BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//fru.dev//Regulations//EN
CALSCALE:GREGORIAN
METHOD:PUBLISH
X-WR-CALNAME:Regulation deadlines (regulations.fru.dev)
X-WR-CALDESC:Compliance deadlines tracked at regulations.fru.dev
REFRESH-INTERVAL;VALUE=DURATION:P1D
X-PUBLISHED-TTL:P1D
BEGIN:VEVENT
UID:deadline-231@regulations.fru.dev
DTSTAMP:20260926T191425Z
DTSTART;VALUE=DATE:20100222
DTEND;VALUE=DATE:20100223
SUMMARY:FTC Health Breach Notification Rule: Full compliance with original 
 Rule
DESCRIPTION:Full compliance with the 2009 Health Breach Notification Rule w
 as required.\n\nFTC Health Breach Notification Rule (16 CFR Part 318)\, as
  amended 2024 (United States (Federal))\n\nSource: https://www.federalregi
 ster.gov/citation/74-FR-42962\n\nhttps://regulations.fru.dev/regulations/u
 s-ftc-hbnr
URL:https://regulations.fru.dev/regulations/us-ftc-hbnr
CATEGORIES:United States (Federal),health,privacy,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-233@regulations.fru.dev
DTSTAMP:20260926T191425Z
DTSTART;VALUE=DATE:20220110
DTEND;VALUE=DATE:20220111
SUMMARY:GLBA Safeguards Rule: 2021 Safeguards Rule amendments effective
DESCRIPTION:The amended Safeguards Rule published December 9\, 2021 took ef
 fect\, with the more detailed program elements in 314.5 deferred.\n\nFTC S
 tandards for Safeguarding Customer Information (Safeguards Rule)\, 16 CFR 
 Part 314\, under the Gramm-Leach-Bliley Act (United States (Federal))\n\nS
 ource: https://www.federalregister.gov/documents/2021/12/09/2021-25736/sta
 ndards-for-safeguarding-customer-information\n\nhttps://regulations.fru.de
 v/regulations/us-glba-safeguards
URL:https://regulations.fru.dev/regulations/us-glba-safeguards
CATEGORIES:United States (Federal),financial,cybersecurity,breach-notificat
 ion,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-234@regulations.fru.dev
DTSTAMP:20260926T191425Z
DTSTART;VALUE=DATE:20230609
DTEND;VALUE=DATE:20230610
SUMMARY:GLBA Safeguards Rule: Compliance with expanded security program ele
 ments
DESCRIPTION:Applicability of the 314.5 provisions (qualified individual\, w
 ritten risk assessment\, encryption\, MFA\, pen testing\, incident respons
 e plan\, board reporting) was delayed from December 9\, 2022 to this date.
 \n\nFTC Standards for Safeguarding Customer Information (Safeguards Rule)\
 , 16 CFR Part 314\, under the Gramm-Leach-Bliley Act (United States (Feder
 al))\n\nSource: https://www.federalregister.gov/documents/2022/11/23/2022-
 25201/standards-for-safeguarding-customer-information\n\nhttps://regulatio
 ns.fru.dev/regulations/us-glba-safeguards
URL:https://regulations.fru.dev/regulations/us-glba-safeguards
CATEGORIES:United States (Federal),financial,cybersecurity,breach-notificat
 ion,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-290@regulations.fru.dev
DTSTAMP:20260926T191425Z
DTSTART;VALUE=DATE:20231215
DTEND;VALUE=DATE:20231216
SUMMARY:SEC Cyber Disclosure Rules: Annual cybersecurity disclosures begin 
 (Item 106 / 16K)
DESCRIPTION:Required in annual reports for fiscal years ending on or after 
 this date.\n\nSEC Cybersecurity Risk Management\, Strategy\, Governance\, 
 and Incident Disclosure (Release No. 33-11216) (United States (Federal))\n
 \nSource: https://www.federalregister.gov/documents/2023/08/04/2023-16194/
 cybersecurity-risk-management-strategy-governance-and-incident-disclosure\
 n\nhttps://regulations.fru.dev/regulations/us-sec-cyber
URL:https://regulations.fru.dev/regulations/us-sec-cyber
CATEGORIES:United States (Federal),cybersecurity,breach-notification,financ
 ial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-291@regulations.fru.dev
DTSTAMP:20260926T191425Z
DTSTART;VALUE=DATE:20231218
DTEND;VALUE=DATE:20231219
SUMMARY:SEC Cyber Disclosure Rules: Form 8-K Item 1.05 incident disclosure 
 begins
DESCRIPTION:All registrants other than smaller reporting companies must fil
 e material incident disclosures from this date.\n\nSEC Cybersecurity Risk 
 Management\, Strategy\, Governance\, and Incident Disclosure (Release No. 
 33-11216) (United States (Federal))\n\nSource: https://www.federalregister
 .gov/documents/2023/08/04/2023-16194/cybersecurity-risk-management-strateg
 y-governance-and-incident-disclosure\n\nhttps://regulations.fru.dev/regula
 tions/us-sec-cyber
URL:https://regulations.fru.dev/regulations/us-sec-cyber
CATEGORIES:United States (Federal),cybersecurity,breach-notification,financ
 ial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-229@regulations.fru.dev
DTSTAMP:20260926T191425Z
DTSTART;VALUE=DATE:20240313
DTEND;VALUE=DATE:20240314
SUMMARY:FCC CPNI Breach Rule: Order effective except revised notification r
 ules
DESCRIPTION:Definitions and other parts of the order took effect\; the revi
 sed 64.2011 and 64.5111 notification requirements were delayed pending OMB
  approval.\n\nFCC Data Breach Reporting Requirements for telecommunication
 s carriers\, interconnected VoIP and TRS providers (47 CFR 64.2011\, 64.51
 11) (United States (Federal))\n\nSource: https://www.federalregister.gov/d
 ocuments/2024/02/12/2024-01667/data-breach-reporting-requirements\n\nhttps
 ://regulations.fru.dev/regulations/us-fcc-cpni-breach
URL:https://regulations.fru.dev/regulations/us-fcc-cpni-breach
CATEGORIES:United States (Federal),privacy,breach-notification,cybersecurit
 y
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-235@regulations.fru.dev
DTSTAMP:20260926T191425Z
DTSTART;VALUE=DATE:20240513
DTEND;VALUE=DATE:20240514
SUMMARY:GLBA Safeguards Rule: FTC breach notification requirement effective
DESCRIPTION:Section 314.4(j) requires notice to the FTC within 30 days of d
 iscovering a notification event involving at least 500 consumers.\n\nFTC S
 tandards for Safeguarding Customer Information (Safeguards Rule)\, 16 CFR 
 Part 314\, under the Gramm-Leach-Bliley Act (United States (Federal))\n\nS
 ource: https://www.federalregister.gov/documents/2023/11/13/2023-24412/sta
 ndards-for-safeguarding-customer-information\n\nhttps://regulations.fru.de
 v/regulations/us-glba-safeguards
URL:https://regulations.fru.dev/regulations/us-glba-safeguards
CATEGORIES:United States (Federal),financial,cybersecurity,breach-notificat
 ion,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-292@regulations.fru.dev
DTSTAMP:20260926T191425Z
DTSTART;VALUE=DATE:20240615
DTEND;VALUE=DATE:20240616
SUMMARY:SEC Cyber Disclosure Rules: Smaller reporting companies: Item 1.05 
 compliance
DESCRIPTION:Smaller reporting companies must begin complying with Form 8-K 
 Item 1.05 incident disclosure.\n\nSEC Cybersecurity Risk Management\, Stra
 tegy\, Governance\, and Incident Disclosure (Release No. 33-11216) (United
  States (Federal))\n\nSource: https://www.federalregister.gov/documents/20
 23/08/04/2023-16194/cybersecurity-risk-management-strategy-governance-and-
 incident-disclosure\n\nhttps://regulations.fru.dev/regulations/us-sec-cybe
 r
URL:https://regulations.fru.dev/regulations/us-sec-cyber
CATEGORIES:United States (Federal),cybersecurity,breach-notification,financ
 ial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-288@regulations.fru.dev
DTSTAMP:20260926T191425Z
DTSTART;VALUE=DATE:20240623
DTEND;VALUE=DATE:20240624
SUMMARY:PADFA: PADFA takes effect
DESCRIPTION:The prohibition takes effect 60 days after enactment (April 24\
 , 2024).\n\nProtecting Americans' Data from Foreign Adversaries Act of 202
 4 (United States (Federal))\n\nSource: https://www.govinfo.gov/content/pkg
 /PLAW-118publ50/html/PLAW-118publ50.htm\n\nhttps://regulations.fru.dev/reg
 ulations/us-padfa
URL:https://regulations.fru.dev/regulations/us-padfa
CATEGORIES:United States (Federal),privacy,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-236@regulations.fru.dev
DTSTAMP:20260926T191425Z
DTSTART;VALUE=DATE:20240625
DTEND;VALUE=DATE:20240626
SUMMARY:HIPAA: Reproductive health care privacy rule effective (later vacat
 ed)
DESCRIPTION:The HIPAA Privacy Rule to Support Reproductive Health Care Priv
 acy (89 FR 32976) took effect\; it was vacated nationwide on June 18\, 202
 5 in Purl v. HHS (N.D. Tex.).\n\nHIPAA Privacy\, Security and Breach Notif
 ication Rules (45 CFR Parts 160 and 164) (United States (Federal))\n\nSour
 ce: https://www.federalregister.gov/documents/2024/04/26/2024-08503/hipaa-
 privacy-rule-to-support-reproductive-health-care-privacy\n\nhttps://regula
 tions.fru.dev/regulations/us-hipaa
URL:https://regulations.fru.dev/regulations/us-hipaa
CATEGORIES:United States (Federal),privacy,health,cybersecurity,breach-noti
 fication
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-193@regulations.fru.dev
DTSTAMP:20260926T191425Z
DTSTART;VALUE=DATE:20240703
DTEND;VALUE=DATE:20240704
SUMMARY:CIRCIA: NPRM comment period closed
DESCRIPTION:Extended comment period on the CIRCIA proposed rule closed.\n\n
 Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA) 
 and proposed implementing rule (6 CFR Part 226) (United States (Federal))\
 n\nSource: https://www.federalregister.gov/documents/2024/04/04/2024-06526
 /cyber-incident-reporting-for-critical-infrastructure-act-circia-reporting
 -requirements\n\nhttps://regulations.fru.dev/regulations/us-circia
URL:https://regulations.fru.dev/regulations/us-circia
CATEGORIES:United States (Federal),cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-232@regulations.fru.dev
DTSTAMP:20260926T191425Z
DTSTART;VALUE=DATE:20240729
DTEND;VALUE=DATE:20240730
SUMMARY:FTC Health Breach Notification Rule: 2024 amendments effective
DESCRIPTION:Amendments clarifying health app coverage\, unauthorized disclo
 sure as breach\, email notice and FTC notice timing took effect.\n\nFTC He
 alth Breach Notification Rule (16 CFR Part 318)\, as amended 2024 (United 
 States (Federal))\n\nSource: https://www.federalregister.gov/documents/202
 4/05/30/2024-10855/health-breach-notification-rule\n\nhttps://regulations.
 fru.dev/regulations/us-ftc-hbnr
URL:https://regulations.fru.dev/regulations/us-ftc-hbnr
CATEGORIES:United States (Federal),health,privacy,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-295@regulations.fru.dev
DTSTAMP:20260926T191425Z
DTSTART;VALUE=DATE:20240802
DTEND;VALUE=DATE:20240803
SUMMARY:SEC Regulation S-P: Amendments effective
DESCRIPTION:The Regulation S-P amendments became effective\; compliance tie
 red by entity size.\n\nRegulation S-P: Privacy of Consumer Financial Infor
 mation and Safeguarding Customer Information (2024 amendments) (United Sta
 tes (Federal))\n\nSource: https://www.federalregister.gov/documents/2024/0
 6/03/2024-11116/regulation-s-p-privacy-of-consumer-financial-information-a
 nd-safeguarding-customer-information\n\nhttps://regulations.fru.dev/regula
 tions/us-sec-reg-sp
URL:https://regulations.fru.dev/regulations/us-sec-reg-sp
CATEGORIES:United States (Federal),financial,privacy,cybersecurity,breach-n
 otification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-293@regulations.fru.dev
DTSTAMP:20260926T191425Z
DTSTART;VALUE=DATE:20241215
DTEND;VALUE=DATE:20241216
SUMMARY:SEC Cyber Disclosure Rules: Inline XBRL tagging of annual cybersecu
 rity disclosures
DESCRIPTION:Item 106 / Item 16K disclosures must be tagged in Inline XBRL f
 or fiscal years ending on or after this date.\n\nSEC Cybersecurity Risk Ma
 nagement\, Strategy\, Governance\, and Incident Disclosure (Release No. 33
 -11216) (United States (Federal))\n\nSource: https://www.federalregister.g
 ov/documents/2023/08/04/2023-16194/cybersecurity-risk-management-strategy-
 governance-and-incident-disclosure\n\nhttps://regulations.fru.dev/regulati
 ons/us-sec-cyber
URL:https://regulations.fru.dev/regulations/us-sec-cyber
CATEGORIES:United States (Federal),cybersecurity,breach-notification,financ
 ial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-194@regulations.fru.dev
DTSTAMP:20260926T191425Z
DTSTART;VALUE=DATE:20241216
DTEND;VALUE=DATE:20241217
SUMMARY:CMMC 2.0: CMMC Program rule (32 CFR Part 170) effective
DESCRIPTION:The program rule establishing CMMC levels and assessment proces
 ses took effect\; contract enforcement awaited the DFARS rule.\n\nCybersec
 urity Maturity Model Certification (CMMC) Program (32 CFR Part 170) and DF
 ARS acquisition rule (48 CFR Parts 204\, 212\, 217\, 252) (United States (
 Federal))\n\nSource: https://www.federalregister.gov/documents/2024/10/15/
 2024-22905/cybersecurity-maturity-model-certification-cmmc-program\n\nhttp
 s://regulations.fru.dev/regulations/us-cmmc
URL:https://regulations.fru.dev/regulations/us-cmmc
CATEGORIES:United States (Federal),cybersecurity
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-294@regulations.fru.dev
DTSTAMP:20260926T191425Z
DTSTART;VALUE=DATE:20241218
DTEND;VALUE=DATE:20241219
SUMMARY:SEC Cyber Disclosure Rules: Inline XBRL tagging of Item 1.05 disclo
 sures
DESCRIPTION:Form 8-K Item 1.05 and Form 6-K incident disclosures must be ta
 gged in Inline XBRL.\n\nSEC Cybersecurity Risk Management\, Strategy\, Gov
 ernance\, and Incident Disclosure (Release No. 33-11216) (United States (F
 ederal))\n\nSource: https://www.federalregister.gov/documents/2023/08/04/2
 023-16194/cybersecurity-risk-management-strategy-governance-and-incident-d
 isclosure\n\nhttps://regulations.fru.dev/regulations/us-sec-cyber
URL:https://regulations.fru.dev/regulations/us-sec-cyber
CATEGORIES:United States (Federal),cybersecurity,breach-notification,financ
 ial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-237@regulations.fru.dev
DTSTAMP:20260926T191425Z
DTSTART;VALUE=DATE:20241223
DTEND;VALUE=DATE:20241224
SUMMARY:HIPAA: Reproductive health privacy compliance date (vacated)
DESCRIPTION:Original compliance date for the reproductive health care priva
 cy provisions\, including the attestation requirement\; these provisions n
 o longer apply after the June 2025 vacatur.\n\nHIPAA Privacy\, Security an
 d Breach Notification Rules (45 CFR Parts 160 and 164) (United States (Fed
 eral))\n\nSource: https://www.federalregister.gov/documents/2024/04/26/202
 4-08503/hipaa-privacy-rule-to-support-reproductive-health-care-privacy\n\n
 https://regulations.fru.dev/regulations/us-hipaa
URL:https://regulations.fru.dev/regulations/us-hipaa
CATEGORIES:United States (Federal),privacy,health,cybersecurity,breach-noti
 fication
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6890@regulations.fru.dev
DTSTAMP:20260926T191425Z
DTSTART;VALUE=DATE:20250106
DTEND;VALUE=DATE:20250107
SUMMARY:HIPAA Security Rule update (NPRM): NPRM published
DESCRIPTION:Proposed Security Rule changes published in the Federal Registe
 r.\n\nHIPAA Security Rule To Strengthen the Cybersecurity of Electronic Pr
 otected Health Information (proposed rule) (United States)\n\nSource: http
 s://www.federalregister.gov/documents/2025/01/06/2024-30983/hipaa-security
 -rule-to-strengthen-the-cybersecurity-of-electronic-protected-health-infor
 mation\n\nhttps://regulations.fru.dev/regulations/us-hhs-hipaa-security-np
 rm
URL:https://regulations.fru.dev/regulations/us-hhs-hipaa-security-nprm
CATEGORIES:United States,health,cybersecurity,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6880@regulations.fru.dev
DTSTAMP:20260926T191425Z
DTSTART;VALUE=DATE:20250117
DTEND;VALUE=DATE:20250118
SUMMARY:CFPB Open Banking Rule (Section 1033): Final rule effective
DESCRIPTION:Rule published 2024-11-18 takes effect.\n\nRequired Rulemaking 
 on Personal Financial Data Rights (12 CFR Part 1033) (United States)\n\nSo
 urce: https://www.federalregister.gov/documents/2024/11/18/2024-25079/requ
 ired-rulemaking-on-personal-financial-data-rights\n\nhttps://regulations.f
 ru.dev/regulations/us-cfpb-1033
URL:https://regulations.fru.dev/regulations/us-cfpb-1033
CATEGORIES:United States,data-access,financial,privacy,cybersecurity
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-238@regulations.fru.dev
DTSTAMP:20260926T191425Z
DTSTART;VALUE=DATE:20250307
DTEND;VALUE=DATE:20250308
SUMMARY:HIPAA: Security Rule NPRM comment period closed
DESCRIPTION:Comments closed on the proposed HIPAA Security Rule update (90 
 FR 898)\; OCR has not issued a final rule.\n\nHIPAA Privacy\, Security and
  Breach Notification Rules (45 CFR Parts 160 and 164) (United States (Fede
 ral))\n\nSource: https://www.federalregister.gov/documents/2025/01/06/2024
 -30983/hipaa-security-rule-to-strengthen-the-cybersecurity-of-electronic-p
 rotected-health-information\n\nhttps://regulations.fru.dev/regulations/us-
 hipaa
URL:https://regulations.fru.dev/regulations/us-hipaa
CATEGORIES:United States (Federal),privacy,health,cybersecurity,breach-noti
 fication
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6891@regulations.fru.dev
DTSTAMP:20260926T191425Z
DTSTART;VALUE=DATE:20250307
DTEND;VALUE=DATE:20250308
SUMMARY:HIPAA Security Rule update (NPRM): Comment period closes
DESCRIPTION:Public comments on the NPRM due.\n\nHIPAA Security Rule To Stre
 ngthen the Cybersecurity of Electronic Protected Health Information (propo
 sed rule) (United States)\n\nSource: https://www.federalregister.gov/docum
 ents/2025/01/06/2024-30983/hipaa-security-rule-to-strengthen-the-cybersecu
 rity-of-electronic-protected-health-information\n\nhttps://regulations.fru
 .dev/regulations/us-hhs-hipaa-security-nprm
URL:https://regulations.fru.dev/regulations/us-hhs-hipaa-security-nprm
CATEGORIES:United States,health,cybersecurity,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-227@regulations.fru.dev
DTSTAMP:20260926T191425Z
DTSTART;VALUE=DATE:20250408
DTEND;VALUE=DATE:20250409
SUMMARY:DOJ Bulk Data Rule: Prohibitions and restrictions take effect
DESCRIPTION:Core prohibitions on covered data transactions and security req
 uirements for restricted transactions apply.\n\nPreventing Access to U.S. 
 Sensitive Personal Data and Government-Related Data by Countries of Concer
 n or Covered Persons (28 CFR Part 202) - DOJ Data Security Program (United
  States (Federal))\n\nSource: https://www.federalregister.gov/documents/20
 25/01/08/2024-31486/preventing-access-to-us-sensitive-personal-data-and-go
 vernment-related-data-by-countries-of-concern\n\nhttps://regulations.fru.d
 ev/regulations/us-doj-bulk-data
URL:https://regulations.fru.dev/regulations/us-doj-bulk-data
CATEGORIES:United States (Federal),privacy,data-residency,cybersecurity,bio
 metrics,health,financial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-298@regulations.fru.dev
DTSTAMP:20260926T191425Z
DTSTART;VALUE=DATE:20250519
DTEND;VALUE=DATE:20250520
SUMMARY:TAKE IT DOWN Act: Criminal provisions effective on enactment
DESCRIPTION:Publishing or threatening to publish non-consensual intimate im
 ages\, including digital forgeries\, became a federal crime upon signature
 .\n\nTools to Address Known Exploitation by Immobilizing Technological Dee
 pfakes on Websites and Networks Act (TAKE IT DOWN Act) (United States (Fed
 eral))\n\nSource: https://www.govinfo.gov/content/pkg/PLAW-119publ12/html/
 PLAW-119publ12.htm\n\nhttps://regulations.fru.dev/regulations/us-take-it-d
 own
URL:https://regulations.fru.dev/regulations/us-take-it-down
CATEGORIES:United States (Federal),online-safety,ai,children,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-213@regulations.fru.dev
DTSTAMP:20260926T191425Z
DTSTART;VALUE=DATE:20250623
DTEND;VALUE=DATE:20250624
SUMMARY:COPPA Rule: Amended COPPA Rule takes effect
DESCRIPTION:The April 2025 amendments to 16 CFR Part 312 became effective\;
  during the transition operators could comply with either the pre-2025 or 
 the amended Rule.\n\nChildren's Online Privacy Protection Rule (16 CFR Par
 t 312)\, as amended April 2025 (United States (Federal))\n\nSource: https:
 //www.federalregister.gov/documents/2025/04/22/2025-05904/childrens-online
 -privacy-protection-rule\n\nhttps://regulations.fru.dev/regulations/us-cop
 pa
URL:https://regulations.fru.dev/regulations/us-coppa
CATEGORIES:United States (Federal),privacy,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6881@regulations.fru.dev
DTSTAMP:20260926T191425Z
DTSTART;VALUE=DATE:20250729
DTEND;VALUE=DATE:20250730
SUMMARY:CFPB Open Banking Rule (Section 1033): Court stays Forcht Bank liti
 gation
DESCRIPTION:E.D. Ky. stays the industry challenge after the CFPB says it wi
 ll reconsider the rule\; compliance dates stayed by 90 days.\n\nRequired R
 ulemaking on Personal Financial Data Rights (12 CFR Part 1033) (United Sta
 tes)\n\nSource: https://www.federalregister.gov/documents/2025/08/22/2025-
 16139/personal-financial-data-rights-reconsideration\n\nhttps://regulation
 s.fru.dev/regulations/us-cfpb-1033
URL:https://regulations.fru.dev/regulations/us-cfpb-1033
CATEGORIES:United States,data-access,financial,privacy,cybersecurity
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6882@regulations.fru.dev
DTSTAMP:20260926T191425Z
DTSTART;VALUE=DATE:20250822
DTEND;VALUE=DATE:20250823
SUMMARY:CFPB Open Banking Rule (Section 1033): Reconsideration ANPR publish
 ed
DESCRIPTION:CFPB seeks comment on representatives\, fees\, data security an
 d privacy\, and on extending compliance dates.\n\nRequired Rulemaking on P
 ersonal Financial Data Rights (12 CFR Part 1033) (United States)\n\nSource
 : https://www.federalregister.gov/documents/2025/08/22/2025-16139/personal
 -financial-data-rights-reconsideration\n\nhttps://regulations.fru.dev/regu
 lations/us-cfpb-1033
URL:https://regulations.fru.dev/regulations/us-cfpb-1033
CATEGORIES:United States,data-access,financial,privacy,cybersecurity
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-228@regulations.fru.dev
DTSTAMP:20260926T191425Z
DTSTART;VALUE=DATE:20251006
DTEND;VALUE=DATE:20251007
SUMMARY:DOJ Bulk Data Rule: Due diligence\, audit and reporting obligations
  apply
DESCRIPTION:Subpart J (data compliance program\, due diligence and audits f
 or restricted transactions) and reporting requirements in 202.1103 and 202
 .1104 apply.\n\nPreventing Access to U.S. Sensitive Personal Data and Gove
 rnment-Related Data by Countries of Concern or Covered Persons (28 CFR Par
 t 202) - DOJ Data Security Program (United States (Federal))\n\nSource: ht
 tps://www.federalregister.gov/documents/2025/01/08/2024-31486/preventing-a
 ccess-to-us-sensitive-personal-data-and-government-related-data-by-countri
 es-of-concern\n\nhttps://regulations.fru.dev/regulations/us-doj-bulk-data
URL:https://regulations.fru.dev/regulations/us-doj-bulk-data
CATEGORIES:United States (Federal),privacy,data-residency,cybersecurity,bio
 metrics,health,financial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6883@regulations.fru.dev
DTSTAMP:20260926T191425Z
DTSTART;VALUE=DATE:20251021
DTEND;VALUE=DATE:20251022
SUMMARY:CFPB Open Banking Rule (Section 1033): Reconsideration comment peri
 od closes
DESCRIPTION:Comments on the ANPR due.\n\nRequired Rulemaking on Personal Fi
 nancial Data Rights (12 CFR Part 1033) (United States)\n\nSource: https://
 www.federalregister.gov/documents/2025/08/22/2025-16139/personal-financial
 -data-rights-reconsideration\n\nhttps://regulations.fru.dev/regulations/us
 -cfpb-1033
URL:https://regulations.fru.dev/regulations/us-cfpb-1033
CATEGORIES:United States,data-access,financial,privacy,cybersecurity
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6884@regulations.fru.dev
DTSTAMP:20260926T191425Z
DTSTART;VALUE=DATE:20251029
DTEND;VALUE=DATE:20251030
SUMMARY:CFPB Open Banking Rule (Section 1033): Court enjoins enforcement
DESCRIPTION:E.D. Ky. enjoins the CFPB from enforcing the rule until it comp
 letes its reconsideration.\n\nRequired Rulemaking on Personal Financial Da
 ta Rights (12 CFR Part 1033) (United States)\n\nSource: https://www.govinf
 o.gov/content/pkg/USCOURTS-kyed-5_24-cv-00304/pdf/USCOURTS-kyed-5_24-cv-00
 304-1.pdf\n\nhttps://regulations.fru.dev/regulations/us-cfpb-1033
URL:https://regulations.fru.dev/regulations/us-cfpb-1033
CATEGORIES:United States,data-access,financial,privacy,cybersecurity
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-195@regulations.fru.dev
DTSTAMP:20260926T191425Z
DTSTART;VALUE=DATE:20251110
DTEND;VALUE=DATE:20251111
SUMMARY:CMMC 2.0: DFARS rule effective\; Phase 1 begins
DESCRIPTION:CMMC Level 1 and Level 2 self-assessment requirements begin app
 earing in applicable DoD solicitations and contracts (32 CFR 170.3(e)(1)).
 \n\nCybersecurity Maturity Model Certification (CMMC) Program (32 CFR Part
  170) and DFARS acquisition rule (48 CFR Parts 204\, 212\, 217\, 252) (Uni
 ted States (Federal))\n\nSource: https://www.federalregister.gov/documents
 /2025/09/10/2025-17359/defense-federal-acquisition-regulation-supplement-a
 ssessing-contractor-implementation-of\n\nhttps://regulations.fru.dev/regul
 ations/us-cmmc
URL:https://regulations.fru.dev/regulations/us-cmmc
CATEGORIES:United States (Federal),cybersecurity
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-296@regulations.fru.dev
DTSTAMP:20260926T191425Z
DTSTART;VALUE=DATE:20251203
DTEND;VALUE=DATE:20251204
SUMMARY:SEC Regulation S-P: Larger entities must comply
DESCRIPTION:Larger covered institutions (18 months after Federal Register p
 ublication) must have incident response programs\, 30-day customer notific
 ation\, and service-provider oversight in place.\n\nRegulation S-P: Privac
 y of Consumer Financial Information and Safeguarding Customer Information 
 (2024 amendments) (United States (Federal))\n\nSource: https://www.federal
 register.gov/documents/2024/06/03/2024-11116/regulation-s-p-privacy-of-con
 sumer-financial-information-and-safeguarding-customer-information\n\nhttps
 ://regulations.fru.dev/regulations/us-sec-reg-sp
URL:https://regulations.fru.dev/regulations/us-sec-reg-sp
CATEGORIES:United States (Federal),financial,privacy,cybersecurity,breach-n
 otification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6892@regulations.fru.dev
DTSTAMP:20260926T191425Z
DTSTART;VALUE=DATE:20251216
DTEND;VALUE=DATE:20251217
SUMMARY:AI state-law preemption EO: EO published in Federal Register
DESCRIPTION:Signed 2025-12-11 and published at 90 FR 58499.\n\nExecutive Or
 der 14365: Ensuring a National Policy Framework for Artificial Intelligenc
 e (United States)\n\nSource: https://www.federalregister.gov/documents/202
 5/12/16/2025-23092/ensuring-a-national-policy-framework-for-artificial-int
 elligence\n\nhttps://regulations.fru.dev/regulations/us-eo-14365-ai-preemp
 tion
URL:https://regulations.fru.dev/regulations/us-eo-14365-ai-preemption
CATEGORIES:United States,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6893@regulations.fru.dev
DTSTAMP:20260926T191425Z
DTSTART;VALUE=DATE:20260110
DTEND;VALUE=DATE:20260111
SUMMARY:AI state-law preemption EO: AI Litigation Task Force due
DESCRIPTION:Attorney General to set up a task force to challenge state AI l
 aws within 30 days of the order (date computed from signing).\n\nExecutive
  Order 14365: Ensuring a National Policy Framework for Artificial Intellig
 ence (United States)\n\nSource: https://www.federalregister.gov/documents/
 2025/12/16/2025-23092/ensuring-a-national-policy-framework-for-artificial-
 intelligence\n\nhttps://regulations.fru.dev/regulations/us-eo-14365-ai-pre
 emption
URL:https://regulations.fru.dev/regulations/us-eo-14365-ai-preemption
CATEGORIES:United States,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-239@regulations.fru.dev
DTSTAMP:20260926T191425Z
DTSTART;VALUE=DATE:20260216
DTEND;VALUE=DATE:20260217
SUMMARY:HIPAA: Notice of Privacy Practices updates (Part 2 alignment)
DESCRIPTION:Covered entities must update Notices of Privacy Practices under
  45 CFR 164.520 for the 2024 Part 2 (substance use disorder records) chang
 es\; this NPP piece survived the Purl vacatur.\n\nHIPAA Privacy\, Security
  and Breach Notification Rules (45 CFR Parts 160 and 164) (United States (
 Federal))\n\nSource: https://www.federalregister.gov/documents/2024/04/26/
 2024-08503/hipaa-privacy-rule-to-support-reproductive-health-care-privacy\
 n\nhttps://regulations.fru.dev/regulations/us-hipaa
URL:https://regulations.fru.dev/regulations/us-hipaa
CATEGORIES:United States (Federal),privacy,health,cybersecurity,breach-noti
 fication
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6894@regulations.fru.dev
DTSTAMP:20260926T191425Z
DTSTART;VALUE=DATE:20260311
DTEND;VALUE=DATE:20260312
SUMMARY:AI state-law preemption EO: Commerce state-law evaluation\, BEAD no
 tice and FTC statement due
DESCRIPTION:Within 90 days of the order: Commerce publishes its list of one
 rous state AI laws\, NTIA issues the BEAD policy notice\, and the FTC issu
 es a policy statement (date computed from signing).\n\nExecutive Order 143
 65: Ensuring a National Policy Framework for Artificial Intelligence (Unit
 ed States)\n\nSource: https://www.federalregister.gov/documents/2025/12/16
 /2025-23092/ensuring-a-national-policy-framework-for-artificial-intelligen
 ce\n\nhttps://regulations.fru.dev/regulations/us-eo-14365-ai-preemption
URL:https://regulations.fru.dev/regulations/us-eo-14365-ai-preemption
CATEGORIES:United States,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-214@regulations.fru.dev
DTSTAMP:20260926T191425Z
DTSTART;VALUE=DATE:20260422
DTEND;VALUE=DATE:20260423
SUMMARY:COPPA Rule: Full compliance with amended COPPA Rule
DESCRIPTION:Operators must comply with all amended provisions (separate thi
 rd-party disclosure consent\, written retention policy\, written security 
 program\, updated notices)\; excludes Safe Harbor provisions 312.11(d)(1)\
 , (d)(4) and (g)\, which had earlier dates.\n\nChildren's Online Privacy P
 rotection Rule (16 CFR Part 312)\, as amended April 2025 (United States (F
 ederal))\n\nSource: https://www.federalregister.gov/documents/2025/04/22/2
 025-05904/childrens-online-privacy-protection-rule\n\nhttps://regulations.
 fru.dev/regulations/us-coppa
URL:https://regulations.fru.dev/regulations/us-coppa
CATEGORIES:United States (Federal),privacy,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-299@regulations.fru.dev
DTSTAMP:20260926T191425Z
DTSTART;VALUE=DATE:20260519
DTEND;VALUE=DATE:20260520
SUMMARY:TAKE IT DOWN Act: Platform notice-and-removal process required
DESCRIPTION:Covered platforms must have a clear notice-and-removal process 
 and remove valid reported content within 48 hours (Sec. 3\, one year after
  enactment).\n\nTools to Address Known Exploitation by Immobilizing Techno
 logical Deepfakes on Websites and Networks Act (TAKE IT DOWN Act) (United 
 States (Federal))\n\nSource: https://www.govinfo.gov/content/pkg/PLAW-119p
 ubl12/html/PLAW-119publ12.htm\n\nhttps://regulations.fru.dev/regulations/u
 s-take-it-down
URL:https://regulations.fru.dev/regulations/us-take-it-down
CATEGORIES:United States (Federal),online-safety,ai,children,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-297@regulations.fru.dev
DTSTAMP:20260926T191425Z
DTSTART;VALUE=DATE:20260603
DTEND;VALUE=DATE:20260604
SUMMARY:SEC Regulation S-P: Smaller entities must comply
DESCRIPTION:Smaller covered institutions (24 months after Federal Register 
 publication) must comply with the amended Regulation S-P.\n\nRegulation S-
 P: Privacy of Consumer Financial Information and Safeguarding Customer Inf
 ormation (2024 amendments) (United States (Federal))\n\nSource: https://ww
 w.federalregister.gov/documents/2024/06/03/2024-11116/regulation-s-p-priva
 cy-of-consumer-financial-information-and-safeguarding-customer-information
 \n\nhttps://regulations.fru.dev/regulations/us-sec-reg-sp
URL:https://regulations.fru.dev/regulations/us-sec-reg-sp
CATEGORIES:United States (Federal),financial,privacy,cybersecurity,breach-n
 otification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6885@regulations.fru.dev
DTSTAMP:20260926T191425Z
DTSTART;VALUE=DATE:20260630
DTEND;VALUE=DATE:20260701
SUMMARY:CFPB Open Banking Rule (Section 1033): First compliance date (staye
 d\, enjoined)
DESCRIPTION:Largest data providers (banks with $250B or more in assets\; no
 ndepositories with $10B or more in receipts). Originally 2026-04-01\, move
 d 90 days by court stay. Not enforceable while the injunction stands.\n\nT
 entative: depends on a proposal not yet adopted.\n\nRequired Rulemaking on
  Personal Financial Data Rights (12 CFR Part 1033) (United States)\n\nSour
 ce: https://www.federalregister.gov/documents/2025/08/22/2025-16139/person
 al-financial-data-rights-reconsideration\n\nhttps://regulations.fru.dev/re
 gulations/us-cfpb-1033
URL:https://regulations.fru.dev/regulations/us-cfpb-1033
CATEGORIES:United States,data-access,financial,privacy,cybersecurity
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6895@regulations.fru.dev
DTSTAMP:20260926T191425Z
DTSTART;VALUE=DATE:20260707
DTEND;VALUE=DATE:20260708
SUMMARY:AI state-law preemption EO: FTC proposes AI accuracy policy stateme
 nt
DESCRIPTION:FTC publishes a proposed policy statement on deceptive suppress
 ion of accuracy in AI systems (91 FR 41638)\, linked to Section 7 of the E
 O.\n\nExecutive Order 14365: Ensuring a National Policy Framework for Arti
 ficial Intelligence (United States)\n\nSource: https://www.federalregister
 .gov/documents/2026/07/07/2026-13628/policy-statement-concerning-the-suppr
 ession-of-accuracy-in-artificial-intelligence-systems\n\nhttps://regulatio
 ns.fru.dev/regulations/us-eo-14365-ai-preemption
URL:https://regulations.fru.dev/regulations/us-eo-14365-ai-preemption
CATEGORIES:United States,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6896@regulations.fru.dev
DTSTAMP:20260926T191425Z
DTSTART;VALUE=DATE:20260731
DTEND;VALUE=DATE:20260801
SUMMARY:AI state-law preemption EO: FTC policy statement comments close
DESCRIPTION:Comment deadline on the proposed FTC AI policy statement.\n\nEx
 ecutive Order 14365: Ensuring a National Policy Framework for Artificial I
 ntelligence (United States)\n\nSource: https://www.federalregister.gov/doc
 uments/2026/07/07/2026-13628/policy-statement-concerning-the-suppression-o
 f-accuracy-in-artificial-intelligence-systems\n\nhttps://regulations.fru.d
 ev/regulations/us-eo-14365-ai-preemption
URL:https://regulations.fru.dev/regulations/us-eo-14365-ai-preemption
CATEGORIES:United States,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-196@regulations.fru.dev
DTSTAMP:20260926T191425Z
DTSTART;VALUE=DATE:20261110
DTEND;VALUE=DATE:20261111
SUMMARY:CMMC 2.0: Phase 2: Level 2 C3PAO certification
DESCRIPTION:Phase 2 begins one calendar year after Phase 1\; applicable sol
 icitations require CMMC Level 2 third-party (C3PAO) certification (32 CFR 
 170.3(e)(2)).\n\nCybersecurity Maturity Model Certification (CMMC) Program
  (32 CFR Part 170) and DFARS acquisition rule (48 CFR Parts 204\, 212\, 21
 7\, 252) (United States (Federal))\n\nSource: https://www.federalregister.
 gov/documents/2024/10/15/2024-22905/cybersecurity-maturity-model-certifica
 tion-cmmc-program\n\nhttps://regulations.fru.dev/regulations/us-cmmc
URL:https://regulations.fru.dev/regulations/us-cmmc
CATEGORIES:United States (Federal),cybersecurity
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6886@regulations.fru.dev
DTSTAMP:20260926T191425Z
DTSTART;VALUE=DATE:20270401
DTEND;VALUE=DATE:20270402
SUMMARY:CFPB Open Banking Rule (Section 1033): Tier 2 compliance date (orig
 inal)
DESCRIPTION:Banks with $10B to $250B in assets and smaller nondepositories.
  Original date in 12 CFR 1033.121\; subject to the 90-day stay\, planned e
 xtension and injunction.\n\nTentative: depends on a proposal not yet adopt
 ed.\n\nRequired Rulemaking on Personal Financial Data Rights (12 CFR Part 
 1033) (United States)\n\nSource: https://www.federalregister.gov/documents
 /2024/11/18/2024-25079/required-rulemaking-on-personal-financial-data-righ
 ts\n\nhttps://regulations.fru.dev/regulations/us-cfpb-1033
URL:https://regulations.fru.dev/regulations/us-cfpb-1033
CATEGORIES:United States,data-access,financial,privacy,cybersecurity
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-197@regulations.fru.dev
DTSTAMP:20260926T191425Z
DTSTART;VALUE=DATE:20271110
DTEND;VALUE=DATE:20271111
SUMMARY:CMMC 2.0: Phase 3: Level 3 certification
DESCRIPTION:Phase 3 begins one year after Phase 2\; Level 3 (DIBCAC) requir
 ements added to applicable solicitations (32 CFR 170.3(e)(3)).\n\nCybersec
 urity Maturity Model Certification (CMMC) Program (32 CFR Part 170) and DF
 ARS acquisition rule (48 CFR Parts 204\, 212\, 217\, 252) (United States (
 Federal))\n\nSource: https://www.federalregister.gov/documents/2024/10/15/
 2024-22905/cybersecurity-maturity-model-certification-cmmc-program\n\nhttp
 s://regulations.fru.dev/regulations/us-cmmc
URL:https://regulations.fru.dev/regulations/us-cmmc
CATEGORIES:United States (Federal),cybersecurity
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6887@regulations.fru.dev
DTSTAMP:20260926T191425Z
DTSTART;VALUE=DATE:20280401
DTEND;VALUE=DATE:20280402
SUMMARY:CFPB Open Banking Rule (Section 1033): Tier 3 compliance date (orig
 inal)
DESCRIPTION:Banks with $3B to $10B in assets. Original date\; subject to st
 ay\, extension and injunction.\n\nTentative: depends on a proposal not yet
  adopted.\n\nRequired Rulemaking on Personal Financial Data Rights (12 CFR
  Part 1033) (United States)\n\nSource: https://www.federalregister.gov/doc
 uments/2024/11/18/2024-25079/required-rulemaking-on-personal-financial-dat
 a-rights\n\nhttps://regulations.fru.dev/regulations/us-cfpb-1033
URL:https://regulations.fru.dev/regulations/us-cfpb-1033
CATEGORIES:United States,data-access,financial,privacy,cybersecurity
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-198@regulations.fru.dev
DTSTAMP:20260926T191425Z
DTSTART;VALUE=DATE:20281110
DTEND;VALUE=DATE:20281111
SUMMARY:CMMC 2.0: Phase 4: full implementation
DESCRIPTION:CMMC requirements included in all applicable DoD solicitations 
 and contracts\, including option periods (32 CFR 170.3(e)(4)).\n\nCybersec
 urity Maturity Model Certification (CMMC) Program (32 CFR Part 170) and DF
 ARS acquisition rule (48 CFR Parts 204\, 212\, 217\, 252) (United States (
 Federal))\n\nSource: https://www.federalregister.gov/documents/2024/10/15/
 2024-22905/cybersecurity-maturity-model-certification-cmmc-program\n\nhttp
 s://regulations.fru.dev/regulations/us-cmmc
URL:https://regulations.fru.dev/regulations/us-cmmc
CATEGORIES:United States (Federal),cybersecurity
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6888@regulations.fru.dev
DTSTAMP:20260926T191425Z
DTSTART;VALUE=DATE:20290401
DTEND;VALUE=DATE:20290402
SUMMARY:CFPB Open Banking Rule (Section 1033): Tier 4 compliance date (orig
 inal)
DESCRIPTION:Banks with $1.5B to $3B in assets. Original date\; subject to s
 tay\, extension and injunction.\n\nTentative: depends on a proposal not ye
 t adopted.\n\nRequired Rulemaking on Personal Financial Data Rights (12 CF
 R Part 1033) (United States)\n\nSource: https://www.federalregister.gov/do
 cuments/2024/11/18/2024-25079/required-rulemaking-on-personal-financial-da
 ta-rights\n\nhttps://regulations.fru.dev/regulations/us-cfpb-1033
URL:https://regulations.fru.dev/regulations/us-cfpb-1033
CATEGORIES:United States,data-access,financial,privacy,cybersecurity
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6889@regulations.fru.dev
DTSTAMP:20260926T191425Z
DTSTART;VALUE=DATE:20300401
DTEND;VALUE=DATE:20300402
SUMMARY:CFPB Open Banking Rule (Section 1033): Tier 5 compliance date (orig
 inal)
DESCRIPTION:Banks with $850M to $1.5B in assets. Original date\; subject to
  stay\, extension and injunction.\n\nTentative: depends on a proposal not 
 yet adopted.\n\nRequired Rulemaking on Personal Financial Data Rights (12 
 CFR Part 1033) (United States)\n\nSource: https://www.federalregister.gov/
 documents/2024/11/18/2024-25079/required-rulemaking-on-personal-financial-
 data-rights\n\nhttps://regulations.fru.dev/regulations/us-cfpb-1033
URL:https://regulations.fru.dev/regulations/us-cfpb-1033
CATEGORIES:United States,data-access,financial,privacy,cybersecurity
TRANSP:TRANSPARENT
END:VEVENT
END:VCALENDAR
