn/2026-07/24/c_1786638889704872.htm","extraSources":[],"notes":"Adopted 2026-06-26, signed 2026-07-22, published 2026-07-24. Special rules still apply to children under 14 and to sensitive personal information.","lastVerified":"2026-09-25","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-25 11:14:17","sourceType":"official","verifiedBy":"research from official sources (2026-09-25)","deadlines":[{"id":6989,"regulationId":"cn-small-pi-handlers","date":"2026-09-01","title":"Simplified measures for small handlers take effect","description":"Small handlers may use simplified notice, audit and assessment methods.","kind":"effective","sourceUrl":"https://www.cac.gov.cn/2026-07/24/c_1786638889704872.htm","tentative":false,"review":"verified"}]},{"id":"coe-ai-convention","name":"Council of Europe Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law","shortName":"CoE AI Framework Convention","jurisdiction":"coe","jurisdictionName":"Council of Europe","region":"uk-europe","topics":["ai"],"status":"enacted","citation":"CETS No. 225","enactedDate":"2024-09-05","effectiveDate":"","summary":"First binding international treaty on AI. Parties must ensure AI activities across the lifecycle respect human rights, democracy and the rule of law, with risk and impact assessments, transparency, oversight and remedies. Each party chooses how to apply it to private actors.","appliesTo":"States and the EU that ratify it; obligations reach public authorities directly and private actors through each party's chosen measures.","penalties":"None in the treaty; implemented through national law.","enforcer":"Each party; Conference of the Parties monitors implementation.","sourceUrl":"https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:22026A01081","extraSources":["https://publications.europa.eu/resource/celex/22026A01081","https://eur-lex.europa.eu/eli/dec/2026/1080/oj/eng","https://publications.europa.eu/resource/celex/32026D1080","https://www.coe.int/en/web/conventions/full-list?module=treaty-detail&treatynum=225"],"notes":"Enters into force on the first day of the month after three months following the fifth ratification, including at least three Council of Europe member states (Article 30). Whether that threshold has been met could not be verified: the Council of Europe treaty office blocks automated access. The UK, Norway and Switzerland are signatories.","lastVerified":"2026-09-25","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-25 10:55:47","sourceType":"official","verifiedBy":"research from official sources (2026-09-25)","deadlines":[{"id":6878,"regulationId":"coe-ai-convention","date":"2024-09-05","title":"Opened for signature","description":"Convention opened for signature; the EU signed under Council Decision (EU) 2024/2218.","kind":"transition","sourceUrl":"https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:22026A01081","tentative":false,"review":"verified"},{"id":6879,"regulationId":"coe-ai-convention","date":"2026-04-21","title":"EU concludes the Convention","description":"Council Decision (EU) 2026/1080 approves conclusion on behalf of the EU (published 2026-05-13).","kind":"transition","sourceUrl":"https://eur-lex.europa.eu/eli/dec/2026/1080/oj/eng","tentative":false,"review":"verified"}]},{"id":"us-co-ai-act","name":"Colorado SB 24-205 (Consumer Protections for Artificial Intelligence), as delayed by SB 25B-004 and repealed and reenacted by SB 26-189 (Automated Decision-Making Technology)","shortName":"Colorado AI Act","jurisdiction":"us-co","jurisdictionName":"Colorado","region":"us-states","topics":["ai","privacy"],"status":"enacted","citation":"SB 24-205 (2024); SB 25B-004 (2025 1st Extraordinary Session); SB 26-189 (2026); C.R.S. Title 6, Art. 1, Part 17","enactedDate":"2024-05-17","effectiveDate":"2027-01-01","summary":"Colorado's 2024 high-risk AI law (risk-management programs, impact assessments) never took effect: it was delayed to June 30, 2026 and then repealed and reenacted by SB 26-189, signed May 14, 2026, as a narrower automated decision-making technology (ADMT) law. From January 1, 2027, developers must give deployers technical documentation (intended uses, training data categories, limitations) and deployers must notify consumers at the point of interaction, explain ADMT's role within 30 days after an adverse outcome, and offer data correction and meaningful human review. Impact-assessment and risk-management-program mandates were dropped; 3-year record retention remains.","appliesTo":"Developers and deployers of covered ADMT that processes personal data to materially influence consequential decisions about Colorado consumers in education, employment, housing, financial/lending services, insurance, health care and essential government services. No revenue or volume threshold identified. SB 26-189 removed the federally-regulated-entity exemptions in SB 24-205.","penalties":"Violations are deceptive trade practices under the Colorado Consumer Protection Act (civil penalties under C.R.S. 6-1-112). No private right of action. Until January 1, 2030 the AG must give a 60-day notice and opportunity to cure where a cure is possible.","enforcer":"Colorado Attorney General (exclusive)","sourceUrl":"https://leg.colorado.gov/bills/sb26-189","extraSources":["https://leg.colorado.gov/bills/sb24-205","https://leg.colorado.gov/bills/sb25b-004","https://coag.gov/ai/","https://www.consumerfinancemonitor.com/2026/05/12/colorado-rewrites-its-landmark-ai-law-unpacking-sb-26-189-and-what-it-means-for-businesses/","https://www.akingump.com/en/insights/ai-law-and-regulation-tracker/colorado-postpones-implementation-of-colorado-ai-act-sb-24-205"],"notes":"SB 24-205's high-risk AI obligations never became operative. SB 26-189 was signed May 14, 2026, which is why the June 30, 2026 date never took effect. Specific Colorado AG rulemaking hearing dates under SB 26-189 were not verified. The per-violation civil penalty amount comes from the general Colorado CPA and is not restated in SB 26-189.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-22 20:04:22","sourceType":"official","verifiedBy":"research from official sources","deadlines":[{"id":199,"regulationId":"us-co-ai-act","date":"2024-05-17","title":"SB 24-205 signed","description":"Governor Polis signs the original Colorado AI Act with a February 1, 2026 effective date.","kind":"effective","sourceUrl":"https://leg.colorado.gov/bills/sb24-205","tentative":false,"review":"verified"},{"id":200,"regulationId":"us-co-ai-act","date":"2025-08-28","title":"SB 25B-004 delays the act","description":"Special-session bill pushes the SB 24-205 effective date from February 1, 2026 to June 30, 2026.","kind":"transition","sourceUrl":"https://leg.colorado.gov/bills/sb25b-004","tentative":false,"review":"verified"},{"id":201,"regulationId":"us-co-ai-act","date":"2026-02-01","title":"Original effective date (superseded)","description":"Original SB 24-205 date; postponed by SB 25B-004, so no obligations applied.","kind":"transition","sourceUrl":"https://leg.colorado.gov/bills/sb24-205","tentative":false,"review":"verified"},{"id":202,"regulationId":"us-co-ai-act","date":"2026-05-14","title":"SB 26-189 signed (repeal and reenact)","description":"SB 26-189 replaces SB 24-205 with a narrower ADMT disclosure framework and moves the effective date to January 1, 2027.","kind":"transition","sourceUrl":"https://leg.colorado.gov/bills/sb26-189","tentative":false,"review":"verified"},{"id":203,"regulationId":"us-co-ai-act","date":"2026-06-30","title":"Delayed effective date (superseded)","description":"SB 25B-004 date; superseded by SB 26-189 before it arrived, so no obligations applied.","kind":"transition","sourceUrl":"https://leg.colorado.gov/bills/sb25b-004","tentative":false,"review":"verified"},{"id":204,"regulationId":"us-co-ai-act","date":"2027-01-01","title":"ADMT obligations apply","description":"Developer documentation, consumer notices, post-adverse-outcome disclosure, correction and human-review rights take effect.","kind":"effective","sourceUrl":"https://leg.colorado.gov/bills/sb26-189","tentative":false,"review":"verified"},{"id":205,"regulationId":"us-co-ai-act","date":"2027-01-01","title":"AG rules due","description":"Attorney General must adopt rules clarifying the post-adverse-outcome disclosure requirements.","kind":"compliance","sourceUrl":"https://leg.colorado.gov/bills/sb26-189","tentative":false,"review":"verified"},{"id":206,"regulationId":"us-co-ai-act","date":"2030-01-01","title":"Mandatory cure period ends","description":"The AG's obligation to offer a 60-day notice-and-cure period expires.","kind":"sunset","sourceUrl":"https://leg.colorado.gov/bills/sb26-189","tentative":false,"review":"verified"}]},{"id":"us-co-cpa","name":"Colorado Privacy Act (SB 21-190), C.R.S. 6-1-1301 et seq., as amended by HB 24-1130, SB 24-041 and SB 25-276","shortName":"Colorado Privacy Act (CPA)","jurisdiction":"us-co","jurisdictionName":"Colorado","region":"us-states","topics":["privacy","children","biometrics"],"status":"amended","citation":"SB 21-190 (2021 Colo. Sess. Laws ch. 483); C.R.S. 6-1-1301 to 6-1-1313; 4 CCR 904-3 (CPA Rules)","enactedDate":"2021-07-07","effectiveDate":"2023-07-01","summary":"Comprehensive privacy law giving Colorado consumers rights to access, correct, delete, port and opt out of targeted advertising, sale and certain profiling, with mandatory recognition of universal opt-out mechanisms and data protection assessments for high-risk processing. 2024 amendments added biometric identifier duties (July 1, 2025) and heightened protections for minors under 18 (Oct 1, 2025); 2025's SB 25-276 expanded precise geolocation rules and requires consent before selling sensitive data.","appliesTo":"Controllers doing business in Colorado or targeting Colorado residents that control or process personal data of 100,000+ consumers per year, or derive revenue or discounts from selling personal data and process personal data of 25,000+ consumers. Biometric provisions (HB 24-1130) and minors' provisions (SB 24-041) apply regardless of these volume thresholds.","penalties":"Violations are deceptive trade practices under the Colorado Consumer Protection Act: civil penalties up to $20,000 per violation (up to $50,000 per violation against an elderly person), per C.R.S. 6-1-112. 60-day cure period applied only until Jan 1, 2025.","enforcer":"Colorado Attorney General and district attorneys","sourceUrl":"https://leg.colorado.gov/bills/sb21-190","extraSources":["https://leg.colorado.gov/bills/hb24-1130","https://leg.colorado.gov/bills/sb24-041","https://leg.colorado.gov/bills/sb25-276","https://coag.gov/resources/colorado-privacy-act/"],"notes":"CO AG site (coag.gov) could not be fetched directly during verification; dates taken from leg.colorado.gov bill pages. The separate Colorado AI Act (SB 24-205, rewritten 2026) is a distinct law not covered here. No 2026 CPA amendments were confirmed; web search budget ran out before a full 2026 session check.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-22 20:04:22","sourceType":"official","verifiedBy":"research from official sources","deadlines":[{"id":207,"regulationId":"us-co-cpa","date":"2023-07-01","title":"CPA takes effect","description":"Core consumer rights and controller duties apply.","kind":"effective","sourceUrl":"https://leg.colorado.gov/bills/sb21-190","tentative":false,"review":"verified"},{"id":208,"regulationId":"us-co-cpa","date":"2024-07-01","title":"Universal opt-out mechanism recognition required","description":"Controllers must honor AG-recognized universal opt-out mechanisms (e.g. Global Privacy Control).","kind":"compliance","sourceUrl":"https://leg.colorado.gov/bills/sb21-190","tentative":false,"review":"verified"},{"id":209,"regulationId":"us-co-cpa","date":"2025-01-01","title":"60-day cure period expires","description":"Mandatory 60-day notice-and-cure before AG enforcement ends; enforcement may proceed without cure.","kind":"enforcement","sourceUrl":"https://leg.colorado.gov/bills/sb21-190","tentative":false,"review":"verified"},{"id":210,"regulationId":"us-co-cpa","date":"2025-05-23","title":"SB 25-276 geolocation and sensitive-data sale amendment effective","description":"Adds precise geolocation data definitions and prohibits selling sensitive data without consent (effective on signature).","kind":"effective","sourceUrl":"https://leg.colorado.gov/bills/sb25-276","tentative":false,"review":"verified"},{"id":211,"regulationId":"us-co-cpa","date":"2025-07-01","title":"Biometric identifier amendment (HB 24-1130) effective","description":"Any controller processing biometric identifiers must adopt a written biometric policy, give notice, obtain consent and follow retention/deletion rules.","kind":"effective","sourceUrl":"https://leg.colorado.gov/bills/hb24-1130","tentative":false,"review":"verified"},{"id":212,"regulationId":"us-co-cpa","date":"2025-10-01","title":"Minors' data amendment (SB 24-041) effective","description":"Controllers offering online services to minors must use reasonable care, conduct assessments, and obtain consent for targeted ads, sale and certain profiling of minors.","kind":"effective","sourceUrl":"https://leg.colorado.gov/bills/sb24-041","tentative":false,"review":"verified"}]},{"id":"us-ct-ctdpa","name":"Connecticut Data Privacy Act (Public Act 22-15), Conn. Gen. Stat. 42-515 et seq., as amended by Public Act 25-113 (SB 1295) and Public Act 26-64 (SB 4)","shortName":"Connecticut Data Privacy Act (CTDPA)","jurisdiction":"us-ct","jurisdictionName":"Connecticut","region":"us-states","topics":["privacy","children","ai","health"],"status":"amended","citation":"Public Act 22-15 (SB 6, 2022); Conn. Gen. Stat. 42-515 to 42-526; PA 25-113; PA 26-64","enactedDate":"2022-05-10","effectiveDate":"2023-07-01","summary":"Comprehensive privacy law with access, correction, deletion, portability and opt-out rights. PA 25-113 (effective July 1, 2026) sharply lowered applicability thresholds, broadened sensitive data, added profiling impact assessments, and requires disclosure of whether personal data is used to train large language models. PA 26-64 (effective Oct 1, 2026) bans the sale of precise geolocation data and creates a data broker registry (registration required from Jan 1, 2027) and a state deletion mechanism brokers must honor from Oct 1, 2028.","appliesTo":"From July 1, 2026: entities doing business in Connecticut or targeting residents that in the preceding calendar year (1) controlled or processed personal data of 35,000+ consumers (excluding payment-only data), (2) controlled or processed any consumers' sensitive data, or (3) offered consumers' personal data for sale. Before July 1, 2026: 100,000+ consumers, or 25,000+ consumers and more than 25% of gross revenue from selling personal data.","penalties":"Violations are unfair trade practices under CUTPA; civil penalties up to $5,000 per willful violation, plus restitution and injunctive relief. Mandatory 60-day cure period ended Dec 31, 2024; AG now has discretion to offer a cure.","enforcer":"Connecticut Attorney General","sourceUrl":"https://www.cga.ct.gov/2025/ACT/PA/PDF/2025PA-00113-R00SB-01295-PA.PDF","extraSources":["https://www.cga.ct.gov/asp/cgabillstatus/cgabillstatus.asp?selBillType=Bill&which_year=2022&bill_num=6","https://www.cga.ct.gov/2026/ACT/PA/PDF/2026PA-00064-R00SB-00004-PA.PDF","https://www.cga.ct.gov/asp/cgabillstatus/cgabillstatus.asp?selBillType=Bill&which_year=2026&bill_num=4","https://www.wiley.law/alert-Major-Changes-to-Connecticut-Consumer-Privacy-Law-Will-Take-Effect-July-1-2026"],"notes":"PA 25-113 is an omnibus act (also covers broadband, gaming, social media). Opt-out preference signal date (Jan 1, 2025) and CUTPA $5,000 willful-violation penalty are from the original act/CUTPA and not re-verified line by line. The DCP must establish the deletion mechanism by July 1, 2028. Consumer health data and minors' provisions added by PA 23-56 (2023) are folded into this record.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-22 20:04:22","sourceType":"official","verifiedBy":"research from official sources","deadlines":[{"id":215,"regulationId":"us-ct-ctdpa","date":"2023-07-01","title":"CTDPA takes effect","description":"Core consumer rights and controller obligations apply.","kind":"effective","sourceUrl":"https://www.cga.ct.gov/asp/cgabillstatus/cgabillstatus.asp?selBillType=Bill&which_year=2022&bill_num=6","tentative":false,"review":"verified"},{"id":216,"regulationId":"us-ct-ctdpa","date":"2024-12-31","title":"Mandatory 60-day cure period expires","description":"After Dec 31, 2024, the AG is no longer required to offer a 60-day cure before enforcement; cure becomes discretionary.","kind":"enforcement","sourceUrl":"https://www.cga.ct.gov/asp/cgabillstatus/cgabillstatus.asp?selBillType=Bill&which_year=2022&bill_num=6","tentative":false,"review":"verified"},{"id":217,"regulationId":"us-ct-ctdpa","date":"2025-01-01","title":"Universal opt-out preference signals required","description":"Controllers must honor opt-out preference signals for targeted advertising and sale (effective Jan 1, 2025).","kind":"compliance","sourceUrl":"https://www.cga.ct.gov/asp/cgabillstatus/cgabillstatus.asp?selBillType=Bill&which_year=2022&bill_num=6","tentative":false,"review":"verified"},{"id":218,"regulationId":"us-ct-ctdpa","date":"2026-07-01","title":"PA 25-113 (SB 1295) amendments take effect","description":"Thresholds drop to 35,000 consumers or any sensitive-data processing or data sale; expanded sensitive data, minors' protections, and LLM-training disclosure in privacy notices.","kind":"effective","sourceUrl":"https://www.cga.ct.gov/2025/ACT/PA/PDF/2025PA-00113-R00SB-01295-PA.PDF","tentative":false,"review":"verified"},{"id":219,"regulationId":"us-ct-ctdpa","date":"2026-08-01","title":"Profiling impact assessments apply","description":"Impact assessment requirements apply to profiling activities created or generated on or after Aug 1, 2026 (Conn. Gen. Stat. 42-522 as amended).","kind":"compliance","sourceUrl":"https://www.cga.ct.gov/2025/ACT/PA/PDF/2025PA-00113-R00SB-01295-PA.PDF","tentative":false,"review":"verified"},{"id":220,"regulationId":"us-ct-ctdpa","date":"2026-10-01","title":"PA 26-64 (SB 4) amendments take effect","description":"Prohibits controllers and third parties from selling precise geolocation data and enacts data broker and other consumer protection provisions.","kind":"effective","sourceUrl":"https://www.cga.ct.gov/2026/ACT/PA/PDF/2026PA-00064-R00SB-00004-PA.PDF","tentative":false,"review":"verified"},{"id":221,"regulationId":"us-ct-ctdpa","date":"2027-01-01","title":"Data broker registration required","description":"Data brokers may not sell or license brokered personal data in Connecticut unless registered with the Department of Consumer Protection ($2,500 initial fee).","kind":"compliance","sourceUrl":"https://www.cga.ct.gov/2026/ACT/PA/PDF/2026PA-00064-R00SB-00004-PA.PDF","tentative":false,"review":"verified"},{"id":222,"regulationId":"us-ct-ctdpa","date":"2028-10-01","title":"Data brokers must process state deletion mechanism requests","description":"Registered data brokers must access the DCP accessible deletion mechanism at least every 45 days and process deletion requests.","kind":"compliance","sourceUrl":"https://www.cga.ct.gov/2026/ACT/PA/PDF/2026PA-00064-R00SB-00004-PA.PDF","tentative":false,"review":"verified"}]},{"id":"eu-cra","name":"Regulation (EU) 2024/2847 on horizontal cybersecurity requirements for products with digital elements (Cyber Resilience Act)","shortName":"Cyber Resilience Act","jurisdiction":"eu","jurisdictionName":"European Union","region":"eu","topics":["cybersecurity","breach-notification"],"status":"enacted","citation":"OJ L, 2024/2847, 20.11.2024","enactedDate":"2024-10-23","effectiveDate":"2024-12-10","summary":"Sets mandatory cybersecurity requirements for hardware and software products with digital elements sold in the EU: secure by design, vulnerability handling, security updates for the support period, SBOMs, and CE marking after conformity assessment. Manufacturers must report actively exploited vulnerabilities and severe incidents to CSIRTs and ENISA from 11 Sep 2026.","appliesTo":"Manufacturers, importers and distributors of products with digital elements (connected hardware and software, including remote data processing solutions) made available on the EU market. Stricter conformity assessment for 'important' and 'critical' products. Non-commercial open source is largely excluded, with light-touch rules for open-source software stewards.","penalties":"Essential requirements and Arts 13-14 obligations: up to EUR 15M or 2.5% of worldwide annual turnover, whichever is higher. Other obligations: up to EUR 10M or 2%. Incorrect or misleading information: up to EUR 5M or 1% (Art 64).","enforcer":"National market surveillance authorities; CSIRTs and ENISA (vulnerability and incident reporting via the single reporting platform); European Commission","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2024/2847/oj","extraSources":[],"notes":"Status is 'enacted' because the main product obligations do not apply until 11 Dec 2027, although reporting obligations apply from 11 Sep 2026. No proposal to delay CRA dates was confirmed in this research. The Digital Omnibus's single-entry point for incident reporting is designed to build on the CRA single reporting platform.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-22 20:04:22","sourceType":"official","verifiedBy":"research from official sources","deadlines":[{"id":48,"regulationId":"eu-cra","date":"2024-12-10","title":"CRA enters into force","description":"Entered into force on the twentieth day after publication in the OJ on 20 Nov 2024 (Art 71(1)).","kind":"effective","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2024/2847/oj","tentative":false,"review":"verified"},{"id":49,"regulationId":"eu-cra","date":"2026-06-11","title":"Conformity assessment body provisions apply","description":"Chapter IV (Arts 35-51, notification of conformity assessment bodies) applies (Art 71(2)).","kind":"effective","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2024/2847/oj","tentative":false,"review":"verified"},{"id":50,"regulationId":"eu-cra","date":"2026-09-11","title":"Vulnerability and incident reporting obligations apply","description":"Art 14: manufacturers must report actively exploited vulnerabilities and severe incidents (24-hour early warning, 72-hour notification) via the single reporting platform. Also covers products placed on the market before 11 Dec 2027 (Art 69(3)).","kind":"reporting","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2024/2847/oj","tentative":false,"review":"verified"},{"id":51,"regulationId":"eu-cra","date":"2027-12-11","title":"CRA fully applies","description":"All remaining obligations, including essential cybersecurity requirements, conformity assessment and CE marking, apply (Art 71(2)). Products placed on the market earlier are covered only if substantially modified (Art 69(2)).","kind":"compliance","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2024/2847/oj","tentative":false,"review":"verified"},{"id":52,"regulationId":"eu-cra","date":"2028-06-11","title":"Legacy type-examination certificates expire","description":"EU type-examination certificates and approval decisions on cybersecurity requirements under other harmonisation legislation remain valid until this date unless they expire earlier (Art 69(1)).","kind":"sunset","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2024/2847/oj","tentative":false,"review":"verified"},{"id":53,"regulationId":"eu-cra","date":"2028-09-11","title":"Report on single reporting platform","description":"Commission report assessing the single reporting platform's effectiveness (Art 70(2)).","kind":"reporting","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2024/2847/oj","tentative":false,"review":"verified"},{"id":54,"regulationId":"eu-cra","date":"2030-12-11","title":"First CRA evaluation","description":"Commission evaluation and review report, then every four years (Art 70(1)).","kind":"reporting","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2024/2847/oj","tentative":false,"review":"verified"}]},{"id":"us-doj-bulk-data","name":"Preventing Access to U.S. Sensitive Personal Data and Government-Related Data by Countries of Concern or Covered Persons (28 CFR Part 202) - DOJ Data Security Program","shortName":"DOJ Bulk Data Rule","jurisdiction":"us","jurisdictionName":"United States (Federal)","region":"us-federal","topics":["privacy","data-residency","cybersecurity","biometrics","health","financial"],"status":"in_force","citation":"28 CFR Part 202; 90 FR 1636 (Jan. 8, 2025); Executive Order 14117; IEEPA (50 U.S.C. 1701 et seq.)","enactedDate":"2025-01-08","effectiveDate":"2025-04-08","summary":"Prohibits U.S. persons from data brokerage and genomic-data transactions with countries of concern or covered persons, and restricts vendor, employment and investment agreements involving bulk U.S. sensitive personal data or government-related data unless CISA security requirements are met. Restricted transactions require a data compliance program, due diligence, audits, recordkeeping and reporting.","appliesTo":"U.S. persons (companies and individuals) engaging in covered data transactions with China (incl. Hong Kong and Macau), Cuba, Iran, North Korea, Russia or Venezuela, or covered persons. Bulk thresholds over the preceding 12 months: human genomic data on 100+ U.S. persons; other human 'omic data or biometric identifiers on 1,000+; precise geolocation on 1,000+ devices; personal health or personal financial data on 10,000+; covered personal identifiers on 100,000+. Government-related data has no threshold.","penalties":"Civil penalty up to the greater of $368,136 (as stated in the rule; inflation-adjusted) or twice the transaction value per violation; willful violations up to $1,000,000 in fines and, for individuals, up to 20 years' imprisonment (IEEPA).","enforcer":"U.S. Department of Justice, National Security Division","sourceUrl":"https://www.federalregister.gov/documents/2025/01/08/2024-31486/preventing-access-to-us-sensitive-personal-data-and-government-related-data-by-countries-of-concern","extraSources":["https://www.ecfr.gov/current/title-28/chapter-I/part-202","https://www.justice.gov/nsd/data-security","https://www.federalregister.gov/documents/2025/04/18/2025-06477/pertaining-to-preventing-access-to-us-sensitive-personal-data-and-government-related-data-by"],"notes":"DOJ announced a 90-day limited enforcement period after April 8, 2025 for good-faith efforts (per DOJ NSD policy, not re-verified here). An April 18, 2025 technical amendment (90 FR 16466) corrected the rule. Penalty figure is the one printed in the January 2025 rule.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-22 20:04:22","sourceType":"official","verifiedBy":"research from official sources","deadlines":[{"id":227,"regulationId":"us-doj-bulk-data","date":"2025-04-08","title":"Prohibitions and restrictions take effect","description":"Core prohibitions on covered data transactions and security requirements for restricted transactions apply.","kind":"effective","sourceUrl":"https://www.federalregister.gov/documents/2025/01/08/2024-31486/preventing-access-to-us-sensitive-personal-data-and-government-related-data-by-countries-of-concern","tentative":false,"review":"verified"},{"id":228,"regulationId":"us-doj-bulk-data","date":"2025-10-06","title":"Due diligence, audit and reporting obligations apply","description":"Subpart J (data compliance program, due diligence and audits for restricted transactions) and reporting requirements in 202.1103 and 202.1104 apply.","kind":"compliance","sourceUrl":"https://www.federalregister.gov/documents/2025/01/08/2024-31486/preventing-access-to-us-sensitive-personal-data-and-government-related-data-by-countries-of-concern","tentative":false,"review":"verified"}]},{"id":"eu-dora","name":"Regulation (EU) 2022/2554 on digital operational resilience for the financial sector (Digital Operational Resilience Act)","shortName":"DORA","jurisdiction":"eu","jurisdictionName":"European Union","region":"eu","topics":["cybersecurity","financial","breach-notification"],"status":"in_force","citation":"OJ L 333, 27.12.2022, p. 1","enactedDate":"2022-12-14","effectiveDate":"2023-01-16","summary":"Harmonised ICT risk-management, major ICT-incident reporting, digital operational resilience testing (including threat-led penetration testing) and ICT third-party risk rules for EU financial entities. Financial entities must keep a register of all ICT third-party contracts. Critical ICT third-party providers (cloud, data centres and similar) come under direct EU oversight.","appliesTo":"About 20 types of EU financial entities (credit institutions, payment and e-money institutions, investment firms, crypto-asset service providers, insurers, trading venues, CCPs and others) and ICT third-party service providers designated as critical. Microenterprises and some small entities get a simplified framework.","penalties":"Administrative penalties for financial entities are set by Member States. Critical ICT third-party providers face periodic penalty payments of up to 1% of average daily worldwide turnover of the preceding business year, imposed daily for up to six months (Art 35(8)).","enforcer":"National competent authorities for financial supervision; the European Supervisory Authorities (EBA, EIOPA, ESMA) as Lead Overseers of critical ICT third-party providers","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2022/2554/oj","extraSources":["https://www.eba.europa.eu/publications-and-media/press-releases/esas-announce-timeline-collect-information-designation-critical-ict-third-party-service-providers","https://www.eba.europa.eu/publications-and-media/press-releases/european-supervisory-authorities-designate-critical-ict-third-party-providers-under-digital","https://eur-lex.europa.eu/eli/reg_del/2025/1190/oj"],"notes":"TLPT must be performed at least every three years by entities identified by their competent authority (Art 26). There is no single EU-wide first-test date; each authority notifies its entities. Registers of information are now collected annually; confirm each year's deadline with the national authority. The Digital Omnibus proposal COM(2025) 837 does not amend DORA in its title, but its single-entry point for incident reporting could interact with DORA reporting.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-22 20:04:22","sourceType":"official","verifiedBy":"research from official sources","deadlines":[{"id":70,"regulationId":"eu-dora","date":"2023-01-16","title":"DORA enters into force","description":"Entered into force on the twentieth day after publication in OJ L 333 of 27 Dec 2022 (Art 64).","kind":"effective","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2022/2554/oj","tentative":false,"review":"verified"},{"id":71,"regulationId":"eu-dora","date":"2025-01-17","title":"DORA applies","description":"All DORA obligations (ICT risk management, incident reporting, testing, third-party risk, register of information) apply from 17 Jan 2025 (Art 64).","kind":"effective","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2022/2554/oj","tentative":false,"review":"verified"},{"id":72,"regulationId":"eu-dora","date":"2025-04-30","title":"First registers of information submitted to the ESAs","description":"Competent authorities had to submit financial entities' registers of ICT third-party contractual arrangements (reference date 31 Mar 2025) to the ESAs by 30 Apr 2025. National authorities set earlier deadlines for entities.","kind":"reporting","sourceUrl":"https://www.eba.europa.eu/publications-and-media/press-releases/esas-announce-timeline-collect-information-designation-critical-ict-third-party-service-providers","tentative":false,"review":"verified"},{"id":73,"regulationId":"eu-dora","date":"2025-07-08","title":"TLPT regulatory technical standards enter into force","description":"Commission Delegated Regulation (EU) 2025/1190 (published 18 June 2025) sets criteria for which financial entities must run threat-led penetration testing, plus methodology and tester requirements.","kind":"effective","sourceUrl":"https://eur-lex.europa.eu/eli/reg_del/2025/1190/oj","tentative":false,"review":"verified"},{"id":74,"regulationId":"eu-dora","date":"2025-11-18","title":"First critical ICT third-party providers designated","description":"The ESAs published the first list of 19 critical ICT third-party providers (including AWS, Google Cloud and Microsoft), which now come under direct EU oversight.","kind":"enforcement","sourceUrl":"https://www.eba.europa.eu/publications-and-media/press-releases/european-supervisory-authorities-designate-critical-ict-third-party-providers-under-digital","tentative":false,"review":"verified"}]},{"id":"uk-duaa","name":"Data (Use and Access) Act 2025","shortName":"Data (Use and Access) Act","jurisdiction":"uk","jurisdictionName":"United Kingdom","region":"uk-europe","topics":["privacy","data-access","ai"],"status":"in_force","citation":"2025 c. 18","enactedDate":"2025-06-19","effectiveDate":"2025-08-20","summary":"Amends the UK GDPR, DPA 2018 and PECR (recognised legitimate interests, relaxed automated decision-making rules, reasonable-and-proportionate DSAR searches, new transfer test, cookie exemptions, PECR fines raised to UK GDPR levels), creates Smart Data schemes and digital verification services, and replaces the ICO with an Information Commission. Commenced in stages from August 2025 to 2026.","appliesTo":"All organisations subject to UK GDPR / PECR; Smart Data provisions apply to sectors designated by regulations; digital verification services providers.","penalties":"PECR fines raised to UK GDPR levels (up to GBP 17.5 million or 4% of worldwide annual turnover).","enforcer":"Information Commissioner's Office / Information Commission; DSIT for Smart Data and digital verification","sourceUrl":"https://www.legislation.gov.uk/ukpga/2025/18/contents","extraSources":["https://www.legislation.gov.uk/uksi/2026/82/contents/made","https://www.legislation.gov.uk/uksi/2026/1015/contents/made","https://www.hunton.com/privacy-and-information-security-law/uk-government-publishes-commencement-dates-for-the-uk-data-use-and-access-act","https://privacymatters.dlapiper.com/2026/02/uk-commencement-of-the-data-protection-provisions-in-the-data-use-and-access-act/"],"notes":"Stage 2 (digital verification services, retention of data on a child's death) was planned for roughly 3-4 months after Royal Assent (autumn 2025); exact date not verified so omitted. Further Stage 4 items (e.g. National Underground Asset Register, births/deaths registration) commence on separate dates not all verified.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-22 20:04:22","sourceType":"official","verifiedBy":"research from official sources","deadlines":[{"id":148,"regulationId":"uk-duaa","date":"2025-06-19","title":"Royal Assent","description":"The Act receives Royal Assent; commencement staged by regulations.","kind":"effective","sourceUrl":"https://www.legislation.gov.uk/ukpga/2025/18/contents","tentative":false,"review":"verified"},{"id":149,"regulationId":"uk-duaa","date":"2025-08-20","title":"Stage 1 commencement","description":"Technical data protection provisions, ICO statutory objects, Smart Data framework (Part 1) and AI/copyright reporting duties commence (Commencement No. 1 Regulations 2025).","kind":"effective","sourceUrl":"https://www.legislation.gov.uk/ukpga/2025/18/contents","tentative":false,"review":"verified"},{"id":150,"regulationId":"uk-duaa","date":"2026-02-05","title":"Stage 3: main data protection changes commence","description":"Recognised legitimate interests, ADM reforms, DSAR changes, international transfer test, cookie exemptions and PECR fines at UK GDPR levels apply (Commencement No. 6 Regulations 2026, reg. 2).","kind":"effective","sourceUrl":"https://www.legislation.gov.uk/uksi/2026/82/contents/made","tentative":false,"review":"verified"},{"id":151,"regulationId":"uk-duaa","date":"2026-06-19","title":"Mandatory data protection complaints procedure","description":"Controllers must have a process for data subject complaints (s.103 and Sch. 10), per Commencement No. 6 Regulations 2026, reg. 3.","kind":"compliance","sourceUrl":"https://www.legislation.gov.uk/uksi/2026/82/contents/made","tentative":false,"review":"verified"},{"id":152,"regulationId":"uk-duaa","date":"2026-09-30","title":"ICO abolished; Information Commission takes over","description":"Sections 118-119 commence: office of Information Commissioner abolished and functions transferred to the Information Commission (Commencement No. 9 Regulations 2026).","kind":"effective","sourceUrl":"https://www.legislation.gov.uk/uksi/2026/1015/regulation/2/made","tentative":false,"review":"verified"}]},{"id":"eu-dga","name":"Regulation (EU) 2022/868 on European data governance (Data Governance Act)","shortName":"Data Governance Act","jurisdiction":"eu","jurisdictionName":"European Union","region":"eu","topics":["data-access","privacy"],"status":"amended","citation":"OJ L 152, 3.6.2022, p. 1","enactedDate":"2022-05-30","effectiveDate":"2022-06-23","summary":"Sets conditions for re-use of protected public-sector data (personal data, trade secrets, IP) and creates a notification and neutrality regime for data intermediation services. It also sets up voluntary registration of 'recognised data altruism organisations'. Data intermediaries must stay neutral, separate the intermediation service from other services and notify a competent authority.","appliesTo":"Public sector bodies making protected data available for re-use and re-users; providers of data intermediation services (data marketplaces, data-sharing pools, data cooperatives) offered in the EU; data altruism organisations seeking recognition.","penalties":"Set by Member States (Art 34); no EU-level maximum.","enforcer":"National competent authorities for data intermediation services and data altruism; European Data Innovation Board","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2022/868/oj","extraSources":["https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:52025PC0837"],"notes":"The Digital Omnibus proposal COM(2025) 837 would repeal Regulation (EU) 2022/868 and move its content into the Data Act. It is still pending (not adopted as of Sept 2026), hence status 'amended' (amendment pending).","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-22 20:04:22","sourceType":"official","verifiedBy":"research from official sources","deadlines":[{"id":63,"regulationId":"eu-dga","date":"2022-06-23","title":"DGA enters into force","description":"Entered into force on the twentieth day after publication in OJ L 152 of 3 June 2022 (Art 38).","kind":"effective","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2022/868/oj","tentative":false,"review":"verified"},{"id":64,"regulationId":"eu-dga","date":"2023-09-24","title":"DGA applies","description":"All DGA rules apply (Art 38).","kind":"effective","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2022/868/oj","tentative":false,"review":"verified"},{"id":65,"regulationId":"eu-dga","date":"2025-09-24","title":"Legacy data intermediaries must comply","description":"Entities that were already providing data intermediation services on 23 June 2022 had to comply with Chapter III by 24 Sep 2025 (Art 37).","kind":"compliance","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2022/868/oj","tentative":false,"review":"verified"}]},{"id":"us-de-dpdpa","name":"Delaware Personal Data Privacy Act (HB 154), 6 Del. C. ch. 12D","shortName":"Delaware Personal Data Privacy Act (DPDPA)","jurisdiction":"us-de","jurisdictionName":"Delaware","region":"us-states","topics":["privacy","children"],"status":"amended","citation":"HB 154 (152nd GA), 84 Del. Laws c. 197; amended by 85 Del. Laws c. 463; 6 Del. C. 12D-101 to 12D-111","enactedDate":"2023-09-11","effectiveDate":"2025-01-01","summary":"Comprehensive privacy law with low applicability thresholds and no exemption for nonprofits. Grants rights to access, correct, delete, port, and opt out of targeted advertising, sale and profiling, and requires honoring opt-out preference signals from Jan 1, 2026. A 2026 amendment (85 Del. Laws c. 463) lowers thresholds further and adds third-party duties from Jan 1, 2027.","appliesTo":"Until Jan 1, 2027: persons doing business in Delaware or targeting residents that controlled or processed personal data of 35,000+ consumers (excluding payment-only data), or 10,000+ consumers and derived over 20% of gross revenue from selling personal data. From Jan 1, 2027: 10,000+ consumers, or 5,000+ consumers and over 20% of gross revenue from sale, plus third parties that acquire personal data from a controller.","penalties":"Violations are unlawful practices under 6 Del. C. 2513 and subchapter II of chapter 25 of Title 29, enforced by the Department of Justice (civil penalties up to $10,000 per willful violation under Delaware consumer fraud law). Mandatory 60-day cure ran Jan 1 - Dec 31, 2025; from Jan 1, 2026 cure is at DOJ discretion.","enforcer":"Delaware Department of Justice (Attorney General)","sourceUrl":"https://delcode.delaware.gov/title6/c012d/index.html","extraSources":[],"notes":"The 2026 amending act is cited in the Delaware Code as 85 Del. Laws c. 463; the underlying bill number and signing date were not verified. The per-violation penalty amount comes from Delaware's general consumer fraud enforcement law (the DPDPA itself does not state a dollar figure) and was not re-verified on the official code page.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-22 20:04:22","sourceType":"official","verifiedBy":"research from official sources","deadlines":[{"id":223,"regulationId":"us-de-dpdpa","date":"2025-01-01","title":"DPDPA takes effect","description":"Consumer rights and controller duties apply; 60-day mandatory cure period begins.","kind":"effective","sourceUrl":"https://delcode.delaware.gov/title6/c012d/index.html","tentative":false,"review":"verified"},{"id":224,"regulationId":"us-de-dpdpa","date":"2025-12-31","title":"Mandatory 60-day cure period expires","description":"Mandatory notice-and-cure ends Dec 31, 2025; from Jan 1, 2026 DOJ decides whether to offer a cure using statutory factors.","kind":"enforcement","sourceUrl":"https://delcode.delaware.gov/title6/c012d/index.html","tentative":false,"review":"verified"},{"id":225,"regulationId":"us-de-dpdpa","date":"2026-01-01","title":"Opt-out preference signals must be honored","description":"Controllers must allow opt-out of targeted advertising and sale via opt-out preference signals (12D-106).","kind":"compliance","sourceUrl":"https://delcode.delaware.gov/title6/c012d/index.html","tentative":false,"review":"verified"},{"id":226,"regulationId":"us-de-dpdpa","date":"2027-01-01","title":"Amended thresholds and third-party duties take effect","description":"Applicability drops to 10,000 consumers (or 5,000 + 20% revenue from sale) and new third-party duties (12D-107A) apply.","kind":"effective","sourceUrl":"https://delcode.delaware.gov/title6/c012d/index.html","tentative":false,"review":"verified"}]},{"id":"eu-dma","name":"Regulation (EU) 2022/1925 on contestable and fair markets in the digital sector (Digital Markets Act)","shortName":"Digital Markets Act","jurisdiction":"eu","jurisdictionName":"European Union","region":"eu","topics":["data-access","privacy"],"status":"in_force","citation":"OJ L 265, 12.10.2022, p. 1","enactedDate":"2022-09-14","effectiveDate":"2022-11-01","summary":"Imposes ex-ante do's and don'ts on designated gatekeepers. Examples: no combining personal data across services without consent, no self-preferencing, interoperability, data portability, and business-user data access. Gatekeepers must notify all acquisitions and submit an audited description of consumer profiling techniques.","appliesTo":"Undertakings providing a core platform service with annual EU turnover of at least EUR 7.5bn (or market capitalisation of at least EUR 75bn), in at least three Member States, with 45M+ monthly active EU end users and 10,000+ yearly active EU business users in each of the last three financial years (Art 3). Designated by the Commission.","penalties":"Up to 10% of total worldwide turnover; up to 20% for repeated infringement within 8 years. Up to 1% for procedural breaches (Art 30). Periodic penalties up to 5% of average daily turnover. Systematic non-compliance can lead to structural remedies.","enforcer":"European Commission (exclusive enforcer), assisted by national competition authorities","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2022/1925/oj","extraSources":["https://digital-markets-act.ec.europa.eu/gatekeepers_en","https://ec.europa.eu/commission/presscorner/detail/en/ip_23_4328"],"notes":"The 7 Mar 2024 compliance date comes from the six-month period after the 6 Sep 2023 designation (Art 8 / press release IP/23/4328); the press release itself says 'six months'. Later designations (e.g. Booking) have their own six-month deadlines.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-22 20:04:22","sourceType":"official","verifiedBy":"research from official sources","deadlines":[{"id":66,"regulationId":"eu-dma","date":"2022-11-01","title":"DMA enters into force","description":"Entered into force twenty days after publication; certain procedural articles apply from this date (Art 54).","kind":"effective","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2022/1925/oj","tentative":false,"review":"verified"},{"id":67,"regulationId":"eu-dma","date":"2023-05-02","title":"DMA applies","description":"DMA becomes applicable; undertakings meeting thresholds must notify the Commission within two months (Arts 3(3), 54).","kind":"effective","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2022/1925/oj","tentative":false,"review":"verified"},{"id":68,"regulationId":"eu-dma","date":"2023-09-06","title":"First six gatekeepers designated","description":"Commission designated Alphabet, Amazon, Apple, ByteDance, Meta and Microsoft (22 core platform services). They had six months to fully comply.","kind":"enforcement","sourceUrl":"https://digital-markets-act.ec.europa.eu/gatekeepers_en","tentative":false,"review":"verified"},{"id":69,"regulationId":"eu-dma","date":"2024-03-07","title":"Gatekeeper compliance deadline (first designations)","description":"First-wave gatekeepers had to comply with Arts 5-7 obligations and submit compliance reports six months after the 6 Sep 2023 designation.","kind":"compliance","sourceUrl":"https://ec.europa.eu/commission/presscorner/detail/en/ip_23_4328","tentative":false,"review":"verified"},{"id":6973,"regulationId":"eu-dma","date":"2026-05-03","title":"DMA first review","description":"Commission evaluation of the DMA under Article 53, then every 3 years.","kind":"reporting","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2022/1925/oj/eng","tentative":false,"review":"verified"}]},{"id":"eu-digital-omnibus","name":"Proposal for a Regulation amending Regulations (EU) 2016/679, 2018/1724, 2018/1725, 2023/2854 and Directives 2002/58/EC, 2022/2555 and 2022/2557 as regards the simplification of the digital legislative framework (Digital Omnibus)","shortName":"Digital Omnibus (data/GDPR)","jurisdiction":"eu","jurisdictionName":"European Union","region":"eu","topics":["privacy","data-access","cybersecurity","breach-notification","ai"],"status":"proposed","citation":"COM(2025) 837 final, 2025/0360(COD)","enactedDate":"","effectiveDate":"","summary":"Commission proposal to simplify EU digital rules. It would amend the GDPR (personal data definition, processing for AI, a new cookie/terminal-equipment consent regime in Art 88a/88b, breach notification only for high-risk breaches within 96 hours) and the ePrivacy Directive, NIS2, CER Directive and Data Act. A single-entry point would handle incident reporting, and the Data Governance Act, Free Flow Regulation, Platform-to-Business Regulation and Open Data Directive would be repealed and merged into the Data Act. The AI Act part was split out and adopted separately as Regulation (EU) 2026/1744.","appliesTo":"Would affect all GDPR controllers/processors, website and app operators using cookies, NIS2/CER entities (incident reporting), and Data Act/DGA actors.","penalties":"No new penalties; existing regimes (GDPR, Data Act, NIS2) would continue to apply.","enforcer":"N/A (legislative proposal); European Parliament (ITRE/LIBE) and Council","sourceUrl":"https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:52025PC0837","extraSources":["https://www.europarl.europa.eu/legislative-train/theme-a-new-plan-for-europe-s-sustainable-prosperity-and-competitiveness/file-digital-package","https://digital-strategy.ec.europa.eu/en/library/digital-omnibus-regulation-proposal"],"notes":"Tabled 19 Nov 2025. Per the European Parliament Legislative Train (updated 1 Aug 2026): ITRE/LIBE joint draft report published 22 June 2026, amendment deadline 15 July 2026 with 1,750+ amendments, and no plenary vote date. A Council negotiating-mandate vote planned for 26 June 2026 was cancelled, and work continues under the Irish Presidency. No trilogues had started, and adoption is not expected before late 2026 at the earliest. No dates apply until it is adopted.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-22 20:04:22","sourceType":"official","verifiedBy":"research from official sources","deadlines":[]},{"id":"eu-dsa","name":"Regulation (EU) 2022/2065 on a Single Market for Digital Services (Digital Services Act)","shortName":"Digital Services Act","jurisdiction":"eu","jurisdictionName":"European Union","region":"eu","topics":["online-safety","children","privacy"],"status":"in_force","citation":"OJ L 277, 27.10.2022, p. 1","enactedDate":"2022-10-19","effectiveDate":"2022-11-16","summary":"Layered obligations for intermediary services: notice-and-action for illegal content, statements of reasons, complaint handling, transparency reporting, and ad and recommender transparency. Profiling-based ads to minors and ads based on sensitive data are banned. Very large online platforms and search engines (45M+ EU users) must also run annual systemic-risk assessments and audits and give researchers data access.","appliesTo":"Intermediary services offered to EU recipients (mere conduit, caching, hosting, online platforms, marketplaces, search engines). VLOP/VLOSE tier: 45 million or more average monthly active EU recipients, designated by the Commission. Micro and small enterprises are exempt from some platform duties.","penalties":"Up to 6% of annual worldwide turnover for failure to comply. Up to 1% for incorrect, incomplete or misleading information or failure to submit to inspection. Periodic penalty payments up to 5% of average daily worldwide turnover (Arts 52, 74).","enforcer":"European Commission (VLOPs/VLOSEs); national Digital Services Coordinators; European Board for Digital Services","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2022/2065/oj","extraSources":["https://digital-strategy.ec.europa.eu/en/policies/list-designated-vlops-and-vloses","https://digital-strategy.ec.europa.eu/en/news/commission-designates-chatgpt-reddit-roblox-under-digital-services-act"],"notes":"The exact compliance date for the Aug 2026 designations depends on the notification date (four months after notification); the Commission says 'by January 2027', so no exact deadline row. The 31 Aug 2026 date is the date of the Commission news item.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-22 20:04:22","sourceType":"official","verifiedBy":"research from official sources","deadlines":[{"id":75,"regulationId":"eu-dsa","date":"2022-11-16","title":"DSA enters into force","description":"Entered into force twenty days after publication; VLOP designation provisions (Art 33(3)-(6)) and Commission enforcement sections apply from this date (Art 93).","kind":"effective","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2022/2065/oj","tentative":false,"review":"verified"},{"id":76,"regulationId":"eu-dsa","date":"2023-02-17","title":"Platforms publish EU user numbers","description":"Online platforms and search engines had to publish average monthly active EU recipients, and must update them at least every six months (Art 24(2)).","kind":"reporting","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2022/2065/oj","tentative":false,"review":"verified"},{"id":77,"regulationId":"eu-dsa","date":"2023-04-25","title":"First VLOP/VLOSE designations","description":"Commission designated the first 19 very large online platforms and search engines (e.g. Amazon Store, Facebook, Google Search, TikTok, X). Obligations apply four months after notification.","kind":"enforcement","sourceUrl":"https://digital-strategy.ec.europa.eu/en/policies/list-designated-vlops-and-vloses","tentative":false,"review":"verified"},{"id":78,"regulationId":"eu-dsa","date":"2024-02-17","title":"DSA applies to all intermediary services","description":"Full application to all providers of intermediary services (Art 93(2)).","kind":"effective","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2022/2065/oj","tentative":false,"review":"verified"},{"id":6969,"regulationId":"eu-dsa","date":"2025-07-01","title":"DSA transparency report templates mandatory","description":"Implementing Regulation (EU) 2024/2835 requires all intermediary services to use harmonised templates for content moderation data collected from this date.","kind":"compliance","sourceUrl":"https://eur-lex.europa.eu/eli/reg_impl/2024/2835/oj/eng","tentative":false,"review":"verified"},{"id":6968,"regulationId":"eu-dsa","date":"2025-10-29","title":"DSA delegated act on researcher data access in force","description":"Delegated Regulation (EU) 2025/2050 sets the procedure for vetted researchers to access VLOP and VLOSE data under Article 40(4). Published in the OJ on 2025-10-09; in force on the 20th day.","kind":"effective","sourceUrl":"https://eur-lex.europa.eu/eli/reg_del/2025/2050/oj/eng","tentative":false,"review":"verified"},{"id":6971,"regulationId":"eu-dsa","date":"2025-11-17","title":"DSA review report on VLOP scope and interplay","description":"Commission report under Article 91 on Article 33 scope and interaction with other laws.","kind":"reporting","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2022/2065/oj/eng","tentative":false,"review":"verified"},{"id":6970,"regulationId":"eu-dsa","date":"2026-01-01","title":"DSA first harmonised transparency reporting cycle","description":"First full annual reporting period (to 2026-12-31) under the harmonised templates for all intermediary services.","kind":"reporting","sourceUrl":"https://eur-lex.europa.eu/eli/reg_impl/2024/2835/oj/eng","tentative":false,"review":"verified"},{"id":79,"regulationId":"eu-dsa","date":"2026-08-31","title":"ChatGPT designated as VLOSE; Reddit and Roblox as VLOPs","description":"Commission designated ChatGPT as a very large online search engine and Reddit and Roblox as very large online platforms. They have four months (by January 2027) to meet VLOP/VLOSE obligations.","kind":"enforcement","sourceUrl":"https://digital-strategy.ec.europa.eu/en/news/commission-designates-chatgpt-reddit-roblox-under-digital-services-act","tentative":false,"review":"verified"},{"id":6972,"regulationId":"eu-dsa","date":"2027-02-18","title":"DSA SME impact report","description":"Commission report under Article 91 on effects on SMEs.","kind":"reporting","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2022/2065/oj/eng","tentative":false,"review":"verified"}]},{"id":"eu-ai-act","name":"Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act), as amended by Regulation (EU) 2026/1744 (Digital Omnibus on AI)","shortName":"EU AI Act","jurisdiction":"eu","jurisdictionName":"European Union","region":"eu","topics":["ai","biometrics","children"],"status":"amended","citation":"OJ L, 2024/1689, 12.7.2024; amended by OJ L, 2026/1744, 24.7.2026","enactedDate":"2024-06-13","effectiveDate":"2024-08-01","summary":"A risk-based product-safety regime for AI. It bans certain AI practices, imposes strict requirements on high-risk AI systems (risk management, data governance, documentation, human oversight, conformity assessment), sets transparency duties for chatbots, deepfakes and AI-generated content, and sets obligations for general-purpose AI model providers. The Digital Omnibus on AI (Regulation (EU) 2026/1744, in force 27 July 2026) pushed the high-risk dates back to 2 December 2027 (Annex III) and 2 August 2028 (Annex I). It also softened the AI literacy duty and added bans on non-consensual sexual deepfakes and child sexual abuse material (CSAM) generation.","appliesTo":"Providers placing AI systems or general-purpose AI models on the EU market (wherever established), deployers of AI systems in the EU, importers, distributors, and non-EU providers/deployers whose AI output is used in the EU. GPAI models trained with more than 10^25 FLOPs are presumed to have systemic risk.","penalties":"Prohibited practices: up to EUR 35M or 7% of worldwide annual turnover, whichever is higher. Most other operator obligations: up to EUR 15M or 3%. Incorrect or misleading information to authorities: up to EUR 7.5M or 1%. For SMEs, and since the 2026 Omnibus also small mid-caps (SMCs), the lower of the two amounts applies. GPAI providers: Commission fines up to EUR 15M or 3% (Art 101).","enforcer":"National market surveillance authorities and notifying authorities; European Commission AI Office (GPAI models and AI systems built on them); European AI Board","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","extraSources":["https://eur-lex.europa.eu/eli/reg/2026/1744/oj","https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-113","https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-111","https://www.freshfields.com/en/our-thinking/blogs/technology-quotient/eu-ai-act-unpacked-34-the-final-digital-omnibus-on-ai-key-amendments-to-the-a-102nber"],"notes":"The Digital Omnibus on AI (Commission proposal 19 Nov 2025; EP position 16 June 2026; Council decision 29 June 2026; signed 8 July 2026) was published in the OJ on 24 July 2026 as Regulation (EU) 2026/1744 and has been in force since 27 July 2026. The high-risk delays are therefore legally binding, not tentative. Other Omnibus changes: Art 4 AI literacy recast as 'take measures to support' AI literacy (no guaranteed level); SME relief extended to small mid-caps; registration for Art 6(3) non-high-risk systems simplified; machinery moved from Annex I Section A to Section B; Commission guidance on post-market monitoring due 2 Sep 2027. Existing high-risk systems placed on the market before the relevant Chapter III date are covered only if significantly changed afterwards (Art 111(2)). The AI Act Service Desk article pages had not yet been updated to show the Omnibus text when checked.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-22 20:04:22","sourceType":"official","verifiedBy":"research from official sources","deadlines":[{"id":37,"regulationId":"eu-ai-act","date":"2024-08-01","title":"AI Act enters into force","description":"Regulation (EU) 2024/1689 enters into force twenty days after publication on 12 July 2024 (Art 113).","kind":"effective","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","tentative":false,"review":"verified"},{"id":38,"regulationId":"eu-ai-act","date":"2025-02-02","title":"Prohibited practices and AI literacy apply","description":"Chapters I and II apply, including the Article 5 bans on prohibited AI practices and the Article 4 AI literacy duty (Art 113(a)).","kind":"effective","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","tentative":false,"review":"verified"},{"id":39,"regulationId":"eu-ai-act","date":"2025-08-02","title":"GPAI, governance, notified bodies and penalties apply","description":"Chapter III Section 4 (notifying authorities), Chapter V (general-purpose AI model obligations), Chapter VII (governance), Chapter XII (penalties, except Art 101) and Art 78 apply (Art 113(b)).","kind":"effective","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","tentative":false,"review":"verified"},{"id":40,"regulationId":"eu-ai-act","date":"2026-07-27","title":"Digital Omnibus on AI enters into force","description":"Regulation (EU) 2026/1744 (adopted 8 July 2026, OJ 24 July 2026) enters into force on the third day after publication. Amended Articles 102 to 110 apply from this date (new Art 113(d)).","kind":"transition","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","tentative":false,"review":"verified"},{"id":41,"regulationId":"eu-ai-act","date":"2026-08-02","title":"General application: transparency obligations, GPAI fines, most other rules","description":"The AI Act's general date of application. Article 50 transparency obligations (chatbot disclosure, deepfake labelling, machine-readable marking of synthetic content) and Commission fines on GPAI providers (Art 101) apply. Not deferred by the Omnibus.","kind":"effective","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","tentative":false,"review":"verified"},{"id":42,"regulationId":"eu-ai-act","date":"2026-12-02","title":"New bans on sexual deepfakes and CSAM generation; Art 50(2) grace period ends","description":"New Art 5(1)(ba)/(bb) prohibitions on AI systems that generate non-consensual intimate imagery of identifiable persons or child sexual abuse material apply. Generative AI systems placed on the market before 2 Aug 2026 must comply with the Art 50(2) marking duty by this date (new Art 111(4)).","kind":"compliance","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","tentative":false,"review":"verified"},{"id":43,"regulationId":"eu-ai-act","date":"2027-08-02","title":"Legacy GPAI models must comply; national AI sandboxes operational","description":"Providers of GPAI models placed on the market before 2 Aug 2025 must comply (Art 111(3)). Each Member State must have at least one national AI regulatory sandbox operational (Art 57(1) as amended by the Omnibus).","kind":"compliance","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","tentative":false,"review":"verified"},{"id":44,"regulationId":"eu-ai-act","date":"2027-12-02","title":"High-risk obligations apply to Annex III systems","description":"Chapter III Sections 1-3 (high-risk requirements and provider/deployer obligations) apply to AI systems classified high-risk under Art 6(2) and Annex III (employment, credit scoring, education, biometrics, essential services and similar). Deferred from 2 Aug 2026 by Regulation (EU) 2026/1744.","kind":"compliance","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","tentative":false,"review":"verified"},{"id":45,"regulationId":"eu-ai-act","date":"2028-08-02","title":"High-risk obligations apply to Annex I product-embedded systems","description":"Chapter III Sections 1-3 apply to AI systems classified high-risk under Art 6(1) and Annex I (safety components of products covered by EU harmonisation legislation). Deferred from 2 Aug 2027 by Regulation (EU) 2026/1744.","kind":"compliance","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","tentative":false,"review":"verified"},{"id":46,"regulationId":"eu-ai-act","date":"2030-08-02","title":"Public-authority high-risk systems must comply","description":"Providers and deployers of high-risk AI systems intended for use by public authorities that were placed on the market before the Chapter III application date must comply (Art 111(2), as replaced by the Omnibus).","kind":"compliance","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","tentative":false,"review":"verified"},{"id":47,"regulationId":"eu-ai-act","date":"2030-12-31","title":"Large-scale EU IT systems must comply","description":"AI systems that are components of the large-scale IT systems in Annex X (e.g. SIS, VIS, Eurodac, EES, ETIAS) placed on the market before 2 Aug 2027 must be brought into compliance (Art 111(1)).","kind":"compliance","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","tentative":false,"review":"verified"}]},{"id":"eu-csam-interim","name":"Regulation (EU) 2026/1881 on a temporary derogation from certain provisions of Directive 2002/58/EC for combating online child sexual abuse","shortName":"EU CSAM Interim Regulation","jurisdiction":"eu","jurisdictionName":"European Union","region":"eu","topics":["privacy","children","online-safety"],"status":"in_force","citation":"Regulation (EU) 2026/1881 (successor to Regulation (EU) 2021/1232)","enactedDate":"2026-07-24","effectiveDate":"2026-07-31","summary":"Lets providers of number-independent interpersonal communications services, such as messaging and email, voluntarily scan for and report online child sexual abuse despite ePrivacy confidentiality rules, under strict conditions. It replaces Regulation (EU) 2021/1232, which expired on 2026-04-03. The permanent CSA Regulation proposed in 2022 is still not adopted.","appliesTo":"Providers of number-independent interpersonal communications services that voluntarily detect, remove and report child sexual abuse material.","penalties":"No specific fines; processing outside its conditions falls back under the ePrivacy Directive and GDPR.","enforcer":"National data protection authorities; Commission reporting.","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2026/1881/oj/eng","extraSources":["https://publications.europa.eu/resource/celex/32026R1881","https://eur-lex.europa.eu/eli/reg/2024/1307/oj/eng","https://eur-lex.europa.eu/eli/reg/2021/1232/oj/eng"],"notes":"There was a gap with no legal basis for voluntary scanning between 2026-04-03 and 2026-07-31. The proposed permanent Regulation laying down rules to prevent and combat child sexual abuse (COM(2022) 209) remained in negotiation as of 2026-09-25.","lastVerified":"2026-09-25","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-25 10:55:47","sourceType":"official","verifiedBy":"research from official sources (2026-09-25)","deadlines":[{"id":6860,"regulationId":"eu-csam-interim","date":"2026-04-03","title":"Previous interim regulation expires","description":"Regulation (EU) 2021/1232, as extended by Regulation (EU) 2024/1307, applied until this date.","kind":"sunset","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2024/1307/oj/eng","tentative":false,"review":"verified"},{"id":6861,"regulationId":"eu-csam-interim","date":"2026-07-31","title":"New interim regulation enters into force","description":"Published in the OJ on 2026-07-28; enters into force on the third day.","kind":"effective","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2026/1881/oj/eng","tentative":false,"review":"verified"},{"id":6862,"regulationId":"eu-csam-interim","date":"2028-02-01","title":"Commission implementation report","description":"Commission report on implementation, including proportionality and error rates (Article 9).","kind":"reporting","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2026/1881/oj/eng","tentative":false,"review":"verified"},{"id":6863,"regulationId":"eu-csam-interim","date":"2028-04-03","title":"Interim derogation expires","description":"The Regulation applies until this date.","kind":"sunset","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2026/1881/oj/eng","tentative":false,"review":"verified"}]},{"id":"eu-ccd2","name":"Directive (EU) 2023/2225 on credit agreements for consumers","shortName":"EU Consumer Credit Directive 2 (CCD2)","jurisdiction":"eu","jurisdictionName":"European Union","region":"eu","topics":["financial","privacy","ai"],"status":"enacted","citation":"Directive (EU) 2023/2225","enactedDate":"2023-10-18","effectiveDate":"2026-11-20","summary":"Replaces the 2008 Consumer Credit Directive and extends it to buy-now-pay-later and small loans. Creditworthiness assessments must use relevant, accurate data and may not use special category data or social media data. Where the assessment involves automated processing, consumers get a right to human intervention and an explanation.","appliesTo":"Creditors and credit intermediaries offering consumer credit in the EU, including online lenders and BNPL providers.","penalties":"Set by Member States (Article 44). In coordinated cross-border cases under Regulation (EU) 2017/2394, authorities must be able to impose fines.","enforcer":"National consumer credit and financial conduct authorities.","sourceUrl":"https://eur-lex.europa.eu/eli/dir/2023/2225/oj/eng","extraSources":["https://publications.europa.eu/resource/celex/32023L2225"],"notes":"Recitals state creditworthiness data should not include special category data or information obtained from social networks. Member States must notify penalty rules by 2026-11-20.","lastVerified":"2026-09-25","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-25 10:55:47","sourceType":"official","verifiedBy":"research from official sources (2026-09-25)","deadlines":[{"id":6867,"regulationId":"eu-ccd2","date":"2025-11-20","title":"Transposition deadline","description":"Member States must adopt and publish transposing laws (Article 48).","kind":"compliance","sourceUrl":"https://eur-lex.europa.eu/eli/dir/2023/2225/oj/eng","tentative":false,"review":"verified"},{"id":6868,"regulationId":"eu-ccd2","date":"2026-11-20","title":"National rules apply","description":"Member States must apply the transposing measures from this date and the 2008 Directive is repealed.","kind":"effective","sourceUrl":"https://eur-lex.europa.eu/eli/dir/2023/2225/oj/eng","tentative":false,"review":"verified"}]},{"id":"eu-cyber-solidarity-act","name":"Regulation (EU) 2025/38 laying down measures to strengthen solidarity and capacities in the Union to detect, prepare for and respond to cyber threats and incidents (Cyber Solidarity Act)","shortName":"EU Cyber Solidarity Act","jurisdiction":"eu","jurisdictionName":"European Union","region":"eu","topics":["cybersecurity"],"status":"in_force","citation":"Regulation (EU) 2025/38","enactedDate":"2024-12-19","effectiveDate":"2025-02-04","summary":"Sets up a European Cybersecurity Alert System of national and cross-border Cyber Hubs, a Cybersecurity Emergency Mechanism with an EU Cybersecurity Reserve of trusted private incident response providers, and a Cybersecurity Incident Review Mechanism for significant and large-scale incidents.","appliesTo":"Member States, national Cyber Hubs, ENISA, and entities in NIS2 critical sectors that may receive support from the Reserve; trusted managed security service providers.","penalties":"No direct fines; funding and cooperation instrument.","enforcer":"European Commission, ENISA and Member State authorities.","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2025/38/oj/eng","extraSources":["https://publications.europa.eu/resource/celex/32025R0038"],"notes":"Entry into force computed from OJ publication plus 20 days.","lastVerified":"2026-09-25","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-25 10:55:47","sourceType":"official","verifiedBy":"research from official sources (2026-09-25)","deadlines":[{"id":6858,"regulationId":"eu-cyber-solidarity-act","date":"2025-02-04","title":"Cyber Solidarity Act enters into force","description":"Published in the OJ on 2025-01-15; enters into force on the 20th day.","kind":"effective","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2025/38/oj/eng","tentative":false,"review":"verified"},{"id":6859,"regulationId":"eu-cyber-solidarity-act","date":"2027-02-05","title":"First Commission evaluation","description":"Commission evaluates the Regulation and reports to Parliament and Council, then every 4 years (Article 25).","kind":"reporting","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2025/38/oj/eng","tentative":false,"review":"verified"}]},{"id":"eu-cybersecurity-act","name":"Regulation (EU) 2019/881 on ENISA and on information and communications technology cybersecurity certification (Cybersecurity Act)","shortName":"EU Cybersecurity Act","jurisdiction":"eu","jurisdictionName":"European Union","region":"eu","topics":["cybersecurity"],"status":"amended","citation":"Regulation (EU) 2019/881, amended by Regulation (EU) 2025/37","enactedDate":"2019-04-17","effectiveDate":"2019-06-27","summary":"Gives ENISA a permanent mandate and sets up the EU framework for voluntary cybersecurity certification schemes for ICT products, services and processes, such as the EUCC scheme. On 2026-01-20 the Commission proposed a replacement, the Cybersecurity Act 2 (COM(2026) 11), adding an ICT supply chain security framework aimed at high-risk suppliers.","appliesTo":"ENISA, national cybersecurity certification authorities, and manufacturers or providers of ICT products, services and processes that seek EU certification.","penalties":"Member States set penalties for infringements of the certification title and of certification schemes.","enforcer":"ENISA and national cybersecurity certification authorities.","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2019/881/oj/eng","extraSources":["https://publications.europa.eu/resource/celex/32019R0881","https://publications.europa.eu/resource/celex/32025R0037","https://publications.europa.eu/resource/celex/52026PC0011"],"notes":"Regulation (EU) 2025/37 of 2024-12-19 added managed security services to the certification scope. A companion proposal COM(2026) 13 would amend NIS2 to align with CSA2. The CSA2 proposal is not law as of 2026-09-25.","lastVerified":"2026-09-25","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-25 10:55:47","sourceType":"official","verifiedBy":"research from official sources (2026-09-25)","deadlines":[{"id":6852,"regulationId":"eu-cybersecurity-act","date":"2019-06-27","title":"Cybersecurity Act enters into force","description":"Published in the OJ on 2019-06-07; enters into force on the 20th day.","kind":"effective","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2019/881/oj/eng","tentative":false,"review":"verified"},{"id":6853,"regulationId":"eu-cybersecurity-act","date":"2021-06-28","title":"Certification enforcement articles apply","description":"Articles 58, 60, 61, 63, 64 and 65 on national certification authorities, conformity assessment bodies, complaints and remedies apply.","kind":"effective","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2019/881/oj/eng","tentative":false,"review":"verified"},{"id":6854,"regulationId":"eu-cybersecurity-act","date":"2026-01-20","title":"Cybersecurity Act 2 proposed","description":"Commission proposal COM(2026) 11 to repeal and replace the Act, adding ICT supply chain security rules. Now in the ordinary legislative procedure (2026/0011(COD)).","kind":"transition","sourceUrl":"https://publications.europa.eu/resource/celex/52026PC0011","tentative":false,"review":"verified"}]},{"id":"eu-data-act","name":"Regulation (EU) 2023/2854 on harmonised rules on fair access to and use of data (Data Act)","shortName":"EU Data Act","jurisdiction":"eu","jurisdictionName":"European Union","region":"eu","topics":["data-access","privacy"],"status":"in_force","citation":"OJ L, 2023/2854, 22.12.2023","enactedDate":"2023-12-13","effectiveDate":"2024-01-11","summary":"Gives users of connected products and related services the right to access and share the data those products generate, and sets rules for business-to-business data sharing. It bans unfair data-sharing contract terms imposed on businesses and lets public bodies obtain data in cases of exceptional need. Cloud and other data processing service providers must make switching easy, and switching charges are phased out.","appliesTo":"Manufacturers of connected products and providers of related services placed on the EU market; data holders and data recipients; providers of data processing services (cloud/edge) to EU customers; participants in data spaces. Micro and small enterprises are exempt from some data-holder obligations.","penalties":"Set by Member States (Art 40), which had to notify their rules by 12 Sep 2025. Where personal data is involved, data protection authorities may impose GDPR-level fines (up to EUR 20M or 4% of worldwide turnover).","enforcer":"National competent authorities designated by each Member State (data coordinator); data protection authorities for personal data; European Data Innovation Board (EDIB)","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2023/2854/oj","extraSources":["https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:52025PC0837","https://www.europarl.europa.eu/legislative-train/theme-a-new-plan-for-europe-s-sustainable-prosperity-and-competitiveness/file-digital-package"],"notes":"The Digital Omnibus proposal COM(2025) 837 would amend the Data Act and fold in the Data Governance Act, Free Flow of Non-Personal Data Regulation and Open Data Directive. Still under negotiation as of Sept 2026 (Legislative Train status 'tabled', 1 Aug 2026), so no Data Act dates have changed.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-22 20:04:22","sourceType":"official","verifiedBy":"research from official sources","deadlines":[{"id":55,"regulationId":"eu-data-act","date":"2024-01-11","title":"Data Act enters into force","description":"Entered into force on the twentieth day after publication in the OJ on 22 Dec 2023 (Art 50).","kind":"effective","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2023/2854/oj","tentative":false,"review":"verified"},{"id":56,"regulationId":"eu-data-act","date":"2024-01-11","title":"Reduced switching charges period begins","description":"From 11 Jan 2024 to 12 Jan 2027, data processing providers may charge only reduced switching fees, capped at costs directly linked to switching (Art 29(2)-(3)).","kind":"transition","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2023/2854/oj","tentative":false,"review":"verified"},{"id":57,"regulationId":"eu-data-act","date":"2025-09-12","title":"Data Act applies","description":"Most obligations apply, including user data access and sharing (Chapters II-III), cloud switching (Chapter VI) and interoperability; Chapter IV unfair terms apply to contracts concluded after this date (Art 50).","kind":"effective","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2023/2854/oj","tentative":false,"review":"verified"},{"id":58,"regulationId":"eu-data-act","date":"2025-09-12","title":"Member States notify penalty rules","description":"Member States had to notify the Commission of their penalty rules (Art 40(2)).","kind":"reporting","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2023/2854/oj","tentative":false,"review":"verified"},{"id":59,"regulationId":"eu-data-act","date":"2026-09-12","title":"Access-by-design for new connected products","description":"Art 3(1) design obligation (product data and related service data accessible to the user by default) applies to connected products and related services placed on the market after 12 Sep 2026.","kind":"compliance","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2023/2854/oj","tentative":false,"review":"verified"},{"id":60,"regulationId":"eu-data-act","date":"2027-01-12","title":"Cloud switching charges abolished","description":"Providers of data processing services may no longer impose any switching charges on customers (Art 29(1)).","kind":"compliance","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2023/2854/oj","tentative":false,"review":"verified"},{"id":61,"regulationId":"eu-data-act","date":"2027-09-12","title":"Unfair-terms rules extend to older long-term contracts","description":"Chapter IV (unfair contractual terms) applies to contracts concluded on or before 12 Sep 2025 that are of indefinite duration or expire at least 10 years from 11 Jan 2024 (Art 50).","kind":"compliance","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2023/2854/oj","tentative":false,"review":"verified"},{"id":62,"regulationId":"eu-data-act","date":"2028-09-12","title":"Commission evaluation","description":"Commission evaluation report due, including the impact of cloud switching rules (Arts 23-31) (Art 49(2)).","kind":"reporting","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2023/2854/oj","tentative":false,"review":"verified"}]},{"id":"eu-fida","name":"Proposal for a Regulation on a framework for Financial Data Access (FIDA)","shortName":"EU Financial Data Access (FIDA) proposal","jurisdiction":"eu","jurisdictionName":"European Union","region":"eu","topics":["financial","data-access","privacy"],"status":"proposed","citation":"COM(2023) 360 final, 2023/0205(COD)","enactedDate":"","effectiveDate":"","summary":"Would create a right for customers to have their financial data beyond payment accounts, such as savings, investments, insurance and credit data, shared with authorised third parties. Data holders would join financial data sharing schemes and customers would manage permissions through dashboards.","appliesTo":"Banks, investment firms, insurers, credit providers and other financial institutions as data holders, and new financial information service providers as data users.","penalties":"Proposed administrative penalties set by Member States and competent authorities.","enforcer":"National financial competent authorities; EBA, EIOPA and ESMA for technical standards.","sourceUrl":"https://publications.europa.eu/resource/celex/52023PC0360","extraSources":["https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:52023PC0360"],"notes":"Not on the Commission withdrawal list of 2025-10-06 (C/2025/5423). As proposed it would apply 24 months after entry into force, with schemes rules after 18 months. Trilogue status as of 2026-09-25 not verified from an official source.","lastVerified":"2026-09-25","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-25 10:55:47","sourceType":"official","verifiedBy":"research from official sources (2026-09-25)","deadlines":[{"id":6869,"regulationId":"eu-fida","date":"2023-06-28","title":"FIDA proposed","description":"Commission adopts the proposal together with the payment services package.","kind":"transition","sourceUrl":"https://publications.europa.eu/resource/celex/52023PC0360","tentative":false,"review":"verified"}]},{"id":"eu-platform-work","name":"Directive (EU) 2024/2831 on improving working conditions in platform work","shortName":"EU Platform Work Directive","jurisdiction":"eu","jurisdictionName":"European Union","region":"eu","topics":["privacy","ai"],"status":"enacted","citation":"Directive (EU) 2024/2831","enactedDate":"2024-10-23","effectiveDate":"2024-12-01","summary":"First EU law on algorithmic management at work. Digital labour platforms may not use automated systems to process emotional, psychological or certain other personal data of platform workers, must be transparent about automated monitoring and decision systems, and must ensure human oversight and human review of significant decisions. It also creates a rebuttable presumption of employment.","appliesTo":"Digital labour platforms organising platform work in the EU, and people performing platform work, including the self-employed for the data rules.","penalties":"Set by Member States in national transposing law; must be effective, proportionate and dissuasive.","enforcer":"National labour authorities and data protection authorities (GDPR supervisory authorities for the data provisions).","sourceUrl":"https://eur-lex.europa.eu/eli/dir/2024/2831/oj/eng","extraSources":["https://publications.europa.eu/resource/celex/32024L2831"],"notes":"Obligations bind platforms through national law from the transposition date. Entry into force computed from OJ publication plus 20 days.","lastVerified":"2026-09-25","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-25 10:55:47","sourceType":"official","verifiedBy":"research from official sources (2026-09-25)","deadlines":[{"id":6850,"regulationId":"eu-platform-work","date":"2024-12-01","title":"Directive enters into force","description":"Published in the OJ on 2024-11-11; enters into force on the 20th day.","kind":"effective","sourceUrl":"https://eur-lex.europa.eu/eli/dir/2024/2831/oj/eng","tentative":false,"review":"verified"},{"id":6851,"regulationId":"eu-platform-work","date":"2026-12-02","title":"Transposition deadline","description":"Member States must bring national laws into force to comply with the Directive (Article 29).","kind":"compliance","sourceUrl":"https://eur-lex.europa.eu/eli/dir/2024/2831/oj/eng","tentative":false,"review":"verified"}]},{"id":"eu-ttpa","name":"Regulation (EU) 2024/900 on the transparency and targeting of political advertising","shortName":"EU Political Advertising Regulation (TTPA)","jurisdiction":"eu","jurisdictionName":"European Union","region":"eu","topics":["privacy","online-safety"],"status":"in_force","citation":"Regulation (EU) 2024/900","enactedDate":"2024-03-13","effectiveDate":"2025-10-10","summary":"Sets EU-wide transparency rules for paid political advertising, including labels, transparency notices and a public ad repository. Online targeting and ad delivery using personal data is only allowed with explicit consent, on data collected from the person, and never using special category data or profiling.","appliesTo":"Sponsors of political ads and providers of political advertising services, including online platforms and publishers, for ads disseminated in the EU.","penalties":"Member States set sanctions; maximum fines of 6% of annual income, budget or worldwide turnover of the sponsor or provider, whichever applies.","enforcer":"Data protection authorities for the targeting rules (Articles 18 and 19); national competent authorities and Digital Services Coordinators for the rest.","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2024/900/oj/eng","extraSources":["https://publications.europa.eu/resource/celex/32024R0900"],"notes":"Entry into force date computed from OJ publication on 2024-03-20 plus 20 days. Verified against the OJ text on the Publications Office portal because EUR-Lex blocks automated fetches.","lastVerified":"2026-09-25","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-25 10:55:47","sourceType":"official","verifiedBy":"research from official sources (2026-09-25)","deadlines":[{"id":6847,"regulationId":"eu-ttpa","date":"2024-04-09","title":"TTPA enters into force","description":"Published in the OJ on 2024-03-20; enters into force on the 20th day. Articles 3 and 5(1) apply from this date.","kind":"effective","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2024/900/oj/eng","tentative":false,"review":"verified"},{"id":6848,"regulationId":"eu-ttpa","date":"2025-10-10","title":"TTPA applies","description":"Most of the Regulation applies, including labelling, transparency notices and the targeting restrictions.","kind":"effective","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2024/900/oj/eng","tentative":false,"review":"verified"},{"id":6849,"regulationId":"eu-ttpa","date":"2026-01-10","title":"Member States notify sanction rules","description":"Deadline for Member States to notify the Commission of their sanction rules under Article 25(3).","kind":"reporting","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2024/900/oj/eng","tentative":false,"review":"verified"}]},{"id":"eu-e-evidence","name":"Regulation (EU) 2023/1543 on European Production Orders and European Preservation Orders for electronic evidence in criminal proceedings, and Directive (EU) 2023/1544 on legal representatives","shortName":"EU e-Evidence Package","jurisdiction":"eu","jurisdictionName":"European Union","region":"eu","topics":["privacy","data-access"],"status":"in_force","citation":"Regulation (EU) 2023/1543; Directive (EU) 2023/1544","enactedDate":"2023-07-12","effectiveDate":"2026-08-18","summary":"Lets judicial authorities in one Member State order service providers in another to produce or preserve electronic evidence, such as subscriber, traffic and content data, directly and within tight deadlines. Non-EU providers offering services in the EU must appoint a designated establishment or legal representative to receive orders.","appliesTo":"Electronic communications services, domain name and IP services, and information society services offered in the EU, including providers established outside the EU.","penalties":"Fines of up to 2% of total worldwide annual turnover of the preceding financial year for non-compliance with orders.","enforcer":"National judicial authorities and Member State enforcing authorities.","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2023/1543/oj/eng","extraSources":["https://publications.europa.eu/resource/celex/32023R1543","https://eur-lex.europa.eu/eli/dir/2023/1544/oj/eng","https://publications.europa.eu/resource/celex/32023L1544"],"notes":"Use of the decentralised IT system becomes mandatory one year after the Commission's implementing acts under Article 25; that date is not yet fixed.","lastVerified":"2026-09-25","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-25 10:55:47","sourceType":"official","verifiedBy":"research from official sources (2026-09-25)","deadlines":[{"id":6864,"regulationId":"eu-e-evidence","date":"2023-08-17","title":"Package enters into force","description":"Published in the OJ on 2023-07-28; enters into force on the 20th day.","kind":"effective","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2023/1543/oj/eng","tentative":false,"review":"verified"},{"id":6865,"regulationId":"eu-e-evidence","date":"2026-02-18","title":"Legal representatives Directive transposition","description":"Member States must transpose Directive (EU) 2023/1544 on designated establishments and legal representatives.","kind":"compliance","sourceUrl":"https://eur-lex.europa.eu/eli/dir/2023/1544/oj/eng","tentative":false,"review":"verified"},{"id":6866,"regulationId":"eu-e-evidence","date":"2026-08-18","title":"e-Evidence Regulation applies","description":"European Production and Preservation Orders become available.","kind":"effective","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2023/1543/oj/eng","tentative":false,"review":"verified"}]},{"id":"eu-us-dpf","name":"Commission Implementing Decision (EU) 2023/1795 on the adequate level of protection of personal data under the EU-US Data Privacy Framework","shortName":"EU-US Data Privacy Framework","jurisdiction":"eu","jurisdictionName":"European Union","region":"eu","topics":["privacy","data-residency"],"status":"in_force","citation":"OJ L 231, 20.9.2023, p. 118 (notified under document C(2023)4745)","enactedDate":"2023-07-10","effectiveDate":"2023-07-10","summary":"GDPR Art 45 adequacy decision letting personal data flow from the EEA to US organisations self-certified under the Data Privacy Framework with the US Department of Commerce, with no further transfer mechanism needed. It relies on US Executive Order 14086 safeguards and the Data Protection Review Court for redress. The EU General Court upheld it in Latombe v Commission (T-553/23) on 3 Sep 2025, and an appeal is pending before the Court of Justice.","appliesTo":"EEA exporters transferring personal data to US organisations on the DPF List (self-certified, under FTC or DOT jurisdiction). Transfers to non-certified US recipients still need SCCs/BCRs, which benefit from the same US safeguards.","penalties":"No standalone fines; unlawful transfers fall under GDPR Art 83(5) (up to EUR 20M or 4% of worldwide turnover). US certified organisations face FTC/DOT enforcement.","enforcer":"European Commission (monitoring, periodic review); EU data protection authorities; US Department of Commerce, FTC and DOT","sourceUrl":"https://eur-lex.europa.eu/eli/dec_impl/2023/1795/oj","extraSources":["https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/eu-us-data-transfers_en","https://curia.europa.eu/jcms/upload/docs/application/pdf/2025-09/cp250106en.pdf","https://iapp.org/news/a/european-general-court-dismisses-latombe-challenge-upholds-eu-us-data-privacy-framework","https://www.wilmerhale.com/en/insights/blogs/wilmerhale-privacy-and-cybersecurity-law/20251201-european-court-of-justice-to-review-challenge-to-eu-us-data-privacy-framework"],"notes":"Art 3(4) required a first review one year after notification. The Commission completed the first periodic review in October 2024 (exact date not re-verified here), with the next review expected after about three years. Appeal case number C-703/25 P and the 31 Oct 2025 lodging date come from secondary sources, not CURIA directly. No CJEU hearing or judgment was found as of the research date. The decision's validity also depends on US safeguards (EO 14086, PCLOB functioning), which the Commission monitors.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-22 20:04:22","sourceType":"official","verifiedBy":"research from official sources","deadlines":[{"id":108,"regulationId":"eu-us-dpf","date":"2023-07-10","title":"DPF adequacy decision adopted and effective","description":"Commission adopted Implementing Decision (EU) 2023/1795, effective on notification to Member States; EU-US transfers to DPF-certified organisations may proceed without additional safeguards.","kind":"effective","sourceUrl":"https://eur-lex.europa.eu/eli/dec_impl/2023/1795/oj","tentative":false,"review":"verified"},{"id":109,"regulationId":"eu-us-dpf","date":"2025-09-03","title":"General Court upholds DPF (Latombe v Commission)","description":"General Court dismissed Philippe Latombe's action for annulment (Case T-553/23) and confirmed the US offered adequate protection when the decision was adopted.","kind":"enforcement","sourceUrl":"https://curia.europa.eu/jcms/upload/docs/application/pdf/2025-09/cp250106en.pdf","tentative":false,"review":"verified"},{"id":110,"regulationId":"eu-us-dpf","date":"2025-10-31","title":"Latombe appeal lodged at the Court of Justice","description":"Latombe appealed the General Court judgment to the Court of Justice on points of law (reported as Case C-703/25 P); the DPF stays valid while it is pending.","kind":"enforcement","sourceUrl":"https://www.wilmerhale.com/en/insights/blogs/wilmerhale-privacy-and-cybersecurity-law/20251201-european-court-of-justice-to-review-challenge-to-eu-us-data-privacy-framework","tentative":false,"review":"verified"}]},{"id":"eg-pdpl","name":"Law No. 151 of 2020 on the Protection of Personal Data and its Executive Regulations","shortName":"Egypt PDPL","jurisdiction":"eg","jurisdictionName":"Egypt","region":"mea","topics":["privacy","data-residency","breach-notification"],"status":"in_force","citation":"Law No. 151 of 2020; Minister of Communications and IT Decree No. 816 of 2025","enactedDate":"2020-07-13","effectiveDate":"2020-10-16","summary":"Egypt's data protection law covers personal data processed electronically. It sets consent and lawful processing rules, strict rules for sensitive data and cross-border transfers, and a licensing and permit system run by the Personal Data Protection Center. The Executive Regulations were only issued in November 2025, which starts a one-year window to comply.","appliesTo":"Holders, controllers and processors of personal data processed electronically in Egypt, and offences by Egyptians abroad or by foreigners where the data concerns Egyptians or residents. Central Bank regulated entities are largely excluded.","penalties":"Criminal fines from EGP 100,000 up to EGP 5 million. Unlawful processing of sensitive data and breaches of cross-border rules carry at least three months in prison and fines of EGP 500,000 to 5 million (Arts. 41 and 42). Licensing breaches carry EGP 500,000 to 5 million (Art. 45).","enforcer":"Personal Data Protection Center (PDPC)","sourceUrl":"https://www.pdpc.gov.eg/assets/pdf-data/PDPL%20no.%20151%20of%202020%20(ar).pdf","extraSources":["https://www.pdpc.gov.eg/laws","https://www.pdpc.gov.eg/assets/pdf-data/Executive%20Regulation.pdf"],"notes":"Both official PDFs are scanned Gazette copies hosted by the PDPC and were read page by page.","lastVerified":"2026-09-25","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-25 11:14:17","sourceType":"official","verifiedBy":"research from official sources (2026-09-25)","deadlines":[{"id":7031,"regulationId":"eg-pdpl","date":"2020-10-16","title":"PDPL takes effect","description":"Article 7 of the issuing law: in force three months after the day following publication (Gazette No. 28 bis (h), 15 July 2020). Date computed from that rule.","kind":"effective","sourceUrl":"https://www.pdpc.gov.eg/assets/pdf-data/PDPL%20no.%20151%20of%202020%20(ar).pdf","tentative":true,"review":"verified"},{"id":7032,"regulationId":"eg-pdpl","date":"2025-11-02","title":"Executive Regulations take effect","description":"Decree No. 816 of 2025 was published in Al-Waqa'i al-Misriyya No. 244 (supplement A) on 1 November 2025 and applies from the next day.","kind":"effective","sourceUrl":"https://www.pdpc.gov.eg/assets/pdf-data/Executive%20Regulation.pdf","tentative":false,"review":"verified"},{"id":7033,"regulationId":"eg-pdpl","date":"2026-11-02","title":"One-year compliance window ends","description":"Article 6 of the issuing law gives those covered one year from the issue of the Executive Regulations to comply. The decree's signing date was not shown, so this date is counted from publication and is an estimate.","kind":"compliance","sourceUrl":"https://www.pdpc.gov.eg/assets/pdf-data/PDPL%20no.%20151%20of%202020%20(ar).pdf","tentative":true,"review":"verified"}]},{"id":"eu-ehds","name":"Regulation (EU) 2025/327 on the European Health Data Space","shortName":"European Health Data Space (EHDS)","jurisdiction":"eu","jurisdictionName":"European Union","region":"eu","topics":["health","privacy","data-access"],"status":"enacted","citation":"OJ L, 2025/327, 5.3.2025","enactedDate":"2025-02-11","effectiveDate":"2025-03-25","summary":"Gives individuals electronic access to, and control over, their health data across the EU (primary use), with a cross-border MyHealth@EU infrastructure and mandatory requirements for electronic health record (EHR) systems. It also creates a permit-based framework for secondary use of health data (research, innovation, policy) through national Health Data Access Bodies, with data holders required to make data available.","appliesTo":"Health data holders (healthcare providers, researchers, companies holding electronic health data; micro-enterprises largely exempt as data holders), manufacturers and distributors of EHR systems and wellness apps claiming interoperability, health data users seeking secondary use, and Member State digital health authorities.","penalties":"Secondary-use infringements by data holders/users: up to EUR 10M or 2% of worldwide annual turnover, and up to EUR 20M or 4% for the most serious infringements, e.g. unlawful re-identification or use outside a data permit (Art 64). Member States set other penalties.","enforcer":"National digital health authorities, Health Data Access Bodies, market surveillance authorities (EHR systems), data protection authorities; EHDS Board and European Commission","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2025/327/oj","extraSources":[],"notes":"Some provisions (e.g. Art 55(6), 70, 73(5), 75(1),(12), 77(4), 78(6)) apply from 26 Mar 2027. Many details depend on implementing acts still being adopted. The effective date is computed as the twentieth day after the 5 Mar 2025 OJ publication.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-22 20:04:22","sourceType":"official","verifiedBy":"research from official sources","deadlines":[{"id":80,"regulationId":"eu-ehds","date":"2025-03-25","title":"EHDS enters into force","description":"Regulation (EU) 2025/327, published 5 Mar 2025, enters into force on the twentieth day following publication.","kind":"effective","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2025/327/oj","tentative":false,"review":"verified"},{"id":81,"regulationId":"eu-ehds","date":"2027-03-26","title":"EHDS general application date","description":"The regulation applies generally from 26 Mar 2027, subject to the phased exceptions below (final article).","kind":"effective","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2025/327/oj","tentative":false,"review":"verified"},{"id":82,"regulationId":"eu-ehds","date":"2029-03-26","title":"Primary use for first data categories; secondary use framework applies","description":"Patient rights and EHR rules apply to patient summaries, ePrescriptions and eDispensations (Art 14(1)(a)-(c)). Chapter IV secondary-use rules (data permits, Health Data Access Bodies) apply.","kind":"compliance","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2025/327/oj","tentative":false,"review":"verified"},{"id":83,"regulationId":"eu-ehds","date":"2031-03-26","title":"Primary use for second data categories; EHR systems in service; extra secondary-use categories","description":"Primary-use rules extend to medical images, lab results and discharge reports (Art 14(1)(d)-(f)). Chapter III applies to EHR systems put into service under Art 26(2). Additional secondary-use categories in Art 51(1)(b),(f),(g),(m),(p) apply.","kind":"compliance","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2025/327/oj","tentative":false,"review":"verified"},{"id":84,"regulationId":"eu-ehds","date":"2035-03-26","title":"Third-country participation in secondary use","description":"Art 75(5) applies from 26 Mar 2035.","kind":"effective","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2025/327/oj","tentative":false,"review":"verified"}]},{"id":"us-fcc-cpni-breach","name":"FCC Data Breach Reporting Requirements for telecommunications carriers, interconnected VoIP and TRS providers (47 CFR 64.2011, 64.5111)","shortName":"FCC CPNI Breach Rule","jurisdiction":"us","jurisdictionName":"United States (Federal)","region":"us-federal","topics":["privacy","breach-notification","cybersecurity"],"status":"amended","citation":"47 CFR 64.2011 and 64.5111; FCC 23-111, WC Docket No. 22-21; 89 FR 9968 (Feb. 12, 2024)","enactedDate":"2024-02-12","effectiveDate":"2024-03-13","summary":"The 2023 order expands carrier breach rules from CPNI to all customer personally identifiable information, covers inadvertent disclosures, requires notice to the FCC (in addition to the Secret Service and FBI) within seven business days, and adopts a harm-based trigger for customer notice. Until the revised 64.2011 takes effect, the existing CPNI breach rule (law enforcement notice within 7 business days, customer notice after a waiting period) continues to apply.","appliesTo":"Telecommunications carriers, interconnected VoIP providers, and telecommunications relay service (TRS) providers. As adopted, breaches affecting fewer than 500 customers with no reasonable likelihood of harm may be reported in an annual summary.","penalties":"Forfeitures under the Communications Act (47 U.S.C. 503); no rule-specific amount.","enforcer":"Federal Communications Commission (Enforcement Bureau)","sourceUrl":"https://www.federalregister.gov/documents/2024/02/12/2024-01667/data-breach-reporting-requirements","extraSources":["https://www.ecfr.gov/current/title-47/chapter-I/subchapter-B/part-64/subpart-U/section-64.2011","https://www.opn.ca6.uscourts.gov/opinions.pdf/25a0224p-06.pdf"],"notes":"As of 2026-09-22 eCFR still shows the revised 64.2011 as a pending amendment (89 FR 10002) and no Federal Register notice announcing its effective date was found. The Sixth Circuit upheld the order in Ohio Telecom Ass'n v. FCC (Aug. 2025).","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-22 20:04:22","sourceType":"official","verifiedBy":"research from official sources","deadlines":[{"id":229,"regulationId":"us-fcc-cpni-breach","date":"2024-03-13","title":"Order effective except revised notification rules","description":"Definitions and other parts of the order took effect; the revised 64.2011 and 64.5111 notification requirements were delayed pending OMB approval.","kind":"effective","sourceUrl":"https://www.federalregister.gov/documents/2024/02/12/2024-01667/data-breach-reporting-requirements","tentative":false,"review":"verified"}]},{"id":"us-ftc-hbnr","name":"FTC Health Breach Notification Rule (16 CFR Part 318), as amended 2024","shortName":"FTC Health Breach Notification Rule","jurisdiction":"us","jurisdictionName":"United States (Federal)","region":"us-federal","topics":["health","privacy","breach-notification"],"status":"amended","citation":"16 CFR Part 318; 74 FR 42962 (2009); amendments 89 FR 47028 (May 30, 2024)","enactedDate":"2009-08-25","effectiveDate":"2009-09-24","summary":"Requires vendors of personal health records (including health and wellness apps) and PHR related entities not covered by HIPAA to notify affected individuals, the FTC and, for 500+ residents of a state, prominent media, after a breach of unsecured PHR identifiable health information. The 2024 amendments confirm that unauthorized disclosures (not just hacks) are breaches, clarify coverage of health apps drawing data from multiple sources, allow email notice, and expand notice content.","appliesTo":"Vendors of personal health records, PHR related entities, and their third-party service providers that are not HIPAA covered entities or business associates. Notice to individuals within 60 calendar days of discovery; FTC notice for breaches of 500+ individuals contemporaneously with individual notice; smaller breaches logged and reported annually.","penalties":"Treated as violations of an FTC trade regulation rule: civil penalties up to $53,088 per violation (FTC Act 5(m)(1)(A) amount as adjusted January 2025, 90 FR 5580; adjusted annually for inflation).","enforcer":"Federal Trade Commission","sourceUrl":"https://www.federalregister.gov/documents/2024/05/30/2024-10855/health-breach-notification-rule","extraSources":["https://www.ecfr.gov/current/title-16/chapter-I/subchapter-C/part-318","https://www.federalregister.gov/citation/74-FR-42962"],"notes":"Prior FTC enforcement: GoodRx ($1.5 million civil penalty, 2023) and Easy Healthcare ($100,000, 2023), cited in the 2024 rule.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-22 20:04:22","sourceType":"official","verifiedBy":"research from official sources","deadlines":[{"id":231,"regulationId":"us-ftc-hbnr","date":"2010-02-22","title":"Full compliance with original Rule","description":"Full compliance with the 2009 Health Breach Notification Rule was required.","kind":"compliance","sourceUrl":"https://www.federalregister.gov/citation/74-FR-42962","tentative":false,"review":"verified"},{"id":232,"regulationId":"us-ftc-hbnr","date":"2024-07-29","title":"2024 amendments effective","description":"Amendments clarifying health app coverage, unauthorized disclosure as breach, email notice and FTC notice timing took effect.","kind":"effective","sourceUrl":"https://www.federalregister.gov/documents/2024/05/30/2024-10855/health-breach-notification-rule","tentative":false,"review":"verified"}]},{"id":"us-fl-fdbr","name":"Florida Digital Bill of Rights (CS/CS/SB 262, 2023)","shortName":"Florida Digital Bill of Rights","jurisdiction":"us-fl","jurisdictionName":"Florida","region":"us-states","topics":["privacy","children"],"status":"in_force","citation":"Fla. Stat. 501.701 to 501.722 (Ch. 2023-201, Laws of Fla.)","enactedDate":"2023-06-07","effectiveDate":"2024-07-01","summary":"Privacy law aimed at very large tech companies: access, correction, deletion, portability and opt-out rights (sale, targeted ads, profiling), opt-in consent for sensitive data, voice/face recognition limits, data retention schedules and protections for known children. Separately, any for-profit business that sells sensitive data must post a notice, and the sale-of-sensitive-data consent rule applies beyond the big-tech controllers.","appliesTo":"Controllers: for-profit entities doing business in Florida with over $1 billion in global gross annual revenue that also (a) derive 50%+ of global revenue from online ad sales, (b) operate a consumer smart speaker and voice command service with a cloud-connected virtual assistant, or (c) operate an app store or digital distribution platform with at least 250,000 software applications (501.702(9)). Some provisions (e.g. sensitive data sale) reach other for-profit entities.","penalties":"Unfair and deceptive trade practice enforceable only by the Department of Legal Affairs: civil penalty up to $50,000 per violation, tripled for violations involving known children, failure to delete or correct after a verified request, or continuing to sell/share after opt-out (501.72(1)). The Department may grant a 45-day cure period at its discretion (not available for child violations) (501.72(2)). No private right of action.","enforcer":"Florida Department of Legal Affairs (Attorney General)","sourceUrl":"https://www.flsenate.gov/Session/Bill/2023/262","extraSources":["http://www.leg.state.fl.us/statutes/index.cfm?App_mode=Display_Statute&URL=0500-0599/0501/Sections/0501.72.html","http://www.leg.state.fl.us/statutes/index.cfm?App_mode=Display_Statute&URL=0500-0599/0501/Sections/0501.702.html"],"notes":"Approved by the Governor June 7, 2023 (Ch. 2023-201), per the Florida Senate bill page. The cure period is discretionary and has no sunset. The app-store threshold (250,000 apps) is from the statute's controller definition, sub-subparagraph c; only (a) and (b) were read verbatim. No amendments found through Sept 2026.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-22 20:04:22","sourceType":"official","verifiedBy":"research from official sources","deadlines":[{"id":230,"regulationId":"us-fl-fdbr","date":"2024-07-01","title":"Florida Digital Bill of Rights takes effect","description":"SB 262 obligations under Fla. Stat. 501.701-501.722 apply.","kind":"effective","sourceUrl":"https://www.flsenate.gov/Session/Bill/2023/262","tentative":false,"review":"verified"}]},{"id":"eu-gdpr","name":"Regulation (EU) 2016/679 (General Data Protection Regulation)","shortName":"GDPR","jurisdiction":"eu","jurisdictionName":"European Union","region":"eu","topics":["privacy","breach-notification","data-access","children","biometrics","health"],"status":"amended","citation":"OJ L 119, 4.5.2016, p. 1","enactedDate":"2016-04-27","effectiveDate":"2016-05-24","summary":"The EU's core data protection law: any processing of personal data needs a lawful basis, must follow principles such as purpose limitation and data minimisation, and gives individuals rights of access, erasure, portability and objection. Controllers must notify breaches to the supervisory authority within 72 hours and restrict transfers outside the EEA to adequate countries or safeguarded mechanisms. Regulation (EU) 2025/2518 adds harmonised procedural rules for cross-border enforcement from 2 April 2027.","appliesTo":"Controllers and processors established in the EU, and non-EU controllers/processors that offer goods or services to, or monitor the behaviour of, individuals in the EU. No revenue or volume threshold; some record-keeping relief below 250 employees.","penalties":"Up to EUR 20M or 4% of total worldwide annual turnover of the preceding year, whichever is higher (Art 83(5)); up to EUR 10M or 2% for other infringements (Art 83(4)).","enforcer":"National data protection supervisory authorities (DPAs), coordinated by the European Data Protection Board (EDPB) via the one-stop-shop mechanism","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2016/679/oj","extraSources":["https://eur-lex.europa.eu/eli/reg/2025/2518/oj","https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:52025PC0837","https://www.europarl.europa.eu/legislative-train/theme-a-new-plan-for-europe-s-sustainable-prosperity-and-competitiveness/file-digital-package","https://www.consilium.europa.eu/en/press/press-releases/2025/11/17/council-adopts-new-eu-law-to-speed-up-handling-cross-border-data-protection-complaints/"],"notes":"Digital Omnibus proposal COM(2025) 837 (19 Nov 2025, procedure 2025/0360(COD)) would amend the GDPR: clarify the definition of personal data, move cookie/terminal-equipment consent from the ePrivacy Directive into a new GDPR Art 88a, add machine-readable preference signals (Art 88b), and require breach notification to DPAs only for high-risk breaches within 96 hours via a single-entry point. As of the Parliament Legislative Train update of 1 Aug 2026 it is still 'tabled': ITRE/LIBE draft report 22 June 2026, 1,750+ amendments, no plenary vote, a planned Council mandate vote on 26 June 2026 was cancelled, and no trilogues. None of these changes are law. The procedural regulation's 12- and 15-month investigation timelines are reported by the Council; check the regulation text for exact extensions.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-22 20:04:22","sourceType":"official","verifiedBy":"research from official sources","deadlines":[{"id":93,"regulationId":"eu-gdpr","date":"2016-05-24","title":"GDPR enters into force","description":"Regulation entered into force on the twentieth day after publication in OJ L 119 of 4 May 2016 (Art 99(1)).","kind":"effective","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2016/679/oj","tentative":false,"review":"verified"},{"id":94,"regulationId":"eu-gdpr","date":"2018-05-25","title":"GDPR applies","description":"All GDPR obligations apply from 25 May 2018 (Art 99(2)), replacing Directive 95/46/EC.","kind":"effective","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2016/679/oj","tentative":false,"review":"verified"},{"id":95,"regulationId":"eu-gdpr","date":"2025-11-26","title":"GDPR Procedural Regulation adopted","description":"Regulation (EU) 2025/2518 laying down additional procedural rules for cross-border GDPR enforcement signed by Parliament and Council.","kind":"transition","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2025/2518/oj","tentative":false,"review":"verified"},{"id":96,"regulationId":"eu-gdpr","date":"2026-01-01","title":"GDPR Procedural Regulation enters into force","description":"Regulation (EU) 2025/2518, published in the OJ on 12 December 2025, enters into force on the twentieth day after publication.","kind":"transition","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2025/2518/oj","tentative":false,"review":"verified"},{"id":97,"regulationId":"eu-gdpr","date":"2027-04-02","title":"GDPR Procedural Regulation applies","description":"Harmonised rules for cross-border complaint admissibility, rights to be heard and access to preliminary findings, and investigation timelines apply to DPAs from 2 April 2027 (Regulation (EU) 2025/2518, final article).","kind":"enforcement","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2025/2518/oj","tentative":false,"review":"verified"}]},{"id":"us-glba-safeguards","name":"FTC Standards for Safeguarding Customer Information (Safeguards Rule), 16 CFR Part 314, under the Gramm-Leach-Bliley Act","shortName":"GLBA Safeguards Rule","jurisdiction":"us","jurisdictionName":"United States (Federal)","region":"us-federal","topics":["financial","cybersecurity","breach-notification","privacy"],"status":"amended","citation":"15 U.S.C. 6801(b), 6805(b)(2); 16 CFR Part 314; amendments at 86 FR 70272 (2021) and 88 FR 77499 (2023)","enactedDate":"1999-11-12","effectiveDate":"2003-05-23","summary":"Requires non-bank financial institutions under FTC jurisdiction to maintain a written information security program with a qualified individual, risk assessments, access controls, encryption, MFA, monitoring and board reporting. Since May 13, 2024, institutions must notify the FTC within 30 days of discovering a 'notification event' (unauthorized acquisition of unencrypted customer information) affecting at least 500 consumers.","appliesTo":"Financial institutions subject to FTC jurisdiction (e.g. mortgage brokers, lenders, auto dealers, tax preparers, payment and fintech companies, and other non-bank entities significantly engaged in financial activities). Certain program elements (written risk assessment, continuous monitoring/pen testing, incident response plan, annual board report) do not apply to institutions holding customer information on fewer than 5,000 consumers.","penalties":"The Rule itself carries no civil penalty; the FTC enforces through Section 5 of the FTC Act (injunctive orders), with civil penalties for violating resulting orders.","enforcer":"Federal Trade Commission","sourceUrl":"https://www.ecfr.gov/current/title-16/chapter-I/subchapter-C/part-314","extraSources":["https://www.federalregister.gov/documents/2023/11/13/2023-24412/standards-for-safeguarding-customer-information","https://www.federalregister.gov/documents/2022/11/23/2022-25201/standards-for-safeguarding-customer-information","https://www.federalregister.gov/documents/2021/12/09/2021-25736/standards-for-safeguarding-customer-information"],"notes":"Banks and credit unions follow the parallel Interagency Guidelines, not this Rule. FTC notices of notification events may be made public.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-22 20:04:22","sourceType":"official","verifiedBy":"research from official sources","deadlines":[{"id":233,"regulationId":"us-glba-safeguards","date":"2022-01-10","title":"2021 Safeguards Rule amendments effective","description":"The amended Safeguards Rule published December 9, 2021 took effect, with the more detailed program elements in 314.5 deferred.","kind":"effective","sourceUrl":"https://www.federalregister.gov/documents/2021/12/09/2021-25736/standards-for-safeguarding-customer-information","tentative":false,"review":"verified"},{"id":234,"regulationId":"us-glba-safeguards","date":"2023-06-09","title":"Compliance with expanded security program elements","description":"Applicability of the 314.5 provisions (qualified individual, written risk assessment, encryption, MFA, pen testing, incident response plan, board reporting) was delayed from December 9, 2022 to this date.","kind":"compliance","sourceUrl":"https://www.federalregister.gov/documents/2022/11/23/2022-25201/standards-for-safeguarding-customer-information","tentative":false,"review":"verified"},{"id":235,"regulationId":"us-glba-safeguards","date":"2024-05-13","title":"FTC breach notification requirement effective","description":"Section 314.4(j) requires notice to the FTC within 30 days of discovering a notification event involving at least 500 consumers.","kind":"effective","sourceUrl":"https://www.federalregister.gov/documents/2023/11/13/2023-24412/standards-for-safeguarding-customer-information","tentative":false,"review":"verified"}]},{"id":"us-hipaa","name":"HIPAA Privacy, Security and Breach Notification Rules (45 CFR Parts 160 and 164)","shortName":"HIPAA","jurisdiction":"us","jurisdictionName":"United States (Federal)","region":"us-federal","topics":["privacy","health","cybersecurity","breach-notification"],"status":"amended","citation":"Pub. L. 104-191; 42 U.S.C. 1320d et seq.; 45 CFR Parts 160 and 164","enactedDate":"1996-08-21","effectiveDate":"2003-04-14","summary":"Sets national standards for the use and disclosure of protected health information (Privacy Rule), administrative, physical and technical safeguards for electronic PHI (Security Rule), and notification of breaches of unsecured PHI. A proposed overhaul of the Security Rule (Jan. 2025 NPRM) would make most 'addressable' specifications mandatory, require asset inventories, MFA, encryption, annual compliance audits and 72-hour restoration planning, but it is not final. The 2024 reproductive health care privacy amendments were vacated nationwide in June 2025.","appliesTo":"Covered entities (health plans, health care clearinghouses, and health care providers that conduct standard electronic transactions) and their business associates, including cloud and data vendors that create, receive, maintain or transmit PHI. No size threshold.","penalties":"Civil money penalties, 2026 inflation-adjusted (91 FR 3665): tiered from $145 to $73,011 per violation, with a calendar-year cap of $2,190,294 per identical provision. Criminal penalties under 42 U.S.C. 1320d-6 up to $250,000 and 10 years' imprisonment for offenses with intent to sell or use PHI for commercial advantage or malicious harm.","enforcer":"HHS Office for Civil Rights (OCR); State Attorneys General (HITECH); DOJ for criminal violations","sourceUrl":"https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164","extraSources":["https://www.federalregister.gov/documents/2025/01/06/2024-30983/hipaa-security-rule-to-strengthen-the-cybersecurity-of-electronic-protected-health-information","https://www.federalregister.gov/documents/2024/04/26/2024-08503/hipaa-privacy-rule-to-support-reproductive-health-care-privacy","https://www.federalregister.gov/documents/2026/01/28/2026-01688/annual-civil-monetary-penalties-inflation-adjustment","https://www.reginfo.gov/public/do/eAgendaViewRule?pubId=202510&RIN=0945-AA22","https://www.hklaw.com/en/insights/publications/2025/06/hipaas-reproductive-health-rule-is-vacated-nationally","https://www.americanbar.org/groups/health_law/news/2025/signaling-end-purl-case/"],"notes":"Security Rule NPRM (90 FR 898, Jan. 6, 2025; RIN 0945-AA22): the Unified Agenda lists final action for 07/2027 (month only, so no deadline row). The NPRM proposed a compliance date 180 days after a final rule's effective date. Reproductive health rule vacated June 18, 2025 (Purl v. HHS, N.D. Tex.), except NPP amendments tied to Part 2; the Fifth Circuit dismissed the appeal in September 2025 (per ABA/law firm reporting). Original Privacy Rule compliance date April 14, 2003 (small health plans April 14, 2004); Security Rule compliance April 20, 2005. HHS also exercises 2019 enforcement discretion capping annual penalties per tier below the statutory cap.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-22 20:04:22","sourceType":"official","verifiedBy":"research from official sources","deadlines":[{"id":236,"regulationId":"us-hipaa","date":"2024-06-25","title":"Reproductive health care privacy rule effective (later vacated)","description":"The HIPAA Privacy Rule to Support Reproductive Health Care Privacy (89 FR 32976) took effect; it was vacated nationwide on June 18, 2025 in Purl v. HHS (N.D. Tex.).","kind":"effective","sourceUrl":"https://www.federalregister.gov/documents/2024/04/26/2024-08503/hipaa-privacy-rule-to-support-reproductive-health-care-privacy","tentative":false,"review":"verified"},{"id":237,"regulationId":"us-hipaa","date":"2024-12-23","title":"Reproductive health privacy compliance date (vacated)","description":"Original compliance date for the reproductive health care privacy provisions, including the attestation requirement; these provisions no longer apply after the June 2025 vacatur.","kind":"compliance","sourceUrl":"https://www.federalregister.gov/documents/2024/04/26/2024-08503/hipaa-privacy-rule-to-support-reproductive-health-care-privacy","tentative":false,"review":"verified"},{"id":238,"regulationId":"us-hipaa","date":"2025-03-07","title":"Security Rule NPRM comment period closed","description":"Comments closed on the proposed HIPAA Security Rule update (90 FR 898); OCR has not issued a final rule.","kind":"transition","sourceUrl":"https://www.federalregister.gov/documents/2025/01/06/2024-30983/hipaa-security-rule-to-strengthen-the-cybersecurity-of-electronic-protected-health-information","tentative":false,"review":"verified"},{"id":239,"regulationId":"us-hipaa","date":"2026-02-16","title":"Notice of Privacy Practices updates (Part 2 alignment)","description":"Covered entities must update Notices of Privacy Practices under 45 CFR 164.520 for the 2024 Part 2 (substance use disorder records) changes; this NPP piece survived the Purl vacatur.","kind":"compliance","sourceUrl":"https://www.federalregister.gov/documents/2024/04/26/2024-08503/hipaa-privacy-rule-to-support-reproductive-health-care-privacy","tentative":false,"review":"verified"}]},{"id":"us-hhs-hipaa-security-nprm","name":"HIPAA Security Rule To Strengthen the Cybersecurity of Electronic Protected Health Information (proposed rule)","shortName":"HIPAA Security Rule update (NPRM)","jurisdiction":"us","jurisdictionName":"United States","region":"us-federal","topics":["health","cybersecurity","privacy"],"status":"proposed","citation":"90 FR 898 (RIN 0945-AA22); would amend 45 CFR Parts 160 and 164","enactedDate":"","effectiveDate":"","summary":"Proposed overhaul of the HIPAA Security Rule. It would remove the addressable versus required distinction, and require a technology asset inventory and network map, encryption, multi-factor authentication, vulnerability scanning, penetration testing and 72-hour restoration planning. No final rule has been issued.","appliesTo":"HIPAA covered entities (health plans, clearinghouses, most providers) and their business associates.","penalties":"HIPAA civil money penalties under HITECH tiers once final.","enforcer":"HHS Office for Civil Rights","sourceUrl":"https://www.federalregister.gov/documents/2025/01/06/2024-30983/hipaa-security-rule-to-strengthen-the-cybersecurity-of-electronic-protected-health-information","extraSources":["https://www.reginfo.gov/public/do/eAgendaViewRule?pubId=202510&RIN=0945-AA22"],"notes":"The Fall 2025 Unified Agenda lists this as a Long-Term Action with a final action targeted for July 2027 (no exact day, so not listed as a deadline). The proposal would give most entities 180 days after the final rule's effective date to comply.","lastVerified":"2026-09-25","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-25 10:55:47","sourceType":"official","verifiedBy":"research from official sources (2026-09-25)","deadlines":[{"id":6890,"regulationId":"us-hhs-hipaa-security-nprm","date":"2025-01-06","title":"NPRM published","description":"Proposed Security Rule changes published in the Federal Register.","kind":"transition","sourceUrl":"https://www.federalregister.gov/documents/2025/01/06/2024-30983/hipaa-security-rule-to-strengthen-the-cybersecurity-of-electronic-protected-health-information","tentative":false,"review":"verified"},{"id":6891,"regulationId":"us-hhs-hipaa-security-nprm","date":"2025-03-07","title":"Comment period closes","description":"Public comments on the NPRM due.","kind":"reporting","sourceUrl":"https://www.federalregister.gov/documents/2025/01/06/2024-30983/hipaa-security-rule-to-strengthen-the-cybersecurity-of-electronic-protected-health-information","tentative":false,"review":"verified"}]},{"id":"hk-pcico","name":"Protection of Critical Infrastructures (Computer Systems) Ordinance (Cap. 653)","shortName":"Hong Kong Critical Infrastructure Cyber Ordinance","jurisdiction":"hk","jurisdictionName":"Hong Kong","region":"apac","topics":["cybersecurity","breach-notification"],"status":"in_force","citation":"Cap. 653","enactedDate":"2025-03-28","effectiveDate":"2026-01-01","summary":"Hong Kong's critical infrastructure cybersecurity law. Designated critical infrastructure operators (CIOs) must keep a Hong Kong office, set up a computer-system security management unit, run risk assessments and audits, keep security and emergency plans, take part in drills, and report incidents. Serious incidents must be reported within 12 hours and other incidents within 48 hours.","appliesTo":"Operators designated by regulators in 8 sectors: energy, IT, banking and financial services, air transport, land transport, maritime transport, healthcare, and telecommunications and broadcasting (plus other infrastructure critical to society). Only designated CIOs and their designated critical computer systems are covered.","penalties":"Fines from HKD 300,000 up to HKD 5 million, plus daily fines for continuing offences.","enforcer":"Commissioner of Critical Infrastructure (Computer-system Security) under the Security Bureau; Hong Kong Monetary Authority and Communications Authority as designated authorities for their sectors","sourceUrl":"https://www.elegislation.gov.hk/hk/cap653","extraSources":["https://www.info.gov.hk/gia/general/202506/27/P2025062700238.htm","https://www.coms-auth.hk/en/policies_regulations/other/pcicso/index.html","https://www.mayerbrown.com/en/insights/publications/2026/01/hong-kong-issues-code-of-practice-under-the-protection-of-critical-infrastructures-computer-systems-ordinance"],"notes":"Gazetted 28 Mar 2025 (the date used as enacted_date); commencement notice gazetted 27 Jun 2025. Duties for each operator run from its designation date, so there is no fixed calendar deadline. The penalty range comes from the Baker McKenzie summary. Reporting windows come from the Code of Practice via Mayer Brown.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-22 20:04:22","sourceType":"official","verifiedBy":"research from official sources","deadlines":[{"id":111,"regulationId":"hk-pcico","date":"2026-01-01","title":"PCICSO comes into operation","description":"Commissioner's Office is established and designation of CIOs begins; obligations apply to designated operators.","kind":"effective","sourceUrl":"https://www.info.gov.hk/gia/general/202506/27/P2025062700238.htm","tentative":false,"review":"verified"}]},{"id":"hk-pdpo","name":"Personal Data (Privacy) Ordinance (Cap. 486)","shortName":"Hong Kong PDPO","jurisdiction":"hk","jurisdictionName":"Hong Kong","region":"apac","topics":["privacy","online-safety"],"status":"amended","citation":"Cap. 486","enactedDate":"","effectiveDate":"1996-12-20","summary":"Hong Kong's privacy law for public and private data users, built on six Data Protection Principles covering collection, accuracy and retention, use, security, openness and access. Amendments in 2012 added direct marketing rules. The 2021 amendment made doxxing a crime and gave the Privacy Commissioner powers to investigate, prosecute and order removal of doxxing content.","appliesTo":"Any person in Hong Kong who controls the collection, holding, processing or use of personal data, in both public and private sectors.","penalties":"Breaking a DPP is not itself an offence, but breaching an enforcement notice carries up to HK$50,000 and 2 years in prison (HK$100,000 on repeat). Direct marketing offences carry up to HK$500,000 and 3 years, or HK$1 million and 5 years for sale of data. Doxxing carries up to HK$100,000 and 2 years, or HK$1 million and 5 years on indictment.","enforcer":"Privacy Commissioner for Personal Data (PCPD)","sourceUrl":"https://www.pcpd.org.hk/english/data_privacy_law/ordinance_at_a_Glance/ordinance.html","extraSources":["https://www.pcpd.org.hk/english/data_privacy_law/amendments_2021/amendment_2021.html","https://www.elegislation.gov.hk/hk/cap486"],"notes":"Passed in 1995. There is no mandatory breach notification or administrative fining power yet. Reform proposals have not been enacted.","lastVerified":"2026-09-25","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-25 11:14:17","sourceType":"official","verifiedBy":"research from official sources (2026-09-25)","deadlines":[{"id":7003,"regulationId":"hk-pdpo","date":"1996-12-20","title":"PDPO takes effect","description":"The PCPD says the PDPO took effect in December 1996, except certain provisions. The exact day was not confirmed on the official pages checked.","kind":"effective","sourceUrl":"https://www.pcpd.org.hk/english/data_privacy_law/ordinance_at_a_Glance/ordinance.html","tentative":true,"review":"verified"},{"id":7004,"regulationId":"hk-pdpo","date":"2021-10-08","title":"Anti-doxxing amendments take effect","description":"New doxxing offences and PCPD criminal investigation, prosecution and cessation notice powers apply.","kind":"effective","sourceUrl":"https://www.pcpd.org.hk/english/data_privacy_law/amendments_2021/amendment_2021.html","tentative":false,"review":"verified"}]},{"id":"us-il-hb3773","name":"Illinois HB 3773 (Public Act 103-0804), amending the Illinois Human Rights Act on artificial intelligence in employment","shortName":"Illinois AI in Employment Law (HB 3773)","jurisdiction":"us-il","jurisdictionName":"Illinois","region":"us-states","topics":["ai"],"status":"in_force","citation":"Public Act 103-0804; 775 ILCS 5/2-102(L)","enactedDate":"2024-08-09","effectiveDate":"2026-01-01","summary":"Makes it a civil-rights violation for an employer to use AI that has the effect of discriminating against employees or applicants on the basis of a protected class in recruitment, hiring, promotion, discipline, discharge or the terms of employment. It also bars using ZIP codes as a proxy for a protected class. Employers must notify employees when they use AI for these decisions; IDHR is to set the notice rules.","appliesTo":"Employers covered by the Illinois Human Rights Act, generally those with 1 or more employees in Illinois, using AI (including generative AI) for covered employment decisions.","penalties":"Remedies under the Illinois Human Rights Act (e.g., actual damages, back pay, attorney fees) through IDHR charge process and Human Rights Commission or civil action. No AI-specific fine amount.","enforcer":"Illinois Department of Human Rights; Illinois Human Rights Commission; private civil action after the IDHR process","sourceUrl":"https://www.ilga.gov/ftp/legislation/103/BillStatus/HTML/10300HB3773.html","extraSources":["https://ogletree.com/insights-resources/blog-posts/illinois-postpones-proposed-regulations-on-ai-in-employment/"],"notes":"The statute applies without implementing rules. As of September 2026, IDHR's notice rules were withdrawn and pending, with no timeline announced. The 1-employee IHRA coverage threshold is general IHRA law and was not re-verified for this record.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-22 20:04:22","sourceType":"official","verifiedBy":"research from official sources","deadlines":[{"id":244,"regulationId":"us-il-hb3773","date":"2024-08-09","title":"HB 3773 signed","description":"Governor Pritzker signs Public Act 103-0804.","kind":"transition","sourceUrl":"https://www.ilga.gov/ftp/legislation/103/BillStatus/HTML/10300HB3773.html","tentative":false,"review":"verified"},{"id":245,"regulationId":"us-il-hb3773","date":"2026-01-01","title":"AI anti-discrimination and notice duties apply","description":"Prohibition on discriminatory AI use and the employee notice requirement take effect.","kind":"effective","sourceUrl":"https://www.ilga.gov/ftp/legislation/103/BillStatus/HTML/10300HB3773.html","tentative":false,"review":"verified"},{"id":246,"regulationId":"us-il-hb3773","date":"2026-05-15","title":"IDHR proposed notice rules published","description":"IDHR publishes proposed Subpart J rules on AI notice in the Illinois Register.","kind":"transition","sourceUrl":"https://ogletree.com/insights-resources/blog-posts/illinois-postpones-proposed-regulations-on-ai-in-employment/","tentative":false,"review":"verified"},{"id":247,"regulationId":"us-il-hb3773","date":"2026-06-02","title":"IDHR withdraws and postpones proposed rules","description":"IDHR withdraws the Subpart J proposal and postpones the June 10, 2026 hearing; no new date announced.","kind":"transition","sourceUrl":"https://ogletree.com/insights-resources/blog-posts/illinois-postpones-proposed-regulations-on-ai-in-employment/","tentative":false,"review":"verified"}]},{"id":"us-il-bipa","name":"Illinois Biometric Information Privacy Act (740 ILCS 14), as amended by SB 2979 (Public Act 103-0769)","shortName":"Illinois BIPA","jurisdiction":"us-il","jurisdictionName":"Illinois","region":"us-states","topics":["biometrics","privacy"],"status":"amended","citation":"740 ILCS 14; Public Act 95-994; Public Act 103-0769","enactedDate":"","effectiveDate":"2008-10-03","summary":"Private entities must publish a biometric retention and destruction policy, give written notice, and obtain a written release before collecting biometric identifiers such as fingerprints, face geometry or voiceprints. They may not sell or profit from biometric data and need consent to disclose it. The 2024 SB 2979 amendment treats repeated collection or disclosure from the same person by the same method as a single violation and allows electronic signatures for consent. The Seventh Circuit held on April 1, 2026 that the amendment applies retroactively to pending cases.","appliesTo":"Any private entity (individual, company, partnership, etc.) collecting, capturing, purchasing, receiving, possessing or disclosing biometric identifiers or information of Illinois residents. No size threshold; government agencies excluded.","penalties":"Private right of action: $1,000 liquidated damages per negligent violation or $5,000 per intentional or reckless violation (or actual damages if greater), plus attorney fees. After PA 103-0769, at most one recovery per person per method of collection.","enforcer":"Private right of action (courts)","sourceUrl":"https://www.ilga.gov/legislation/ilcs/ilcs3.asp?ActID=3004&ChapterID=57","extraSources":["https://www.ilga.gov/Legislation/publicacts/view/103-0769","https://law.justia.com/cases/federal/appellate-courts/ca7/25-2185/25-2185-2026-04-01.html"],"notes":"BIPA's enacted date is not included here; its effective date comes from Public Act 95-994. The Illinois Supreme Court has not ruled on whether the amendment is retroactive, so the Seventh Circuit decision binds federal courts only.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-22 20:04:22","sourceType":"official","verifiedBy":"research from official sources","deadlines":[{"id":241,"regulationId":"us-il-bipa","date":"2008-10-03","title":"BIPA effective","description":"The Biometric Information Privacy Act takes effect.","kind":"effective","sourceUrl":"https://www.ilga.gov/legislation/ilcs/ilcs3.asp?ActID=3004&ChapterID=57","tentative":false,"review":"verified"},{"id":242,"regulationId":"us-il-bipa","date":"2024-08-02","title":"SB 2979 amendment effective","description":"Public Act 103-0769 signed and effective immediately: single recovery per person and electronic signatures allowed for consent.","kind":"effective","sourceUrl":"https://www.ilga.gov/Legislation/publicacts/view/103-0769","tentative":false,"review":"verified"},{"id":243,"regulationId":"us-il-bipa","date":"2026-04-01","title":"Seventh Circuit: amendment applies retroactively","description":"Clay v. Union Pacific (No. 25-2185) holds the damages amendment is remedial and applies to pending cases.","kind":"transition","sourceUrl":"https://law.justia.com/cases/federal/appellate-courts/ca7/25-2185/25-2185-2026-04-01.html","tentative":false,"review":"verified"}]},{"id":"in-certin-directions","name":"Directions under section 70B(6) of the Information Technology Act, 2000 relating to information security practices, procedure, prevention, response and reporting of cyber incidents for Safe and Trusted Internet","shortName":"India CERT-In Cyber Security Directions","jurisdiction":"in","jurisdictionName":"India","region":"apac","topics":["cybersecurity","breach-notification","data-residency"],"status":"in_force","citation":"CERT-In Directions No. 20(3)/2022-CERT-In, 28 Apr 2022","enactedDate":"2022-04-28","effectiveDate":"2022-06-27","summary":"Requires service providers, intermediaries, data centres, body corporates and government bodies to report listed cyber incidents to CERT-In within 6 hours of noticing them. Entities must sync clocks to Indian NTP servers, keep ICT logs for a rolling 180 days within India, and name a point of contact. Data centre, VPS, cloud and VPN providers must keep validated subscriber details for 5 years.","appliesTo":"Service providers, intermediaries, data centres, body corporates and government organisations in India, with extra record duties for data centres, VPS, cloud and VPN providers, virtual asset providers and exchanges.","penalties":"Non-compliance can lead to punitive action under section 70B(7) of the IT Act, which provides for imprisonment of up to one year, a fine of up to INR 1 lakh, or both.","enforcer":"Indian Computer Emergency Response Team (CERT-In), MeitY","sourceUrl":"https://www.cert-in.org.in/PDF/CERT-In_Directions_70B_28.04.2022.pdf","extraSources":["https://www.cert-in.org.in/PDF/CERT-In_directions_extension_MSMEs_and_validation_27.06.2022.pdf","https://www.cert-in.org.in/Directions70B.jsp","https://www.cert-in.org.in/PDF/FAQs_on_CyberSecurityDirections_May2022.pdf"],"notes":"The Directions say they take effect 60 days after issue, and the 27 June 2022 extension notice repeats this without naming a day, so the main effective date is marked tentative. Penalty figures come from section 70B(7) of the IT Act, which the Directions cite.","lastVerified":"2026-09-25","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-25 11:14:17","sourceType":"official","verifiedBy":"research from official sources (2026-09-25)","deadlines":[{"id":6991,"regulationId":"in-certin-directions","date":"2022-06-27","title":"CERT-In Directions take effect","description":"The Directions apply 60 days after issue on 28 Apr 2022. The exact day (27 or 28 June 2022) depends on how the 60 days are counted.","kind":"effective","sourceUrl":"https://www.cert-in.org.in/PDF/CERT-In_Directions_70B_28.04.2022.pdf","tentative":true,"review":"verified"},{"id":6992,"regulationId":"in-certin-directions","date":"2022-09-25","title":"Extended date for MSMEs and subscriber validation","description":"The Directions apply to micro, small and medium enterprises, and subscriber validation duties apply to data centres, VPS, cloud and VPN providers, from this date.","kind":"compliance","sourceUrl":"https://www.cert-in.org.in/PDF/CERT-In_directions_extension_MSMEs_and_validation_27.06.2022.pdf","tentative":false,"review":"verified"}]},{"id":"in-dpdp","name":"Digital Personal Data Protection Act, 2023 and Digital Personal Data Protection Rules, 2025","shortName":"India DPDP Act","jurisdiction":"in","jurisdictionName":"India","region":"apac","topics":["privacy","children","breach-notification"],"status":"enacted","citation":"Act No. 22 of 2023; DPDP Rules 2025 G.S.R. 846(E) (13 Nov 2025); Act commencement notification G.S.R. 843(E)","enactedDate":"2023-08-11","effectiveDate":"2025-11-13","summary":"India's first comprehensive data protection law: consent-based processing with notice, data principal rights, security safeguards, breach notification to the Data Protection Board and affected individuals, verifiable parental consent for children under 18, and extra duties for Significant Data Fiduciaries. The Rules notified in November 2025 phase it in: Board and procedure now, consent managers at 12 months, and main fiduciary obligations at 18 months.","appliesTo":"Processing of digital personal data in India, and processing outside India connected with offering goods or services to data principals in India. No revenue or volume threshold; Significant Data Fiduciaries (designated by the government on volume and risk) have extra duties (DPO in India, annual DPIA and audit).","penalties":"Schedule to the Act: up to INR 250 crore for failing to take reasonable security safeguards to prevent a breach; up to INR 200 crore for failing to notify a breach or breaching children's-data obligations; up to INR 150 crore for Significant Data Fiduciary obligations; up to INR 50 crore for other breaches. Imposed by the Data Protection Board.","enforcer":"Data Protection Board of India (MeitY)","sourceUrl":"https://egazette.gov.in/WriteReadData/2025/267650.pdf","extraSources":["https://www.meity.gov.in/documents/act-and-policies/digital-personal-data-protection-rules-2025","https://dpdprules.org/rules/1"],"notes":"Fact-check 2026-09-22 against the eGazette PDF: Gazette of India Extraordinary No. 760, Part II Section 3(i), dated Thursday 13 November 2025, G.S.R. 846(E). The eGazette ID CG-DL-E-14112025-267650 reflects upload on 14 Nov 2025, which is why some sources cite 14 Nov; the publication date is 13 Nov 2025. Rule 1(3) and 1(4) run 'one year' and 'eighteen months after the date of publication of this Gazette', giving 13 Nov 2026 and 13 May 2027. Corrigendum G.S.R. 892(E) of 11 Dec 2025 fixed wording only. MeitY consulted in early 2026 on shortening the 18-month runway to 12 months; not notified as of verification. The MeitY page is JavaScript-rendered and could not be read directly; dates come from the Rule 1 text in the gazette.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-22 20:04:22","sourceType":"official","verifiedBy":"research from official sources","deadlines":[{"id":116,"regulationId":"in-dpdp","date":"2025-11-13","title":"DPDP Rules published; Board and procedural rules in force","description":"Rules 1, 2 and 17-21 (Data Protection Board constitution and functioning) take effect on publication in the Official Gazette.","kind":"effective","sourceUrl":"https://egazette.gov.in/WriteReadData/2025/267650.pdf","tentative":false,"review":"verified"},{"id":117,"regulationId":"in-dpdp","date":"2026-11-13","title":"Consent Manager registration rule in force (12 months)","description":"Rule 4 (registration and obligations of Consent Managers) comes into force one year after publication.","kind":"transition","sourceUrl":"https://egazette.gov.in/WriteReadData/2025/267650.pdf","tentative":false,"review":"verified"},{"id":118,"regulationId":"in-dpdp","date":"2027-05-13","title":"Main data fiduciary obligations apply (18 months)","description":"Rules 3, 5-16, 22 and 23 (notice, security safeguards, breach notification, retention, children's consent, SDF duties, cross-border) come into force 18 months after publication.","kind":"compliance","sourceUrl":"https://egazette.gov.in/WriteReadData/2025/267650.pdf","tentative":false,"review":"verified"}]},{"id":"in-it-rules-sgi","name":"Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2026","shortName":"India IT Rules amendment on synthetic content","jurisdiction":"in","jurisdictionName":"India","region":"apac","topics":["ai","online-safety"],"status":"in_force","citation":"G.S.R. 120(E), Gazette of India Extraordinary No. 114, 10 Feb 2026","enactedDate":"2026-02-10","effectiveDate":"2026-02-20","summary":"Amends India's IT Rules 2021 to regulate synthetically generated information (AI-made or AI-altered audio, images and video). Intermediaries that enable such content must label it prominently, keep labels and metadata from being removed, and significant social media intermediaries must get a user declaration and verify it. Takedown clocks are cut sharply: 3 hours after a court or government order, 36 hours for certain grievances, and 2 hours for intimate or morphed images.","appliesTo":"Intermediaries under the IT Act 2000 operating in India, with added duties for significant social media intermediaries and for services that let users create or alter synthetic content.","penalties":"Intermediaries that fail due diligence lose the safe harbour under section 79 of the IT Act and can be liable for user content. Other penalties follow the IT Act and criminal law.","enforcer":"Ministry of Electronics and Information Technology (MeitY)","sourceUrl":"https://www.meity.gov.in/static/uploads/2026/02/f55fe52418b03f58b0669f6a8bc03b6d.pdf","extraSources":["https://www.meity.gov.in/static/uploads/2025/10/065b6deb585441b5ccdf8be42502a49c.pdf","https://www.meity.gov.in/static/uploads/2026/03/20c30107195f68865104dd4e16176f4d.pdf","https://www.meity.gov.in/documents/act-and-policies/information-technology-intermediary-guidelines-and-digital-media-ethics-code-rules-2021-it-rules-2021-IjM5QjMtQWa"],"notes":"Notified 10 Feb 2026 after a draft published for consultation in October 2025. A corrigendum (G.S.R. 148(E)) was published on 26 Feb 2026. MeitY issued FAQs on the same date as the notification.","lastVerified":"2026-09-25","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-25 11:14:17","sourceType":"official","verifiedBy":"research from official sources (2026-09-25)","deadlines":[{"id":6990,"regulationId":"in-it-rules-sgi","date":"2026-02-20","title":"Synthetic content rules take effect","description":"SGI labeling, user declaration and verification duties, and the shorter 3 hour, 36 hour and 2 hour takedown timelines apply.","kind":"effective","sourceUrl":"https://www.meity.gov.in/static/uploads/2026/02/f55fe52418b03f58b0669f6a8bc03b6d.pdf","tentative":false,"review":"verified"}]},{"id":"us-in-icdpa","name":"Indiana Consumer Data Protection Act (SEA 5, 2023), Ind. Code 24-15","shortName":"Indiana Consumer Data Protection Act (ICDPA)","jurisdiction":"us-in","jurisdictionName":"Indiana","region":"us-states","topics":["privacy"],"status":"in_force","citation":"Senate Enrolled Act 5 (2023), P.L. 94-2023; Ind. Code 24-15-1 to 24-15-11","enactedDate":"2023-05-01","effectiveDate":"2026-01-01","summary":"Virginia-style comprehensive privacy law granting rights to confirm, access, correct, delete, obtain a copy of, and opt out of targeted advertising, sale and profiling. Requires consent for sensitive data processing and data protection impact assessments for high-risk processing.","appliesTo":"Persons doing business in Indiana or targeting Indiana residents that during a calendar year control or process personal data of 100,000+ Indiana consumers, or 25,000+ consumers and derive over 50% of gross revenue from the sale of personal data.","penalties":"Civil penalty up to $7,500 per violation plus injunctive relief. Permanent 30-day cure period (no sunset): AG must give 30 days' written notice and may not sue if the violation is cured.","enforcer":"Indiana Attorney General (exclusive)","sourceUrl":"https://iga.in.gov/legislative/2023/bills/senate/5/details","extraSources":["https://iapp.org/resources/article/us-state-privacy-legislation-tracker"],"notes":"Official Indiana legislature pages are JavaScript-rendered and could not be text-extracted during verification; thresholds, $7,500 penalty and permanent 30-day cure are consistent with IAPP and law-firm trackers. The cure period has no sunset, so there is no cure-expiry deadline. No 2025-2026 amendments confirmed.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-22 20:04:22","sourceType":"official","verifiedBy":"research from official sources","deadlines":[{"id":248,"regulationId":"us-in-icdpa","date":"2026-01-01","title":"ICDPA takes effect","description":"Consumer rights and controller/processor obligations apply; assessments required for processing activities created on or after this date.","kind":"effective","sourceUrl":"https://iga.in.gov/legislative/2023/bills/senate/5/details","tentative":false,"review":"verified"}]},{"id":"id-pdp","name":"Law No. 27 of 2022 on Personal Data Protection (Undang-Undang Pelindungan Data Pribadi)","shortName":"Indonesia PDP Law","jurisdiction":"id","jurisdictionName":"Indonesia","region":"apac","topics":["privacy","breach-notification","data-residency","children"],"status":"amended","citation":"Law No. 27 of 2022; implementing Government Regulation No. 33 of 2026","enactedDate":"2022-10-17","effectiveDate":"2022-10-17","summary":"Indonesia's GDPR-style data protection law: lawful bases, data subject rights, DPIAs for high-risk processing, DPOs, breach notification within 3x24 hours, and cross-border transfer rules. Full compliance was required after a 2-year transition ending 17 October 2024. Government Regulation 33/2026 (enacted 16 July 2026, effective 16 January 2027) adds implementing detail, including parental consent for children and cross-border transfer mechanisms.","appliesTo":"Any person, public body or international organization processing personal data in Indonesia, or abroad where the processing has legal effect in Indonesia or on Indonesian citizens abroad.","penalties":"Administrative fines up to 2% of annual revenue or receipts (per violating variable). Criminal penalties up to 4-6 years imprisonment and fines up to IDR 4-6 billion for individuals; corporate criminal fines up to 10x the maximum.","enforcer":"PDP Agency (not yet established); interim supervision by the Ministry of Communication and Digital Affairs (Komdigi)","sourceUrl":"https://peraturan.bpk.go.id/Details/229798/uu-no-27-tahun-2022","extraSources":["https://www.kk-advocates.com/news/read/indonesia-gr-pdp-personal-data-protection-compliance-regime-new-phase","https://conventuslaw.com/report/indonesia-personal-data-protection-under-2026-implementing-regulation/"],"notes":"GR 33/2026 dates come from law-firm reports; an official JDIH link was not found. One source says the PDP Law was amended by Law No. 1 of 2026 (probably criminal-provision alignment with the new Criminal Code, in force 2 Jan 2026), which is why status is 'amended'; this is unverified. The PDP Agency has still not been formed. The BPK JDIH source_url could not be fetched automatically (403), so the page ID should be confirmed.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-22 20:04:22","sourceType":"official","verifiedBy":"research from official sources","deadlines":[{"id":112,"regulationId":"id-pdp","date":"2022-10-17","title":"PDP Law enacted and in force","description":"Law takes effect on enactment, starting a 2-year transition.","kind":"effective","sourceUrl":"https://peraturan.bpk.go.id/Details/229798/uu-no-27-tahun-2022","tentative":false,"review":"verified"},{"id":113,"regulationId":"id-pdp","date":"2024-10-17","title":"PDP Law transition ends","description":"Controllers and processors must fully comply (Art. 74 two-year transition).","kind":"compliance","sourceUrl":"https://peraturan.bpk.go.id/Details/229798/uu-no-27-tahun-2022","tentative":false,"review":"verified"},{"id":114,"regulationId":"id-pdp","date":"2027-01-16","title":"Implementing regulation GR 33/2026 takes effect","description":"Detailed PDP implementing rules (DPIA, cross-border, children's consent) apply, 6 months after the 16 Jul 2026 enactment.","kind":"compliance","sourceUrl":"https://www.kk-advocates.com/news/read/indonesia-gr-pdp-personal-data-protection-compliance-regime-new-phase","tentative":false,"review":"verified"}]},{"id":"id-child-online-protection","name":"Government Regulation No. 17 of 2025 on Governance of Electronic Systems in Child Protection","shortName":"Indonesia PP 17/2025 (Child Protection Online)","jurisdiction":"id","jurisdictionName":"Indonesia","region":"apac","topics":["children","online-safety","privacy"],"status":"in_force","citation":"Peraturan Pemerintah No. 17 Tahun 2025; LN 2025 (36), TLN 7105","enactedDate":"2025-03-27","effectiveDate":"2025-03-27","summary":"Implements the child protection provisions added to Indonesia's Electronic Information and Transactions Law by Law No. 1 of 2024. It sets rules for how electronic system operators must protect children who use their products and services, how the government supervises them, and which administrative sanctions apply. Ministries and the public also have defined roles.","appliesTo":"Electronic system operators whose products, services or features are used by or accessible to children in Indonesia.","penalties":"Administrative sanctions under the regulation. The types and amounts are not captured here.","enforcer":"Ministry of Communication and Digital Affairs (Komdigi)","sourceUrl":"https://peraturan.bpk.go.id/Details/316698/pp-no-17-tahun-2025","extraSources":[],"notes":"The BPK database (peraturan.bpk.go.id) blocks automated fetch but loads in a browser. Its abstract confirms the scope and dates. Any transition period for existing operators was not verified from the regulation text. Komdigi as enforcer is from established knowledge.","lastVerified":"2026-09-25","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-25 11:14:17","sourceType":"official","verifiedBy":"research from official sources (2026-09-25)","deadlines":[{"id":7026,"regulationId":"id-child-online-protection","date":"2025-03-27","title":"PP 17/2025 in force","description":"The regulation was signed, promulgated and took effect on the same day.","kind":"effective","sourceUrl":"https://peraturan.bpk.go.id/Details/316698/pp-no-17-tahun-2025","tentative":false,"review":"verified"}]},{"id":"eu-interoperable-europe","name":"Regulation (EU) 2024/903 laying down measures for a high level of public sector interoperability across the Union (Interoperable Europe Act)","shortName":"Interoperable Europe Act","jurisdiction":"eu","jurisdictionName":"European Union","region":"eu","topics":["data-access"],"status":"in_force","citation":"Regulation (EU) 2024/903","enactedDate":"2024-03-13","effectiveDate":"2024-07-12","summary":"Creates a cooperation framework for cross-border interoperability of public sector digital services and data exchange. Public bodies must carry out interoperability assessments before changing binding requirements for trans-European digital public services, and an Interoperable Europe Board steers common solutions.","appliesTo":"EU institutions and Member State public sector bodies that set up or change network and information systems for trans-European digital public services.","penalties":"No fines; governance and procedural obligations.","enforcer":"European Commission, Interoperable Europe Board and national competent authorities.","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2024/903/oj/eng","extraSources":["https://publications.europa.eu/resource/celex/32024R0903"],"notes":"Public sector focus. Relevant to vendors supplying cross-border government systems.","lastVerified":"2026-09-25","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-25 10:55:47","sourceType":"official","verifiedBy":"research from official sources (2026-09-25)","deadlines":[{"id":6855,"regulationId":"eu-interoperable-europe","date":"2024-04-11","title":"Act enters into force","description":"Published in the OJ on 2024-03-22; enters into force on the 20th day.","kind":"effective","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2024/903/oj/eng","tentative":false,"review":"verified"},{"id":6856,"regulationId":"eu-interoperable-europe","date":"2024-07-12","title":"Act applies","description":"General application date.","kind":"effective","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2024/903/oj/eng","tentative":false,"review":"verified"},{"id":6857,"regulationId":"eu-interoperable-europe","date":"2025-01-12","title":"Interoperability assessments mandatory","description":"Article 3(1) to (4) (interoperability assessments) and Article 17 apply.","kind":"compliance","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2024/903/oj/eng","tentative":false,"review":"verified"}]},{"id":"us-ia-icdpa","name":"Iowa Consumer Data Protection Act (SF 262, 2023), Iowa Code ch. 715D","shortName":"Iowa Consumer Data Protection Act (ICDPA)","jurisdiction":"us-ia","jurisdictionName":"Iowa","region":"us-states","topics":["privacy"],"status":"in_force","citation":"SF 262 (2023 Iowa Acts ch. 17); Iowa Code 715D.1-715D.9","enactedDate":"2023-03-28","effectiveDate":"2025-01-01","summary":"Business-friendly comprehensive privacy law giving rights to confirm, access, delete, obtain a copy of, and opt out of sale and targeted advertising (no correction right, no profiling opt-out). Sensitive data requires notice and an opt-out opportunity rather than opt-in consent.","appliesTo":"Persons conducting business in Iowa or targeting Iowa residents that during a calendar year control or process personal data of 100,000+ consumers, or 25,000+ consumers and derive over 50% of gross revenue from the sale of personal data.","penalties":"Civil penalties up to $7,500 per violation plus injunctive relief. Permanent 90-day cure period (no sunset): AG must give 90 days' written notice and may not sue if cured with a written statement.","enforcer":"Iowa Attorney General (exclusive)","sourceUrl":"https://www.legis.iowa.gov/docs/code/715D.pdf","extraSources":[],"notes":"90-day cure period is permanent, so no cure-expiry deadline. No 2025-2026 amendments found.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-22 20:04:22","sourceType":"official","verifiedBy":"research from official sources","deadlines":[{"id":240,"regulationId":"us-ia-icdpa","date":"2025-01-01","title":"ICDPA takes effect","description":"Consumer rights and controller/processor obligations apply.","kind":"effective","sourceUrl":"https://www.legis.iowa.gov/docs/code/715D.pdf","tentative":false,"review":"verified"}]},{"id":"il-ppl-amendment-13","name":"Privacy Protection Law, 5741-1981 (Amendment No. 13)","shortName":"Israel Privacy Protection Law Amendment 13","jurisdiction":"il","jurisdictionName":"Israel","region":"mea","topics":["privacy","breach-notification"],"status":"amended","citation":"Privacy Protection Law, 5741-1981, Amendment No. 13 (5784-2024)","enactedDate":"2024-08-05","effectiveDate":"2025-08-14","summary":"Major overhaul of Israel's privacy law: broadens definitions (personal and highly sensitive information), narrows database registration, requires privacy protection officers for certain entities, and gives the Privacy Protection Authority powers to impose large administrative fines and orders, plus statutory damages.","appliesTo":"Controllers and holders of databases in Israel; DPO requirement for public bodies, data brokers, and entities whose core activities involve large-scale systematic monitoring or processing of highly sensitive data.","penalties":"Administrative fines scaled to the number of data subjects and data sensitivity, reaching millions of shekels; statutory damages up to ILS 10,000 per violation without proof of harm; criminal offences.","enforcer":"Privacy Protection Authority (PPA)","sourceUrl":"https://www.gov.il/en/departments/the_privacy_protection_authority/govil-landing-page","extraSources":["https://www.pearlcohen.com/israel-significant-amendment-to-the-privacy-law-takes-effect/"],"notes":"Knesset approval 5 Aug 2024 from recollection/secondary sources. Exact fine tables not reproduced to avoid error.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-22 20:04:22","sourceType":"official","verifiedBy":"research from official sources","deadlines":[{"id":115,"regulationId":"il-ppl-amendment-13","date":"2025-08-14","title":"Amendment 13 in force","description":"Amended Privacy Protection Law, PPA enforcement powers and statutory damages take effect.","kind":"effective","sourceUrl":"https://www.gov.il/en/departments/the_privacy_protection_authority/govil-landing-page","tentative":false,"review":"verified"}]},{"id":"jp-ai-act","name":"Act on Promotion of Research and Development, and Utilization of Artificial Intelligence-Related Technology","shortName":"Japan AI Promotion Act","jurisdiction":"jp","jurisdictionName":"Japan","region":"apac","topics":["ai"],"status":"in_force","citation":"Enacted by the 217th Diet (bill submitted 28 Feb 2025)","enactedDate":"2025-05-28","effectiveDate":"2025-06-04","summary":"A framework law to promote AI R&D and use, not to restrict it. It sets up the AI Strategy Headquarters under the Prime Minister and an AI Basic Plan. The government can investigate cases where AI causes harm to rights and publish guidance and names. It sets no direct compliance obligations or fines for businesses, beyond a duty to cooperate with government measures.","appliesTo":"National and local government, research institutions, and businesses using or developing AI (duty to cooperate). No thresholds.","penalties":"None. No administrative fines or criminal penalties; the government may issue guidance, investigate, and publicize inappropriate cases.","enforcer":"AI Strategy Headquarters (Cabinet), Cabinet Office","sourceUrl":"https://www8.cao.go.jp/cstp/ai/ai_act/ai_act.html","extraSources":["https://www.cao.go.jp/houan/217/index.html","https://fpf.org/blog/understanding-japans-ai-promotion-act-an-innovation-first-blueprint-for-ai-regulation/"],"notes":"The Cabinet Office confirms promulgation and partial effect on 4 June 2025 and full effect on 1 September 2025. The Diet passage date (28 May 2025) comes from secondary sources. The law number is not verified.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-22 20:04:22","sourceType":"official","verifiedBy":"research from official sources","deadlines":[{"id":119,"regulationId":"jp-ai-act","date":"2025-06-04","title":"AI Promotion Act promulgated and partly in force","description":"Most provisions, including basic principles and stakeholder duties, take effect on promulgation.","kind":"effective","sourceUrl":"https://www8.cao.go.jp/cstp/ai/ai_act/ai_act.html","tentative":false,"review":"verified"},{"id":120,"regulationId":"jp-ai-act","date":"2025-09-01","title":"AI Promotion Act fully in force","description":"Provisions establishing the AI Strategy Headquarters and AI Basic Plan take effect.","kind":"effective","sourceUrl":"https://www8.cao.go.jp/cstp/ai/ai_act/ai_act.html","tentative":false,"review":"verified"}]},{"id":"jp-appi","name":"Act on the Protection of Personal Information (Act No. 57 of 2003), as amended including the 2026 amendment act","shortName":"Japan APPI","jurisdiction":"jp","jurisdictionName":"Japan","region":"apac","topics":["privacy","children","biometrics","breach-notification","ai"],"status":"amended","citation":"Act No. 57 of 2003; 2026 amendment act promulgated 17 July 2026","enactedDate":"2003-05-30","effectiveDate":"2005-04-01","summary":"Japan's general privacy law covering purpose specification, security, third-party transfer consent (with an opt-out scheme), cross-border transfer rules, mandatory breach reporting, and pseudonymized data. The 2026 amendment (promulgated 17 July 2026) adds Japan's first administrative fine (disgorgement of gains from serious violations), guardian consent for children under 16, stricter rules on facial-feature data, relaxed breach notification to individuals, and a consent exemption for statistics and AI development.","appliesTo":"All business operators handling personal information in Japan, with no size threshold, and foreign operators handling data of people in Japan in connection with supplying goods or services. Under the 2026 amendment, fines target serious violations involving large-scale misuse for economic gain; reported exclusions cover negligence or fewer than 1,000 affected people.","penalties":"Current: PPC orders; criminal penalties for violating orders up to 1 year imprisonment or JPY 1 million, and corporate fines up to JPY 100 million for order violations and unlawful database provision. 2026 amendment: administrative fine equal to the economic benefit from the violation (reported 1.5x uplift for repeat offenders within 10 years and a 50% cut for self-reporting), plus higher criminal penalties for unlawful database provision and new penalties for obtaining PI by fraud.","enforcer":"Personal Information Protection Commission (PPC)","sourceUrl":"https://www.ppc.go.jp/files/pdf/260731_shiryou-1.pdf","extraSources":["https://www.ppc.go.jp/files/pdf/260407_gaiyou.pdf","https://www.ppc.go.jp/news/press/2026/260407/","https://www.ppc.go.jp/en/legal/","https://www.bakermckenzie.com/en/insight/publications/2026/05/japan-appi-reform-key-changes"],"notes":"Main body of the 2026 amendment commences by cabinet order within 2 years of promulgation (by about July 2028); the PPC roadmap of 31 July 2026 gives a rough outlook of spring to July 2028, so no exact date is listed. One narrow provision (digitised service by public notice) takes effect 6 months after promulgation. The 1,000-person exclusion and the 1.5x and 50% fine adjustments come from law-firm summaries, not re-verified in the official text. Earlier dates (2003 enactment, 2005 full effect, 2022 amendments) are from the PPC legal page and general knowledge. Full English consolidation as of 1 Apr 2023 is at japaneselawtranslation.go.jp.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-22 20:04:22","sourceType":"official","verifiedBy":"research from official sources","deadlines":[{"id":121,"regulationId":"jp-appi","date":"2022-04-01","title":"2020 amendments in force","description":"Mandatory breach reporting, pseudonymized information and stricter cross-border rules apply.","kind":"effective","sourceUrl":"https://www.ppc.go.jp/en/legal/","tentative":false,"review":"verified"},{"id":122,"regulationId":"jp-appi","date":"2026-07-17","title":"2026 APPI amendment act promulgated","description":"Amendment enacted by the Diet on 10 July 2026 and promulgated; main provisions take effect by cabinet order within two years of promulgation.","kind":"transition","sourceUrl":"https://www.ppc.go.jp/files/pdf/260731_shiryou-1.pdf","tentative":false,"review":"verified"}]},{"id":"jp-active-cyber-defense","name":"Act on the Prevention of Damage from Unauthorized Acts against Important Computers (Act No. 42 of 2025)","shortName":"Japan Active Cyber Defense Act","jurisdiction":"jp","jurisdictionName":"Japan","region":"apac","topics":["cybersecurity","breach-notification"],"status":"enacted","citation":"Act No. 42 of 2025 (Reiwa 7)","enactedDate":"2025-05-23","effectiveDate":"2026-10-01","summary":"Japan's active cyber defense law. Designated critical infrastructure operators must register the important computers they bring in (product and maker) with their sector minister and report cyber intrusions and precursor events to that minister and the Prime Minister. The Act also lets the government collect and analyse communications data on foreign cyber attacks under oversight by a new Cyber Communications Information Supervisory Commission.","appliesTo":"Special social infrastructure operators, meaning designated critical infrastructure operators under the Economic Security Promotion Act that use specified important computers, plus telecom carriers asked to cooperate with communications data measures.","penalties":"Fine of up to JPY 2 million for breaching a ministerial order to register or report (art. 83). Fine of up to JPY 300,000 for failing to give requested reports or giving false ones (art. 84). Leaks of secrets by officials carry up to 2 years in prison or JPY 1 million.","enforcer":"Prime Minister (Cabinet Office) and sector ministers; Cyber Communications Information Supervisory Commission for communications data","sourceUrl":"https://laws.e-gov.go.jp/law/507AC0000000042","extraSources":["https://laws.e-gov.go.jp/api/2/law_revisions/507AC0000000042?response_format=json"],"notes":"Dates come from the e-Gov law revision history. e-Gov also lists a 2025-07-01 revision, which was not mapped to specific provisions here, so it is not listed as a deadline.","lastVerified":"2026-09-25","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-25 11:14:17","sourceType":"official","verifiedBy":"research from official sources (2026-09-25)","deadlines":[{"id":6993,"regulationId":"jp-active-cyber-defense","date":"2025-05-23","title":"Act promulgated","description":"Act No. 42 of 2025 promulgated; preparatory supplementary provisions apply from this day.","kind":"transition","sourceUrl":"https://laws.e-gov.go.jp/api/2/law_revisions/507AC0000000042?response_format=json","tentative":false,"review":"verified"},{"id":6994,"regulationId":"jp-active-cyber-defense","date":"2026-04-01","title":"Supervisory Commission provisions in force","description":"Provisions setting up the Cyber Communications Information Supervisory Commission take effect, per the e-Gov revision history.","kind":"effective","sourceUrl":"https://laws.e-gov.go.jp/api/2/law_revisions/507AC0000000042?response_format=json","tentative":false,"review":"verified"},{"id":6995,"regulationId":"jp-active-cyber-defense","date":"2026-10-01","title":"Registration and incident reporting duties start","description":"Main provisions take effect, including Chapter 2 duties for special social infrastructure operators to register important computers and report specified intrusion incidents.","kind":"compliance","sourceUrl":"https://laws.e-gov.go.jp/api/2/law_revisions/507AC0000000042?response_format=json","tentative":false,"review":"verified"},{"id":6996,"regulationId":"jp-active-cyber-defense","date":"2027-11-22","title":"Communications data measures in force (latest date)","description":"Chapters 3 to 7 on agreements with operators and collection of communications data take effect by Cabinet Order within 2 years and 6 months of promulgation. e-Gov lists 22 Nov 2027 as the outer limit, not a fixed date.","kind":"effective","sourceUrl":"https://laws.e-gov.go.jp/api/2/law_revisions/507AC0000000042?response_format=json","tentative":true,"review":"verified"}]},{"id":"kz-ai-law","name":"Law of the Republic of Kazakhstan on Artificial Intelligence (No. 230-VIII)","shortName":"Kazakhstan AI Law","jurisdiction":"kz","jurisdictionName":"Kazakhstan","region":"apac","topics":["ai","privacy","biometrics"],"status":"in_force","citation":"Law No. 230-VIII ZRK of 17 Nov 2025","enactedDate":"2025-11-17","effectiveDate":"2026-01-18","summary":"Kazakhstan's first AI statute. Owners sort their AI systems into minimal, medium or high risk and must run yearly risk management, keep documentation and inform users when AI is used. Some AI functions are banned outright, including manipulation, exploiting vulnerable people, social scoring, biometric categorisation for discrimination and emotion recognition without consent. AI-generated synthetic content must carry machine-readable marking and a visible warning.","appliesTo":"Owners, holders and users of AI systems in Kazakhstan, owners of data libraries used for training, and the national AI platform operator.","penalties":"The Law defers to liability set in other Kazakh laws (art. 30). No fines are set in the Law itself.","enforcer":"Authorised central executive body for AI, with the Government of Kazakhstan","sourceUrl":"https://adilet.zan.kz/rus/docs/Z2500000230","extraSources":["https://adilet.zan.kz/rus/docs/Z2500000230?tab=publication"],"notes":"Published in Egemen Kazakhstan and Kazakhstanskaya Pravda No. 222 on 18 Nov 2025. Amended by Law No. 326-VIII of 24 Jun 2026. Copyright applies to AI-assisted works only with human creative input, and training on works is allowed unless the author opts out in machine-readable form.","lastVerified":"2026-09-25","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-25 11:14:17","sourceType":"official","verifiedBy":"research from official sources (2026-09-25)","deadlines":[{"id":7007,"regulationId":"kz-ai-law","date":"2026-01-18","title":"AI Law takes effect","description":"The Law takes effect after 60 calendar days from first official publication on 18 Nov 2025 (art. 31). The day is computed, not stated.","kind":"effective","sourceUrl":"https://adilet.zan.kz/rus/docs/Z2500000230","tentative":true,"review":"verified"}]},{"id":"us-ky-kcdpa","name":"Kentucky Consumer Data Protection Act (HB 15, 2024), KRS 367.3611-367.3629","shortName":"Kentucky Consumer Data Protection Act (KCDPA)","jurisdiction":"us-ky","jurisdictionName":"Kentucky","region":"us-states","topics":["privacy"],"status":"in_force","citation":"HB 15 (2024 Ky. Acts ch. 72); KRS 367.3611 et seq.","enactedDate":"2024-04-04","effectiveDate":"2026-01-01","summary":"Virginia-style comprehensive privacy law granting rights to confirm, access, correct, delete, obtain a copy of, and opt out of targeted advertising, sale and profiling. Requires opt-in consent for sensitive data and data protection assessments for high-risk processing.","appliesTo":"Persons conducting business in Kentucky or targeting Kentucky residents that during a calendar year control or process personal data of 100,000+ consumers, or 25,000+ consumers and derive over 50% of gross revenue from the sale of personal data.","penalties":"Civil penalties up to $7,500 for each continued violation plus injunctive relief. Permanent 30-day cure period (no sunset).","enforcer":"Kentucky Attorney General (exclusive)","sourceUrl":"https://apps.legislature.ky.gov/record/24rs/hb15.html","extraSources":["https://apps.legislature.ky.gov/recorddocuments/bill/24RS/hb15/bill.pdf"],"notes":"30-day cure period is permanent, so no cure-expiry deadline. Penalty text refers to each 'continued' violation after the cure period. No 2025-2026 amendments confirmed.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-22 20:04:22","sourceType":"official","verifiedBy":"research from official sources","deadlines":[{"id":249,"regulationId":"us-ky-kcdpa","date":"2026-01-01","title":"KCDPA takes effect","description":"Consumer rights and controller/processor obligations apply (HB 15 section 12).","kind":"effective","sourceUrl":"https://apps.legislature.ky.gov/recorddocuments/bill/24RS/hb15/bill.pdf","tentative":false,"review":"verified"}]},{"id":"ke-cmca","name":"Computer Misuse and Cybercrimes Act, 2018","shortName":"Kenya Computer Misuse and Cybercrimes Act","jurisdiction":"ke","jurisdictionName":"Kenya","region":"mea","topics":["cybersecurity","online-safety"],"status":"amended","citation":"Act No. 5 of 2018 (Cap. 79C), amended by Act No. 17 of 2025","enactedDate":"2018-05-16","effectiveDate":"2018-05-30","summary":"Kenya's main cybercrime law. It creates offences such as unauthorised access, interference, cyber harassment and false publication, sets up a National Computer and Cybercrimes Co-ordination Committee, and requires critical infrastructure owners to report threatening incidents. The 2025 amendment adds identity theft rules and lets the Committee order websites or apps that promote unlawful activity, child sexual content, terrorism or extremism to be blocked.","appliesTo":"Everyone in Kenya; owners and operators of designated critical information infrastructure have reporting and protection duties.","penalties":"For example, unauthorised access carries a fine up to KES 5 million or up to 3 years in prison; offences against protected systems carry up to KES 25 million or 20 years.","enforcer":"National Computer and Cybercrimes Co-ordination Committee, National Police Service and the courts","sourceUrl":"https://new.kenyalaw.org/akn/ke/act/2018/5/eng@2022-12-31","extraSources":["https://new.kenyalaw.org/akn/ke/act/2025/17"],"notes":"Kenya Law is run by the National Council for Law Reporting, a state body. Several sections of the 2018 Act were challenged in court, and Kenya Law lists a 2025 challenge (Law Society of Kenya and 8 others v Attorney General) that cites the 2025 amendment. Check current court orders before relying on the amended provisions.","lastVerified":"2026-09-25","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-25 11:14:17","sourceType":"official","verifiedBy":"research from official sources (2026-09-25)","deadlines":[{"id":7041,"regulationId":"ke-cmca","date":"2018-05-30","title":"Act commences","description":"Assented 16 May 2018, published 18 May 2018, commenced 30 May 2018.","kind":"effective","sourceUrl":"https://new.kenyalaw.org/akn/ke/act/2018/5/eng@2022-12-31","tentative":false,"review":"verified"},{"id":7042,"regulationId":"ke-cmca","date":"2025-11-04","title":"2025 amendments commence","description":"Computer Misuse and Cybercrimes (Amendment) Act No. 17 of 2025: assented 15 October 2025, published 21 October 2025, commenced 4 November 2025.","kind":"effective","sourceUrl":"https://new.kenyalaw.org/akn/ke/act/2025/17","tentative":false,"review":"verified"}]},{"id":"ke-dpa","name":"Data Protection Act, 2019 (No. 24 of 2019)","shortName":"Kenya Data Protection Act","jurisdiction":"ke","jurisdictionName":"Kenya","region":"mea","topics":["privacy","breach-notification","data-residency"],"status":"in_force","citation":"Act No. 24 of 2019","enactedDate":"2019-11-08","effectiveDate":"2019-11-25","summary":"Kenya's GDPR-inspired data protection law establishing the ODPC, mandatory registration of data controllers and processors, data subject rights, 72-hour breach notification to the Commissioner, DPIAs, and conditions on cross-border transfers (with some data localisation for strategic public interest processing).","appliesTo":"Controllers and processors established or resident in Kenya, or processing personal data of data subjects located in Kenya. Registration required unless exempt under the Registration Regulations (e.g. small entities below turnover/employee thresholds, except sectors listed as mandatory).","penalties":"Administrative fines up to KES 5 million or 1% of annual turnover of the preceding financial year, whichever is lower; criminal offences with fines and imprisonment.","enforcer":"Office of the Data Protection Commissioner (ODPC)","sourceUrl":"https://www.odpc.go.ke/","extraSources":["https://new.kenyalaw.org/akn/ke/act/2019/24/eng@2022-12-31"],"notes":"Data Protection (General), (Registration) and (Complaints Handling) Regulations 2021 followed; the registration compliance date (reported as July 2022) was not verified so is omitted. Assent date 8 Nov 2019 from recollection.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-22 20:04:22","sourceType":"official","verifiedBy":"research from official sources","deadlines":[{"id":123,"regulationId":"ke-dpa","date":"2019-11-25","title":"Data Protection Act in force","description":"Act commences.","kind":"effective","sourceUrl":"https://www.odpc.go.ke/","tentative":false,"review":"verified"}]},{"id":"us-la-ldpa","name":"Louisiana Data Privacy Act (SB 386, 2026 Regular Session, Act No. 502), La. R.S. 51:1780.1-1780.5","shortName":"Louisiana Data Privacy Act","jurisdiction":"us-la","jurisdictionName":"Louisiana","region":"us-states","topics":["privacy","biometrics"],"status":"enacted","citation":"SB 386 (2026 RS), Act No. 502; La. R.S. 51:1780.1-1780.5","enactedDate":"2026-05-29","effectiveDate":"2027-01-01","summary":"Louisiana's comprehensive privacy law, signed May 29, 2026, gives consumers access, deletion, correction, portability and opt-out rights and requires conspicuous notice when sensitive or biometric data is sold. It uses CCPA-style applicability thresholds, including a $25M revenue trigger.","appliesTo":"Persons doing business in Louisiana that (1) have annual gross revenues over $25 million, (2) annually buy, receive, sell or share for commercial purposes personal information of 75,000+ consumers, households or devices, or (3) derive 50%+ of annual revenues from selling consumers' personal information.","penalties":"Violations are unfair and deceptive trade practices under the Louisiana Unfair Trade Practices and Consumer Protection Law (R.S. 51:1401 et seq.), excluding private rights of action; LUTPA civil penalties apply. 30-day notice-and-cure available only Jan 1 - July 31, 2027.","enforcer":"Louisiana Attorney General","sourceUrl":"https://legis.la.gov/legis/BillInfo.aspx?s=26RS&b=SB386&sbi=y","extraSources":["https://legis.la.gov/legis/ViewDocument.aspx?d=1480202","https://www.afslaw.com/perspectives/privacy-counsel/new-state-privacy-laws-signal-growing-partisan-divide","https://www.concord.tech/blog/concord-privacy-news-6-30-26"],"notes":"The act does not state a dollar penalty; LUTPA (R.S. 51:1407) civil penalties apply (commonly up to $5,000 per violation) but the figure was not verified against the official statute. One secondary source (Venable) misidentified the bill as SB 546; the official record shows SB 386 / Act 502.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-22 20:04:22","sourceType":"official","verifiedBy":"research from official sources","deadlines":[{"id":250,"regulationId":"us-la-ldpa","date":"2027-01-01","title":"Louisiana Data Privacy Act takes effect","description":"Consumer rights and controller duties apply (Act 502, Section 2); data protection assessment requirements apply to processing from this date.","kind":"effective","sourceUrl":"https://legis.la.gov/legis/ViewDocument.aspx?d=1480202","tentative":false,"review":"verified"},{"id":251,"regulationId":"us-la-ldpa","date":"2027-07-31","title":"30-day cure period expires","description":"AG's obligation to give 30-day notice and allow cure before investigating applies only from Jan 1 through July 31, 2027 (R.S. 51:1780.5(D)).","kind":"enforcement","sourceUrl":"https://legis.la.gov/legis/ViewDocument.aspx?d=1480202","tentative":false,"review":"verified"}]},{"id":"us-la-app-store","name":"Louisiana Act 481 of 2025 on Minors' Use of Applications (HB 570)","shortName":"Louisiana app store age verification law","jurisdiction":"us-la","jurisdictionName":"Louisiana","region":"us-states","topics":["children","privacy","online-safety"],"status":"in_force","citation":"Acts 2025, No. 481; La. R.S. 51:1771 to 1775","enactedDate":"2025-06-30","effectiveDate":"2026-07-01","summary":"App stores must use age verification methods, affiliate minor accounts with a parent account and give parents consent disclosures before minors use apps. Developers have matching duties to use age and consent data and protect it.","appliesTo":"Covered application store providers and developers serving Louisiana users on mobile devices.","penalties":"AG civil actions; civil penalty up to $5,000 per violation of an order, plus fees and costs.","enforcer":"Louisiana Attorney General","sourceUrl":"https://legis.la.gov/legis/BillInfo.aspx?s=25RS&b=HB570&sbi=y","extraSources":["https://legis.la.gov/legis/ViewDocument.aspx?d=1427667"],"notes":"","lastVerified":"2026-09-25","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-25 10:55:47","sourceType":"official","verifiedBy":"research from official sources (2026-09-25)","deadlines":[{"id":6931,"regulationId":"us-la-app-store","date":"2025-06-30","title":"Signed by Governor","description":"Became Act 481 of the 2025 Regular Session.","kind":"transition","sourceUrl":"https://legis.la.gov/legis/BillInfo.aspx?s=25RS&b=HB570&sbi=y","tentative":false,"review":"verified"},{"id":6932,"regulationId":"us-la-app-store","date":"2026-07-01","title":"Takes effect","description":"Section 5: act effective July 1, 2026.","kind":"effective","sourceUrl":"https://legis.la.gov/legis/ViewDocument.aspx?d=1427667","tentative":false,"review":"verified"}]},{"id":"my-cyber-security-act","name":"Cyber Security Act 2024 (Act 854)","shortName":"Malaysia Cyber Security Act","jurisdiction":"my","jurisdictionName":"Malaysia","region":"apac","topics":["cybersecurity","breach-notification"],"status":"in_force","citation":"Act 854; commencement P.U. (B) 334/2024","enactedDate":"2024-06-18","effectiveDate":"2024-08-26","summary":"Malaysia's first standalone cybersecurity law. It sets up the National Cyber Security Committee, gives powers to the Chief Executive of NACSA, and places duties on national critical information infrastructure (NCII) sector leads and entities. NCII entities must follow codes of practice, run a risk assessment at least once a year and an audit at least once every two years, and notify cybersecurity incidents within 6 hours. Cybersecurity service providers must be licensed.","appliesTo":"Government and private NCII sector leads and NCII entities in 11 sectors, and providers of licensable cybersecurity services in Malaysia.","penalties":"Fines of up to MYR 500,000 and up to 10 years in prison for the most serious offences. Other offences carry fines of MYR 100,000 to MYR 200,000 and up to 2 or 3 years in prison.","enforcer":"National Cyber Security Agency (NACSA), National Security Council, Prime Minister's Department","sourceUrl":"https://lom.agc.gov.my/act-detail.php?a=YWN0PTg1NCZsYW5nPUJJfDM3MjhhYmRhY2U0YWNlOTZlMGI3MmRlODVkNjQ2YzM4ZTNmMTE0YzA3YzY5ZGJhOGExZTNmYmQ4ZTc0OWJlYWY=","extraSources":["https://www.nacsa.gov.my/act854.php","https://lom.agc.gov.my/ilims/upload/portal/akta/outputp/2303986/PUA220_2024.pdf","https://lom.agc.gov.my/ilims/upload/portal/akta/outputp/2304311/PUA219_2024.pdf"],"notes":"Royal Assent 2024-06-18; gazetted 2024-06-26. The incident regulations (P.U. (A) 220/2024) require initial notice within 6 hours and full details within 14 days. P.U. (A) 219/2024 sets the risk assessment (yearly) and audit (every two years) cycle. An exemption order, P.U. (A) 47/2025, was published 2025-01-28.","lastVerified":"2026-09-25","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-25 11:14:17","sourceType":"official","verifiedBy":"research from official sources (2026-09-25)","deadlines":[{"id":7014,"regulationId":"my-cyber-security-act","date":"2024-08-26","title":"Act 854 and first regulations in force","description":"The Act and its incident notification, risk assessment and audit, and licensing regulations take effect.","kind":"effective","sourceUrl":"https://lom.agc.gov.my/act-detail.php?a=YWN0PTg1NCZsYW5nPUJJfDM3MjhhYmRhY2U0YWNlOTZlMGI3MmRlODVkNjQ2YzM4ZTNmMTE0YzA3YzY5ZGJhOGExZTNmYmQ4ZTc0OWJlYWY=","tentative":false,"review":"verified"}]},{"id":"my-online-safety-act","name":"Online Safety Act 2025 (Act 866)","shortName":"Malaysia Online Safety Act","jurisdiction":"my","jurisdictionName":"Malaysia","region":"apac","topics":["online-safety","children"],"status":"in_force","citation":"Act 866; commencement P.U. (B) 449/2025","enactedDate":"2025-05-06","effectiveDate":"2026-01-01","summary":"Puts duties on licensed application service providers and content application service providers to reduce users' exposure to harmful content. They must issue user guidelines, give users safety tools and reporting channels, protect child users, make priority harmful content (such as child sexual abuse material) inaccessible, and prepare an Online Safety Plan. An Online Safety Appeal Tribunal hears appeals.","appliesTo":"Application service providers and content application service providers licensed under Malaysia's communications licensing regime, including large social media and messaging platforms operating in Malaysia.","penalties":"Fines of up to MYR 1 million for many offences, with lower caps (MYR 100,000 to MYR 500,000) for others. Offences can be compounded under the 2026 compounding regulations.","enforcer":"Malaysian Communications and Multimedia Commission (MCMC)","sourceUrl":"https://lom.agc.gov.my/act-detail.php?a=YWN0PTg2NiZsYW5nPUJJ","extraSources":["https://lom.agc.gov.my/ilims/upload/portal/akta/outputaktap/2867049_BI/Act%20866-Online%20Safety%20Act%202025.pdf","https://lom.agc.gov.my/ilims/upload/portal/akta/outputp/3240953/PUB449_2025.pdf","https://lom.agc.gov.my/ilims/upload/portal/akta/outputp/3582105/PUA%20244_2026.pdf"],"notes":"Royal Assent 2025-05-06; published 2025-05-22. The 2026-12-28 date is 180 days after the 2026-07-01 start of the Online Safety Plan Regulations. Providers licensed after that date have 180 days from licence start.","lastVerified":"2026-09-25","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-25 11:14:17","sourceType":"official","verifiedBy":"research from official sources (2026-09-25)","deadlines":[{"id":7015,"regulationId":"my-online-safety-act","date":"2026-01-01","title":"Online Safety Act and first regulations in force","description":"The Act and the Period, Fees, Form of Undertaking and Appeal Tribunal regulations take effect.","kind":"effective","sourceUrl":"https://lom.agc.gov.my/act-detail.php?a=YWN0PTg2NiZsYW5nPUJJ","tentative":false,"review":"verified"},{"id":7016,"regulationId":"my-online-safety-act","date":"2026-07-01","title":"Online Safety Plan and compounding regulations in force","description":"P.U. (A) 244/2026 and P.U. (A) 245/2026 take effect.","kind":"effective","sourceUrl":"https://lom.agc.gov.my/ilims/upload/portal/akta/outputp/3582105/PUA%20244_2026.pdf","tentative":false,"review":"verified"},{"id":7017,"regulationId":"my-online-safety-act","date":"2026-12-28","title":"Online Safety Plan due to MCMC","description":"Licensed providers must prepare an Online Safety Plan and submit it to MCMC within 180 days of 1 July 2026. Updates are due each year and after material changes.","kind":"compliance","sourceUrl":"https://lom.agc.gov.my/ilims/upload/portal/akta/outputp/3582105/PUA%20244_2026.pdf","tentative":false,"review":"verified"}]},{"id":"my-pdpa","name":"Personal Data Protection Act 2010 (Act 709), as amended by the Personal Data Protection (Amendment) Act 2024 (Act A1727)","shortName":"Malaysia PDPA","jurisdiction":"my","jurisdictionName":"Malaysia","region":"apac","topics":["privacy","breach-notification","biometrics","data-residency"],"status":"amended","citation":"Act 709; Act A1727 (Royal Assent 9 Oct 2024, gazetted 17 Oct 2024)","enactedDate":"","effectiveDate":"2013-11-15","summary":"Malaysia's commercial-sector data protection law. The 2024 amendments, phased in during 2025, rename 'data users' as 'data controllers', add biometric data to sensitive data, apply the Security Principle directly to processors, replace the transfer whitelist with adequacy and safeguards tests, raise fines, and add mandatory DPOs, data breach notification and data portability.","appliesTo":"Anyone processing personal data in commercial transactions in Malaysia, or using equipment in Malaysia for processing (federal and state governments excluded). Certain classes of data controllers must register. The DPO and breach notification guidelines set scale-based triggers.","penalties":"General offences: fine up to RM 1,000,000 and/or imprisonment up to 3 years (raised from RM 500,000 / 2 years).","enforcer":"Personal Data Protection Commissioner (Jabatan Perlindungan Data Peribadi)","sourceUrl":"https://www.pdp.gov.my/ppdpv1/wp-content/uploads/2024/11/Act-A1727.pdf","extraSources":["https://www.pdp.gov.my/ppdpv1/en/personal-data-protection-amendment-act-2024-commencement-date-determination/","https://www.christopherleeong.com/viewpoints/news-alert-dates-of-coming-into-operation-of-the-personal-data-protection-amendment-act-2024/"],"notes":"The phase breakdown comes from Christopher & Lee Ong's reading of the Minister's commencement notice; the pdp.gov.my notice page did not render its contents. The PDPA's original commencement (15 Nov 2013) is from established knowledge. Breach notification timelines (Commissioner within 72 hours; data subjects within 7 days) are in the Commissioner's guideline and were not re-verified here. The Personal Data Protection (Amendment) Act 2024 received royal assent on 9 Oct 2024; the original Act 709 came into force on 15 Nov 2013.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-22 20:04:22","sourceType":"official","verifiedBy":"research from official sources","deadlines":[{"id":129,"regulationId":"my-pdpa","date":"2025-01-01","title":"PDPA amendments phase 1","description":"Miscellaneous provisions commence (e.g. electronic service of notices).","kind":"effective","sourceUrl":"https://www.pdp.gov.my/ppdpv1/en/personal-data-protection-amendment-act-2024-commencement-date-determination/","tentative":false,"review":"verified"},{"id":130,"regulationId":"my-pdpa","date":"2025-04-01","title":"PDPA amendments phase 2","description":"'Data controller' terminology, biometric data as sensitive data, higher penalties, Security Principle for processors, and removal of the cross-border whitelist take effect.","kind":"effective","sourceUrl":"https://www.pdp.gov.my/ppdpv1/en/personal-data-protection-amendment-act-2024-commencement-date-determination/","tentative":false,"review":"verified"},{"id":131,"regulationId":"my-pdpa","date":"2025-06-01","title":"PDPA amendments phase 3","description":"Mandatory DPO appointment, data breach notification, and data portability take effect.","kind":"compliance","sourceUrl":"https://www.pdp.gov.my/ppdpv1/en/personal-data-protection-amendment-act-2024-commencement-date-determination/","tentative":false,"review":"verified"}]},{"id":"us-md-kids-code","name":"Maryland Age-Appropriate Design Code Act (Maryland Kids Code, HB 603)","shortName":"Maryland Kids Code","jurisdiction":"us-md","jurisdictionName":"Maryland","region":"us-states","topics":["children","privacy","online-safety"],"status":"in_force","citation":"2024 Md. Laws ch. 461","enactedDate":"2024-05-09","effectiveDate":"2024-10-01","summary":"Online products reasonably likely to be accessed by children must be designed in the best interests of children, use high-privacy defaults and avoid certain data collection and profiling. Covered entities must complete data protection impact assessments.","appliesTo":"Businesses offering online products reasonably likely to be accessed by children under 18 in Maryland that meet the Maryland business thresholds.","penalties":"Civil penalties enforced by the AG; see statute.","enforcer":"Maryland Attorney General (Consumer Protection Division)","sourceUrl":"https://mgaleg.maryland.gov/mgawebsite/Legislation/Details/hb0603?ys=2024RS","extraSources":[],"notes":"Challenged in NetChoice v. Brown (D. Md., No. 1:25-cv-00322); case in discovery as of a 2026-09-23 order.","lastVerified":"2026-09-25","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-25 10:55:47","sourceType":"official","verifiedBy":"research from official sources (2026-09-25)","deadlines":[{"id":6933,"regulationId":"us-md-kids-code","date":"2024-05-09","title":"Approved by Governor","description":"Chapter 461 of 2024.","kind":"transition","sourceUrl":"https://mgaleg.maryland.gov/mgawebsite/Legislation/Details/hb0603?ys=2024RS","tentative":false,"review":"verified"},{"id":6934,"regulationId":"us-md-kids-code","date":"2024-10-01","title":"Takes effect","description":"Act effective.","kind":"effective","sourceUrl":"https://mgaleg.maryland.gov/mgawebsite/Legislation/Details/hb0603?ys=2024RS","tentative":false,"review":"verified"},{"id":6935,"regulationId":"us-md-kids-code","date":"2026-04-01","title":"Data protection impact assessments due","description":"Covered entities must complete DPIAs by this date.","kind":"compliance","sourceUrl":"https://mgaleg.maryland.gov/mgawebsite/Legislation/Details/hb0603?ys=2024RS","tentative":false,"review":"verified"}]},{"id":"us-md-modpa","name":"Maryland Online Data Privacy Act of 2024 (SB 541 / HB 567), Md. Code, Com. Law 14-4601 et seq.","shortName":"Maryland Online Data Privacy Act (MODPA)","jurisdiction":"us-md","jurisdictionName":"Maryland","region":"us-states","topics":["privacy","children","health","biometrics"],"status":"amended","citation":"2024 Md. Laws ch. 455 (SB 541) and ch. 454 (HB 567); Md. Code, Com. Law 14-4601 to 14-4614","enactedDate":"2024-05-09","effectiveDate":"2025-10-01","summary":"The strictest US state comprehensive privacy law: imposes data minimization limited to what is strictly necessary, bans the sale of sensitive data outright, and bans targeted advertising to and sale of data of consumers under 18 (known or should have known). Took effect Oct 1, 2025 but does not apply to personal data processing activities before April 1, 2026.","appliesTo":"Persons doing business in Maryland or targeting Maryland residents that in the preceding calendar year controlled or processed personal data of 35,000+ consumers (excluding payment-only data), or 10,000+ consumers and derived more than 20% of gross revenue from the sale of personal data.","penalties":"Violations are unfair, abusive or deceptive trade practices under the Maryland Consumer Protection Act (civil penalties up to $10,000 per violation and $25,000 for repeat violations). Discretionary 60-day cure period for violations occurring on or before April 1, 2027. Consumers may pursue other remedies but no private right of action under the MCPA's section 13-408.","enforcer":"Maryland Attorney General, Consumer Protection Division","sourceUrl":"https://mgaleg.maryland.gov/2024RS/Chapters_noln/CH_455_sb0541e.pdf","extraSources":["https://mgaleg.maryland.gov/mgawebsite/Legislation/Details/sb0541?ys=2024RS","https://www.venable.com/insights/publications/2026/07/2026-mid-year-state-privacy-law-update"],"notes":"A 2026 amendment reportedly expanded the precise geolocation definition (1,750-foot radius) effective July 1, 2026 (Venable, July 2026); bill number not verified, so no deadline row added. Penalty amounts come from the Maryland Consumer Protection Act (Com. Law 13-410), not restated in MODPA.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-22 20:04:22","sourceType":"official","verifiedBy":"research from official sources","deadlines":[{"id":252,"regulationId":"us-md-modpa","date":"2025-10-01","title":"MODPA takes effect","description":"Act takes effect; data protection assessments apply to processing activities on or after Oct 1, 2025.","kind":"effective","sourceUrl":"https://mgaleg.maryland.gov/2024RS/Chapters_noln/CH_455_sb0541e.pdf","tentative":false,"review":"verified"},{"id":253,"regulationId":"us-md-modpa","date":"2026-04-01","title":"MODPA applies to personal data processing","description":"The act applies to personal data processing activities from April 1, 2026 (Section 2 of ch. 455).","kind":"compliance","sourceUrl":"https://mgaleg.maryland.gov/2024RS/Chapters_noln/CH_455_sb0541e.pdf","tentative":false,"review":"verified"},{"id":254,"regulationId":"us-md-modpa","date":"2027-04-01","title":"Discretionary 60-day cure period ends","description":"The Division's discretionary notice-and-cure (at least 60 days) applies only to violations occurring on or before April 1, 2027 (Com. Law 14-4614).","kind":"enforcement","sourceUrl":"https://mgaleg.maryland.gov/2024RS/Chapters_noln/CH_455_sb0541e.pdf","tentative":false,"review":"verified"}]},{"id":"mx-lfpdppp","name":"Ley Federal de Protección de Datos Personales en Posesión de los Particulares (2025)","shortName":"Mexico LFPDPPP 2025","jurisdiction":"mx","jurisdictionName":"Mexico","region":"americas","topics":["privacy"],"status":"in_force","citation":"DOF 20-03-2025","enactedDate":"2025-03-20","effectiveDate":"2025-03-21","summary":"New federal private-sector data protection law replacing the 2010 law after the dissolution of INAI; keeps the ARCO rights and privacy-notice model, broadens the personal data definition and moves enforcement to the Secretaría Anticorrupción y Buen Gobierno.","appliesTo":"Private individuals and legal entities processing personal data in Mexico (credit bureaus and purely personal/domestic processing excluded).","penalties":"Fines from 100 to 320,000 times the UMA depending on the infraction (100-160,000 UMA for fractions II-VII; 200-320,000 UMA for fractions VIII-XVIII), doubled for sensitive data; criminal penalties for certain misuse.","enforcer":"Secretaría Anticorrupción y Buen Gobierno","sourceUrl":"https://www.diputados.gob.mx/LeyesBiblio/pdf/LFPDPPP.pdf","extraSources":["https://www.dof.gob.mx/","https://iapp.org/news/a/entendiendo-la-ley-federal-de-protecci-n-de-datos-personales-en-posesi-n-de-los-particulares-en-mexico"],"notes":"Implementing regulations (Reglamento) for the 2025 law were reported as still pending in 2026; the 2011 regulations apply where not contrary.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-22 20:04:22","sourceType":"official","verifiedBy":"research from official sources","deadlines":[{"id":128,"regulationId":"mx-lfpdppp","date":"2025-03-21","title":"New LFPDPPP in force","description":"Law published 20 March 2025 enters into force the following day, repealing the 2010 law.","kind":"effective","sourceUrl":"https://www.diputados.gob.mx/LeyesBiblio/pdf/LFPDPPP.pdf","tentative":false,"review":"verified"}]},{"id":"us-mn-mcdpa","name":"Minnesota Consumer Data Privacy Act (HF 4757, 2024 Minn. Laws ch. 121, art. 5), Minn. Stat. 325M.10-325M.21","shortName":"Minnesota Consumer Data Privacy Act (MCDPA)","jurisdiction":"us-mn","jurisdictionName":"Minnesota","region":"us-states","topics":["privacy"],"status":"in_force","citation":"2024 Minn. Laws ch. 121, art. 5; Minn. Stat. 325M.10-325M.21","enactedDate":"2024-05-24","effectiveDate":"2025-07-31","summary":"Comprehensive privacy law with distinctive rights to question the result of profiling decisions and to obtain a list of specific third parties that received the consumer's data. Requires data inventories, documented privacy policies and procedures, and data protection assessments.","appliesTo":"Legal entities doing business in Minnesota or targeting residents that during a calendar year control or process personal data of 100,000+ consumers (excluding payment-only data), or derive over 25% of gross revenue from the sale of personal data and process personal data of 25,000+ consumers. Small businesses as defined by the SBA are exempt except they may not sell sensitive data without consent.","penalties":"Civil penalty up to $7,500 per violation plus injunction and litigation expenses. 30-day warning-letter cure period expired Jan 31, 2026.","enforcer":"Minnesota Attorney General","sourceUrl":"https://www.revisor.mn.gov/statutes/cite/325M.20","extraSources":["https://www.revisor.mn.gov/statutes/cite/325M.12"],"notes":"SBA small-business exemption summarized from the act's structure; not re-verified line by line. No 2025-2026 amendments confirmed.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-22 20:04:22","sourceType":"official","verifiedBy":"research from official sources","deadlines":[{"id":255,"regulationId":"us-mn-mcdpa","date":"2025-07-31","title":"MCDPA takes effect","description":"Consumer rights and controller/processor obligations apply (postsecondary institutions excepted).","kind":"effective","sourceUrl":"https://www.revisor.mn.gov/statutes/cite/325M.20","tentative":false,"review":"verified"},{"id":256,"regulationId":"us-mn-mcdpa","date":"2026-01-31","title":"30-day cure period expires","description":"The requirement that the AG send a warning letter and allow 30 days to cure before suing expires Jan 31, 2026 (325M.20(a)).","kind":"enforcement","sourceUrl":"https://www.revisor.mn.gov/statutes/cite/325M.20","tentative":false,"review":"verified"},{"id":257,"regulationId":"us-mn-mcdpa","date":"2029-07-31","title":"Postsecondary institutions must comply","description":"Postsecondary institutions regulated by the Office of Higher Education must comply by July 31, 2029.","kind":"compliance","sourceUrl":"https://www.revisor.mn.gov/statutes/cite/325M.20","tentative":false,"review":"verified"}]},{"id":"us-mt-mcdpa","name":"Montana Consumer Data Privacy Act (SB 384, 2023), Mont. Code Ann. 30-14-2801 et seq., as amended by SB 297 (2025)","shortName":"Montana Consumer Data Privacy Act (MCDPA)","jurisdiction":"us-mt","jurisdictionName":"Montana","region":"us-states","topics":["privacy","children"],"status":"amended","citation":"SB 384 (2023 Mont. Laws ch. 681); SB 297 (2025 Mont. Laws ch. 567); MCA 30-14-2801 to 30-14-2819","enactedDate":"2023-05-19","effectiveDate":"2024-10-01","summary":"Comprehensive privacy law with access, correction, deletion, portability and opt-out rights and mandatory recognition of opt-out preference signals. SB 297 (2025) lowered thresholds, removed the cure period, added minors' protections that apply regardless of size, and lets the AG demand data protection assessments in investigations.","appliesTo":"From Oct 1, 2025: persons doing business in Montana or targeting residents that control or process personal data of 25,000+ consumers (excluding payment-only data), or 15,000+ consumers and derive over 25% of gross revenue from selling personal data. Minors' provisions (30-14-2811, -2818, -2819) apply to anyone doing business in Montana or intentionally targeting products at residents regardless of volume. Original thresholds (Oct 1, 2024): 50,000 consumers, or 25,000 + over 25% revenue from sale.","penalties":"AG enforces using Montana Unfair Trade Practices and Consumer Protection Act powers (MCA Title 30, ch. 14, parts 1-2); no private right of action. SB 297 eliminated the 60-day cure period.","enforcer":"Montana Attorney General (exclusive)","sourceUrl":"https://archive.legmt.gov/bills/mca/title_0300/chapter_0140/part_0280/section_0030/0300-0140-0280-0030.html","extraSources":["https://archive.legmt.gov/bills/mca/title_0300/chapter_0140/part_0280/section_0170/0300-0140-0280-0170.html","https://www.hunton.com/privacy-and-cybersecurity-law-blog/montana-amends-consumer-data-privacy-act"],"notes":"The original act's 60-day cure period was scheduled to expire April 1, 2026; SB 297 removed it effective Oct 1, 2025 (per Hunton; MCA 30-14-2817 as amended by ch. 567 L. 2025 no longer contains a cure provision). The Oct 1, 2025 effective date of SB 297 is from secondary sources and the task brief, not the session law text. Hunton reports penalties up to $7,500 per violation under SB 297, but the codified enforcement section (30-14-2817) contains no dollar figure; penalties flow from the Montana Consumer Protection Act, so no exact per-violation figure is asserted here.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-22 20:04:22","sourceType":"official","verifiedBy":"research from official sources","deadlines":[{"id":258,"regulationId":"us-mt-mcdpa","date":"2024-10-01","title":"MCDPA takes effect","description":"Consumer rights, controller duties and opt-out preference signal support apply.","kind":"effective","sourceUrl":"https://archive.legmt.gov/bills/mca/title_0300/chapter_0140/part_0280/section_0030/0300-0140-0280-0030.html","tentative":false,"review":"verified"},{"id":259,"regulationId":"us-mt-mcdpa","date":"2025-10-01","title":"SB 297 amendments take effect; cure period eliminated","description":"Lower thresholds (25,000 / 15,000 + 25%), minors' data protections, AG assessment demands; the 60-day cure period is removed.","kind":"enforcement","sourceUrl":"https://archive.legmt.gov/bills/mca/title_0300/chapter_0140/part_0280/section_0170/0300-0140-0280-0170.html","tentative":false,"review":"verified"}]},{"id":"eu-nis2","name":"Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union (NIS2 Directive)","shortName":"NIS2","jurisdiction":"eu","jurisdictionName":"European Union","region":"eu","topics":["cybersecurity","breach-notification"],"status":"amended","citation":"OJ L 333, 27.12.2022, p. 80","enactedDate":"2022-12-14","effectiveDate":"2023-01-16","summary":"Requires medium and large entities in 18 critical sectors, including cloud, data centres, managed services, online marketplaces, search and social networks, to adopt cybersecurity risk-management measures. They must report significant incidents within 24 hours (early warning), 72 hours (notification) and one month (final report). Management bodies are accountable. Obligations apply through national transposing laws.","appliesTo":"Essential and important entities in Annex I/II sectors, generally medium-sized or larger (50+ employees or over EUR 10M turnover/balance sheet). DNS, TLD registries, trust service providers and public electronic communications providers are covered regardless of size.","penalties":"Essential entities: maximum of at least EUR 10M or 2% of worldwide annual turnover, whichever is higher. Important entities: maximum of at least EUR 7M or 1.4% (Art 34). Management can be held personally liable and temporarily suspended in some cases.","enforcer":"National competent authorities and CSIRTs designated by each Member State; NIS Cooperation Group; ENISA","sourceUrl":"https://eur-lex.europa.eu/eli/dir/2022/2555/oj","extraSources":["https://eur-lex.europa.eu/eli/reg_impl/2024/2690/oj","https://www.insideprivacy.com/data-security/cybersecurity/european-commission-proposes-targeted-amendments-to-nis2-to-simplify-compliance-and-align-with-proposed-cybersecurity-act-2/"],"notes":"Transposition was late in most Member States, so obligations and registration deadlines differ by country. On 20 Jan 2026 the Commission proposed targeted NIS2 amendments alongside a revised Cybersecurity Act (CSA2): narrower scope, more harmonised measures, certification-based compliance and a bigger role for ENISA. The Digital Omnibus COM(2025) 837 also proposes a single-entry point for incident reporting. Neither was adopted as of Sept 2026. The 2027-04-17 date is computed from 'every two years' after 17 Apr 2025.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-22 20:04:22","sourceType":"official","verifiedBy":"research from official sources","deadlines":[{"id":98,"regulationId":"eu-nis2","date":"2023-01-16","title":"NIS2 enters into force","description":"Directive entered into force on the twentieth day after publication in OJ L 333 of 27 Dec 2022.","kind":"effective","sourceUrl":"https://eur-lex.europa.eu/eli/dir/2022/2555/oj","tentative":false,"review":"verified"},{"id":99,"regulationId":"eu-nis2","date":"2024-10-17","title":"Transposition deadline","description":"Member States had to adopt and publish national transposing measures by 17 Oct 2024 (Art 41(1)).","kind":"transition","sourceUrl":"https://eur-lex.europa.eu/eli/dir/2022/2555/oj","tentative":false,"review":"verified"},{"id":100,"regulationId":"eu-nis2","date":"2024-10-18","title":"National NIS2 measures apply; NIS1 repealed","description":"Member States apply their NIS2 measures from 18 Oct 2024 and Directive (EU) 2016/1148 (NIS1) is repealed (Arts 41(1), 44).","kind":"effective","sourceUrl":"https://eur-lex.europa.eu/eli/dir/2022/2555/oj","tentative":false,"review":"verified"},{"id":101,"regulationId":"eu-nis2","date":"2024-11-07","title":"Implementing Regulation 2024/2690 enters into force","description":"Commission Implementing Regulation (EU) 2024/2690 (published 18 Oct 2024) sets technical risk-management measures and significant-incident thresholds for DNS, TLD, cloud, data centre, CDN, managed (security) service providers, online marketplaces, search engines, social networks and trust service providers.","kind":"effective","sourceUrl":"https://eur-lex.europa.eu/eli/reg_impl/2024/2690/oj","tentative":false,"review":"verified"},{"id":102,"regulationId":"eu-nis2","date":"2025-01-17","title":"Digital infrastructure entities submit registration data","description":"DNS providers, TLD registries, domain registration services, cloud, data centre, CDN, managed (security) service providers, marketplaces, search engines and social networks had to submit registration details to competent authorities (Art 27(2)).","kind":"reporting","sourceUrl":"https://eur-lex.europa.eu/eli/dir/2022/2555/oj","tentative":false,"review":"verified"},{"id":103,"regulationId":"eu-nis2","date":"2025-04-17","title":"Member States establish entity lists","description":"Member States had to establish lists of essential and important entities and notify the Commission of entity numbers (Art 3(3) and (5)). Repeated every two years.","kind":"reporting","sourceUrl":"https://eur-lex.europa.eu/eli/dir/2022/2555/oj","tentative":false,"review":"verified"},{"id":104,"regulationId":"eu-nis2","date":"2027-04-17","title":"Next biennial entity notification","description":"Competent authorities notify the Commission and Cooperation Group of the number of essential and important entities, repeated every two years after 17 Apr 2025 (Art 3(5)).","kind":"reporting","sourceUrl":"https://eur-lex.europa.eu/eli/dir/2022/2555/oj","tentative":false,"review":"verified"},{"id":105,"regulationId":"eu-nis2","date":"2027-10-17","title":"Commission review of NIS2","description":"Commission must review the functioning of NIS2 and report to Parliament and Council, then every 36 months (Art 40).","kind":"reporting","sourceUrl":"https://eur-lex.europa.eu/eli/dir/2022/2555/oj","tentative":false,"review":"verified"}]},{"id":"us-ny-algo-pricing","name":"New York Algorithmic Pricing Disclosure Act (General Business Law section 349-a)","shortName":"NY Algorithmic Pricing Disclosure Act","jurisdiction":"us-ny","jurisdictionName":"New York","region":"us-states","topics":["privacy","ai"],"status":"in_force","citation":"L. 2025, ch. 58, Part X; N.Y. Gen. Bus. Law section 349-a","enactedDate":"2025-05-09","effectiveDate":"2025-11-10","summary":"Any business that sets a price using personalized algorithmic pricing must show the disclosure 'THIS PRICE WAS SET BY AN ALGORITHM USING YOUR PERSONAL DATA' next to the price. Insurers, GLBA financial institutions and certain subscription prices are exempt.","appliesTo":"Entities domiciled or doing business in New York that set prices with algorithms using consumer personal data.","penalties":"Civil penalty up to $1,000 per violation; AG cease-and-desist and injunctions.","enforcer":"New York Attorney General","sourceUrl":"https://ag.ny.gov/press-release/2025/attorney-general-james-warns-new-yorkers-about-algorithmic-pricing-new-law-takes","extraSources":["https://www.nysenate.gov/legislation/laws/GBS/349-A","https://www.nysenate.gov/legislation/bills/2025/S3008/amendment/C"],"notes":"The One Fair Price Act (S.8623B/A.9349B), which would ban surveillance pricing, passed the legislature in June 2026 per the AG; signature not confirmed, so not tracked.","lastVerified":"2026-09-25","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-25 10:55:47","sourceType":"official","verifiedBy":"research from official sources (2026-09-25)","deadlines":[{"id":6912,"regulationId":"us-ny-algo-pricing","date":"2025-05-09","title":"Signed as part of FY2026 budget","description":"S3008C Part X signed as Chapter 58 of 2025.","kind":"transition","sourceUrl":"https://www.nysenate.gov/legislation/bills/2025/S3008/amendment/C","tentative":false,"review":"verified"},{"id":6913,"regulationId":"us-ny-algo-pricing","date":"2025-11-10","title":"Disclosure duty takes effect","description":"Algorithmic pricing disclosures required.","kind":"effective","sourceUrl":"https://ag.ny.gov/press-release/2025/attorney-general-james-warns-new-yorkers-about-algorithmic-pricing-new-law-takes","tentative":false,"review":"verified"}]},{"id":"us-ny-cdpa","name":"New York Child Data Protection Act","shortName":"NY Child Data Protection Act","jurisdiction":"us-ny","jurisdictionName":"New York","region":"us-states","topics":["children","privacy"],"status":"in_force","citation":"L. 2024, ch. 121 (S7695B); N.Y. Gen. Bus. Law Article 45-A","enactedDate":"2024-06-20","effectiveDate":"2025-06-20","summary":"Online operators may not collect, use, share or sell personal data of users under 18 unless it is strictly necessary for the service or they obtain informed consent. It covers sites and apps directed to minors or with actual knowledge that a user is a minor.","appliesTo":"Operators of websites, online services, apps and connected devices, and their processors, handling data of New York minors.","penalties":"Civil penalties up to $5,000 per violation, damages and injunctions.","enforcer":"New York Attorney General","sourceUrl":"https://www.nysenate.gov/legislation/bills/2023/S7695/amendment/B","extraSources":["https://ag.ny.gov/press-release/2024/attorney-general-james-governor-hochul-and-bill-sponsors-announce-nation-leading","https://ag.ny.gov/press-release/2026/attorney-general-james-and-governor-hochul-release-final-safe-kids-act-rules"],"notes":"The AG's July 2026 SAFE release confirms the Child Data Protection Act is in effect.","lastVerified":"2026-09-25","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-25 10:55:47","sourceType":"official","verifiedBy":"research from official sources (2026-09-25)","deadlines":[{"id":6918,"regulationId":"us-ny-cdpa","date":"2024-06-20","title":"Signed by Governor","description":"Chapter 121 of 2024.","kind":"transition","sourceUrl":"https://www.nysenate.gov/legislation/bills/2023/S7695/amendment/B","tentative":false,"review":"verified"},{"id":6919,"regulationId":"us-ny-cdpa","date":"2025-06-20","title":"Takes effect","description":"Effective one year after becoming law.","kind":"effective","sourceUrl":"https://www.nysenate.gov/legislation/bills/2023/S7695/amendment/B","tentative":false,"review":"verified"}]},{"id":"us-ny-raise","name":"New York Responsible AI Safety and Education (RAISE) Act (S6953-B/A6453-B of 2025), as amended by chapter amendment S8828 of 2026","shortName":"NY RAISE Act","jurisdiction":"us-ny","jurisdictionName":"New York","region":"us-states","topics":["ai"],"status":"enacted","citation":"S6953-B/A6453-B (2025); S8828 (2026, chapter amendment, Laws of 2026 ch. 96); N.Y. Gen. Bus. Law Art. 44-B","enactedDate":"2025-12-19","effectiveDate":"2027-01-01","summary":"Frontier AI developers must publish transparency reports when they deploy models and report critical safety incidents to a new DFS oversight office within 72 hours, or within 24 hours to authorities where there is imminent risk of death or injury. Large frontier developers must also publish and annually update a Frontier AI Framework, submit catastrophic-risk assessments, file disclosure statements with DFS every two years, and pay a share of the office's costs. The March 2026 chapter amendment realigned the law closely with California SB 53.","appliesTo":"Frontier developers training models with more than 10^26 FLOPs; large frontier developers are those with $500 million or more in prior-year revenue, including affiliates.","penalties":"Civil penalties up to $1,000,000 for a first violation and up to $3,000,000 for subsequent violations, sought by the AG. The DFS office may fine $1,000 per day after notice and hearing for failing to file a disclosure statement.","enforcer":"New York Attorney General; DFS AI oversight office (disclosure filings, assessments, regulations)","sourceUrl":"https://www.governor.ny.gov/news/governor-hochul-signs-nation-leading-legislation-require-ai-frameworks-ai-frontier-models","extraSources":["https://www.nysenate.gov/legislation/bills/2025/S8828","https://www.wiley.law/alert-New-York-Finalizes-RAISE-Act-for-Frontier-AI-Models-Law-Takes-Effect-January-1-2027","https://www.dwt.com/blogs/artificial-intelligence-law-advisor/2026/04/ny-overhauls-frontier-ai-transparency-law"],"notes":"nysenate.gov confirms S8828 was signed March 27, 2026 as chapter 96, effective January 1, 2027. Some commentary cites July 1, 2027 for certain provisions; that was not confirmed. The first DFS annual report is due in January 2028 (exact day not verified).","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-22 20:04:22","sourceType":"official","verifiedBy":"research from official sources","deadlines":[{"id":278,"regulationId":"us-ny-raise","date":"2025-12-19","title":"RAISE Act signed","description":"Governor Hochul signs the RAISE Act with an agreed chapter amendment.","kind":"transition","sourceUrl":"https://www.governor.ny.gov/news/governor-hochul-signs-nation-leading-legislation-require-ai-frameworks-ai-frontier-models","tentative":false,"review":"verified"},{"id":279,"regulationId":"us-ny-raise","date":"2026-03-27","title":"Chapter amendment S8828 signed","description":"Chapter amendment (ch. 96) finalizes the RAISE Act text.","kind":"transition","sourceUrl":"https://www.nysenate.gov/legislation/bills/2025/S8828","tentative":false,"review":"verified"},{"id":280,"regulationId":"us-ny-raise","date":"2027-01-01","title":"RAISE Act takes effect","description":"Transparency reports, frontier AI frameworks, incident reporting and DFS disclosure filings apply.","kind":"effective","sourceUrl":"https://www.nysenate.gov/legislation/bills/2025/S8828","tentative":false,"review":"verified"}]},{"id":"us-ny-safe-kids","name":"Stop Addictive Feeds Exploitation (SAFE) for Kids Act","shortName":"NY SAFE for Kids Act","jurisdiction":"us-ny","jurisdictionName":"New York","region":"us-states","topics":["children","online-safety"],"status":"enacted","citation":"L. 2024, ch. 120; N.Y. Gen. Bus. Law Article 45; 13 NYCRR Part 700","enactedDate":"2024-06-20","effectiveDate":"2027-01-25","summary":"Social media platforms may not show algorithmically personalized feeds to users under 18, or send them notifications between midnight and 6 a.m., without parental consent. The AG's final rules set age assurance accuracy standards, certification and parental consent methods.","appliesTo":"Addictive online platforms (user-generated content where users spend at least 20 percent of time on addictive feeds) serving New York users.","penalties":"Civil penalties up to $5,000 per violation, plus injunctions.","enforcer":"New York Attorney General","sourceUrl":"https://ag.ny.gov/press-release/2026/attorney-general-james-and-governor-hochul-release-final-safe-kids-act-rules","extraSources":["https://ag.ny.gov/SAFE-for-kids-act","https://ag.ny.gov/press-release/2024/attorney-general-james-governor-hochul-and-bill-sponsors-announce-nation-leading","https://www.nysenate.gov/legislation/bills/2023/S7694/amendment/A"],"notes":"","lastVerified":"2026-09-25","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-25 10:55:47","sourceType":"official","verifiedBy":"research from official sources (2026-09-25)","deadlines":[{"id":6914,"regulationId":"us-ny-safe-kids","date":"2024-06-20","title":"Signed by Governor","description":"Chapter 120 of 2024.","kind":"transition","sourceUrl":"https://ag.ny.gov/press-release/2024/attorney-general-james-governor-hochul-and-bill-sponsors-announce-nation-leading","tentative":false,"review":"verified"},{"id":6915,"regulationId":"us-ny-safe-kids","date":"2026-07-28","title":"Final SAFE for Kids rules released","description":"AG releases final 13 NYCRR Part 700 rules.","kind":"transition","sourceUrl":"https://ag.ny.gov/press-release/2026/attorney-general-james-and-governor-hochul-release-final-safe-kids-act-rules","tentative":false,"review":"verified"},{"id":6916,"regulationId":"us-ny-safe-kids","date":"2026-07-29","title":"Rules published in State Register","description":"Starts the 180-day clock.","kind":"transition","sourceUrl":"https://ag.ny.gov/press-release/2026/attorney-general-james-and-governor-hochul-release-final-safe-kids-act-rules","tentative":false,"review":"verified"},{"id":6917,"regulationId":"us-ny-safe-kids","date":"2027-01-25","title":"Act and rules take effect","description":"180 days after State Register publication.","kind":"effective","sourceUrl":"https://ag.ny.gov/press-release/2026/attorney-general-james-and-governor-hochul-release-final-safe-kids-act-rules","tentative":false,"review":"verified"}]},{"id":"us-nyc-ll144","name":"New York City Local Law 144 of 2021, Automated Employment Decision Tools (NYC Admin. Code 20-870 et seq.)","shortName":"NYC Local Law 144 (AEDT)","jurisdiction":"us-ny","jurisdictionName":"New York City, New York","region":"us-states","topics":["ai"],"status":"in_force","citation":"NYC Local Law 144 of 2021; NYC Admin. Code 20-870 to 20-874; 6 RCNY 5-300 et seq.","enactedDate":"","effectiveDate":"2023-07-05","summary":"Employers and employment agencies may not use an automated employment decision tool (AEDT) to screen candidates or employees for hiring or promotion unless the tool has had an independent bias audit within the past year. They must publish a summary of the audit results and give candidates at least 10 business days' notice that an AEDT will be used.","appliesTo":"Employers and employment agencies using AEDTs for hiring or promotion decisions for candidates or employees in New York City. No size threshold.","penalties":"Civil penalties up to $500 for a first violation (and each additional violation the same day) and $500 to $1,500 for each subsequent violation; each day of non-compliant use and each failure to notice is a separate violation.","enforcer":"NYC Department of Consumer and Worker Protection (DCWP)","sourceUrl":"https://www.nyc.gov/site/dca/about/automated-employment-decision-tools.page","extraSources":[],"notes":"Law enacted December 2021 with an original January 1, 2023 effective date; enforcement was postponed twice while DCWP finalized rules. Penalty amounts come from Admin. Code 20-872 and were not re-fetched for this record. No 2025-2026 amendments were verified; the search budget was exhausted before checking for proposed City Council amendments.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-22 20:04:22","sourceType":"official","verifiedBy":"research from official sources","deadlines":[{"id":281,"regulationId":"us-nyc-ll144","date":"2023-07-05","title":"DCWP enforcement begins","description":"Bias audit, results publication and candidate notice requirements are enforced.","kind":"enforcement","sourceUrl":"https://www.nyc.gov/site/dca/about/automated-employment-decision-tools.page","tentative":false,"review":"verified"}]},{"id":"us-ny-dfs-500","name":"New York DFS Cybersecurity Requirements for Financial Services Companies (23 NYCRR Part 500), Second Amendment","shortName":"NYDFS Cybersecurity Regulation (Part 500)","jurisdiction":"us-ny","jurisdictionName":"New York","region":"us-states","topics":["cybersecurity","breach-notification","financial"],"status":"amended","citation":"23 NYCRR Part 500 (Second Amendment effective 2023-11-01)","enactedDate":"2023-11-01","effectiveDate":"2017-03-01","summary":"DFS-licensed financial companies must keep a risk-based cybersecurity program, CISO, policies, access controls, MFA, encryption, an asset inventory, and incident response and business continuity plans. They must notify DFS within 72 hours of a cybersecurity event and within 24 hours of any extortion payment, and certify compliance or acknowledge non-compliance each April 15. The 2023 Second Amendment added governance duties, Class A company requirements and phased controls through November 1, 2025.","appliesTo":"Covered entities: persons operating under a DFS license, registration, charter or similar authorization (banks, insurers, money transmitters, etc.). Class A companies: at least $20,000,000 gross annual revenue in each of the last two fiscal years from NY business, and either over 2,000 employees averaged over two years or over $1,000,000,000 gross annual revenue in each of the last two fiscal years. Limited exemption for fewer than 20 employees and contractors, under $7,500,000 gross annual revenue in each of the last 3 fiscal years, or under $15,000,000 year-end total assets.","penalties":"Penalties under the Banking Law, Insurance Law and Financial Services Law. 500.20 lists the factors DFS weighs; the regulation sets no fixed maximum. A single act or failure, including failing to comply for any 24-hour period, is a violation.","enforcer":"New York State Department of Financial Services (DFS)","sourceUrl":"https://www.dfs.ny.gov/cybersecurity/23-NYCRR-Part-500","extraSources":["https://www.dfs.ny.gov/cybersecurity/exemptions"],"notes":"Dates are computed from the 500.22 transitional periods (30 days, 180 days, 1 year, 18 months and 2 years from the November 1, 2023 Second Amendment) and match DFS guidance. DFS also issued 2026 industry letters on frontier-AI cyber risk (May 21, 2026) and risk assessment (September 10, 2026); these are guidance, not rule changes.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-22 20:04:22","sourceType":"official","verifiedBy":"research from official sources","deadlines":[{"id":269,"regulationId":"us-ny-dfs-500","date":"2017-03-01","title":"Part 500 effective","description":"Original cybersecurity regulation takes effect.","kind":"effective","sourceUrl":"https://www.dfs.ny.gov/cybersecurity/23-NYCRR-Part-500","tentative":false,"review":"verified"},{"id":270,"regulationId":"us-ny-dfs-500","date":"2023-11-01","title":"Second Amendment effective","description":"Second Amendment takes effect; 500.19(e)-(h), 500.20, 500.21, 500.22 and 500.24 apply immediately.","kind":"effective","sourceUrl":"https://www.dfs.ny.gov/cybersecurity/23-NYCRR-Part-500","tentative":false,"review":"verified"},{"id":271,"regulationId":"us-ny-dfs-500","date":"2023-12-01","title":"Amended notification requirements (500.17)","description":"New 72-hour event notice, 24-hour extortion payment notice and certification changes apply (30 days).","kind":"compliance","sourceUrl":"https://www.dfs.ny.gov/cybersecurity/23-NYCRR-Part-500","tentative":false,"review":"verified"},{"id":272,"regulationId":"us-ny-dfs-500","date":"2024-04-15","title":"Annual compliance notification","description":"Certification of compliance or acknowledgment of non-compliance due (recurs every April 15).","kind":"reporting","sourceUrl":"https://www.dfs.ny.gov/cybersecurity/23-NYCRR-Part-500","tentative":false,"review":"verified"},{"id":273,"regulationId":"us-ny-dfs-500","date":"2024-04-29","title":"General 180-day transition ends","description":"Most new Second Amendment requirements apply, e.g. annual reporting to the board and risk assessment updates.","kind":"compliance","sourceUrl":"https://www.dfs.ny.gov/cybersecurity/23-NYCRR-Part-500","tentative":false,"review":"verified"},{"id":274,"regulationId":"us-ny-dfs-500","date":"2024-11-01","title":"Governance, encryption, IR/BCDR, exemptions","description":"500.4 governance, 500.15 encryption, 500.16 incident response and business continuity plans, and 500.19(a) revised exemptions apply.","kind":"compliance","sourceUrl":"https://www.dfs.ny.gov/cybersecurity/23-NYCRR-Part-500","tentative":false,"review":"verified"},{"id":275,"regulationId":"us-ny-dfs-500","date":"2025-05-01","title":"Vulnerability scans, access privileges, malware controls, Class A monitoring","description":"500.5(a)(2) automated scans, 500.7 access privilege restrictions, 500.14(a)(2) malicious code protection, and 500.14(b) Class A endpoint detection and centralized logging apply.","kind":"compliance","sourceUrl":"https://www.dfs.ny.gov/cybersecurity/23-NYCRR-Part-500","tentative":false,"review":"verified"},{"id":276,"regulationId":"us-ny-dfs-500","date":"2025-11-01","title":"Universal MFA and asset inventory","description":"500.12 multi-factor authentication for all users and 500.13(a) asset inventory requirements apply.","kind":"compliance","sourceUrl":"https://www.dfs.ny.gov/cybersecurity/23-NYCRR-Part-500","tentative":false,"review":"verified"},{"id":277,"regulationId":"us-ny-dfs-500","date":"2026-04-15","title":"Annual compliance notification","description":"Annual certification or acknowledgment covering calendar year 2025 due.","kind":"reporting","sourceUrl":"https://www.dfs.ny.gov/cybersecurity/23-NYCRR-Part-500","tentative":false,"review":"verified"}]},{"id":"us-ne-aadc","name":"Nebraska Age-Appropriate Online Design Code Act (LB 504)","shortName":"Nebraska Kids Code","jurisdiction":"us-ne","jurisdictionName":"Nebraska","region":"us-states","topics":["children","privacy","online-safety"],"status":"in_force","citation":"Laws 2025, LB 504","enactedDate":"2025-05-30","effectiveDate":"2026-01-01","summary":"Covered online services must use reasonable care to avoid harms to minors from design features, provide default privacy and safety tools, and designate a compliance officer.","appliesTo":"Covered online services that meet the act's business thresholds and are reasonably likely to be used by Nebraska minors.","penalties":"Civil penalty up to $50,000 per violation, recoverable only from 2026-07-01.","enforcer":"Nebraska Attorney General","sourceUrl":"https://nebraskalegislature.gov/FloorDocs/109/PDF/Slip/LB504.pdf","extraSources":[],"notes":"","lastVerified":"2026-09-25","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-25 10:55:47","sourceType":"official","verifiedBy":"research from official sources (2026-09-25)","deadlines":[{"id":6938,"regulationId":"us-ne-aadc","date":"2025-05-30","title":"Approved by Governor","description":"LB 504 signed.","kind":"transition","sourceUrl":"https://nebraskalegislature.gov/FloorDocs/109/PDF/Slip/LB504.pdf","tentative":false,"review":"verified"},{"id":6939,"regulationId":"us-ne-aadc","date":"2026-01-01","title":"Operative date","description":"Act becomes operative.","kind":"effective","sourceUrl":"https://nebraskalegislature.gov/FloorDocs/109/PDF/Slip/LB504.pdf","tentative":false,"review":"verified"},{"id":6940,"regulationId":"us-ne-aadc","date":"2026-07-01","title":"Civil penalties available","description":"AG may begin actions to recover civil penalties.","kind":"enforcement","sourceUrl":"https://nebraskalegislature.gov/FloorDocs/109/PDF/Slip/LB504.pdf","tentative":false,"review":"verified"}]},{"id":"us-ne-ndpa","name":"Nebraska Data Privacy Act (LB 1074, 2024)","shortName":"Nebraska NDPA","jurisdiction":"us-ne","jurisdictionName":"Nebraska","region":"us-states","topics":["privacy"],"status":"in_force","citation":"Neb. Rev. Stat. 87-1101 to 87-1130 (Laws 2024, LB 1074)","enactedDate":"2024-04-17","effectiveDate":"2025-01-01","summary":"Comprehensive consumer privacy law modeled on the Texas TDPSA: consumers get access, correction, deletion, portability and opt-out rights (targeted ads, sale, profiling). Controllers must post privacy notices, obtain opt-in consent for sensitive data, honor universal opt-out signals and run data protection assessments.","appliesTo":"Any person that conducts business in Nebraska or produces products/services consumed by Nebraska residents, processes or sells personal data, and is not a small business as defined by the federal Small Business Act (no consumer-count threshold). Small businesses are still barred from selling sensitive data without consent (87-1118). Exempts state agencies, GLBA financial institutions, HIPAA covered entities/business associates, nonprofits, higher education, utilities.","penalties":"Civil penalty up to $7,500 per violation (87-1124), plus injunctive relief and AG fees/expenses. Mandatory 30-day written-notice cure period before any action (87-1122); it does not sunset. No private right of action (87-1125).","enforcer":"Nebraska Attorney General (exclusive)","sourceUrl":"https://nebraskalegislature.gov/laws/statutes.php?statute=87-1103","extraSources":["https://nebraskalegislature.gov/laws/statutes.php?statute=87-1122","https://nebraskalegislature.gov/laws/statutes.php?statute=87-1124","https://nebraskalegislature.gov/bills/view_bill.php?DocumentID=54904"],"notes":"LB 1074 was approved by the Governor on April 17, 2024 (per the Legislature's bill history). The 30-day cure right is permanent, so there is no cure-sunset deadline. Nebraska's separate Age-Appropriate Online Design Code Act (LB 504, 2025) is a different statute and not covered in this record. No amendments to the NDPA found through Sept 2026.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-22 20:04:22","sourceType":"official","verifiedBy":"research from official sources","deadlines":[{"id":260,"regulationId":"us-ne-ndpa","date":"2025-01-01","title":"Nebraska Data Privacy Act takes effect","description":"Controller and processor obligations and consumer rights under Neb. Rev. Stat. 87-1101 et seq. apply.","kind":"effective","sourceUrl":"https://nebraskalegislature.gov/bills/view_bill.php?DocumentID=54904","tentative":false,"review":"verified"}]},{"id":"us-nv-sb370","name":"Nevada Consumer Health Data Privacy Law (SB 370)","shortName":"Nevada consumer health data law","jurisdiction":"us-nv","jurisdictionName":"Nevada","region":"us-states","topics":["health","privacy","biometrics"],"status":"in_force","citation":"Stats. 2023, ch. 525; NRS 603A.400 to 603A.550","enactedDate":"2023-06-16","effectiveDate":"2024-03-31","summary":"Washington-style consumer health data law. Regulated entities need consent to collect and share consumer health data, must publish a health data privacy policy, honor access and deletion rights, and cannot geofence health care facilities. Selling consumer health data needs written authorization.","appliesTo":"Persons doing business in Nevada or targeting Nevada consumers that determine how consumer health data is processed; HIPAA and GLBA data and some small entities are excluded.","penalties":"Deceptive trade practice; AG may seek civil penalties. No private right of action.","enforcer":"Nevada Attorney General","sourceUrl":"https://www.leg.state.nv.us/Session/82nd2023/Bills/SB/SB370_EN.pdf","extraSources":["https://www.leg.state.nv.us/NRS/NRS-603A.html","https://www.leg.state.nv.us/App/NELIS/REL/82nd2023/Bill/10323/Overview"],"notes":"Complements us-wa-mhmda.","lastVerified":"2026-09-25","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-25 10:55:47","sourceType":"official","verifiedBy":"research from official sources (2026-09-25)","deadlines":[{"id":6922,"regulationId":"us-nv-sb370","date":"2023-06-16","title":"Approved by Governor","description":"Chapter 525, Statutes of Nevada 2023.","kind":"transition","sourceUrl":"https://www.leg.state.nv.us/App/NELIS/REL/82nd2023/Bill/10323/Overview","tentative":false,"review":"verified"},{"id":6923,"regulationId":"us-nv-sb370","date":"2024-03-31","title":"Takes effect","description":"Section 36: act effective March 31, 2024.","kind":"effective","sourceUrl":"https://www.leg.state.nv.us/Session/82nd2023/Bills/SB/SB370_EN.pdf","tentative":false,"review":"verified"}]},{"id":"us-nh-privacy","name":"New Hampshire Privacy Act (SB 255, 2024), RSA chapter 507-H","shortName":"New Hampshire Privacy Act","jurisdiction":"us-nh","jurisdictionName":"New Hampshire","region":"us-states","topics":["privacy","children"],"status":"amended","citation":"RSA 507-H (Laws 2024, ch. 5; amended 2026, ch. 168 (HB 1460))","enactedDate":"2024-03-06","effectiveDate":"2025-01-01","summary":"Comprehensive consumer privacy law giving New Hampshire residents access, correction, deletion, portability and opt-out rights (sale, targeted ads, profiling), with opt-in consent for sensitive data, universal opt-out signal support and data protection assessments. A 2026 amendment (HB 1460) bans selling the personal data of children under 13 starting in 2027.","appliesTo":"Persons conducting business in NH or targeting NH residents that in a one-year period controlled or processed personal data of at least 35,000 unique consumers (excluding payment-only data), or at least 10,000 unique consumers while deriving more than 25% of gross revenue from selling personal data (RSA 507-H:2). Usual GLBA, HIPAA, nonprofit and higher-ed exemptions.","penalties":"Violations are unfair or deceptive acts under the Consumer Protection Act (RSA 358-A): civil penalties up to $10,000 per violation (RSA 358-A:4). 60-day cure notice was mandatory Jan 1 to Dec 31, 2025; from Jan 1, 2026 the AG may offer a cure at its discretion (RSA 507-H:11). No private right of action.","enforcer":"New Hampshire Attorney General (exclusive)","sourceUrl":"https://gc.nh.gov/rsa/html/LII/507-H/507-H-2.htm","extraSources":["https://gc.nh.gov/rsa/html/LII/507-H/507-H-11.htm","https://gc.nh.gov/rsa/html/XXXI/358-A/358-A-mrg.htm","https://gc.nh.gov/bill_status/billinfo.aspx?id=2443&inflect=2","https://www.insideprivacy.com/state-privacy/state-comprehensive-privacy-law-round-up-several-states-amend-their-privacy-statutes/"],"notes":"SB 255 signing date (March 6, 2024) is from contemporaneous reporting; RSA source note confirms Laws 2024, ch. 5. HB 1460 signed June 19, 2026 (chapter 168); Jan 1, 2027 effective date is per Covington Inside Privacy, cross-checked against the NH bill status page showing the bill was signed. The Secretary of State publishes the law link per RSA 507-H:2 II; AG rulemaking is not provided for.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-22 20:04:22","sourceType":"official","verifiedBy":"research from official sources","deadlines":[{"id":261,"regulationId":"us-nh-privacy","date":"2025-01-01","title":"New Hampshire Privacy Act takes effect","description":"RSA 507-H obligations and consumer rights apply (Laws 2024, 5:1, eff. Jan. 1, 2025).","kind":"effective","sourceUrl":"https://gc.nh.gov/rsa/html/LII/507-H/507-H-2.htm","tentative":false,"review":"verified"},{"id":262,"regulationId":"us-nh-privacy","date":"2026-01-01","title":"Mandatory 60-day cure period expires","description":"The AG's obligation to issue a cure notice ended Dec 31, 2025; from Jan 1, 2026 cure opportunities are discretionary (RSA 507-H:11 II-III).","kind":"enforcement","sourceUrl":"https://gc.nh.gov/rsa/html/LII/507-H/507-H-11.htm","tentative":false,"review":"verified"},{"id":263,"regulationId":"us-nh-privacy","date":"2027-01-01","title":"Ban on selling personal data of children under 13 (HB 1460)","description":"HB 1460 (2026, ch. 168) prohibits controllers from selling the personal data of a child under 13.","kind":"effective","sourceUrl":"https://gc.nh.gov/bill_status/billinfo.aspx?id=2443&inflect=2","tentative":false,"review":"verified"}]},{"id":"us-nj-njdpa","name":"New Jersey Data Privacy Act (P.L.2023, c.266; S332)","shortName":"New Jersey NJDPA","jurisdiction":"us-nj","jurisdictionName":"New Jersey","region":"us-states","topics":["privacy","children"],"status":"amended","citation":"P.L.2023, c.266; N.J.S.A. 56:8-166.4 et seq.","enactedDate":"2024-01-16","effectiveDate":"2025-01-15","summary":"Comprehensive consumer privacy law with access, correction, deletion, portability and opt-out rights, opt-in consent for sensitive data, consent for targeted advertising/sale/profiling of known 13-17 year olds, universal opt-out signal support and data protection assessments. It has no revenue-share floor for the smaller threshold, and the Division of Consumer Affairs has rulemaking authority. A June 2026 law (A5328) bans selling sensitive data and creates a data broker registry.","appliesTo":"Controllers conducting business in NJ or targeting NJ residents that in a calendar year control or process personal data of at least 100,000 consumers (excluding payment-only data), or at least 25,000 consumers where the controller derives revenue or receives a discount from selling personal data (any amount). Exempts GLBA financial institutions, HIPAA PHI, and certain other regulated data; nonprofits are NOT exempt.","penalties":"Violations are unlawful practices under the NJ Consumer Fraud Act (N.J.S.A. 56:8-1 et seq.): civil penalties up to $10,000 for the first violation and $20,000 for each subsequent violation (N.J.S.A. 56:8-13). 30-day cure notice required, where a cure is deemed possible, until July 1, 2026 (the first day of the 18th month after the effective date; N.J.S.A. 56:8-166.17). No private right of action.","enforcer":"New Jersey Attorney General / Division of Consumer Affairs","sourceUrl":"https://pub.njleg.state.nj.us/Bills/2022/PL23/266_.PDF","extraSources":["https://www.njoag.gov/murphy-administration-announces-proposed-rules-establishing-comprehensive-consumer-data-privacy-protections/","https://www.insideprivacy.com/state-privacy/state-comprehensive-privacy-law-round-up-several-states-amend-their-privacy-statutes/","https://www.venable.com/insights/publications/2026/07/2026-mid-year-state-privacy-law-update"],"notes":"Rules status: proposed N.J.A.C. 13:45L published June 2, 2025 (57 N.J.R. 1101(a)); no notice of adoption could be confirmed as of Sept 22, 2026. Under NJ's APA a proposal expires one year after publication unless adopted, so check whether the Division re-proposed. A5328 (signed June 30, 2026) details come from Covington Inside Privacy and Venable because the NJ Legislature bill page renders only via JavaScript and could not be read. It also creates a data broker registry with what are reported as the highest fees in the US; data broker obligations are reported to start 270 days after enactment (around late March 2027). That date is omitted because the exact start could not be verified.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-22 20:04:22","sourceType":"official","verifiedBy":"research from official sources","deadlines":[{"id":264,"regulationId":"us-nj-njdpa","date":"2025-01-15","title":"NJDPA takes effect","description":"The act takes effect on the 365th day after enactment on Jan 16, 2024 (sec. 17).","kind":"effective","sourceUrl":"https://pub.njleg.state.nj.us/Bills/2022/PL23/266_.PDF","tentative":false,"review":"verified"},{"id":265,"regulationId":"us-nj-njdpa","date":"2025-06-02","title":"Division of Consumer Affairs proposes NJDPA rules (N.J.A.C. 13:45L)","description":"Proposed rules published at 57 N.J.R. 1101(a); comments were due Aug 1, 2025.","kind":"transition","sourceUrl":"https://www.njoag.gov/murphy-administration-announces-proposed-rules-establishing-comprehensive-consumer-data-privacy-protections/","tentative":false,"review":"verified"},{"id":266,"regulationId":"us-nj-njdpa","date":"2025-07-15","title":"Universal opt-out mechanism must be honored","description":"Controllers that sell personal data or process it for targeted advertising must honor user-selected universal opt-out signals within six months of the effective date (N.J.S.A. 56:8-166.11).","kind":"compliance","sourceUrl":"https://pub.njleg.state.nj.us/Bills/2022/PL23/266_.PDF","tentative":false,"review":"verified"},{"id":267,"regulationId":"us-nj-njdpa","date":"2026-06-30","title":"A5328 sensitive data sale ban takes effect","description":"A5328, signed June 30, 2026, prohibits selling sensitive personal data; the ban took effect on signing.","kind":"effective","sourceUrl":"https://www.njleg.state.nj.us/bill-search/2026/A5328","tentative":false,"review":"verified"},{"id":268,"regulationId":"us-nj-njdpa","date":"2026-07-01","title":"Mandatory 30-day cure period expires","description":"The Division's duty to issue a cure notice before enforcement ends on the first day of the 18th month after the effective date (N.J.S.A. 56:8-166.17(b)).","kind":"enforcement","sourceUrl":"https://pub.njleg.state.nj.us/Bills/2022/PL23/266_.PDF","tentative":false,"review":"verified"}]},{"id":"nz-biometric-code","name":"Biometric Processing Privacy Code 2025","shortName":"New Zealand Biometric Processing Privacy Code","jurisdiction":"nz","jurisdictionName":"New Zealand","region":"apac","topics":["biometrics","privacy"],"status":"in_force","citation":"Code of practice issued under the Privacy Act 2020; Amendment No. 1 (March 2026)","enactedDate":"2025-07-21","effectiveDate":"2025-11-03","summary":"A binding code of practice under the Privacy Act 2020. It sets the privacy rules for organisations that collect and use biometric information, such as face, fingerprints, voice, keystroke patterns or gait, in automated biometric processing like facial recognition. Agencies already using biometrics had a nine-month grace period, which ended on 3 August 2026. Amendment No. 1 aligns the code with the new indirect collection principle (IPP 3A) from 1 May 2026.","appliesTo":"Agencies (public and private organisations) in New Zealand that use biometric processing.","penalties":"A breach of the code is treated as a breach of an information privacy principle, and can lead to complaints, compliance notices and Human Rights Review Tribunal remedies under the Privacy Act 2020.","enforcer":"Office of the Privacy Commissioner","sourceUrl":"https://www.privacy.org.nz/privacy-principles/codes-of-practice/biometric-processing-privacy-code/","extraSources":["https://www.justice.govt.nz/justice-sector-policy/key-initiatives/enhancing-the-privacy-act/"],"notes":"The penalty description is a general statement of how codes work under the Privacy Act 2020. It was not taken from the code page.","lastVerified":"2026-09-25","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-25 11:14:17","sourceType":"official","verifiedBy":"research from official sources (2026-09-25)","deadlines":[{"id":7027,"regulationId":"nz-biometric-code","date":"2025-11-03","title":"Biometric code in force","description":"The Biometric Processing Privacy Code applies to new biometric processing.","kind":"effective","sourceUrl":"https://www.privacy.org.nz/privacy-principles/codes-of-practice/biometric-processing-privacy-code/","tentative":false,"review":"verified"},{"id":7028,"regulationId":"nz-biometric-code","date":"2026-05-01","title":"Amendment No. 1 applies (IPP 3A)","description":"The amended code, which reflects IPP 3A, is in force from 1 May 2026.","kind":"effective","sourceUrl":"https://www.privacy.org.nz/privacy-principles/codes-of-practice/biometric-processing-privacy-code/","tentative":false,"review":"verified"},{"id":7029,"regulationId":"nz-biometric-code","date":"2026-08-03","title":"Grace period ends for existing biometric processing","description":"Agencies already using biometrics before the code started must comply by this date.","kind":"transition","sourceUrl":"https://www.privacy.org.nz/privacy-principles/codes-of-practice/biometric-processing-privacy-code/","tentative":false,"review":"verified"}]},{"id":"nz-privacy-act","name":"Privacy Act 2020 (New Zealand), as amended by the Privacy Amendment Act 2025","shortName":"New Zealand Privacy Act","jurisdiction":"nz","jurisdictionName":"New Zealand","region":"apac","topics":["privacy","breach-notification"],"status":"amended","citation":"Privacy Act 2020 (2020 No 31); Privacy Amendment Act 2025","enactedDate":"2020-06-30","effectiveDate":"2020-12-01","summary":"New Zealand's privacy law, built on 13 Information Privacy Principles plus mandatory notification of serious privacy breaches. The Privacy Amendment Act 2025 adds IPP 3A from 1 May 2026: agencies that collect personal information indirectly (from third parties) must take reasonable steps to tell the individual about the collection, its purpose, recipients and their rights.","appliesTo":"All 'agencies' (public and private sector, any size) that collect or hold personal information, including overseas agencies carrying on business in New Zealand.","penalties":"Criminal fines up to NZD 10,000 for offences such as failing to notify a notifiable privacy breach, misleading an agency, or ignoring a compliance notice. The Human Rights Review Tribunal can award damages.","enforcer":"Office of the Privacy Commissioner; Human Rights Review Tribunal","sourceUrl":"https://www.justice.govt.nz/justice-sector-policy/key-initiatives/enhancing-the-privacy-act/","extraSources":["https://www.privacy.org.nz/privacy-principles/3a/"],"notes":"The 2020 Act assent date (30 Jun 2020) and the NZD 10,000 penalty come from established knowledge, not re-fetched.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-22 20:04:22","sourceType":"official","verifiedBy":"research from official sources","deadlines":[{"id":134,"regulationId":"nz-privacy-act","date":"2020-12-01","title":"Privacy Act 2020 in force","description":"IPPs, mandatory breach notification and compliance notices apply.","kind":"effective","sourceUrl":"https://www.justice.govt.nz/justice-sector-policy/key-initiatives/enhancing-the-privacy-act/","tentative":false,"review":"verified"},{"id":135,"regulationId":"nz-privacy-act","date":"2025-09-24","title":"Privacy Amendment Act 2025 technical changes commence","description":"Technical amendments commence the day after Royal Assent (23 Sep 2025).","kind":"effective","sourceUrl":"https://www.justice.govt.nz/justice-sector-policy/key-initiatives/enhancing-the-privacy-act/","tentative":false,"review":"verified"},{"id":136,"regulationId":"nz-privacy-act","date":"2026-05-01","title":"IPP 3A indirect-collection notification applies","description":"Agencies collecting personal information from third parties must take reasonable steps to notify individuals, subject to exceptions.","kind":"compliance","sourceUrl":"https://www.justice.govt.nz/justice-sector-policy/key-initiatives/enhancing-the-privacy-act/","tentative":false,"review":"verified"}]},{"id":"ng-ndpa","name":"Nigeria Data Protection Act, 2023 and NDPA General Application and Implementation Directive (GAID) 2025","shortName":"Nigeria NDPA","jurisdiction":"ng","jurisdictionName":"Nigeria","region":"mea","topics":["privacy","breach-notification","data-residency"],"status":"amended","citation":"Nigeria Data Protection Act, 2023","enactedDate":"2023-06-12","effectiveDate":"2023-06-12","summary":"Nigeria's primary data protection statute, establishing the NDPC, lawful bases, data subject rights, 72-hour breach notification, and special duties for data controllers and processors of major importance (registration, DPO, compliance audits). The GAID 2025 supersedes the NDPR 2019 and its Implementation Framework with detailed rules on audits, DPIAs, transfers and more.","appliesTo":"Controllers and processors domiciled or operating in Nigeria, or processing personal data of data subjects in Nigeria. 'Data controllers/processors of major importance' designated by NDPC thresholds (tiered by number of data subjects processed).","penalties":"Data controllers/processors of major importance: higher of NGN 10 million or 2% of annual gross revenue in the preceding financial year; others: higher of NGN 2 million or 2% of annual gross revenue.","enforcer":"Nigeria Data Protection Commission (NDPC)","sourceUrl":"https://ndpc.gov.ng/resources/","extraSources":["https://www.aluko-oyebode.com/insights/general-application-and-implementation-directive/","https://www.mondaq.com/nigeria/data-protection/1683848/the-operationality-of-the-nigeria-data-protection-act-ndpa-general-application-and-implementation-directive-gaid-2025"],"notes":"GAID was issued in March 2025 (exact issuance date not verified). Status marked 'amended' because GAID materially changed implementing rules in 2025.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-22 20:04:22","sourceType":"official","verifiedBy":"research from official sources","deadlines":[{"id":132,"regulationId":"ng-ndpa","date":"2023-06-12","title":"NDPA signed into law","description":"President signs the Nigeria Data Protection Act, 2023.","kind":"effective","sourceUrl":"https://ndpc.gov.ng/resources/","tentative":false,"review":"verified"},{"id":133,"regulationId":"ng-ndpa","date":"2025-09-19","title":"GAID 2025 takes effect","description":"General Application and Implementation Directive becomes effective, replacing the NDPR 2019 and NDPR Implementation Framework.","kind":"effective","sourceUrl":"https://ndpc.gov.ng/resources/","tentative":false,"review":"verified"}]},{"id":"us-ok-okcdpa","name":"Oklahoma Consumer Data Privacy Act (SB 546, 2026)","shortName":"Oklahoma OKCDPA","jurisdiction":"us-ok","jurisdictionName":"Oklahoma","region":"us-states","topics":["privacy"],"status":"enacted","citation":"SB 546 (60th Leg., 2nd Sess., 2026)","enactedDate":"2026-03-20","effectiveDate":"2027-01-01","summary":"New Virginia-style comprehensive privacy law: consumers get access, correction, deletion, portability and opt-out rights (sale, targeted ads, profiling), with opt-in consent for sensitive data, privacy notices and data protection assessments. It treats pseudonymous data as personal data and lets controllers authenticate opt-out requests.","appliesTo":"Controllers and processors doing business in Oklahoma or targeting Oklahoma residents that in the preceding calendar year controlled or processed personal data of at least 100,000 consumers, or at least 25,000 consumers while deriving over 50% of gross revenue from selling personal data. Exempts government, nonprofits, GLBA financial institutions, HIPAA entities, higher education; FCRA, FERPA, DPPA data; employee data.","penalties":"Civil penalty up to $7,500 per violation not cured, plus attorney fees and investigative costs. Mandatory 30-day notice-and-cure period that does not sunset. No private right of action.","enforcer":"Oklahoma Attorney General (exclusive)","sourceUrl":"http://www.oklegislature.gov/BillInfo.aspx?Bill=SB546&Session=2600","extraSources":["https://www.okhouse.gov/posts/news-20260323_2","https://www.dwt.com/blogs/privacy--security-law-blog/2026/03/oklahoma-privacy-law-sb-546","https://www.wilmerhale.com/en/insights/blogs/wilmerhale-privacy-and-cybersecurity-law/20260327-oklahoma-enacts-nations-twentieth-state-comprehensive-privacy-law"],"notes":"SB 546 was introduced in 2025 and passed the Senate in March 2025, but it was not enacted until the 2026 session; the Governor approved it March 20, 2026 per the Oklahoma Legislature bill history. So it was not effective Jan 1, 2026. Oklahoma Statutes codification is not yet confirmed. Thresholds, penalty and cure terms are from DWT, WilmerHale and the Oklahoma House press release.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-22 20:04:22","sourceType":"official","verifiedBy":"research from official sources","deadlines":[{"id":282,"regulationId":"us-ok-okcdpa","date":"2027-01-01","title":"Oklahoma Consumer Data Privacy Act takes effect","description":"All OKCDPA obligations and consumer rights apply.","kind":"effective","sourceUrl":"https://www.okhouse.gov/posts/news-20260323_2","tentative":false,"review":"verified"}]},{"id":"ca-on-bill194","name":"Strengthening Cyber Security and Building Trust in the Public Sector Act, 2024","shortName":"Ontario Bill 194","jurisdiction":"ca-on","jurisdictionName":"Ontario, Canada","region":"americas","topics":["cybersecurity","ai","privacy","children","breach-notification"],"status":"in_force","citation":"S.O. 2024, c. 24","enactedDate":"2024-11-25","effectiveDate":"2025-01-29","summary":"Enacts the Enhancing Digital Security and Trust Act, 2024, which lets Ontario set cyber security program, incident reporting and AI governance rules for public sector entities, and rules on digital information about minors held by school boards and children's aid societies. It also amends FIPPA to require privacy impact assessments, reasonable safeguards and breach notification to the IPC and affected people where there is a real risk of significant harm.","appliesTo":"Ontario ministries and provincial institutions under FIPPA, municipal bodies, children's aid societies and school boards. Private companies are not directly covered.","penalties":"No administrative fines in the Act; obligations are enforced through regulations, ministerial directives and IPC review powers.","enforcer":"Ontario Ministry of Public and Business Service Delivery and Procurement; Information and Privacy Commissioner of Ontario (FIPPA parts)","sourceUrl":"https://www.ontario.ca/laws/statute/s24024","extraSources":["https://www.ontario.ca/laws/oic/o250361","https://www.ola.org/en/legislative-business/bills/parliament-43/session-1/bill-194"],"notes":"Detailed cyber security and AI duties depend on regulations and directives made under Schedule 1.","lastVerified":"2026-09-25","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-25 10:55:47","sourceType":"official","verifiedBy":"research from official sources (2026-09-25)","deadlines":[{"id":6943,"regulationId":"ca-on-bill194","date":"2024-11-25","title":"Royal Assent","description":"Bill 194 receives Royal Assent as S.O. 2024, c. 24.","kind":"effective","sourceUrl":"https://www.ontario.ca/laws/statute/s24024","tentative":false,"review":"verified"},{"id":6944,"regulationId":"ca-on-bill194","date":"2025-01-29","title":"Enhancing Digital Security and Trust Act in force","description":"Schedule 1 (cyber security, AI and minors' data framework) and some FIPPA amendments come into force by OIC 361/2025.","kind":"effective","sourceUrl":"https://www.ontario.ca/laws/oic/o250361","tentative":false,"review":"verified"},{"id":6945,"regulationId":"ca-on-bill194","date":"2025-07-01","title":"FIPPA privacy amendments in force","description":"Remaining FIPPA amendments, including privacy impact assessments, safeguards and breach notification to the IPC, come into force.","kind":"compliance","sourceUrl":"https://www.ontario.ca/laws/oic/o250361","tentative":false,"review":"verified"}]},{"id":"us-or-ocpa","name":"Oregon Consumer Privacy Act (SB 619, 2023)","shortName":"Oregon OCPA","jurisdiction":"us-or","jurisdictionName":"Oregon","region":"us-states","topics":["privacy","children"],"status":"amended","citation":"ORS 646A.570 to 646A.589 (Or. Laws 2023, ch. 369); amended by HB 2008 (2025) and HB 3875 (2025)","enactedDate":"2023-07-18","effectiveDate":"2024-07-01","summary":"Comprehensive consumer privacy law with access (including a list of specific third parties data was shared with), correction, deletion, portability and opt-out rights, opt-in consent for sensitive data, universal opt-out signals and data protection assessments. Unusually, it covers nonprofits. 2025 amendments ban selling precise geolocation data and data of consumers under 16, and bring all motor vehicle manufacturers into scope.","appliesTo":"Persons conducting business in Oregon or providing products/services to Oregon residents that in a calendar year control or process personal data of 100,000+ consumers (excluding payment-only data), or 25,000+ consumers while deriving 25%+ of annual gross revenue from selling personal data (ORS 646A.572). Nonprofits covered from July 1, 2025. Motor vehicle manufacturers and certain affiliates are covered regardless of thresholds (HB 3875).","penalties":"Civil penalty up to $7,500 per violation, plus injunctions and AG fees/costs (ORS 646A.589(4)). 30-day cure notice required, where a cure is possible, only until Jan 1, 2026. No private right of action.","enforcer":"Oregon Attorney General (Oregon DOJ Privacy Unit)","sourceUrl":"https://www.oregonlegislature.gov/bills_laws/ors/ors646A.html","extraSources":["https://www.doj.state.or.us/consumer-protection/id-theft-data-breaches/privacy/","https://www.doj.state.or.us/consumer-protection/for-businesses/privacy-law-faqs-for-nonprofits/","https://www.hunton.com/privacy-and-cybersecurity-law-blog/oregon-amends-consumer-privacy-act","https://www.dwt.com/blogs/privacy--security-law-blog/2025/06/oregon-teen-and-geolocation-privacy-law-2026"],"notes":"HB 3875 (signed May 27, 2025) extends OCPA to all motor vehicle manufacturers regardless of thresholds; its exact effective date was not verified, so it has no deadline row. HB 2008 was signed June 3, 2025. Oregon DOJ has released quarterly and annual enforcement reports.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-22 20:04:22","sourceType":"official","verifiedBy":"research from official sources","deadlines":[{"id":283,"regulationId":"us-or-ocpa","date":"2024-07-01","title":"OCPA takes effect for most controllers","description":"OCPA obligations apply to for-profit controllers meeting the thresholds.","kind":"effective","sourceUrl":"https://www.doj.state.or.us/consumer-protection/id-theft-data-breaches/privacy/","tentative":false,"review":"verified"},{"id":284,"regulationId":"us-or-ocpa","date":"2025-07-01","title":"OCPA applies to nonprofits","description":"Nonprofit organizations meeting the thresholds become subject to OCPA.","kind":"effective","sourceUrl":"https://www.doj.state.or.us/consumer-protection/for-businesses/privacy-law-faqs-for-nonprofits/","tentative":false,"review":"verified"},{"id":285,"regulationId":"us-or-ocpa","date":"2026-01-01","title":"Cure period sunsets","description":"The AG's 30-day notice-and-cure requirement expires; enforcement can proceed without a cure opportunity.","kind":"enforcement","sourceUrl":"https://www.oregonlegislature.gov/bills_laws/ors/ors646A.html","tentative":false,"review":"verified"},{"id":286,"regulationId":"us-or-ocpa","date":"2026-01-01","title":"Universal opt-out signals must be honored","description":"Controllers must honor opt-out preference signals such as Global Privacy Control.","kind":"compliance","sourceUrl":"https://www.doj.state.or.us/consumer-protection/id-theft-data-breaches/privacy/","tentative":false,"review":"verified"},{"id":287,"regulationId":"us-or-ocpa","date":"2026-01-01","title":"Sale ban on precise geolocation and under-16 data (HB 2008)","description":"Selling precise geolocation (1,750-ft radius) and the personal data of consumers the controller knows or willfully disregards are under 16 is prohibited.","kind":"effective","sourceUrl":"https://www.doj.state.or.us/consumer-protection/id-theft-data-breaches/privacy/","tentative":false,"review":"verified"}]},{"id":"us-padfa","name":"Protecting Americans' Data from Foreign Adversaries Act of 2024","shortName":"PADFA","jurisdiction":"us","jurisdictionName":"United States (Federal)","region":"us-federal","topics":["privacy","data-residency"],"status":"in_force","citation":"Pub. L. 118-50, div. I, sec. 2 (15 U.S.C. 9901)","enactedDate":"2024-04-24","effectiveDate":"2024-06-23","summary":"Makes it unlawful for a data broker to sell, license, transfer, disclose or otherwise make available personally identifiable sensitive data of U.S. individuals to a foreign adversary country (China, Iran, North Korea, Russia) or to an entity controlled by one. Covered data is broad, including health, financial, biometric, genetic, precise geolocation, private communications and data about minors.","appliesTo":"Data brokers: entities that, for valuable consideration, make available data of U.S. individuals they did not collect directly from those individuals. Excludes entities acting as service providers, entities whose product is not the data itself, and news reporting. 'Controlled by a foreign adversary' includes entities with 20%+ ownership by foreign adversary persons. No volume threshold.","penalties":"Violations are treated as violations of an FTC rule on unfair or deceptive practices: civil penalties up to $53,088 per violation (FTC Act 5(m)(1)(A) amount as adjusted January 2025, 90 FR 5580; adjusted annually for inflation).","enforcer":"Federal Trade Commission","sourceUrl":"https://www.govinfo.gov/content/pkg/PLAW-118publ50/html/PLAW-118publ50.htm","extraSources":["https://www.congress.gov/bill/118th-congress/house-bill/815"],"notes":"Overlaps with the DOJ bulk data rule (28 CFR Part 202); DOJ rule transactions subject to PADFA are carved out of certain DOJ provisions. No FTC implementing regulations are required.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-22 20:04:22","sourceType":"official","verifiedBy":"research from official sources","deadlines":[{"id":288,"regulationId":"us-padfa","date":"2024-06-23","title":"PADFA takes effect","description":"The prohibition takes effect 60 days after enactment (April 24, 2024).","kind":"effective","sourceUrl":"https://www.govinfo.gov/content/pkg/PLAW-118publ50/html/PLAW-118publ50.htm","tentative":false,"review":"verified"}]},{"id":"ca-pipeda","name":"Personal Information Protection and Electronic Documents Act","shortName":"PIPEDA","jurisdiction":"ca","jurisdictionName":"Canada","region":"americas","topics":["privacy","breach-notification"],"status":"in_force","citation":"S.C. 2000, c. 5","enactedDate":"2000-04-13","effectiveDate":"2001-01-01","summary":"Canada's federal private-sector privacy law based on 10 fair information principles, with mandatory breach reporting to the OPC and notification of individuals for breaches creating a real risk of significant harm. It is proposed to be replaced by the Protecting Privacy and Consumer Data Act (Bill C-36, tabled June 2026).","appliesTo":"Private-sector organisations collecting, using or disclosing personal information in the course of commercial activities (except in provinces with substantially similar laws, e.g. Quebec, Alberta, BC for intra-provincial activity), plus federal works, undertakings and businesses' employee data.","penalties":"Fines up to CAD 100,000 per offence for knowingly failing to report/record breaches or obstructing the Commissioner; no administrative monetary penalties.","enforcer":"Office of the Privacy Commissioner of Canada (Federal Court for orders)","sourceUrl":"https://laws-lois.justice.gc.ca/eng/acts/p-8.6/","extraSources":["https://www.priv.gc.ca/"],"notes":"Bill C-27 (CPPA/AIDA) died on the order paper in January 2025. Successor Bill C-36 is tracked separately as ca-c36-ppcda.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-22 20:04:22","sourceType":"official","verifiedBy":"research from official sources","deadlines":[{"id":18,"regulationId":"ca-pipeda","date":"2001-01-01","title":"PIPEDA Part 1 in force (phase 1)","description":"Applies to federally regulated organisations.","kind":"effective","sourceUrl":"https://laws-lois.justice.gc.ca/eng/acts/p-8.6/","tentative":false,"review":"verified"},{"id":19,"regulationId":"ca-pipeda","date":"2004-01-01","title":"PIPEDA applies to all commercial activity","description":"Extended to commercial activity in provinces without substantially similar legislation.","kind":"effective","sourceUrl":"https://laws-lois.justice.gc.ca/eng/acts/p-8.6/","tentative":false,"review":"verified"},{"id":20,"regulationId":"ca-pipeda","date":"2018-11-01","title":"Mandatory breach reporting","description":"Breach of security safeguards reporting, notification and record-keeping obligations take effect.","kind":"compliance","sourceUrl":"https://laws-lois.justice.gc.ca/eng/acts/p-8.6/","tentative":false,"review":"verified"}]},{"id":"pk-peca","name":"Prevention of Electronic Crimes Act, 2016 (as amended by the Prevention of Electronic Crimes (Amendment) Act, 2025)","shortName":"Pakistan PECA","jurisdiction":"pk","jurisdictionName":"Pakistan","region":"apac","topics":["cybersecurity","online-safety"],"status":"amended","citation":"Act No. XL of 2016; amended by Act No. II of 2025","enactedDate":"","effectiveDate":"","summary":"Pakistan's main cybercrime law, covering unauthorised access, data interference, cyber stalking and related offences, plus investigation powers. The 2025 amendment creates a Social Media Protection and Regulatory Authority that enlists social media platforms, orders removal or blocking of unlawful content, and can block non-compliant platforms. It also adds a Social Media Protection Tribunal, a new National Cyber Crime Investigation Agency, and an offence of spreading false information.","appliesTo":"Everyone in Pakistan, Pakistani citizens anywhere, acts abroad that affect people or systems in Pakistan, and social media platforms accessible from Pakistan.","penalties":"The new false information offence (s. 26A) carries up to 3 years in prison, a fine of up to PKR 2 million, or both. The Authority can partly or fully block platforms that do not comply.","enforcer":"Social Media Protection and Regulatory Authority; National Cyber Crime Investigation Agency (NCCIA); Pakistan Telecommunication Authority","sourceUrl":"https://na.gov.pk/uploads/documents/679b243193585_457.pdf","extraSources":["https://www.na.gov.pk/uploads/documents/1470910659_707.pdf"],"notes":"The 2016 Act took effect at once on enactment, but the official NA copy checked does not show the assent date, so enacted_date and effective_date are left blank. Pakistan's draft personal data protection bill has not been enacted.","lastVerified":"2026-09-25","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-25 11:14:17","sourceType":"official","verifiedBy":"research from official sources (2026-09-25)","deadlines":[{"id":7008,"regulationId":"pk-peca","date":"2025-01-29","title":"PECA amendment takes effect","description":"Act No. II of 2025 got presidential assent and took effect on 29 Jan 2025, per the Gazette of Pakistan.","kind":"effective","sourceUrl":"https://na.gov.pk/uploads/documents/679b243193585_457.pdf","tentative":false,"review":"verified"}]},{"id":"pe-ai-law","name":"Ley N° 31814, Ley que promueve el uso de la inteligencia artificial en favor del desarrollo económico y social del país, and its Regulation (Decreto Supremo N° 115-2025-PCM)","shortName":"Peru AI Law and Regulation","jurisdiction":"pe","jurisdictionName":"Peru","region":"americas","topics":["ai"],"status":"in_force","citation":"Ley N° 31814; Decreto Supremo N° 115-2025-PCM","enactedDate":"2023-07-05","effectiveDate":"2026-01-20","summary":"Peru's AI law and its 2025 regulation set a risk-based framework with prohibited uses and high-risk uses (for example in credit, employment, health and education access). Developers and deployers of high-risk systems must run impact assessments, keep human oversight and give transparency. Obligations phase in by sector and company size over one to four years.","appliesTo":"Public administration entities and private sector developers and implementers of AI systems in Peru; personal use and certain national defense uses are excluded.","penalties":"No new fine schedule; complaints go to existing authorities such as INDECOPI and the data protection authority under their own powers.","enforcer":"Presidencia del Consejo de Ministros, Secretaría de Gobierno y Transformación Digital (SGTD)","sourceUrl":"https://www.gob.pe/institucion/pcm/normas-legales/7133522-115-2025-pcm","extraSources":["https://www.gob.pe/institucion/congreso-de-la-republica/normas-legales/4565760-31814"],"notes":"Phase-in dates are counted from the day after publication (2025-09-10) and marked tentative for day-counting. Small and micro enterprises get two and three years respectively.","lastVerified":"2026-09-25","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-25 10:55:47","sourceType":"official","verifiedBy":"research from official sources (2026-09-25)","deadlines":[{"id":6961,"regulationId":"pe-ai-law","date":"2023-07-05","title":"Law 31814 published","description":"AI promotion law published.","kind":"effective","sourceUrl":"https://www.gob.pe/institucion/congreso-de-la-republica/normas-legales/4565760-31814","tentative":false,"review":"verified"},{"id":6962,"regulationId":"pe-ai-law","date":"2025-09-09","title":"Regulation published","description":"DS 115-2025-PCM approving the AI regulation published in El Peruano.","kind":"effective","sourceUrl":"https://www.gob.pe/institucion/pcm/normas-legales/7133522-115-2025-pcm","tentative":false,"review":"verified"},{"id":6963,"regulationId":"pe-ai-law","date":"2026-01-20","title":"Regulation in force","description":"Regulation enters into force 90 business days after publication. Date computed with national holidays, so tentative.","kind":"effective","sourceUrl":"https://www.gob.pe/institucion/pcm/normas-legales/7133522-115-2025-pcm","tentative":true,"review":"verified"},{"id":6964,"regulationId":"pe-ai-law","date":"2026-09-10","title":"Private sector: health, education, justice, security, finance","description":"High-risk and related obligations apply one year after publication for these sectors.","kind":"compliance","sourceUrl":"https://www.gob.pe/institucion/pcm/normas-legales/7133522-115-2025-pcm","tentative":true,"review":"verified"},{"id":6965,"regulationId":"pe-ai-law","date":"2027-09-10","title":"Private sector: transport, commerce, labour","description":"Obligations apply two years after publication.","kind":"compliance","sourceUrl":"https://www.gob.pe/institucion/pcm/normas-legales/7133522-115-2025-pcm","tentative":true,"review":"verified"},{"id":6966,"regulationId":"pe-ai-law","date":"2028-09-10","title":"Private sector: production, agriculture, energy, mining","description":"Obligations apply three years after publication.","kind":"compliance","sourceUrl":"https://www.gob.pe/institucion/pcm/normas-legales/7133522-115-2025-pcm","tentative":true,"review":"verified"},{"id":6967,"regulationId":"pe-ai-law","date":"2029-09-10","title":"Private sector: all other uses","description":"Obligations apply four years after publication.","kind":"compliance","sourceUrl":"https://www.gob.pe/institucion/pcm/normas-legales/7133522-115-2025-pcm","tentative":true,"review":"verified"}]},{"id":"pe-pdpl","name":"Ley N° 29733, Ley de Protección de Datos Personales, and its Regulation (Decreto Supremo N° 016-2024-JUS)","shortName":"Peru PDPL and 2024 Regulation","jurisdiction":"pe","jurisdictionName":"Peru","region":"americas","topics":["privacy","breach-notification","data-residency"],"status":"amended","citation":"Ley N° 29733; Decreto Supremo N° 016-2024-JUS","enactedDate":"2024-11-30","effectiveDate":"2025-03-30","summary":"Peru's 2011 data protection law now runs under a new regulation that replaced the 2013 rules. The regulation adds 48-hour breach notification to the authority, data protection officers phased in by company size, data portability, stronger rules for processors and cross-border transfers, and detailed sanctions procedures.","appliesTo":"Controllers and processors of personal data in Peru, and processing outside Peru in cases set by the regulation.","penalties":"Fines under Law 29733 graded by severity up to 100 UIT per infraction, plus coercive fines of up to 100 UIT for failing to follow orders.","enforcer":"Autoridad Nacional de Protección de Datos Personales (Ministerio de Justicia y Derechos Humanos)","sourceUrl":"https://www.gob.pe/institucion/smv/normas-legales/6426760-016-2024-jus","extraSources":[],"notes":"enacted_date is the regulation's publication date; Law 29733 itself dates from 2011. The 2025-09-30 portability date is computed as six months after entry into force, hence tentative.","lastVerified":"2026-09-25","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-25 10:55:47","sourceType":"official","verifiedBy":"research from official sources (2026-09-25)","deadlines":[{"id":6954,"regulationId":"pe-pdpl","date":"2024-11-30","title":"New regulation published","description":"DS 016-2024-JUS published in El Peruano.","kind":"effective","sourceUrl":"https://www.gob.pe/institucion/smv/normas-legales/6426760-016-2024-jus","tentative":false,"review":"verified"},{"id":6955,"regulationId":"pe-pdpl","date":"2025-03-30","title":"New regulation in force","description":"Regulation enters into force 120 calendar days after publication.","kind":"effective","sourceUrl":"https://www.gob.pe/institucion/smv/normas-legales/6426760-016-2024-jus","tentative":false,"review":"verified"},{"id":6956,"regulationId":"pe-pdpl","date":"2025-09-30","title":"Data portability applies","description":"Article 76 on portability takes effect six months after the regulation enters into force.","kind":"compliance","sourceUrl":"https://www.gob.pe/institucion/smv/normas-legales/6426760-016-2024-jus","tentative":true,"review":"verified"},{"id":6957,"regulationId":"pe-pdpl","date":"2025-11-30","title":"DPO required: large companies","description":"Companies with annual sales above 2,300 UIT must appoint a data protection officer where Art. 37.1(2)-(3) applies.","kind":"compliance","sourceUrl":"https://www.gob.pe/institucion/smv/normas-legales/6426760-016-2024-jus","tentative":false,"review":"verified"},{"id":6958,"regulationId":"pe-pdpl","date":"2026-11-30","title":"DPO required: medium companies","description":"Companies with annual sales above 1,700 UIT up to 2,300 UIT.","kind":"compliance","sourceUrl":"https://www.gob.pe/institucion/smv/normas-legales/6426760-016-2024-jus","tentative":false,"review":"verified"},{"id":6959,"regulationId":"pe-pdpl","date":"2027-11-30","title":"DPO required: small companies","description":"Companies with annual sales above 150 UIT up to 1,700 UIT.","kind":"compliance","sourceUrl":"https://www.gob.pe/institucion/smv/normas-legales/6426760-016-2024-jus","tentative":false,"review":"verified"},{"id":6960,"regulationId":"pe-pdpl","date":"2028-11-30","title":"DPO required: micro companies","description":"Micro companies with annual sales up to 150 UIT.","kind":"compliance","sourceUrl":"https://www.gob.pe/institucion/smv/normas-legales/6426760-016-2024-jus","tentative":false,"review":"verified"}]},{"id":"ph-dpa","name":"Data Privacy Act of 2012 (Republic Act No. 10173)","shortName":"Philippines Data Privacy Act","jurisdiction":"ph","jurisdictionName":"Philippines","region":"apac","topics":["privacy","breach-notification"],"status":"in_force","citation":"Republic Act No. 10173","enactedDate":"2012-08-15","effectiveDate":"2012-09-08","summary":"The Philippines' general data privacy law. It sets consent and lawful processing rules, protects sensitive personal information, gives data subjects access, correction, erasure and portability rights, and creates the National Privacy Commission. Its 2016 Implementing Rules require breach notice to the NPC and affected people within 72 hours, plus registration of data processing systems.","appliesTo":"Personal information controllers and processors in the Philippines, and those outside it that process data of Philippine citizens or residents or use equipment in the Philippines.","penalties":"Criminal penalties, for example 1 to 3 years in prison and PHP 500,000 to 2 million for unauthorized processing, or 3 to 6 years and up to PHP 4 million for sensitive information. The NPC can also issue compliance and stop orders.","enforcer":"National Privacy Commission (NPC)","sourceUrl":"https://privacy.gov.ph/data-privacy-act/","extraSources":["https://privacy.gov.ph/implementing-rules-regulations-data-privacy-act-2012/","https://lawphil.net/statutes/repacts/ra2012/ra_10173_2012.html"],"notes":"The NPC page shows the approval date (15 Aug 2012) but not the publication or start dates. Penalty figures come from the Act text as given on LawPhil.","lastVerified":"2026-09-25","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-25 11:14:17","sourceType":"official","verifiedBy":"research from official sources (2026-09-25)","deadlines":[{"id":7005,"regulationId":"ph-dpa","date":"2012-09-08","title":"Data Privacy Act takes effect","description":"The Act takes effect 15 days after publication in two national newspapers (sec. 45). This date comes from secondary sources, not the NPC page.","kind":"effective","sourceUrl":"https://privacy.gov.ph/data-privacy-act/","tentative":true,"review":"verified"},{"id":7006,"regulationId":"ph-dpa","date":"2016-09-09","title":"Implementing Rules take effect","description":"The IRR takes effect 15 days after publication in the Official Gazette (sec. 72), with 72-hour breach notice. The exact date was not shown on the NPC page.","kind":"effective","sourceUrl":"https://privacy.gov.ph/implementing-rules-regulations-data-privacy-act-2012/","tentative":true,"review":"verified"}]},{"id":"eu-pld","name":"Directive (EU) 2024/2853 on liability for defective products (new Product Liability Directive)","shortName":"Product Liability Directive","jurisdiction":"eu","jurisdictionName":"European Union","region":"eu","topics":["ai","cybersecurity"],"status":"enacted","citation":"OJ L, 2024/2853, 18.11.2024","enactedDate":"2024-10-23","effectiveDate":"2024-12-08","summary":"Modernises EU strict (no-fault) liability for defective products. Software (including AI systems and SaaS), digital manufacturing files and related digital services now count as products. Destruction or corruption of non-professional data is compensable damage, and missing security updates or cybersecurity vulnerabilities can make a product defective. Courts can order evidence disclosure and presume defectiveness in complex cases.","appliesTo":"Manufacturers (including software developers and AI providers), importers, authorised representatives, fulfilment service providers and, in some cases, distributors and online platforms, for products placed on the EU market on or after 9 Dec 2026. Free and open-source software supplied outside a commercial activity is excluded.","penalties":"Civil liability: compensation for death, personal injury, damage to property and destruction/corruption of data. No regulatory fines. Claims expire 10 years after placing on the market (25 years for latent personal injury).","enforcer":"National courts (private claims by injured persons)","sourceUrl":"https://eur-lex.europa.eu/eli/dir/2024/2853/oj","extraSources":[],"notes":"The companion AI Liability Directive proposal was withdrawn by the Commission (2025 work programme); it is not covered here.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-22 20:04:22","sourceType":"official","verifiedBy":"research from official sources","deadlines":[{"id":106,"regulationId":"eu-pld","date":"2024-12-08","title":"New PLD enters into force","description":"Directive entered into force on the twentieth day after publication in the OJ on 18 Nov 2024 (Art 23).","kind":"effective","sourceUrl":"https://eur-lex.europa.eu/eli/dir/2024/2853/oj","tentative":false,"review":"verified"},{"id":107,"regulationId":"eu-pld","date":"2026-12-09","title":"Transposition deadline; old PLD repealed","description":"Member States must transpose by 9 Dec 2026 (Art 22). Directive 85/374/EEC is repealed from that date but still applies to products placed on the market before it (Art 21).","kind":"transition","sourceUrl":"https://eur-lex.europa.eu/eli/dir/2024/2853/oj","tentative":false,"review":"verified"}]},{"id":"ca-qc-law25","name":"Act to modernize legislative provisions as regards the protection of personal information (Law 25, formerly Bill 64)","shortName":"Quebec Law 25","jurisdiction":"ca-qc","jurisdictionName":"Quebec, Canada","region":"americas","topics":["privacy","breach-notification","biometrics"],"status":"in_force","citation":"S.Q. 2021, c. 25 (amending CQLR c. P-39.1)","enactedDate":"2021-09-22","effectiveDate":"2022-09-22","summary":"Overhauls Quebec's private-sector privacy law with GDPR-style duties: a designated person in charge of privacy, confidentiality incident reporting, privacy impact assessments (including before transfers outside Quebec), privacy by default, automated decision transparency, and data portability.","appliesTo":"Any enterprise collecting, holding, using or communicating personal information of individuals in Quebec in the course of carrying on an enterprise; no size threshold.","penalties":"Administrative monetary penalties up to CAD 10 million or 2% of worldwide turnover; penal fines up to CAD 25 million or 4% of worldwide turnover (whichever is greater), doubled for repeat offences; private right of action with punitive damages of at least CAD 1,000 for intentional or grossly negligent breaches.","enforcer":"Commission d'accès à l'information du Québec (CAI)","sourceUrl":"https://www.legisquebec.gouv.qc.ca/en/document/cs/P-39.1","extraSources":["https://www.cai.gouv.qc.ca/"],"notes":"Dates and penalties from well-established sources; LegisQuebec consolidation used as the official reference.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-22 20:04:22","sourceType":"official","verifiedBy":"research from official sources","deadlines":[{"id":21,"regulationId":"ca-qc-law25","date":"2021-09-22","title":"Assent","description":"Bill 64 assented to as S.Q. 2021, c. 25.","kind":"effective","sourceUrl":"https://www.legisquebec.gouv.qc.ca/en/document/cs/P-39.1","tentative":false,"review":"verified"},{"id":22,"regulationId":"ca-qc-law25","date":"2022-09-22","title":"Phase 1: privacy officer and incident reporting","description":"Person in charge of personal information protection, confidentiality incident notification and register apply.","kind":"compliance","sourceUrl":"https://www.legisquebec.gouv.qc.ca/en/document/cs/P-39.1","tentative":false,"review":"verified"},{"id":23,"regulationId":"ca-qc-law25","date":"2023-09-22","title":"Phase 2: main obligations and penalties","description":"Governance policies, PIAs, consent, transparency, privacy by default, ADM notices, cross-border PIAs and AMP/penal regime apply.","kind":"compliance","sourceUrl":"https://www.legisquebec.gouv.qc.ca/en/document/cs/P-39.1","tentative":false,"review":"verified"},{"id":24,"regulationId":"ca-qc-law25","date":"2024-09-22","title":"Phase 3: data portability","description":"Right to data portability in a structured, commonly used technological format applies.","kind":"compliance","sourceUrl":"https://www.legisquebec.gouv.qc.ca/en/document/cs/P-39.1","tentative":false,"review":"verified"}]},{"id":"us-ri-dtppa","name":"Rhode Island Data Transparency and Privacy Protection Act","shortName":"Rhode Island RIDTPPA","jurisdiction":"us-ri","jurisdictionName":"Rhode Island","region":"us-states","topics":["privacy"],"status":"in_force","citation":"R.I. Gen. Laws 6-48.1-1 et seq. (P.L. 2024, ch. 430 and ch. 453; H 7787 / S 2500)","enactedDate":"2024-06-28","effectiveDate":"2026-01-01","summary":"Comprehensive consumer privacy law giving access, correction, deletion, portability and opt-out rights, requiring opt-in consent for sensitive data and data protection assessments. A notable extra: any commercial website or ISP that sells personally identifiable information must disclose the categories collected and every third party it has sold or may sell data to, whatever its size.","appliesTo":"For-profit entities conducting business in RI or targeting RI residents that in the preceding calendar year controlled or processed personal data of at least 35,000 customers (excluding payment-only data), or at least 10,000 customers while deriving more than 20% of gross revenue from selling personal data (6-48.1-4). The 6-48.1-3 disclosure duties apply to any commercial website or ISP doing business in RI. Exempts government, nonprofits, higher education, GLBA and HIPAA entities.","penalties":"Violations are deceptive trade practices under R.I. Gen. Laws ch. 6-13.1 (civil penalty up to $10,000 per violation, 6-13.1-8). Intentional disclosures to shell entities or otherwise in violation of the act also carry a fine of $100 to $500 per disclosure (6-48.1-8). No cure period. No private right of action.","enforcer":"Rhode Island Attorney General (sole enforcement authority)","sourceUrl":"https://webserver.rilegislature.gov/Statutes/TITLE6/6-48.1/INDEX.htm","extraSources":["https://webserver.rilegislature.gov/Statutes/TITLE6/6-48.1/6-48.1-4.htm","https://webserver.rilegislature.gov/Statutes/TITLE6/6-48.1/6-48.1-8.htm","https://webserver.rilegislature.gov/Statutes/TITLE6/6-13.1/6-13.1-8.htm"],"notes":"The act became law without the Governor's signature in late June 2024; June 28, 2024 is the commonly reported date and was not confirmed on an official page. The statute has no cure period and no rulemaking authority. No amendments found through Sept 2026.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-22 20:04:22","sourceType":"official","verifiedBy":"research from official sources","deadlines":[{"id":289,"regulationId":"us-ri-dtppa","date":"2026-01-01","title":"RIDTPPA takes effect","description":"All provisions of R.I. Gen. Laws ch. 6-48.1 apply (P.L. 2024, ch. 430/453, effective Jan 1, 2026).","kind":"effective","sourceUrl":"https://webserver.rilegislature.gov/Statutes/TITLE6/6-48.1/INDEX.htm","tentative":false,"review":"verified"}]},{"id":"rw-dpp","name":"Law No. 058/2021 of 13/10/2021 relating to the Protection of Personal Data and Privacy","shortName":"Rwanda DPP Law","jurisdiction":"rw","jurisdictionName":"Rwanda","region":"mea","topics":["privacy","data-residency","breach-notification"],"status":"in_force","citation":"Law No. 058/2021 of 13/10/2021","enactedDate":"2021-10-13","effectiveDate":"2021-10-15","summary":"Rwanda's data protection law, modelled on the GDPR. Controllers and processors must register with the supervisory authority, report breaches within 72 hours, and store personal data in Rwanda unless they hold a certificate allowing storage abroad. Cross-border transfers need authorisation or another listed ground.","appliesTo":"Controllers, processors and third parties established or resident in Rwanda, and those outside Rwanda that process data of people in Rwanda.","penalties":"Administrative fines of RWF 2 million to 5 million or 1% of global turnover for the prior year; legal entities face 1% of global turnover. Criminal offences under Arts. 56 and after carry prison terms and fines.","enforcer":"National Cyber Security Authority (NCSA), through its Data Protection and Privacy Office","sourceUrl":"https://www.minijust.gov.rw/fileadmin/user_upload/Minijust/Official_gazettes_2/_________2021_Official_Gazettes/October/OG_Special_of_15.10.2021_Amakuru_bwite.pdf","extraSources":["https://rwandalii.org/akn/rw/act/law/2021/58/eng@2021-10-15","https://dpo.gov.rw/"],"notes":"Dates and article numbers were checked in the official gazette PDF from the Ministry of Justice; RwandaLII has a searchable copy of the same text.","lastVerified":"2026-09-25","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-25 11:14:17","sourceType":"official","verifiedBy":"research from official sources (2026-09-25)","deadlines":[{"id":7034,"regulationId":"rw-dpp","date":"2021-10-15","title":"Law published and in force","description":"Published in Official Gazette No. Special of 15/10/2021. Article 70: in force on publication.","kind":"effective","sourceUrl":"https://www.minijust.gov.rw/fileadmin/user_upload/Minijust/Official_gazettes_2/_________2021_Official_Gazettes/October/OG_Special_of_15.10.2021_Amakuru_bwite.pdf","tentative":false,"review":"verified"},{"id":7035,"regulationId":"rw-dpp","date":"2023-10-15","title":"Two-year transition ends","description":"Article 67 gave controllers and processors already operating two years from publication to comply.","kind":"transition","sourceUrl":"https://www.minijust.gov.rw/fileadmin/user_upload/Minijust/Official_gazettes_2/_________2021_Official_Gazettes/October/OG_Special_of_15.10.2021_Amakuru_bwite.pdf","tentative":false,"review":"verified"}]},{"id":"us-sec-cyber","name":"SEC Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure (Release No. 33-11216)","shortName":"SEC Cyber Disclosure Rules","jurisdiction":"us","jurisdictionName":"United States (Federal)","region":"us-federal","topics":["cybersecurity","breach-notification","financial"],"status":"in_force","citation":"Release No. 33-11216; 88 FR 51896 (Aug. 4, 2023); Form 8-K Item 1.05; Regulation S-K Item 106","enactedDate":"2023-07-26","effectiveDate":"2023-09-05","summary":"Public companies must disclose a material cybersecurity incident on Form 8-K Item 1.05 within four business days of determining it is material (foreign private issuers use Form 6-K), and describe cybersecurity risk management, strategy and governance annually in Form 10-K (Item 106) or Form 20-F (Item 16K).","appliesTo":"SEC registrants filing Exchange Act reports, including smaller reporting companies and foreign private issuers. Disclosure delay is available only if the U.S. Attorney General determines immediate disclosure poses a substantial risk to national security or public safety.","penalties":"No fixed fine schedule; violations enforced under the federal securities laws (civil penalties, disgorgement, injunctions, officer and director bars).","enforcer":"U.S. Securities and Exchange Commission","sourceUrl":"https://www.federalregister.gov/documents/2023/08/04/2023-16194/cybersecurity-risk-management-strategy-governance-and-incident-disclosure","extraSources":["https://www.sec.gov/newsroom/press-releases/2023-139","https://www.sec.gov/files/rules/final/2023/33-11216.pdf","https://www.federalregister.gov/documents/2025/06/17/2025-11110/withdrawal-of-proposed-regulatory-actions"],"notes":"Industry petitions (e.g. April 2026 comment letters) ask the SEC to rescind Item 1.05; no proposed rescission had appeared in the Federal Register as of 2026-09-22. In June 2025 the SEC withdrew its separate 2022/2023 cybersecurity risk management proposals for investment advisers/funds and for broker-dealers and other market entities.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-22 20:04:22","sourceType":"official","verifiedBy":"research from official sources","deadlines":[{"id":290,"regulationId":"us-sec-cyber","date":"2023-12-15","title":"Annual cybersecurity disclosures begin (Item 106 / 16K)","description":"Required in annual reports for fiscal years ending on or after this date.","kind":"compliance","sourceUrl":"https://www.federalregister.gov/documents/2023/08/04/2023-16194/cybersecurity-risk-management-strategy-governance-and-incident-disclosure","tentative":false,"review":"verified"},{"id":291,"regulationId":"us-sec-cyber","date":"2023-12-18","title":"Form 8-K Item 1.05 incident disclosure begins","description":"All registrants other than smaller reporting companies must file material incident disclosures from this date.","kind":"compliance","sourceUrl":"https://www.federalregister.gov/documents/2023/08/04/2023-16194/cybersecurity-risk-management-strategy-governance-and-incident-disclosure","tentative":false,"review":"verified"},{"id":292,"regulationId":"us-sec-cyber","date":"2024-06-15","title":"Smaller reporting companies: Item 1.05 compliance","description":"Smaller reporting companies must begin complying with Form 8-K Item 1.05 incident disclosure.","kind":"compliance","sourceUrl":"https://www.federalregister.gov/documents/2023/08/04/2023-16194/cybersecurity-risk-management-strategy-governance-and-incident-disclosure","tentative":false,"review":"verified"},{"id":293,"regulationId":"us-sec-cyber","date":"2024-12-15","title":"Inline XBRL tagging of annual cybersecurity disclosures","description":"Item 106 / Item 16K disclosures must be tagged in Inline XBRL for fiscal years ending on or after this date.","kind":"compliance","sourceUrl":"https://www.federalregister.gov/documents/2023/08/04/2023-16194/cybersecurity-risk-management-strategy-governance-and-incident-disclosure","tentative":false,"review":"verified"},{"id":294,"regulationId":"us-sec-cyber","date":"2024-12-18","title":"Inline XBRL tagging of Item 1.05 disclosures","description":"Form 8-K Item 1.05 and Form 6-K incident disclosures must be tagged in Inline XBRL.","kind":"compliance","sourceUrl":"https://www.federalregister.gov/documents/2023/08/04/2023-16194/cybersecurity-risk-management-strategy-governance-and-incident-disclosure","tentative":false,"review":"verified"}]},{"id":"us-sec-reg-sp","name":"Regulation S-P: Privacy of Consumer Financial Information and Safeguarding Customer Information (2024 amendments)","shortName":"SEC Regulation S-P","jurisdiction":"us","jurisdictionName":"United States (Federal)","region":"us-federal","topics":["financial","privacy","cybersecurity","breach-notification"],"status":"amended","citation":"17 CFR Part 248; 89 FR 47688 (June 3, 2024)","enactedDate":"2024-05-16","effectiveDate":"2024-08-02","summary":"Requires broker-dealers, investment companies, registered investment advisers and transfer agents to adopt a written incident response program and notify affected individuals as soon as practicable, and no later than 30 days, after becoming aware that sensitive customer information was, or is reasonably likely to have been, accessed or used without authorization. Service providers must be overseen and must notify the covered institution within 72 hours of a breach; recordkeeping and annual privacy notice changes also apply.","appliesTo":"SEC-registered broker-dealers (incl. funding portals), investment companies, registered investment advisers and transfer agents. 'Larger entities' (earlier deadline): investment companies with $1 billion+ net assets (with related funds), RIAs with $1.5 billion+ AUM, and broker-dealers and transfer agents that are not small entities; all others are smaller entities.","penalties":"No fixed fine schedule; enforced under the federal securities laws (civil penalties, cease-and-desist orders, censures, bars).","enforcer":"U.S. Securities and Exchange Commission","sourceUrl":"https://www.federalregister.gov/documents/2024/06/03/2024-11116/regulation-s-p-privacy-of-consumer-financial-information-and-safeguarding-customer-information","extraSources":["https://www.ecfr.gov/current/title-17/chapter-II/part-248/subpart-A/section-248.30"],"notes":"Compliance dates are stated in the release as 18 and 24 months after the June 3, 2024 publication. No delay of these dates was found in the Federal Register as of 2026-09-22.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-22 20:04:22","sourceType":"official","verifiedBy":"research from official sources","deadlines":[{"id":295,"regulationId":"us-sec-reg-sp","date":"2024-08-02","title":"Amendments effective","description":"The Regulation S-P amendments became effective; compliance tiered by entity size.","kind":"effective","sourceUrl":"https://www.federalregister.gov/documents/2024/06/03/2024-11116/regulation-s-p-privacy-of-consumer-financial-information-and-safeguarding-customer-information","tentative":false,"review":"verified"},{"id":296,"regulationId":"us-sec-reg-sp","date":"2025-12-03","title":"Larger entities must comply","description":"Larger covered institutions (18 months after Federal Register publication) must have incident response programs, 30-day customer notification, and service-provider oversight in place.","kind":"compliance","sourceUrl":"https://www.federalregister.gov/documents/2024/06/03/2024-11116/regulation-s-p-privacy-of-consumer-financial-information-and-safeguarding-customer-information","tentative":false,"review":"verified"},{"id":297,"regulationId":"us-sec-reg-sp","date":"2026-06-03","title":"Smaller entities must comply","description":"Smaller covered institutions (24 months after Federal Register publication) must comply with the amended Regulation S-P.","kind":"compliance","sourceUrl":"https://www.federalregister.gov/documents/2024/06/03/2024-11116/regulation-s-p-privacy-of-consumer-financial-information-and-safeguarding-customer-information","tentative":false,"review":"verified"}]},{"id":"sa-pdpl","name":"Personal Data Protection Law (Royal Decree M/19 of 9/2/1443H, as amended by Royal Decree M/148 of 5/9/1444H)","shortName":"Saudi PDPL","jurisdiction":"sa","jurisdictionName":"Saudi Arabia","region":"mea","topics":["privacy","data-residency","breach-notification"],"status":"in_force","citation":"Royal Decree M/19 (1443H); amended by Royal Decree M/148 (1444H)","enactedDate":"2021-09-16","effectiveDate":"2023-09-14","summary":"Saudi Arabia's comprehensive data protection law with implementing regulations and separate transfer regulations: legal bases, data subject rights, breach notification to SDAIA within 72 hours, DPO and registration requirements, and restrictions on transfers outside the Kingdom.","appliesTo":"Any processing of personal data of individuals in Saudi Arabia by entities inside or outside the Kingdom, including data of deceased persons.","penalties":"Disclosure/publication of sensitive data with intent to harm: up to 2 years' imprisonment and/or fine up to SAR 3 million; other violations: warning or fine up to SAR 5 million, which may be doubled for repeat violations.","enforcer":"Saudi Data and Artificial Intelligence Authority (SDAIA) / National Data Management Office","sourceUrl":"https://sdaia.gov.sa/en/SDAIA/about/Documents/Personal%20Data%20English%20V2-23April2023-%20Reviewed-.pdf","extraSources":["https://sdaia.gov.sa/","https://iapp.org/news/a/saudi-pdpl-s-first-anniversary-amendments-enforcement-and-ongoing-developments"],"notes":"SDAIA consulted on amendments to the implementing regulations (closed 27 May 2025); adoption not verified.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-22 20:04:22","sourceType":"official","verifiedBy":"research from official sources","deadlines":[{"id":137,"regulationId":"sa-pdpl","date":"2023-09-14","title":"PDPL in force","description":"PDPL and its implementing regulations take effect.","kind":"effective","sourceUrl":"https://sdaia.gov.sa/en/SDAIA/about/Documents/Personal%20Data%20English%20V2-23April2023-%20Reviewed-.pdf","tentative":false,"review":"verified"},{"id":138,"regulationId":"sa-pdpl","date":"2024-09-14","title":"One-year grace period ends","description":"Grace period for controllers to comply ends; PDPL fully enforceable.","kind":"enforcement","sourceUrl":"https://sdaia.gov.sa/en/SDAIA/about/Documents/Personal%20Data%20English%20V2-23April2023-%20Reviewed-.pdf","tentative":false,"review":"verified"}]},{"id":"sg-cybersecurity-act","name":"Cybersecurity Act 2018","shortName":"Singapore Cybersecurity Act","jurisdiction":"sg","jurisdictionName":"Singapore","region":"apac","topics":["cybersecurity","breach-notification"],"status":"amended","citation":"Act No. 9 of 2018; amended by Cybersecurity (Amendment) Act 2024 (Act No. 19 of 2024)","enactedDate":"2018-03-02","effectiveDate":"2018-08-31","summary":"Singapore's framework for protecting critical information infrastructure (CII). CII owners must meet codes of practice, run audits and risk assessments, and report prescribed cybersecurity incidents to the Commissioner of Cybersecurity. Providers of licensable services (penetration testing and managed SOC) need a licence. The 2024 amendments extend oversight to foundational digital infrastructure providers, entities of special cybersecurity interest, systems of temporary cybersecurity concern, and CII located overseas, and add civil penalties.","appliesTo":"Owners of designated CII, licensed cybersecurity service providers, and since 2025 foundational digital infrastructure providers (such as cloud and data centre operators), entities of special cybersecurity interest and owners of systems of temporary cybersecurity concern.","penalties":"For some offences, fines up to the greater of SGD 200,000 or 10% of the person's annual turnover in Singapore, plus up to SGD 5,000 a day for continuing offences. The Commissioner may seek a court-ordered civil penalty instead of prosecution (section 37A).","enforcer":"Commissioner of Cybersecurity (Cyber Security Agency of Singapore)","sourceUrl":"https://sso.agc.gov.sg/Acts-Supp/9-2018/Published/20211231?DocDate=20180312","extraSources":["https://sso.agc.gov.sg/Acts-Supp/19-2024/Published/20240704?DocDate=20240704","https://sso.agc.gov.sg/Act/CA2018"],"notes":"Passed 2018-02-05 and assented 2018-03-02. The 2024 amendment was passed 2024-05-07 and assented 2024-05-23. Some sections of the 2024 Act are not listed in the 2025-10-31 commencement. SSO blocks automated fetch but loads in a browser.","lastVerified":"2026-09-25","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-25 11:14:17","sourceType":"official","verifiedBy":"research from official sources (2026-09-25)","deadlines":[{"id":7011,"regulationId":"sg-cybersecurity-act","date":"2018-08-31","title":"Cybersecurity Act main provisions commence","description":"Parts 1 to 4, 6 and the First Schedule (CII regime) commence.","kind":"effective","sourceUrl":"https://sso.agc.gov.sg/Acts-Supp/9-2018/Published/20211231?DocDate=20180312","tentative":false,"review":"verified"},{"id":7012,"regulationId":"sg-cybersecurity-act","date":"2022-04-11","title":"Cybersecurity service provider licensing commences","description":"Part 5 and the Second Schedule take effect. Penetration testing and managed SOC providers need a licence.","kind":"effective","sourceUrl":"https://sso.agc.gov.sg/Acts-Supp/9-2018/Published/20211231?DocDate=20180312","tentative":false,"review":"verified"},{"id":7013,"regulationId":"sg-cybersecurity-act","date":"2025-10-31","title":"2024 amendments commence","description":"Most of the Cybersecurity (Amendment) Act 2024 takes effect, covering foundational digital infrastructure, entities of special cybersecurity interest and systems of temporary cybersecurity concern.","kind":"effective","sourceUrl":"https://sso.agc.gov.sg/Acts-Supp/19-2024/Published/20240704?DocDate=20240704","tentative":false,"review":"verified"}]},{"id":"sg-online-safety-act","name":"Online Safety (Relief and Accountability) Act 2025","shortName":"Singapore Online Safety (Relief and Accountability) Act","jurisdiction":"sg","jurisdictionName":"Singapore","region":"apac","topics":["online-safety","children","privacy"],"status":"in_force","citation":"Act No. 23 of 2025","enactedDate":"2025-11-25","effectiveDate":"2026-06-29","summary":"Creates a Commissioner of Online Safety, supported by the Online Safety Commission (OSC), who can direct platforms, posters and group administrators to stop or limit specified online harms. The first phase covers online harassment, doxxing, online stalking, intimate image abuse and image-based child abuse; eight further harm categories, including inauthentic material abuse, will be brought in later. The Act also creates statutory torts so victims can sue communicators, administrators and prescribed platforms in court.","appliesTo":"Online service providers, including prescribed platforms with significant reach in Singapore, group and page administrators, and people who post harmful material about Singapore citizens and residents.","penalties":"Failure to comply with OSC directions can lead to orders such as access blocking. For intimate image abuse and image-based child abuse, courts must award at least SGD 5,000 per image or recording when a statutory tort claim succeeds. Criminal fine amounts are not captured here.","enforcer":"Commissioner of Online Safety and the Online Safety Commission (under MDDI); courts for statutory torts; Online Safety Appeal Panel for appeals","sourceUrl":"https://sso.agc.gov.sg/Acts-Supp/23-2025/Published/20251208?DocDate=20251208","extraSources":["https://www.osc.gov.sg/newsroom/the-online-safety-commission-begins-operations-on-29-june-2026/","https://www.osc.gov.sg/about-us/","https://www.mddi.gov.sg/newsroom/mddi-response-to-pq-on-protecting-against-unauthorised-ai-generated-likeness-in-advertisements-and-operationalising-online-safety-commission-mandate-over-inauthentic-material-abuse"],"notes":"Passed 2025-11-05; published in the Acts Supplement on 2025-12-12. SSO blocks automated fetch but loads in a browser. MDDI said on 2026-09-10 that the commencement date for inauthentic material abuse (including AI deepfakes) will be announced later. Victims must report harassment and stalking to the platform first and may go to the OSC if there is no adequate response within 24 hours.","lastVerified":"2026-09-25","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-25 11:14:17","sourceType":"official","verifiedBy":"research from official sources (2026-09-25)","deadlines":[{"id":7009,"regulationId":"sg-online-safety-act","date":"2025-11-25","title":"Act assented to","description":"Passed by Parliament on 5 November 2025 and assented to by the President on 25 November 2025.","kind":"effective","sourceUrl":"https://sso.agc.gov.sg/Acts-Supp/23-2025/Published/20251208?DocDate=20251208","tentative":false,"review":"verified"},{"id":7010,"regulationId":"sg-online-safety-act","date":"2026-06-29","title":"OSC begins operations and first provisions commence","description":"OSC starts taking reports for five harms, and the statutory torts for those harms take effect.","kind":"effective","sourceUrl":"https://www.osc.gov.sg/newsroom/the-online-safety-commission-begins-operations-on-29-june-2026/","tentative":false,"review":"verified"}]},{"id":"sg-pdpa","name":"Personal Data Protection Act 2012 (Singapore)","shortName":"Singapore PDPA","jurisdiction":"sg","jurisdictionName":"Singapore","region":"apac","topics":["privacy","breach-notification"],"status":"in_force","citation":"Act 26 of 2012; amended by Personal Data Protection (Amendment) Act 2020","enactedDate":"2012-10-15","effectiveDate":"2014-07-02","summary":"Singapore's baseline private-sector data protection law covering consent, purpose limitation, notification, access and correction, protection, retention, transfer limitation, and the Do Not Call registry. The 2020 amendments added mandatory breach notification, expanded deemed consent and legitimate-interests exceptions, and raised fines.","appliesTo":"All private-sector organizations collecting, using or disclosing personal data in Singapore (public agencies excluded). Breach notification: notify PDPC within 3 calendar days of assessing a breach as notifiable (significant harm, or affecting 500+ individuals).","penalties":"Financial penalties up to 10% of annual Singapore turnover for organizations with turnover above SGD 10 million, otherwise up to SGD 1 million (since 1 Oct 2022). Criminal offences for individuals who mishandle personal data.","enforcer":"Personal Data Protection Commission (PDPC)","sourceUrl":"https://www.pdpc.gov.sg/overview-of-pdpa/the-legislation/personal-data-protection-act","extraSources":["https://sso.agc.gov.sg/Act/PDPA2012"],"notes":"Dates and thresholds come from established knowledge; the PDPC overview page did not list them and sso.agc.gov.sg blocked automated fetch. The data portability obligation has been legislated but not yet brought into force. No 2025-2026 PDPA amendment was found.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-22 20:04:22","sourceType":"official","verifiedBy":"research from official sources","deadlines":[{"id":139,"regulationId":"sg-pdpa","date":"2014-07-02","title":"PDPA data protection obligations take effect","description":"Main data protection provisions come into force.","kind":"effective","sourceUrl":"https://sso.agc.gov.sg/Act/PDPA2012","tentative":false,"review":"verified"},{"id":140,"regulationId":"sg-pdpa","date":"2021-02-01","title":"2020 amendments largely in force","description":"Mandatory data breach notification and revised consent framework apply.","kind":"effective","sourceUrl":"https://sso.agc.gov.sg/Act/PDPA2012","tentative":false,"review":"verified"},{"id":141,"regulationId":"sg-pdpa","date":"2022-10-01","title":"Higher financial penalty cap applies","description":"Maximum penalty rises to 10% of Singapore turnover for organizations with turnover above SGD 10 million.","kind":"enforcement","sourceUrl":"https://sso.agc.gov.sg/Act/PDPA2012","tentative":false,"review":"verified"}]},{"id":"za-cybercrimes-act","name":"Cybercrimes Act 19 of 2020","shortName":"South Africa Cybercrimes Act","jurisdiction":"za","jurisdictionName":"South Africa","region":"mea","topics":["cybersecurity","online-safety","breach-notification"],"status":"in_force","citation":"Act 19 of 2020 (Gazette 44651)","enactedDate":"2021-06-01","effectiveDate":"2021-12-01","summary":"Creates cybercrime offences such as unlawful access, interception, interference with data and systems, cyber fraud, extortion, and malicious communications including harmful intimate images. It also sets rules for search, seizure and cross-border cooperation. The duty for electronic communications service providers and financial institutions to report cybercrime (section 54) has not yet commenced.","appliesTo":"Everyone in South Africa; electronic communications service providers and financial institutions have specific duties once section 54 commences.","penalties":"Criminal fines and prison terms set per offence, up to 15 years for the most serious offences.","enforcer":"South African Police Service, National Prosecuting Authority and the courts","sourceUrl":"https://www.gov.za/documents/cybercrimes-act-19-2020-1-jun-2021-0000","extraSources":["https://www.gov.za/sites/default/files/gcis_document/202106/44651gon324.pdf"],"notes":"enacted_date is the Gazette publication date (1 June 2021). Section 54 reporting (72 hours) has no commencement date yet.","lastVerified":"2026-09-25","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-25 11:14:17","sourceType":"official","verifiedBy":"research from official sources (2026-09-25)","deadlines":[{"id":7040,"regulationId":"za-cybercrimes-act","date":"2021-12-01","title":"Most of the Act commences","description":"Commenced by proclamation in Gazette 45562 of 30 November 2021, excluding Part VI of Chapter 2, some Chapter 4 sections and section 54.","kind":"effective","sourceUrl":"https://www.gov.za/documents/cybercrimes-act-19-2020-1-jun-2021-0000","tentative":false,"review":"verified"}]},{"id":"za-popia","name":"Protection of Personal Information Act, 2013 (Act No. 4 of 2013)","shortName":"South Africa POPIA","jurisdiction":"za","jurisdictionName":"South Africa","region":"mea","topics":["privacy","breach-notification"],"status":"in_force","citation":"Act No. 4 of 2013","enactedDate":"2013-11-19","effectiveDate":"2020-07-01","summary":"South Africa's comprehensive data protection law built on eight conditions for lawful processing, with Information Officer registration, security compromise notification to the Regulator and data subjects, and restrictions on direct marketing and cross-border transfers. Protects juristic persons as well as individuals.","appliesTo":"Responsible parties domiciled in South Africa, or not domiciled but using automated or non-automated means in South Africa.","penalties":"Administrative fines up to ZAR 10 million; criminal offences punishable by fines or imprisonment up to 10 years (e.g. obstruction, unlawful acts relating to account numbers).","enforcer":"Information Regulator (South Africa)","sourceUrl":"https://www.gov.za/documents/protection-personal-information-act","extraSources":["https://inforegulator.org.za/"],"notes":"Amendments to the POPIA Regulations were reported as gazetted in April 2025 (including electronic breach reporting via the eServices portal); exact date not verified so omitted.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-22 20:04:22","sourceType":"official","verifiedBy":"research from official sources","deadlines":[{"id":325,"regulationId":"za-popia","date":"2020-07-01","title":"Main POPIA provisions commence","description":"Most sections commence with a 12-month grace period.","kind":"effective","sourceUrl":"https://www.gov.za/documents/protection-personal-information-act","tentative":false,"review":"verified"},{"id":326,"regulationId":"za-popia","date":"2021-07-01","title":"Compliance grace period ends","description":"Responsible parties must comply; Regulator enforcement begins (grace period ended 30 June 2021).","kind":"enforcement","sourceUrl":"https://www.gov.za/documents/protection-personal-information-act","tentative":false,"review":"verified"}]},{"id":"kr-ai-basic-act","name":"Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust (AI Basic Act)","shortName":"South Korea AI Basic Act","jurisdiction":"kr","jurisdictionName":"South Korea","region":"apac","topics":["ai"],"status":"in_force","citation":"Framework Act on AI Development and Trust (promulgated Jan 2025) and its Enforcement Decree","enactedDate":"2025-01-21","effectiveDate":"2026-01-22","summary":"Korea's comprehensive AI law: transparency duties (notify users in advance that AI is used, label generative AI outputs and deepfakes), risk management, explainability and human oversight for 'high-impact' AI (e.g. hiring, lending, healthcare), safety duties for very large models (10^26 FLOPs+ training compute), and a domestic representative for large foreign providers. MSIT is running a grace period of at least one year, deferring fact-finding and fines except in serious cases.","appliesTo":"AI business operators (developers and deployers) whose activities affect the Korean market. Foreign operators without a Korean address must appoint a domestic representative if they meet any of: prior-year total revenue of KRW 1 trillion+, AI-service revenue of KRW 10 billion+, or 1 million+ average daily Korean users over the prior 3 months.","penalties":"Administrative fines up to KRW 30 million, for example for failing to notify AI use or label outputs, failing to appoint a domestic representative, or not complying with corrective orders. Fines generally deferred during the grace period of at least one year from 22 Jan 2026.","enforcer":"Ministry of Science and ICT (MSIT)","sourceUrl":"https://www.law.go.kr/법령/인공지능발전과신뢰기반조성등에관한기본법","extraSources":["https://www.trade.gov/market-intelligence/south-korea-ai-basic-act","https://www.shinkim.com/eng/media/newsletter/3117","https://www.cooley.com/news/insight/2026/2026-01-27-south-koreas-ai-basic-act-overview-and-key-takeaways"],"notes":"The grace period is 'at least one year' with no fixed end date announced, so there is no enforcement deadline row. The promulgation date (21 Jan 2025) and passage (26 Dec 2024) come from general knowledge and secondary sources; law.go.kr could not be parsed. Labeling breaches may lead to corrective orders before fines.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-22 20:04:22","sourceType":"official","verifiedBy":"research from official sources","deadlines":[{"id":124,"regulationId":"kr-ai-basic-act","date":"2026-01-22","title":"AI Basic Act and Enforcement Decree take effect","description":"Transparency, labeling, high-impact AI, and domestic representative obligations apply (fines deferred during the grace period).","kind":"effective","sourceUrl":"https://www.law.go.kr/법령/인공지능발전과신뢰기반조성등에관한기본법","tentative":false,"review":"verified"}]},{"id":"kr-pipa","name":"Personal Information Protection Act (as amended by Act No. 21445, 2026)","shortName":"South Korea PIPA","jurisdiction":"kr","jurisdictionName":"South Korea","region":"apac","topics":["privacy","breach-notification","biometrics","data-residency"],"status":"amended","citation":"Act No. 10465 (2011); latest amendment Act No. 21445 (promulgated 10 Mar 2026)","enactedDate":"2011-03-29","effectiveDate":"2011-09-30","summary":"Korea's comprehensive privacy law, with consent-centric processing, breach notification, cross-border transfer rules, automated decision rights (since 2024), and revenue-based penalty surcharges. The 2026 amendment, effective 11 September 2026, raises the maximum fine to 10% of total revenue for aggravated cases, makes the CEO the ultimate responsible person, requires notice when a breach is merely possible, and makes ISMS-P certification mandatory for certain entities from 1 July 2027.","appliesTo":"All personal information controllers (public and private) processing personal information of people in Korea; foreign controllers above set thresholds must designate a domestic representative. 10% fines apply to repeat intentional or grossly negligent violations within 3 years, intentional or grossly negligent conduct affecting 10 million+ people, or a breach after ignoring a PIPC corrective order.","penalties":"Before 11 Sept 2026: penalty surcharge up to 3% of total revenue (excluding revenue unrelated to the violation), in place since 2023. From 11 Sept 2026: up to 10% of total revenue in aggravated cases, with reductions for qualifying privacy investment. Criminal penalties also apply.","enforcer":"Personal Information Protection Commission (PIPC)","sourceUrl":"https://www.law.go.kr/법령/개인정보보호법","extraSources":["https://www.pipc.go.kr/eng/index.do","https://www.hunton.com/privacy-and-cybersecurity-law-blog/south-korea-amends-privacy-law-to-authorize-fines-of-up-to-10-of-total-revenue","https://iapp.org/news/a/south-korea-overhauls-pipa-and-ties-fines-to-ceo-accountability","https://www.yulchon.com/en/resources/publications/newsletter-view/43667/page.do"],"notes":"The National Assembly passed the amendment on 12 Feb 2026 and the PIPC announced promulgation for 10 Mar 2026 with effect from 11 Sep 2026. Fact-check 2026-09-22 confirmed on law.go.kr: 개인정보 보호법 [시행 2026. 9. 11.] [법률 제21445호, 2026. 3. 10., 일부개정]; Addendum Art 1 sets effect 6 months after promulgation, except the Art 32-2(1) proviso (mandatory certification for controllers meeting Presidential Decree criteria on revenue and processing scale) and Art 75(2)15, which apply from 1 July 2027; Art 64-2(2) sets the 10% of total revenue cap (KRW 5 billion where revenue cannot be calculated) for repeat intentional or grossly negligent violations within 3 years, violations affecting 10 million+ people, or breaches after ignoring a corrective order. The 3% pre-existing cap comes from the 2023 amendment. The 2011 enactment and effective dates come from general knowledge. The ISMS-P scope criteria are set by decree.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-22 20:04:22","sourceType":"official","verifiedBy":"research from official sources","deadlines":[{"id":125,"regulationId":"kr-pipa","date":"2026-03-10","title":"2026 PIPA amendment promulgated (Act No. 21445)","description":"Amendment raising fines to 10% of revenue and adding CEO accountability promulgated.","kind":"transition","sourceUrl":"https://www.law.go.kr/법령/개인정보보호법","tentative":false,"review":"verified"},{"id":126,"regulationId":"kr-pipa","date":"2026-09-11","title":"2026 PIPA amendments take effect","description":"10%-of-revenue fines, CEO accountability, and notice duties for possible breaches apply.","kind":"effective","sourceUrl":"https://www.law.go.kr/법령/개인정보보호법","tentative":false,"review":"verified"},{"id":127,"regulationId":"kr-pipa","date":"2027-07-01","title":"Mandatory ISMS-P certification","description":"ISMS-P certification becomes mandatory for private entities meeting the statutory criteria.","kind":"compliance","sourceUrl":"https://www.law.go.kr/법령/개인정보보호법","tentative":false,"review":"verified"}]},{"id":"ch-fadp","name":"Federal Act on Data Protection (revised FADP) of 25 September 2020","shortName":"Swiss revised FADP (nFADP)","jurisdiction":"ch","jurisdictionName":"Switzerland","region":"uk-europe","topics":["privacy","breach-notification"],"status":"in_force","citation":"SR 235.1","enactedDate":"2020-09-25","effectiveDate":"2023-09-01","summary":"Switzerland's modernised data protection law, closely aligned to GDPR: privacy by design/default, records of processing, DPIAs, breach notification to the FDPIC as soon as possible, and cross-border transfer rules. Protects only natural persons' data.","appliesTo":"Private persons and federal bodies processing personal data of natural persons, including processing abroad that has effects in Switzerland. Records-of-processing exemption for companies with fewer than 250 employees unless high-risk processing.","penalties":"Criminal fines of up to CHF 250,000 imposed on responsible individuals (not the company) for intentional breaches of key duties.","enforcer":"Federal Data Protection and Information Commissioner (FDPIC); cantonal criminal prosecution authorities","sourceUrl":"https://www.fedlex.admin.ch/eli/cc/2022/491/en","extraSources":["https://www.edoeb.admin.ch/"],"notes":"No transition period was granted.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-22 20:04:22","sourceType":"official","verifiedBy":"research from official sources","deadlines":[{"id":25,"regulationId":"ch-fadp","date":"2023-09-01","title":"Revised FADP enters into force","description":"Revised FADP and Data Protection Ordinance apply with no transition period.","kind":"effective","sourceUrl":"https://www.fedlex.admin.ch/eli/cc/2022/491/en","tentative":false,"review":"verified"}]},{"id":"us-take-it-down","name":"Tools to Address Known Exploitation by Immobilizing Technological Deepfakes on Websites and Networks Act (TAKE IT DOWN Act)","shortName":"TAKE IT DOWN Act","jurisdiction":"us","jurisdictionName":"United States (Federal)","region":"us-federal","topics":["online-safety","ai","children","privacy"],"status":"in_force","citation":"Pub. L. 119-12 (S. 146)","enactedDate":"2025-05-19","effectiveDate":"2025-05-19","summary":"Criminalizes knowingly publishing non-consensual intimate images, including AI-generated 'digital forgeries', and threats to do so. Covered platforms must set up a notice-and-removal process and remove reported content, plus known identical copies, within 48 hours of a valid request.","appliesTo":"Covered platforms: public-facing websites, online services and apps that primarily host user-generated content, or regularly publish or host non-consensual intimate imagery. Excludes broadband providers and email, among others. Criminal provisions apply to any person.","penalties":"Platform failures to comply with notice-and-removal are treated as FTC rule violations: civil penalties up to $53,088 per violation (FTC Act 5(m)(1)(A) amount as adjusted January 2025, 90 FR 5580; adjusted annually for inflation). Individuals: fines and up to 2 years' imprisonment (adults depicted) or 3 years (minors depicted); threats carry lesser terms.","enforcer":"Federal Trade Commission (platform obligations, including over non-profits); DOJ (criminal provisions)","sourceUrl":"https://www.congress.gov/bill/119th-congress/senate-bill/146","extraSources":["https://www.govinfo.gov/content/pkg/PLAW-119publ12/html/PLAW-119publ12.htm"],"notes":"Platforms get a good-faith safe harbor for removals. FTC penalty figure is the January 2025 adjustment.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-22 20:04:22","sourceType":"official","verifiedBy":"research from official sources","deadlines":[{"id":298,"regulationId":"us-take-it-down","date":"2025-05-19","title":"Criminal provisions effective on enactment","description":"Publishing or threatening to publish non-consensual intimate images, including digital forgeries, became a federal crime upon signature.","kind":"effective","sourceUrl":"https://www.govinfo.gov/content/pkg/PLAW-119publ12/html/PLAW-119publ12.htm","tentative":false,"review":"verified"},{"id":299,"regulationId":"us-take-it-down","date":"2026-05-19","title":"Platform notice-and-removal process required","description":"Covered platforms must have a clear notice-and-removal process and remove valid reported content within 48 hours (Sec. 3, one year after enactment).","kind":"compliance","sourceUrl":"https://www.govinfo.gov/content/pkg/PLAW-119publ12/html/PLAW-119publ12.htm","tentative":false,"review":"verified"}]},{"id":"us-tx-traiga","name":"Texas Responsible Artificial Intelligence Governance Act (HB 149, 89th Legislature)","shortName":"TRAIGA","jurisdiction":"us-tx","jurisdictionName":"Texas","region":"us-states","topics":["ai","biometrics"],"status":"in_force","citation":"Tex. HB 149 (89th Leg., R.S., 2025)","enactedDate":"2025-06-22","effectiveDate":"2026-01-01","summary":"Bans developing or deploying AI with the intent to incite self-harm or crime, to unlawfully discriminate against a protected class, to produce child sexual abuse material or unlawful sexual deepfakes, or to infringe constitutional rights. Government agencies must also disclose AI use and may not use it for social scoring or biometric identification without consent. Creates a Texas AI regulatory sandbox, where approved participants can test systems for up to 36 months, and a Texas AI Council. Liability generally turns on intent, not disparate impact alone.","appliesTo":"Any person who promotes, advertises or conducts business in Texas, produces a product or service used by Texas residents, or develops or deploys an AI system in Texas. Most disclosure duties fall on governmental entities. No revenue threshold.","penalties":"Civil penalties: $10,000 to $12,000 per curable violation; $80,000 to $200,000 per uncurable violation; $2,000 to $40,000 per day for continuing violations. 60-day cure period after written AG notice. No private right of action.","enforcer":"Texas Attorney General (exclusive); state licensing agencies may impose additional sanctions on licensees","sourceUrl":"https://capitol.texas.gov/BillLookup/History.aspx?LegSess=89R&Bill=HB149","extraSources":["https://capitol.texas.gov/tlodocs/89R/billtext/html/HB00149F.htm","https://iapp.org/news/a/governor-signs-texas-responsible-artificial-intelligence-governance-act","https://www.klgates.com/Pared-Back-Version-of-the-Texas-Responsible-Artificial-Intelligence-Governance-Act-Signed-Into-Law-6-24-2025"],"notes":"Penalty ranges were confirmed via secondary sources (IAPP, K&L Gates) matching the enrolled text. No 2026 amendments were found; the Texas Legislature has no regular session in 2026.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-22 20:04:22","sourceType":"official","verifiedBy":"research from official sources","deadlines":[{"id":303,"regulationId":"us-tx-traiga","date":"2025-06-22","title":"HB 149 signed","description":"Governor Abbott signs TRAIGA.","kind":"transition","sourceUrl":"https://capitol.texas.gov/BillLookup/History.aspx?LegSess=89R&Bill=HB149","tentative":false,"review":"verified"},{"id":304,"regulationId":"us-tx-traiga","date":"2026-01-01","title":"TRAIGA takes effect","description":"Prohibited-practice rules, AG enforcement, sandbox program and government AI disclosure duties apply.","kind":"effective","sourceUrl":"https://capitol.texas.gov/BillLookup/History.aspx?LegSess=89R&Bill=HB149","tentative":false,"review":"verified"}]},{"id":"tw-ai-basic-act","name":"Artificial Intelligence Basic Act","shortName":"Taiwan AI Basic Act","jurisdiction":"tw","jurisdictionName":"Taiwan","region":"apac","topics":["ai"],"status":"in_force","citation":"Presidential Order Hua-Zong-Yi-Zi No. 11500001671 (14 Jan 2026)","enactedDate":"2026-01-14","effectiveDate":"2026-01-14","summary":"Taiwan's framework law for AI. It sets seven principles (including privacy, security, transparency, fairness and accountability), names the National Science and Technology Council as the lead authority, and has the Ministry of Digital Affairs build a risk classification framework that sector regulators use for risk-based rules. High-risk AI must carry warnings, and the government must set liability and remedy rules for high-risk AI.","appliesTo":"Government agencies, which must implement it through sector rules. Private AI developers and deployers are affected through those sector rules and risk-based management standards.","penalties":"None in the Act itself. Obligations are expected to come through sector laws and rules.","enforcer":"National Science and Technology Council (lead), Ministry of Digital Affairs (risk framework), and sector regulators","sourceUrl":"https://law.moj.gov.tw/LawClass/LawAll.aspx?pcode=H0160093","extraSources":["https://law.moj.gov.tw/LawClass/LawHistory.aspx?pcode=H0160093"],"notes":"20 articles. Article 18 two-year deadline is counted from 14 Jan 2026.","lastVerified":"2026-09-25","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-25 11:14:17","sourceType":"official","verifiedBy":"research from official sources (2026-09-25)","deadlines":[{"id":6997,"regulationId":"tw-ai-basic-act","date":"2026-01-14","title":"AI Basic Act in force","description":"Promulgated and in force on the same day (art. 20).","kind":"effective","sourceUrl":"https://law.moj.gov.tw/LawClass/LawAll.aspx?pcode=H0160093","tentative":false,"review":"verified"},{"id":6998,"regulationId":"tw-ai-basic-act","date":"2028-01-14","title":"Agencies must align laws with the Act","description":"Government agencies must finish amending or adopting laws and administrative measures within 2 years of entry into force (art. 18). Date is computed from the statute.","kind":"transition","sourceUrl":"https://law.moj.gov.tw/LawClass/LawAll.aspx?pcode=H0160093","tentative":true,"review":"verified"}]},{"id":"tw-pdpa","name":"Personal Data Protection Act","shortName":"Taiwan PDPA","jurisdiction":"tw","jurisdictionName":"Taiwan","region":"apac","topics":["privacy","breach-notification"],"status":"amended","citation":"Personal Data Protection Act (as amended 11 Nov 2025)","enactedDate":"1995-08-11","effectiveDate":"2012-10-01","summary":"Taiwan's general privacy law for public and private bodies, covering collection, processing and use, special data, data subject rights, breach notice and cross-border transfer limits. The 2023 amendment raised fines and created an independent Personal Data Protection Commission. The 2025 amendment makes the PDPC the sole regulator, adds breach reporting to the PDPC, security maintenance duties and audits, but its start date is still to be set.","appliesTo":"Government agencies and non-government entities (companies, organisations and individuals) that collect, process or use personal data in Taiwan.","penalties":"Since 31 May 2023, security failures by private entities draw fines of NT$20,000 to NT$2 million, then NT$150,000 to NT$15 million for each uncured violation. Other breaches carry fines from NT$20,000 and criminal penalties for unlawful use with intent to profit.","enforcer":"Personal Data Protection Commission (Preparatory Office), with sector regulators during the transition","sourceUrl":"https://law.moj.gov.tw/LawClass/LawAll.aspx?pcode=I0050021","extraSources":["https://law.moj.gov.tw/LawClass/LawHistory.aspx?pcode=I0050021"],"notes":"The MOJ database says parts of the Act are not yet in force and the final start date is still to be set (as of the 18 Sep 2026 update). Article 51-1 of the 2025 text lets sector regulators keep supervising some private entities for up to 6 years after the PDPC is set up.","lastVerified":"2026-09-25","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-25 11:14:17","sourceType":"official","verifiedBy":"research from official sources (2026-09-25)","deadlines":[{"id":6999,"regulationId":"tw-pdpa","date":"2012-10-01","title":"2010 PDPA rewrite takes effect","description":"The 2010 full rewrite of the Act takes effect, except articles 6 and 54.","kind":"effective","sourceUrl":"https://law.moj.gov.tw/LawClass/LawHistory.aspx?pcode=I0050021","tentative":false,"review":"verified"},{"id":7000,"regulationId":"tw-pdpa","date":"2023-05-31","title":"Higher fines take effect","description":"Amended article 48 with higher fines for security failures takes effect on promulgation.","kind":"effective","sourceUrl":"https://law.moj.gov.tw/LawClass/LawHistory.aspx?pcode=I0050021","tentative":false,"review":"verified"},{"id":7001,"regulationId":"tw-pdpa","date":"2024-01-01","title":"PDPC Preparatory Office takes over","description":"The PDPC Preparatory Office takes over PDPA duties from the National Development Council.","kind":"transition","sourceUrl":"https://law.moj.gov.tw/LawClass/LawHistory.aspx?pcode=I0050021","tentative":false,"review":"verified"},{"id":7002,"regulationId":"tw-pdpa","date":"2025-11-11","title":"2025 amendment promulgated","description":"Amendment adds PDPC powers, breach reporting and security duties. Its start date will be set by the Executive Yuan and is not yet known.","kind":"transition","sourceUrl":"https://law.moj.gov.tw/LawClass/LawHistory.aspx?pcode=I0050021","tentative":true,"review":"verified"}]},{"id":"us-tn-elvis","name":"Ensuring Likeness, Voice, and Image Security Act of 2024 (ELVIS Act)","shortName":"Tennessee ELVIS Act","jurisdiction":"us-tn","jurisdictionName":"Tennessee","region":"us-states","topics":["ai","privacy","biometrics"],"status":"in_force","citation":"Pub. Ch. 588 (2024) (HB 2091/SB 2096); Tenn. Code Ann. section 47-25-1101 et seq.","enactedDate":"2024-03-26","effectiveDate":"2024-07-01","summary":"Replaces the Personal Rights Protection Act of 1984 and adds voice to the protected property right in name, photograph and likeness. It targets unauthorized AI voice clones and deepfakes, including liability for distributing tools whose primary purpose is producing unauthorized voice or likeness.","appliesTo":"Anyone commercially using, publishing or distributing an individual's name, image, likeness or voice, or tools for doing so, in Tennessee.","penalties":"Civil actions for injunctions and damages by rights holders; see statute for further remedies.","enforcer":"Private right of action (rights holders and licensees)","sourceUrl":"https://wapp.capitol.tn.gov/apps/BillInfo/Default.aspx?BillNumber=HB2091&GA=113","extraSources":[],"notes":"","lastVerified":"2026-09-25","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-25 10:55:47","sourceType":"official","verifiedBy":"research from official sources (2026-09-25)","deadlines":[{"id":6920,"regulationId":"us-tn-elvis","date":"2024-03-26","title":"Signed by Governor","description":"Became Public Chapter 588.","kind":"transition","sourceUrl":"https://wapp.capitol.tn.gov/apps/BillInfo/Default.aspx?BillNumber=HB2091&GA=113","tentative":false,"review":"verified"},{"id":6921,"regulationId":"us-tn-elvis","date":"2024-07-01","title":"Takes effect","description":"ELVIS Act provisions effective.","kind":"effective","sourceUrl":"https://wapp.capitol.tn.gov/apps/BillInfo/Default.aspx?BillNumber=HB2091&GA=113","tentative":false,"review":"verified"}]},{"id":"us-tn-tipa","name":"Tennessee Information Protection Act (HB 1181 / SB 73, 2023)","shortName":"Tennessee TIPA","jurisdiction":"us-tn","jurisdictionName":"Tennessee","region":"us-states","topics":["privacy"],"status":"in_force","citation":"Tenn. Code Ann. 47-18-3301 et seq. (Pub. Ch. 408, 2023)","enactedDate":"2023-05-24","effectiveDate":"2025-07-01","summary":"Comprehensive consumer privacy law with access, correction, deletion, portability and opt-out rights (sale, targeted ads, profiling), opt-in consent for sensitive data and data protection assessments. Controllers must keep a written privacy program that reasonably conforms to the NIST Privacy Framework, which also serves as an affirmative defense.","appliesTo":"Persons doing business in TN or targeting TN residents with annual revenue over $25 million that either control or process personal information of 175,000+ consumers in a calendar year, or control or process personal information of 25,000+ consumers and derive more than 50% of gross revenue from selling personal information. Exempts GLBA financial institutions, HIPAA entities, nonprofits, higher education, insurers and others.","penalties":"Civil penalty up to $7,500 per violation; treble damages for willful or knowing violations; injunctive relief and AG fees. 60-day cure notice required before any action; it does not sunset. No private right of action.","enforcer":"Tennessee Attorney General and Reporter (exclusive)","sourceUrl":"https://wapp.capitol.tn.gov/apps/BillInfo/Default.aspx?BillNumber=HB1181&GA=113","extraSources":[],"notes":"The Legislature's bill history records Pub. Ch. 408 signed by the Governor on May 24, 2023 (sent to the Governor May 11, 2023). The 60-day cure right is permanent, so there is no cure-sunset deadline. No amendments found through Sept 2026.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-22 20:04:22","sourceType":"official","verifiedBy":"research from official sources","deadlines":[{"id":300,"regulationId":"us-tn-tipa","date":"2025-07-01","title":"TIPA takes effect","description":"Controller and processor obligations and consumer rights under Tenn. Code Ann. 47-18-3301 et seq. apply.","kind":"effective","sourceUrl":"https://wapp.capitol.tn.gov/apps/BillInfo/Default.aspx?BillNumber=HB1181&GA=113","tentative":false,"review":"verified"}]},{"id":"us-tx-app-store","name":"Texas App Store Accountability Act (SB 2420)","shortName":"Texas App Store Accountability Act","jurisdiction":"us-tx","jurisdictionName":"Texas","region":"us-states","topics":["children","privacy","online-safety"],"status":"enacted","citation":"Acts 2025, 89th Leg., R.S. (SB 2420); Tex. Bus. & Com. Code section 121.021 et seq.","enactedDate":"2025-05-27","effectiveDate":"2026-01-01","summary":"App stores must verify user ages, link minor accounts to a parent and obtain parental consent before minors download or buy apps. Developers must use the app store's age and consent signals. A federal court has preliminarily enjoined enforcement.","appliesTo":"App store providers and app developers serving Texas users.","penalties":"Deceptive trade practice enforcement by the AG; see statute. Currently enjoined.","enforcer":"Texas Attorney General","sourceUrl":"https://capitol.texas.gov/BillLookup/History.aspx?LegSess=89R&Bill=SB2420","extraSources":["https://www.govinfo.gov/content/pkg/USCOURTS-txwd-1_25-cv-01660/pdf/USCOURTS-txwd-1_25-cv-01660-0.pdf","https://www.govinfo.gov/content/pkg/USCOURTS-txwd-1_25-cv-01660/pdf/USCOURTS-txwd-1_25-cv-01660-1.pdf"],"notes":"Appeal pending in the Fifth Circuit as of the last verified order.","lastVerified":"2026-09-25","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-25 10:55:47","sourceType":"official","verifiedBy":"research from official sources (2026-09-25)","deadlines":[{"id":6924,"regulationId":"us-tx-app-store","date":"2025-05-27","title":"Signed by Governor","description":"SB 2420 signed.","kind":"transition","sourceUrl":"https://capitol.texas.gov/BillLookup/History.aspx?LegSess=89R&Bill=SB2420","tentative":false,"review":"verified"},{"id":6925,"regulationId":"us-tx-app-store","date":"2025-12-23","title":"Preliminary injunction","description":"W.D. Tex. (CCIA v. Paxton) enjoins the AG from implementing or enforcing SB 2420 on First Amendment grounds.","kind":"enforcement","sourceUrl":"https://www.govinfo.gov/content/pkg/USCOURTS-txwd-1_25-cv-01660/pdf/USCOURTS-txwd-1_25-cv-01660-0.pdf","tentative":false,"review":"verified"},{"id":6926,"regulationId":"us-tx-app-store","date":"2026-01-01","title":"Scheduled effective date (enjoined)","description":"Statutory effective date; not enforceable while the injunction stands.","kind":"effective","sourceUrl":"https://capitol.texas.gov/BillLookup/History.aspx?LegSess=89R&Bill=SB2420","tentative":false,"review":"verified"},{"id":6927,"regulationId":"us-tx-app-store","date":"2026-05-06","title":"Stay pending appeal denied","description":"District court keeps the injunction in place during the state's appeal.","kind":"enforcement","sourceUrl":"https://www.govinfo.gov/content/pkg/USCOURTS-txwd-1_25-cv-01660/pdf/USCOURTS-txwd-1_25-cv-01660-1.pdf","tentative":false,"review":"verified"}]},{"id":"us-tx-tdpsa","name":"Texas Data Privacy and Security Act (HB 4, 2023)","shortName":"Texas TDPSA","jurisdiction":"us-tx","jurisdictionName":"Texas","region":"us-states","topics":["privacy"],"status":"in_force","citation":"Tex. Bus. & Com. Code ch. 541 (Acts 2023, 88th Leg., R.S., HB 4)","enactedDate":"2023-06-18","effectiveDate":"2024-07-01","summary":"Comprehensive consumer privacy law with access, correction, deletion, portability and opt-out rights, opt-in consent for sensitive data, data protection assessments and a universal opt-out signal requirement. Scope turns on the SBA small-business definition instead of consumer-count thresholds, so it reaches most non-small businesses.","appliesTo":"Persons conducting business in Texas or producing products/services consumed by Texas residents that process or sell personal data and are not a small business as defined by the U.S. Small Business Administration (no consumer-count threshold). Small businesses may not sell sensitive data without consent. Exempts state agencies, GLBA financial institutions, HIPAA entities, nonprofits, higher education, utilities.","penalties":"Civil penalty up to $7,500 per violation, plus injunctive relief and AG fees/expenses. Mandatory 30-day notice-and-cure period before any action; it does not sunset. No private right of action.","enforcer":"Texas Attorney General (exclusive)","sourceUrl":"https://capitol.texas.gov/BillLookup/History.aspx?LegSess=88R&Bill=HB4","extraSources":["https://statutes.capitol.texas.gov/Docs/BC/htm/BC.541.htm"],"notes":"The penalty ($7,500) and cure terms are from the enrolled statute. They were not re-read from the official statute site on Sept 22, 2026 because that site renders via JavaScript. No amendments to ch. 541 found through Sept 2026. The Texas AG has brought TDPSA enforcement actions (e.g. against Allstate/Arity, Jan 2025).","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-22 20:04:22","sourceType":"official","verifiedBy":"research from official sources","deadlines":[{"id":301,"regulationId":"us-tx-tdpsa","date":"2024-07-01","title":"TDPSA takes effect","description":"Most TDPSA obligations and consumer rights apply.","kind":"effective","sourceUrl":"https://capitol.texas.gov/BillLookup/History.aspx?LegSess=88R&Bill=HB4","tentative":false,"review":"verified"},{"id":302,"regulationId":"us-tx-tdpsa","date":"2025-01-01","title":"Universal opt-out mechanism requirement applies","description":"Controllers must honor global privacy control / universal opt-out signals (Bus. & Com. Code 541.055(e)).","kind":"compliance","sourceUrl":"https://capitol.texas.gov/BillLookup/History.aspx?LegSess=88R&Bill=HB4","tentative":false,"review":"verified"}]},{"id":"th-cybersecurity-act","name":"Cybersecurity Act B.E. 2562 (2019)","shortName":"Thailand Cybersecurity Act","jurisdiction":"th","jurisdictionName":"Thailand","region":"apac","topics":["cybersecurity","breach-notification"],"status":"in_force","citation":"Cybersecurity Act B.E. 2562 (2019)","enactedDate":"","effectiveDate":"2019-05-28","summary":"Thailand's cybersecurity framework for government agencies and critical information infrastructure (CII) operators. It creates the National Cyber Security Committee and the National Cyber Security Agency (NCSA). It also sets codes of practice and standards, incident reporting and response duties, and escalating powers for serious and critical cyber threats. The Committee issues binding standards under the Act, such as the Website Security Standard B.E. 2568.","appliesTo":"Government agencies, regulators, and public and private organisations designated as CII in Thailand.","penalties":"Criminal fines and imprisonment for non-compliance with orders and duties. Amounts were not verified here.","enforcer":"National Cyber Security Committee and National Cyber Security Agency (NCSA)","sourceUrl":"https://www.ncsa.or.th/about","extraSources":["https://www.ncsa.or.th/news/3a613ca26532320a0b000264"],"notes":"The Royal Gazette site blocks automated access, so the enactment date and penalties were not verified from the gazette. The NCSA website is a single-page app and needs a browser. The National Cyber Security Committee also issued new CII designation criteria on 2025-09-16.","lastVerified":"2026-09-25","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-25 11:14:17","sourceType":"official","verifiedBy":"research from official sources (2026-09-25)","deadlines":[{"id":7021,"regulationId":"th-cybersecurity-act","date":"2019-05-28","title":"Cybersecurity Act in force","description":"NCSA states the Act took effect on 28 May 2019.","kind":"effective","sourceUrl":"https://www.ncsa.or.th/about","tentative":false,"review":"verified"},{"id":7022,"regulationId":"th-cybersecurity-act","date":"2026-09-16","title":"Website Security Standard B.E. 2568 enforced","description":"The website security standard announced on 16 September 2025 becomes enforceable for government agencies, regulators and CII organisations.","kind":"compliance","sourceUrl":"https://www.ncsa.or.th/news/3a613ca26532320a0b000264","tentative":false,"review":"verified"}]},{"id":"th-pdpa","name":"Personal Data Protection Act B.E. 2562 (2019)","shortName":"Thailand PDPA","jurisdiction":"th","jurisdictionName":"Thailand","region":"apac","topics":["privacy","breach-notification","data-residency"],"status":"in_force","citation":"Government Gazette Vol. 136, Part 69 Kor, 27 May 2019","enactedDate":"2019-05-24","effectiveDate":"2022-06-01","summary":"Thailand's GDPR-style data protection law: lawful bases including explicit consent for sensitive data, data subject rights, DPOs for large-scale or sensitive processing, breach notification to the PDPC within 72 hours, and cross-border transfer restrictions. Main obligations applied from 1 June 2022 after two postponements.","appliesTo":"Data controllers and processors in Thailand, and those outside Thailand offering goods or services to, or monitoring the behaviour of, data subjects in Thailand.","penalties":"Administrative fines up to THB 5 million per violation; criminal penalties up to 1 year imprisonment and/or THB 1 million for some offences; civil punitive damages up to twice actual damages.","enforcer":"Personal Data Protection Committee (PDPC) and its Office","sourceUrl":"https://www.ratchakitcha.soc.go.th/DATA/PDF/2562/A/069/T_0052.PDF","extraSources":["https://www.pdpc.or.th/"],"notes":"Dates and penalty figures come from established knowledge; the official ratchakitcha and PDPC sites blocked automated fetch, so re-verification was not possible this run. The 24 May 2019 enactment date is the date of royal endorsement (the gazette was published 27 May 2019). No 2025-2026 amendment was checked (search budget exhausted).","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-22 20:04:22","sourceType":"official","verifiedBy":"research from official sources","deadlines":[{"id":142,"regulationId":"th-pdpa","date":"2022-06-01","title":"PDPA main obligations take effect","description":"Core data protection obligations and penalties apply after postponement Royal Decrees.","kind":"effective","sourceUrl":"https://www.ratchakitcha.soc.go.th/DATA/PDF/2562/A/069/T_0052.PDF","tentative":false,"review":"verified"}]},{"id":"tr-kvkk","name":"Law No. 6698 on the Protection of Personal Data (KVKK), as amended by Law No. 7499","shortName":"Turkey KVKK","jurisdiction":"tr","jurisdictionName":"Turkey","region":"uk-europe","topics":["privacy","data-residency"],"status":"amended","citation":"Law No. 6698 (OG 7 April 2016); amended by Law No. 7499 (OG 12 March 2024)","enactedDate":"2016-03-24","effectiveDate":"2016-04-07","summary":"Turkey's general data protection law. The 2024 amendments reworked sensitive-data processing and replaced the consent-first cross-border transfer rule with a GDPR-style tiered regime (adequacy, appropriate safeguards such as standard contracts that must be notified to the Authority within 5 business days, then limited derogations).","appliesTo":"All natural and legal persons processing personal data in Turkey; data controllers meeting VERBIS thresholds must register.","penalties":"Administrative fines set in Article 18 and revalued annually (amounts not verified here); under Law 7499, failure to notify standard contracts carries a separate administrative fine.","enforcer":"Personal Data Protection Authority (KVKK) / Personal Data Protection Board","sourceUrl":"https://www.resmigazete.gov.tr/eskiler/2024/03/20240312-1.htm","extraSources":["https://www.kvkk.gov.tr/"],"notes":"Dates from recollection cross-checked only against the Official Gazette issue reference; fine amounts omitted because they are revalued each year.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-22 20:04:22","sourceType":"official","verifiedBy":"research from official sources","deadlines":[{"id":143,"regulationId":"tr-kvkk","date":"2024-06-01","title":"Law 7499 amendments take effect","description":"New sensitive data and cross-border transfer rules (Arts. 6 and 9) apply.","kind":"effective","sourceUrl":"https://www.resmigazete.gov.tr/eskiler/2024/03/20240312-1.htm","tentative":false,"review":"verified"},{"id":144,"regulationId":"tr-kvkk","date":"2024-09-01","title":"Old transfer regime ends","description":"Transitional period ends in which the former Article 9 explicit-consent transfer basis could still be relied on.","kind":"transition","sourceUrl":"https://www.resmigazete.gov.tr/eskiler/2024/03/20240312-1.htm","tentative":false,"review":"verified"}]},{"id":"ae-child-digital-safety","name":"Federal Decree by Law No. 26 of 2025 Regarding Child Digital Safety","shortName":"UAE Child Digital Safety Law","jurisdiction":"ae","jurisdictionName":"United Arab Emirates","region":"mea","topics":["children","online-safety","privacy"],"status":"in_force","citation":"Federal Decree by Law No. (26) of 2025; Cabinet Resolution No. (106) of 2026","enactedDate":"2025-10-01","effectiveDate":"2026-01-01","summary":"Sets child safety duties for internet service providers and digital platforms that operate in or target the UAE, from social media and games to e-commerce. Platforms may not process personal data of children under 13 without verifiable parental consent and must use age verification and risk-based controls. A 2026 Cabinet Resolution bars social media accounts for children under 15 and restricts accounts for 15 year olds.","appliesTo":"Internet service providers and digital platforms operating in the UAE or directed at UAE users, including websites, search engines, apps, messaging, gaming, social media, live streaming, podcast, streaming and e-commerce platforms, and child caregivers.","penalties":"Administrative penalties are to be set by a Cabinet regulation (Art. 16).","enforcer":"Child Digital Safety Council, Ministry of Family and the competent authorities; TDRA for the social media age rules","sourceUrl":"https://uaelegislation.gov.ae/en/legislations/3912","extraSources":["https://uaelegislation.gov.ae/en/legislations/4506"],"notes":"The 2027 dates are computed from the one-year and 12-month periods in the texts.","lastVerified":"2026-09-25","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-25 11:14:17","sourceType":"official","verifiedBy":"research from official sources (2026-09-25)","deadlines":[{"id":7036,"regulationId":"ae-child-digital-safety","date":"2026-01-01","title":"Child Digital Safety Law takes effect","description":"Effective date shown on the official legislation portal. Published in Official Gazette No. 809 (supplement 1) on 14 October 2025.","kind":"effective","sourceUrl":"https://uaelegislation.gov.ae/en/legislations/3912","tentative":false,"review":"verified"},{"id":7037,"regulationId":"ae-child-digital-safety","date":"2026-06-30","title":"Social media minimum age resolution takes effect","description":"Cabinet Resolution No. 106 of 2026 applies from the day after publication in Official Gazette No. 826 on 29 June 2026.","kind":"effective","sourceUrl":"https://uaelegislation.gov.ae/en/legislations/4506","tentative":false,"review":"verified"},{"id":7038,"regulationId":"ae-child-digital-safety","date":"2027-01-01","title":"Compliance deadline under the Decree by Law","description":"Article 18: those covered must comply within one year from entry into force. The Cabinet may extend this.","kind":"compliance","sourceUrl":"https://uaelegislation.gov.ae/en/legislations/3912","tentative":false,"review":"verified"},{"id":7039,"regulationId":"ae-child-digital-safety","date":"2027-06-30","title":"Social media platforms' transition ends","description":"Article 8 of Cabinet Resolution No. 106 of 2026 gives platforms 12 months from entry into force to comply.","kind":"compliance","sourceUrl":"https://uaelegislation.gov.ae/en/legislations/4506","tentative":false,"review":"verified"}]},{"id":"ae-pdpl","name":"Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data","shortName":"UAE PDPL","jurisdiction":"ae","jurisdictionName":"United Arab Emirates","region":"mea","topics":["privacy","breach-notification","data-residency"],"status":"in_force","citation":"Federal Decree-Law No. 45 of 2021","enactedDate":"2021-09-20","effectiveDate":"2022-01-02","summary":"Federal GDPR-style data protection law for the onshore UAE covering consent and other bases, data subject rights, breach notification, DPOs and cross-border transfers. Key details (including fines and some thresholds) depend on Executive Regulations that have not been issued.","appliesTo":"Processing of personal data of UAE residents or by controllers/processors established in the UAE; excludes free zones with their own laws (DIFC, ADGM), government data, and health/banking data covered by sectoral laws.","penalties":"Administrative penalties to be set by Cabinet decision; not yet issued.","enforcer":"UAE Data Office","sourceUrl":"https://uaelegislation.gov.ae/en/legislations/1972","extraSources":["https://u.ae/en/about-the-uae/digital-uae/data/data-protection-laws"],"notes":"Executive Regulations still unpublished as of 2026; organisations get six months from their issuance to comply. No dated compliance deadline yet.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-22 20:04:22","sourceType":"official","verifiedBy":"research from official sources","deadlines":[{"id":1,"regulationId":"ae-pdpl","date":"2022-01-02","title":"PDPL enters into force","description":"Decree-law takes effect; compliance obligations tied to Executive Regulations.","kind":"effective","sourceUrl":"https://uaelegislation.gov.ae/en/legislations/1972","tentative":false,"review":"verified"}]},{"id":"uk-csr-bill","name":"Cyber Security and Resilience (Network and Information Systems) Bill","shortName":"UK Cyber Security and Resilience Bill","jurisdiction":"uk","jurisdictionName":"United Kingdom","region":"uk-europe","topics":["cybersecurity","breach-notification"],"status":"proposed","citation":"Bill 4035 (HL Bill, 2026 session)","enactedDate":"","effectiveDate":"","summary":"Updates the NIS Regulations 2018: brings managed service providers and data centres into scope, lets regulators designate critical suppliers, tightens incident reporting (initial notice within 24 hours, full report within 72 hours) and strengthens regulator powers. Substantive duties will follow via secondary legislation after Royal Assent.","appliesTo":"Operators of essential services and relevant digital service providers under NIS, plus (proposed) managed service providers, data centres above capacity thresholds, and designated critical suppliers.","penalties":"Proposed higher maximum penalties aligned with turnover-based fines; final figures depend on the enacted text (not verified).","enforcer":"Sector NIS competent authorities and the ICO (for digital services); DSIT policy lead","sourceUrl":"https://bills.parliament.uk/bills/4035","extraSources":["https://bills-api.parliament.uk/api/v1/Bills/4035/Stages","https://compliancehub.wiki/uk-cyber-security-resilience-bill-lords-committee-september-2026-msp-data-centre-scope/"],"notes":"Not yet law as of 2026-09-22 (in House of Lords). Royal Assent expected late 2026 or early 2027; substantive obligations expected around 2028 via secondary legislation. 24h/72h reporting timeline is from the government's published policy, not the final text.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-22 20:04:22","sourceType":"official","verifiedBy":"research from official sources","deadlines":[{"id":145,"regulationId":"uk-csr-bill","date":"2025-11-12","title":"Introduced (Commons first reading)","description":"Bill introduced in the House of Commons.","kind":"effective","sourceUrl":"https://bills.parliament.uk/bills/4035","tentative":false,"review":"verified"},{"id":146,"regulationId":"uk-csr-bill","date":"2026-06-16","title":"Passes House of Commons","description":"Report stage and third reading completed in the Commons after carry-over into the new session.","kind":"effective","sourceUrl":"https://bills.parliament.uk/bills/4035","tentative":false,"review":"verified"},{"id":147,"regulationId":"uk-csr-bill","date":"2026-10-26","title":"Lords report stage scheduled","description":"House of Lords report stage scheduled (committee stage sat 1, 3 and 7 Sept 2026).","kind":"effective","sourceUrl":"https://bills.parliament.uk/bills/4035","tentative":true,"review":"verified"}]},{"id":"uk-dpa-2018","name":"Data Protection Act 2018","shortName":"UK Data Protection Act 2018","jurisdiction":"uk","jurisdictionName":"United Kingdom","region":"uk-europe","topics":["privacy","breach-notification","children"],"status":"amended","citation":"2018 c. 12","enactedDate":"2018-05-23","effectiveDate":"2018-05-25","summary":"Core UK data protection statute that sits alongside the UK GDPR. It sets exemptions and conditions for special category and criminal offence data, the law enforcement and intelligence services regimes, and the regulator's powers and fines. It has been substantially amended by the Data (Use and Access) Act 2025.","appliesTo":"Controllers and processors processing personal data in the UK or of people in the UK, plus law enforcement and intelligence processing.","penalties":"Fines up to GBP 17.5 million or 4% of worldwide annual turnover for the most serious UK GDPR infringements; criminal offences for certain conduct.","enforcer":"Information Commissioner (Information Commission from 2026)","sourceUrl":"https://www.legislation.gov.uk/ukpga/2018/12/contents","extraSources":["https://www.legislation.gov.uk/uksi/2018/625/made"],"notes":"Tracked separately from uk-gdpr and uk-duaa. Fine maximums come from the UK GDPR as read with section 157; check before display.","lastVerified":"2026-09-25","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-25 10:55:47","sourceType":"official","verifiedBy":"research from official sources (2026-09-25)","deadlines":[{"id":6870,"regulationId":"uk-dpa-2018","date":"2018-05-23","title":"Royal Assent","description":"Data Protection Act 2018 receives Royal Assent.","kind":"effective","sourceUrl":"https://www.legislation.gov.uk/ukpga/2018/12/introduction/enacted","tentative":false,"review":"verified"},{"id":6871,"regulationId":"uk-dpa-2018","date":"2018-05-25","title":"Main provisions commence","description":"Most provisions come into force under SI 2018/625.","kind":"effective","sourceUrl":"https://www.legislation.gov.uk/uksi/2018/625/made","tentative":false,"review":"verified"},{"id":6872,"regulationId":"uk-dpa-2018","date":"2018-07-23","title":"Age appropriate design code powers commence","description":"Section 123 (age-appropriate design code) comes into force.","kind":"effective","sourceUrl":"https://www.legislation.gov.uk/uksi/2018/625/made","tentative":false,"review":"verified"}]},{"id":"uk-gdpr","name":"UK General Data Protection Regulation and Data Protection Act 2018","shortName":"UK GDPR","jurisdiction":"uk","jurisdictionName":"United Kingdom","region":"uk-europe","topics":["privacy","breach-notification"],"status":"amended","citation":"Data Protection Act 2018 c. 12; UK GDPR (retained Regulation (EU) 2016/679)","enactedDate":"2018-05-23","effectiveDate":"2018-05-25","summary":"The UK's core data protection regime: lawful bases, transparency, data subject rights, security, breach notification within 72 hours, and international transfer rules. Retained EU GDPR became the UK GDPR from 1 January 2021 and was materially amended by the Data (Use and Access) Act 2025 from 5 February 2026.","appliesTo":"Controllers and processors established in the UK, and non-UK organisations offering goods/services to, or monitoring, individuals in the UK. No revenue or volume threshold.","penalties":"Up to GBP 17.5 million or 4% of total worldwide annual turnover, whichever is higher (lower tier GBP 8.7 million or 2%). Since 5 Feb 2026, PECR fines are aligned to the same UK GDPR levels.","enforcer":"Information Commissioner's Office (becoming the Information Commission on 30 Sept 2026)","sourceUrl":"https://www.legislation.gov.uk/ukpga/2018/12/contents","extraSources":["https://www.legislation.gov.uk/eur/2016/679/contents","https://ico.org.uk/"],"notes":"See uk-duaa for the full staged commencement of the 2025 amendments. UK adequacy decision from the EU was renewed in 2025 (not separately verified here).","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-22 20:04:22","sourceType":"official","verifiedBy":"research from official sources","deadlines":[{"id":153,"regulationId":"uk-gdpr","date":"2018-05-25","title":"Data Protection Act 2018 and GDPR apply","description":"DPA 2018 and EU GDPR began applying in the UK.","kind":"effective","sourceUrl":"https://www.legislation.gov.uk/ukpga/2018/12/contents","tentative":false,"review":"verified"},{"id":154,"regulationId":"uk-gdpr","date":"2021-01-01","title":"UK GDPR takes effect after Brexit transition","description":"Retained EU GDPR becomes the UK GDPR at the end of the Brexit implementation period.","kind":"effective","sourceUrl":"https://www.legislation.gov.uk/eur/2016/679/contents","tentative":false,"review":"verified"},{"id":155,"regulationId":"uk-gdpr","date":"2026-02-05","title":"DUAA amendments to UK GDPR commence","description":"Main Data (Use and Access) Act 2025 Part 5 amendments (recognised legitimate interests, ADM, DSAR, transfers, cookies, PECR fines) apply.","kind":"effective","sourceUrl":"https://www.legislation.gov.uk/uksi/2026/82/contents/made","tentative":false,"review":"verified"}]},{"id":"uk-ipa-2024","name":"Investigatory Powers (Amendment) Act 2024","shortName":"UK Investigatory Powers (Amendment) Act 2024","jurisdiction":"uk","jurisdictionName":"United Kingdom","region":"uk-europe","topics":["privacy","data-access","cybersecurity"],"status":"enacted","citation":"2024 c. 9","enactedDate":"2024-04-25","effectiveDate":"","summary":"Amends the Investigatory Powers Act 2016. It creates a lighter regime for intelligence agencies to hold bulk personal datasets with low or no expectation of privacy, widens communications data rules, and bars telecoms operators from making relevant changes to their services that would weaken lawful access capabilities while a retention notice is under review.","appliesTo":"UK intelligence services, public authorities using investigatory powers, and telecommunications operators including overseas tech companies subject to notices.","penalties":"Enforcement of notices through civil proceedings brought by the Secretary of State.","enforcer":"Home Office; Investigatory Powers Commissioner oversees use.","sourceUrl":"https://www.legislation.gov.uk/ukpga/2024/9/contents","extraSources":[],"notes":"Provisions commence in stages by regulations; commencement dates were not individually verified, so effective_date is left empty.","lastVerified":"2026-09-25","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-25 10:55:47","sourceType":"official","verifiedBy":"research from official sources (2026-09-25)","deadlines":[{"id":6877,"regulationId":"uk-ipa-2024","date":"2024-04-25","title":"Royal Assent","description":"Investigatory Powers (Amendment) Act 2024 receives Royal Assent.","kind":"effective","sourceUrl":"https://www.legislation.gov.uk/ukpga/2024/9/introduction/enacted","tentative":false,"review":"verified"}]},{"id":"uk-osa","name":"Online Safety Act 2023","shortName":"UK Online Safety Act","jurisdiction":"uk","jurisdictionName":"United Kingdom","region":"uk-europe","topics":["online-safety","children"],"status":"in_force","citation":"2023 c. 50","enactedDate":"2023-10-26","effectiveDate":"2025-03-17","summary":"Imposes duties of care on user-to-user services and search engines to assess and mitigate illegal content risks and, where children can access the service, to protect children (including highly effective age assurance for pornography and other primary priority content). Categorised services face additional transparency, user empowerment and fraudulent advertising duties.","appliesTo":"User-to-user services, search services and pornography providers with links to the UK (significant number of UK users or UK target market), regardless of where based. Categorised (Category 1/2A/2B) services based on UK user numbers and functionality thresholds in secondary legislation. Fees payable by providers with qualifying worldwide revenue at or above the threshold set by regulations.","penalties":"Up to GBP 18 million or 10% of qualifying worldwide revenue, whichever is greater; business disruption measures and criminal liability for senior managers in some cases.","enforcer":"Ofcom","sourceUrl":"https://www.legislation.gov.uk/ukpga/2023/50/contents","extraSources":["https://www.ofcom.org.uk/online-safety/protecting-children/protection-of-children-duties-under-the-online-safety-act","https://www.ofcom.org.uk/online-safety/illegal-and-harmful-content/online-safety-fees-and-penalties","https://www.rpclegal.com/thinking/media/ofcom-publishes-register-of-categorised-services/"],"notes":"Ofcom published its register of categorised services on 10 July 2026 (per RPC and Bristows reporting; Ofcom page not fetched), with consultations on Category 1 duties open to 2 Oct 2026 and final codes expected by mid-2027. Fee notification close date (11 Apr 2026) taken from Ofcom-sourced reporting; Ofcom page returned 403 during verification.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-22 20:04:22","sourceType":"official","verifiedBy":"research from official sources","deadlines":[{"id":156,"regulationId":"uk-osa","date":"2023-10-26","title":"Royal Assent","description":"The Online Safety Act receives Royal Assent.","kind":"effective","sourceUrl":"https://www.legislation.gov.uk/ukpga/2023/50/contents","tentative":false,"review":"verified"},{"id":157,"regulationId":"uk-osa","date":"2025-03-17","title":"Illegal harms duties enforceable","description":"Illegal content safety duties apply; illegal content risk assessments had to be completed by 16 March 2025.","kind":"effective","sourceUrl":"https://www.ofcom.org.uk/online-safety/illegal-and-harmful-content","tentative":false,"review":"verified"},{"id":158,"regulationId":"uk-osa","date":"2025-04-16","title":"Children's access assessments due","description":"Services had to complete children's access assessments to determine whether children are likely to access them.","kind":"compliance","sourceUrl":"https://www.ofcom.org.uk/online-safety/protecting-children/protection-of-children-duties-under-the-online-safety-act","tentative":false,"review":"verified"},{"id":159,"regulationId":"uk-osa","date":"2025-07-25","title":"Protection of children duties apply","description":"Children's safety duties and Protection of Children Codes take effect, including highly effective age assurance; children's risk assessments due by 24 July 2025.","kind":"effective","sourceUrl":"https://www.ofcom.org.uk/online-safety/protecting-children/protection-of-children-duties-under-the-online-safety-act","tentative":false,"review":"verified"},{"id":160,"regulationId":"uk-osa","date":"2026-04-11","title":"Fee notification window closes (2026/27)","description":"Fee-liable providers must notify Ofcom before the notification window for the first charging year closes.","kind":"reporting","sourceUrl":"https://www.ofcom.org.uk/online-safety/illegal-and-harmful-content/online-safety-fees-and-penalties","tentative":false,"review":"verified"}]},{"id":"uk-psti","name":"Product Security and Telecommunications Infrastructure Act 2022 and the Product Security Regulations 2023","shortName":"UK PSTI Act (product security)","jurisdiction":"uk","jurisdictionName":"United Kingdom","region":"uk-europe","topics":["cybersecurity"],"status":"in_force","citation":"2022 c. 46; SI 2023/1007","enactedDate":"2022-12-06","effectiveDate":"2024-04-29","summary":"Sets baseline security requirements for consumer connectable products sold in the UK. Manufacturers must ban universal default passwords, publish a way to report vulnerabilities, and state the minimum security update support period. Importers and distributors share compliance duties.","appliesTo":"Manufacturers, importers and distributors of relevant connectable consumer products (smart TVs, cameras, phones, routers, wearables and similar) made available in the UK.","penalties":"Monetary penalties up to the greater of GBP 10 million or 4% of qualifying worldwide revenue, plus daily penalties; compliance, stop and recall notices.","enforcer":"Secretary of State, delegated to the Office for Product Safety and Standards (OPSS).","sourceUrl":"https://www.legislation.gov.uk/ukpga/2022/46/contents","extraSources":["https://www.legislation.gov.uk/uksi/2023/1007/made"],"notes":"Part 2 of the Act covers telecoms infrastructure (code rights) and is out of scope here.","lastVerified":"2026-09-25","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-25 10:55:47","sourceType":"official","verifiedBy":"research from official sources (2026-09-25)","deadlines":[{"id":6873,"regulationId":"uk-psti","date":"2022-12-06","title":"Royal Assent","description":"PSTI Act receives Royal Assent.","kind":"effective","sourceUrl":"https://www.legislation.gov.uk/ukpga/2022/46/introduction/enacted","tentative":false,"review":"verified"},{"id":6874,"regulationId":"uk-psti","date":"2024-04-29","title":"Product security requirements apply","description":"Security requirements regulations (SI 2023/1007) come into force.","kind":"compliance","sourceUrl":"https://www.legislation.gov.uk/uksi/2023/1007/made","tentative":false,"review":"verified"}]},{"id":"uk-telecom-security","name":"Telecommunications (Security) Act 2021 and the Electronic Communications (Security Measures) Regulations 2022","shortName":"UK Telecommunications Security Act","jurisdiction":"uk","jurisdictionName":"United Kingdom","region":"uk-europe","topics":["cybersecurity","breach-notification"],"status":"in_force","citation":"2021 c. 31; SI 2022/933","enactedDate":"2021-11-17","effectiveDate":"2022-10-01","summary":"Imposes strengthened security duties on UK public telecoms providers, backed by detailed security measures regulations and a code of practice. It also gives the government powers to restrict the use of high-risk vendors' equipment through designated vendor directions.","appliesTo":"Public electronic communications network and service providers in the UK.","penalties":"Ofcom penalties up to 10% of relevant turnover, or up to GBP 100,000 per day for continuing contraventions.","enforcer":"Ofcom; Secretary of State for designated vendor directions.","sourceUrl":"https://www.legislation.gov.uk/ukpga/2021/31/contents","extraSources":["https://www.legislation.gov.uk/uksi/2022/933/made"],"notes":"Tiered implementation timeframes for specific measures are set in the government's Telecommunications Security Code of Practice; those dates were not verified from an official page here and are left out.","lastVerified":"2026-09-25","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-25 10:55:47","sourceType":"official","verifiedBy":"research from official sources (2026-09-25)","deadlines":[{"id":6875,"regulationId":"uk-telecom-security","date":"2021-11-17","title":"Royal Assent","description":"Telecommunications (Security) Act receives Royal Assent.","kind":"effective","sourceUrl":"https://www.legislation.gov.uk/ukpga/2021/31/introduction/enacted","tentative":false,"review":"verified"},{"id":6876,"regulationId":"uk-telecom-security","date":"2022-10-01","title":"Security measures regulations in force","description":"Electronic Communications (Security Measures) Regulations 2022 come into force.","kind":"compliance","sourceUrl":"https://www.legislation.gov.uk/uksi/2022/933/made","tentative":false,"review":"verified"}]},{"id":"uy-pdpl","name":"Ley N° 18.331 de Protección de Datos Personales","shortName":"Uruguay Law 18.331","jurisdiction":"uy","jurisdictionName":"Uruguay","region":"americas","topics":["privacy","data-residency"],"status":"amended","citation":"Ley N° 18.331","enactedDate":"2008-08-11","effectiveDate":"2008-08-18","summary":"Uruguay's data protection law, which treats data protection as a human right and covers consent, purpose limits, security, sensitive data, data subject rights and international transfers. Law 19.670 of 2018 added accountability duties, regulated by Decree 64/020. Uruguay holds EU adequacy status.","appliesTo":"Personal data recorded in any medium in Uruguay, by public or private entities.","penalties":"Observation, warning, fines up to 500,000 indexed units (UI), suspension of the database for five days, or closure of the database (Art. 35).","enforcer":"Unidad Reguladora y de Control de Datos Personales (URCDP)","sourceUrl":"https://www.impo.com.uy/bases/leyes/18331-2008","extraSources":[],"notes":"effective_date uses the publication date shown by IMPO. Regulated originally by Decree 414/009 of 2009-08-31.","lastVerified":"2026-09-25","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-25 10:55:47","sourceType":"official","verifiedBy":"research from official sources (2026-09-25)","deadlines":[{"id":6950,"regulationId":"uy-pdpl","date":"2008-08-11","title":"Law promulgated","description":"Law 18.331 promulgated.","kind":"effective","sourceUrl":"https://www.impo.com.uy/bases/leyes/18331-2008","tentative":false,"review":"verified"},{"id":6951,"regulationId":"uy-pdpl","date":"2008-08-18","title":"Law published","description":"Published in Diario Oficial.","kind":"effective","sourceUrl":"https://www.impo.com.uy/bases/leyes/18331-2008","tentative":false,"review":"verified"},{"id":6952,"regulationId":"uy-pdpl","date":"2018-10-15","title":"Law 19.670 amendments","description":"Law 19.670 rewrites parts of the law, including proactive accountability duties.","kind":"transition","sourceUrl":"https://www.impo.com.uy/bases/leyes/18331-2008","tentative":false,"review":"verified"},{"id":6953,"regulationId":"uy-pdpl","date":"2020-02-17","title":"Decree 64/020","description":"Decree 64/020 regulates the Law 19.670 amendments.","kind":"compliance","sourceUrl":"https://www.impo.com.uy/bases/leyes/18331-2008","tentative":false,"review":"verified"}]},{"id":"us-ut-aipa","name":"Utah Artificial Intelligence Policy Act (SB 149, 2024), as amended by SB 226 and SB 332 (2025)","shortName":"Utah AI Policy Act","jurisdiction":"us-ut","jurisdictionName":"Utah","region":"us-states","topics":["ai"],"status":"amended","citation":"Utah Code Title 13, Ch. 72 and Ch. 75; SB 149 (2024); SB 226 (2025); SB 332 (2025); Utah Code 63I-2-213","enactedDate":"2024-03-13","effectiveDate":"2024-05-01","summary":"Makes businesses liable under Utah consumer protection law for deceptive acts committed through generative AI. Businesses must disclose generative AI use when a consumer clearly and unequivocally asks, and must disclose it proactively in high-risk interactions and regulated-occupation services. The act created the Office of Artificial Intelligence Policy and a regulatory learning lab. In 2025, SB 226 narrowed the disclosure duties and added a safe harbor, and SB 332 moved the act's repeal date to July 1, 2027.","appliesTo":"Persons using generative AI to interact with consumers in connection with activities regulated by the Utah Division of Consumer Protection, and licensed regulated occupations. No size threshold.","penalties":"Division of Consumer Protection administrative fines up to $2,500 per violation; courts may impose fines up to $2,500 per violation, and violating an administrative or court order carries a civil penalty up to $5,000 per violation.","enforcer":"Utah Division of Consumer Protection; Utah Attorney General","sourceUrl":"https://le.utah.gov/~2025/bills/static/SB0332.html","extraSources":["https://le.utah.gov/~2025/bills/static/SB0226.html","https://le.utah.gov/~2024/bills/static/SB0149.html","https://le.utah.gov/Session/2025/bills/enrolled/SB0332.pdf","https://le.utah.gov/Session/2025/bills/enrolled/SB0226.pdf"],"notes":"SB 226 and SB 332 were verified from the enrolled bill text. The SB 149 signing date (March 13, 2024) was not re-verified. Whether the 2026 Utah session changed the July 1, 2027 repeal date was not verified because the search budget ran out. HB 452 (2025, mental health chatbots) is a related Utah law not covered here.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-22 20:04:22","sourceType":"official","verifiedBy":"research from official sources","deadlines":[{"id":305,"regulationId":"us-ut-aipa","date":"2024-05-01","title":"AI Policy Act effective","description":"Generative AI disclosure duties and the Office of AI Policy take effect.","kind":"effective","sourceUrl":"https://le.utah.gov/~2024/bills/static/SB0149.html","tentative":false,"review":"verified"},{"id":306,"regulationId":"us-ut-aipa","date":"2025-05-07","title":"SB 226 amendments effective","description":"Disclosure duties narrowed (on clear request or high-risk interactions), safe harbor added, provisions recodified in Title 13, Ch. 75.","kind":"effective","sourceUrl":"https://le.utah.gov/~2025/bills/static/SB0226.html","tentative":false,"review":"verified"},{"id":307,"regulationId":"us-ut-aipa","date":"2027-07-01","title":"Scheduled repeal of Title 13, Ch. 72","description":"SB 332 extends the AI Policy Act repeal date from May 1, 2025 to July 1, 2027.","kind":"sunset","sourceUrl":"https://le.utah.gov/~2025/bills/static/SB0332.html","tentative":false,"review":"verified"}]},{"id":"us-ut-app-store","name":"Utah App Store Accountability Act (SB 142)","shortName":"Utah App Store Accountability Act","jurisdiction":"us-ut","jurisdictionName":"Utah","region":"us-states","topics":["children","privacy","online-safety"],"status":"in_force","citation":"2025 Utah Laws (S.B. 142); Utah Code section 13-75-101 et seq.","enactedDate":"","effectiveDate":"2025-05-07","summary":"App stores must verify each user's age category, obtain parental consent for minor accounts and share age and consent status with developers. Developers must check age and consent through the app store and cannot enforce contracts against minors without consent. Parents of harmed minors can sue.","appliesTo":"App store providers and app developers serving Utah users.","penalties":"Deceptive trade practice; private action for parents with the greater of actual damages or $1,000 per violation, plus fees.","enforcer":"Utah Division of Consumer Protection; private right of action","sourceUrl":"https://le.utah.gov/Session/2025/bills/enrolled/SB0142.pdf","extraSources":[],"notes":"Governor signing date not confirmed from an official page, so enacted_date is left empty.","lastVerified":"2026-09-25","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-25 10:55:47","sourceType":"official","verifiedBy":"research from official sources (2026-09-25)","deadlines":[{"id":6928,"regulationId":"us-ut-app-store","date":"2025-05-07","title":"Act takes effect","description":"Definitions and general provisions effective.","kind":"effective","sourceUrl":"https://le.utah.gov/Session/2025/bills/enrolled/SB0142.pdf","tentative":false,"review":"verified"},{"id":6929,"regulationId":"us-ut-app-store","date":"2026-05-06","title":"App store and developer duties apply","description":"Sections 13-75-201 and 13-75-202 take effect.","kind":"compliance","sourceUrl":"https://le.utah.gov/Session/2025/bills/enrolled/SB0142.pdf","tentative":false,"review":"verified"},{"id":6930,"regulationId":"us-ut-app-store","date":"2026-12-31","title":"Private right of action begins","description":"Section 13-75-401 takes effect.","kind":"enforcement","sourceUrl":"https://le.utah.gov/Session/2025/bills/enrolled/SB0142.pdf","tentative":false,"review":"verified"}]},{"id":"us-ut-ucpa","name":"Utah Consumer Privacy Act (SB 227, 2022)","shortName":"Utah UCPA","jurisdiction":"us-ut","jurisdictionName":"Utah","region":"us-states","topics":["privacy"],"status":"amended","citation":"Utah Code 13-61-101 et seq. (Laws 2022, ch. 462; amended 2025 ch. 468, 2026 ch. 193)","enactedDate":"2022-03-24","effectiveDate":"2023-12-31","summary":"Business-friendly comprehensive privacy law with access, deletion, portability and opt-out rights (targeted advertising, sale); sensitive data needs notice and a chance to opt out rather than opt-in consent, and data protection assessments are not required. A right to correct was added from July 1, 2026, and from Jan 1, 2027 the law covers motor vehicle manufacturers regardless of thresholds.","appliesTo":"Controllers or processors conducting business in Utah or targeting Utah residents with annual revenue of $25,000,000 or more that either control or process personal data of 100,000+ consumers in a calendar year, or derive over 50% of gross revenue from selling personal data and control or process data of 25,000+ consumers (13-61-102). From Jan 1, 2027, also any motor vehicle manufacturer whose vehicles are sold or leased in Utah and that collects personal data through a vehicle data collection system. Exempts government, tribes, higher education, nonprofits, HIPAA entities, GLBA, and others.","penalties":"AG may recover actual damages and up to $7,500 per violation not cured (13-61-402(3)(d)). Mandatory 30-day notice-and-cure period; it does not sunset. The Division of Consumer Protection takes complaints and refers cases to the AG. No private right of action.","enforcer":"Utah Attorney General (exclusive), on referral from the Utah Division of Consumer Protection","sourceUrl":"https://le.utah.gov/xcode/Title13/Chapter61/13-61.html","extraSources":["https://le.utah.gov/xcode/Title13/Chapter61/13-61-S102.html","https://le.utah.gov/xcode/Title13/Chapter61/13-61-S201.html","https://le.utah.gov/xcode/Title13/Chapter61/13-61-S402.html","https://www.gunster.com/newsroom/publications/2026-data-privacy-laws-state-changes-universal-opt-out-compliance"],"notes":"Amendments are identified by session-law chapter from the Utah Code version notes. The bill numbers behind 2025 ch. 468 and 2026 ch. 193 were not confirmed. Utah's separate 2025 social media data portability/interoperability law (Digital Choice Act) is reported to take effect July 2026 but sits outside the UCPA and is not included here. SB 227 signing date is March 24, 2022 per contemporaneous reporting.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-22 20:04:22","sourceType":"official","verifiedBy":"research from official sources","deadlines":[{"id":308,"regulationId":"us-ut-ucpa","date":"2023-12-31","title":"UCPA takes effect","description":"Utah Consumer Privacy Act obligations and consumer rights apply.","kind":"effective","sourceUrl":"https://le.utah.gov/xcode/Title13/Chapter61/13-61-S402.html","tentative":false,"review":"verified"},{"id":309,"regulationId":"us-ut-ucpa","date":"2026-07-01","title":"Right to correct takes effect","description":"Consumers may ask controllers to correct inaccurate personal data (13-61-201(4), as amended by Laws 2025, ch. 468).","kind":"effective","sourceUrl":"https://le.utah.gov/xcode/Title13/Chapter61/13-61-S201.html","tentative":false,"review":"verified"},{"id":310,"regulationId":"us-ut-ucpa","date":"2027-01-01","title":"UCPA extends to motor vehicle manufacturers","description":"Motor vehicle manufacturers whose vehicles are sold or leased in Utah and that collect personal data through vehicle data systems are covered regardless of the revenue and consumer thresholds (13-61-102, as amended by Laws 2026, ch. 193).","kind":"effective","sourceUrl":"https://le.utah.gov/xcode/Title13/Chapter61/13-61-S102.html","tentative":false,"review":"verified"}]},{"id":"us-vt-aadc","name":"Vermont Age-Appropriate Design Code (Act 63 of 2025, S.69)","shortName":"Vermont Kids Code","jurisdiction":"us-vt","jurisdictionName":"Vermont","region":"us-states","topics":["children","privacy","online-safety"],"status":"enacted","citation":"2025 Vt. Acts No. 63; 9 V.S.A. sections 2449a to 2449j","enactedDate":"2025-06-12","effectiveDate":"2027-01-01","summary":"Covered online businesses owe minors a minimum duty of care, must set high-privacy defaults and offer tools, and must avoid prohibited data and design practices. Age assurance data has privacy limits.","appliesTo":"Covered businesses offering online services reasonably likely to be accessed by Vermont minors.","penalties":"Enforced by the Attorney General; see 9 V.S.A. section 2449h.","enforcer":"Vermont Attorney General","sourceUrl":"https://legislature.vermont.gov/bill/status/2026/S.69","extraSources":[],"notes":"","lastVerified":"2026-09-25","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-25 10:55:47","sourceType":"official","verifiedBy":"research from official sources (2026-09-25)","deadlines":[{"id":6936,"regulationId":"us-vt-aadc","date":"2025-06-12","title":"Signed by Governor","description":"Became Act 63.","kind":"transition","sourceUrl":"https://legislature.vermont.gov/bill/status/2026/S.69","tentative":false,"review":"verified"},{"id":6937,"regulationId":"us-vt-aadc","date":"2027-01-01","title":"Takes effect","description":"9 V.S.A. sections 2449a to 2449j effective.","kind":"effective","sourceUrl":"https://legislature.vermont.gov/bill/status/2026/S.69","tentative":false,"review":"verified"}]},{"id":"us-vt-vdposa","name":"Vermont Data Privacy and Online Surveillance Act (S.71, Act 145 of 2026)","shortName":"Vermont VDPOSA","jurisdiction":"us-vt","jurisdictionName":"Vermont","region":"us-states","topics":["privacy","health","ai"],"status":"enacted","citation":"S.71, Act No. 145 (2026)","enactedDate":"2026-06-16","effectiveDate":"2028-01-01","summary":"New comprehensive privacy law with low applicability thresholds, broad consumer health data provisions that apply to all businesses, an expanded sensitive data definition, profiling and automated-decision transparency, and a disclosure requirement for using personal data to train AI models. Consumers get the usual access, correction, deletion, portability and opt-out rights.","appliesTo":"Persons conducting business in Vermont or targeting Vermont residents that in the preceding calendar year controlled or processed personal data of at least 35,000 consumers (excluding payment-only data), controlled or processed sensitive data of at least 3,000 consumers, or offered for sale personal data of at least 3,000 consumers. Consumer health data provisions apply regardless of thresholds.","penalties":"Violations are unfair and deceptive acts under the Vermont Consumer Protection Act (9 V.S.A. ch. 63): civil penalty up to $10,000 per unfair or deceptive act (9 V.S.A. 2458(b)(1)). Mandatory 60-day cure notice, where a cure is possible, from Jan 1, 2028 through June 30, 2029 (Act 145 sec. 3). No private right of action.","enforcer":"Vermont Attorney General (exclusive)","sourceUrl":"https://legislature.vermont.gov/bill/status/2026/S.71","extraSources":["https://legislature.vermont.gov/Documents/2026/Docs/ACTS/ACT145/ACT145%20As%20Enacted.pdf","https://legislature.vermont.gov/statutes/section/09/063/02458","https://www.mayerbrown.com/en/insights/publications/2026/06/vermont-enacts-comprehensive-consumer-privacy-law","https://www.hunton.com/privacy-and-cybersecurity-law-blog/vermont-becomes-23rd-state-with-comprehensive-consumer-privacy-law"],"notes":"The act has no penalty amount of its own; the $10,000 figure comes from the Vermont Consumer Protection Act's general civil penalty for unfair or deceptive acts. The AG must report annually by Dec 1 on notices of violation. Sources disagree on whether Vermont is the 23rd or 24th state with a comprehensive privacy law.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-22 20:04:22","sourceType":"official","verifiedBy":"research from official sources","deadlines":[{"id":315,"regulationId":"us-vt-vdposa","date":"2028-01-01","title":"Vermont Data Privacy and Online Surveillance Act takes effect","description":"All obligations under Act 145 apply (sec. 4).","kind":"effective","sourceUrl":"https://legislature.vermont.gov/Documents/2026/Docs/ACTS/ACT145/ACT145%20As%20Enacted.pdf","tentative":false,"review":"verified"},{"id":316,"regulationId":"us-vt-vdposa","date":"2029-06-30","title":"Mandatory 60-day cure period expires","description":"The AG's duty to issue a cure notice before enforcement ends June 30, 2029 (Act 145 sec. 3).","kind":"enforcement","sourceUrl":"https://legislature.vermont.gov/Documents/2026/Docs/ACTS/ACT145/ACT145%20As%20Enacted.pdf","tentative":false,"review":"verified"}]},{"id":"vn-ai-law","name":"Law on Artificial Intelligence (Law No. 134/2025/QH15)","shortName":"Vietnam AI Law","jurisdiction":"vn","jurisdictionName":"Vietnam","region":"apac","topics":["ai"],"status":"in_force","citation":"Law No. 134/2025/QH15","enactedDate":"2025-12-10","effectiveDate":"2026-03-01","summary":"Vietnam's first standalone AI law (35 articles). It classifies AI systems as high, medium or low risk based on their impact on life, health, rights and public order, requires human oversight, and requires disclosure when users interact with AI and labeling of AI-generated audio, image and video content. It applies to domestic and foreign actors in AI activities in Vietnam, with transition periods for existing systems.","appliesTo":"Vietnamese and foreign organizations and individuals researching, developing, providing, deploying or using AI systems in Vietnam.","penalties":"The law sets principles; administrative penalty amounts are left to implementing decrees (not verified).","enforcer":"Ministry of Science and Technology","sourceUrl":"https://beta-en.mic.gov.vn/first-ever-law-on-artificial-intelligence-approved-197251215231241888.htm","extraSources":["https://www.vilaf.com.vn/blog/vietnam-enacts-its-first-law-on-artificial-intelligence-key-regulatory-obligations-from-1-march-2026/","https://www.bakermckenzie.com/en/insight/publications/2026/02/vietnam-artificial-intelligence-law-foundation-and-outlook"],"notes":"Transition deadlines come from law-firm summaries (VILAF, Baker McKenzie), not the official text. The Law on Digital Technology Industry (No. 71/2025/QH15), which also contains AI provisions, was not verified here. The ministry page is the former MIC portal, now under the Ministry of Science and Technology.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-22 20:04:22","sourceType":"official","verifiedBy":"research from official sources","deadlines":[{"id":321,"regulationId":"vn-ai-law","date":"2026-03-01","title":"AI Law takes effect","description":"Risk classification, transparency and labeling obligations apply to new AI systems.","kind":"effective","sourceUrl":"https://beta-en.mic.gov.vn/first-ever-law-on-artificial-intelligence-approved-197251215231241888.htm","tentative":false,"review":"verified"},{"id":322,"regulationId":"vn-ai-law","date":"2027-03-01","title":"Transition ends for existing AI systems (general)","description":"Existing AI systems in most sectors must comply (12-month transition).","kind":"transition","sourceUrl":"https://www.vilaf.com.vn/blog/vietnam-enacts-its-first-law-on-artificial-intelligence-key-regulatory-obligations-from-1-march-2026/","tentative":false,"review":"verified"},{"id":323,"regulationId":"vn-ai-law","date":"2027-09-01","title":"Transition ends for existing AI systems in health, education and finance","description":"Existing AI systems in healthcare, education and finance must comply (18-month transition).","kind":"transition","sourceUrl":"https://www.vilaf.com.vn/blog/vietnam-enacts-its-first-law-on-artificial-intelligence-key-regulatory-obligations-from-1-march-2026/","tentative":false,"review":"verified"}]},{"id":"vn-cybersecurity-law","name":"Cybersecurity Law 2025 (Law No. 116/2025/QH15)","shortName":"Vietnam Cybersecurity Law 2025","jurisdiction":"vn","jurisdictionName":"Vietnam","region":"apac","topics":["cybersecurity","data-residency","online-safety"],"status":"in_force","citation":"Law No. 116/2025/QH15","enactedDate":"2025-12-10","effectiveDate":"2026-07-01","summary":"A single cybersecurity law that replaces both the Law on Network Information Security (2015) and the Cybersecurity Law (2018) from 1 July 2026. It covers cybersecurity protection, the security of information systems by classification level, cybersecurity products and services, and the duties of domestic and foreign organisations. Systems and products approved under the old laws have 12 months to meet the new requirements.","appliesTo":"Vietnamese agencies, organisations and individuals, and foreign organisations and individuals in Vietnam or directly involved in cybersecurity protection or cybersecurity products and services in Vietnam.","penalties":"Handled under administrative sanctions decrees and the Criminal Code. The Law itself does not set fine amounts.","enforcer":"Ministry of Public Security","sourceUrl":"https://vanban.chinhphu.vn/?pageid=27160&docid=216499","extraSources":["https://datafiles.chinhphu.vn/cpp/files/vbpq/2026/01/luat116-2025.pdf"],"notes":"Passed at the 10th session of the 15th National Assembly. The official PDF is a scanned image, and dates were read by OCR of Articles 44 and 45. Licences issued under the 2015 law stay valid until they expire. Ministry of Public Security as enforcer is from established knowledge, not confirmed in the fetched text.","lastVerified":"2026-09-25","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-25 11:14:17","sourceType":"official","verifiedBy":"research from official sources (2026-09-25)","deadlines":[{"id":7019,"regulationId":"vn-cybersecurity-law","date":"2026-07-01","title":"Cybersecurity Law 2025 takes effect","description":"The new law takes effect. Law 86/2015/QH13 and Law 24/2018/QH14 cease to have effect.","kind":"effective","sourceUrl":"https://vanban.chinhphu.vn/?pageid=27160&docid=216499","tentative":false,"review":"verified"},{"id":7020,"regulationId":"vn-cybersecurity-law","date":"2027-07-01","title":"Transition ends for existing systems and products","description":"Information systems classified under the 2015 law, and security products already in use, must meet the new law's conditions within 12 months of its effective date.","kind":"transition","sourceUrl":"https://vanban.chinhphu.vn/?pageid=27160&docid=216499","tentative":false,"review":"verified"}]},{"id":"vn-data-law","name":"Law on Data (Law No. 60/2024/QH15)","shortName":"Vietnam Law on Data","jurisdiction":"vn","jurisdictionName":"Vietnam","region":"apac","topics":["data-residency","data-access","cybersecurity"],"status":"in_force","citation":"Law No. 60/2024/QH15","enactedDate":"2024-11-30","effectiveDate":"2025-07-01","summary":"Vietnam's framework law for digital data. It classifies data as core, important or other, with lists of core and important data set by the Prime Minister, and requires cross-border transfer and processing of core and important data to protect national defence, security and the public interest. It also sets up the National Data Center and national database, and governs data products, data services and data exchanges.","appliesTo":"Vietnamese agencies, organisations and individuals, and foreign organisations and individuals in Vietnam or directly involved in digital data activities in Vietnam.","penalties":"Handled under implementing decrees and general administrative and criminal law. The Law itself does not set fine amounts.","enforcer":"Government of Vietnam, with the Ministry of Public Security as the lead data management body","sourceUrl":"https://vanban.chinhphu.vn/?pageid=27160&docid=212488","extraSources":["https://datafiles.chinhphu.vn/cpp/files/vbpq/2025/01/luat60.pdf"],"notes":"Passed at the 8th session of the 15th National Assembly. The Ministry of Public Security's lead role comes from the Law's state management provisions and implementing decrees; exact decree numbers are not captured here. The Cybersecurity Law 2025 amends some wording of this Law.","lastVerified":"2026-09-25","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-25 11:14:17","sourceType":"official","verifiedBy":"research from official sources (2026-09-25)","deadlines":[{"id":7018,"regulationId":"vn-data-law","date":"2025-07-01","title":"Law on Data takes effect","description":"The Law on Data enters into force.","kind":"effective","sourceUrl":"https://vanban.chinhphu.vn/?pageid=27160&docid=212488","tentative":false,"review":"verified"}]},{"id":"vn-pdpl","name":"Law on Personal Data Protection (Law No. 91/2025/QH15)","shortName":"Vietnam PDPL","jurisdiction":"vn","jurisdictionName":"Vietnam","region":"apac","topics":["privacy","data-residency","children","breach-notification"],"status":"in_force","citation":"Law No. 91/2025/QH15; implemented by Decree No. 356/2025/ND-CP","enactedDate":"2025-06-26","effectiveDate":"2026-01-01","summary":"Vietnam's first statute on personal data protection, replacing Decree 13/2023. It covers consent, data subject rights, processing and transfer impact assessments filed with the regulator, cross-border transfers, breach reporting, and bans on buying and selling personal data. Decree 356/2025 took effect alongside it and details DPIA/TIA and DPO requirements.","appliesTo":"Vietnamese and foreign agencies, organizations and individuals directly processing or involved in processing personal data of Vietnamese citizens and people in Vietnam. Household businesses and micro-enterprises are exempt from DPIA/TIA unless they provide data processing services, process sensitive data directly, or process data of large numbers of people. DPIA/TIA must be filed within 60 days of starting processing.","penalties":"Cross-border transfer violations: up to 5% of prior-year revenue. Illegal buying or selling of personal data: up to 10x the illegal proceeds (VND 3 billion cap if proceeds cannot be determined). Other violations: up to VND 3 billion for organizations. Criminal liability may apply. A separate penalty decree is still expected.","enforcer":"Ministry of Public Security (Department of Cybersecurity and High-Tech Crime Prevention, A05)","sourceUrl":"https://vanban.chinhphu.vn/?pageid=27160&docid=214590","extraSources":["https://datafiles.chinhphu.vn/cpp/files/vbpq/2025/7/91qh.signed.pdf","https://vanban.chinhphu.vn/?pageid=27160&docid=216387","https://english.luatvietnam.vn/legal-updates/the-latest-law-on-personal-data-protection-and-the-guiding-documents-892-106778-article.html","https://www.dfdl.com/insights/legal-and-tax-updates/vietnam-personal-data-protection-2026-what-foreign-organizations-need-to-know/","https://www.tilleke.com/insights/vietnams-new-personal-data-protection-law-a-closer-look/"],"notes":"source_url is the Government legal documents portal (vanban.chinhphu.vn) record for Law 91/2025/QH15: issued 26 Jun 2025 by the National Assembly (signed by Tran Thanh Man), effective 1 Jan 2026; the signed PDF is in extra_sources. The same portal lists Decree 356/2025/ND-CP as issued 31 Dec 2025, effective 1 Jan 2026. Reports of a 5-year exemption for small enterprises and startups from some duties were not verified. The implementing penalty decree was still pending as of the latest source.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-22 20:04:22","sourceType":"official","verifiedBy":"research from official sources","deadlines":[{"id":324,"regulationId":"vn-pdpl","date":"2026-01-01","title":"PDPL and Decree 356/2025 take effect","description":"Personal data protection obligations, DPIA/TIA filing and penalty framework apply; Decree 13/2023 replaced.","kind":"effective","sourceUrl":"https://vanban.chinhphu.vn/?pageid=27160&docid=214590","tentative":false,"review":"verified"}]},{"id":"us-va-vcdpa","name":"Virginia Consumer Data Protection Act (SB 1392 / HB 2307, 2021)","shortName":"Virginia VCDPA","jurisdiction":"us-va","jurisdictionName":"Virginia","region":"us-states","topics":["privacy","children","online-safety"],"status":"amended","citation":"Va. Code 59.1-575 to 59.1-585 (Acts 2021, Sp. Sess. I, ch. 35 and 36); amended 2025 (SB 854) and 2026 (SB 338)","enactedDate":"2021-03-02","effectiveDate":"2023-01-01","summary":"The second US comprehensive state privacy law: access, correction, deletion, portability and opt-out rights (targeted ads, sale, profiling), opt-in consent for sensitive data and data protection assessments. SB 854 (2025) added a 1-hour-per-day default social media limit for users under 16, effective Jan 1, 2026, but a federal court has preliminarily enjoined it. SB 338 (2026) bans selling precise geolocation data from July 1, 2026.","appliesTo":"Persons conducting business in Virginia or targeting Virginia residents that in a calendar year control or process personal data of at least 100,000 consumers, or control or process personal data of at least 25,000 consumers and derive over 50% of gross revenue from selling personal data (59.1-576). Exempts government, GLBA financial institutions, HIPAA entities, nonprofits, higher education.","penalties":"Civil penalties up to $7,500 per violation, plus injunction and AG expenses/fees (59.1-584). Mandatory 30-day notice-and-cure period; it does not sunset. No private right of action.","enforcer":"Virginia Attorney General (exclusive)","sourceUrl":"https://law.lis.virginia.gov/vacode/title59.1/chapter53/","extraSources":["https://law.lis.virginia.gov/vacode/title59.1/chapter53/section59.1-576/","https://law.lis.virginia.gov/vacode/title59.1/chapter53/section59.1-584/","https://netchoice.org/wp-content/uploads/2026/02/Virginia-PI-Opinion_Granted.pdf","https://www.hunton.com/privacy-and-cybersecurity-law-blog/virginia-bans-sale-of-geolocation-data","https://www.hunton.com/privacy-and-cybersecurity-law-blog/virginia-appeals-preliminary-injunction-barring-enforcement-of-age-based-restrictions-on-social-media-use"],"notes":"SB 338 signed by Gov. Spanberger on April 13, 2026 (per Hunton, Proskauer and Consumer Reports; the LIS bill page renders via JavaScript and could not be read). SB 854's Feb 27, 2026 injunction comes from the court opinion hosted by NetChoice; Virginia's appeal to the Fourth Circuit was pending as of the latest sources found. Treat the SB 854 obligations as unenforceable while the injunction stands.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-22 20:04:22","sourceType":"official","verifiedBy":"research from official sources","deadlines":[{"id":311,"regulationId":"us-va-vcdpa","date":"2023-01-01","title":"VCDPA takes effect","description":"VCDPA obligations and consumer rights apply.","kind":"effective","sourceUrl":"https://law.lis.virginia.gov/vacode/title59.1/chapter53/","tentative":false,"review":"verified"},{"id":312,"regulationId":"us-va-vcdpa","date":"2026-01-01","title":"Under-16 social media time limit (SB 854) takes effect","description":"Social media platforms must use commercially reasonable age determination and cap users under 16 at 1 hour/day unless a parent consents. A preliminary injunction issued Feb 27, 2026 bars enforcement.","kind":"effective","sourceUrl":"https://netchoice.org/wp-content/uploads/2026/02/Virginia-PI-Opinion_Granted.pdf","tentative":false,"review":"verified"},{"id":313,"regulationId":"us-va-vcdpa","date":"2026-02-27","title":"SB 854 preliminarily enjoined (NetChoice v. Jones)","description":"E.D. Va. preliminarily enjoined enforcement of the SB 854 social media time-limit provisions on First Amendment grounds; Virginia has appealed.","kind":"enforcement","sourceUrl":"https://netchoice.org/wp-content/uploads/2026/02/Virginia-PI-Opinion_Granted.pdf","tentative":false,"review":"verified"},{"id":314,"regulationId":"us-va-vcdpa","date":"2026-07-01","title":"Ban on selling precise geolocation data (SB 338)","description":"Controllers may not sell consumers' precise geolocation data (1,750-ft radius), replacing the prior consent-based treatment.","kind":"effective","sourceUrl":"https://lis.virginia.gov/bill-details/20261/SB338","tentative":false,"review":"verified"}]},{"id":"us-wa-mhmda","name":"Washington My Health My Data Act (HB 1155, Laws of 2023, ch. 191; RCW 19.373)","shortName":"Washington My Health My Data Act","jurisdiction":"us-wa","jurisdictionName":"Washington","region":"us-states","topics":["health","privacy"],"status":"in_force","citation":"RCW 19.373; Laws of 2023, ch. 191 (HB 1155)","enactedDate":"2023-04-27","effectiveDate":"2024-03-31","summary":"Regulated entities must publish a consumer health data privacy policy linked from their homepage and get opt-in consent to collect or share consumer health data. Selling it requires a signed authorization. Consumers get rights to access, delete and withdraw consent. Geofencing within 2,000 feet of health care facilities is banned. 'Consumer health data' is defined broadly and includes inferences from non-health data.","appliesTo":"Any legal entity that conducts business in Washington or targets Washington consumers and determines the purpose and means of processing consumer health data, with no revenue threshold. Small businesses (health data of fewer than 100,000 consumers a year, or under 50% of revenue from health data and fewer than 25,000 consumers) got a later compliance date.","penalties":"A violation is a per se violation of the Washington Consumer Protection Act: AG civil penalties up to $7,500 per violation (RCW 19.86.140). Private right of action for actual damages, with possible treble damages and attorney fees.","enforcer":"Washington Attorney General; private right of action","sourceUrl":"https://www.atg.wa.gov/protecting-washingtonians-personal-health-data-and-privacy","extraSources":["https://app.leg.wa.gov/billsummary?BillNumber=1155&Year=2023","https://app.leg.wa.gov/rcw/default.aspx?cite=19.373.010","https://app.leg.wa.gov/rcw/default.aspx?cite=19.86.140"],"notes":"The treble-damages cap for private actions (RCW 19.86.090) was not re-verified for this record.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-22 20:04:22","sourceType":"official","verifiedBy":"research from official sources","deadlines":[{"id":317,"regulationId":"us-wa-mhmda","date":"2023-04-27","title":"HB 1155 signed","description":"Governor signs My Health My Data Act.","kind":"transition","sourceUrl":"https://app.leg.wa.gov/billsummary?BillNumber=1155&Year=2023","tentative":false,"review":"verified"},{"id":318,"regulationId":"us-wa-mhmda","date":"2023-07-23","title":"Geofencing ban (Section 10) effective","description":"Ban on geofencing around health care facilities applies to all persons.","kind":"effective","sourceUrl":"https://www.atg.wa.gov/protecting-washingtonians-personal-health-data-and-privacy","tentative":false,"review":"verified"},{"id":319,"regulationId":"us-wa-mhmda","date":"2024-03-31","title":"Regulated entities must comply","description":"Sections 4-9 (privacy policy, consent, consumer rights, sale authorization) apply to regulated entities.","kind":"compliance","sourceUrl":"https://www.atg.wa.gov/protecting-washingtonians-personal-health-data-and-privacy","tentative":false,"review":"verified"},{"id":320,"regulationId":"us-wa-mhmda","date":"2024-06-30","title":"Small businesses must comply","description":"Sections 4-9 apply to small businesses.","kind":"compliance","sourceUrl":"https://www.atg.wa.gov/protecting-washingtonians-personal-health-data-and-privacy","tentative":false,"review":"verified"}]},{"id":"eu-eidas2","name":"Regulation (EU) 2024/1183 amending Regulation (EU) No 910/2014 as regards establishing the European Digital Identity Framework (eIDAS 2)","shortName":"eIDAS 2 / EU Digital Identity Wallet","jurisdiction":"eu","jurisdictionName":"European Union","region":"eu","topics":["privacy","data-access","biometrics"],"status":"enacted","citation":"OJ L, 2024/1183, 30.4.2024","enactedDate":"2024-04-11","effectiveDate":"2024-05-20","summary":"Requires every Member State to offer at least one European Digital Identity Wallet so people can identify themselves and share verified attributes with selective disclosure. It adds new qualified trust services such as electronic attestations of attributes and electronic ledgers. Private relying parties that must use strong authentication, and very large online platforms, have to accept the wallet when the user asks.","appliesTo":"Member States (wallet issuance); qualified and non-qualified trust service providers; relying parties relying on wallets, incl. private relying parties legally or contractually required to use strong user authentication (transport, energy, banking, financial services, health, telecoms and similar) and VLOPs under the DSA.","penalties":"Trust service providers: maximum of at least EUR 5M, or for legal persons EUR 5M or 1% of worldwide annual turnover, whichever is higher (Art 16 as amended). Other penalties set by Member States.","enforcer":"National supervisory bodies for trust services and wallets; European Commission","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2024/1183/oj","extraSources":["https://eur-lex.europa.eu/eli/reg_impl/2024/2977/oj"],"notes":"The 2026-12-24 and 2027-12-24 dates are computed as 24 and 36 months after the 24 Dec 2024 entry into force of the Art 5a(23)/5c(6) implementing acts (20th day after 4 Dec 2024 publication). The Commission often says 'by end of 2026' for wallets. Further implementing acts adopted in 2025 may affect specific features.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-22 20:04:22","sourceType":"official","verifiedBy":"research from official sources","deadlines":[{"id":85,"regulationId":"eu-eidas2","date":"2024-05-20","title":"eIDAS 2 enters into force","description":"Regulation (EU) 2024/1183 entered into force on the twentieth day after publication on 30 Apr 2024 (Art 2).","kind":"effective","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2024/1183/oj","tentative":false,"review":"verified"},{"id":86,"regulationId":"eu-eidas2","date":"2024-12-24","title":"First wallet implementing acts enter into force","description":"Commission Implementing Regulations (EU) 2024/2977, 2024/2979, 2024/2980, 2024/2981 and 2024/2982 (adopted 28 Nov 2024, published 4 Dec 2024) enter into force. This starts the wallet deadline clocks in Arts 5a and 5f.","kind":"effective","sourceUrl":"https://eur-lex.europa.eu/eli/reg_impl/2024/2977/oj","tentative":false,"review":"verified"},{"id":87,"regulationId":"eu-eidas2","date":"2026-05-21","title":"Legacy qualified trust service providers conformity report","description":"QTSPs qualified before 20 May 2024 had to submit a conformity assessment report proving compliance with Art 24(1), (1a) and (1b) by 21 May 2026.","kind":"compliance","sourceUrl":"https://eur-lex.europa.eu/eli/reg/2024/1183/oj","tentative":false,"review":"verified"},{"id":88,"regulationId":"eu-eidas2","date":"2026-12-24","title":"Member States must provide EU Digital Identity Wallets","description":"Each Member State must provide at least one wallet within 24 months of the entry into force of the implementing acts under Arts 5a(23) and 5c(6) (Art 5a(1)).","kind":"compliance","sourceUrl":"https://eur-lex.europa.eu/eli/reg_impl/2024/2977/oj","tentative":false,"review":"verified"},{"id":89,"regulationId":"eu-eidas2","date":"2027-12-24","title":"Private relying parties must accept wallets","description":"Private relying parties required by law or contract to use strong user authentication must accept wallets on user request within 36 months of the implementing acts' entry into force (Art 5f(2)).","kind":"compliance","sourceUrl":"https://eur-lex.europa.eu/eli/reg_impl/2024/2977/oj","tentative":false,"review":"verified"}]},{"id":"eu-eprivacy","name":"Directive 2002/58/EC concerning the processing of personal data and the protection of privacy in the electronic communications sector (ePrivacy Directive), as amended by Directive 2009/136/EC","shortName":"ePrivacy Directive (cookie law)","jurisdiction":"eu","jurisdictionName":"European Union","region":"eu","topics":["privacy","breach-notification"],"status":"amended","citation":"OJ L 201, 31.7.2002, p. 37","enactedDate":"2002-07-12","effectiveDate":"2002-07-31","summary":"Requires prior consent to store or access information on a user's device (cookies, SDKs, fingerprinting), except where strictly necessary. Also covers confidentiality of communications, traffic and location data, and unsolicited direct marketing (opt-in for email/SMS to individuals). Telecom providers must notify personal data breaches. Enforced through national laws.","appliesTo":"Any entity storing or accessing information on users' terminal equipment in the EU (websites, apps, ad tech), senders of electronic direct marketing, and providers of publicly available electronic communications services.","penalties":"Set by national transposing laws; many Member States let DPAs apply GDPR-level fines. Amounts vary by country.","enforcer":"National data protection authorities and/or telecom regulators, depending on the Member State","sourceUrl":"https://eur-lex.europa.eu/eli/dir/2002/58/oj","extraSources":["https://eur-lex.europa.eu/eli/dir/2009/136/oj","https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:52025PC0837","https://www.europarl.europa.eu/legislative-train/theme-a-new-plan-for-europe-s-sustainable-prosperity-and-competitiveness/file-digital-package"],"notes":"The proposed ePrivacy Regulation (2017) was withdrawn by the Commission in 2025. The Digital Omnibus proposal COM(2025) 837 would move consent rules for personal data on terminal equipment into the GDPR (new Art 88a/88b, incl. browser-level preference signals). As of the 1 Aug 2026 Legislative Train update it is still under negotiation, and Council drafts reportedly drop some of the cookie provisions. Status 'amended' reflects the pending amendment.","lastVerified":"2026-09-22","origin":"seed","review":"verified","updatedAt":"2026-09-26 13:37:04","foundAt":"2026-09-22 20:04:22","sourceType":"official","verifiedBy":"research from official sources","deadlines":[{"id":90,"regulationId":"eu-eprivacy","date":"2002-07-31","title":"ePrivacy Directive enters into force","description":"Entered into force on the day of publication in the OJ (Art 20).","kind":"effective","sourceUrl":"https://eur-lex.europa.eu/eli/dir/2002/58/oj","tentative":false,"review":"verified"},{"id":91,"regulationId":"eu-eprivacy","date":"2003-10-31","title":"Original transposition deadline","description":"Member States had to bring national laws into force before 31 Oct 2003 (Art 17).","kind":"transition","sourceUrl":"https://eur-lex.europa.eu/eli/dir/2002/58/oj","tentative":false,"review":"verified"},{"id":92,"regulationId":"eu-eprivacy","date":"2011-05-25","title":"Cookie consent amendment transposition deadline","description":"Directive 2009/136/EC, which changed Art 5(3) to require consent for cookies, had to be transposed by 25 May 2011.","kind":"transition","sourceUrl":"https://eur-lex.europa.eu/eli/dir/2009/136/oj","tentative":false,"review":"verified"}]},{"id":"eu-eu-kids-act","name":"EU KIDS Act","shortName":"eu-kids-act","jurisdiction":"eu","jurisdictionName":"European Union","region":"eu","topics":["children","online-safety","privacy"],"status":"proposed","citation":"","enactedDate":"","effectiveDate":"","summary":"A legislative initiative designed to restrict social media platforms' access to children within the European Union.","appliesTo":"","penalties":"","enforcer":"","sourceUrl":"https://digital-strategy.ec.europa.eu/en/news/eu-kids-act-restrict-social-media-platforms-access-children-eu","extraSources":[],"notes":"Found by the nightly agent. Not yet reviewed.","lastVerified":"2026-09-24","origin":"agent","review":"unverified","updatedAt":"2026-09-24 08:48:01","foundAt":"2026-09-24 08:48:01","sourceType":"official","verifiedBy":"","deadlines":[]}],"generatedAt":"2026-09-26T14:26:58.841Z","freshness":{"lastOk":"2026-09-25T10:47:50Z","lastAttempt":"2026-09-25T10:42:51Z","lastState":"ok","lastNote":"29 feeds read (0 did not answer), 54 relevant items, 52 new leads; 113 official hosts looked at, 23 feeds added","verified":"2026-09-25"},"growth":{"launched":"2026-09-25","added30":0,"deadlines30":0,"sources":26,"sourcesFound":20,"leads":39,"hosts":113}}