BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//fru.dev//Regulations//EN
CALSCALE:GREGORIAN
METHOD:PUBLISH
X-WR-CALNAME:Regulation deadlines (regulations.fru.dev)
X-WR-CALDESC:Compliance deadlines tracked at regulations.fru.dev
REFRESH-INTERVAL;VALUE=DURATION:P1D
X-PUBLISHED-TTL:P1D
BEGIN:VEVENT
UID:deadline-7003@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:19961220
DTEND;VALUE=DATE:19961221
SUMMARY:Hong Kong PDPO: PDPO takes effect
DESCRIPTION:The PCPD says the PDPO took effect in December 1996\, except ce
 rtain provisions. The exact day was not confirmed on the official pages ch
 ecked.\n\nTentative: depends on a proposal not yet adopted.\n\nPersonal Da
 ta (Privacy) Ordinance (Cap. 486) (Hong Kong)\n\nSource: https://www.pcpd.
 org.hk/english/data_privacy_law/ordinance_at_a_Glance/ordinance.html\n\nht
 tps://regulations.fru.dev/regulations/hk-pdpo
URL:https://regulations.fru.dev/regulations/hk-pdpo
CATEGORIES:Hong Kong,privacy,online-safety
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6948@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20001004
DTEND;VALUE=DATE:20001005
SUMMARY:Argentina Law 25.326: Law sanctioned
DESCRIPTION:Congress sanctions Law 25.326.\n\nLey 25.326 de Protección de 
 los Datos Personales (Argentina)\n\nSource: https://servicios.infoleg.gob.
 ar/infolegInternet/anexos/60000-64999/64790/norma.htm\n\nhttps://regulatio
 ns.fru.dev/regulations/ar-pdpl
URL:https://regulations.fru.dev/regulations/ar-pdpl
CATEGORIES:Argentina,privacy,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6949@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20001102
DTEND;VALUE=DATE:20001103
SUMMARY:Argentina Law 25.326: Published in Boletín Oficial
DESCRIPTION:Published in Boletín Oficial No. 29517.\n\nLey 25.326 de Prote
 cción de los Datos Personales (Argentina)\n\nSource: https://servicios.in
 foleg.gob.ar/infolegInternet/verNorma.do?id=64790\n\nhttps://regulations.f
 ru.dev/regulations/ar-pdpl
URL:https://regulations.fru.dev/regulations/ar-pdpl
CATEGORIES:Argentina,privacy,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-18@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20010101
DTEND;VALUE=DATE:20010102
SUMMARY:PIPEDA: PIPEDA Part 1 in force (phase 1)
DESCRIPTION:Applies to federally regulated organisations.\n\nPersonal Infor
 mation Protection and Electronic Documents Act (Canada)\n\nSource: https:/
 /laws-lois.justice.gc.ca/eng/acts/p-8.6/\n\nhttps://regulations.fru.dev/re
 gulations/ca-pipeda
URL:https://regulations.fru.dev/regulations/ca-pipeda
CATEGORIES:Canada,privacy,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-90@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20020731
DTEND;VALUE=DATE:20020801
SUMMARY:ePrivacy Directive (cookie law): ePrivacy Directive enters into for
 ce
DESCRIPTION:Entered into force on the day of publication in the OJ (Art 20)
 .\n\nDirective 2002/58/EC concerning the processing of personal data and t
 he protection of privacy in the electronic communications sector (ePrivacy
  Directive)\, as amended by Directive 2009/136/EC (European Union)\n\nSour
 ce: https://eur-lex.europa.eu/eli/dir/2002/58/oj\n\nhttps://regulations.fr
 u.dev/regulations/eu-eprivacy
URL:https://regulations.fru.dev/regulations/eu-eprivacy
CATEGORIES:European Union,privacy,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-91@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20031031
DTEND;VALUE=DATE:20031101
SUMMARY:ePrivacy Directive (cookie law): Original transposition deadline
DESCRIPTION:Member States had to bring national laws into force before 31 O
 ct 2003 (Art 17).\n\nDirective 2002/58/EC concerning the processing of per
 sonal data and the protection of privacy in the electronic communications 
 sector (ePrivacy Directive)\, as amended by Directive 2009/136/EC (Europea
 n Union)\n\nSource: https://eur-lex.europa.eu/eli/dir/2002/58/oj\n\nhttps:
 //regulations.fru.dev/regulations/eu-eprivacy
URL:https://regulations.fru.dev/regulations/eu-eprivacy
CATEGORIES:European Union,privacy,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-19@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20040101
DTEND;VALUE=DATE:20040102
SUMMARY:PIPEDA: PIPEDA applies to all commercial activity
DESCRIPTION:Extended to commercial activity in provinces without substantia
 lly similar legislation.\n\nPersonal Information Protection and Electronic
  Documents Act (Canada)\n\nSource: https://laws-lois.justice.gc.ca/eng/act
 s/p-8.6/\n\nhttps://regulations.fru.dev/regulations/ca-pipeda
URL:https://regulations.fru.dev/regulations/ca-pipeda
CATEGORIES:Canada,privacy,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6950@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20080811
DTEND;VALUE=DATE:20080812
SUMMARY:Uruguay Law 18.331: Law promulgated
DESCRIPTION:Law 18.331 promulgated.\n\nLey N° 18.331 de Protección de Dat
 os Personales (Uruguay)\n\nSource: https://www.impo.com.uy/bases/leyes/183
 31-2008\n\nhttps://regulations.fru.dev/regulations/uy-pdpl
URL:https://regulations.fru.dev/regulations/uy-pdpl
CATEGORIES:Uruguay,privacy,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6951@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20080818
DTEND;VALUE=DATE:20080819
SUMMARY:Uruguay Law 18.331: Law published
DESCRIPTION:Published in Diario Oficial.\n\nLey N° 18.331 de Protección d
 e Datos Personales (Uruguay)\n\nSource: https://www.impo.com.uy/bases/leye
 s/18331-2008\n\nhttps://regulations.fru.dev/regulations/uy-pdpl
URL:https://regulations.fru.dev/regulations/uy-pdpl
CATEGORIES:Uruguay,privacy,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-241@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20081003
DTEND;VALUE=DATE:20081004
SUMMARY:Illinois BIPA: BIPA effective
DESCRIPTION:The Biometric Information Privacy Act takes effect.\n\nIllinois
  Biometric Information Privacy Act (740 ILCS 14)\, as amended by SB 2979 (
 Public Act 103-0769) (Illinois)\n\nSource: https://www.ilga.gov/legislatio
 n/ilcs/ilcs3.asp?ActID=3004&ChapterID=57\n\nhttps://regulations.fru.dev/re
 gulations/us-il-bipa
URL:https://regulations.fru.dev/regulations/us-il-bipa
CATEGORIES:Illinois,biometrics,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-231@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20100222
DTEND;VALUE=DATE:20100223
SUMMARY:FTC Health Breach Notification Rule: Full compliance with original 
 Rule
DESCRIPTION:Full compliance with the 2009 Health Breach Notification Rule w
 as required.\n\nFTC Health Breach Notification Rule (16 CFR Part 318)\, as
  amended 2024 (United States (Federal))\n\nSource: https://www.federalregi
 ster.gov/citation/74-FR-42962\n\nhttps://regulations.fru.dev/regulations/u
 s-ftc-hbnr
URL:https://regulations.fru.dev/regulations/us-ftc-hbnr
CATEGORIES:United States (Federal),health,privacy,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-92@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20110525
DTEND;VALUE=DATE:20110526
SUMMARY:ePrivacy Directive (cookie law): Cookie consent amendment transposi
 tion deadline
DESCRIPTION:Directive 2009/136/EC\, which changed Art 5(3) to require conse
 nt for cookies\, had to be transposed by 25 May 2011.\n\nDirective 2002/58
 /EC concerning the processing of personal data and the protection of priva
 cy in the electronic communications sector (ePrivacy Directive)\, as amend
 ed by Directive 2009/136/EC (European Union)\n\nSource: https://eur-lex.eu
 ropa.eu/eli/dir/2009/136/oj\n\nhttps://regulations.fru.dev/regulations/eu-
 eprivacy
URL:https://regulations.fru.dev/regulations/eu-eprivacy
CATEGORIES:European Union,privacy,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-7005@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20120908
DTEND;VALUE=DATE:20120909
SUMMARY:Philippines Data Privacy Act: Data Privacy Act takes effect
DESCRIPTION:The Act takes effect 15 days after publication in two national 
 newspapers (sec. 45). This date comes from secondary sources\, not the NPC
  page.\n\nTentative: depends on a proposal not yet adopted.\n\nData Privac
 y Act of 2012 (Republic Act No. 10173) (Philippines)\n\nSource: https://pr
 ivacy.gov.ph/data-privacy-act/\n\nhttps://regulations.fru.dev/regulations/
 ph-dpa
URL:https://regulations.fru.dev/regulations/ph-dpa
CATEGORIES:Philippines,privacy,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6999@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20121001
DTEND;VALUE=DATE:20121002
SUMMARY:Taiwan PDPA: 2010 PDPA rewrite takes effect
DESCRIPTION:The 2010 full rewrite of the Act takes effect\, except articles
  6 and 54.\n\nPersonal Data Protection Act (Taiwan)\n\nSource: https://law
 .moj.gov.tw/LawClass/LawHistory.aspx?pcode=I0050021\n\nhttps://regulations
 .fru.dev/regulations/tw-pdpa
URL:https://regulations.fru.dev/regulations/tw-pdpa
CATEGORIES:Taiwan,privacy,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-139@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20140702
DTEND;VALUE=DATE:20140703
SUMMARY:Singapore PDPA: PDPA data protection obligations take effect
DESCRIPTION:Main data protection provisions come into force.\n\nPersonal Da
 ta Protection Act 2012 (Singapore) (Singapore)\n\nSource: https://sso.agc.
 gov.sg/Act/PDPA2012\n\nhttps://regulations.fru.dev/regulations/sg-pdpa
URL:https://regulations.fru.dev/regulations/sg-pdpa
CATEGORIES:Singapore,privacy,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-93@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20160524
DTEND;VALUE=DATE:20160525
SUMMARY:GDPR: GDPR enters into force
DESCRIPTION:Regulation entered into force on the twentieth day after public
 ation in OJ L 119 of 4 May 2016 (Art 99(1)).\n\nRegulation (EU) 2016/679 (
 General Data Protection Regulation) (European Union)\n\nSource: https://eu
 r-lex.europa.eu/eli/reg/2016/679/oj\n\nhttps://regulations.fru.dev/regulat
 ions/eu-gdpr
URL:https://regulations.fru.dev/regulations/eu-gdpr
CATEGORIES:European Union,privacy,breach-notification,data-access,children,
 biometrics,health
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-7006@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20160909
DTEND;VALUE=DATE:20160910
SUMMARY:Philippines Data Privacy Act: Implementing Rules take effect
DESCRIPTION:The IRR takes effect 15 days after publication in the Official 
 Gazette (sec. 72)\, with 72-hour breach notice. The exact date was not sho
 wn on the NPC page.\n\nTentative: depends on a proposal not yet adopted.\n
 \nData Privacy Act of 2012 (Republic Act No. 10173) (Philippines)\n\nSourc
 e: https://privacy.gov.ph/implementing-rules-regulations-data-privacy-act-
 2012/\n\nhttps://regulations.fru.dev/regulations/ph-dpa
URL:https://regulations.fru.dev/regulations/ph-dpa
CATEGORIES:Philippines,privacy,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-269@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20170301
DTEND;VALUE=DATE:20170302
SUMMARY:NYDFS Cybersecurity Regulation (Part 500): Part 500 effective
DESCRIPTION:Original cybersecurity regulation takes effect.\n\nNew York DFS
  Cybersecurity Requirements for Financial Services Companies (23 NYCRR Par
 t 500)\, Second Amendment (New York)\n\nSource: https://www.dfs.ny.gov/cyb
 ersecurity/23-NYCRR-Part-500\n\nhttps://regulations.fru.dev/regulations/us
 -ny-dfs-500
URL:https://regulations.fru.dev/regulations/us-ny-dfs-500
CATEGORIES:New York,cybersecurity,breach-notification,financial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-31@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20170601
DTEND;VALUE=DATE:20170602
SUMMARY:China Cybersecurity Law: Cybersecurity Law takes effect
DESCRIPTION:Original CSL obligations for network operators and CII operator
 s apply.\n\nCybersecurity Law of the People's Republic of China (as amende
 d by the NPC Standing Committee Decision of 28 October 2025) (China)\n\nSo
 urce: https://www.gov.cn/yaowen/liebiao/202510/content_7046194.htm\n\nhttp
 s://regulations.fru.dev/regulations/cn-csl
URL:https://regulations.fru.dev/regulations/cn-csl
CATEGORIES:China,cybersecurity,data-residency,ai,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6870@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20180523
DTEND;VALUE=DATE:20180524
SUMMARY:UK Data Protection Act 2018: Royal Assent
DESCRIPTION:Data Protection Act 2018 receives Royal Assent.\n\nData Protect
 ion Act 2018 (United Kingdom)\n\nSource: https://www.legislation.gov.uk/uk
 pga/2018/12/introduction/enacted\n\nhttps://regulations.fru.dev/regulation
 s/uk-dpa-2018
URL:https://regulations.fru.dev/regulations/uk-dpa-2018
CATEGORIES:United Kingdom,privacy,breach-notification,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-94@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20180525
DTEND;VALUE=DATE:20180526
SUMMARY:GDPR: GDPR applies
DESCRIPTION:All GDPR obligations apply from 25 May 2018 (Art 99(2))\, repla
 cing Directive 95/46/EC.\n\nRegulation (EU) 2016/679 (General Data Protect
 ion Regulation) (European Union)\n\nSource: https://eur-lex.europa.eu/eli/
 reg/2016/679/oj\n\nhttps://regulations.fru.dev/regulations/eu-gdpr
URL:https://regulations.fru.dev/regulations/eu-gdpr
CATEGORIES:European Union,privacy,breach-notification,data-access,children,
 biometrics,health
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6871@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20180525
DTEND;VALUE=DATE:20180526
SUMMARY:UK Data Protection Act 2018: Main provisions commence
DESCRIPTION:Most provisions come into force under SI 2018/625.\n\nData Prot
 ection Act 2018 (United Kingdom)\n\nSource: https://www.legislation.gov.uk
 /uksi/2018/625/made\n\nhttps://regulations.fru.dev/regulations/uk-dpa-2018
URL:https://regulations.fru.dev/regulations/uk-dpa-2018
CATEGORIES:United Kingdom,privacy,breach-notification,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-153@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20180525
DTEND;VALUE=DATE:20180526
SUMMARY:UK GDPR: Data Protection Act 2018 and GDPR apply
DESCRIPTION:DPA 2018 and EU GDPR began applying in the UK.\n\nUK General Da
 ta Protection Regulation and Data Protection Act 2018 (United Kingdom)\n\n
 Source: https://www.legislation.gov.uk/ukpga/2018/12/contents\n\nhttps://r
 egulations.fru.dev/regulations/uk-gdpr
URL:https://regulations.fru.dev/regulations/uk-gdpr
CATEGORIES:United Kingdom,privacy,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-7041@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20180530
DTEND;VALUE=DATE:20180531
SUMMARY:Kenya Computer Misuse and Cybercrimes Act: Act commences
DESCRIPTION:Assented 16 May 2018\, published 18 May 2018\, commenced 30 May
  2018.\n\nComputer Misuse and Cybercrimes Act\, 2018 (Kenya)\n\nSource: ht
 tps://new.kenyalaw.org/akn/ke/act/2018/5/eng@2022-12-31\n\nhttps://regulat
 ions.fru.dev/regulations/ke-cmca
URL:https://regulations.fru.dev/regulations/ke-cmca
CATEGORIES:Kenya,cybersecurity,online-safety
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-7024@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20180711
DTEND;VALUE=DATE:20180712
SUMMARY:Australia SOCI Act: SOCI Act commences
DESCRIPTION:The whole Act commences by Proclamation.\n\nSecurity of Critica
 l Infrastructure Act 2018 (Australia)\n\nSource: https://www.legislation.g
 ov.au/C2018A00029/asmade\n\nhttps://regulations.fru.dev/regulations/au-soc
 i-act
URL:https://regulations.fru.dev/regulations/au-soci-act
CATEGORIES:Australia,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6872@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20180723
DTEND;VALUE=DATE:20180724
SUMMARY:UK Data Protection Act 2018: Age appropriate design code powers com
 mence
DESCRIPTION:Section 123 (age-appropriate design code) comes into force.\n\n
 Data Protection Act 2018 (United Kingdom)\n\nSource: https://www.legislati
 on.gov.uk/uksi/2018/625/made\n\nhttps://regulations.fru.dev/regulations/uk
 -dpa-2018
URL:https://regulations.fru.dev/regulations/uk-dpa-2018
CATEGORIES:United Kingdom,privacy,breach-notification,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-7011@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20180831
DTEND;VALUE=DATE:20180901
SUMMARY:Singapore Cybersecurity Act: Cybersecurity Act main provisions comm
 ence
DESCRIPTION:Parts 1 to 4\, 6 and the First Schedule (CII regime) commence.\
 n\nCybersecurity Act 2018 (Singapore)\n\nSource: https://sso.agc.gov.sg/Ac
 ts-Supp/9-2018/Published/20211231?DocDate=20180312\n\nhttps://regulations.
 fru.dev/regulations/sg-cybersecurity-act
URL:https://regulations.fru.dev/regulations/sg-cybersecurity-act
CATEGORIES:Singapore,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6952@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20181015
DTEND;VALUE=DATE:20181016
SUMMARY:Uruguay Law 18.331: Law 19.670 amendments
DESCRIPTION:Law 19.670 rewrites parts of the law\, including proactive acco
 untability duties.\n\nLey N° 18.331 de Protección de Datos Personales (U
 ruguay)\n\nSource: https://www.impo.com.uy/bases/leyes/18331-2008\n\nhttps
 ://regulations.fru.dev/regulations/uy-pdpl
URL:https://regulations.fru.dev/regulations/uy-pdpl
CATEGORIES:Uruguay,privacy,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-20@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20181101
DTEND;VALUE=DATE:20181102
SUMMARY:PIPEDA: Mandatory breach reporting
DESCRIPTION:Breach of security safeguards reporting\, notification and reco
 rd-keeping obligations take effect.\n\nPersonal Information Protection and
  Electronic Documents Act (Canada)\n\nSource: https://laws-lois.justice.gc
 .ca/eng/acts/p-8.6/\n\nhttps://regulations.fru.dev/regulations/ca-pipeda
URL:https://regulations.fru.dev/regulations/ca-pipeda
CATEGORIES:Canada,privacy,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-7021@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20190528
DTEND;VALUE=DATE:20190529
SUMMARY:Thailand Cybersecurity Act: Cybersecurity Act in force
DESCRIPTION:NCSA states the Act took effect on 28 May 2019.\n\nCybersecurit
 y Act B.E. 2562 (2019) (Thailand)\n\nSource: https://www.ncsa.or.th/about\
 n\nhttps://regulations.fru.dev/regulations/th-cybersecurity-act
URL:https://regulations.fru.dev/regulations/th-cybersecurity-act
CATEGORIES:Thailand,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6852@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20190627
DTEND;VALUE=DATE:20190628
SUMMARY:EU Cybersecurity Act: Cybersecurity Act enters into force
DESCRIPTION:Published in the OJ on 2019-06-07\; enters into force on the 20
 th day.\n\nRegulation (EU) 2019/881 on ENISA and on information and commun
 ications technology cybersecurity certification (Cybersecurity Act) (Europ
 ean Union)\n\nSource: https://eur-lex.europa.eu/eli/reg/2019/881/oj/eng\n\
 nhttps://regulations.fru.dev/regulations/eu-cybersecurity-act
URL:https://regulations.fru.dev/regulations/eu-cybersecurity-act
CATEGORIES:European Union,cybersecurity
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-7030@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20190801
DTEND;VALUE=DATE:20190802
SUMMARY:Bahrain PDPL: PDPL takes effect
DESCRIPTION:Article 4 of the issuing law says the law applies from the firs
 t day of the month after one year from Gazette publication.\n\nTentative: 
 depends on a proposal not yet adopted.\n\nLaw No. 30 of 2018 on the Protec
 tion of Personal Data (Bahrain)\n\nSource: https://www.lloc.gov.bh/Legisla
 tion/HTM/K3018\n\nhttps://regulations.fru.dev/regulations/bh-pdpl
URL:https://regulations.fru.dev/regulations/bh-pdpl
CATEGORIES:Bahrain,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-123@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20191125
DTEND;VALUE=DATE:20191126
SUMMARY:Kenya Data Protection Act: Data Protection Act in force
DESCRIPTION:Act commences.\n\nData Protection Act\, 2019 (No. 24 of 2019) (
 Kenya)\n\nSource: https://www.odpc.go.ke/\n\nhttps://regulations.fru.dev/r
 egulations/ke-dpa
URL:https://regulations.fru.dev/regulations/ke-dpa
CATEGORIES:Kenya,privacy,breach-notification,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-164@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20200101
DTEND;VALUE=DATE:20200102
SUMMARY:CCPA / CPRA: CCPA takes effect
DESCRIPTION:Original CCPA consumer rights and business obligations take eff
 ect.\n\nCalifornia Consumer Privacy Act of 2018\, as amended by the Califo
 rnia Privacy Rights Act of 2020 (Cal. Civ. Code 1798.100 et seq.) and CPPA
  regulations (Cal. Code Regs. tit. 11\, 7000 et seq.) (California)\n\nSour
 ce: https://cppa.ca.gov/regulations/pdf/ccpa_statute_eff_20260101.pdf\n\nh
 ttps://regulations.fru.dev/regulations/us-ca-ccpa
URL:https://regulations.fru.dev/regulations/us-ca-ccpa
CATEGORIES:California,privacy,ai,cybersecurity,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6953@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20200217
DTEND;VALUE=DATE:20200218
SUMMARY:Uruguay Law 18.331: Decree 64/020
DESCRIPTION:Decree 64/020 regulates the Law 19.670 amendments.\n\nLey N° 1
 8.331 de Protección de Datos Personales (Uruguay)\n\nSource: https://www.
 impo.com.uy/bases/leyes/18331-2008\n\nhttps://regulations.fru.dev/regulati
 ons/uy-pdpl
URL:https://regulations.fru.dev/regulations/uy-pdpl
CATEGORIES:Uruguay,privacy,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-325@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20200701
DTEND;VALUE=DATE:20200702
SUMMARY:South Africa POPIA: Main POPIA provisions commence
DESCRIPTION:Most sections commence with a 12-month grace period.\n\nProtect
 ion of Personal Information Act\, 2013 (Act No. 4 of 2013) (South Africa)\
 n\nSource: https://www.gov.za/documents/protection-personal-information-ac
 t\n\nhttps://regulations.fru.dev/regulations/za-popia
URL:https://regulations.fru.dev/regulations/za-popia
CATEGORIES:South Africa,privacy,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-11@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20200918
DTEND;VALUE=DATE:20200919
SUMMARY:Brazil LGPD: LGPD in force
DESCRIPTION:Main LGPD provisions take effect.\n\nLei Geral de Proteção de
  Dados Pessoais (Law No. 13.709/2018) (Brazil)\n\nSource: https://www.plan
 alto.gov.br/ccivil_03/_ato2015-2018/2018/lei/l13709.htm\n\nhttps://regulat
 ions.fru.dev/regulations/br-lgpd
URL:https://regulations.fru.dev/regulations/br-lgpd
CATEGORIES:Brazil,privacy,breach-notification,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-7031@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20201016
DTEND;VALUE=DATE:20201017
SUMMARY:Egypt PDPL: PDPL takes effect
DESCRIPTION:Article 7 of the issuing law: in force three months after the d
 ay following publication (Gazette No. 28 bis (h)\, 15 July 2020). Date com
 puted from that rule.\n\nTentative: depends on a proposal not yet adopted.
 \n\nLaw No. 151 of 2020 on the Protection of Personal Data and its Executi
 ve Regulations (Egypt)\n\nSource: https://www.pdpc.gov.eg/assets/pdf-data/
 PDPL%20no.%20151%20of%202020%20(ar).pdf\n\nhttps://regulations.fru.dev/reg
 ulations/eg-pdpl
URL:https://regulations.fru.dev/regulations/eg-pdpl
CATEGORIES:Egypt,privacy,data-residency,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-134@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20201201
DTEND;VALUE=DATE:20201202
SUMMARY:New Zealand Privacy Act: Privacy Act 2020 in force
DESCRIPTION:IPPs\, mandatory breach notification and compliance notices app
 ly.\n\nPrivacy Act 2020 (New Zealand)\, as amended by the Privacy Amendmen
 t Act 2025 (New Zealand)\n\nSource: https://www.justice.govt.nz/justice-se
 ctor-policy/key-initiatives/enhancing-the-privacy-act/\n\nhttps://regulati
 ons.fru.dev/regulations/nz-privacy-act
URL:https://regulations.fru.dev/regulations/nz-privacy-act
CATEGORIES:New Zealand,privacy,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-154@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20210101
DTEND;VALUE=DATE:20210102
SUMMARY:UK GDPR: UK GDPR takes effect after Brexit transition
DESCRIPTION:Retained EU GDPR becomes the UK GDPR at the end of the Brexit i
 mplementation period.\n\nUK General Data Protection Regulation and Data Pr
 otection Act 2018 (United Kingdom)\n\nSource: https://www.legislation.gov.
 uk/eur/2016/679/contents\n\nhttps://regulations.fru.dev/regulations/uk-gdp
 r
URL:https://regulations.fru.dev/regulations/uk-gdpr
CATEGORIES:United Kingdom,privacy,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-140@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20210201
DTEND;VALUE=DATE:20210202
SUMMARY:Singapore PDPA: 2020 amendments largely in force
DESCRIPTION:Mandatory data breach notification and revised consent framewor
 k apply.\n\nPersonal Data Protection Act 2012 (Singapore) (Singapore)\n\nS
 ource: https://sso.agc.gov.sg/Act/PDPA2012\n\nhttps://regulations.fru.dev/
 regulations/sg-pdpa
URL:https://regulations.fru.dev/regulations/sg-pdpa
CATEGORIES:Singapore,privacy,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6853@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20210628
DTEND;VALUE=DATE:20210629
SUMMARY:EU Cybersecurity Act: Certification enforcement articles apply
DESCRIPTION:Articles 58\, 60\, 61\, 63\, 64 and 65 on national certificatio
 n authorities\, conformity assessment bodies\, complaints and remedies app
 ly.\n\nRegulation (EU) 2019/881 on ENISA and on information and communicat
 ions technology cybersecurity certification (Cybersecurity Act) (European 
 Union)\n\nSource: https://eur-lex.europa.eu/eli/reg/2019/881/oj/eng\n\nhtt
 ps://regulations.fru.dev/regulations/eu-cybersecurity-act
URL:https://regulations.fru.dev/regulations/eu-cybersecurity-act
CATEGORIES:European Union,cybersecurity
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-326@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20210701
DTEND;VALUE=DATE:20210702
SUMMARY:South Africa POPIA: Compliance grace period ends
DESCRIPTION:Responsible parties must comply\; Regulator enforcement begins 
 (grace period ended 30 June 2021).\n\nProtection of Personal Information A
 ct\, 2013 (Act No. 4 of 2013) (South Africa)\n\nSource: https://www.gov.za
 /documents/protection-personal-information-act\n\nhttps://regulations.fru.
 dev/regulations/za-popia
URL:https://regulations.fru.dev/regulations/za-popia
CATEGORIES:South Africa,privacy,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-12@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20210801
DTEND;VALUE=DATE:20210802
SUMMARY:Brazil LGPD: ANPD sanctions enforceable
DESCRIPTION:Administrative sanctions (Arts. 52-54) become applicable per La
 w 14.010/2020.\n\nLei Geral de Proteção de Dados Pessoais (Law No. 13.70
 9/2018) (Brazil)\n\nSource: https://www.planalto.gov.br/ccivil_03/_ato2015
 -2018/2018/lei/l13709.htm\n\nhttps://regulations.fru.dev/regulations/br-lg
 pd
URL:https://regulations.fru.dev/regulations/br-lgpd
CATEGORIES:Brazil,privacy,breach-notification,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-33@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20210901
DTEND;VALUE=DATE:20210902
SUMMARY:China Data Security Law: Data Security Law takes effect
DESCRIPTION:Data classification\, important-data protection and data export
  restrictions apply (Art. 55).\n\nData Security Law of the People's Republ
 ic of China (China)\n\nSource: http://www.cac.gov.cn/2021-06/11/c_16249945
 66919140.htm\n\nhttps://regulations.fru.dev/regulations/cn-dsl
URL:https://regulations.fru.dev/regulations/cn-dsl
CATEGORIES:China,cybersecurity,data-residency,data-access
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-21@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20210922
DTEND;VALUE=DATE:20210923
SUMMARY:Quebec Law 25: Assent
DESCRIPTION:Bill 64 assented to as S.Q. 2021\, c. 25.\n\nAct to modernize l
 egislative provisions as regards the protection of personal information (L
 aw 25\, formerly Bill 64) (Quebec\, Canada)\n\nSource: https://www.legisqu
 ebec.gouv.qc.ca/en/document/cs/P-39.1\n\nhttps://regulations.fru.dev/regul
 ations/ca-qc-law25
URL:https://regulations.fru.dev/regulations/ca-qc-law25
CATEGORIES:Quebec\, Canada,privacy,breach-notification,biometrics
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-7004@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20211008
DTEND;VALUE=DATE:20211009
SUMMARY:Hong Kong PDPO: Anti-doxxing amendments take effect
DESCRIPTION:New doxxing offences and PCPD criminal investigation\, prosecut
 ion and cessation notice powers apply.\n\nPersonal Data (Privacy) Ordinanc
 e (Cap. 486) (Hong Kong)\n\nSource: https://www.pcpd.org.hk/english/data_p
 rivacy_law/amendments_2021/amendment_2021.html\n\nhttps://regulations.fru.
 dev/regulations/hk-pdpo
URL:https://regulations.fru.dev/regulations/hk-pdpo
CATEGORIES:Hong Kong,privacy,online-safety
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-7034@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20211015
DTEND;VALUE=DATE:20211016
SUMMARY:Rwanda DPP Law: Law published and in force
DESCRIPTION:Published in Official Gazette No. Special of 15/10/2021. Articl
 e 70: in force on publication.\n\nLaw No. 058/2021 of 13/10/2021 relating 
 to the Protection of Personal Data and Privacy (Rwanda)\n\nSource: https:/
 /www.minijust.gov.rw/fileadmin/user_upload/Minijust/Official_gazettes_2/__
 _______2021_Official_Gazettes/October/OG_Special_of_15.10.2021_Amakuru_bwi
 te.pdf\n\nhttps://regulations.fru.dev/regulations/rw-dpp
URL:https://regulations.fru.dev/regulations/rw-dpp
CATEGORIES:Rwanda,privacy,data-residency,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-36@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20211101
DTEND;VALUE=DATE:20211102
SUMMARY:China PIPL: PIPL takes effect
DESCRIPTION:All PIPL obligations (legal bases\, consent\, cross-border rule
 s\, data subject rights) apply (Art. 74).\n\nPersonal Information Protecti
 on Law of the People's Republic of China (China)\n\nSource: http://www.cac
 .gov.cn/2021-08/20/c_1631050028355286.htm\n\nhttps://regulations.fru.dev/r
 egulations/cn-pipl
URL:https://regulations.fru.dev/regulations/cn-pipl
CATEGORIES:China,privacy,data-residency,biometrics,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6875@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20211117
DTEND;VALUE=DATE:20211118
SUMMARY:UK Telecommunications Security Act: Royal Assent
DESCRIPTION:Telecommunications (Security) Act receives Royal Assent.\n\nTel
 ecommunications (Security) Act 2021 and the Electronic Communications (Sec
 urity Measures) Regulations 2022 (United Kingdom)\n\nSource: https://www.l
 egislation.gov.uk/ukpga/2021/31/introduction/enacted\n\nhttps://regulation
 s.fru.dev/regulations/uk-telecom-security
URL:https://regulations.fru.dev/regulations/uk-telecom-security
CATEGORIES:United Kingdom,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-7040@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20211201
DTEND;VALUE=DATE:20211202
SUMMARY:South Africa Cybercrimes Act: Most of the Act commences
DESCRIPTION:Commenced by proclamation in Gazette 45562 of 30 November 2021\
 , excluding Part VI of Chapter 2\, some Chapter 4 sections and section 54.
 \n\nCybercrimes Act 19 of 2020 (South Africa)\n\nSource: https://www.gov.z
 a/documents/cybercrimes-act-19-2020-1-jun-2021-0000\n\nhttps://regulations
 .fru.dev/regulations/za-cybercrimes-act
URL:https://regulations.fru.dev/regulations/za-cybercrimes-act
CATEGORIES:South Africa,cybersecurity,online-safety,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-1@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20220102
DTEND;VALUE=DATE:20220103
SUMMARY:UAE PDPL: PDPL enters into force
DESCRIPTION:Decree-law takes effect\; compliance obligations tied to Execut
 ive Regulations.\n\nFederal Decree-Law No. 45 of 2021 on the Protection of
  Personal Data (United Arab Emirates)\n\nSource: https://uaelegislation.go
 v.ae/en/legislations/1972\n\nhttps://regulations.fru.dev/regulations/ae-pd
 pl
URL:https://regulations.fru.dev/regulations/ae-pdpl
CATEGORIES:United Arab Emirates,privacy,breach-notification,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-233@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20220110
DTEND;VALUE=DATE:20220111
SUMMARY:GLBA Safeguards Rule: 2021 Safeguards Rule amendments effective
DESCRIPTION:The amended Safeguards Rule published December 9\, 2021 took ef
 fect\, with the more detailed program elements in 314.5 deferred.\n\nFTC S
 tandards for Safeguarding Customer Information (Safeguards Rule)\, 16 CFR 
 Part 314\, under the Gramm-Leach-Bliley Act (United States (Federal))\n\nS
 ource: https://www.federalregister.gov/documents/2021/12/09/2021-25736/sta
 ndards-for-safeguarding-customer-information\n\nhttps://regulations.fru.de
 v/regulations/us-glba-safeguards
URL:https://regulations.fru.dev/regulations/us-glba-safeguards
CATEGORIES:United States (Federal),financial,cybersecurity,breach-notificat
 ion,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-7023@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20220123
DTEND;VALUE=DATE:20220124
SUMMARY:Australia Online Safety Act: Online Safety Act commences
DESCRIPTION:The whole Act commences by Proclamation.\n\nOnline Safety Act 2
 021 (Australia)\n\nSource: https://www.legislation.gov.au/C2021A00076/asma
 de\n\nhttps://regulations.fru.dev/regulations/au-online-safety-act
URL:https://regulations.fru.dev/regulations/au-online-safety-act
CATEGORIES:Australia,online-safety,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6975@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20220301
DTEND;VALUE=DATE:20220302
SUMMARY:China Algorithmic Recommendation Provisions: Algorithmic recommenda
 tion provisions take effect
DESCRIPTION:User opt-out\, transparency and algorithm filing duties apply.\
 n\nProvisions on the Administration of Algorithmic Recommendation in Inter
 net Information Services (China)\n\nSource: https://www.cac.gov.cn/2022-01
 /04/c_1642894606364259.htm\n\nhttps://regulations.fru.dev/regulations/cn-a
 lgorithm-recommendation
URL:https://regulations.fru.dev/regulations/cn-algorithm-recommendation
CATEGORIES:China,ai,online-safety,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-121@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20220401
DTEND;VALUE=DATE:20220402
SUMMARY:Japan APPI: 2020 amendments in force
DESCRIPTION:Mandatory breach reporting\, pseudonymized information and stri
 cter cross-border rules apply.\n\nAct on the Protection of Personal Inform
 ation (Act No. 57 of 2003)\, as amended including the 2026 amendment act (
 Japan)\n\nSource: https://www.ppc.go.jp/en/legal/\n\nhttps://regulations.f
 ru.dev/regulations/jp-appi
URL:https://regulations.fru.dev/regulations/jp-appi
CATEGORIES:Japan,privacy,children,biometrics,breach-notification,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-7012@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20220411
DTEND;VALUE=DATE:20220412
SUMMARY:Singapore Cybersecurity Act: Cybersecurity service provider licensi
 ng commences
DESCRIPTION:Part 5 and the Second Schedule take effect. Penetration testing
  and managed SOC providers need a licence.\n\nCybersecurity Act 2018 (Sing
 apore)\n\nSource: https://sso.agc.gov.sg/Acts-Supp/9-2018/Published/202112
 31?DocDate=20180312\n\nhttps://regulations.fru.dev/regulations/sg-cybersec
 urity-act
URL:https://regulations.fru.dev/regulations/sg-cybersecurity-act
CATEGORIES:Singapore,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-142@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20220601
DTEND;VALUE=DATE:20220602
SUMMARY:Thailand PDPA: PDPA main obligations take effect
DESCRIPTION:Core data protection obligations and penalties apply after post
 ponement Royal Decrees.\n\nPersonal Data Protection Act B.E. 2562 (2019) (
 Thailand)\n\nSource: https://www.ratchakitcha.soc.go.th/DATA/PDF/2562/A/06
 9/T_0052.PDF\n\nhttps://regulations.fru.dev/regulations/th-pdpa
URL:https://regulations.fru.dev/regulations/th-pdpa
CATEGORIES:Thailand,privacy,breach-notification,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-63@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20220623
DTEND;VALUE=DATE:20220624
SUMMARY:Data Governance Act: DGA enters into force
DESCRIPTION:Entered into force on the twentieth day after publication in OJ
  L 152 of 3 June 2022 (Art 38).\n\nRegulation (EU) 2022/868 on European da
 ta governance (Data Governance Act) (European Union)\n\nSource: https://eu
 r-lex.europa.eu/eli/reg/2022/868/oj\n\nhttps://regulations.fru.dev/regulat
 ions/eu-dga
URL:https://regulations.fru.dev/regulations/eu-dga
CATEGORIES:European Union,data-access,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6991@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20220627
DTEND;VALUE=DATE:20220628
SUMMARY:India CERT-In Cyber Security Directions: CERT-In Directions take ef
 fect
DESCRIPTION:The Directions apply 60 days after issue on 28 Apr 2022. The ex
 act day (27 or 28 June 2022) depends on how the 60 days are counted.\n\nTe
 ntative: depends on a proposal not yet adopted.\n\nDirections under sectio
 n 70B(6) of the Information Technology Act\, 2000 relating to information 
 security practices\, procedure\, prevention\, response and reporting of cy
 ber incidents for Safe and Trusted Internet (India)\n\nSource: https://www
 .cert-in.org.in/PDF/CERT-In_Directions_70B_28.04.2022.pdf\n\nhttps://regul
 ations.fru.dev/regulations/in-certin-directions
URL:https://regulations.fru.dev/regulations/in-certin-directions
CATEGORIES:India,cybersecurity,breach-notification,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-7025@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20220708
DTEND;VALUE=DATE:20220709
SUMMARY:Australia SOCI Act: Mandatory cyber incident reporting starts for m
 ost assets
DESCRIPTION:The Application Rules registered on 7 April 2022 gave most asse
 t classes a 3-month grace period before Part 2B incident reporting applied
 . The date is worked out from that grace period.\n\nTentative: depends on 
 a proposal not yet adopted.\n\nSecurity of Critical Infrastructure Act 201
 8 (Australia)\n\nSource: https://www.legislation.gov.au/F2022L00562/asmade
 \n\nhttps://regulations.fru.dev/regulations/au-soci-act
URL:https://regulations.fru.dev/regulations/au-soci-act
CATEGORIES:Australia,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6977@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20220901
DTEND;VALUE=DATE:20220902
SUMMARY:China Data Export Security Assessment Measures: Security assessment
  measures take effect
DESCRIPTION:Covered data exports require a CAC security assessment.\n\nMeas
 ures for the Security Assessment of Outbound Data Transfers (China)\n\nSou
 rce: https://www.cac.gov.cn/2022-07/07/c_1658811536396503.htm\n\nhttps://r
 egulations.fru.dev/regulations/cn-sa-measures
URL:https://regulations.fru.dev/regulations/cn-sa-measures
CATEGORIES:China,data-residency,privacy,cybersecurity
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-22@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20220922
DTEND;VALUE=DATE:20220923
SUMMARY:Quebec Law 25: Phase 1: privacy officer and incident reporting
DESCRIPTION:Person in charge of personal information protection\, confident
 iality incident notification and register apply.\n\nAct to modernize legis
 lative provisions as regards the protection of personal information (Law 2
 5\, formerly Bill 64) (Quebec\, Canada)\n\nSource: https://www.legisquebec
 .gouv.qc.ca/en/document/cs/P-39.1\n\nhttps://regulations.fru.dev/regulatio
 ns/ca-qc-law25
URL:https://regulations.fru.dev/regulations/ca-qc-law25
CATEGORIES:Quebec\, Canada,privacy,breach-notification,biometrics
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6992@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20220925
DTEND;VALUE=DATE:20220926
SUMMARY:India CERT-In Cyber Security Directions: Extended date for MSMEs an
 d subscriber validation
DESCRIPTION:The Directions apply to micro\, small and medium enterprises\, 
 and subscriber validation duties apply to data centres\, VPS\, cloud and V
 PN providers\, from this date.\n\nDirections under section 70B(6) of the I
 nformation Technology Act\, 2000 relating to information security practice
 s\, procedure\, prevention\, response and reporting of cyber incidents for
  Safe and Trusted Internet (India)\n\nSource: https://www.cert-in.org.in/P
 DF/CERT-In_directions_extension_MSMEs_and_validation_27.06.2022.pdf\n\nhtt
 ps://regulations.fru.dev/regulations/in-certin-directions
URL:https://regulations.fru.dev/regulations/in-certin-directions
CATEGORIES:India,cybersecurity,breach-notification,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-141@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20221001
DTEND;VALUE=DATE:20221002
SUMMARY:Singapore PDPA: Higher financial penalty cap applies
DESCRIPTION:Maximum penalty rises to 10% of Singapore turnover for organiza
 tions with turnover above SGD 10 million.\n\nPersonal Data Protection Act 
 2012 (Singapore) (Singapore)\n\nSource: https://sso.agc.gov.sg/Act/PDPA201
 2\n\nhttps://regulations.fru.dev/regulations/sg-pdpa
URL:https://regulations.fru.dev/regulations/sg-pdpa
CATEGORIES:Singapore,privacy,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6876@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20221001
DTEND;VALUE=DATE:20221002
SUMMARY:UK Telecommunications Security Act: Security measures regulations i
 n force
DESCRIPTION:Electronic Communications (Security Measures) Regulations 2022 
 come into force.\n\nTelecommunications (Security) Act 2021 and the Electro
 nic Communications (Security Measures) Regulations 2022 (United Kingdom)\n
 \nSource: https://www.legislation.gov.uk/uksi/2022/933/made\n\nhttps://reg
 ulations.fru.dev/regulations/uk-telecom-security
URL:https://regulations.fru.dev/regulations/uk-telecom-security
CATEGORIES:United Kingdom,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-112@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20221017
DTEND;VALUE=DATE:20221018
SUMMARY:Indonesia PDP Law: PDP Law enacted and in force
DESCRIPTION:Law takes effect on enactment\, starting a 2-year transition.\n
 \nLaw No. 27 of 2022 on Personal Data Protection (Undang-Undang Pelindunga
 n Data Pribadi) (Indonesia)\n\nSource: https://peraturan.bpk.go.id/Details
 /229798/uu-no-27-tahun-2022\n\nhttps://regulations.fru.dev/regulations/id-
 pdp
URL:https://regulations.fru.dev/regulations/id-pdp
CATEGORIES:Indonesia,privacy,breach-notification,data-residency,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-66@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20221101
DTEND;VALUE=DATE:20221102
SUMMARY:Digital Markets Act: DMA enters into force
DESCRIPTION:Entered into force twenty days after publication\; certain proc
 edural articles apply from this date (Art 54).\n\nRegulation (EU) 2022/192
 5 on contestable and fair markets in the digital sector (Digital Markets A
 ct) (European Union)\n\nSource: https://eur-lex.europa.eu/eli/reg/2022/192
 5/oj\n\nhttps://regulations.fru.dev/regulations/eu-dma
URL:https://regulations.fru.dev/regulations/eu-dma
CATEGORIES:European Union,data-access,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-75@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20221116
DTEND;VALUE=DATE:20221117
SUMMARY:Digital Services Act: DSA enters into force
DESCRIPTION:Entered into force twenty days after publication\; VLOP designa
 tion provisions (Art 33(3)-(6)) and Commission enforcement sections apply 
 from this date (Art 93).\n\nRegulation (EU) 2022/2065 on a Single Market f
 or Digital Services (Digital Services Act) (European Union)\n\nSource: htt
 ps://eur-lex.europa.eu/eli/reg/2022/2065/oj\n\nhttps://regulations.fru.dev
 /regulations/eu-dsa
URL:https://regulations.fru.dev/regulations/eu-dsa
CATEGORIES:European Union,online-safety,children,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6873@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20221206
DTEND;VALUE=DATE:20221207
SUMMARY:UK PSTI Act (product security): Royal Assent
DESCRIPTION:PSTI Act receives Royal Assent.\n\nProduct Security and Telecom
 munications Infrastructure Act 2022 and the Product Security Regulations 2
 023 (United Kingdom)\n\nSource: https://www.legislation.gov.uk/ukpga/2022/
 46/introduction/enacted\n\nhttps://regulations.fru.dev/regulations/uk-psti
URL:https://regulations.fru.dev/regulations/uk-psti
CATEGORIES:United Kingdom,cybersecurity
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-165@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20230101
DTEND;VALUE=DATE:20230102
SUMMARY:CCPA / CPRA: CPRA amendments operative
DESCRIPTION:CPRA amendments (correction right\, sensitive PI limits\, shari
 ng opt-out\, employee/B2B data coverage) become operative.\n\nCalifornia C
 onsumer Privacy Act of 2018\, as amended by the California Privacy Rights 
 Act of 2020 (Cal. Civ. Code 1798.100 et seq.) and CPPA regulations (Cal. C
 ode Regs. tit. 11\, 7000 et seq.) (California)\n\nSource: https://cppa.ca.
 gov/regulations/pdf/ccpa_statute_eff_20260101.pdf\n\nhttps://regulations.f
 ru.dev/regulations/us-ca-ccpa
URL:https://regulations.fru.dev/regulations/us-ca-ccpa
CATEGORIES:California,privacy,ai,cybersecurity,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-311@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20230101
DTEND;VALUE=DATE:20230102
SUMMARY:Virginia VCDPA: VCDPA takes effect
DESCRIPTION:VCDPA obligations and consumer rights apply.\n\nVirginia Consum
 er Data Protection Act (SB 1392 / HB 2307\, 2021) (Virginia)\n\nSource: ht
 tps://law.lis.virginia.gov/vacode/title59.1/chapter53/\n\nhttps://regulati
 ons.fru.dev/regulations/us-va-vcdpa
URL:https://regulations.fru.dev/regulations/us-va-vcdpa
CATEGORIES:Virginia,privacy,children,online-safety
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6976@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20230110
DTEND;VALUE=DATE:20230111
SUMMARY:China Deep Synthesis Provisions: Deep synthesis provisions take eff
 ect
DESCRIPTION:Labeling\, identity verification and filing duties apply to dee
 p synthesis services.\n\nProvisions on the Administration of Deep Synthesi
 s in Internet Information Services (China)\n\nSource: https://www.cac.gov.
 cn/2022-12/11/c_1672221949354811.htm\n\nhttps://regulations.fru.dev/regula
 tions/cn-deep-synthesis
URL:https://regulations.fru.dev/regulations/cn-deep-synthesis
CATEGORIES:China,ai,online-safety,biometrics
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-70@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20230116
DTEND;VALUE=DATE:20230117
SUMMARY:DORA: DORA enters into force
DESCRIPTION:Entered into force on the twentieth day after publication in OJ
  L 333 of 27 Dec 2022 (Art 64).\n\nRegulation (EU) 2022/2554 on digital op
 erational resilience for the financial sector (Digital Operational Resilie
 nce Act) (European Union)\n\nSource: https://eur-lex.europa.eu/eli/reg/202
 2/2554/oj\n\nhttps://regulations.fru.dev/regulations/eu-dora
URL:https://regulations.fru.dev/regulations/eu-dora
CATEGORIES:European Union,cybersecurity,financial,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-98@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20230116
DTEND;VALUE=DATE:20230117
SUMMARY:NIS2: NIS2 enters into force
DESCRIPTION:Directive entered into force on the twentieth day after publica
 tion in OJ L 333 of 27 Dec 2022.\n\nDirective (EU) 2022/2555 on measures f
 or a high common level of cybersecurity across the Union (NIS2 Directive) 
 (European Union)\n\nSource: https://eur-lex.europa.eu/eli/dir/2022/2555/oj
 \n\nhttps://regulations.fru.dev/regulations/eu-nis2
URL:https://regulations.fru.dev/regulations/eu-nis2
CATEGORIES:European Union,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-76@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20230217
DTEND;VALUE=DATE:20230218
SUMMARY:Digital Services Act: Platforms publish EU user numbers
DESCRIPTION:Online platforms and search engines had to publish average mont
 hly active EU recipients\, and must update them at least every six months 
 (Art 24(2)).\n\nRegulation (EU) 2022/2065 on a Single Market for Digital S
 ervices (Digital Services Act) (European Union)\n\nSource: https://eur-lex
 .europa.eu/eli/reg/2022/2065/oj\n\nhttps://regulations.fru.dev/regulations
 /eu-dsa
URL:https://regulations.fru.dev/regulations/eu-dsa
CATEGORIES:European Union,online-safety,children,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6978@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20230301
DTEND;VALUE=DATE:20230302
SUMMARY:China Data Export Security Assessment Measures: Remediation window 
 for existing transfers ends
DESCRIPTION:Existing exports had to be remediated within six months of 2022
 -09-01. The exact end date is computed\, not stated.\n\nTentative: depends
  on a proposal not yet adopted.\n\nMeasures for the Security Assessment of
  Outbound Data Transfers (China)\n\nSource: https://www.cac.gov.cn/2022-07
 /07/c_1658811536396503.htm\n\nhttps://regulations.fru.dev/regulations/cn-s
 a-measures
URL:https://regulations.fru.dev/regulations/cn-sa-measures
CATEGORIES:China,data-residency,privacy,cybersecurity
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-77@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20230425
DTEND;VALUE=DATE:20230426
SUMMARY:Digital Services Act: First VLOP/VLOSE designations
DESCRIPTION:Commission designated the first 19 very large online platforms 
 and search engines (e.g. Amazon Store\, Facebook\, Google Search\, TikTok\
 , X). Obligations apply four months after notification.\n\nRegulation (EU)
  2022/2065 on a Single Market for Digital Services (Digital Services Act) 
 (European Union)\n\nSource: https://digital-strategy.ec.europa.eu/en/polic
 ies/list-designated-vlops-and-vloses\n\nhttps://regulations.fru.dev/regula
 tions/eu-dsa
URL:https://regulations.fru.dev/regulations/eu-dsa
CATEGORIES:European Union,online-safety,children,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-317@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20230427
DTEND;VALUE=DATE:20230428
SUMMARY:Washington My Health My Data Act: HB 1155 signed
DESCRIPTION:Governor signs My Health My Data Act.\n\nWashington My Health M
 y Data Act (HB 1155\, Laws of 2023\, ch. 191\; RCW 19.373) (Washington)\n\
 nSource: https://app.leg.wa.gov/billsummary?BillNumber=1155&Year=2023\n\nh
 ttps://regulations.fru.dev/regulations/us-wa-mhmda
URL:https://regulations.fru.dev/regulations/us-wa-mhmda
CATEGORIES:Washington,health,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-67@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20230502
DTEND;VALUE=DATE:20230503
SUMMARY:Digital Markets Act: DMA applies
DESCRIPTION:DMA becomes applicable\; undertakings meeting thresholds must n
 otify the Commission within two months (Arts 3(3)\, 54).\n\nRegulation (EU
 ) 2022/1925 on contestable and fair markets in the digital sector (Digital
  Markets Act) (European Union)\n\nSource: https://eur-lex.europa.eu/eli/re
 g/2022/1925/oj\n\nhttps://regulations.fru.dev/regulations/eu-dma
URL:https://regulations.fru.dev/regulations/eu-dma
CATEGORIES:European Union,data-access,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-7000@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20230531
DTEND;VALUE=DATE:20230601
SUMMARY:Taiwan PDPA: Higher fines take effect
DESCRIPTION:Amended article 48 with higher fines for security failures take
 s effect on promulgation.\n\nPersonal Data Protection Act (Taiwan)\n\nSour
 ce: https://law.moj.gov.tw/LawClass/LawHistory.aspx?pcode=I0050021\n\nhttp
 s://regulations.fru.dev/regulations/tw-pdpa
URL:https://regulations.fru.dev/regulations/tw-pdpa
CATEGORIES:Taiwan,privacy,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6979@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20230601
DTEND;VALUE=DATE:20230602
SUMMARY:China PI Export Standard Contract Measures: Standard contract measu
 res take effect
DESCRIPTION:The standard contract route and filing duty apply.\n\nMeasures 
 on the Standard Contract for Outbound Transfer of Personal Information (Ch
 ina)\n\nSource: https://www.cac.gov.cn/2023-02/24/c_1678884830036813.htm\n
 \nhttps://regulations.fru.dev/regulations/cn-scc-measures
URL:https://regulations.fru.dev/regulations/cn-scc-measures
CATEGORIES:China,data-residency,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-234@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20230609
DTEND;VALUE=DATE:20230610
SUMMARY:GLBA Safeguards Rule: Compliance with expanded security program ele
 ments
DESCRIPTION:Applicability of the 314.5 provisions (qualified individual\, w
 ritten risk assessment\, encryption\, MFA\, pen testing\, incident respons
 e plan\, board reporting) was delayed from December 9\, 2022 to this date.
 \n\nFTC Standards for Safeguarding Customer Information (Safeguards Rule)\
 , 16 CFR Part 314\, under the Gramm-Leach-Bliley Act (United States (Feder
 al))\n\nSource: https://www.federalregister.gov/documents/2022/11/23/2022-
 25201/standards-for-safeguarding-customer-information\n\nhttps://regulatio
 ns.fru.dev/regulations/us-glba-safeguards
URL:https://regulations.fru.dev/regulations/us-glba-safeguards
CATEGORIES:United States (Federal),financial,cybersecurity,breach-notificat
 ion,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-132@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20230612
DTEND;VALUE=DATE:20230613
SUMMARY:Nigeria NDPA: NDPA signed into law
DESCRIPTION:President signs the Nigeria Data Protection Act\, 2023.\n\nNige
 ria Data Protection Act\, 2023 and NDPA General Application and Implementa
 tion Directive (GAID) 2025 (Nigeria)\n\nSource: https://ndpc.gov.ng/resour
 ces/\n\nhttps://regulations.fru.dev/regulations/ng-ndpa
URL:https://regulations.fru.dev/regulations/ng-ndpa
CATEGORIES:Nigeria,privacy,breach-notification,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6922@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20230616
DTEND;VALUE=DATE:20230617
SUMMARY:Nevada consumer health data law: Approved by Governor
DESCRIPTION:Chapter 525\, Statutes of Nevada 2023.\n\nNevada Consumer Healt
 h Data Privacy Law (SB 370) (Nevada)\n\nSource: https://www.leg.state.nv.u
 s/App/NELIS/REL/82nd2023/Bill/10323/Overview\n\nhttps://regulations.fru.de
 v/regulations/us-nv-sb370
URL:https://regulations.fru.dev/regulations/us-nv-sb370
CATEGORIES:Nevada,health,privacy,biometrics
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6869@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20230628
DTEND;VALUE=DATE:20230629
SUMMARY:EU Financial Data Access (FIDA) proposal: FIDA proposed
DESCRIPTION:Commission adopts the proposal together with the payment servic
 es package.\n\nProposal for a Regulation on a framework for Financial Data
  Access (FIDA) (European Union)\n\nSource: https://publications.europa.eu/
 resource/celex/52023PC0360\n\nhttps://regulations.fru.dev/regulations/eu-f
 ida
URL:https://regulations.fru.dev/regulations/eu-fida
CATEGORIES:European Union,financial,data-access,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-207@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20230701
DTEND;VALUE=DATE:20230702
SUMMARY:Colorado Privacy Act (CPA): CPA takes effect
DESCRIPTION:Core consumer rights and controller duties apply.\n\nColorado P
 rivacy Act (SB 21-190)\, C.R.S. 6-1-1301 et seq.\, as amended by HB 24-113
 0\, SB 24-041 and SB 25-276 (Colorado)\n\nSource: https://leg.colorado.gov
 /bills/sb21-190\n\nhttps://regulations.fru.dev/regulations/us-co-cpa
URL:https://regulations.fru.dev/regulations/us-co-cpa
CATEGORIES:Colorado,privacy,children,biometrics
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-215@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20230701
DTEND;VALUE=DATE:20230702
SUMMARY:Connecticut Data Privacy Act (CTDPA): CTDPA takes effect
DESCRIPTION:Core consumer rights and controller obligations apply.\n\nConne
 cticut Data Privacy Act (Public Act 22-15)\, Conn. Gen. Stat. 42-515 et se
 q.\, as amended by Public Act 25-113 (SB 1295) and Public Act 26-64 (SB 4)
  (Connecticut)\n\nSource: https://www.cga.ct.gov/asp/cgabillstatus/cgabill
 status.asp?selBillType=Bill&which_year=2022&bill_num=6\n\nhttps://regulati
 ons.fru.dev/regulations/us-ct-ctdpa
URL:https://regulations.fru.dev/regulations/us-ct-ctdpa
CATEGORIES:Connecticut,privacy,children,ai,health
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-281@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20230705
DTEND;VALUE=DATE:20230706
SUMMARY:NYC Local Law 144 (AEDT): DCWP enforcement begins
DESCRIPTION:Bias audit\, results publication and candidate notice requireme
 nts are enforced.\n\nNew York City Local Law 144 of 2021\, Automated Emplo
 yment Decision Tools (NYC Admin. Code 20-870 et seq.) (New York City\, New
  York)\n\nSource: https://www.nyc.gov/site/dca/about/automated-employment-
 decision-tools.page\n\nhttps://regulations.fru.dev/regulations/us-nyc-ll14
 4
URL:https://regulations.fru.dev/regulations/us-nyc-ll144
CATEGORIES:New York City\, New York,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6961@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20230705
DTEND;VALUE=DATE:20230706
SUMMARY:Peru AI Law and Regulation: Law 31814 published
DESCRIPTION:AI promotion law published.\n\nLey N° 31814\, Ley que promueve
  el uso de la inteligencia artificial en favor del desarrollo económico y
  social del país\, and its Regulation (Decreto Supremo N° 115-2025-PCM) 
 (Peru)\n\nSource: https://www.gob.pe/institucion/congreso-de-la-republica/
 normas-legales/4565760-31814\n\nhttps://regulations.fru.dev/regulations/pe
 -ai-law
URL:https://regulations.fru.dev/regulations/pe-ai-law
CATEGORIES:Peru,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-108@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20230710
DTEND;VALUE=DATE:20230711
SUMMARY:EU-US Data Privacy Framework: DPF adequacy decision adopted and eff
 ective
DESCRIPTION:Commission adopted Implementing Decision (EU) 2023/1795\, effec
 tive on notification to Member States\; EU-US transfers to DPF-certified o
 rganisations may proceed without additional safeguards.\n\nCommission Impl
 ementing Decision (EU) 2023/1795 on the adequate level of protection of pe
 rsonal data under the EU-US Data Privacy Framework (European Union)\n\nSou
 rce: https://eur-lex.europa.eu/eli/dec_impl/2023/1795/oj\n\nhttps://regula
 tions.fru.dev/regulations/eu-us-dpf
URL:https://regulations.fru.dev/regulations/eu-us-dpf
CATEGORIES:European Union,privacy,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-318@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20230723
DTEND;VALUE=DATE:20230724
SUMMARY:Washington My Health My Data Act: Geofencing ban (Section 10) effec
 tive
DESCRIPTION:Ban on geofencing around health care facilities applies to all 
 persons.\n\nWashington My Health My Data Act (HB 1155\, Laws of 2023\, ch.
  191\; RCW 19.373) (Washington)\n\nSource: https://www.atg.wa.gov/protecti
 ng-washingtonians-personal-health-data-and-privacy\n\nhttps://regulations.
 fru.dev/regulations/us-wa-mhmda
URL:https://regulations.fru.dev/regulations/us-wa-mhmda
CATEGORIES:Washington,health,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6974@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20230815
DTEND;VALUE=DATE:20230816
SUMMARY:China Generative AI Measures: Generative AI measures take effect
DESCRIPTION:Training data\, labeling\, content and user protection duties a
 pply to public generative AI services.\n\nInterim Measures for the Managem
 ent of Generative Artificial Intelligence Services (China)\n\nSource: http
 s://www.cac.gov.cn/2023-07/13/c_1690898327029107.htm\n\nhttps://regulation
 s.fru.dev/regulations/cn-genai-measures
URL:https://regulations.fru.dev/regulations/cn-genai-measures
CATEGORIES:China,ai,online-safety,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6864@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20230817
DTEND;VALUE=DATE:20230818
SUMMARY:EU e-Evidence Package: Package enters into force
DESCRIPTION:Published in the OJ on 2023-07-28\; enters into force on the 20
 th day.\n\nRegulation (EU) 2023/1543 on European Production Orders and Eur
 opean Preservation Orders for electronic evidence in criminal proceedings\
 , and Directive (EU) 2023/1544 on legal representatives (European Union)\n
 \nSource: https://eur-lex.europa.eu/eli/reg/2023/1543/oj/eng\n\nhttps://re
 gulations.fru.dev/regulations/eu-e-evidence
URL:https://regulations.fru.dev/regulations/eu-e-evidence
CATEGORIES:European Union,privacy,data-access
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-25@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20230901
DTEND;VALUE=DATE:20230902
SUMMARY:Swiss revised FADP (nFADP): Revised FADP enters into force
DESCRIPTION:Revised FADP and Data Protection Ordinance apply with no transi
 tion period.\n\nFederal Act on Data Protection (revised FADP) of 25 Septem
 ber 2020 (Switzerland)\n\nSource: https://www.fedlex.admin.ch/eli/cc/2022/
 491/en\n\nhttps://regulations.fru.dev/regulations/ch-fadp
URL:https://regulations.fru.dev/regulations/ch-fadp
CATEGORIES:Switzerland,privacy,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-68@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20230906
DTEND;VALUE=DATE:20230907
SUMMARY:Digital Markets Act: First six gatekeepers designated
DESCRIPTION:Commission designated Alphabet\, Amazon\, Apple\, ByteDance\, M
 eta and Microsoft (22 core platform services). They had six months to full
 y comply.\n\nRegulation (EU) 2022/1925 on contestable and fair markets in 
 the digital sector (Digital Markets Act) (European Union)\n\nSource: https
 ://digital-markets-act.ec.europa.eu/gatekeepers_en\n\nhttps://regulations.
 fru.dev/regulations/eu-dma
URL:https://regulations.fru.dev/regulations/eu-dma
CATEGORIES:European Union,data-access,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-137@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20230914
DTEND;VALUE=DATE:20230915
SUMMARY:Saudi PDPL: PDPL in force
DESCRIPTION:PDPL and its implementing regulations take effect.\n\nPersonal 
 Data Protection Law (Royal Decree M/19 of 9/2/1443H\, as amended by Royal 
 Decree M/148 of 5/9/1444H) (Saudi Arabia)\n\nSource: https://sdaia.gov.sa/
 en/SDAIA/about/Documents/Personal%20Data%20English%20V2-23April2023-%20Rev
 iewed-.pdf\n\nhttps://regulations.fru.dev/regulations/sa-pdpl
URL:https://regulations.fru.dev/regulations/sa-pdpl
CATEGORIES:Saudi Arabia,privacy,data-residency,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-23@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20230922
DTEND;VALUE=DATE:20230923
SUMMARY:Quebec Law 25: Phase 2: main obligations and penalties
DESCRIPTION:Governance policies\, PIAs\, consent\, transparency\, privacy b
 y default\, ADM notices\, cross-border PIAs and AMP/penal regime apply.\n\
 nAct to modernize legislative provisions as regards the protection of pers
 onal information (Law 25\, formerly Bill 64) (Quebec\, Canada)\n\nSource: 
 https://www.legisquebec.gouv.qc.ca/en/document/cs/P-39.1\n\nhttps://regula
 tions.fru.dev/regulations/ca-qc-law25
URL:https://regulations.fru.dev/regulations/ca-qc-law25
CATEGORIES:Quebec\, Canada,privacy,breach-notification,biometrics
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-64@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20230924
DTEND;VALUE=DATE:20230925
SUMMARY:Data Governance Act: DGA applies
DESCRIPTION:All DGA rules apply (Art 38).\n\nRegulation (EU) 2022/868 on Eu
 ropean data governance (Data Governance Act) (European Union)\n\nSource: h
 ttps://eur-lex.europa.eu/eli/reg/2022/868/oj\n\nhttps://regulations.fru.de
 v/regulations/eu-dga
URL:https://regulations.fru.dev/regulations/eu-dga
CATEGORIES:European Union,data-access,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-7035@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20231015
DTEND;VALUE=DATE:20231016
SUMMARY:Rwanda DPP Law: Two-year transition ends
DESCRIPTION:Article 67 gave controllers and processors already operating tw
 o years from publication to comply.\n\nLaw No. 058/2021 of 13/10/2021 rela
 ting to the Protection of Personal Data and Privacy (Rwanda)\n\nSource: ht
 tps://www.minijust.gov.rw/fileadmin/user_upload/Minijust/Official_gazettes
 _2/_________2021_Official_Gazettes/October/OG_Special_of_15.10.2021_Amakur
 u_bwite.pdf\n\nhttps://regulations.fru.dev/regulations/rw-dpp
URL:https://regulations.fru.dev/regulations/rw-dpp
CATEGORIES:Rwanda,privacy,data-residency,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-156@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20231026
DTEND;VALUE=DATE:20231027
SUMMARY:UK Online Safety Act: Royal Assent
DESCRIPTION:The Online Safety Act receives Royal Assent.\n\nOnline Safety A
 ct 2023 (United Kingdom)\n\nSource: https://www.legislation.gov.uk/ukpga/2
 023/50/contents\n\nhttps://regulations.fru.dev/regulations/uk-osa
URL:https://regulations.fru.dev/regulations/uk-osa
CATEGORIES:United Kingdom,online-safety,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-270@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20231101
DTEND;VALUE=DATE:20231102
SUMMARY:NYDFS Cybersecurity Regulation (Part 500): Second Amendment effecti
 ve
DESCRIPTION:Second Amendment takes effect\; 500.19(e)-(h)\, 500.20\, 500.21
 \, 500.22 and 500.24 apply immediately.\n\nNew York DFS Cybersecurity Requ
 irements for Financial Services Companies (23 NYCRR Part 500)\, Second Ame
 ndment (New York)\n\nSource: https://www.dfs.ny.gov/cybersecurity/23-NYCRR
 -Part-500\n\nhttps://regulations.fru.dev/regulations/us-ny-dfs-500
URL:https://regulations.fru.dev/regulations/us-ny-dfs-500
CATEGORIES:New York,cybersecurity,breach-notification,financial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6980@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20231201
DTEND;VALUE=DATE:20231202
SUMMARY:China PI Export Standard Contract Measures: Remediation window for 
 existing transfers ends
DESCRIPTION:Existing exports had to comply within six months of 2023-06-01.
  The exact end date is computed\, not stated.\n\nTentative: depends on a p
 roposal not yet adopted.\n\nMeasures on the Standard Contract for Outbound
  Transfer of Personal Information (China)\n\nSource: https://www.cac.gov.c
 n/2023-02/24/c_1678884830036813.htm\n\nhttps://regulations.fru.dev/regulat
 ions/cn-scc-measures
URL:https://regulations.fru.dev/regulations/cn-scc-measures
CATEGORIES:China,data-residency,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-271@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20231201
DTEND;VALUE=DATE:20231202
SUMMARY:NYDFS Cybersecurity Regulation (Part 500): Amended notification req
 uirements (500.17)
DESCRIPTION:New 72-hour event notice\, 24-hour extortion payment notice and
  certification changes apply (30 days).\n\nNew York DFS Cybersecurity Requ
 irements for Financial Services Companies (23 NYCRR Part 500)\, Second Ame
 ndment (New York)\n\nSource: https://www.dfs.ny.gov/cybersecurity/23-NYCRR
 -Part-500\n\nhttps://regulations.fru.dev/regulations/us-ny-dfs-500
URL:https://regulations.fru.dev/regulations/us-ny-dfs-500
CATEGORIES:New York,cybersecurity,breach-notification,financial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-290@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20231215
DTEND;VALUE=DATE:20231216
SUMMARY:SEC Cyber Disclosure Rules: Annual cybersecurity disclosures begin 
 (Item 106 / 16K)
DESCRIPTION:Required in annual reports for fiscal years ending on or after 
 this date.\n\nSEC Cybersecurity Risk Management\, Strategy\, Governance\, 
 and Incident Disclosure (Release No. 33-11216) (United States (Federal))\n
 \nSource: https://www.federalregister.gov/documents/2023/08/04/2023-16194/
 cybersecurity-risk-management-strategy-governance-and-incident-disclosure\
 n\nhttps://regulations.fru.dev/regulations/us-sec-cyber
URL:https://regulations.fru.dev/regulations/us-sec-cyber
CATEGORIES:United States (Federal),cybersecurity,breach-notification,financ
 ial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-291@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20231218
DTEND;VALUE=DATE:20231219
SUMMARY:SEC Cyber Disclosure Rules: Form 8-K Item 1.05 incident disclosure 
 begins
DESCRIPTION:All registrants other than smaller reporting companies must fil
 e material incident disclosures from this date.\n\nSEC Cybersecurity Risk 
 Management\, Strategy\, Governance\, and Incident Disclosure (Release No. 
 33-11216) (United States (Federal))\n\nSource: https://www.federalregister
 .gov/documents/2023/08/04/2023-16194/cybersecurity-risk-management-strateg
 y-governance-and-incident-disclosure\n\nhttps://regulations.fru.dev/regula
 tions/us-sec-cyber
URL:https://regulations.fru.dev/regulations/us-sec-cyber
CATEGORIES:United States (Federal),cybersecurity,breach-notification,financ
 ial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-308@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20231231
DTEND;VALUE=DATE:20240101
SUMMARY:Utah UCPA: UCPA takes effect
DESCRIPTION:Utah Consumer Privacy Act obligations and consumer rights apply
 .\n\nUtah Consumer Privacy Act (SB 227\, 2022) (Utah)\n\nSource: https://l
 e.utah.gov/xcode/Title13/Chapter61/13-61-S402.html\n\nhttps://regulations.
 fru.dev/regulations/us-ut-ucpa
URL:https://regulations.fru.dev/regulations/us-ut-ucpa
CATEGORIES:Utah,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6983@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20240101
DTEND;VALUE=DATE:20240102
SUMMARY:China Minors Online Protection Regulations: Minors online protectio
 n regulations take effect
DESCRIPTION:Platform\, content\, personal information and anti-addiction du
 ties apply.\n\nRegulations on the Protection of Minors Online (China)\n\nS
 ource: https://www.cac.gov.cn/2023-10/24/c_1699806932316206.htm\n\nhttps:/
 /regulations.fru.dev/regulations/cn-minors-online-protection
URL:https://regulations.fru.dev/regulations/cn-minors-online-protection
CATEGORIES:China,children,privacy,online-safety
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-7001@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20240101
DTEND;VALUE=DATE:20240102
SUMMARY:Taiwan PDPA: PDPC Preparatory Office takes over
DESCRIPTION:The PDPC Preparatory Office takes over PDPA duties from the Nat
 ional Development Council.\n\nPersonal Data Protection Act (Taiwan)\n\nSou
 rce: https://law.moj.gov.tw/LawClass/LawHistory.aspx?pcode=I0050021\n\nhtt
 ps://regulations.fru.dev/regulations/tw-pdpa
URL:https://regulations.fru.dev/regulations/tw-pdpa
CATEGORIES:Taiwan,privacy,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-55@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20240111
DTEND;VALUE=DATE:20240112
SUMMARY:EU Data Act: Data Act enters into force
DESCRIPTION:Entered into force on the twentieth day after publication in th
 e OJ on 22 Dec 2023 (Art 50).\n\nRegulation (EU) 2023/2854 on harmonised r
 ules on fair access to and use of data (Data Act) (European Union)\n\nSour
 ce: https://eur-lex.europa.eu/eli/reg/2023/2854/oj\n\nhttps://regulations.
 fru.dev/regulations/eu-data-act
URL:https://regulations.fru.dev/regulations/eu-data-act
CATEGORIES:European Union,data-access,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-56@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20240111
DTEND;VALUE=DATE:20240112
SUMMARY:EU Data Act: Reduced switching charges period begins
DESCRIPTION:From 11 Jan 2024 to 12 Jan 2027\, data processing providers may
  charge only reduced switching fees\, capped at costs directly linked to s
 witching (Art 29(2)-(3)).\n\nRegulation (EU) 2023/2854 on harmonised rules
  on fair access to and use of data (Data Act) (European Union)\n\nSource: 
 https://eur-lex.europa.eu/eli/reg/2023/2854/oj\n\nhttps://regulations.fru.
 dev/regulations/eu-data-act
URL:https://regulations.fru.dev/regulations/eu-data-act
CATEGORIES:European Union,data-access,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-78@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20240217
DTEND;VALUE=DATE:20240218
SUMMARY:Digital Services Act: DSA applies to all intermediary services
DESCRIPTION:Full application to all providers of intermediary services (Art
  93(2)).\n\nRegulation (EU) 2022/2065 on a Single Market for Digital Servi
 ces (Digital Services Act) (European Union)\n\nSource: https://eur-lex.eur
 opa.eu/eli/reg/2022/2065/oj\n\nhttps://regulations.fru.dev/regulations/eu-
 dsa
URL:https://regulations.fru.dev/regulations/eu-dsa
CATEGORIES:European Union,online-safety,children,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-69@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20240307
DTEND;VALUE=DATE:20240308
SUMMARY:Digital Markets Act: Gatekeeper compliance deadline (first designat
 ions)
DESCRIPTION:First-wave gatekeepers had to comply with Arts 5-7 obligations 
 and submit compliance reports six months after the 6 Sep 2023 designation.
 \n\nRegulation (EU) 2022/1925 on contestable and fair markets in the digit
 al sector (Digital Markets Act) (European Union)\n\nSource: https://ec.eur
 opa.eu/commission/presscorner/detail/en/ip_23_4328\n\nhttps://regulations.
 fru.dev/regulations/eu-dma
URL:https://regulations.fru.dev/regulations/eu-dma
CATEGORIES:European Union,data-access,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-229@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20240313
DTEND;VALUE=DATE:20240314
SUMMARY:FCC CPNI Breach Rule: Order effective except revised notification r
 ules
DESCRIPTION:Definitions and other parts of the order took effect\; the revi
 sed 64.2011 and 64.5111 notification requirements were delayed pending OMB
  approval.\n\nFCC Data Breach Reporting Requirements for telecommunication
 s carriers\, interconnected VoIP and TRS providers (47 CFR 64.2011\, 64.51
 11) (United States (Federal))\n\nSource: https://www.federalregister.gov/d
 ocuments/2024/02/12/2024-01667/data-breach-reporting-requirements\n\nhttps
 ://regulations.fru.dev/regulations/us-fcc-cpni-breach
URL:https://regulations.fru.dev/regulations/us-fcc-cpni-breach
CATEGORIES:United States (Federal),privacy,breach-notification,cybersecurit
 y
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-30@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20240322
DTEND;VALUE=DATE:20240323
SUMMARY:China Cross-Border Data Flow Provisions: Cross-border data flow pro
 visions take effect
DESCRIPTION:Exemptions and volume thresholds apply from publication (Art. 1
 4)\; security assessment results are valid for 3 years (Art. 9).\n\nProvis
 ions on Promoting and Regulating Cross-Border Data Flows (CAC Order No. 16
 ) (China)\n\nSource: https://www.cac.gov.cn/2024-03/22/c_1712776611775634.
 htm\n\nhttps://regulations.fru.dev/regulations/cn-cross-border
URL:https://regulations.fru.dev/regulations/cn-cross-border
CATEGORIES:China,data-residency,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6920@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20240326
DTEND;VALUE=DATE:20240327
SUMMARY:Tennessee ELVIS Act: Signed by Governor
DESCRIPTION:Became Public Chapter 588.\n\nEnsuring Likeness\, Voice\, and I
 mage Security Act of 2024 (ELVIS Act) (Tennessee)\n\nSource: https://wapp.
 capitol.tn.gov/apps/BillInfo/Default.aspx?BillNumber=HB2091&GA=113\n\nhttp
 s://regulations.fru.dev/regulations/us-tn-elvis
URL:https://regulations.fru.dev/regulations/us-tn-elvis
CATEGORIES:Tennessee,ai,privacy,biometrics
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6923@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20240331
DTEND;VALUE=DATE:20240401
SUMMARY:Nevada consumer health data law: Takes effect
DESCRIPTION:Section 36: act effective March 31\, 2024.\n\nNevada Consumer H
 ealth Data Privacy Law (SB 370) (Nevada)\n\nSource: https://www.leg.state.
 nv.us/Session/82nd2023/Bills/SB/SB370_EN.pdf\n\nhttps://regulations.fru.de
 v/regulations/us-nv-sb370
URL:https://regulations.fru.dev/regulations/us-nv-sb370
CATEGORIES:Nevada,health,privacy,biometrics
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-319@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20240331
DTEND;VALUE=DATE:20240401
SUMMARY:Washington My Health My Data Act: Regulated entities must comply
DESCRIPTION:Sections 4-9 (privacy policy\, consent\, consumer rights\, sale
  authorization) apply to regulated entities.\n\nWashington My Health My Da
 ta Act (HB 1155\, Laws of 2023\, ch. 191\; RCW 19.373) (Washington)\n\nSou
 rce: https://www.atg.wa.gov/protecting-washingtonians-personal-health-data
 -and-privacy\n\nhttps://regulations.fru.dev/regulations/us-wa-mhmda
URL:https://regulations.fru.dev/regulations/us-wa-mhmda
CATEGORIES:Washington,health,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6847@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20240409
DTEND;VALUE=DATE:20240410
SUMMARY:EU Political Advertising Regulation (TTPA): TTPA enters into force
DESCRIPTION:Published in the OJ on 2024-03-20\; enters into force on the 20
 th day. Articles 3 and 5(1) apply from this date.\n\nRegulation (EU) 2024/
 900 on the transparency and targeting of political advertising (European U
 nion)\n\nSource: https://eur-lex.europa.eu/eli/reg/2024/900/oj/eng\n\nhttp
 s://regulations.fru.dev/regulations/eu-ttpa
URL:https://regulations.fru.dev/regulations/eu-ttpa
CATEGORIES:European Union,privacy,online-safety
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6855@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20240411
DTEND;VALUE=DATE:20240412
SUMMARY:Interoperable Europe Act: Act enters into force
DESCRIPTION:Published in the OJ on 2024-03-22\; enters into force on the 20
 th day.\n\nRegulation (EU) 2024/903 laying down measures for a high level 
 of public sector interoperability across the Union (Interoperable Europe A
 ct) (European Union)\n\nSource: https://eur-lex.europa.eu/eli/reg/2024/903
 /oj/eng\n\nhttps://regulations.fru.dev/regulations/eu-interoperable-europe
URL:https://regulations.fru.dev/regulations/eu-interoperable-europe
CATEGORIES:European Union,data-access
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-272@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20240415
DTEND;VALUE=DATE:20240416
SUMMARY:NYDFS Cybersecurity Regulation (Part 500): Annual compliance notifi
 cation
DESCRIPTION:Certification of compliance or acknowledgment of non-compliance
  due (recurs every April 15).\n\nNew York DFS Cybersecurity Requirements f
 or Financial Services Companies (23 NYCRR Part 500)\, Second Amendment (Ne
 w York)\n\nSource: https://www.dfs.ny.gov/cybersecurity/23-NYCRR-Part-500\
 n\nhttps://regulations.fru.dev/regulations/us-ny-dfs-500
URL:https://regulations.fru.dev/regulations/us-ny-dfs-500
CATEGORIES:New York,cybersecurity,breach-notification,financial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6877@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20240425
DTEND;VALUE=DATE:20240426
SUMMARY:UK Investigatory Powers (Amendment) Act 2024: Royal Assent
DESCRIPTION:Investigatory Powers (Amendment) Act 2024 receives Royal Assent
 .\n\nInvestigatory Powers (Amendment) Act 2024 (United Kingdom)\n\nSource:
  https://www.legislation.gov.uk/ukpga/2024/9/introduction/enacted\n\nhttps
 ://regulations.fru.dev/regulations/uk-ipa-2024
URL:https://regulations.fru.dev/regulations/uk-ipa-2024
CATEGORIES:United Kingdom,privacy,data-access,cybersecurity
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-273@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20240429
DTEND;VALUE=DATE:20240430
SUMMARY:NYDFS Cybersecurity Regulation (Part 500): General 180-day transiti
 on ends
DESCRIPTION:Most new Second Amendment requirements apply\, e.g. annual repo
 rting to the board and risk assessment updates.\n\nNew York DFS Cybersecur
 ity Requirements for Financial Services Companies (23 NYCRR Part 500)\, Se
 cond Amendment (New York)\n\nSource: https://www.dfs.ny.gov/cybersecurity/
 23-NYCRR-Part-500\n\nhttps://regulations.fru.dev/regulations/us-ny-dfs-500
URL:https://regulations.fru.dev/regulations/us-ny-dfs-500
CATEGORIES:New York,cybersecurity,breach-notification,financial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6874@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20240429
DTEND;VALUE=DATE:20240430
SUMMARY:UK PSTI Act (product security): Product security requirements apply
DESCRIPTION:Security requirements regulations (SI 2023/1007) come into forc
 e.\n\nProduct Security and Telecommunications Infrastructure Act 2022 and 
 the Product Security Regulations 2023 (United Kingdom)\n\nSource: https://
 www.legislation.gov.uk/uksi/2023/1007/made\n\nhttps://regulations.fru.dev/
 regulations/uk-psti
URL:https://regulations.fru.dev/regulations/uk-psti
CATEGORIES:United Kingdom,cybersecurity
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-305@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20240501
DTEND;VALUE=DATE:20240502
SUMMARY:Utah AI Policy Act: AI Policy Act effective
DESCRIPTION:Generative AI disclosure duties and the Office of AI Policy tak
 e effect.\n\nUtah Artificial Intelligence Policy Act (SB 149\, 2024)\, as 
 amended by SB 226 and SB 332 (2025) (Utah)\n\nSource: https://le.utah.gov/
 ~2024/bills/static/SB0149.html\n\nhttps://regulations.fru.dev/regulations/
 us-ut-aipa
URL:https://regulations.fru.dev/regulations/us-ut-aipa
CATEGORIES:Utah,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6933@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20240509
DTEND;VALUE=DATE:20240510
SUMMARY:Maryland Kids Code: Approved by Governor
DESCRIPTION:Chapter 461 of 2024.\n\nMaryland Age-Appropriate Design Code Ac
 t (Maryland Kids Code\, HB 603) (Maryland)\n\nSource: https://mgaleg.maryl
 and.gov/mgawebsite/Legislation/Details/hb0603?ys=2024RS\n\nhttps://regulat
 ions.fru.dev/regulations/us-md-kids-code
URL:https://regulations.fru.dev/regulations/us-md-kids-code
CATEGORIES:Maryland,children,privacy,online-safety
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-235@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20240513
DTEND;VALUE=DATE:20240514
SUMMARY:GLBA Safeguards Rule: FTC breach notification requirement effective
DESCRIPTION:Section 314.4(j) requires notice to the FTC within 30 days of d
 iscovering a notification event involving at least 500 consumers.\n\nFTC S
 tandards for Safeguarding Customer Information (Safeguards Rule)\, 16 CFR 
 Part 314\, under the Gramm-Leach-Bliley Act (United States (Federal))\n\nS
 ource: https://www.federalregister.gov/documents/2023/11/13/2023-24412/sta
 ndards-for-safeguarding-customer-information\n\nhttps://regulations.fru.de
 v/regulations/us-glba-safeguards
URL:https://regulations.fru.dev/regulations/us-glba-safeguards
CATEGORIES:United States (Federal),financial,cybersecurity,breach-notificat
 ion,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-199@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20240517
DTEND;VALUE=DATE:20240518
SUMMARY:Colorado AI Act: SB 24-205 signed
DESCRIPTION:Governor Polis signs the original Colorado AI Act with a Februa
 ry 1\, 2026 effective date.\n\nColorado SB 24-205 (Consumer Protections fo
 r Artificial Intelligence)\, as delayed by SB 25B-004 and repealed and ree
 nacted by SB 26-189 (Automated Decision-Making Technology) (Colorado)\n\nS
 ource: https://leg.colorado.gov/bills/sb24-205\n\nhttps://regulations.fru.
 dev/regulations/us-co-ai-act
URL:https://regulations.fru.dev/regulations/us-co-ai-act
CATEGORIES:Colorado,ai,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-85@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20240520
DTEND;VALUE=DATE:20240521
SUMMARY:eIDAS 2 / EU Digital Identity Wallet: eIDAS 2 enters into force
DESCRIPTION:Regulation (EU) 2024/1183 entered into force on the twentieth d
 ay after publication on 30 Apr 2024 (Art 2).\n\nRegulation (EU) 2024/1183 
 amending Regulation (EU) No 910/2014 as regards establishing the European 
 Digital Identity Framework (eIDAS 2) (European Union)\n\nSource: https://e
 ur-lex.europa.eu/eli/reg/2024/1183/oj\n\nhttps://regulations.fru.dev/regul
 ations/eu-eidas2
URL:https://regulations.fru.dev/regulations/eu-eidas2
CATEGORIES:European Union,privacy,data-access,biometrics
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-143@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20240601
DTEND;VALUE=DATE:20240602
SUMMARY:Turkey KVKK: Law 7499 amendments take effect
DESCRIPTION:New sensitive data and cross-border transfer rules (Arts. 6 and
  9) apply.\n\nLaw No. 6698 on the Protection of Personal Data (KVKK)\, as 
 amended by Law No. 7499 (Turkey)\n\nSource: https://www.resmigazete.gov.tr
 /eskiler/2024/03/20240312-1.htm\n\nhttps://regulations.fru.dev/regulations
 /tr-kvkk
URL:https://regulations.fru.dev/regulations/tr-kvkk
CATEGORIES:Turkey,privacy,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-292@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20240615
DTEND;VALUE=DATE:20240616
SUMMARY:SEC Cyber Disclosure Rules: Smaller reporting companies: Item 1.05 
 compliance
DESCRIPTION:Smaller reporting companies must begin complying with Form 8-K 
 Item 1.05 incident disclosure.\n\nSEC Cybersecurity Risk Management\, Stra
 tegy\, Governance\, and Incident Disclosure (Release No. 33-11216) (United
  States (Federal))\n\nSource: https://www.federalregister.gov/documents/20
 23/08/04/2023-16194/cybersecurity-risk-management-strategy-governance-and-
 incident-disclosure\n\nhttps://regulations.fru.dev/regulations/us-sec-cybe
 r
URL:https://regulations.fru.dev/regulations/us-sec-cyber
CATEGORIES:United States (Federal),cybersecurity,breach-notification,financ
 ial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6918@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20240620
DTEND;VALUE=DATE:20240621
SUMMARY:NY Child Data Protection Act: Signed by Governor
DESCRIPTION:Chapter 121 of 2024.\n\nNew York Child Data Protection Act (New
  York)\n\nSource: https://www.nysenate.gov/legislation/bills/2023/S7695/am
 endment/B\n\nhttps://regulations.fru.dev/regulations/us-ny-cdpa
URL:https://regulations.fru.dev/regulations/us-ny-cdpa
CATEGORIES:New York,children,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6914@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20240620
DTEND;VALUE=DATE:20240621
SUMMARY:NY SAFE for Kids Act: Signed by Governor
DESCRIPTION:Chapter 120 of 2024.\n\nStop Addictive Feeds Exploitation (SAFE
 ) for Kids Act (New York)\n\nSource: https://ag.ny.gov/press-release/2024/
 attorney-general-james-governor-hochul-and-bill-sponsors-announce-nation-l
 eading\n\nhttps://regulations.fru.dev/regulations/us-ny-safe-kids
URL:https://regulations.fru.dev/regulations/us-ny-safe-kids
CATEGORIES:New York,children,online-safety
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-288@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20240623
DTEND;VALUE=DATE:20240624
SUMMARY:PADFA: PADFA takes effect
DESCRIPTION:The prohibition takes effect 60 days after enactment (April 24\
 , 2024).\n\nProtecting Americans' Data from Foreign Adversaries Act of 202
 4 (United States (Federal))\n\nSource: https://www.govinfo.gov/content/pkg
 /PLAW-118publ50/html/PLAW-118publ50.htm\n\nhttps://regulations.fru.dev/reg
 ulations/us-padfa
URL:https://regulations.fru.dev/regulations/us-padfa
CATEGORIES:United States (Federal),privacy,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-236@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20240625
DTEND;VALUE=DATE:20240626
SUMMARY:HIPAA: Reproductive health care privacy rule effective (later vacat
 ed)
DESCRIPTION:The HIPAA Privacy Rule to Support Reproductive Health Care Priv
 acy (89 FR 32976) took effect\; it was vacated nationwide on June 18\, 202
 5 in Purl v. HHS (N.D. Tex.).\n\nHIPAA Privacy\, Security and Breach Notif
 ication Rules (45 CFR Parts 160 and 164) (United States (Federal))\n\nSour
 ce: https://www.federalregister.gov/documents/2024/04/26/2024-08503/hipaa-
 privacy-rule-to-support-reproductive-health-care-privacy\n\nhttps://regula
 tions.fru.dev/regulations/us-hipaa
URL:https://regulations.fru.dev/regulations/us-hipaa
CATEGORIES:United States (Federal),privacy,health,cybersecurity,breach-noti
 fication
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-320@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20240630
DTEND;VALUE=DATE:20240701
SUMMARY:Washington My Health My Data Act: Small businesses must comply
DESCRIPTION:Sections 4-9 apply to small businesses.\n\nWashington My Health
  My Data Act (HB 1155\, Laws of 2023\, ch. 191\; RCW 19.373) (Washington)\
 n\nSource: https://www.atg.wa.gov/protecting-washingtonians-personal-healt
 h-data-and-privacy\n\nhttps://regulations.fru.dev/regulations/us-wa-mhmda
URL:https://regulations.fru.dev/regulations/us-wa-mhmda
CATEGORIES:Washington,health,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-208@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20240701
DTEND;VALUE=DATE:20240702
SUMMARY:Colorado Privacy Act (CPA): Universal opt-out mechanism recognition
  required
DESCRIPTION:Controllers must honor AG-recognized universal opt-out mechanis
 ms (e.g. Global Privacy Control).\n\nColorado Privacy Act (SB 21-190)\, C.
 R.S. 6-1-1301 et seq.\, as amended by HB 24-1130\, SB 24-041 and SB 25-276
  (Colorado)\n\nSource: https://leg.colorado.gov/bills/sb21-190\n\nhttps://
 regulations.fru.dev/regulations/us-co-cpa
URL:https://regulations.fru.dev/regulations/us-co-cpa
CATEGORIES:Colorado,privacy,children,biometrics
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-230@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20240701
DTEND;VALUE=DATE:20240702
SUMMARY:Florida Digital Bill of Rights: Florida Digital Bill of Rights take
 s effect
DESCRIPTION:SB 262 obligations under Fla. Stat. 501.701-501.722 apply.\n\nF
 lorida Digital Bill of Rights (CS/CS/SB 262\, 2023) (Florida)\n\nSource: h
 ttps://www.flsenate.gov/Session/Bill/2023/262\n\nhttps://regulations.fru.d
 ev/regulations/us-fl-fdbr
URL:https://regulations.fru.dev/regulations/us-fl-fdbr
CATEGORIES:Florida,privacy,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-283@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20240701
DTEND;VALUE=DATE:20240702
SUMMARY:Oregon OCPA: OCPA takes effect for most controllers
DESCRIPTION:OCPA obligations apply to for-profit controllers meeting the th
 resholds.\n\nOregon Consumer Privacy Act (SB 619\, 2023) (Oregon)\n\nSourc
 e: https://www.doj.state.or.us/consumer-protection/id-theft-data-breaches/
 privacy/\n\nhttps://regulations.fru.dev/regulations/us-or-ocpa
URL:https://regulations.fru.dev/regulations/us-or-ocpa
CATEGORIES:Oregon,privacy,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6921@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20240701
DTEND;VALUE=DATE:20240702
SUMMARY:Tennessee ELVIS Act: Takes effect
DESCRIPTION:ELVIS Act provisions effective.\n\nEnsuring Likeness\, Voice\, 
 and Image Security Act of 2024 (ELVIS Act) (Tennessee)\n\nSource: https://
 wapp.capitol.tn.gov/apps/BillInfo/Default.aspx?BillNumber=HB2091&GA=113\n\
 nhttps://regulations.fru.dev/regulations/us-tn-elvis
URL:https://regulations.fru.dev/regulations/us-tn-elvis
CATEGORIES:Tennessee,ai,privacy,biometrics
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-301@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20240701
DTEND;VALUE=DATE:20240702
SUMMARY:Texas TDPSA: TDPSA takes effect
DESCRIPTION:Most TDPSA obligations and consumer rights apply.\n\nTexas Data
  Privacy and Security Act (HB 4\, 2023) (Texas)\n\nSource: https://capitol
 .texas.gov/BillLookup/History.aspx?LegSess=88R&Bill=HB4\n\nhttps://regulat
 ions.fru.dev/regulations/us-tx-tdpsa
URL:https://regulations.fru.dev/regulations/us-tx-tdpsa
CATEGORIES:Texas,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-193@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20240703
DTEND;VALUE=DATE:20240704
SUMMARY:CIRCIA: NPRM comment period closed
DESCRIPTION:Extended comment period on the CIRCIA proposed rule closed.\n\n
 Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA) 
 and proposed implementing rule (6 CFR Part 226) (United States (Federal))\
 n\nSource: https://www.federalregister.gov/documents/2024/04/04/2024-06526
 /cyber-incident-reporting-for-critical-infrastructure-act-circia-reporting
 -requirements\n\nhttps://regulations.fru.dev/regulations/us-circia
URL:https://regulations.fru.dev/regulations/us-circia
CATEGORIES:United States (Federal),cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6856@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20240712
DTEND;VALUE=DATE:20240713
SUMMARY:Interoperable Europe Act: Act applies
DESCRIPTION:General application date.\n\nRegulation (EU) 2024/903 laying do
 wn measures for a high level of public sector interoperability across the 
 Union (Interoperable Europe Act) (European Union)\n\nSource: https://eur-l
 ex.europa.eu/eli/reg/2024/903/oj/eng\n\nhttps://regulations.fru.dev/regula
 tions/eu-interoperable-europe
URL:https://regulations.fru.dev/regulations/eu-interoperable-europe
CATEGORIES:European Union,data-access
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-232@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20240729
DTEND;VALUE=DATE:20240730
SUMMARY:FTC Health Breach Notification Rule: 2024 amendments effective
DESCRIPTION:Amendments clarifying health app coverage\, unauthorized disclo
 sure as breach\, email notice and FTC notice timing took effect.\n\nFTC He
 alth Breach Notification Rule (16 CFR Part 318)\, as amended 2024 (United 
 States (Federal))\n\nSource: https://www.federalregister.gov/documents/202
 4/05/30/2024-10855/health-breach-notification-rule\n\nhttps://regulations.
 fru.dev/regulations/us-ftc-hbnr
URL:https://regulations.fru.dev/regulations/us-ftc-hbnr
CATEGORIES:United States (Federal),health,privacy,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-37@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20240801
DTEND;VALUE=DATE:20240802
SUMMARY:EU AI Act: AI Act enters into force
DESCRIPTION:Regulation (EU) 2024/1689 enters into force twenty days after p
 ublication on 12 July 2024 (Art 113).\n\nRegulation (EU) 2024/1689 laying 
 down harmonised rules on artificial intelligence (Artificial Intelligence 
 Act)\, as amended by Regulation (EU) 2026/1744 (Digital Omnibus on AI) (Eu
 ropean Union)\n\nSource: https://eur-lex.europa.eu/eli/reg/2024/1689/oj\n\
 nhttps://regulations.fru.dev/regulations/eu-ai-act
URL:https://regulations.fru.dev/regulations/eu-ai-act
CATEGORIES:European Union,ai,biometrics,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-242@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20240802
DTEND;VALUE=DATE:20240803
SUMMARY:Illinois BIPA: SB 2979 amendment effective
DESCRIPTION:Public Act 103-0769 signed and effective immediately: single re
 covery per person and electronic signatures allowed for consent.\n\nIllino
 is Biometric Information Privacy Act (740 ILCS 14)\, as amended by SB 2979
  (Public Act 103-0769) (Illinois)\n\nSource: https://www.ilga.gov/Legislat
 ion/publicacts/view/103-0769\n\nhttps://regulations.fru.dev/regulations/us
 -il-bipa
URL:https://regulations.fru.dev/regulations/us-il-bipa
CATEGORIES:Illinois,biometrics,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-295@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20240802
DTEND;VALUE=DATE:20240803
SUMMARY:SEC Regulation S-P: Amendments effective
DESCRIPTION:The Regulation S-P amendments became effective\; compliance tie
 red by entity size.\n\nRegulation S-P: Privacy of Consumer Financial Infor
 mation and Safeguarding Customer Information (2024 amendments) (United Sta
 tes (Federal))\n\nSource: https://www.federalregister.gov/documents/2024/0
 6/03/2024-11116/regulation-s-p-privacy-of-consumer-financial-information-a
 nd-safeguarding-customer-information\n\nhttps://regulations.fru.dev/regula
 tions/us-sec-reg-sp
URL:https://regulations.fru.dev/regulations/us-sec-reg-sp
CATEGORIES:United States (Federal),financial,privacy,cybersecurity,breach-n
 otification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-244@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20240809
DTEND;VALUE=DATE:20240810
SUMMARY:Illinois AI in Employment Law (HB 3773): HB 3773 signed
DESCRIPTION:Governor Pritzker signs Public Act 103-0804.\n\nIllinois HB 377
 3 (Public Act 103-0804)\, amending the Illinois Human Rights Act on artifi
 cial intelligence in employment (Illinois)\n\nSource: https://www.ilga.gov
 /ftp/legislation/103/BillStatus/HTML/10300HB3773.html\n\nhttps://regulatio
 ns.fru.dev/regulations/us-il-hb3773
URL:https://regulations.fru.dev/regulations/us-il-hb3773
CATEGORIES:Illinois,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-13@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20240823
DTEND;VALUE=DATE:20240824
SUMMARY:Brazil LGPD: International transfer regulation published
DESCRIPTION:Resolution CD/ANPD 19/2024 on international transfers and stand
 ard contractual clauses published and in force.\n\nLei Geral de Proteção
  de Dados Pessoais (Law No. 13.709/2018) (Brazil)\n\nSource: https://www.i
 n.gov.br/en/web/dou/-/resolucao-cd/anpd-n-19-de-23-de-agosto-de-2024-58009
 5396\n\nhttps://regulations.fru.dev/regulations/br-lgpd
URL:https://regulations.fru.dev/regulations/br-lgpd
CATEGORIES:Brazil,privacy,breach-notification,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-7014@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20240826
DTEND;VALUE=DATE:20240827
SUMMARY:Malaysia Cyber Security Act: Act 854 and first regulations in force
DESCRIPTION:The Act and its incident notification\, risk assessment and aud
 it\, and licensing regulations take effect.\n\nCyber Security Act 2024 (Ac
 t 854) (Malaysia)\n\nSource: https://lom.agc.gov.my/act-detail.php?a=YWN0P
 Tg1NCZsYW5nPUJJfDM3MjhhYmRhY2U0YWNlOTZlMGI3MmRlODVkNjQ2YzM4ZTNmMTE0YzA3YzY
 5ZGJhOGExZTNmYmQ4ZTc0OWJlYWY=\n\nhttps://regulations.fru.dev/regulations/m
 y-cyber-security-act
URL:https://regulations.fru.dev/regulations/my-cyber-security-act
CATEGORIES:Malaysia,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-144@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20240901
DTEND;VALUE=DATE:20240902
SUMMARY:Turkey KVKK: Old transfer regime ends
DESCRIPTION:Transitional period ends in which the former Article 9 explicit
 -consent transfer basis could still be relied on.\n\nLaw No. 6698 on the P
 rotection of Personal Data (KVKK)\, as amended by Law No. 7499 (Turkey)\n\
 nSource: https://www.resmigazete.gov.tr/eskiler/2024/03/20240312-1.htm\n\n
 https://regulations.fru.dev/regulations/tr-kvkk
URL:https://regulations.fru.dev/regulations/tr-kvkk
CATEGORIES:Turkey,privacy,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6878@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20240905
DTEND;VALUE=DATE:20240906
SUMMARY:CoE AI Framework Convention: Opened for signature
DESCRIPTION:Convention opened for signature\; the EU signed under Council D
 ecision (EU) 2024/2218.\n\nCouncil of Europe Framework Convention on Artif
 icial Intelligence and Human Rights\, Democracy and the Rule of Law (Counc
 il of Europe)\n\nSource: https://eur-lex.europa.eu/legal-content/EN/TXT/?u
 ri=CELEX:22026A01081\n\nhttps://regulations.fru.dev/regulations/coe-ai-con
 vention
URL:https://regulations.fru.dev/regulations/coe-ai-convention
CATEGORIES:Council of Europe,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-138@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20240914
DTEND;VALUE=DATE:20240915
SUMMARY:Saudi PDPL: One-year grace period ends
DESCRIPTION:Grace period for controllers to comply ends\; PDPL fully enforc
 eable.\n\nPersonal Data Protection Law (Royal Decree M/19 of 9/2/1443H\, a
 s amended by Royal Decree M/148 of 5/9/1444H) (Saudi Arabia)\n\nSource: ht
 tps://sdaia.gov.sa/en/SDAIA/about/Documents/Personal%20Data%20English%20V2
 -23April2023-%20Reviewed-.pdf\n\nhttps://regulations.fru.dev/regulations/s
 a-pdpl
URL:https://regulations.fru.dev/regulations/sa-pdpl
CATEGORIES:Saudi Arabia,privacy,data-residency,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-187@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20240919
DTEND;VALUE=DATE:20240920
SUMMARY:California AI Transparency Act (SB 942): SB 942 signed
DESCRIPTION:SB 942 chaptered (ch. 291) with an original operative date of J
 anuary 1\, 2026.\n\nCalifornia AI Transparency Act (SB 942\, Stats. 2024\,
  ch. 291)\, as amended by AB 853 (Stats. 2025\, ch. 674) (California)\n\nS
 ource: https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_i
 d=202320240SB942\n\nhttps://regulations.fru.dev/regulations/us-ca-sb942
URL:https://regulations.fru.dev/regulations/us-ca-sb942
CATEGORIES:California,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6907@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20240920
DTEND;VALUE=DATE:20240921
SUMMARY:California SB 976 addictive feeds: Signed by Governor
DESCRIPTION:Chaptered as Chapter 321\, Statutes of 2024.\n\nProtecting Our 
 Kids from Social Media Addiction Act (SB 976) (California)\n\nSource: http
 s://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202320240
 SB976\n\nhttps://regulations.fru.dev/regulations/us-ca-sb976
URL:https://regulations.fru.dev/regulations/us-ca-sb976
CATEGORIES:California,children,online-safety
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-24@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20240922
DTEND;VALUE=DATE:20240923
SUMMARY:Quebec Law 25: Phase 3: data portability
DESCRIPTION:Right to data portability in a structured\, commonly used techn
 ological format applies.\n\nAct to modernize legislative provisions as reg
 ards the protection of personal information (Law 25\, formerly Bill 64) (Q
 uebec\, Canada)\n\nSource: https://www.legisquebec.gouv.qc.ca/en/document/
 cs/P-39.1\n\nhttps://regulations.fru.dev/regulations/ca-qc-law25
URL:https://regulations.fru.dev/regulations/ca-qc-law25
CATEGORIES:Quebec\, Canada,privacy,breach-notification,biometrics
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-162@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20240928
DTEND;VALUE=DATE:20240929
SUMMARY:California AB 2013 (AI training data transparency): AB 2013 signed
DESCRIPTION:AB 2013 chaptered (ch. 817).\n\nCalifornia AB 2013\, Generative
  Artificial Intelligence: Training Data Transparency (Stats. 2024\, ch. 81
 7) (California)\n\nSource: https://leginfo.legislature.ca.gov/faces/billNa
 vClient.xhtml?bill_id=202320240AB2013\n\nhttps://regulations.fru.dev/regul
 ations/us-ca-ab2013
URL:https://regulations.fru.dev/regulations/us-ca-ab2013
CATEGORIES:California,ai,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6934@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20241001
DTEND;VALUE=DATE:20241002
SUMMARY:Maryland Kids Code: Takes effect
DESCRIPTION:Act effective.\n\nMaryland Age-Appropriate Design Code Act (Mar
 yland Kids Code\, HB 603) (Maryland)\n\nSource: https://mgaleg.maryland.go
 v/mgawebsite/Legislation/Details/hb0603?ys=2024RS\n\nhttps://regulations.f
 ru.dev/regulations/us-md-kids-code
URL:https://regulations.fru.dev/regulations/us-md-kids-code
CATEGORIES:Maryland,children,privacy,online-safety
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-258@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20241001
DTEND;VALUE=DATE:20241002
SUMMARY:Montana Consumer Data Privacy Act (MCDPA): MCDPA takes effect
DESCRIPTION:Consumer rights\, controller duties and opt-out preference sign
 al support apply.\n\nMontana Consumer Data Privacy Act (SB 384\, 2023)\, M
 ont. Code Ann. 30-14-2801 et seq.\, as amended by SB 297 (2025) (Montana)\
 n\nSource: https://archive.legmt.gov/bills/mca/title_0300/chapter_0140/par
 t_0280/section_0030/0300-0140-0280-0030.html\n\nhttps://regulations.fru.de
 v/regulations/us-mt-mcdpa
URL:https://regulations.fru.dev/regulations/us-mt-mcdpa
CATEGORIES:Montana,privacy,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-113@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20241017
DTEND;VALUE=DATE:20241018
SUMMARY:Indonesia PDP Law: PDP Law transition ends
DESCRIPTION:Controllers and processors must fully comply (Art. 74 two-year 
 transition).\n\nLaw No. 27 of 2022 on Personal Data Protection (Undang-Und
 ang Pelindungan Data Pribadi) (Indonesia)\n\nSource: https://peraturan.bpk
 .go.id/Details/229798/uu-no-27-tahun-2022\n\nhttps://regulations.fru.dev/r
 egulations/id-pdp
URL:https://regulations.fru.dev/regulations/id-pdp
CATEGORIES:Indonesia,privacy,breach-notification,data-residency,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-99@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20241017
DTEND;VALUE=DATE:20241018
SUMMARY:NIS2: Transposition deadline
DESCRIPTION:Member States had to adopt and publish national transposing mea
 sures by 17 Oct 2024 (Art 41(1)).\n\nDirective (EU) 2022/2555 on measures 
 for a high common level of cybersecurity across the Union (NIS2 Directive)
  (European Union)\n\nSource: https://eur-lex.europa.eu/eli/dir/2022/2555/o
 j\n\nhttps://regulations.fru.dev/regulations/eu-nis2
URL:https://regulations.fru.dev/regulations/eu-nis2
CATEGORIES:European Union,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-100@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20241018
DTEND;VALUE=DATE:20241019
SUMMARY:NIS2: National NIS2 measures apply\; NIS1 repealed
DESCRIPTION:Member States apply their NIS2 measures from 18 Oct 2024 and Di
 rective (EU) 2016/1148 (NIS1) is repealed (Arts 41(1)\, 44).\n\nDirective 
 (EU) 2022/2555 on measures for a high common level of cybersecurity across
  the Union (NIS2 Directive) (European Union)\n\nSource: https://eur-lex.eu
 ropa.eu/eli/dir/2022/2555/oj\n\nhttps://regulations.fru.dev/regulations/eu
 -nis2
URL:https://regulations.fru.dev/regulations/eu-nis2
CATEGORIES:European Union,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-274@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20241101
DTEND;VALUE=DATE:20241102
SUMMARY:NYDFS Cybersecurity Regulation (Part 500): Governance\, encryption\
 , IR/BCDR\, exemptions
DESCRIPTION:500.4 governance\, 500.15 encryption\, 500.16 incident response
  and business continuity plans\, and 500.19(a) revised exemptions apply.\n
 \nNew York DFS Cybersecurity Requirements for Financial Services Companies
  (23 NYCRR Part 500)\, Second Amendment (New York)\n\nSource: https://www.
 dfs.ny.gov/cybersecurity/23-NYCRR-Part-500\n\nhttps://regulations.fru.dev/
 regulations/us-ny-dfs-500
URL:https://regulations.fru.dev/regulations/us-ny-dfs-500
CATEGORIES:New York,cybersecurity,breach-notification,financial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-101@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20241107
DTEND;VALUE=DATE:20241108
SUMMARY:NIS2: Implementing Regulation 2024/2690 enters into force
DESCRIPTION:Commission Implementing Regulation (EU) 2024/2690 (published 18
  Oct 2024) sets technical risk-management measures and significant-inciden
 t thresholds for DNS\, TLD\, cloud\, data centre\, CDN\, managed (security
 ) service providers\, online marketplaces\, search engines\, social networ
 ks and trust service providers.\n\nDirective (EU) 2022/2555 on measures fo
 r a high common level of cybersecurity across the Union (NIS2 Directive) (
 European Union)\n\nSource: https://eur-lex.europa.eu/eli/reg_impl/2024/269
 0/oj\n\nhttps://regulations.fru.dev/regulations/eu-nis2
URL:https://regulations.fru.dev/regulations/eu-nis2
CATEGORIES:European Union,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6943@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20241125
DTEND;VALUE=DATE:20241126
SUMMARY:Ontario Bill 194: Royal Assent
DESCRIPTION:Bill 194 receives Royal Assent as S.O. 2024\, c. 24.\n\nStrengt
 hening Cyber Security and Building Trust in the Public Sector Act\, 2024 (
 Ontario\, Canada)\n\nSource: https://www.ontario.ca/laws/statute/s24024\n\
 nhttps://regulations.fru.dev/regulations/ca-on-bill194
URL:https://regulations.fru.dev/regulations/ca-on-bill194
CATEGORIES:Ontario\, Canada,cybersecurity,ai,privacy,children,breach-notifi
 cation
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6954@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20241130
DTEND;VALUE=DATE:20241201
SUMMARY:Peru PDPL and 2024 Regulation: New regulation published
DESCRIPTION:DS 016-2024-JUS published in El Peruano.\n\nLey N° 29733\, Ley
  de Protección de Datos Personales\, and its Regulation (Decreto Supremo 
 N° 016-2024-JUS) (Peru)\n\nSource: https://www.gob.pe/institucion/smv/nor
 mas-legales/6426760-016-2024-jus\n\nhttps://regulations.fru.dev/regulation
 s/pe-pdpl
URL:https://regulations.fru.dev/regulations/pe-pdpl
CATEGORIES:Peru,privacy,breach-notification,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6850@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20241201
DTEND;VALUE=DATE:20241202
SUMMARY:EU Platform Work Directive: Directive enters into force
DESCRIPTION:Published in the OJ on 2024-11-11\; enters into force on the 20
 th day.\n\nDirective (EU) 2024/2831 on improving working conditions in pla
 tform work (European Union)\n\nSource: https://eur-lex.europa.eu/eli/dir/2
 024/2831/oj/eng\n\nhttps://regulations.fru.dev/regulations/eu-platform-wor
 k
URL:https://regulations.fru.dev/regulations/eu-platform-work
CATEGORIES:European Union,privacy,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-106@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20241208
DTEND;VALUE=DATE:20241209
SUMMARY:Product Liability Directive: New PLD enters into force
DESCRIPTION:Directive entered into force on the twentieth day after publica
 tion in the OJ on 18 Nov 2024 (Art 23).\n\nDirective (EU) 2024/2853 on lia
 bility for defective products (new Product Liability Directive) (European 
 Union)\n\nSource: https://eur-lex.europa.eu/eli/dir/2024/2853/oj\n\nhttps:
 //regulations.fru.dev/regulations/eu-pld
URL:https://regulations.fru.dev/regulations/eu-pld
CATEGORIES:European Union,ai,cybersecurity
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-9@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20241210
DTEND;VALUE=DATE:20241211
SUMMARY:Brazil AI Bill (PL 2338/2023): Approved by the Federal Senate
DESCRIPTION:Senate approves the consolidated text and sends it to the Chamb
 er of Deputies.\n\nProjeto de Lei nº 2338/2023 (Brazilian AI Legal Framew
 ork) (Brazil)\n\nSource: https://www25.senado.leg.br/web/atividade/materia
 s/-/materia/157233\n\nhttps://regulations.fru.dev/regulations/br-ai-bill
URL:https://regulations.fru.dev/regulations/br-ai-bill
CATEGORIES:Brazil,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-48@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20241210
DTEND;VALUE=DATE:20241211
SUMMARY:Cyber Resilience Act: CRA enters into force
DESCRIPTION:Entered into force on the twentieth day after publication in th
 e OJ on 20 Nov 2024 (Art 71(1)).\n\nRegulation (EU) 2024/2847 on horizonta
 l cybersecurity requirements for products with digital elements (Cyber Res
 ilience Act) (European Union)\n\nSource: https://eur-lex.europa.eu/eli/reg
 /2024/2847/oj\n\nhttps://regulations.fru.dev/regulations/eu-cra
URL:https://regulations.fru.dev/regulations/eu-cra
CATEGORIES:European Union,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-4@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20241211
DTEND;VALUE=DATE:20241212
SUMMARY:Australia Privacy Act: Most POLA Act 2024 amendments commence
DESCRIPTION:Tiered penalties\, infringement notices\, OAIC powers\, securit
 y and overseas-transfer clarifications and doxxing offences commence the d
 ay after Royal Assent.\n\nPrivacy Act 1988 (Cth)\, as amended by the Priva
 cy and Other Legislation Amendment Act 2024 (Australia)\n\nSource: https:/
 /www.legislation.gov.au/C2024A00128/asmade\n\nhttps://regulations.fru.dev/
 regulations/au-privacy-act
URL:https://regulations.fru.dev/regulations/au-privacy-act
CATEGORIES:Australia,privacy,children,breach-notification,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-26@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20241213
DTEND;VALUE=DATE:20241214
SUMMARY:Chile Personal Data Protection Law (Ley 21.719): Published in Diari
 o Oficial
DESCRIPTION:Law 21.719 published\; 24-month vacatio legis begins.\n\nLey N
 º 21.719 que regula la protección y el tratamiento de los datos personal
 es y crea la Agencia de Protección de Datos Personales (Chile)\n\nSource:
  https://www.bcn.cl/leychile/navegar?idNorma=1209272\n\nhttps://regulation
 s.fru.dev/regulations/cl-pdpl
URL:https://regulations.fru.dev/regulations/cl-pdpl
CATEGORIES:Chile,privacy,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-293@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20241215
DTEND;VALUE=DATE:20241216
SUMMARY:SEC Cyber Disclosure Rules: Inline XBRL tagging of annual cybersecu
 rity disclosures
DESCRIPTION:Item 106 / Item 16K disclosures must be tagged in Inline XBRL f
 or fiscal years ending on or after this date.\n\nSEC Cybersecurity Risk Ma
 nagement\, Strategy\, Governance\, and Incident Disclosure (Release No. 33
 -11216) (United States (Federal))\n\nSource: https://www.federalregister.g
 ov/documents/2023/08/04/2023-16194/cybersecurity-risk-management-strategy-
 governance-and-incident-disclosure\n\nhttps://regulations.fru.dev/regulati
 ons/us-sec-cyber
URL:https://regulations.fru.dev/regulations/us-sec-cyber
CATEGORIES:United States (Federal),cybersecurity,breach-notification,financ
 ial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-194@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20241216
DTEND;VALUE=DATE:20241217
SUMMARY:CMMC 2.0: CMMC Program rule (32 CFR Part 170) effective
DESCRIPTION:The program rule establishing CMMC levels and assessment proces
 ses took effect\; contract enforcement awaited the DFARS rule.\n\nCybersec
 urity Maturity Model Certification (CMMC) Program (32 CFR Part 170) and DF
 ARS acquisition rule (48 CFR Parts 204\, 212\, 217\, 252) (United States (
 Federal))\n\nSource: https://www.federalregister.gov/documents/2024/10/15/
 2024-22905/cybersecurity-maturity-model-certification-cmmc-program\n\nhttp
 s://regulations.fru.dev/regulations/us-cmmc
URL:https://regulations.fru.dev/regulations/us-cmmc
CATEGORIES:United States (Federal),cybersecurity
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-294@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20241218
DTEND;VALUE=DATE:20241219
SUMMARY:SEC Cyber Disclosure Rules: Inline XBRL tagging of Item 1.05 disclo
 sures
DESCRIPTION:Form 8-K Item 1.05 and Form 6-K incident disclosures must be ta
 gged in Inline XBRL.\n\nSEC Cybersecurity Risk Management\, Strategy\, Gov
 ernance\, and Incident Disclosure (Release No. 33-11216) (United States (F
 ederal))\n\nSource: https://www.federalregister.gov/documents/2023/08/04/2
 023-16194/cybersecurity-risk-management-strategy-governance-and-incident-d
 isclosure\n\nhttps://regulations.fru.dev/regulations/us-sec-cyber
URL:https://regulations.fru.dev/regulations/us-sec-cyber
CATEGORIES:United States (Federal),cybersecurity,breach-notification,financ
 ial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-237@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20241223
DTEND;VALUE=DATE:20241224
SUMMARY:HIPAA: Reproductive health privacy compliance date (vacated)
DESCRIPTION:Original compliance date for the reproductive health care priva
 cy provisions\, including the attestation requirement\; these provisions n
 o longer apply after the June 2025 vacatur.\n\nHIPAA Privacy\, Security an
 d Breach Notification Rules (45 CFR Parts 160 and 164) (United States (Fed
 eral))\n\nSource: https://www.federalregister.gov/documents/2024/04/26/202
 4-08503/hipaa-privacy-rule-to-support-reproductive-health-care-privacy\n\n
 https://regulations.fru.dev/regulations/us-hipaa
URL:https://regulations.fru.dev/regulations/us-hipaa
CATEGORIES:United States (Federal),privacy,health,cybersecurity,breach-noti
 fication
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-86@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20241224
DTEND;VALUE=DATE:20241225
SUMMARY:eIDAS 2 / EU Digital Identity Wallet: First wallet implementing act
 s enter into force
DESCRIPTION:Commission Implementing Regulations (EU) 2024/2977\, 2024/2979\
 , 2024/2980\, 2024/2981 and 2024/2982 (adopted 28 Nov 2024\, published 4 D
 ec 2024) enter into force. This starts the wallet deadline clocks in Arts 
 5a and 5f.\n\nRegulation (EU) 2024/1183 amending Regulation (EU) No 910/20
 14 as regards establishing the European Digital Identity Framework (eIDAS 
 2) (European Union)\n\nSource: https://eur-lex.europa.eu/eli/reg_impl/2024
 /2977/oj\n\nhttps://regulations.fru.dev/regulations/eu-eidas2
URL:https://regulations.fru.dev/regulations/eu-eidas2
CATEGORIES:European Union,privacy,data-access,biometrics
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-216@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20241231
DTEND;VALUE=DATE:20250101
SUMMARY:Connecticut Data Privacy Act (CTDPA): Mandatory 60-day cure period 
 expires
DESCRIPTION:After Dec 31\, 2024\, the AG is no longer required to offer a 6
 0-day cure before enforcement\; cure becomes discretionary.\n\nConnecticut
  Data Privacy Act (Public Act 22-15)\, Conn. Gen. Stat. 42-515 et seq.\, a
 s amended by Public Act 25-113 (SB 1295) and Public Act 26-64 (SB 4) (Conn
 ecticut)\n\nSource: https://www.cga.ct.gov/asp/cgabillstatus/cgabillstatus
 .asp?selBillType=Bill&which_year=2022&bill_num=6\n\nhttps://regulations.fr
 u.dev/regulations/us-ct-ctdpa
URL:https://regulations.fru.dev/regulations/us-ct-ctdpa
CATEGORIES:Connecticut,privacy,children,ai,health
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6908@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20250101
DTEND;VALUE=DATE:20250102
SUMMARY:California SB 976 addictive feeds: Takes effect
DESCRIPTION:Actual-knowledge feed and notification limits apply\, subject t
 o litigation.\n\nProtecting Our Kids from Social Media Addiction Act (SB 9
 76) (California)\n\nSource: https://leginfo.legislature.ca.gov/faces/billN
 avClient.xhtml?bill_id=202320240SB976\n\nhttps://regulations.fru.dev/regul
 ations/us-ca-sb976
URL:https://regulations.fru.dev/regulations/us-ca-sb976
CATEGORIES:California,children,online-safety
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-166@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20250101
DTEND;VALUE=DATE:20250102
SUMMARY:CCPA / CPRA: CPI adjustment of thresholds and fines
DESCRIPTION:Revenue threshold rises to $26\,625\,000 and fines to $2\,663 /
  $7\,988 per violation.\n\nCalifornia Consumer Privacy Act of 2018\, as am
 ended by the California Privacy Rights Act of 2020 (Cal. Civ. Code 1798.10
 0 et seq.) and CPPA regulations (Cal. Code Regs. tit. 11\, 7000 et seq.) (
 California)\n\nSource: https://cppa.ca.gov/regulations/cpi_adjustment.html
 \n\nhttps://regulations.fru.dev/regulations/us-ca-ccpa
URL:https://regulations.fru.dev/regulations/us-ca-ccpa
CATEGORIES:California,privacy,ai,cybersecurity,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-34@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20250101
DTEND;VALUE=DATE:20250102
SUMMARY:China Network Data Security Regulations: Network Data Regulations t
 ake effect
DESCRIPTION:All provisions\, including the 10-million-person threshold duti
 es and annual important-data risk assessments\, apply.\n\nRegulations on N
 etwork Data Security Management (State Council Order No. 790) (China)\n\nS
 ource: https://www.gov.cn/zhengce/content/202409/content_6977766.htm\n\nht
 tps://regulations.fru.dev/regulations/cn-network-data-regs
URL:https://regulations.fru.dev/regulations/cn-network-data-regs
CATEGORIES:China,privacy,cybersecurity,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-209@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20250101
DTEND;VALUE=DATE:20250102
SUMMARY:Colorado Privacy Act (CPA): 60-day cure period expires
DESCRIPTION:Mandatory 60-day notice-and-cure before AG enforcement ends\; e
 nforcement may proceed without cure.\n\nColorado Privacy Act (SB 21-190)\,
  C.R.S. 6-1-1301 et seq.\, as amended by HB 24-1130\, SB 24-041 and SB 25-
 276 (Colorado)\n\nSource: https://leg.colorado.gov/bills/sb21-190\n\nhttps
 ://regulations.fru.dev/regulations/us-co-cpa
URL:https://regulations.fru.dev/regulations/us-co-cpa
CATEGORIES:Colorado,privacy,children,biometrics
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-217@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20250101
DTEND;VALUE=DATE:20250102
SUMMARY:Connecticut Data Privacy Act (CTDPA): Universal opt-out preference 
 signals required
DESCRIPTION:Controllers must honor opt-out preference signals for targeted 
 advertising and sale (effective Jan 1\, 2025).\n\nConnecticut Data Privacy
  Act (Public Act 22-15)\, Conn. Gen. Stat. 42-515 et seq.\, as amended by 
 Public Act 25-113 (SB 1295) and Public Act 26-64 (SB 4) (Connecticut)\n\nS
 ource: https://www.cga.ct.gov/asp/cgabillstatus/cgabillstatus.asp?selBillT
 ype=Bill&which_year=2022&bill_num=6\n\nhttps://regulations.fru.dev/regulat
 ions/us-ct-ctdpa
URL:https://regulations.fru.dev/regulations/us-ct-ctdpa
CATEGORIES:Connecticut,privacy,children,ai,health
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-223@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20250101
DTEND;VALUE=DATE:20250102
SUMMARY:Delaware Personal Data Privacy Act (DPDPA): DPDPA takes effect
DESCRIPTION:Consumer rights and controller duties apply\; 60-day mandatory 
 cure period begins.\n\nDelaware Personal Data Privacy Act (HB 154)\, 6 Del
 . C. ch. 12D (Delaware)\n\nSource: https://delcode.delaware.gov/title6/c01
 2d/index.html\n\nhttps://regulations.fru.dev/regulations/us-de-dpdpa
URL:https://regulations.fru.dev/regulations/us-de-dpdpa
CATEGORIES:Delaware,privacy,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-240@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20250101
DTEND;VALUE=DATE:20250102
SUMMARY:Iowa Consumer Data Protection Act (ICDPA): ICDPA takes effect
DESCRIPTION:Consumer rights and controller/processor obligations apply.\n\n
 Iowa Consumer Data Protection Act (SF 262\, 2023)\, Iowa Code ch. 715D (Io
 wa)\n\nSource: https://www.legis.iowa.gov/docs/code/715D.pdf\n\nhttps://re
 gulations.fru.dev/regulations/us-ia-icdpa
URL:https://regulations.fru.dev/regulations/us-ia-icdpa
CATEGORIES:Iowa,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-129@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20250101
DTEND;VALUE=DATE:20250102
SUMMARY:Malaysia PDPA: PDPA amendments phase 1
DESCRIPTION:Miscellaneous provisions commence (e.g. electronic service of n
 otices).\n\nPersonal Data Protection Act 2010 (Act 709)\, as amended by th
 e Personal Data Protection (Amendment) Act 2024 (Act A1727) (Malaysia)\n\n
 Source: https://www.pdp.gov.my/ppdpv1/en/personal-data-protection-amendmen
 t-act-2024-commencement-date-determination/\n\nhttps://regulations.fru.dev
 /regulations/my-pdpa
URL:https://regulations.fru.dev/regulations/my-pdpa
CATEGORIES:Malaysia,privacy,breach-notification,biometrics,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-260@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20250101
DTEND;VALUE=DATE:20250102
SUMMARY:Nebraska NDPA: Nebraska Data Privacy Act takes effect
DESCRIPTION:Controller and processor obligations and consumer rights under 
 Neb. Rev. Stat. 87-1101 et seq. apply.\n\nNebraska Data Privacy Act (LB 10
 74\, 2024) (Nebraska)\n\nSource: https://nebraskalegislature.gov/bills/vie
 w_bill.php?DocumentID=54904\n\nhttps://regulations.fru.dev/regulations/us-
 ne-ndpa
URL:https://regulations.fru.dev/regulations/us-ne-ndpa
CATEGORIES:Nebraska,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-261@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20250101
DTEND;VALUE=DATE:20250102
SUMMARY:New Hampshire Privacy Act: New Hampshire Privacy Act takes effect
DESCRIPTION:RSA 507-H obligations and consumer rights apply (Laws 2024\, 5:
 1\, eff. Jan. 1\, 2025).\n\nNew Hampshire Privacy Act (SB 255\, 2024)\, RS
 A chapter 507-H (New Hampshire)\n\nSource: https://gc.nh.gov/rsa/html/LII/
 507-H/507-H-2.htm\n\nhttps://regulations.fru.dev/regulations/us-nh-privacy
URL:https://regulations.fru.dev/regulations/us-nh-privacy
CATEGORIES:New Hampshire,privacy,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-302@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20250101
DTEND;VALUE=DATE:20250102
SUMMARY:Texas TDPSA: Universal opt-out mechanism requirement applies
DESCRIPTION:Controllers must honor global privacy control / universal opt-o
 ut signals (Bus. & Com. Code 541.055(e)).\n\nTexas Data Privacy and Securi
 ty Act (HB 4\, 2023) (Texas)\n\nSource: https://capitol.texas.gov/BillLook
 up/History.aspx?LegSess=88R&Bill=HB4\n\nhttps://regulations.fru.dev/regula
 tions/us-tx-tdpsa
URL:https://regulations.fru.dev/regulations/us-tx-tdpsa
CATEGORIES:Texas,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6890@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20250106
DTEND;VALUE=DATE:20250107
SUMMARY:HIPAA Security Rule update (NPRM): NPRM published
DESCRIPTION:Proposed Security Rule changes published in the Federal Registe
 r.\n\nHIPAA Security Rule To Strengthen the Cybersecurity of Electronic Pr
 otected Health Information (proposed rule) (United States)\n\nSource: http
 s://www.federalregister.gov/documents/2025/01/06/2024-30983/hipaa-security
 -rule-to-strengthen-the-cybersecurity-of-electronic-protected-health-infor
 mation\n\nhttps://regulations.fru.dev/regulations/us-hhs-hipaa-security-np
 rm
URL:https://regulations.fru.dev/regulations/us-hhs-hipaa-security-nprm
CATEGORIES:United States,health,cybersecurity,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6857@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20250112
DTEND;VALUE=DATE:20250113
SUMMARY:Interoperable Europe Act: Interoperability assessments mandatory
DESCRIPTION:Article 3(1) to (4) (interoperability assessments) and Article 
 17 apply.\n\nRegulation (EU) 2024/903 laying down measures for a high leve
 l of public sector interoperability across the Union (Interoperable Europe
  Act) (European Union)\n\nSource: https://eur-lex.europa.eu/eli/reg/2024/9
 03/oj/eng\n\nhttps://regulations.fru.dev/regulations/eu-interoperable-euro
 pe
URL:https://regulations.fru.dev/regulations/eu-interoperable-europe
CATEGORIES:European Union,data-access
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-264@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20250115
DTEND;VALUE=DATE:20250116
SUMMARY:New Jersey NJDPA: NJDPA takes effect
DESCRIPTION:The act takes effect on the 365th day after enactment on Jan 16
 \, 2024 (sec. 17).\n\nNew Jersey Data Privacy Act (P.L.2023\, c.266\; S332
 ) (New Jersey)\n\nSource: https://pub.njleg.state.nj.us/Bills/2022/PL23/26
 6_.PDF\n\nhttps://regulations.fru.dev/regulations/us-nj-njdpa
URL:https://regulations.fru.dev/regulations/us-nj-njdpa
CATEGORIES:New Jersey,privacy,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6880@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20250117
DTEND;VALUE=DATE:20250118
SUMMARY:CFPB Open Banking Rule (Section 1033): Final rule effective
DESCRIPTION:Rule published 2024-11-18 takes effect.\n\nRequired Rulemaking 
 on Personal Financial Data Rights (12 CFR Part 1033) (United States)\n\nSo
 urce: https://www.federalregister.gov/documents/2024/11/18/2024-25079/requ
 ired-rulemaking-on-personal-financial-data-rights\n\nhttps://regulations.f
 ru.dev/regulations/us-cfpb-1033
URL:https://regulations.fru.dev/regulations/us-cfpb-1033
CATEGORIES:United States,data-access,financial,privacy,cybersecurity
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-71@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20250117
DTEND;VALUE=DATE:20250118
SUMMARY:DORA: DORA applies
DESCRIPTION:All DORA obligations (ICT risk management\, incident reporting\
 , testing\, third-party risk\, register of information) apply from 17 Jan 
 2025 (Art 64).\n\nRegulation (EU) 2022/2554 on digital operational resilie
 nce for the financial sector (Digital Operational Resilience Act) (Europea
 n Union)\n\nSource: https://eur-lex.europa.eu/eli/reg/2022/2554/oj\n\nhttp
 s://regulations.fru.dev/regulations/eu-dora
URL:https://regulations.fru.dev/regulations/eu-dora
CATEGORIES:European Union,cybersecurity,financial,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-102@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20250117
DTEND;VALUE=DATE:20250118
SUMMARY:NIS2: Digital infrastructure entities submit registration data
DESCRIPTION:DNS providers\, TLD registries\, domain registration services\,
  cloud\, data centre\, CDN\, managed (security) service providers\, market
 places\, search engines and social networks had to submit registration det
 ails to competent authorities (Art 27(2)).\n\nDirective (EU) 2022/2555 on 
 measures for a high common level of cybersecurity across the Union (NIS2 D
 irective) (European Union)\n\nSource: https://eur-lex.europa.eu/eli/dir/20
 22/2555/oj\n\nhttps://regulations.fru.dev/regulations/eu-nis2
URL:https://regulations.fru.dev/regulations/eu-nis2
CATEGORIES:European Union,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6944@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20250129
DTEND;VALUE=DATE:20250130
SUMMARY:Ontario Bill 194: Enhancing Digital Security and Trust Act in force
DESCRIPTION:Schedule 1 (cyber security\, AI and minors' data framework) and
  some FIPPA amendments come into force by OIC 361/2025.\n\nStrengthening C
 yber Security and Building Trust in the Public Sector Act\, 2024 (Ontario\
 , Canada)\n\nSource: https://www.ontario.ca/laws/oic/o250361\n\nhttps://re
 gulations.fru.dev/regulations/ca-on-bill194
URL:https://regulations.fru.dev/regulations/ca-on-bill194
CATEGORIES:Ontario\, Canada,cybersecurity,ai,privacy,children,breach-notifi
 cation
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-7008@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20250129
DTEND;VALUE=DATE:20250130
SUMMARY:Pakistan PECA: PECA amendment takes effect
DESCRIPTION:Act No. II of 2025 got presidential assent and took effect on 2
 9 Jan 2025\, per the Gazette of Pakistan.\n\nPrevention of Electronic Crim
 es Act\, 2016 (as amended by the Prevention of Electronic Crimes (Amendmen
 t) Act\, 2025) (Pakistan)\n\nSource: https://na.gov.pk/uploads/documents/6
 79b243193585_457.pdf\n\nhttps://regulations.fru.dev/regulations/pk-peca
URL:https://regulations.fru.dev/regulations/pk-peca
CATEGORIES:Pakistan,cybersecurity,online-safety
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-38@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20250202
DTEND;VALUE=DATE:20250203
SUMMARY:EU AI Act: Prohibited practices and AI literacy apply
DESCRIPTION:Chapters I and II apply\, including the Article 5 bans on prohi
 bited AI practices and the Article 4 AI literacy duty (Art 113(a)).\n\nReg
 ulation (EU) 2024/1689 laying down harmonised rules on artificial intellig
 ence (Artificial Intelligence Act)\, as amended by Regulation (EU) 2026/17
 44 (Digital Omnibus on AI) (European Union)\n\nSource: https://eur-lex.eur
 opa.eu/eli/reg/2024/1689/oj\n\nhttps://regulations.fru.dev/regulations/eu-
 ai-act
URL:https://regulations.fru.dev/regulations/eu-ai-act
CATEGORIES:European Union,ai,biometrics,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6858@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20250204
DTEND;VALUE=DATE:20250205
SUMMARY:EU Cyber Solidarity Act: Cyber Solidarity Act enters into force
DESCRIPTION:Published in the OJ on 2025-01-15\; enters into force on the 20
 th day.\n\nRegulation (EU) 2025/38 laying down measures to strengthen soli
 darity and capacities in the Union to detect\, prepare for and respond to 
 cyber threats and incidents (Cyber Solidarity Act) (European Union)\n\nSou
 rce: https://eur-lex.europa.eu/eli/reg/2025/38/oj/eng\n\nhttps://regulatio
 ns.fru.dev/regulations/eu-cyber-solidarity-act
URL:https://regulations.fru.dev/regulations/eu-cyber-solidarity-act
CATEGORIES:European Union,cybersecurity
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-238@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20250307
DTEND;VALUE=DATE:20250308
SUMMARY:HIPAA: Security Rule NPRM comment period closed
DESCRIPTION:Comments closed on the proposed HIPAA Security Rule update (90 
 FR 898)\; OCR has not issued a final rule.\n\nHIPAA Privacy\, Security and
  Breach Notification Rules (45 CFR Parts 160 and 164) (United States (Fede
 ral))\n\nSource: https://www.federalregister.gov/documents/2025/01/06/2024
 -30983/hipaa-security-rule-to-strengthen-the-cybersecurity-of-electronic-p
 rotected-health-information\n\nhttps://regulations.fru.dev/regulations/us-
 hipaa
URL:https://regulations.fru.dev/regulations/us-hipaa
CATEGORIES:United States (Federal),privacy,health,cybersecurity,breach-noti
 fication
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6891@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20250307
DTEND;VALUE=DATE:20250308
SUMMARY:HIPAA Security Rule update (NPRM): Comment period closes
DESCRIPTION:Public comments on the NPRM due.\n\nHIPAA Security Rule To Stre
 ngthen the Cybersecurity of Electronic Protected Health Information (propo
 sed rule) (United States)\n\nSource: https://www.federalregister.gov/docum
 ents/2025/01/06/2024-30983/hipaa-security-rule-to-strengthen-the-cybersecu
 rity-of-electronic-protected-health-information\n\nhttps://regulations.fru
 .dev/regulations/us-hhs-hipaa-security-nprm
URL:https://regulations.fru.dev/regulations/us-hhs-hipaa-security-nprm
CATEGORIES:United States,health,cybersecurity,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-157@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20250317
DTEND;VALUE=DATE:20250318
SUMMARY:UK Online Safety Act: Illegal harms duties enforceable
DESCRIPTION:Illegal content safety duties apply\; illegal content risk asse
 ssments had to be completed by 16 March 2025.\n\nOnline Safety Act 2023 (U
 nited Kingdom)\n\nSource: https://www.ofcom.org.uk/online-safety/illegal-a
 nd-harmful-content\n\nhttps://regulations.fru.dev/regulations/uk-osa
URL:https://regulations.fru.dev/regulations/uk-osa
CATEGORIES:United Kingdom,online-safety,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-128@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20250321
DTEND;VALUE=DATE:20250322
SUMMARY:Mexico LFPDPPP 2025: New LFPDPPP in force
DESCRIPTION:Law published 20 March 2025 enters into force the following day
 \, repealing the 2010 law.\n\nLey Federal de Protección de Datos Personal
 es en Posesión de los Particulares (2025) (Mexico)\n\nSource: https://www
 .diputados.gob.mx/LeyesBiblio/pdf/LFPDPPP.pdf\n\nhttps://regulations.fru.d
 ev/regulations/mx-lfpdppp
URL:https://regulations.fru.dev/regulations/mx-lfpdppp
CATEGORIES:Mexico,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-80@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20250325
DTEND;VALUE=DATE:20250326
SUMMARY:European Health Data Space (EHDS): EHDS enters into force
DESCRIPTION:Regulation (EU) 2025/327\, published 5 Mar 2025\, enters into f
 orce on the twentieth day following publication.\n\nRegulation (EU) 2025/3
 27 on the European Health Data Space (European Union)\n\nSource: https://e
 ur-lex.europa.eu/eli/reg/2025/327/oj\n\nhttps://regulations.fru.dev/regula
 tions/eu-ehds
URL:https://regulations.fru.dev/regulations/eu-ehds
CATEGORIES:European Union,health,privacy,data-access
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-7026@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20250327
DTEND;VALUE=DATE:20250328
SUMMARY:Indonesia PP 17/2025 (Child Protection Online): PP 17/2025 in force
DESCRIPTION:The regulation was signed\, promulgated and took effect on the 
 same day.\n\nGovernment Regulation No. 17 of 2025 on Governance of Electro
 nic Systems in Child Protection (Indonesia)\n\nSource: https://peraturan.b
 pk.go.id/Details/316698/pp-no-17-tahun-2025\n\nhttps://regulations.fru.dev
 /regulations/id-child-online-protection
URL:https://regulations.fru.dev/regulations/id-child-online-protection
CATEGORIES:Indonesia,children,online-safety,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6955@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20250330
DTEND;VALUE=DATE:20250331
SUMMARY:Peru PDPL and 2024 Regulation: New regulation in force
DESCRIPTION:Regulation enters into force 120 calendar days after publicatio
 n.\n\nLey N° 29733\, Ley de Protección de Datos Personales\, and its Reg
 ulation (Decreto Supremo N° 016-2024-JUS) (Peru)\n\nSource: https://www.g
 ob.pe/institucion/smv/normas-legales/6426760-016-2024-jus\n\nhttps://regul
 ations.fru.dev/regulations/pe-pdpl
URL:https://regulations.fru.dev/regulations/pe-pdpl
CATEGORIES:Peru,privacy,breach-notification,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-130@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20250401
DTEND;VALUE=DATE:20250402
SUMMARY:Malaysia PDPA: PDPA amendments phase 2
DESCRIPTION:'Data controller' terminology\, biometric data as sensitive dat
 a\, higher penalties\, Security Principle for processors\, and removal of 
 the cross-border whitelist take effect.\n\nPersonal Data Protection Act 20
 10 (Act 709)\, as amended by the Personal Data Protection (Amendment) Act 
 2024 (Act A1727) (Malaysia)\n\nSource: https://www.pdp.gov.my/ppdpv1/en/pe
 rsonal-data-protection-amendment-act-2024-commencement-date-determination/
 \n\nhttps://regulations.fru.dev/regulations/my-pdpa
URL:https://regulations.fru.dev/regulations/my-pdpa
CATEGORIES:Malaysia,privacy,breach-notification,biometrics,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-227@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20250408
DTEND;VALUE=DATE:20250409
SUMMARY:DOJ Bulk Data Rule: Prohibitions and restrictions take effect
DESCRIPTION:Core prohibitions on covered data transactions and security req
 uirements for restricted transactions apply.\n\nPreventing Access to U.S. 
 Sensitive Personal Data and Government-Related Data by Countries of Concer
 n or Covered Persons (28 CFR Part 202) - DOJ Data Security Program (United
  States (Federal))\n\nSource: https://www.federalregister.gov/documents/20
 25/01/08/2024-31486/preventing-access-to-us-sensitive-personal-data-and-go
 vernment-related-data-by-countries-of-concern\n\nhttps://regulations.fru.d
 ev/regulations/us-doj-bulk-data
URL:https://regulations.fru.dev/regulations/us-doj-bulk-data
CATEGORIES:United States (Federal),privacy,data-residency,cybersecurity,bio
 metrics,health,financial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-158@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20250416
DTEND;VALUE=DATE:20250417
SUMMARY:UK Online Safety Act: Children's access assessments due
DESCRIPTION:Services had to complete children's access assessments to deter
 mine whether children are likely to access them.\n\nOnline Safety Act 2023
  (United Kingdom)\n\nSource: https://www.ofcom.org.uk/online-safety/protec
 ting-children/protection-of-children-duties-under-the-online-safety-act\n\
 nhttps://regulations.fru.dev/regulations/uk-osa
URL:https://regulations.fru.dev/regulations/uk-osa
CATEGORIES:United Kingdom,online-safety,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-103@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20250417
DTEND;VALUE=DATE:20250418
SUMMARY:NIS2: Member States establish entity lists
DESCRIPTION:Member States had to establish lists of essential and important
  entities and notify the Commission of entity numbers (Art 3(3) and (5)). 
 Repeated every two years.\n\nDirective (EU) 2022/2555 on measures for a hi
 gh common level of cybersecurity across the Union (NIS2 Directive) (Europe
 an Union)\n\nSource: https://eur-lex.europa.eu/eli/dir/2022/2555/oj\n\nhtt
 ps://regulations.fru.dev/regulations/eu-nis2
URL:https://regulations.fru.dev/regulations/eu-nis2
CATEGORIES:European Union,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6941@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20250421
DTEND;VALUE=DATE:20250422
SUMMARY:Arkansas COPPA 2.0: Approved by Governor
DESCRIPTION:Became Act 952.\n\nArkansas Children and Teens' Online Privacy 
 Protection Act (Act 952 of 2025\, HB 1717) (Arkansas)\n\nSource: https://a
 rkleg.state.ar.us/Bills/Detail?id=HB1717&ddBienniumSession=2025%2F2025R\n\
 nhttps://regulations.fru.dev/regulations/us-ar-cttoppa
URL:https://regulations.fru.dev/regulations/us-ar-cttoppa
CATEGORIES:Arkansas,children,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-72@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20250430
DTEND;VALUE=DATE:20250501
SUMMARY:DORA: First registers of information submitted to the ESAs
DESCRIPTION:Competent authorities had to submit financial entities' registe
 rs of ICT third-party contractual arrangements (reference date 31 Mar 2025
 ) to the ESAs by 30 Apr 2025. National authorities set earlier deadlines f
 or entities.\n\nRegulation (EU) 2022/2554 on digital operational resilienc
 e for the financial sector (Digital Operational Resilience Act) (European 
 Union)\n\nSource: https://www.eba.europa.eu/publications-and-media/press-r
 eleases/esas-announce-timeline-collect-information-designation-critical-ic
 t-third-party-service-providers\n\nhttps://regulations.fru.dev/regulations
 /eu-dora
URL:https://regulations.fru.dev/regulations/eu-dora
CATEGORIES:European Union,cybersecurity,financial,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-35@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20250501
DTEND;VALUE=DATE:20250502
SUMMARY:China PI Compliance Audit Measures: PI compliance audit measures ta
 ke effect
DESCRIPTION:Self-audit and regulator-ordered audit regime applies\; 10M+ pr
 ocessors must audit at least every two years.\n\nAdministrative Measures f
 or Personal Information Protection Compliance Audits (CAC Order No. 18) (C
 hina)\n\nSource: https://www.cac.gov.cn/2025-02/14/c_1741233507681519.htm\
 n\nhttps://regulations.fru.dev/regulations/cn-pi-compliance-audit
URL:https://regulations.fru.dev/regulations/cn-pi-compliance-audit
CATEGORIES:China,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-275@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20250501
DTEND;VALUE=DATE:20250502
SUMMARY:NYDFS Cybersecurity Regulation (Part 500): Vulnerability scans\, ac
 cess privileges\, malware controls\, Class A monitoring
DESCRIPTION:500.5(a)(2) automated scans\, 500.7 access privilege restrictio
 ns\, 500.14(a)(2) malicious code protection\, and 500.14(b) Class A endpoi
 nt detection and centralized logging apply.\n\nNew York DFS Cybersecurity 
 Requirements for Financial Services Companies (23 NYCRR Part 500)\, Second
  Amendment (New York)\n\nSource: https://www.dfs.ny.gov/cybersecurity/23-N
 YCRR-Part-500\n\nhttps://regulations.fru.dev/regulations/us-ny-dfs-500
URL:https://regulations.fru.dev/regulations/us-ny-dfs-500
CATEGORIES:New York,cybersecurity,breach-notification,financial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-306@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20250507
DTEND;VALUE=DATE:20250508
SUMMARY:Utah AI Policy Act: SB 226 amendments effective
DESCRIPTION:Disclosure duties narrowed (on clear request or high-risk inter
 actions)\, safe harbor added\, provisions recodified in Title 13\, Ch. 75.
 \n\nUtah Artificial Intelligence Policy Act (SB 149\, 2024)\, as amended b
 y SB 226 and SB 332 (2025) (Utah)\n\nSource: https://le.utah.gov/~2025/bil
 ls/static/SB0226.html\n\nhttps://regulations.fru.dev/regulations/us-ut-aip
 a
URL:https://regulations.fru.dev/regulations/us-ut-aipa
CATEGORIES:Utah,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6928@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20250507
DTEND;VALUE=DATE:20250508
SUMMARY:Utah App Store Accountability Act: Act takes effect
DESCRIPTION:Definitions and general provisions effective.\n\nUtah App Store
  Accountability Act (SB 142) (Utah)\n\nSource: https://le.utah.gov/Session
 /2025/bills/enrolled/SB0142.pdf\n\nhttps://regulations.fru.dev/regulations
 /us-ut-app-store
URL:https://regulations.fru.dev/regulations/us-ut-app-store
CATEGORIES:Utah,children,privacy,online-safety
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6912@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20250509
DTEND;VALUE=DATE:20250510
SUMMARY:NY Algorithmic Pricing Disclosure Act: Signed as part of FY2026 bud
 get
DESCRIPTION:S3008C Part X signed as Chapter 58 of 2025.\n\nNew York Algorit
 hmic Pricing Disclosure Act (General Business Law section 349-a) (New York
 )\n\nSource: https://www.nysenate.gov/legislation/bills/2025/S3008/amendme
 nt/C\n\nhttps://regulations.fru.dev/regulations/us-ny-algo-pricing
URL:https://regulations.fru.dev/regulations/us-ny-algo-pricing
CATEGORIES:New York,privacy,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-298@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20250519
DTEND;VALUE=DATE:20250520
SUMMARY:TAKE IT DOWN Act: Criminal provisions effective on enactment
DESCRIPTION:Publishing or threatening to publish non-consensual intimate im
 ages\, including digital forgeries\, became a federal crime upon signature
 .\n\nTools to Address Known Exploitation by Immobilizing Technological Dee
 pfakes on Websites and Networks Act (TAKE IT DOWN Act) (United States (Fed
 eral))\n\nSource: https://www.govinfo.gov/content/pkg/PLAW-119publ12/html/
 PLAW-119publ12.htm\n\nhttps://regulations.fru.dev/regulations/us-take-it-d
 own
URL:https://regulations.fru.dev/regulations/us-take-it-down
CATEGORIES:United States (Federal),online-safety,ai,children,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-210@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20250523
DTEND;VALUE=DATE:20250524
SUMMARY:Colorado Privacy Act (CPA): SB 25-276 geolocation and sensitive-dat
 a sale amendment effective
DESCRIPTION:Adds precise geolocation data definitions and prohibits selling
  sensitive data without consent (effective on signature).\n\nColorado Priv
 acy Act (SB 21-190)\, C.R.S. 6-1-1301 et seq.\, as amended by HB 24-1130\,
  SB 24-041 and SB 25-276 (Colorado)\n\nSource: https://leg.colorado.gov/bi
 lls/sb25-276\n\nhttps://regulations.fru.dev/regulations/us-co-cpa
URL:https://regulations.fru.dev/regulations/us-co-cpa
CATEGORIES:Colorado,privacy,children,biometrics
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6993@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20250523
DTEND;VALUE=DATE:20250524
SUMMARY:Japan Active Cyber Defense Act: Act promulgated
DESCRIPTION:Act No. 42 of 2025 promulgated\; preparatory supplementary prov
 isions apply from this day.\n\nAct on the Prevention of Damage from Unauth
 orized Acts against Important Computers (Act No. 42 of 2025) (Japan)\n\nSo
 urce: https://laws.e-gov.go.jp/api/2/law_revisions/507AC0000000042?respons
 e_format=json\n\nhttps://regulations.fru.dev/regulations/jp-active-cyber-d
 efense
URL:https://regulations.fru.dev/regulations/jp-active-cyber-defense
CATEGORIES:Japan,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6924@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20250527
DTEND;VALUE=DATE:20250528
SUMMARY:Texas App Store Accountability Act: Signed by Governor
DESCRIPTION:SB 2420 signed.\n\nTexas App Store Accountability Act (SB 2420)
  (Texas)\n\nSource: https://capitol.texas.gov/BillLookup/History.aspx?LegS
 ess=89R&Bill=SB2420\n\nhttps://regulations.fru.dev/regulations/us-tx-app-s
 tore
URL:https://regulations.fru.dev/regulations/us-tx-app-store
CATEGORIES:Texas,children,privacy,online-safety
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-2@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20250530
DTEND;VALUE=DATE:20250531
SUMMARY:Australia Cyber Security Act (ransomware reporting): Ransomware pay
 ment reporting starts
DESCRIPTION:Reporting business entities must report ransomware/cyber-extort
 ion payments to ASD within 72 hours of payment.\n\nCyber Security Act 2024
  (Cth) and Cyber Security (Ransomware Payment Reporting) Rules 2025 (Austr
 alia)\n\nSource: https://www.homeaffairs.gov.au/cyber-security-subsite/fil
 es/factsheet-ransomware-payment-reporting.pdf\n\nhttps://regulations.fru.d
 ev/regulations/au-cyber-security-act
URL:https://regulations.fru.dev/regulations/au-cyber-security-act
CATEGORIES:Australia,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6938@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20250530
DTEND;VALUE=DATE:20250531
SUMMARY:Nebraska Kids Code: Approved by Governor
DESCRIPTION:LB 504 signed.\n\nNebraska Age-Appropriate Online Design Code A
 ct (LB 504) (Nebraska)\n\nSource: https://nebraskalegislature.gov/FloorDoc
 s/109/PDF/Slip/LB504.pdf\n\nhttps://regulations.fru.dev/regulations/us-ne-
 aadc
URL:https://regulations.fru.dev/regulations/us-ne-aadc
CATEGORIES:Nebraska,children,privacy,online-safety
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6986@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20250601
DTEND;VALUE=DATE:20250602
SUMMARY:China Facial Recognition Measures: Facial recognition measures take
  effect
DESCRIPTION:Consent\, impact assessment\, storage and filing duties apply.\
 n\nMeasures for the Security Management of Facial Recognition Technology A
 pplications (China)\n\nSource: https://www.cac.gov.cn/2025-03/21/c_1744174
 262156096.htm\n\nhttps://regulations.fru.dev/regulations/cn-facial-recogni
 tion
URL:https://regulations.fru.dev/regulations/cn-facial-recognition
CATEGORIES:China,biometrics,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-131@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20250601
DTEND;VALUE=DATE:20250602
SUMMARY:Malaysia PDPA: PDPA amendments phase 3
DESCRIPTION:Mandatory DPO appointment\, data breach notification\, and data
  portability take effect.\n\nPersonal Data Protection Act 2010 (Act 709)\,
  as amended by the Personal Data Protection (Amendment) Act 2024 (Act A172
 7) (Malaysia)\n\nSource: https://www.pdp.gov.my/ppdpv1/en/personal-data-pr
 otection-amendment-act-2024-commencement-date-determination/\n\nhttps://re
 gulations.fru.dev/regulations/my-pdpa
URL:https://regulations.fru.dev/regulations/my-pdpa
CATEGORIES:Malaysia,privacy,breach-notification,biometrics,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-265@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20250602
DTEND;VALUE=DATE:20250603
SUMMARY:New Jersey NJDPA: Division of Consumer Affairs proposes NJDPA rules
  (N.J.A.C. 13:45L)
DESCRIPTION:Proposed rules published at 57 N.J.R. 1101(a)\; comments were d
 ue Aug 1\, 2025.\n\nNew Jersey Data Privacy Act (P.L.2023\, c.266\; S332) 
 (New Jersey)\n\nSource: https://www.njoag.gov/murphy-administration-announ
 ces-proposed-rules-establishing-comprehensive-consumer-data-privacy-protec
 tions/\n\nhttps://regulations.fru.dev/regulations/us-nj-njdpa
URL:https://regulations.fru.dev/regulations/us-nj-njdpa
CATEGORIES:New Jersey,privacy,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-119@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20250604
DTEND;VALUE=DATE:20250605
SUMMARY:Japan AI Promotion Act: AI Promotion Act promulgated and partly in 
 force
DESCRIPTION:Most provisions\, including basic principles and stakeholder du
 ties\, take effect on promulgation.\n\nAct on Promotion of Research and De
 velopment\, and Utilization of Artificial Intelligence-Related Technology 
 (Japan)\n\nSource: https://www8.cao.go.jp/cstp/ai/ai_act/ai_act.html\n\nht
 tps://regulations.fru.dev/regulations/jp-ai-act
URL:https://regulations.fru.dev/regulations/jp-ai-act
CATEGORIES:Japan,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-5@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20250610
DTEND;VALUE=DATE:20250611
SUMMARY:Australia Privacy Act: Statutory tort for serious invasions of priv
 acy commences
DESCRIPTION:Individuals can sue for serious invasions of privacy (Schedule 
 2)\, 6 months after Royal Assent.\n\nPrivacy Act 1988 (Cth)\, as amended b
 y the Privacy and Other Legislation Amendment Act 2024 (Australia)\n\nSour
 ce: https://www.legislation.gov.au/C2024A00128/asmade\n\nhttps://regulatio
 ns.fru.dev/regulations/au-privacy-act
URL:https://regulations.fru.dev/regulations/au-privacy-act
CATEGORIES:Australia,privacy,children,breach-notification,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6946@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20250611
DTEND;VALUE=DATE:20250612
SUMMARY:Alberta POPA: POPA in force
DESCRIPTION:Act comes into force with the Access to Information Act\, procl
 aimed in force June 11\, 2025.\n\nProtection of Privacy Act (Alberta\, Can
 ada)\n\nSource: https://kings-printer.alberta.ca/1266.cfm?page=p28p5.cfm&l
 eg_type=Acts&isbncln=9780779861309&display=html\n\nhttps://regulations.fru
 .dev/regulations/ca-ab-popa
URL:https://regulations.fru.dev/regulations/ca-ab-popa
CATEGORIES:Alberta\, Canada,privacy,breach-notification,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6936@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20250612
DTEND;VALUE=DATE:20250613
SUMMARY:Vermont Kids Code: Signed by Governor
DESCRIPTION:Became Act 63.\n\nVermont Age-Appropriate Design Code (Act 63 o
 f 2025\, S.69) (Vermont)\n\nSource: https://legislature.vermont.gov/bill/s
 tatus/2026/S.69\n\nhttps://regulations.fru.dev/regulations/us-vt-aadc
URL:https://regulations.fru.dev/regulations/us-vt-aadc
CATEGORIES:Vermont,children,privacy,online-safety
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-16@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20250618
DTEND;VALUE=DATE:20250619
SUMMARY:Canada Bill C-8 / CCSPA: Bill C-8 introduced
DESCRIPTION:First reading in the House of Commons.\n\nCritical Cyber System
 s Protection Act (enacted by Bill C-8\, An Act respecting cyber security) 
 (Canada)\n\nSource: https://www.parl.ca/legisinfo/en/bill/45-1/c-8\n\nhttp
 s://regulations.fru.dev/regulations/ca-ccspa
URL:https://regulations.fru.dev/regulations/ca-ccspa
CATEGORIES:Canada,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-148@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20250619
DTEND;VALUE=DATE:20250620
SUMMARY:Data (Use and Access) Act: Royal Assent
DESCRIPTION:The Act receives Royal Assent\; commencement staged by regulati
 ons.\n\nData (Use and Access) Act 2025 (United Kingdom)\n\nSource: https:/
 /www.legislation.gov.uk/ukpga/2025/18/contents\n\nhttps://regulations.fru.
 dev/regulations/uk-duaa
URL:https://regulations.fru.dev/regulations/uk-duaa
CATEGORIES:United Kingdom,privacy,data-access,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6919@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20250620
DTEND;VALUE=DATE:20250621
SUMMARY:NY Child Data Protection Act: Takes effect
DESCRIPTION:Effective one year after becoming law.\n\nNew York Child Data P
 rotection Act (New York)\n\nSource: https://www.nysenate.gov/legislation/b
 ills/2023/S7695/amendment/B\n\nhttps://regulations.fru.dev/regulations/us-
 ny-cdpa
URL:https://regulations.fru.dev/regulations/us-ny-cdpa
CATEGORIES:New York,children,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-303@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20250622
DTEND;VALUE=DATE:20250623
SUMMARY:TRAIGA: HB 149 signed
DESCRIPTION:Governor Abbott signs TRAIGA.\n\nTexas Responsible Artificial I
 ntelligence Governance Act (HB 149\, 89th Legislature) (Texas)\n\nSource: 
 https://capitol.texas.gov/BillLookup/History.aspx?LegSess=89R&Bill=HB149\n
 \nhttps://regulations.fru.dev/regulations/us-tx-traiga
URL:https://regulations.fru.dev/regulations/us-tx-traiga
CATEGORIES:Texas,ai,biometrics
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-213@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20250623
DTEND;VALUE=DATE:20250624
SUMMARY:COPPA Rule: Amended COPPA Rule takes effect
DESCRIPTION:The April 2025 amendments to 16 CFR Part 312 became effective\;
  during the transition operators could comply with either the pre-2025 or 
 the amended Rule.\n\nChildren's Online Privacy Protection Rule (16 CFR Par
 t 312)\, as amended April 2025 (United States (Federal))\n\nSource: https:
 //www.federalregister.gov/documents/2025/04/22/2025-05904/childrens-online
 -privacy-protection-rule\n\nhttps://regulations.fru.dev/regulations/us-cop
 pa
URL:https://regulations.fru.dev/regulations/us-coppa
CATEGORIES:United States (Federal),privacy,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6897@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20250627
DTEND;VALUE=DATE:20250628
SUMMARY:California ADS employment regulations: OAL approves regulations
DESCRIPTION:Office of Administrative Law approves the Civil Rights Council'
 s ADS rules.\n\nCivil Rights Council Regulations on Automated-Decision Sys
 tems in Employment (FEHA) (California)\n\nSource: https://calcivilrights.c
 a.gov/2025/06/30/civil-rights-council-secures-approval-for-regulations-to-
 protect-against-employment-discrimination-related-to-artificial-intelligen
 ce/\n\nhttps://regulations.fru.dev/regulations/us-ca-ads-regs
URL:https://regulations.fru.dev/regulations/us-ca-ads-regs
CATEGORIES:California,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6931@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20250630
DTEND;VALUE=DATE:20250701
SUMMARY:Louisiana app store age verification law: Signed by Governor
DESCRIPTION:Became Act 481 of the 2025 Regular Session.\n\nLouisiana Act 48
 1 of 2025 on Minors' Use of Applications (HB 570) (Louisiana)\n\nSource: h
 ttps://legis.la.gov/legis/BillInfo.aspx?s=25RS&b=HB570&sbi=y\n\nhttps://re
 gulations.fru.dev/regulations/us-la-app-store
URL:https://regulations.fru.dev/regulations/us-la-app-store
CATEGORIES:Louisiana,children,privacy,online-safety
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-211@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20250701
DTEND;VALUE=DATE:20250702
SUMMARY:Colorado Privacy Act (CPA): Biometric identifier amendment (HB 24-1
 130) effective
DESCRIPTION:Any controller processing biometric identifiers must adopt a wr
 itten biometric policy\, give notice\, obtain consent and follow retention
 /deletion rules.\n\nColorado Privacy Act (SB 21-190)\, C.R.S. 6-1-1301 et 
 seq.\, as amended by HB 24-1130\, SB 24-041 and SB 25-276 (Colorado)\n\nSo
 urce: https://leg.colorado.gov/bills/hb24-1130\n\nhttps://regulations.fru.
 dev/regulations/us-co-cpa
URL:https://regulations.fru.dev/regulations/us-co-cpa
CATEGORIES:Colorado,privacy,children,biometrics
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6969@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20250701
DTEND;VALUE=DATE:20250702
SUMMARY:Digital Services Act: DSA transparency report templates mandatory
DESCRIPTION:Implementing Regulation (EU) 2024/2835 requires all intermediar
 y services to use harmonised templates for content moderation data collect
 ed from this date.\n\nRegulation (EU) 2022/2065 on a Single Market for Dig
 ital Services (Digital Services Act) (European Union)\n\nSource: https://e
 ur-lex.europa.eu/eli/reg_impl/2024/2835/oj/eng\n\nhttps://regulations.fru.
 dev/regulations/eu-dsa
URL:https://regulations.fru.dev/regulations/eu-dsa
CATEGORIES:European Union,online-safety,children,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6945@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20250701
DTEND;VALUE=DATE:20250702
SUMMARY:Ontario Bill 194: FIPPA privacy amendments in force
DESCRIPTION:Remaining FIPPA amendments\, including privacy impact assessmen
 ts\, safeguards and breach notification to the IPC\, come into force.\n\nS
 trengthening Cyber Security and Building Trust in the Public Sector Act\, 
 2024 (Ontario\, Canada)\n\nSource: https://www.ontario.ca/laws/oic/o250361
 \n\nhttps://regulations.fru.dev/regulations/ca-on-bill194
URL:https://regulations.fru.dev/regulations/ca-on-bill194
CATEGORIES:Ontario\, Canada,cybersecurity,ai,privacy,children,breach-notifi
 cation
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-284@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20250701
DTEND;VALUE=DATE:20250702
SUMMARY:Oregon OCPA: OCPA applies to nonprofits
DESCRIPTION:Nonprofit organizations meeting the thresholds become subject t
 o OCPA.\n\nOregon Consumer Privacy Act (SB 619\, 2023) (Oregon)\n\nSource:
  https://www.doj.state.or.us/consumer-protection/for-businesses/privacy-la
 w-faqs-for-nonprofits/\n\nhttps://regulations.fru.dev/regulations/us-or-oc
 pa
URL:https://regulations.fru.dev/regulations/us-or-ocpa
CATEGORIES:Oregon,privacy,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-300@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20250701
DTEND;VALUE=DATE:20250702
SUMMARY:Tennessee TIPA: TIPA takes effect
DESCRIPTION:Controller and processor obligations and consumer rights under 
 Tenn. Code Ann. 47-18-3301 et seq. apply.\n\nTennessee Information Protect
 ion Act (HB 1181 / SB 73\, 2023) (Tennessee)\n\nSource: https://wapp.capit
 ol.tn.gov/apps/BillInfo/Default.aspx?BillNumber=HB1181&GA=113\n\nhttps://r
 egulations.fru.dev/regulations/us-tn-tipa
URL:https://regulations.fru.dev/regulations/us-tn-tipa
CATEGORIES:Tennessee,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-7018@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20250701
DTEND;VALUE=DATE:20250702
SUMMARY:Vietnam Law on Data: Law on Data takes effect
DESCRIPTION:The Law on Data enters into force.\n\nLaw on Data (Law No. 60/2
 024/QH15) (Vietnam)\n\nSource: https://vanban.chinhphu.vn/?pageid=27160&do
 cid=212488\n\nhttps://regulations.fru.dev/regulations/vn-data-law
URL:https://regulations.fru.dev/regulations/vn-data-law
CATEGORIES:Vietnam,data-residency,data-access,cybersecurity
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-73@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20250708
DTEND;VALUE=DATE:20250709
SUMMARY:DORA: TLPT regulatory technical standards enter into force
DESCRIPTION:Commission Delegated Regulation (EU) 2025/1190 (published 18 Ju
 ne 2025) sets criteria for which financial entities must run threat-led pe
 netration testing\, plus methodology and tester requirements.\n\nRegulatio
 n (EU) 2022/2554 on digital operational resilience for the financial secto
 r (Digital Operational Resilience Act) (European Union)\n\nSource: https:/
 /eur-lex.europa.eu/eli/reg_del/2025/1190/oj\n\nhttps://regulations.fru.dev
 /regulations/eu-dora
URL:https://regulations.fru.dev/regulations/eu-dora
CATEGORIES:European Union,cybersecurity,financial,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-266@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20250715
DTEND;VALUE=DATE:20250716
SUMMARY:New Jersey NJDPA: Universal opt-out mechanism must be honored
DESCRIPTION:Controllers that sell personal data or process it for targeted 
 advertising must honor user-selected universal opt-out signals within six 
 months of the effective date (N.J.S.A. 56:8-166.11).\n\nNew Jersey Data Pr
 ivacy Act (P.L.2023\, c.266\; S332) (New Jersey)\n\nSource: https://pub.nj
 leg.state.nj.us/Bills/2022/PL23/266_.PDF\n\nhttps://regulations.fru.dev/re
 gulations/us-nj-njdpa
URL:https://regulations.fru.dev/regulations/us-nj-njdpa
CATEGORIES:New Jersey,privacy,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-159@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20250725
DTEND;VALUE=DATE:20250726
SUMMARY:UK Online Safety Act: Protection of children duties apply
DESCRIPTION:Children's safety duties and Protection of Children Codes take 
 effect\, including highly effective age assurance\; children's risk assess
 ments due by 24 July 2025.\n\nOnline Safety Act 2023 (United Kingdom)\n\nS
 ource: https://www.ofcom.org.uk/online-safety/protecting-children/protecti
 on-of-children-duties-under-the-online-safety-act\n\nhttps://regulations.f
 ru.dev/regulations/uk-osa
URL:https://regulations.fru.dev/regulations/uk-osa
CATEGORIES:United Kingdom,online-safety,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6881@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20250729
DTEND;VALUE=DATE:20250730
SUMMARY:CFPB Open Banking Rule (Section 1033): Court stays Forcht Bank liti
 gation
DESCRIPTION:E.D. Ky. stays the industry challenge after the CFPB says it wi
 ll reconsider the rule\; compliance dates stayed by 90 days.\n\nRequired R
 ulemaking on Personal Financial Data Rights (12 CFR Part 1033) (United Sta
 tes)\n\nSource: https://www.federalregister.gov/documents/2025/08/22/2025-
 16139/personal-financial-data-rights-reconsideration\n\nhttps://regulation
 s.fru.dev/regulations/us-cfpb-1033
URL:https://regulations.fru.dev/regulations/us-cfpb-1033
CATEGORIES:United States,data-access,financial,privacy,cybersecurity
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-255@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20250731
DTEND;VALUE=DATE:20250801
SUMMARY:Minnesota Consumer Data Privacy Act (MCDPA): MCDPA takes effect
DESCRIPTION:Consumer rights and controller/processor obligations apply (pos
 tsecondary institutions excepted).\n\nMinnesota Consumer Data Privacy Act 
 (HF 4757\, 2024 Minn. Laws ch. 121\, art. 5)\, Minn. Stat. 325M.10-325M.21
  (Minnesota)\n\nSource: https://www.revisor.mn.gov/statutes/cite/325M.20\n
 \nhttps://regulations.fru.dev/regulations/us-mn-mcdpa
URL:https://regulations.fru.dev/regulations/us-mn-mcdpa
CATEGORIES:Minnesota,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-39@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20250802
DTEND;VALUE=DATE:20250803
SUMMARY:EU AI Act: GPAI\, governance\, notified bodies and penalties apply
DESCRIPTION:Chapter III Section 4 (notifying authorities)\, Chapter V (gene
 ral-purpose AI model obligations)\, Chapter VII (governance)\, Chapter XII
  (penalties\, except Art 101) and Art 78 apply (Art 113(b)).\n\nRegulation
  (EU) 2024/1689 laying down harmonised rules on artificial intelligence (A
 rtificial Intelligence Act)\, as amended by Regulation (EU) 2026/1744 (Dig
 ital Omnibus on AI) (European Union)\n\nSource: https://eur-lex.europa.eu/
 eli/reg/2024/1689/oj\n\nhttps://regulations.fru.dev/regulations/eu-ai-act
URL:https://regulations.fru.dev/regulations/eu-ai-act
CATEGORIES:European Union,ai,biometrics,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-115@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20250814
DTEND;VALUE=DATE:20250815
SUMMARY:Israel Privacy Protection Law Amendment 13: Amendment 13 in force
DESCRIPTION:Amended Privacy Protection Law\, PPA enforcement powers and sta
 tutory damages take effect.\n\nPrivacy Protection Law\, 5741-1981 (Amendme
 nt No. 13) (Israel)\n\nSource: https://www.gov.il/en/departments/the_priva
 cy_protection_authority/govil-landing-page\n\nhttps://regulations.fru.dev/
 regulations/il-ppl-amendment-13
URL:https://regulations.fru.dev/regulations/il-ppl-amendment-13
CATEGORIES:Israel,privacy,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-149@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20250820
DTEND;VALUE=DATE:20250821
SUMMARY:Data (Use and Access) Act: Stage 1 commencement
DESCRIPTION:Technical data protection provisions\, ICO statutory objects\, 
 Smart Data framework (Part 1) and AI/copyright reporting duties commence (
 Commencement No. 1 Regulations 2025).\n\nData (Use and Access) Act 2025 (U
 nited Kingdom)\n\nSource: https://www.legislation.gov.uk/ukpga/2025/18/con
 tents\n\nhttps://regulations.fru.dev/regulations/uk-duaa
URL:https://regulations.fru.dev/regulations/uk-duaa
CATEGORIES:United Kingdom,privacy,data-access,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6882@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20250822
DTEND;VALUE=DATE:20250823
SUMMARY:CFPB Open Banking Rule (Section 1033): Reconsideration ANPR publish
 ed
DESCRIPTION:CFPB seeks comment on representatives\, fees\, data security an
 d privacy\, and on extending compliance dates.\n\nRequired Rulemaking on P
 ersonal Financial Data Rights (12 CFR Part 1033) (United States)\n\nSource
 : https://www.federalregister.gov/documents/2025/08/22/2025-16139/personal
 -financial-data-rights-reconsideration\n\nhttps://regulations.fru.dev/regu
 lations/us-cfpb-1033
URL:https://regulations.fru.dev/regulations/us-cfpb-1033
CATEGORIES:United States,data-access,financial,privacy,cybersecurity
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-14@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20250823
DTEND;VALUE=DATE:20250824
SUMMARY:Brazil LGPD: Deadline to adopt ANPD standard contractual clauses
DESCRIPTION:Agents relying on contractual clauses for international transfe
 rs must incorporate the ANPD-approved SCCs into their contracts within 12 
 months of publication.\n\nLei Geral de Proteção de Dados Pessoais (Law N
 o. 13.709/2018) (Brazil)\n\nSource: https://www.in.gov.br/en/web/dou/-/res
 olucao-cd/anpd-n-19-de-23-de-agosto-de-2024-580095396\n\nhttps://regulatio
 ns.fru.dev/regulations/br-lgpd
URL:https://regulations.fru.dev/regulations/br-lgpd
CATEGORIES:Brazil,privacy,breach-notification,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-200@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20250828
DTEND;VALUE=DATE:20250829
SUMMARY:Colorado AI Act: SB 25B-004 delays the act
DESCRIPTION:Special-session bill pushes the SB 24-205 effective date from F
 ebruary 1\, 2026 to June 30\, 2026.\n\nColorado SB 24-205 (Consumer Protec
 tions for Artificial Intelligence)\, as delayed by SB 25B-004 and repealed
  and reenacted by SB 26-189 (Automated Decision-Making Technology) (Colora
 do)\n\nSource: https://leg.colorado.gov/bills/sb25b-004\n\nhttps://regulat
 ions.fru.dev/regulations/us-co-ai-act
URL:https://regulations.fru.dev/regulations/us-co-ai-act
CATEGORIES:Colorado,ai,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-29@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20250901
DTEND;VALUE=DATE:20250902
SUMMARY:China AI Content Labeling Measures: AI content labeling measures an
 d GB 45438-2025 take effect
DESCRIPTION:Explicit and implicit labeling duties for AI-generated content 
 and platform detection duties apply.\n\nMeasures for Labeling AI-Generated
  Synthetic Content (China)\n\nSource: https://www.cac.gov.cn/2025-03/14/c_
 1743654684782215.htm\n\nhttps://regulations.fru.dev/regulations/cn-ai-labe
 ling
URL:https://regulations.fru.dev/regulations/cn-ai-labeling
CATEGORIES:China,ai,online-safety
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-120@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20250901
DTEND;VALUE=DATE:20250902
SUMMARY:Japan AI Promotion Act: AI Promotion Act fully in force
DESCRIPTION:Provisions establishing the AI Strategy Headquarters and AI Bas
 ic Plan take effect.\n\nAct on Promotion of Research and Development\, and
  Utilization of Artificial Intelligence-Related Technology (Japan)\n\nSour
 ce: https://www8.cao.go.jp/cstp/ai/ai_act/ai_act.html\n\nhttps://regulatio
 ns.fru.dev/regulations/jp-ai-act
URL:https://regulations.fru.dev/regulations/jp-ai-act
CATEGORIES:Japan,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-109@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20250903
DTEND;VALUE=DATE:20250904
SUMMARY:EU-US Data Privacy Framework: General Court upholds DPF (Latombe v 
 Commission)
DESCRIPTION:General Court dismissed Philippe Latombe's action for annulment
  (Case T-553/23) and confirmed the US offered adequate protection when the
  decision was adopted.\n\nCommission Implementing Decision (EU) 2023/1795 
 on the adequate level of protection of personal data under the EU-US Data 
 Privacy Framework (European Union)\n\nSource: https://curia.europa.eu/jcms
 /upload/docs/application/pdf/2025-09/cp250106en.pdf\n\nhttps://regulations
 .fru.dev/regulations/eu-us-dpf
URL:https://regulations.fru.dev/regulations/eu-us-dpf
CATEGORIES:European Union,privacy,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6962@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20250909
DTEND;VALUE=DATE:20250910
SUMMARY:Peru AI Law and Regulation: Regulation published
DESCRIPTION:DS 115-2025-PCM approving the AI regulation published in El Per
 uano.\n\nLey N° 31814\, Ley que promueve el uso de la inteligencia artifi
 cial en favor del desarrollo económico y social del país\, and its Regul
 ation (Decreto Supremo N° 115-2025-PCM) (Peru)\n\nSource: https://www.gob
 .pe/institucion/pcm/normas-legales/7133522-115-2025-pcm\n\nhttps://regulat
 ions.fru.dev/regulations/pe-ai-law
URL:https://regulations.fru.dev/regulations/pe-ai-law
CATEGORIES:Peru,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-57@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20250912
DTEND;VALUE=DATE:20250913
SUMMARY:EU Data Act: Data Act applies
DESCRIPTION:Most obligations apply\, including user data access and sharing
  (Chapters II-III)\, cloud switching (Chapter VI) and interoperability\; C
 hapter IV unfair terms apply to contracts concluded after this date (Art 5
 0).\n\nRegulation (EU) 2023/2854 on harmonised rules on fair access to and
  use of data (Data Act) (European Union)\n\nSource: https://eur-lex.europa
 .eu/eli/reg/2023/2854/oj\n\nhttps://regulations.fru.dev/regulations/eu-dat
 a-act
URL:https://regulations.fru.dev/regulations/eu-data-act
CATEGORIES:European Union,data-access,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-58@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20250912
DTEND;VALUE=DATE:20250913
SUMMARY:EU Data Act: Member States notify penalty rules
DESCRIPTION:Member States had to notify the Commission of their penalty rul
 es (Art 40(2)).\n\nRegulation (EU) 2023/2854 on harmonised rules on fair a
 ccess to and use of data (Data Act) (European Union)\n\nSource: https://eu
 r-lex.europa.eu/eli/reg/2023/2854/oj\n\nhttps://regulations.fru.dev/regula
 tions/eu-data-act
URL:https://regulations.fru.dev/regulations/eu-data-act
CATEGORIES:European Union,data-access,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-133@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20250919
DTEND;VALUE=DATE:20250920
SUMMARY:Nigeria NDPA: GAID 2025 takes effect
DESCRIPTION:General Application and Implementation Directive becomes effect
 ive\, replacing the NDPR 2019 and NDPR Implementation Framework.\n\nNigeri
 a Data Protection Act\, 2023 and NDPA General Application and Implementati
 on Directive (GAID) 2025 (Nigeria)\n\nSource: https://ndpc.gov.ng/resource
 s/\n\nhttps://regulations.fru.dev/regulations/ng-ndpa
URL:https://regulations.fru.dev/regulations/ng-ndpa
CATEGORIES:Nigeria,privacy,breach-notification,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-167@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20250922
DTEND;VALUE=DATE:20250923
SUMMARY:CCPA / CPRA: ADMT\, risk assessment and cybersecurity audit regulat
 ions approved
DESCRIPTION:OAL approves the CCPA Updates\, Cybersecurity Audit\, Risk Asse
 ssment\, ADMT and Insurance regulations and files them with the Secretary 
 of State.\n\nCalifornia Consumer Privacy Act of 2018\, as amended by the C
 alifornia Privacy Rights Act of 2020 (Cal. Civ. Code 1798.100 et seq.) and
  CPPA regulations (Cal. Code Regs. tit. 11\, 7000 et seq.) (California)\n\
 nSource: https://cppa.ca.gov/regulations/ccpa_updates.html\n\nhttps://regu
 lations.fru.dev/regulations/us-ca-ccpa
URL:https://regulations.fru.dev/regulations/us-ca-ccpa
CATEGORIES:California,privacy,ai,cybersecurity,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-65@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20250924
DTEND;VALUE=DATE:20250925
SUMMARY:Data Governance Act: Legacy data intermediaries must comply
DESCRIPTION:Entities that were already providing data intermediation servic
 es on 23 June 2022 had to comply with Chapter III by 24 Sep 2025 (Art 37).
 \n\nRegulation (EU) 2022/868 on European data governance (Data Governance 
 Act) (European Union)\n\nSource: https://eur-lex.europa.eu/eli/reg/2022/86
 8/oj\n\nhttps://regulations.fru.dev/regulations/eu-dga
URL:https://regulations.fru.dev/regulations/eu-dga
CATEGORIES:European Union,data-access,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-135@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20250924
DTEND;VALUE=DATE:20250925
SUMMARY:New Zealand Privacy Act: Privacy Amendment Act 2025 technical chang
 es commence
DESCRIPTION:Technical amendments commence the day after Royal Assent (23 Se
 p 2025).\n\nPrivacy Act 2020 (New Zealand)\, as amended by the Privacy Ame
 ndment Act 2025 (New Zealand)\n\nSource: https://www.justice.govt.nz/justi
 ce-sector-policy/key-initiatives/enhancing-the-privacy-act/\n\nhttps://reg
 ulations.fru.dev/regulations/nz-privacy-act
URL:https://regulations.fru.dev/regulations/nz-privacy-act
CATEGORIES:New Zealand,privacy,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-184@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20250929
DTEND;VALUE=DATE:20250930
SUMMARY:California SB 53 (TFAIA): SB 53 signed
DESCRIPTION:Governor Newsom signs SB 53 (chapter 138).\n\nCalifornia SB 53\
 , Transparency in Frontier Artificial Intelligence Act (Stats. 2025\, ch. 
 138) (California)\n\nSource: https://leginfo.legislature.ca.gov/faces/bill
 NavClient.xhtml?bill_id=202520260SB53\n\nhttps://regulations.fru.dev/regul
 ations/us-ca-sb53
URL:https://regulations.fru.dev/regulations/us-ca-sb53
CATEGORIES:California,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6956@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20250930
DTEND;VALUE=DATE:20251001
SUMMARY:Peru PDPL and 2024 Regulation: Data portability applies
DESCRIPTION:Article 76 on portability takes effect six months after the reg
 ulation enters into force.\n\nTentative: depends on a proposal not yet ado
 pted.\n\nLey N° 29733\, Ley de Protección de Datos Personales\, and its 
 Regulation (Decreto Supremo N° 016-2024-JUS) (Peru)\n\nSource: https://ww
 w.gob.pe/institucion/smv/normas-legales/6426760-016-2024-jus\n\nhttps://re
 gulations.fru.dev/regulations/pe-pdpl
URL:https://regulations.fru.dev/regulations/pe-pdpl
CATEGORIES:Peru,privacy,breach-notification,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6898@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20251001
DTEND;VALUE=DATE:20251002
SUMMARY:California ADS employment regulations: ADS regulations take effect
DESCRIPTION:Rules apply to employment decisions using automated-decision sy
 stems.\n\nCivil Rights Council Regulations on Automated-Decision Systems i
 n Employment (FEHA) (California)\n\nSource: https://calcivilrights.ca.gov/
 2025/06/30/civil-rights-council-secures-approval-for-regulations-to-protec
 t-against-employment-discrimination-related-to-artificial-intelligence/\n\
 nhttps://regulations.fru.dev/regulations/us-ca-ads-regs
URL:https://regulations.fru.dev/regulations/us-ca-ads-regs
CATEGORIES:California,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-212@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20251001
DTEND;VALUE=DATE:20251002
SUMMARY:Colorado Privacy Act (CPA): Minors' data amendment (SB 24-041) effe
 ctive
DESCRIPTION:Controllers offering online services to minors must use reasona
 ble care\, conduct assessments\, and obtain consent for targeted ads\, sal
 e and certain profiling of minors.\n\nColorado Privacy Act (SB 21-190)\, C
 .R.S. 6-1-1301 et seq.\, as amended by HB 24-1130\, SB 24-041 and SB 25-27
 6 (Colorado)\n\nSource: https://leg.colorado.gov/bills/sb24-041\n\nhttps:/
 /regulations.fru.dev/regulations/us-co-cpa
URL:https://regulations.fru.dev/regulations/us-co-cpa
CATEGORIES:Colorado,privacy,children,biometrics
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-252@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20251001
DTEND;VALUE=DATE:20251002
SUMMARY:Maryland Online Data Privacy Act (MODPA): MODPA takes effect
DESCRIPTION:Act takes effect\; data protection assessments apply to process
 ing activities on or after Oct 1\, 2025.\n\nMaryland Online Data Privacy A
 ct of 2024 (SB 541 / HB 567)\, Md. Code\, Com. Law 14-4601 et seq. (Maryla
 nd)\n\nSource: https://mgaleg.maryland.gov/2024RS/Chapters_noln/CH_455_sb0
 541e.pdf\n\nhttps://regulations.fru.dev/regulations/us-md-modpa
URL:https://regulations.fru.dev/regulations/us-md-modpa
CATEGORIES:Maryland,privacy,children,health,biometrics
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-259@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20251001
DTEND;VALUE=DATE:20251002
SUMMARY:Montana Consumer Data Privacy Act (MCDPA): SB 297 amendments take e
 ffect\; cure period eliminated
DESCRIPTION:Lower thresholds (25\,000 / 15\,000 + 25%)\, minors' data prote
 ctions\, AG assessment demands\; the 60-day cure period is removed.\n\nMon
 tana Consumer Data Privacy Act (SB 384\, 2023)\, Mont. Code Ann. 30-14-280
 1 et seq.\, as amended by SB 297 (2025) (Montana)\n\nSource: https://archi
 ve.legmt.gov/bills/mca/title_0300/chapter_0140/part_0280/section_0170/0300
 -0140-0280-0170.html\n\nhttps://regulations.fru.dev/regulations/us-mt-mcdp
 a
URL:https://regulations.fru.dev/regulations/us-mt-mcdpa
CATEGORIES:Montana,privacy,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-228@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20251006
DTEND;VALUE=DATE:20251007
SUMMARY:DOJ Bulk Data Rule: Due diligence\, audit and reporting obligations
  apply
DESCRIPTION:Subpart J (data compliance program\, due diligence and audits f
 or restricted transactions) and reporting requirements in 202.1103 and 202
 .1104 apply.\n\nPreventing Access to U.S. Sensitive Personal Data and Gove
 rnment-Related Data by Countries of Concern or Covered Persons (28 CFR Par
 t 202) - DOJ Data Security Program (United States (Federal))\n\nSource: ht
 tps://www.federalregister.gov/documents/2025/01/08/2024-31486/preventing-a
 ccess-to-us-sensitive-personal-data-and-government-related-data-by-countri
 es-of-concern\n\nhttps://regulations.fru.dev/regulations/us-doj-bulk-data
URL:https://regulations.fru.dev/regulations/us-doj-bulk-data
CATEGORIES:United States (Federal),privacy,data-residency,cybersecurity,bio
 metrics,health,financial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6910@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20251008
DTEND;VALUE=DATE:20251009
SUMMARY:California social media account deletion: Signed by Governor
DESCRIPTION:Chaptered as Chapter 464\, Statutes of 2025.\n\nAccount Cancell
 ation (AB 656) (California)\n\nSource: https://leginfo.legislature.ca.gov/
 faces/billNavClient.xhtml?bill_id=202520260AB656\n\nhttps://regulations.fr
 u.dev/regulations/us-ca-ab656
URL:https://regulations.fru.dev/regulations/us-ca-ab656
CATEGORIES:California,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6848@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20251010
DTEND;VALUE=DATE:20251011
SUMMARY:EU Political Advertising Regulation (TTPA): TTPA applies
DESCRIPTION:Most of the Regulation applies\, including labelling\, transpar
 ency notices and the targeting restrictions.\n\nRegulation (EU) 2024/900 o
 n the transparency and targeting of political advertising (European Union)
 \n\nSource: https://eur-lex.europa.eu/eli/reg/2024/900/oj/eng\n\nhttps://r
 egulations.fru.dev/regulations/eu-ttpa
URL:https://regulations.fru.dev/regulations/eu-ttpa
CATEGORIES:European Union,privacy,online-safety
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6902@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20251013
DTEND;VALUE=DATE:20251014
SUMMARY:California AI autonomous-harm defense ban: Signed by Governor
DESCRIPTION:Chaptered as Chapter 672\, Statutes of 2025.\n\nArtificial Inte
 lligence: Defenses (AB 316) (California)\n\nSource: https://leginfo.legisl
 ature.ca.gov/faces/billNavClient.xhtml?bill_id=202520260AB316\n\nhttps://r
 egulations.fru.dev/regulations/us-ca-ab316
URL:https://regulations.fru.dev/regulations/us-ca-ab316
CATEGORIES:California,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-188@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20251013
DTEND;VALUE=DATE:20251014
SUMMARY:California AI Transparency Act (SB 942): AB 853 signed
DESCRIPTION:AB 853 (ch. 674) delays the operative date and adds platform an
 d device duties.\n\nCalifornia AI Transparency Act (SB 942\, Stats. 2024\,
  ch. 291)\, as amended by AB 853 (Stats. 2025\, ch. 674) (California)\n\nS
 ource: https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_i
 d=202520260AB853\n\nhttps://regulations.fru.dev/regulations/us-ca-sb942
URL:https://regulations.fru.dev/regulations/us-ca-sb942
CATEGORIES:California,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6899@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20251013
DTEND;VALUE=DATE:20251014
SUMMARY:California Digital Age Assurance Act: Signed by Governor
DESCRIPTION:Chaptered as Chapter 675\, Statutes of 2025.\n\nDigital Age Ass
 urance Act (AB 1043) (California)\n\nSource: https://leginfo.legislature.c
 a.gov/faces/billNavClient.xhtml?bill_id=202520260AB1043\n\nhttps://regulat
 ions.fru.dev/regulations/us-ca-ab1043
URL:https://regulations.fru.dev/regulations/us-ca-ab1043
CATEGORIES:California,children,privacy,online-safety
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-181@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20251013
DTEND;VALUE=DATE:20251014
SUMMARY:California SB 243 (companion chatbots): SB 243 signed
DESCRIPTION:SB 243 chaptered (ch. 677).\n\nCalifornia SB 243\, Companion Ch
 atbots (Stats. 2025\, ch. 677) (California)\n\nSource: https://leginfo.leg
 islature.ca.gov/faces/billNavClient.xhtml?bill_id=202520260SB243\n\nhttps:
 //regulations.fru.dev/regulations/us-ca-sb243
URL:https://regulations.fru.dev/regulations/us-ca-sb243
CATEGORIES:California,ai,children,online-safety
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6883@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20251021
DTEND;VALUE=DATE:20251022
SUMMARY:CFPB Open Banking Rule (Section 1033): Reconsideration comment peri
 od closes
DESCRIPTION:Comments on the ANPR due.\n\nRequired Rulemaking on Personal Fi
 nancial Data Rights (12 CFR Part 1033) (United States)\n\nSource: https://
 www.federalregister.gov/documents/2025/08/22/2025-16139/personal-financial
 -data-rights-reconsideration\n\nhttps://regulations.fru.dev/regulations/us
 -cfpb-1033
URL:https://regulations.fru.dev/regulations/us-cfpb-1033
CATEGORIES:United States,data-access,financial,privacy,cybersecurity
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6884@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20251029
DTEND;VALUE=DATE:20251030
SUMMARY:CFPB Open Banking Rule (Section 1033): Court enjoins enforcement
DESCRIPTION:E.D. Ky. enjoins the CFPB from enforcing the rule until it comp
 letes its reconsideration.\n\nRequired Rulemaking on Personal Financial Da
 ta Rights (12 CFR Part 1033) (United States)\n\nSource: https://www.govinf
 o.gov/content/pkg/USCOURTS-kyed-5_24-cv-00304/pdf/USCOURTS-kyed-5_24-cv-00
 304-1.pdf\n\nhttps://regulations.fru.dev/regulations/us-cfpb-1033
URL:https://regulations.fru.dev/regulations/us-cfpb-1033
CATEGORIES:United States,data-access,financial,privacy,cybersecurity
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6968@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20251029
DTEND;VALUE=DATE:20251030
SUMMARY:Digital Services Act: DSA delegated act on researcher data access i
 n force
DESCRIPTION:Delegated Regulation (EU) 2025/2050 sets the procedure for vett
 ed researchers to access VLOP and VLOSE data under Article 40(4). Publishe
 d in the OJ on 2025-10-09\; in force on the 20th day.\n\nRegulation (EU) 2
 022/2065 on a Single Market for Digital Services (Digital Services Act) (E
 uropean Union)\n\nSource: https://eur-lex.europa.eu/eli/reg_del/2025/2050/
 oj/eng\n\nhttps://regulations.fru.dev/regulations/eu-dsa
URL:https://regulations.fru.dev/regulations/eu-dsa
CATEGORIES:European Union,online-safety,children,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-110@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20251031
DTEND;VALUE=DATE:20251101
SUMMARY:EU-US Data Privacy Framework: Latombe appeal lodged at the Court of
  Justice
DESCRIPTION:Latombe appealed the General Court judgment to the Court of Jus
 tice on points of law (reported as Case C-703/25 P)\; the DPF stays valid 
 while it is pending.\n\nCommission Implementing Decision (EU) 2023/1795 on
  the adequate level of protection of personal data under the EU-US Data Pr
 ivacy Framework (European Union)\n\nSource: https://www.wilmerhale.com/en/
 insights/blogs/wilmerhale-privacy-and-cybersecurity-law/20251201-european-
 court-of-justice-to-review-challenge-to-eu-us-data-privacy-framework\n\nht
 tps://regulations.fru.dev/regulations/eu-us-dpf
URL:https://regulations.fru.dev/regulations/eu-us-dpf
CATEGORIES:European Union,privacy,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-7013@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20251031
DTEND;VALUE=DATE:20251101
SUMMARY:Singapore Cybersecurity Act: 2024 amendments commence
DESCRIPTION:Most of the Cybersecurity (Amendment) Act 2024 takes effect\, c
 overing foundational digital infrastructure\, entities of special cybersec
 urity interest and systems of temporary cybersecurity concern.\n\nCybersec
 urity Act 2018 (Singapore)\n\nSource: https://sso.agc.gov.sg/Acts-Supp/19-
 2024/Published/20240704?DocDate=20240704\n\nhttps://regulations.fru.dev/re
 gulations/sg-cybersecurity-act
URL:https://regulations.fru.dev/regulations/sg-cybersecurity-act
CATEGORIES:Singapore,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6982@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20251101
DTEND;VALUE=DATE:20251102
SUMMARY:China Cyber Incident Reporting Measures: Incident reporting measure
 s take effect
DESCRIPTION:1\, 2 and 4 hour reporting windows apply to relatively major an
 d higher incidents.\n\nAdministrative Measures for National Cybersecurity 
 Incident Reporting (China)\n\nSource: https://www.cac.gov.cn/2025-09/15/c_
 1759583017717009.htm\n\nhttps://regulations.fru.dev/regulations/cn-inciden
 t-reporting
URL:https://regulations.fru.dev/regulations/cn-incident-reporting
CATEGORIES:China,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-276@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20251101
DTEND;VALUE=DATE:20251102
SUMMARY:NYDFS Cybersecurity Regulation (Part 500): Universal MFA and asset 
 inventory
DESCRIPTION:500.12 multi-factor authentication for all users and 500.13(a) 
 asset inventory requirements apply.\n\nNew York DFS Cybersecurity Requirem
 ents for Financial Services Companies (23 NYCRR Part 500)\, Second Amendme
 nt (New York)\n\nSource: https://www.dfs.ny.gov/cybersecurity/23-NYCRR-Par
 t-500\n\nhttps://regulations.fru.dev/regulations/us-ny-dfs-500
URL:https://regulations.fru.dev/regulations/us-ny-dfs-500
CATEGORIES:New York,cybersecurity,breach-notification,financial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-7032@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20251102
DTEND;VALUE=DATE:20251103
SUMMARY:Egypt PDPL: Executive Regulations take effect
DESCRIPTION:Decree No. 816 of 2025 was published in Al-Waqa'i al-Misriyya N
 o. 244 (supplement A) on 1 November 2025 and applies from the next day.\n\
 nLaw No. 151 of 2020 on the Protection of Personal Data and its Executive 
 Regulations (Egypt)\n\nSource: https://www.pdpc.gov.eg/assets/pdf-data/Exe
 cutive%20Regulation.pdf\n\nhttps://regulations.fru.dev/regulations/eg-pdpl
URL:https://regulations.fru.dev/regulations/eg-pdpl
CATEGORIES:Egypt,privacy,data-residency,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-7027@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20251103
DTEND;VALUE=DATE:20251104
SUMMARY:New Zealand Biometric Processing Privacy Code: Biometric code in fo
 rce
DESCRIPTION:The Biometric Processing Privacy Code applies to new biometric 
 processing.\n\nBiometric Processing Privacy Code 2025 (New Zealand)\n\nSou
 rce: https://www.privacy.org.nz/privacy-principles/codes-of-practice/biome
 tric-processing-privacy-code/\n\nhttps://regulations.fru.dev/regulations/n
 z-biometric-code
URL:https://regulations.fru.dev/regulations/nz-biometric-code
CATEGORIES:New Zealand,biometrics,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-7042@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20251104
DTEND;VALUE=DATE:20251105
SUMMARY:Kenya Computer Misuse and Cybercrimes Act: 2025 amendments commence
DESCRIPTION:Computer Misuse and Cybercrimes (Amendment) Act No. 17 of 2025:
  assented 15 October 2025\, published 21 October 2025\, commenced 4 Novemb
 er 2025.\n\nComputer Misuse and Cybercrimes Act\, 2018 (Kenya)\n\nSource: 
 https://new.kenyalaw.org/akn/ke/act/2025/17\n\nhttps://regulations.fru.dev
 /regulations/ke-cmca
URL:https://regulations.fru.dev/regulations/ke-cmca
CATEGORIES:Kenya,cybersecurity,online-safety
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-195@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20251110
DTEND;VALUE=DATE:20251111
SUMMARY:CMMC 2.0: DFARS rule effective\; Phase 1 begins
DESCRIPTION:CMMC Level 1 and Level 2 self-assessment requirements begin app
 earing in applicable DoD solicitations and contracts (32 CFR 170.3(e)(1)).
 \n\nCybersecurity Maturity Model Certification (CMMC) Program (32 CFR Part
  170) and DFARS acquisition rule (48 CFR Parts 204\, 212\, 217\, 252) (Uni
 ted States (Federal))\n\nSource: https://www.federalregister.gov/documents
 /2025/09/10/2025-17359/defense-federal-acquisition-regulation-supplement-a
 ssessing-contractor-implementation-of\n\nhttps://regulations.fru.dev/regul
 ations/us-cmmc
URL:https://regulations.fru.dev/regulations/us-cmmc
CATEGORIES:United States (Federal),cybersecurity
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6913@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20251110
DTEND;VALUE=DATE:20251111
SUMMARY:NY Algorithmic Pricing Disclosure Act: Disclosure duty takes effect
DESCRIPTION:Algorithmic pricing disclosures required.\n\nNew York Algorithm
 ic Pricing Disclosure Act (General Business Law section 349-a) (New York)\
 n\nSource: https://ag.ny.gov/press-release/2025/attorney-general-james-war
 ns-new-yorkers-about-algorithmic-pricing-new-law-takes\n\nhttps://regulati
 ons.fru.dev/regulations/us-ny-algo-pricing
URL:https://regulations.fru.dev/regulations/us-ny-algo-pricing
CATEGORIES:New York,privacy,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-7002@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20251111
DTEND;VALUE=DATE:20251112
SUMMARY:Taiwan PDPA: 2025 amendment promulgated
DESCRIPTION:Amendment adds PDPC powers\, breach reporting and security duti
 es. Its start date will be set by the Executive Yuan and is not yet known.
 \n\nTentative: depends on a proposal not yet adopted.\n\nPersonal Data Pro
 tection Act (Taiwan)\n\nSource: https://law.moj.gov.tw/LawClass/LawHistory
 .aspx?pcode=I0050021\n\nhttps://regulations.fru.dev/regulations/tw-pdpa
URL:https://regulations.fru.dev/regulations/tw-pdpa
CATEGORIES:Taiwan,privacy,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-145@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20251112
DTEND;VALUE=DATE:20251113
SUMMARY:UK Cyber Security and Resilience Bill: Introduced (Commons first re
 ading)
DESCRIPTION:Bill introduced in the House of Commons.\n\nCyber Security and 
 Resilience (Network and Information Systems) Bill (United Kingdom)\n\nSour
 ce: https://bills.parliament.uk/bills/4035\n\nhttps://regulations.fru.dev/
 regulations/uk-csr-bill
URL:https://regulations.fru.dev/regulations/uk-csr-bill
CATEGORIES:United Kingdom,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-116@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20251113
DTEND;VALUE=DATE:20251114
SUMMARY:India DPDP Act: DPDP Rules published\; Board and procedural rules i
 n force
DESCRIPTION:Rules 1\, 2 and 17-21 (Data Protection Board constitution and f
 unctioning) take effect on publication in the Official Gazette.\n\nDigital
  Personal Data Protection Act\, 2023 and Digital Personal Data Protection 
 Rules\, 2025 (India)\n\nSource: https://egazette.gov.in/WriteReadData/2025
 /267650.pdf\n\nhttps://regulations.fru.dev/regulations/in-dpdp
URL:https://regulations.fru.dev/regulations/in-dpdp
CATEGORIES:India,privacy,children,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6971@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20251117
DTEND;VALUE=DATE:20251118
SUMMARY:Digital Services Act: DSA review report on VLOP scope and interplay
DESCRIPTION:Commission report under Article 91 on Article 33 scope and inte
 raction with other laws.\n\nRegulation (EU) 2022/2065 on a Single Market f
 or Digital Services (Digital Services Act) (European Union)\n\nSource: htt
 ps://eur-lex.europa.eu/eli/reg/2022/2065/oj/eng\n\nhttps://regulations.fru
 .dev/regulations/eu-dsa
URL:https://regulations.fru.dev/regulations/eu-dsa
CATEGORIES:European Union,online-safety,children,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-74@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20251118
DTEND;VALUE=DATE:20251119
SUMMARY:DORA: First critical ICT third-party providers designated
DESCRIPTION:The ESAs published the first list of 19 critical ICT third-part
 y providers (including AWS\, Google Cloud and Microsoft)\, which now come 
 under direct EU oversight.\n\nRegulation (EU) 2022/2554 on digital operati
 onal resilience for the financial sector (Digital Operational Resilience A
 ct) (European Union)\n\nSource: https://www.eba.europa.eu/publications-and
 -media/press-releases/european-supervisory-authorities-designate-critical-
 ict-third-party-providers-under-digital\n\nhttps://regulations.fru.dev/reg
 ulations/eu-dora
URL:https://regulations.fru.dev/regulations/eu-dora
CATEGORIES:European Union,cybersecurity,financial,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6867@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20251120
DTEND;VALUE=DATE:20251121
SUMMARY:EU Consumer Credit Directive 2 (CCD2): Transposition deadline
DESCRIPTION:Member States must adopt and publish transposing laws (Article 
 48).\n\nDirective (EU) 2023/2225 on credit agreements for consumers (Europ
 ean Union)\n\nSource: https://eur-lex.europa.eu/eli/dir/2023/2225/oj/eng\n
 \nhttps://regulations.fru.dev/regulations/eu-ccd2
URL:https://regulations.fru.dev/regulations/eu-ccd2
CATEGORIES:European Union,financial,privacy,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-7009@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20251125
DTEND;VALUE=DATE:20251126
SUMMARY:Singapore Online Safety (Relief and Accountability) Act: Act assent
 ed to
DESCRIPTION:Passed by Parliament on 5 November 2025 and assented to by the 
 President on 25 November 2025.\n\nOnline Safety (Relief and Accountability
 ) Act 2025 (Singapore)\n\nSource: https://sso.agc.gov.sg/Acts-Supp/23-2025
 /Published/20251208?DocDate=20251208\n\nhttps://regulations.fru.dev/regula
 tions/sg-online-safety-act
URL:https://regulations.fru.dev/regulations/sg-online-safety-act
CATEGORIES:Singapore,online-safety,children,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-95@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20251126
DTEND;VALUE=DATE:20251127
SUMMARY:GDPR: GDPR Procedural Regulation adopted
DESCRIPTION:Regulation (EU) 2025/2518 laying down additional procedural rul
 es for cross-border GDPR enforcement signed by Parliament and Council.\n\n
 Regulation (EU) 2016/679 (General Data Protection Regulation) (European Un
 ion)\n\nSource: https://eur-lex.europa.eu/eli/reg/2025/2518/oj\n\nhttps://
 regulations.fru.dev/regulations/eu-gdpr
URL:https://regulations.fru.dev/regulations/eu-gdpr
CATEGORIES:European Union,privacy,breach-notification,data-access,children,
 biometrics,health
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6957@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20251130
DTEND;VALUE=DATE:20251201
SUMMARY:Peru PDPL and 2024 Regulation: DPO required: large companies
DESCRIPTION:Companies with annual sales above 2\,300 UIT must appoint a dat
 a protection officer where Art. 37.1(2)-(3) applies.\n\nLey N° 29733\, Le
 y de Protección de Datos Personales\, and its Regulation (Decreto Supremo
  N° 016-2024-JUS) (Peru)\n\nSource: https://www.gob.pe/institucion/smv/no
 rmas-legales/6426760-016-2024-jus\n\nhttps://regulations.fru.dev/regulatio
 ns/pe-pdpl
URL:https://regulations.fru.dev/regulations/pe-pdpl
CATEGORIES:Peru,privacy,breach-notification,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-296@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20251203
DTEND;VALUE=DATE:20251204
SUMMARY:SEC Regulation S-P: Larger entities must comply
DESCRIPTION:Larger covered institutions (18 months after Federal Register p
 ublication) must have incident response programs\, 30-day customer notific
 ation\, and service-provider oversight in place.\n\nRegulation S-P: Privac
 y of Consumer Financial Information and Safeguarding Customer Information 
 (2024 amendments) (United States (Federal))\n\nSource: https://www.federal
 register.gov/documents/2024/06/03/2024-11116/regulation-s-p-privacy-of-con
 sumer-financial-information-and-safeguarding-customer-information\n\nhttps
 ://regulations.fru.dev/regulations/us-sec-reg-sp
URL:https://regulations.fru.dev/regulations/us-sec-reg-sp
CATEGORIES:United States (Federal),financial,privacy,cybersecurity,breach-n
 otification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-8@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20251210
DTEND;VALUE=DATE:20251211
SUMMARY:Australia Social Media Minimum Age: Social media minimum age obliga
 tion applies
DESCRIPTION:Age-restricted platforms must take reasonable steps to prevent 
 under-16s from holding accounts.\n\nOnline Safety Amendment (Social Media 
 Minimum Age) Act 2024 (Australia)\n\nSource: https://www.legislation.gov.a
 u/C2024A00127/asmade\n\nhttps://regulations.fru.dev/regulations/au-social-
 media-min-age
URL:https://regulations.fru.dev/regulations/au-social-media-min-age
CATEGORIES:Australia,children,online-safety
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6892@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20251216
DTEND;VALUE=DATE:20251217
SUMMARY:AI state-law preemption EO: EO published in Federal Register
DESCRIPTION:Signed 2025-12-11 and published at 90 FR 58499.\n\nExecutive Or
 der 14365: Ensuring a National Policy Framework for Artificial Intelligenc
 e (United States)\n\nSource: https://www.federalregister.gov/documents/202
 5/12/16/2025-23092/ensuring-a-national-policy-framework-for-artificial-int
 elligence\n\nhttps://regulations.fru.dev/regulations/us-eo-14365-ai-preemp
 tion
URL:https://regulations.fru.dev/regulations/us-eo-14365-ai-preemption
CATEGORIES:United States,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-278@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20251219
DTEND;VALUE=DATE:20251220
SUMMARY:NY RAISE Act: RAISE Act signed
DESCRIPTION:Governor Hochul signs the RAISE Act with an agreed chapter amen
 dment.\n\nNew York Responsible AI Safety and Education (RAISE) Act (S6953-
 B/A6453-B of 2025)\, as amended by chapter amendment S8828 of 2026 (New Yo
 rk)\n\nSource: https://www.governor.ny.gov/news/governor-hochul-signs-nati
 on-leading-legislation-require-ai-frameworks-ai-frontier-models\n\nhttps:/
 /regulations.fru.dev/regulations/us-ny-raise
URL:https://regulations.fru.dev/regulations/us-ny-raise
CATEGORIES:New York,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6925@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20251223
DTEND;VALUE=DATE:20251224
SUMMARY:Texas App Store Accountability Act: Preliminary injunction
DESCRIPTION:W.D. Tex. (CCIA v. Paxton) enjoins the AG from implementing or 
 enforcing SB 2420 on First Amendment grounds.\n\nTexas App Store Accountab
 ility Act (SB 2420) (Texas)\n\nSource: https://www.govinfo.gov/content/pkg
 /USCOURTS-txwd-1_25-cv-01660/pdf/USCOURTS-txwd-1_25-cv-01660-0.pdf\n\nhttp
 s://regulations.fru.dev/regulations/us-tx-app-store
URL:https://regulations.fru.dev/regulations/us-tx-app-store
CATEGORIES:Texas,children,privacy,online-safety
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-224@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20251231
DTEND;VALUE=DATE:20260101
SUMMARY:Delaware Personal Data Privacy Act (DPDPA): Mandatory 60-day cure p
 eriod expires
DESCRIPTION:Mandatory notice-and-cure ends Dec 31\, 2025\; from Jan 1\, 202
 6 DOJ decides whether to offer a cure using statutory factors.\n\nDelaware
  Personal Data Privacy Act (HB 154)\, 6 Del. C. ch. 12D (Delaware)\n\nSour
 ce: https://delcode.delaware.gov/title6/c012d/index.html\n\nhttps://regula
 tions.fru.dev/regulations/us-de-dpdpa
URL:https://regulations.fru.dev/regulations/us-de-dpdpa
CATEGORIES:Delaware,privacy,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-3@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260101
DTEND;VALUE=DATE:20260102
SUMMARY:Australia Cyber Security Act (ransomware reporting): Ransomware rep
 orting moves to compliance phase
DESCRIPTION:The education-first phase (30 May-31 Dec 2025) ends\; Home Affa
 irs moves to a compliance and education approach for missed reports.\n\nCy
 ber Security Act 2024 (Cth) and Cyber Security (Ransomware Payment Reporti
 ng) Rules 2025 (Australia)\n\nSource: https://www.homeaffairs.gov.au/cyber
 -security-subsite/files/factsheet-ransomware-payment-reporting.pdf\n\nhttp
 s://regulations.fru.dev/regulations/au-cyber-security-act
URL:https://regulations.fru.dev/regulations/au-cyber-security-act
CATEGORIES:Australia,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-163@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260101
DTEND;VALUE=DATE:20260102
SUMMARY:California AB 2013 (AI training data transparency): Training-data d
 ocumentation due
DESCRIPTION:Documentation must be posted for GenAI systems released since J
 anuary 1\, 2022\, and before each later release or substantial modificatio
 n.\n\nCalifornia AB 2013\, Generative Artificial Intelligence: Training Da
 ta Transparency (Stats. 2024\, ch. 817) (California)\n\nSource: https://le
 ginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202320240AB2013
 \n\nhttps://regulations.fru.dev/regulations/us-ca-ab2013
URL:https://regulations.fru.dev/regulations/us-ca-ab2013
CATEGORIES:California,ai,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6903@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260101
DTEND;VALUE=DATE:20260102
SUMMARY:California AI autonomous-harm defense ban: Takes effect
DESCRIPTION:Default effective date for 2025 regular-session statutes.\n\nAr
 tificial Intelligence: Defenses (AB 316) (California)\n\nSource: https://l
 eginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202520260AB316
 \n\nhttps://regulations.fru.dev/regulations/us-ca-ab316
URL:https://regulations.fru.dev/regulations/us-ca-ab316
CATEGORIES:California,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-189@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260101
DTEND;VALUE=DATE:20260102
SUMMARY:California AI Transparency Act (SB 942): Original operative date (s
 uperseded)
DESCRIPTION:Original SB 942 date\; delayed to August 2\, 2026 by AB 853.\n\
 nCalifornia AI Transparency Act (SB 942\, Stats. 2024\, ch. 291)\, as amen
 ded by AB 853 (Stats. 2025\, ch. 674) (California)\n\nSource: https://legi
 nfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202320240SB942\n\
 nhttps://regulations.fru.dev/regulations/us-ca-sb942
URL:https://regulations.fru.dev/regulations/us-ca-sb942
CATEGORIES:California,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-176@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260101
DTEND;VALUE=DATE:20260102
SUMMARY:California Delete Act / DROP: DROP opens to consumers
DESCRIPTION:Consumers can submit a single deletion request to all registere
 d data brokers through DROP.\n\nCalifornia Delete Act (SB 362\, 2023)\, Ca
 l. Civ. Code 1798.99.80 et seq.\, and DROP regulations (California)\n\nSou
 rce: https://www.cppa.ca.gov/data_brokers/\n\nhttps://regulations.fru.dev/
 regulations/us-ca-delete-act
URL:https://regulations.fru.dev/regulations/us-ca-delete-act
CATEGORIES:California,privacy,data-access
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-182@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260101
DTEND;VALUE=DATE:20260102
SUMMARY:California SB 243 (companion chatbots): Chatbot safeguards apply
DESCRIPTION:AI disclosure\, suicide and self-harm protocols\, and minor pro
 tections apply.\n\nCalifornia SB 243\, Companion Chatbots (Stats. 2025\, c
 h. 677) (California)\n\nSource: https://leginfo.legislature.ca.gov/faces/b
 illNavClient.xhtml?bill_id=202520260SB243\n\nhttps://regulations.fru.dev/r
 egulations/us-ca-sb243
URL:https://regulations.fru.dev/regulations/us-ca-sb243
CATEGORIES:California,ai,children,online-safety
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-185@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260101
DTEND;VALUE=DATE:20260102
SUMMARY:California SB 53 (TFAIA): Frontier developer obligations apply
DESCRIPTION:Frontier AI frameworks\, transparency reports\, critical safety
  incident reporting (15 days\, or 24 hours for imminent risk of death or s
 erious injury) and whistleblower protections apply.\n\nCalifornia SB 53\, 
 Transparency in Frontier Artificial Intelligence Act (Stats. 2025\, ch. 13
 8) (California)\n\nSource: https://leginfo.legislature.ca.gov/faces/billNa
 vClient.xhtml?bill_id=202520260SB53\n\nhttps://regulations.fru.dev/regulat
 ions/us-ca-sb53
URL:https://regulations.fru.dev/regulations/us-ca-sb53
CATEGORIES:California,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6911@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260101
DTEND;VALUE=DATE:20260102
SUMMARY:California social media account deletion: Takes effect
DESCRIPTION:Default effective date for 2025 regular-session statutes.\n\nAc
 count Cancellation (AB 656) (California)\n\nSource: https://leginfo.legisl
 ature.ca.gov/faces/billNavClient.xhtml?bill_id=202520260AB656\n\nhttps://r
 egulations.fru.dev/regulations/us-ca-ab656
URL:https://regulations.fru.dev/regulations/us-ca-ab656
CATEGORIES:California,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-168@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260101
DTEND;VALUE=DATE:20260102
SUMMARY:CCPA / CPRA: New CCPA regulations take effect
DESCRIPTION:ADMT\, risk assessment\, cybersecurity audit and updated CCPA r
 egulations become effective\; risk assessments required for new high-risk 
 processing.\n\nCalifornia Consumer Privacy Act of 2018\, as amended by the
  California Privacy Rights Act of 2020 (Cal. Civ. Code 1798.100 et seq.) a
 nd CPPA regulations (Cal. Code Regs. tit. 11\, 7000 et seq.) (California)\
 n\nSource: https://cppa.ca.gov/regulations/ccpa_updates.html\n\nhttps://re
 gulations.fru.dev/regulations/us-ca-ccpa
URL:https://regulations.fru.dev/regulations/us-ca-ccpa
CATEGORIES:California,privacy,ai,cybersecurity,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-32@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260101
DTEND;VALUE=DATE:20260102
SUMMARY:China Cybersecurity Law: 2025 amendments take effect
DESCRIPTION:Higher fines\, first-violation fines\, AI governance provisions
  and PIPL-alignment duties apply under the 28 Oct 2025 NPCSC Decision.\n\n
 Cybersecurity Law of the People's Republic of China (as amended by the NPC
  Standing Committee Decision of 28 October 2025) (China)\n\nSource: https:
 //www.gov.cn/yaowen/liebiao/202510/content_7046194.htm\n\nhttps://regulati
 ons.fru.dev/regulations/cn-csl
URL:https://regulations.fru.dev/regulations/cn-csl
CATEGORIES:China,cybersecurity,data-residency,ai,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6981@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260101
DTEND;VALUE=DATE:20260102
SUMMARY:China PI Export Certification Measures: PI export certification mea
 sures take effect
DESCRIPTION:The certification route for personal information exports applie
 s.\n\nMeasures for Personal Information Outbound Transfer Certification (C
 hina)\n\nSource: https://www.cac.gov.cn/2025-10/17/c_1762449728720008.htm\
 n\nhttps://regulations.fru.dev/regulations/cn-pi-certification
URL:https://regulations.fru.dev/regulations/cn-pi-certification
CATEGORIES:China,data-residency,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-225@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260101
DTEND;VALUE=DATE:20260102
SUMMARY:Delaware Personal Data Privacy Act (DPDPA): Opt-out preference sign
 als must be honored
DESCRIPTION:Controllers must allow opt-out of targeted advertising and sale
  via opt-out preference signals (12D-106).\n\nDelaware Personal Data Priva
 cy Act (HB 154)\, 6 Del. C. ch. 12D (Delaware)\n\nSource: https://delcode.
 delaware.gov/title6/c012d/index.html\n\nhttps://regulations.fru.dev/regula
 tions/us-de-dpdpa
URL:https://regulations.fru.dev/regulations/us-de-dpdpa
CATEGORIES:Delaware,privacy,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6970@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260101
DTEND;VALUE=DATE:20260102
SUMMARY:Digital Services Act: DSA first harmonised transparency reporting c
 ycle
DESCRIPTION:First full annual reporting period (to 2026-12-31) under the ha
 rmonised templates for all intermediary services.\n\nRegulation (EU) 2022/
 2065 on a Single Market for Digital Services (Digital Services Act) (Europ
 ean Union)\n\nSource: https://eur-lex.europa.eu/eli/reg_impl/2024/2835/oj/
 eng\n\nhttps://regulations.fru.dev/regulations/eu-dsa
URL:https://regulations.fru.dev/regulations/eu-dsa
CATEGORIES:European Union,online-safety,children,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-96@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260101
DTEND;VALUE=DATE:20260102
SUMMARY:GDPR: GDPR Procedural Regulation enters into force
DESCRIPTION:Regulation (EU) 2025/2518\, published in the OJ on 12 December 
 2025\, enters into force on the twentieth day after publication.\n\nRegula
 tion (EU) 2016/679 (General Data Protection Regulation) (European Union)\n
 \nSource: https://eur-lex.europa.eu/eli/reg/2025/2518/oj\n\nhttps://regula
 tions.fru.dev/regulations/eu-gdpr
URL:https://regulations.fru.dev/regulations/eu-gdpr
CATEGORIES:European Union,privacy,breach-notification,data-access,children,
 biometrics,health
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-111@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260101
DTEND;VALUE=DATE:20260102
SUMMARY:Hong Kong Critical Infrastructure Cyber Ordinance: PCICSO comes int
 o operation
DESCRIPTION:Commissioner's Office is established and designation of CIOs be
 gins\; obligations apply to designated operators.\n\nProtection of Critica
 l Infrastructures (Computer Systems) Ordinance (Cap. 653) (Hong Kong)\n\nS
 ource: https://www.info.gov.hk/gia/general/202506/27/P2025062700238.htm\n\
 nhttps://regulations.fru.dev/regulations/hk-pcico
URL:https://regulations.fru.dev/regulations/hk-pcico
CATEGORIES:Hong Kong,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-245@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260101
DTEND;VALUE=DATE:20260102
SUMMARY:Illinois AI in Employment Law (HB 3773): AI anti-discrimination and
  notice duties apply
DESCRIPTION:Prohibition on discriminatory AI use and the employee notice re
 quirement take effect.\n\nIllinois HB 3773 (Public Act 103-0804)\, amendin
 g the Illinois Human Rights Act on artificial intelligence in employment (
 Illinois)\n\nSource: https://www.ilga.gov/ftp/legislation/103/BillStatus/H
 TML/10300HB3773.html\n\nhttps://regulations.fru.dev/regulations/us-il-hb37
 73
URL:https://regulations.fru.dev/regulations/us-il-hb3773
CATEGORIES:Illinois,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-248@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260101
DTEND;VALUE=DATE:20260102
SUMMARY:Indiana Consumer Data Protection Act (ICDPA): ICDPA takes effect
DESCRIPTION:Consumer rights and controller/processor obligations apply\; as
 sessments required for processing activities created on or after this date
 .\n\nIndiana Consumer Data Protection Act (SEA 5\, 2023)\, Ind. Code 24-15
  (Indiana)\n\nSource: https://iga.in.gov/legislative/2023/bills/senate/5/d
 etails\n\nhttps://regulations.fru.dev/regulations/us-in-icdpa
URL:https://regulations.fru.dev/regulations/us-in-icdpa
CATEGORIES:Indiana,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-249@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260101
DTEND;VALUE=DATE:20260102
SUMMARY:Kentucky Consumer Data Protection Act (KCDPA): KCDPA takes effect
DESCRIPTION:Consumer rights and controller/processor obligations apply (HB 
 15 section 12).\n\nKentucky Consumer Data Protection Act (HB 15\, 2024)\, 
 KRS 367.3611-367.3629 (Kentucky)\n\nSource: https://apps.legislature.ky.go
 v/recorddocuments/bill/24RS/hb15/bill.pdf\n\nhttps://regulations.fru.dev/r
 egulations/us-ky-kcdpa
URL:https://regulations.fru.dev/regulations/us-ky-kcdpa
CATEGORIES:Kentucky,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-7015@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260101
DTEND;VALUE=DATE:20260102
SUMMARY:Malaysia Online Safety Act: Online Safety Act and first regulations
  in force
DESCRIPTION:The Act and the Period\, Fees\, Form of Undertaking and Appeal 
 Tribunal regulations take effect.\n\nOnline Safety Act 2025 (Act 866) (Mal
 aysia)\n\nSource: https://lom.agc.gov.my/act-detail.php?a=YWN0PTg2NiZsYW5n
 PUJJ\n\nhttps://regulations.fru.dev/regulations/my-online-safety-act
URL:https://regulations.fru.dev/regulations/my-online-safety-act
CATEGORIES:Malaysia,online-safety,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6939@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260101
DTEND;VALUE=DATE:20260102
SUMMARY:Nebraska Kids Code: Operative date
DESCRIPTION:Act becomes operative.\n\nNebraska Age-Appropriate Online Desig
 n Code Act (LB 504) (Nebraska)\n\nSource: https://nebraskalegislature.gov/
 FloorDocs/109/PDF/Slip/LB504.pdf\n\nhttps://regulations.fru.dev/regulation
 s/us-ne-aadc
URL:https://regulations.fru.dev/regulations/us-ne-aadc
CATEGORIES:Nebraska,children,privacy,online-safety
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-262@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260101
DTEND;VALUE=DATE:20260102
SUMMARY:New Hampshire Privacy Act: Mandatory 60-day cure period expires
DESCRIPTION:The AG's obligation to issue a cure notice ended Dec 31\, 2025\
 ; from Jan 1\, 2026 cure opportunities are discretionary (RSA 507-H:11 II-
 III).\n\nNew Hampshire Privacy Act (SB 255\, 2024)\, RSA chapter 507-H (Ne
 w Hampshire)\n\nSource: https://gc.nh.gov/rsa/html/LII/507-H/507-H-11.htm\
 n\nhttps://regulations.fru.dev/regulations/us-nh-privacy
URL:https://regulations.fru.dev/regulations/us-nh-privacy
CATEGORIES:New Hampshire,privacy,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-285@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260101
DTEND;VALUE=DATE:20260102
SUMMARY:Oregon OCPA: Cure period sunsets
DESCRIPTION:The AG's 30-day notice-and-cure requirement expires\; enforceme
 nt can proceed without a cure opportunity.\n\nOregon Consumer Privacy Act 
 (SB 619\, 2023) (Oregon)\n\nSource: https://www.oregonlegislature.gov/bill
 s_laws/ors/ors646A.html\n\nhttps://regulations.fru.dev/regulations/us-or-o
 cpa
URL:https://regulations.fru.dev/regulations/us-or-ocpa
CATEGORIES:Oregon,privacy,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-286@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260101
DTEND;VALUE=DATE:20260102
SUMMARY:Oregon OCPA: Universal opt-out signals must be honored
DESCRIPTION:Controllers must honor opt-out preference signals such as Globa
 l Privacy Control.\n\nOregon Consumer Privacy Act (SB 619\, 2023) (Oregon)
 \n\nSource: https://www.doj.state.or.us/consumer-protection/id-theft-data-
 breaches/privacy/\n\nhttps://regulations.fru.dev/regulations/us-or-ocpa
URL:https://regulations.fru.dev/regulations/us-or-ocpa
CATEGORIES:Oregon,privacy,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-287@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260101
DTEND;VALUE=DATE:20260102
SUMMARY:Oregon OCPA: Sale ban on precise geolocation and under-16 data (HB 
 2008)
DESCRIPTION:Selling precise geolocation (1\,750-ft radius) and the personal
  data of consumers the controller knows or willfully disregards are under 
 16 is prohibited.\n\nOregon Consumer Privacy Act (SB 619\, 2023) (Oregon)\
 n\nSource: https://www.doj.state.or.us/consumer-protection/id-theft-data-b
 reaches/privacy/\n\nhttps://regulations.fru.dev/regulations/us-or-ocpa
URL:https://regulations.fru.dev/regulations/us-or-ocpa
CATEGORIES:Oregon,privacy,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-289@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260101
DTEND;VALUE=DATE:20260102
SUMMARY:Rhode Island RIDTPPA: RIDTPPA takes effect
DESCRIPTION:All provisions of R.I. Gen. Laws ch. 6-48.1 apply (P.L. 2024\, 
 ch. 430/453\, effective Jan 1\, 2026).\n\nRhode Island Data Transparency a
 nd Privacy Protection Act (Rhode Island)\n\nSource: https://webserver.rile
 gislature.gov/Statutes/TITLE6/6-48.1/INDEX.htm\n\nhttps://regulations.fru.
 dev/regulations/us-ri-dtppa
URL:https://regulations.fru.dev/regulations/us-ri-dtppa
CATEGORIES:Rhode Island,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6926@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260101
DTEND;VALUE=DATE:20260102
SUMMARY:Texas App Store Accountability Act: Scheduled effective date (enjoi
 ned)
DESCRIPTION:Statutory effective date\; not enforceable while the injunction
  stands.\n\nTexas App Store Accountability Act (SB 2420) (Texas)\n\nSource
 : https://capitol.texas.gov/BillLookup/History.aspx?LegSess=89R&Bill=SB242
 0\n\nhttps://regulations.fru.dev/regulations/us-tx-app-store
URL:https://regulations.fru.dev/regulations/us-tx-app-store
CATEGORIES:Texas,children,privacy,online-safety
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-304@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260101
DTEND;VALUE=DATE:20260102
SUMMARY:TRAIGA: TRAIGA takes effect
DESCRIPTION:Prohibited-practice rules\, AG enforcement\, sandbox program an
 d government AI disclosure duties apply.\n\nTexas Responsible Artificial I
 ntelligence Governance Act (HB 149\, 89th Legislature) (Texas)\n\nSource: 
 https://capitol.texas.gov/BillLookup/History.aspx?LegSess=89R&Bill=HB149\n
 \nhttps://regulations.fru.dev/regulations/us-tx-traiga
URL:https://regulations.fru.dev/regulations/us-tx-traiga
CATEGORIES:Texas,ai,biometrics
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-7036@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260101
DTEND;VALUE=DATE:20260102
SUMMARY:UAE Child Digital Safety Law: Child Digital Safety Law takes effect
DESCRIPTION:Effective date shown on the official legislation portal. Publis
 hed in Official Gazette No. 809 (supplement 1) on 14 October 2025.\n\nFede
 ral Decree by Law No. 26 of 2025 Regarding Child Digital Safety (United Ar
 ab Emirates)\n\nSource: https://uaelegislation.gov.ae/en/legislations/3912
 \n\nhttps://regulations.fru.dev/regulations/ae-child-digital-safety
URL:https://regulations.fru.dev/regulations/ae-child-digital-safety
CATEGORIES:United Arab Emirates,children,online-safety,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-324@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260101
DTEND;VALUE=DATE:20260102
SUMMARY:Vietnam PDPL: PDPL and Decree 356/2025 take effect
DESCRIPTION:Personal data protection obligations\, DPIA/TIA filing and pena
 lty framework apply\; Decree 13/2023 replaced.\n\nLaw on Personal Data Pro
 tection (Law No. 91/2025/QH15) (Vietnam)\n\nSource: https://vanban.chinhph
 u.vn/?pageid=27160&docid=214590\n\nhttps://regulations.fru.dev/regulations
 /vn-pdpl
URL:https://regulations.fru.dev/regulations/vn-pdpl
CATEGORIES:Vietnam,privacy,data-residency,children,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-312@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260101
DTEND;VALUE=DATE:20260102
SUMMARY:Virginia VCDPA: Under-16 social media time limit (SB 854) takes eff
 ect
DESCRIPTION:Social media platforms must use commercially reasonable age det
 ermination and cap users under 16 at 1 hour/day unless a parent consents. 
 A preliminary injunction issued Feb 27\, 2026 bars enforcement.\n\nVirgini
 a Consumer Data Protection Act (SB 1392 / HB 2307\, 2021) (Virginia)\n\nSo
 urce: https://netchoice.org/wp-content/uploads/2026/02/Virginia-PI-Opinion
 _Granted.pdf\n\nhttps://regulations.fru.dev/regulations/us-va-vcdpa
URL:https://regulations.fru.dev/regulations/us-va-vcdpa
CATEGORIES:Virginia,privacy,children,online-safety
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6893@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260110
DTEND;VALUE=DATE:20260111
SUMMARY:AI state-law preemption EO: AI Litigation Task Force due
DESCRIPTION:Attorney General to set up a task force to challenge state AI l
 aws within 30 days of the order (date computed from signing).\n\nExecutive
  Order 14365: Ensuring a National Policy Framework for Artificial Intellig
 ence (United States)\n\nSource: https://www.federalregister.gov/documents/
 2025/12/16/2025-23092/ensuring-a-national-policy-framework-for-artificial-
 intelligence\n\nhttps://regulations.fru.dev/regulations/us-eo-14365-ai-pre
 emption
URL:https://regulations.fru.dev/regulations/us-eo-14365-ai-preemption
CATEGORIES:United States,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6849@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260110
DTEND;VALUE=DATE:20260111
SUMMARY:EU Political Advertising Regulation (TTPA): Member States notify sa
 nction rules
DESCRIPTION:Deadline for Member States to notify the Commission of their sa
 nction rules under Article 25(3).\n\nRegulation (EU) 2024/900 on the trans
 parency and targeting of political advertising (European Union)\n\nSource:
  https://eur-lex.europa.eu/eli/reg/2024/900/oj/eng\n\nhttps://regulations.
 fru.dev/regulations/eu-ttpa
URL:https://regulations.fru.dev/regulations/eu-ttpa
CATEGORIES:European Union,privacy,online-safety
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6997@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260114
DTEND;VALUE=DATE:20260115
SUMMARY:Taiwan AI Basic Act: AI Basic Act in force
DESCRIPTION:Promulgated and in force on the same day (art. 20).\n\nArtifici
 al Intelligence Basic Act (Taiwan)\n\nSource: https://law.moj.gov.tw/LawCl
 ass/LawAll.aspx?pcode=H0160093\n\nhttps://regulations.fru.dev/regulations/
 tw-ai-basic-act
URL:https://regulations.fru.dev/regulations/tw-ai-basic-act
CATEGORIES:Taiwan,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-7007@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260118
DTEND;VALUE=DATE:20260119
SUMMARY:Kazakhstan AI Law: AI Law takes effect
DESCRIPTION:The Law takes effect after 60 calendar days from first official
  publication on 18 Nov 2025 (art. 31). The day is computed\, not stated.\n
 \nTentative: depends on a proposal not yet adopted.\n\nLaw of the Republic
  of Kazakhstan on Artificial Intelligence (No. 230-VIII) (Kazakhstan)\n\nS
 ource: https://adilet.zan.kz/rus/docs/Z2500000230\n\nhttps://regulations.f
 ru.dev/regulations/kz-ai-law
URL:https://regulations.fru.dev/regulations/kz-ai-law
CATEGORIES:Kazakhstan,ai,privacy,biometrics
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6854@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260120
DTEND;VALUE=DATE:20260121
SUMMARY:EU Cybersecurity Act: Cybersecurity Act 2 proposed
DESCRIPTION:Commission proposal COM(2026) 11 to repeal and replace the Act\
 , adding ICT supply chain security rules. Now in the ordinary legislative 
 procedure (2026/0011(COD)).\n\nRegulation (EU) 2019/881 on ENISA and on in
 formation and communications technology cybersecurity certification (Cyber
 security Act) (European Union)\n\nSource: https://publications.europa.eu/r
 esource/celex/52026PC0011\n\nhttps://regulations.fru.dev/regulations/eu-cy
 bersecurity-act
URL:https://regulations.fru.dev/regulations/eu-cybersecurity-act
CATEGORIES:European Union,cybersecurity
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6963@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260120
DTEND;VALUE=DATE:20260121
SUMMARY:Peru AI Law and Regulation: Regulation in force
DESCRIPTION:Regulation enters into force 90 business days after publication
 . Date computed with national holidays\, so tentative.\n\nTentative: depen
 ds on a proposal not yet adopted.\n\nLey N° 31814\, Ley que promueve el u
 so de la inteligencia artificial en favor del desarrollo económico y soci
 al del país\, and its Regulation (Decreto Supremo N° 115-2025-PCM) (Peru
 )\n\nSource: https://www.gob.pe/institucion/pcm/normas-legales/7133522-115
 -2025-pcm\n\nhttps://regulations.fru.dev/regulations/pe-ai-law
URL:https://regulations.fru.dev/regulations/pe-ai-law
CATEGORIES:Peru,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-124@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260122
DTEND;VALUE=DATE:20260123
SUMMARY:South Korea AI Basic Act: AI Basic Act and Enforcement Decree take 
 effect
DESCRIPTION:Transparency\, labeling\, high-impact AI\, and domestic represe
 ntative obligations apply (fines deferred during the grace period).\n\nFra
 mework Act on the Development of Artificial Intelligence and Establishment
  of a Foundation for Trust (AI Basic Act) (South Korea)\n\nSource: https:/
 /www.law.go.kr/법령/인공지능발전과신뢰기반조성등에관한
 기본법\n\nhttps://regulations.fru.dev/regulations/kr-ai-basic-act
URL:https://regulations.fru.dev/regulations/kr-ai-basic-act
CATEGORIES:South Korea,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-177@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260131
DTEND;VALUE=DATE:20260201
SUMMARY:California Delete Act / DROP: Annual data broker registration deadl
 ine
DESCRIPTION:Data brokers must register with CalPrivacy and pay the annual f
 ee ($6\,000 for 2026) by January 31.\n\nCalifornia Delete Act (SB 362\, 20
 23)\, Cal. Civ. Code 1798.99.80 et seq.\, and DROP regulations (California
 )\n\nSource: https://www.cppa.ca.gov/data_brokers/\n\nhttps://regulations.
 fru.dev/regulations/us-ca-delete-act
URL:https://regulations.fru.dev/regulations/us-ca-delete-act
CATEGORIES:California,privacy,data-access
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-256@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260131
DTEND;VALUE=DATE:20260201
SUMMARY:Minnesota Consumer Data Privacy Act (MCDPA): 30-day cure period exp
 ires
DESCRIPTION:The requirement that the AG send a warning letter and allow 30 
 days to cure before suing expires Jan 31\, 2026 (325M.20(a)).\n\nMinnesota
  Consumer Data Privacy Act (HF 4757\, 2024 Minn. Laws ch. 121\, art. 5)\, 
 Minn. Stat. 325M.10-325M.21 (Minnesota)\n\nSource: https://www.revisor.mn.
 gov/statutes/cite/325M.20\n\nhttps://regulations.fru.dev/regulations/us-mn
 -mcdpa
URL:https://regulations.fru.dev/regulations/us-mn-mcdpa
CATEGORIES:Minnesota,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-201@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260201
DTEND;VALUE=DATE:20260202
SUMMARY:Colorado AI Act: Original effective date (superseded)
DESCRIPTION:Original SB 24-205 date\; postponed by SB 25B-004\, so no oblig
 ations applied.\n\nColorado SB 24-205 (Consumer Protections for Artificial
  Intelligence)\, as delayed by SB 25B-004 and repealed and reenacted by SB
  26-189 (Automated Decision-Making Technology) (Colorado)\n\nSource: https
 ://leg.colorado.gov/bills/sb24-205\n\nhttps://regulations.fru.dev/regulati
 ons/us-co-ai-act
URL:https://regulations.fru.dev/regulations/us-co-ai-act
CATEGORIES:Colorado,ai,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-150@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260205
DTEND;VALUE=DATE:20260206
SUMMARY:Data (Use and Access) Act: Stage 3: main data protection changes co
 mmence
DESCRIPTION:Recognised legitimate interests\, ADM reforms\, DSAR changes\, 
 international transfer test\, cookie exemptions and PECR fines at UK GDPR 
 levels apply (Commencement No. 6 Regulations 2026\, reg. 2).\n\nData (Use 
 and Access) Act 2025 (United Kingdom)\n\nSource: https://www.legislation.g
 ov.uk/uksi/2026/82/contents/made\n\nhttps://regulations.fru.dev/regulation
 s/uk-duaa
URL:https://regulations.fru.dev/regulations/uk-duaa
CATEGORIES:United Kingdom,privacy,data-access,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-155@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260205
DTEND;VALUE=DATE:20260206
SUMMARY:UK GDPR: DUAA amendments to UK GDPR commence
DESCRIPTION:Main Data (Use and Access) Act 2025 Part 5 amendments (recognis
 ed legitimate interests\, ADM\, DSAR\, transfers\, cookies\, PECR fines) a
 pply.\n\nUK General Data Protection Regulation and Data Protection Act 201
 8 (United Kingdom)\n\nSource: https://www.legislation.gov.uk/uksi/2026/82/
 contents/made\n\nhttps://regulations.fru.dev/regulations/uk-gdpr
URL:https://regulations.fru.dev/regulations/uk-gdpr
CATEGORIES:United Kingdom,privacy,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-239@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260216
DTEND;VALUE=DATE:20260217
SUMMARY:HIPAA: Notice of Privacy Practices updates (Part 2 alignment)
DESCRIPTION:Covered entities must update Notices of Privacy Practices under
  45 CFR 164.520 for the 2024 Part 2 (substance use disorder records) chang
 es\; this NPP piece survived the Purl vacatur.\n\nHIPAA Privacy\, Security
  and Breach Notification Rules (45 CFR Parts 160 and 164) (United States (
 Federal))\n\nSource: https://www.federalregister.gov/documents/2024/04/26/
 2024-08503/hipaa-privacy-rule-to-support-reproductive-health-care-privacy\
 n\nhttps://regulations.fru.dev/regulations/us-hipaa
URL:https://regulations.fru.dev/regulations/us-hipaa
CATEGORIES:United States (Federal),privacy,health,cybersecurity,breach-noti
 fication
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6865@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260218
DTEND;VALUE=DATE:20260219
SUMMARY:EU e-Evidence Package: Legal representatives Directive transpositio
 n
DESCRIPTION:Member States must transpose Directive (EU) 2023/1544 on design
 ated establishments and legal representatives.\n\nRegulation (EU) 2023/154
 3 on European Production Orders and European Preservation Orders for elect
 ronic evidence in criminal proceedings\, and Directive (EU) 2023/1544 on l
 egal representatives (European Union)\n\nSource: https://eur-lex.europa.eu
 /eli/dir/2023/1544/oj/eng\n\nhttps://regulations.fru.dev/regulations/eu-e-
 evidence
URL:https://regulations.fru.dev/regulations/eu-e-evidence
CATEGORIES:European Union,privacy,data-access
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6990@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260220
DTEND;VALUE=DATE:20260221
SUMMARY:India IT Rules amendment on synthetic content: Synthetic content ru
 les take effect
DESCRIPTION:SGI labeling\, user declaration and verification duties\, and t
 he shorter 3 hour\, 36 hour and 2 hour takedown timelines apply.\n\nInform
 ation Technology (Intermediary Guidelines and Digital Media Ethics Code) A
 mendment Rules\, 2026 (India)\n\nSource: https://www.meity.gov.in/static/u
 ploads/2026/02/f55fe52418b03f58b0669f6a8bc03b6d.pdf\n\nhttps://regulations
 .fru.dev/regulations/in-it-rules-sgi
URL:https://regulations.fru.dev/regulations/in-it-rules-sgi
CATEGORIES:India,ai,online-safety
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-313@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260227
DTEND;VALUE=DATE:20260228
SUMMARY:Virginia VCDPA: SB 854 preliminarily enjoined (NetChoice v. Jones)
DESCRIPTION:E.D. Va. preliminarily enjoined enforcement of the SB 854 socia
 l media time-limit provisions on First Amendment grounds\; Virginia has ap
 pealed.\n\nVirginia Consumer Data Protection Act (SB 1392 / HB 2307\, 2021
 ) (Virginia)\n\nSource: https://netchoice.org/wp-content/uploads/2026/02/V
 irginia-PI-Opinion_Granted.pdf\n\nhttps://regulations.fru.dev/regulations/
 us-va-vcdpa
URL:https://regulations.fru.dev/regulations/us-va-vcdpa
CATEGORIES:Virginia,privacy,children,online-safety
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6984@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260301
DTEND;VALUE=DATE:20260302
SUMMARY:China Minors Online Protection Regulations: Classification measures
  for content harmful to minors take effect
DESCRIPTION:Implementing measures classify online information that may affe
 ct minors' physical and mental health.\n\nRegulations on the Protection of
  Minors Online (China)\n\nSource: https://www.cac.gov.cn/2026-01/23/c_1770
 728781060093.htm\n\nhttps://regulations.fru.dev/regulations/cn-minors-onli
 ne-protection
URL:https://regulations.fru.dev/regulations/cn-minors-online-protection
CATEGORIES:China,children,privacy,online-safety
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-321@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260301
DTEND;VALUE=DATE:20260302
SUMMARY:Vietnam AI Law: AI Law takes effect
DESCRIPTION:Risk classification\, transparency and labeling obligations app
 ly to new AI systems.\n\nLaw on Artificial Intelligence (Law No. 134/2025/
 QH15) (Vietnam)\n\nSource: https://beta-en.mic.gov.vn/first-ever-law-on-ar
 tificial-intelligence-approved-197251215231241888.htm\n\nhttps://regulatio
 ns.fru.dev/regulations/vn-ai-law
URL:https://regulations.fru.dev/regulations/vn-ai-law
CATEGORIES:Vietnam,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-7043@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260304
DTEND;VALUE=DATE:20260305
SUMMARY:Australia Cyber Security Act (ransomware reporting): Smart device s
 ecurity standard applies
DESCRIPTION:Part 2 and Schedule 1 of the Cyber Security (Security Standards
  for Smart Devices) Rules 2025 commence. Manufacturers and suppliers of re
 levant connectable products must meet the security standard.\n\nCyber Secu
 rity Act 2024 (Cth) and Cyber Security (Ransomware Payment Reporting) Rule
 s 2025 (Australia)\n\nSource: https://www.legislation.gov.au/F2025L00276/a
 smade\n\nhttps://regulations.fru.dev/regulations/au-cyber-security-act
URL:https://regulations.fru.dev/regulations/au-cyber-security-act
CATEGORIES:Australia,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-125@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260310
DTEND;VALUE=DATE:20260311
SUMMARY:South Korea PIPA: 2026 PIPA amendment promulgated (Act No. 21445)
DESCRIPTION:Amendment raising fines to 10% of revenue and adding CEO accoun
 tability promulgated.\n\nPersonal Information Protection Act (as amended b
 y Act No. 21445\, 2026) (South Korea)\n\nSource: https://www.law.go.kr/법
 령/개인정보보호법\n\nhttps://regulations.fru.dev/regulations/kr-pi
 pa
URL:https://regulations.fru.dev/regulations/kr-pipa
CATEGORIES:South Korea,privacy,breach-notification,biometrics,data-residenc
 y
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6894@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260311
DTEND;VALUE=DATE:20260312
SUMMARY:AI state-law preemption EO: Commerce state-law evaluation\, BEAD no
 tice and FTC statement due
DESCRIPTION:Within 90 days of the order: Commerce publishes its list of one
 rous state AI laws\, NTIA issues the BEAD policy notice\, and the FTC issu
 es a policy statement (date computed from signing).\n\nExecutive Order 143
 65: Ensuring a National Policy Framework for Artificial Intelligence (Unit
 ed States)\n\nSource: https://www.federalregister.gov/documents/2025/12/16
 /2025-23092/ensuring-a-national-policy-framework-for-artificial-intelligen
 ce\n\nhttps://regulations.fru.dev/regulations/us-eo-14365-ai-preemption
URL:https://regulations.fru.dev/regulations/us-eo-14365-ai-preemption
CATEGORIES:United States,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-10@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260317
DTEND;VALUE=DATE:20260318
SUMMARY:Brazil ECA Digital: ECA Digital in force
DESCRIPTION:Art. 41-A (as set by Law 15.352/2026\, following MP 1.319/2025)
  fixes entry into force on 17 March 2026.\n\nEstatuto Digital da Criança 
 e do Adolescente (Law No. 15.211/2025) (Brazil)\n\nSource: https://www.pla
 nalto.gov.br/ccivil_03/_ato2023-2026/2025/lei/L15211.htm\n\nhttps://regula
 tions.fru.dev/regulations/br-eca-digital
URL:https://regulations.fru.dev/regulations/br-eca-digital
CATEGORIES:Brazil,children,online-safety,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-279@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260327
DTEND;VALUE=DATE:20260328
SUMMARY:NY RAISE Act: Chapter amendment S8828 signed
DESCRIPTION:Chapter amendment (ch. 96) finalizes the RAISE Act text.\n\nNew
  York Responsible AI Safety and Education (RAISE) Act (S6953-B/A6453-B of 
 2025)\, as amended by chapter amendment S8828 of 2026 (New York)\n\nSource
 : https://www.nysenate.gov/legislation/bills/2025/S8828\n\nhttps://regulat
 ions.fru.dev/regulations/us-ny-raise
URL:https://regulations.fru.dev/regulations/us-ny-raise
CATEGORIES:New York,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6985@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260401
DTEND;VALUE=DATE:20260402
SUMMARY:China Minors Online Protection Regulations: Measures identifying la
 rge or influential platforms for minors take effect
DESCRIPTION:Platforms meeting the thresholds (for example 10 million regist
 ered or 1 million monthly active minor users) must apply to be designated.
 \n\nRegulations on the Protection of Minors Online (China)\n\nSource: http
 s://www.cac.gov.cn/2026-02/28/c_1774010730056867.htm\n\nhttps://regulation
 s.fru.dev/regulations/cn-minors-online-protection
URL:https://regulations.fru.dev/regulations/cn-minors-online-protection
CATEGORIES:China,children,privacy,online-safety
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-243@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260401
DTEND;VALUE=DATE:20260402
SUMMARY:Illinois BIPA: Seventh Circuit: amendment applies retroactively
DESCRIPTION:Clay v. Union Pacific (No. 25-2185) holds the damages amendment
  is remedial and applies to pending cases.\n\nIllinois Biometric Informati
 on Privacy Act (740 ILCS 14)\, as amended by SB 2979 (Public Act 103-0769)
  (Illinois)\n\nSource: https://law.justia.com/cases/federal/appellate-cour
 ts/ca7/25-2185/25-2185-2026-04-01.html\n\nhttps://regulations.fru.dev/regu
 lations/us-il-bipa
URL:https://regulations.fru.dev/regulations/us-il-bipa
CATEGORIES:Illinois,biometrics,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6994@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260401
DTEND;VALUE=DATE:20260402
SUMMARY:Japan Active Cyber Defense Act: Supervisory Commission provisions i
 n force
DESCRIPTION:Provisions setting up the Cyber Communications Information Supe
 rvisory Commission take effect\, per the e-Gov revision history.\n\nAct on
  the Prevention of Damage from Unauthorized Acts against Important Compute
 rs (Act No. 42 of 2025) (Japan)\n\nSource: https://laws.e-gov.go.jp/api/2/
 law_revisions/507AC0000000042?response_format=json\n\nhttps://regulations.
 fru.dev/regulations/jp-active-cyber-defense
URL:https://regulations.fru.dev/regulations/jp-active-cyber-defense
CATEGORIES:Japan,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6935@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260401
DTEND;VALUE=DATE:20260402
SUMMARY:Maryland Kids Code: Data protection impact assessments due
DESCRIPTION:Covered entities must complete DPIAs by this date.\n\nMaryland 
 Age-Appropriate Design Code Act (Maryland Kids Code\, HB 603) (Maryland)\n
 \nSource: https://mgaleg.maryland.gov/mgawebsite/Legislation/Details/hb060
 3?ys=2024RS\n\nhttps://regulations.fru.dev/regulations/us-md-kids-code
URL:https://regulations.fru.dev/regulations/us-md-kids-code
CATEGORIES:Maryland,children,privacy,online-safety
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-253@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260401
DTEND;VALUE=DATE:20260402
SUMMARY:Maryland Online Data Privacy Act (MODPA): MODPA applies to personal
  data processing
DESCRIPTION:The act applies to personal data processing activities from Apr
 il 1\, 2026 (Section 2 of ch. 455).\n\nMaryland Online Data Privacy Act of
  2024 (SB 541 / HB 567)\, Md. Code\, Com. Law 14-4601 et seq. (Maryland)\n
 \nSource: https://mgaleg.maryland.gov/2024RS/Chapters_noln/CH_455_sb0541e.
 pdf\n\nhttps://regulations.fru.dev/regulations/us-md-modpa
URL:https://regulations.fru.dev/regulations/us-md-modpa
CATEGORIES:Maryland,privacy,children,health,biometrics
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6860@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260403
DTEND;VALUE=DATE:20260404
SUMMARY:EU CSAM Interim Regulation: Previous interim regulation expires
DESCRIPTION:Regulation (EU) 2021/1232\, as extended by Regulation (EU) 2024
 /1307\, applied until this date.\n\nRegulation (EU) 2026/1881 on a tempora
 ry derogation from certain provisions of Directive 2002/58/EC for combatin
 g online child sexual abuse (European Union)\n\nSource: https://eur-lex.eu
 ropa.eu/eli/reg/2024/1307/oj/eng\n\nhttps://regulations.fru.dev/regulation
 s/eu-csam-interim
URL:https://regulations.fru.dev/regulations/eu-csam-interim
CATEGORIES:European Union,privacy,children,online-safety
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-160@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260411
DTEND;VALUE=DATE:20260412
SUMMARY:UK Online Safety Act: Fee notification window closes (2026/27)
DESCRIPTION:Fee-liable providers must notify Ofcom before the notification 
 window for the first charging year closes.\n\nOnline Safety Act 2023 (Unit
 ed Kingdom)\n\nSource: https://www.ofcom.org.uk/online-safety/illegal-and-
 harmful-content/online-safety-fees-and-penalties\n\nhttps://regulations.fr
 u.dev/regulations/uk-osa
URL:https://regulations.fru.dev/regulations/uk-osa
CATEGORIES:United Kingdom,online-safety,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-277@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260415
DTEND;VALUE=DATE:20260416
SUMMARY:NYDFS Cybersecurity Regulation (Part 500): Annual compliance notifi
 cation
DESCRIPTION:Annual certification or acknowledgment covering calendar year 2
 025 due.\n\nNew York DFS Cybersecurity Requirements for Financial Services
  Companies (23 NYCRR Part 500)\, Second Amendment (New York)\n\nSource: ht
 tps://www.dfs.ny.gov/cybersecurity/23-NYCRR-Part-500\n\nhttps://regulation
 s.fru.dev/regulations/us-ny-dfs-500
URL:https://regulations.fru.dev/regulations/us-ny-dfs-500
CATEGORIES:New York,cybersecurity,breach-notification,financial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6879@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260421
DTEND;VALUE=DATE:20260422
SUMMARY:CoE AI Framework Convention: EU concludes the Convention
DESCRIPTION:Council Decision (EU) 2026/1080 approves conclusion on behalf o
 f the EU (published 2026-05-13).\n\nCouncil of Europe Framework Convention
  on Artificial Intelligence and Human Rights\, Democracy and the Rule of L
 aw (Council of Europe)\n\nSource: https://eur-lex.europa.eu/eli/dec/2026/1
 080/oj/eng\n\nhttps://regulations.fru.dev/regulations/coe-ai-convention
URL:https://regulations.fru.dev/regulations/coe-ai-convention
CATEGORIES:Council of Europe,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-214@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260422
DTEND;VALUE=DATE:20260423
SUMMARY:COPPA Rule: Full compliance with amended COPPA Rule
DESCRIPTION:Operators must comply with all amended provisions (separate thi
 rd-party disclosure consent\, written retention policy\, written security 
 program\, updated notices)\; excludes Safe Harbor provisions 312.11(d)(1)\
 , (d)(4) and (g)\, which had earlier dates.\n\nChildren's Online Privacy P
 rotection Rule (16 CFR Part 312)\, as amended April 2025 (United States (F
 ederal))\n\nSource: https://www.federalregister.gov/documents/2025/04/22/2
 025-05904/childrens-online-privacy-protection-rule\n\nhttps://regulations.
 fru.dev/regulations/us-coppa
URL:https://regulations.fru.dev/regulations/us-coppa
CATEGORIES:United States (Federal),privacy,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-7028@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260501
DTEND;VALUE=DATE:20260502
SUMMARY:New Zealand Biometric Processing Privacy Code: Amendment No. 1 appl
 ies (IPP 3A)
DESCRIPTION:The amended code\, which reflects IPP 3A\, is in force from 1 M
 ay 2026.\n\nBiometric Processing Privacy Code 2025 (New Zealand)\n\nSource
 : https://www.privacy.org.nz/privacy-principles/codes-of-practice/biometri
 c-processing-privacy-code/\n\nhttps://regulations.fru.dev/regulations/nz-b
 iometric-code
URL:https://regulations.fru.dev/regulations/nz-biometric-code
CATEGORIES:New Zealand,biometrics,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-136@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260501
DTEND;VALUE=DATE:20260502
SUMMARY:New Zealand Privacy Act: IPP 3A indirect-collection notification ap
 plies
DESCRIPTION:Agencies collecting personal information from third parties mus
 t take reasonable steps to notify individuals\, subject to exceptions.\n\n
 Privacy Act 2020 (New Zealand)\, as amended by the Privacy Amendment Act 2
 025 (New Zealand)\n\nSource: https://www.justice.govt.nz/justice-sector-po
 licy/key-initiatives/enhancing-the-privacy-act/\n\nhttps://regulations.fru
 .dev/regulations/nz-privacy-act
URL:https://regulations.fru.dev/regulations/nz-privacy-act
CATEGORIES:New Zealand,privacy,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6973@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260503
DTEND;VALUE=DATE:20260504
SUMMARY:Digital Markets Act: DMA first review
DESCRIPTION:Commission evaluation of the DMA under Article 53\, then every 
 3 years.\n\nRegulation (EU) 2022/1925 on contestable and fair markets in t
 he digital sector (Digital Markets Act) (European Union)\n\nSource: https:
 //eur-lex.europa.eu/eli/reg/2022/1925/oj/eng\n\nhttps://regulations.fru.de
 v/regulations/eu-dma
URL:https://regulations.fru.dev/regulations/eu-dma
CATEGORIES:European Union,data-access,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6927@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260506
DTEND;VALUE=DATE:20260507
SUMMARY:Texas App Store Accountability Act: Stay pending appeal denied
DESCRIPTION:District court keeps the injunction in place during the state's
  appeal.\n\nTexas App Store Accountability Act (SB 2420) (Texas)\n\nSource
 : https://www.govinfo.gov/content/pkg/USCOURTS-txwd-1_25-cv-01660/pdf/USCO
 URTS-txwd-1_25-cv-01660-1.pdf\n\nhttps://regulations.fru.dev/regulations/u
 s-tx-app-store
URL:https://regulations.fru.dev/regulations/us-tx-app-store
CATEGORIES:Texas,children,privacy,online-safety
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6929@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260506
DTEND;VALUE=DATE:20260507
SUMMARY:Utah App Store Accountability Act: App store and developer duties a
 pply
DESCRIPTION:Sections 13-75-201 and 13-75-202 take effect.\n\nUtah App Store
  Accountability Act (SB 142) (Utah)\n\nSource: https://le.utah.gov/Session
 /2025/bills/enrolled/SB0142.pdf\n\nhttps://regulations.fru.dev/regulations
 /us-ut-app-store
URL:https://regulations.fru.dev/regulations/us-ut-app-store
CATEGORIES:Utah,children,privacy,online-safety
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-202@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260514
DTEND;VALUE=DATE:20260515
SUMMARY:Colorado AI Act: SB 26-189 signed (repeal and reenact)
DESCRIPTION:SB 26-189 replaces SB 24-205 with a narrower ADMT disclosure fr
 amework and moves the effective date to January 1\, 2027.\n\nColorado SB 2
 4-205 (Consumer Protections for Artificial Intelligence)\, as delayed by S
 B 25B-004 and repealed and reenacted by SB 26-189 (Automated Decision-Maki
 ng Technology) (Colorado)\n\nSource: https://leg.colorado.gov/bills/sb26-1
 89\n\nhttps://regulations.fru.dev/regulations/us-co-ai-act
URL:https://regulations.fru.dev/regulations/us-co-ai-act
CATEGORIES:Colorado,ai,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-246@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260515
DTEND;VALUE=DATE:20260516
SUMMARY:Illinois AI in Employment Law (HB 3773): IDHR proposed notice rules
  published
DESCRIPTION:IDHR publishes proposed Subpart J rules on AI notice in the Ill
 inois Register.\n\nIllinois HB 3773 (Public Act 103-0804)\, amending the I
 llinois Human Rights Act on artificial intelligence in employment (Illinoi
 s)\n\nSource: https://ogletree.com/insights-resources/blog-posts/illinois-
 postpones-proposed-regulations-on-ai-in-employment/\n\nhttps://regulations
 .fru.dev/regulations/us-il-hb3773
URL:https://regulations.fru.dev/regulations/us-il-hb3773
CATEGORIES:Illinois,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-299@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260519
DTEND;VALUE=DATE:20260520
SUMMARY:TAKE IT DOWN Act: Platform notice-and-removal process required
DESCRIPTION:Covered platforms must have a clear notice-and-removal process 
 and remove valid reported content within 48 hours (Sec. 3\, one year after
  enactment).\n\nTools to Address Known Exploitation by Immobilizing Techno
 logical Deepfakes on Websites and Networks Act (TAKE IT DOWN Act) (United 
 States (Federal))\n\nSource: https://www.govinfo.gov/content/pkg/PLAW-119p
 ubl12/html/PLAW-119publ12.htm\n\nhttps://regulations.fru.dev/regulations/u
 s-take-it-down
URL:https://regulations.fru.dev/regulations/us-take-it-down
CATEGORIES:United States (Federal),online-safety,ai,children,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-87@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260521
DTEND;VALUE=DATE:20260522
SUMMARY:eIDAS 2 / EU Digital Identity Wallet: Legacy qualified trust servic
 e providers conformity report
DESCRIPTION:QTSPs qualified before 20 May 2024 had to submit a conformity a
 ssessment report proving compliance with Art 24(1)\, (1a) and (1b) by 21 M
 ay 2026.\n\nRegulation (EU) 2024/1183 amending Regulation (EU) No 910/2014
  as regards establishing the European Digital Identity Framework (eIDAS 2)
  (European Union)\n\nSource: https://eur-lex.europa.eu/eli/reg/2024/1183/o
 j\n\nhttps://regulations.fru.dev/regulations/eu-eidas2
URL:https://regulations.fru.dev/regulations/eu-eidas2
CATEGORIES:European Union,privacy,data-access,biometrics
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-247@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260602
DTEND;VALUE=DATE:20260603
SUMMARY:Illinois AI in Employment Law (HB 3773): IDHR withdraws and postpon
 es proposed rules
DESCRIPTION:IDHR withdraws the Subpart J proposal and postpones the June 10
 \, 2026 hearing\; no new date announced.\n\nIllinois HB 3773 (Public Act 1
 03-0804)\, amending the Illinois Human Rights Act on artificial intelligen
 ce in employment (Illinois)\n\nSource: https://ogletree.com/insights-resou
 rces/blog-posts/illinois-postpones-proposed-regulations-on-ai-in-employmen
 t/\n\nhttps://regulations.fru.dev/regulations/us-il-hb3773
URL:https://regulations.fru.dev/regulations/us-il-hb3773
CATEGORIES:Illinois,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-297@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260603
DTEND;VALUE=DATE:20260604
SUMMARY:SEC Regulation S-P: Smaller entities must comply
DESCRIPTION:Smaller covered institutions (24 months after Federal Register 
 publication) must comply with the amended Regulation S-P.\n\nRegulation S-
 P: Privacy of Consumer Financial Information and Safeguarding Customer Inf
 ormation (2024 amendments) (United States (Federal))\n\nSource: https://ww
 w.federalregister.gov/documents/2024/06/03/2024-11116/regulation-s-p-priva
 cy-of-consumer-financial-information-and-safeguarding-customer-information
 \n\nhttps://regulations.fru.dev/regulations/us-sec-reg-sp
URL:https://regulations.fru.dev/regulations/us-sec-reg-sp
CATEGORIES:United States (Federal),financial,privacy,cybersecurity,breach-n
 otification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6947@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260611
DTEND;VALUE=DATE:20260612
SUMMARY:Alberta POPA: Privacy management programs required
DESCRIPTION:Public bodies must establish and implement a privacy management
  program one year after the section comes into force (s. 25(5)).\n\nProtec
 tion of Privacy Act (Alberta\, Canada)\n\nSource: https://kings-printer.al
 berta.ca/1266.cfm?page=p28p5.cfm&leg_type=Acts&isbncln=9780779861309&displ
 ay=html\n\nhttps://regulations.fru.dev/regulations/ca-ab-popa
URL:https://regulations.fru.dev/regulations/ca-ab-popa
CATEGORIES:Alberta\, Canada,privacy,breach-notification,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-49@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260611
DTEND;VALUE=DATE:20260612
SUMMARY:Cyber Resilience Act: Conformity assessment body provisions apply
DESCRIPTION:Chapter IV (Arts 35-51\, notification of conformity assessment 
 bodies) applies (Art 71(2)).\n\nRegulation (EU) 2024/2847 on horizontal cy
 bersecurity requirements for products with digital elements (Cyber Resilie
 nce Act) (European Union)\n\nSource: https://eur-lex.europa.eu/eli/reg/202
 4/2847/oj\n\nhttps://regulations.fru.dev/regulations/eu-cra
URL:https://regulations.fru.dev/regulations/eu-cra
CATEGORIES:European Union,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-15@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260615
DTEND;VALUE=DATE:20260616
SUMMARY:Canada Bill C-36 (PPCDA): Bill C-36 tabled (first reading)
DESCRIPTION:Government introduces the PPCDA in the House of Commons.\n\nBil
 l C-36\, An Act to enact the Protecting Privacy and Consumer Data Act (Can
 ada)\n\nSource: https://www.parl.ca/DocumentViewer/en/45-1/bill/C-36/first
 -reading\n\nhttps://regulations.fru.dev/regulations/ca-c36-ppcda
URL:https://regulations.fru.dev/regulations/ca-c36-ppcda
CATEGORIES:Canada,privacy,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-17@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260615
DTEND;VALUE=DATE:20260616
SUMMARY:Canada Bill C-8 / CCSPA: Royal Assent
DESCRIPTION:Bill C-8 receives Royal Assent (S.C. 2026\, c. 9)\; Telecommuni
 cations Act amendments take effect.\n\nCritical Cyber Systems Protection A
 ct (enacted by Bill C-8\, An Act respecting cyber security) (Canada)\n\nSo
 urce: https://www.parl.ca/legisinfo/en/bill/45-1/c-8\n\nhttps://regulation
 s.fru.dev/regulations/ca-ccspa
URL:https://regulations.fru.dev/regulations/ca-ccspa
CATEGORIES:Canada,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-146@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260616
DTEND;VALUE=DATE:20260617
SUMMARY:UK Cyber Security and Resilience Bill: Passes House of Commons
DESCRIPTION:Report stage and third reading completed in the Commons after c
 arry-over into the new session.\n\nCyber Security and Resilience (Network 
 and Information Systems) Bill (United Kingdom)\n\nSource: https://bills.pa
 rliament.uk/bills/4035\n\nhttps://regulations.fru.dev/regulations/uk-csr-b
 ill
URL:https://regulations.fru.dev/regulations/uk-csr-bill
CATEGORIES:United Kingdom,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-151@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260619
DTEND;VALUE=DATE:20260620
SUMMARY:Data (Use and Access) Act: Mandatory data protection complaints pro
 cedure
DESCRIPTION:Controllers must have a process for data subject complaints (s.
 103 and Sch. 10)\, per Commencement No. 6 Regulations 2026\, reg. 3.\n\nDa
 ta (Use and Access) Act 2025 (United Kingdom)\n\nSource: https://www.legis
 lation.gov.uk/uksi/2026/82/contents/made\n\nhttps://regulations.fru.dev/re
 gulations/uk-duaa
URL:https://regulations.fru.dev/regulations/uk-duaa
CATEGORIES:United Kingdom,privacy,data-access,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-7010@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260629
DTEND;VALUE=DATE:20260630
SUMMARY:Singapore Online Safety (Relief and Accountability) Act: OSC begins
  operations and first provisions commence
DESCRIPTION:OSC starts taking reports for five harms\, and the statutory to
 rts for those harms take effect.\n\nOnline Safety (Relief and Accountabili
 ty) Act 2025 (Singapore)\n\nSource: https://www.osc.gov.sg/newsroom/the-on
 line-safety-commission-begins-operations-on-29-june-2026/\n\nhttps://regul
 ations.fru.dev/regulations/sg-online-safety-act
URL:https://regulations.fru.dev/regulations/sg-online-safety-act
CATEGORIES:Singapore,online-safety,children,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6885@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260630
DTEND;VALUE=DATE:20260701
SUMMARY:CFPB Open Banking Rule (Section 1033): First compliance date (staye
 d\, enjoined)
DESCRIPTION:Largest data providers (banks with $250B or more in assets\; no
 ndepositories with $10B or more in receipts). Originally 2026-04-01\, move
 d 90 days by court stay. Not enforceable while the injunction stands.\n\nT
 entative: depends on a proposal not yet adopted.\n\nRequired Rulemaking on
  Personal Financial Data Rights (12 CFR Part 1033) (United States)\n\nSour
 ce: https://www.federalregister.gov/documents/2025/08/22/2025-16139/person
 al-financial-data-rights-reconsideration\n\nhttps://regulations.fru.dev/re
 gulations/us-cfpb-1033
URL:https://regulations.fru.dev/regulations/us-cfpb-1033
CATEGORIES:United States,data-access,financial,privacy,cybersecurity
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-203@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260630
DTEND;VALUE=DATE:20260701
SUMMARY:Colorado AI Act: Delayed effective date (superseded)
DESCRIPTION:SB 25B-004 date\; superseded by SB 26-189 before it arrived\, s
 o no obligations applied.\n\nColorado SB 24-205 (Consumer Protections for 
 Artificial Intelligence)\, as delayed by SB 25B-004 and repealed and reena
 cted by SB 26-189 (Automated Decision-Making Technology) (Colorado)\n\nSou
 rce: https://leg.colorado.gov/bills/sb25b-004\n\nhttps://regulations.fru.d
 ev/regulations/us-co-ai-act
URL:https://regulations.fru.dev/regulations/us-co-ai-act
CATEGORIES:Colorado,ai,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-267@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260630
DTEND;VALUE=DATE:20260701
SUMMARY:New Jersey NJDPA: A5328 sensitive data sale ban takes effect
DESCRIPTION:A5328\, signed June 30\, 2026\, prohibits selling sensitive per
 sonal data\; the ban took effect on signing.\n\nNew Jersey Data Privacy Ac
 t (P.L.2023\, c.266\; S332) (New Jersey)\n\nSource: https://www.njleg.stat
 e.nj.us/bill-search/2026/A5328\n\nhttps://regulations.fru.dev/regulations/
 us-nj-njdpa
URL:https://regulations.fru.dev/regulations/us-nj-njdpa
CATEGORIES:New Jersey,privacy,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-7037@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260630
DTEND;VALUE=DATE:20260701
SUMMARY:UAE Child Digital Safety Law: Social media minimum age resolution t
 akes effect
DESCRIPTION:Cabinet Resolution No. 106 of 2026 applies from the day after p
 ublication in Official Gazette No. 826 on 29 June 2026.\n\nFederal Decree 
 by Law No. 26 of 2025 Regarding Child Digital Safety (United Arab Emirates
 )\n\nSource: https://uaelegislation.gov.ae/en/legislations/4506\n\nhttps:/
 /regulations.fru.dev/regulations/ae-child-digital-safety
URL:https://regulations.fru.dev/regulations/ae-child-digital-safety
CATEGORIES:United Arab Emirates,children,online-safety,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6942@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260701
DTEND;VALUE=DATE:20260702
SUMMARY:Arkansas COPPA 2.0: Takes effect
DESCRIPTION:Section 3: effective on and after July 1\, 2026.\n\nArkansas Ch
 ildren and Teens' Online Privacy Protection Act (Act 952 of 2025\, HB 1717
 ) (Arkansas)\n\nSource: https://arkleg.state.ar.us/Bills/Detail?id=HB1717&
 ddBienniumSession=2025%2F2025R\n\nhttps://regulations.fru.dev/regulations/
 us-ar-cttoppa
URL:https://regulations.fru.dev/regulations/us-ar-cttoppa
CATEGORIES:Arkansas,children,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-218@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260701
DTEND;VALUE=DATE:20260702
SUMMARY:Connecticut Data Privacy Act (CTDPA): PA 25-113 (SB 1295) amendment
 s take effect
DESCRIPTION:Thresholds drop to 35\,000 consumers or any sensitive-data proc
 essing or data sale\; expanded sensitive data\, minors' protections\, and 
 LLM-training disclosure in privacy notices.\n\nConnecticut Data Privacy Ac
 t (Public Act 22-15)\, Conn. Gen. Stat. 42-515 et seq.\, as amended by Pub
 lic Act 25-113 (SB 1295) and Public Act 26-64 (SB 4) (Connecticut)\n\nSour
 ce: https://www.cga.ct.gov/2025/ACT/PA/PDF/2025PA-00113-R00SB-01295-PA.PDF
 \n\nhttps://regulations.fru.dev/regulations/us-ct-ctdpa
URL:https://regulations.fru.dev/regulations/us-ct-ctdpa
CATEGORIES:Connecticut,privacy,children,ai,health
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6932@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260701
DTEND;VALUE=DATE:20260702
SUMMARY:Louisiana app store age verification law: Takes effect
DESCRIPTION:Section 5: act effective July 1\, 2026.\n\nLouisiana Act 481 of
  2025 on Minors' Use of Applications (HB 570) (Louisiana)\n\nSource: https
 ://legis.la.gov/legis/ViewDocument.aspx?d=1427667\n\nhttps://regulations.f
 ru.dev/regulations/us-la-app-store
URL:https://regulations.fru.dev/regulations/us-la-app-store
CATEGORIES:Louisiana,children,privacy,online-safety
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-7016@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260701
DTEND;VALUE=DATE:20260702
SUMMARY:Malaysia Online Safety Act: Online Safety Plan and compounding regu
 lations in force
DESCRIPTION:P.U. (A) 244/2026 and P.U. (A) 245/2026 take effect.\n\nOnline 
 Safety Act 2025 (Act 866) (Malaysia)\n\nSource: https://lom.agc.gov.my/ili
 ms/upload/portal/akta/outputp/3582105/PUA%20244_2026.pdf\n\nhttps://regula
 tions.fru.dev/regulations/my-online-safety-act
URL:https://regulations.fru.dev/regulations/my-online-safety-act
CATEGORIES:Malaysia,online-safety,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6940@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260701
DTEND;VALUE=DATE:20260702
SUMMARY:Nebraska Kids Code: Civil penalties available
DESCRIPTION:AG may begin actions to recover civil penalties.\n\nNebraska Ag
 e-Appropriate Online Design Code Act (LB 504) (Nebraska)\n\nSource: https:
 //nebraskalegislature.gov/FloorDocs/109/PDF/Slip/LB504.pdf\n\nhttps://regu
 lations.fru.dev/regulations/us-ne-aadc
URL:https://regulations.fru.dev/regulations/us-ne-aadc
CATEGORIES:Nebraska,children,privacy,online-safety
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-268@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260701
DTEND;VALUE=DATE:20260702
SUMMARY:New Jersey NJDPA: Mandatory 30-day cure period expires
DESCRIPTION:The Division's duty to issue a cure notice before enforcement e
 nds on the first day of the 18th month after the effective date (N.J.S.A. 
 56:8-166.17(b)).\n\nNew Jersey Data Privacy Act (P.L.2023\, c.266\; S332) 
 (New Jersey)\n\nSource: https://pub.njleg.state.nj.us/Bills/2022/PL23/266_
 .PDF\n\nhttps://regulations.fru.dev/regulations/us-nj-njdpa
URL:https://regulations.fru.dev/regulations/us-nj-njdpa
CATEGORIES:New Jersey,privacy,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-309@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260701
DTEND;VALUE=DATE:20260702
SUMMARY:Utah UCPA: Right to correct takes effect
DESCRIPTION:Consumers may ask controllers to correct inaccurate personal da
 ta (13-61-201(4)\, as amended by Laws 2025\, ch. 468).\n\nUtah Consumer Pr
 ivacy Act (SB 227\, 2022) (Utah)\n\nSource: https://le.utah.gov/xcode/Titl
 e13/Chapter61/13-61-S201.html\n\nhttps://regulations.fru.dev/regulations/u
 s-ut-ucpa
URL:https://regulations.fru.dev/regulations/us-ut-ucpa
CATEGORIES:Utah,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-7019@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260701
DTEND;VALUE=DATE:20260702
SUMMARY:Vietnam Cybersecurity Law 2025: Cybersecurity Law 2025 takes effect
DESCRIPTION:The new law takes effect. Law 86/2015/QH13 and Law 24/2018/QH14
  cease to have effect.\n\nCybersecurity Law 2025 (Law No. 116/2025/QH15) (
 Vietnam)\n\nSource: https://vanban.chinhphu.vn/?pageid=27160&docid=216499\
 n\nhttps://regulations.fru.dev/regulations/vn-cybersecurity-law
URL:https://regulations.fru.dev/regulations/vn-cybersecurity-law
CATEGORIES:Vietnam,cybersecurity,data-residency,online-safety
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-314@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260701
DTEND;VALUE=DATE:20260702
SUMMARY:Virginia VCDPA: Ban on selling precise geolocation data (SB 338)
DESCRIPTION:Controllers may not sell consumers' precise geolocation data (1
 \,750-ft radius)\, replacing the prior consent-based treatment.\n\nVirgini
 a Consumer Data Protection Act (SB 1392 / HB 2307\, 2021) (Virginia)\n\nSo
 urce: https://lis.virginia.gov/bill-details/20261/SB338\n\nhttps://regulat
 ions.fru.dev/regulations/us-va-vcdpa
URL:https://regulations.fru.dev/regulations/us-va-vcdpa
CATEGORIES:Virginia,privacy,children,online-safety
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6895@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260707
DTEND;VALUE=DATE:20260708
SUMMARY:AI state-law preemption EO: FTC proposes AI accuracy policy stateme
 nt
DESCRIPTION:FTC publishes a proposed policy statement on deceptive suppress
 ion of accuracy in AI systems (91 FR 41638)\, linked to Section 7 of the E
 O.\n\nExecutive Order 14365: Ensuring a National Policy Framework for Arti
 ficial Intelligence (United States)\n\nSource: https://www.federalregister
 .gov/documents/2026/07/07/2026-13628/policy-statement-concerning-the-suppr
 ession-of-accuracy-in-artificial-intelligence-systems\n\nhttps://regulatio
 ns.fru.dev/regulations/us-eo-14365-ai-preemption
URL:https://regulations.fru.dev/regulations/us-eo-14365-ai-preemption
CATEGORIES:United States,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6987@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260715
DTEND;VALUE=DATE:20260716
SUMMARY:China Anthropomorphic AI Measures: Anthropomorphic AI measures take
  effect
DESCRIPTION:AI disclosure\, usage reminders\, minor protection\, data and s
 ecurity assessment duties apply.\n\nInterim Measures for the Management of
  Anthropomorphic AI Interaction Services (China)\n\nSource: https://www.ca
 c.gov.cn/2026-04/10/c_1777558395078289.htm\n\nhttps://regulations.fru.dev/
 regulations/cn-anthropomorphic-ai
URL:https://regulations.fru.dev/regulations/cn-anthropomorphic-ai
CATEGORIES:China,ai,children,online-safety,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-122@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260717
DTEND;VALUE=DATE:20260718
SUMMARY:Japan APPI: 2026 APPI amendment act promulgated
DESCRIPTION:Amendment enacted by the Diet on 10 July 2026 and promulgated\;
  main provisions take effect by cabinet order within two years of promulga
 tion.\n\nAct on the Protection of Personal Information (Act No. 57 of 2003
 )\, as amended including the 2026 amendment act (Japan)\n\nSource: https:/
 /www.ppc.go.jp/files/pdf/260731_shiryou-1.pdf\n\nhttps://regulations.fru.d
 ev/regulations/jp-appi
URL:https://regulations.fru.dev/regulations/jp-appi
CATEGORIES:Japan,privacy,children,biometrics,breach-notification,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-40@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260727
DTEND;VALUE=DATE:20260728
SUMMARY:EU AI Act: Digital Omnibus on AI enters into force
DESCRIPTION:Regulation (EU) 2026/1744 (adopted 8 July 2026\, OJ 24 July 202
 6) enters into force on the third day after publication. Amended Articles 
 102 to 110 apply from this date (new Art 113(d)).\n\nRegulation (EU) 2024/
 1689 laying down harmonised rules on artificial intelligence (Artificial I
 ntelligence Act)\, as amended by Regulation (EU) 2026/1744 (Digital Omnibu
 s on AI) (European Union)\n\nSource: https://eur-lex.europa.eu/eli/reg/202
 6/1744/oj\n\nhttps://regulations.fru.dev/regulations/eu-ai-act
URL:https://regulations.fru.dev/regulations/eu-ai-act
CATEGORIES:European Union,ai,biometrics,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6915@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260728
DTEND;VALUE=DATE:20260729
SUMMARY:NY SAFE for Kids Act: Final SAFE for Kids rules released
DESCRIPTION:AG releases final 13 NYCRR Part 700 rules.\n\nStop Addictive Fe
 eds Exploitation (SAFE) for Kids Act (New York)\n\nSource: https://ag.ny.g
 ov/press-release/2026/attorney-general-james-and-governor-hochul-release-f
 inal-safe-kids-act-rules\n\nhttps://regulations.fru.dev/regulations/us-ny-
 safe-kids
URL:https://regulations.fru.dev/regulations/us-ny-safe-kids
CATEGORIES:New York,children,online-safety
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6916@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260729
DTEND;VALUE=DATE:20260730
SUMMARY:NY SAFE for Kids Act: Rules published in State Register
DESCRIPTION:Starts the 180-day clock.\n\nStop Addictive Feeds Exploitation 
 (SAFE) for Kids Act (New York)\n\nSource: https://ag.ny.gov/press-release/
 2026/attorney-general-james-and-governor-hochul-release-final-safe-kids-ac
 t-rules\n\nhttps://regulations.fru.dev/regulations/us-ny-safe-kids
URL:https://regulations.fru.dev/regulations/us-ny-safe-kids
CATEGORIES:New York,children,online-safety
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6896@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260731
DTEND;VALUE=DATE:20260801
SUMMARY:AI state-law preemption EO: FTC policy statement comments close
DESCRIPTION:Comment deadline on the proposed FTC AI policy statement.\n\nEx
 ecutive Order 14365: Ensuring a National Policy Framework for Artificial I
 ntelligence (United States)\n\nSource: https://www.federalregister.gov/doc
 uments/2026/07/07/2026-13628/policy-statement-concerning-the-suppression-o
 f-accuracy-in-artificial-intelligence-systems\n\nhttps://regulations.fru.d
 ev/regulations/us-eo-14365-ai-preemption
URL:https://regulations.fru.dev/regulations/us-eo-14365-ai-preemption
CATEGORIES:United States,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6861@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260731
DTEND;VALUE=DATE:20260801
SUMMARY:EU CSAM Interim Regulation: New interim regulation enters into forc
 e
DESCRIPTION:Published in the OJ on 2026-07-28\; enters into force on the th
 ird day.\n\nRegulation (EU) 2026/1881 on a temporary derogation from certa
 in provisions of Directive 2002/58/EC for combating online child sexual ab
 use (European Union)\n\nSource: https://eur-lex.europa.eu/eli/reg/2026/188
 1/oj/eng\n\nhttps://regulations.fru.dev/regulations/eu-csam-interim
URL:https://regulations.fru.dev/regulations/eu-csam-interim
CATEGORIES:European Union,privacy,children,online-safety
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-178@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260801
DTEND;VALUE=DATE:20260802
SUMMARY:California Delete Act / DROP: Data brokers must begin processing DR
 OP deletion requests
DESCRIPTION:Brokers must access DROP at least every 45 days\, process verif
 ied deletion requests within 45 days\, and treat unverified requests as op
 t-outs of sale/sharing.\n\nCalifornia Delete Act (SB 362\, 2023)\, Cal. Ci
 v. Code 1798.99.80 et seq.\, and DROP regulations (California)\n\nSource: 
 https://www.cppa.ca.gov/data_brokers/\n\nhttps://regulations.fru.dev/regul
 ations/us-ca-delete-act
URL:https://regulations.fru.dev/regulations/us-ca-delete-act
CATEGORIES:California,privacy,data-access
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-219@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260801
DTEND;VALUE=DATE:20260802
SUMMARY:Connecticut Data Privacy Act (CTDPA): Profiling impact assessments 
 apply
DESCRIPTION:Impact assessment requirements apply to profiling activities cr
 eated or generated on or after Aug 1\, 2026 (Conn. Gen. Stat. 42-522 as am
 ended).\n\nConnecticut Data Privacy Act (Public Act 22-15)\, Conn. Gen. St
 at. 42-515 et seq.\, as amended by Public Act 25-113 (SB 1295) and Public 
 Act 26-64 (SB 4) (Connecticut)\n\nSource: https://www.cga.ct.gov/2025/ACT/
 PA/PDF/2025PA-00113-R00SB-01295-PA.PDF\n\nhttps://regulations.fru.dev/regu
 lations/us-ct-ctdpa
URL:https://regulations.fru.dev/regulations/us-ct-ctdpa
CATEGORIES:Connecticut,privacy,children,ai,health
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-190@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260802
DTEND;VALUE=DATE:20260803
SUMMARY:California AI Transparency Act (SB 942): Covered provider duties ap
 ply
DESCRIPTION:Detection tool\, manifest and latent disclosures\, and license-
 revocation duties become operative.\n\nCalifornia AI Transparency Act (SB 
 942\, Stats. 2024\, ch. 291)\, as amended by AB 853 (Stats. 2025\, ch. 674
 ) (California)\n\nSource: https://leginfo.legislature.ca.gov/faces/billNav
 Client.xhtml?bill_id=202520260AB853\n\nhttps://regulations.fru.dev/regulat
 ions/us-ca-sb942
URL:https://regulations.fru.dev/regulations/us-ca-sb942
CATEGORIES:California,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-41@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260802
DTEND;VALUE=DATE:20260803
SUMMARY:EU AI Act: General application: transparency obligations\, GPAI fin
 es\, most other rules
DESCRIPTION:The AI Act's general date of application. Article 50 transparen
 cy obligations (chatbot disclosure\, deepfake labelling\, machine-readable
  marking of synthetic content) and Commission fines on GPAI providers (Art
  101) apply. Not deferred by the Omnibus.\n\nRegulation (EU) 2024/1689 lay
 ing down harmonised rules on artificial intelligence (Artificial Intellige
 nce Act)\, as amended by Regulation (EU) 2026/1744 (Digital Omnibus on AI)
  (European Union)\n\nSource: https://eur-lex.europa.eu/eli/reg/2024/1689/o
 j\n\nhttps://regulations.fru.dev/regulations/eu-ai-act
URL:https://regulations.fru.dev/regulations/eu-ai-act
CATEGORIES:European Union,ai,biometrics,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-7029@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260803
DTEND;VALUE=DATE:20260804
SUMMARY:New Zealand Biometric Processing Privacy Code: Grace period ends fo
 r existing biometric processing
DESCRIPTION:Agencies already using biometrics before the code started must 
 comply by this date.\n\nBiometric Processing Privacy Code 2025 (New Zealan
 d)\n\nSource: https://www.privacy.org.nz/privacy-principles/codes-of-pract
 ice/biometric-processing-privacy-code/\n\nhttps://regulations.fru.dev/regu
 lations/nz-biometric-code
URL:https://regulations.fru.dev/regulations/nz-biometric-code
CATEGORIES:New Zealand,biometrics,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6866@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260818
DTEND;VALUE=DATE:20260819
SUMMARY:EU e-Evidence Package: e-Evidence Regulation applies
DESCRIPTION:European Production and Preservation Orders become available.\n
 \nRegulation (EU) 2023/1543 on European Production Orders and European Pre
 servation Orders for electronic evidence in criminal proceedings\, and Dir
 ective (EU) 2023/1544 on legal representatives (European Union)\n\nSource:
  https://eur-lex.europa.eu/eli/reg/2023/1543/oj/eng\n\nhttps://regulations
 .fru.dev/regulations/eu-e-evidence
URL:https://regulations.fru.dev/regulations/eu-e-evidence
CATEGORIES:European Union,privacy,data-access
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6988@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260820
DTEND;VALUE=DATE:20260821
SUMMARY:China Data Security Risk Assessment Measures: Risk assessment measu
 res take effect
DESCRIPTION:Annual risk assessment and reporting duties for important data 
 handlers apply.\n\nMeasures for Network Data Security Risk Assessment (Chi
 na)\n\nSource: https://www.cac.gov.cn/2026-06/18/c_1783525609815499.htm\n\
 nhttps://regulations.fru.dev/regulations/cn-data-risk-assessment
URL:https://regulations.fru.dev/regulations/cn-data-risk-assessment
CATEGORIES:China,cybersecurity,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-79@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260831
DTEND;VALUE=DATE:20260901
SUMMARY:Digital Services Act: ChatGPT designated as VLOSE\; Reddit and Robl
 ox as VLOPs
DESCRIPTION:Commission designated ChatGPT as a very large online search eng
 ine and Reddit and Roblox as very large online platforms. They have four m
 onths (by January 2027) to meet VLOP/VLOSE obligations.\n\nRegulation (EU)
  2022/2065 on a Single Market for Digital Services (Digital Services Act) 
 (European Union)\n\nSource: https://digital-strategy.ec.europa.eu/en/news/
 commission-designates-chatgpt-reddit-roblox-under-digital-services-act\n\n
 https://regulations.fru.dev/regulations/eu-dsa
URL:https://regulations.fru.dev/regulations/eu-dsa
CATEGORIES:European Union,online-safety,children,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6989@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260901
DTEND;VALUE=DATE:20260902
SUMMARY:China Small PI Handler Simplified Measures: Simplified measures for
  small handlers take effect
DESCRIPTION:Small handlers may use simplified notice\, audit and assessment
  methods.\n\nProvisions on Simplified Personal Information Protection Meas
 ures for Small Personal Information Handlers (China)\n\nSource: https://ww
 w.cac.gov.cn/2026-07/24/c_1786638889704872.htm\n\nhttps://regulations.fru.
 dev/regulations/cn-small-pi-handlers
URL:https://regulations.fru.dev/regulations/cn-small-pi-handlers
CATEGORIES:China,privacy,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6904@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260909
DTEND;VALUE=DATE:20260910
SUMMARY:California AI Auditor Registry: Signed by Governor
DESCRIPTION:Chaptered as Chapter 178\, Statutes of 2026.\n\nArtificial Inte
 lligence: Auditors: Registration (AB 1405) (California)\n\nSource: https:/
 /leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202520260AB1
 405\n\nhttps://regulations.fru.dev/regulations/us-ca-ab1405
URL:https://regulations.fru.dev/regulations/us-ca-ab1405
CATEGORIES:California,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6964@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260910
DTEND;VALUE=DATE:20260911
SUMMARY:Peru AI Law and Regulation: Private sector: health\, education\, ju
 stice\, security\, finance
DESCRIPTION:High-risk and related obligations apply one year after publicat
 ion for these sectors.\n\nTentative: depends on a proposal not yet adopted
 .\n\nLey N° 31814\, Ley que promueve el uso de la inteligencia artificial
  en favor del desarrollo económico y social del país\, and its Regulatio
 n (Decreto Supremo N° 115-2025-PCM) (Peru)\n\nSource: https://www.gob.pe/
 institucion/pcm/normas-legales/7133522-115-2025-pcm\n\nhttps://regulations
 .fru.dev/regulations/pe-ai-law
URL:https://regulations.fru.dev/regulations/pe-ai-law
CATEGORIES:Peru,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-50@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260911
DTEND;VALUE=DATE:20260912
SUMMARY:Cyber Resilience Act: Vulnerability and incident reporting obligati
 ons apply
DESCRIPTION:Art 14: manufacturers must report actively exploited vulnerabil
 ities and severe incidents (24-hour early warning\, 72-hour notification) 
 via the single reporting platform. Also covers products placed on the mark
 et before 11 Dec 2027 (Art 69(3)).\n\nRegulation (EU) 2024/2847 on horizon
 tal cybersecurity requirements for products with digital elements (Cyber R
 esilience Act) (European Union)\n\nSource: https://eur-lex.europa.eu/eli/r
 eg/2024/2847/oj\n\nhttps://regulations.fru.dev/regulations/eu-cra
URL:https://regulations.fru.dev/regulations/eu-cra
CATEGORIES:European Union,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-126@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260911
DTEND;VALUE=DATE:20260912
SUMMARY:South Korea PIPA: 2026 PIPA amendments take effect
DESCRIPTION:10%-of-revenue fines\, CEO accountability\, and notice duties f
 or possible breaches apply.\n\nPersonal Information Protection Act (as ame
 nded by Act No. 21445\, 2026) (South Korea)\n\nSource: https://www.law.go.
 kr/법령/개인정보보호법\n\nhttps://regulations.fru.dev/regulations
 /kr-pipa
URL:https://regulations.fru.dev/regulations/kr-pipa
CATEGORIES:South Korea,privacy,breach-notification,biometrics,data-residenc
 y
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-7044@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260912
DTEND;VALUE=DATE:20260913
SUMMARY:Australia Social Media Minimum Age: Strengthened enforcement amendm
 ents commence
DESCRIPTION:The Online Safety Amendment (Strengthening Enforcement for the 
 Social Media Minimum Age) Act 2026 (No. 83\, 2026) commences. The maximum 
 civil penalty for platforms doubles from 30\,000 to 60\,000 penalty units\
 , and eSafety gains new information-gathering powers.\n\nOnline Safety Ame
 ndment (Social Media Minimum Age) Act 2024 (Australia)\n\nSource: https://
 www.legislation.gov.au/C2026A00083/asmade\n\nhttps://regulations.fru.dev/r
 egulations/au-social-media-min-age
URL:https://regulations.fru.dev/regulations/au-social-media-min-age
CATEGORIES:Australia,children,online-safety
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-59@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260912
DTEND;VALUE=DATE:20260913
SUMMARY:EU Data Act: Access-by-design for new connected products
DESCRIPTION:Art 3(1) design obligation (product data and related service da
 ta accessible to the user by default) applies to connected products and re
 lated services placed on the market after 12 Sep 2026.\n\nRegulation (EU) 
 2023/2854 on harmonised rules on fair access to and use of data (Data Act)
  (European Union)\n\nSource: https://eur-lex.europa.eu/eli/reg/2023/2854/o
 j\n\nhttps://regulations.fru.dev/regulations/eu-data-act
URL:https://regulations.fru.dev/regulations/eu-data-act
CATEGORIES:European Union,data-access,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-7022@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260916
DTEND;VALUE=DATE:20260917
SUMMARY:Thailand Cybersecurity Act: Website Security Standard B.E. 2568 enf
 orced
DESCRIPTION:The website security standard announced on 16 September 2025 be
 comes enforceable for government agencies\, regulators and CII organisatio
 ns.\n\nCybersecurity Act B.E. 2562 (2019) (Thailand)\n\nSource: https://ww
 w.ncsa.or.th/news/3a613ca26532320a0b000264\n\nhttps://regulations.fru.dev/
 regulations/th-cybersecurity-act
URL:https://regulations.fru.dev/regulations/th-cybersecurity-act
CATEGORIES:Thailand,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-152@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20260930
DTEND;VALUE=DATE:20261001
SUMMARY:Data (Use and Access) Act: ICO abolished\; Information Commission t
 akes over
DESCRIPTION:Sections 118-119 commence: office of Information Commissioner a
 bolished and functions transferred to the Information Commission (Commence
 ment No. 9 Regulations 2026).\n\nData (Use and Access) Act 2025 (United Ki
 ngdom)\n\nSource: https://www.legislation.gov.uk/uksi/2026/1015/regulation
 /2/made\n\nhttps://regulations.fru.dev/regulations/uk-duaa
URL:https://regulations.fru.dev/regulations/uk-duaa
CATEGORIES:United Kingdom,privacy,data-access,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-220@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20261001
DTEND;VALUE=DATE:20261002
SUMMARY:Connecticut Data Privacy Act (CTDPA): PA 26-64 (SB 4) amendments ta
 ke effect
DESCRIPTION:Prohibits controllers and third parties from selling precise ge
 olocation data and enacts data broker and other consumer protection provis
 ions.\n\nConnecticut Data Privacy Act (Public Act 22-15)\, Conn. Gen. Stat
 . 42-515 et seq.\, as amended by Public Act 25-113 (SB 1295) and Public Ac
 t 26-64 (SB 4) (Connecticut)\n\nSource: https://www.cga.ct.gov/2026/ACT/PA
 /PDF/2026PA-00064-R00SB-00004-PA.PDF\n\nhttps://regulations.fru.dev/regula
 tions/us-ct-ctdpa
URL:https://regulations.fru.dev/regulations/us-ct-ctdpa
CATEGORIES:Connecticut,privacy,children,ai,health
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6995@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20261001
DTEND;VALUE=DATE:20261002
SUMMARY:Japan Active Cyber Defense Act: Registration and incident reporting
  duties start
DESCRIPTION:Main provisions take effect\, including Chapter 2 duties for sp
 ecial social infrastructure operators to register important computers and 
 report specified intrusion incidents.\n\nAct on the Prevention of Damage f
 rom Unauthorized Acts against Important Computers (Act No. 42 of 2025) (Ja
 pan)\n\nSource: https://laws.e-gov.go.jp/api/2/law_revisions/507AC00000000
 42?response_format=json\n\nhttps://regulations.fru.dev/regulations/jp-acti
 ve-cyber-defense
URL:https://regulations.fru.dev/regulations/jp-active-cyber-defense
CATEGORIES:Japan,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-147@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20261026
DTEND;VALUE=DATE:20261027
SUMMARY:UK Cyber Security and Resilience Bill: Lords report stage scheduled
DESCRIPTION:House of Lords report stage scheduled (committee stage sat 1\, 
 3 and 7 Sept 2026).\n\nTentative: depends on a proposal not yet adopted.\n
 \nCyber Security and Resilience (Network and Information Systems) Bill (Un
 ited Kingdom)\n\nSource: https://bills.parliament.uk/bills/4035\n\nhttps:/
 /regulations.fru.dev/regulations/uk-csr-bill
URL:https://regulations.fru.dev/regulations/uk-csr-bill
CATEGORIES:United Kingdom,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-7033@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20261102
DTEND;VALUE=DATE:20261103
SUMMARY:Egypt PDPL: One-year compliance window ends
DESCRIPTION:Article 6 of the issuing law gives those covered one year from 
 the issue of the Executive Regulations to comply. The decree's signing dat
 e was not shown\, so this date is counted from publication and is an estim
 ate.\n\nTentative: depends on a proposal not yet adopted.\n\nLaw No. 151 o
 f 2020 on the Protection of Personal Data and its Executive Regulations (E
 gypt)\n\nSource: https://www.pdpc.gov.eg/assets/pdf-data/PDPL%20no.%20151%
 20of%202020%20(ar).pdf\n\nhttps://regulations.fru.dev/regulations/eg-pdpl
URL:https://regulations.fru.dev/regulations/eg-pdpl
CATEGORIES:Egypt,privacy,data-residency,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-196@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20261110
DTEND;VALUE=DATE:20261111
SUMMARY:CMMC 2.0: Phase 2: Level 2 C3PAO certification
DESCRIPTION:Phase 2 begins one calendar year after Phase 1\; applicable sol
 icitations require CMMC Level 2 third-party (C3PAO) certification (32 CFR 
 170.3(e)(2)).\n\nCybersecurity Maturity Model Certification (CMMC) Program
  (32 CFR Part 170) and DFARS acquisition rule (48 CFR Parts 204\, 212\, 21
 7\, 252) (United States (Federal))\n\nSource: https://www.federalregister.
 gov/documents/2024/10/15/2024-22905/cybersecurity-maturity-model-certifica
 tion-cmmc-program\n\nhttps://regulations.fru.dev/regulations/us-cmmc
URL:https://regulations.fru.dev/regulations/us-cmmc
CATEGORIES:United States (Federal),cybersecurity
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-117@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20261113
DTEND;VALUE=DATE:20261114
SUMMARY:India DPDP Act: Consent Manager registration rule in force (12 mont
 hs)
DESCRIPTION:Rule 4 (registration and obligations of Consent Managers) comes
  into force one year after publication.\n\nDigital Personal Data Protectio
 n Act\, 2023 and Digital Personal Data Protection Rules\, 2025 (India)\n\n
 Source: https://egazette.gov.in/WriteReadData/2025/267650.pdf\n\nhttps://r
 egulations.fru.dev/regulations/in-dpdp
URL:https://regulations.fru.dev/regulations/in-dpdp
CATEGORIES:India,privacy,children,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6868@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20261120
DTEND;VALUE=DATE:20261121
SUMMARY:EU Consumer Credit Directive 2 (CCD2): National rules apply
DESCRIPTION:Member States must apply the transposing measures from this dat
 e and the 2008 Directive is repealed.\n\nDirective (EU) 2023/2225 on credi
 t agreements for consumers (European Union)\n\nSource: https://eur-lex.eur
 opa.eu/eli/dir/2023/2225/oj/eng\n\nhttps://regulations.fru.dev/regulations
 /eu-ccd2
URL:https://regulations.fru.dev/regulations/eu-ccd2
CATEGORIES:European Union,financial,privacy,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6958@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20261130
DTEND;VALUE=DATE:20261201
SUMMARY:Peru PDPL and 2024 Regulation: DPO required: medium companies
DESCRIPTION:Companies with annual sales above 1\,700 UIT up to 2\,300 UIT.\
 n\nLey N° 29733\, Ley de Protección de Datos Personales\, and its Regula
 tion (Decreto Supremo N° 016-2024-JUS) (Peru)\n\nSource: https://www.gob.
 pe/institucion/smv/normas-legales/6426760-016-2024-jus\n\nhttps://regulati
 ons.fru.dev/regulations/pe-pdpl
URL:https://regulations.fru.dev/regulations/pe-pdpl
CATEGORIES:Peru,privacy,breach-notification,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-27@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20261201
DTEND;VALUE=DATE:20261202
SUMMARY:Chile Personal Data Protection Law (Ley 21.719): Law in force
DESCRIPTION:Main obligations apply and the Personal Data Protection Agency 
 begins supervision.\n\nLey Nº 21.719 que regula la protección y el trata
 miento de los datos personales y crea la Agencia de Protección de Datos P
 ersonales (Chile)\n\nSource: https://www.bcn.cl/leychile/navegar?idNorma=1
 209272\n\nhttps://regulations.fru.dev/regulations/cl-pdpl
URL:https://regulations.fru.dev/regulations/cl-pdpl
CATEGORIES:Chile,privacy,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-42@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20261202
DTEND;VALUE=DATE:20261203
SUMMARY:EU AI Act: New bans on sexual deepfakes and CSAM generation\; Art 5
 0(2) grace period ends
DESCRIPTION:New Art 5(1)(ba)/(bb) prohibitions on AI systems that generate 
 non-consensual intimate imagery of identifiable persons or child sexual ab
 use material apply. Generative AI systems placed on the market before 2 Au
 g 2026 must comply with the Art 50(2) marking duty by this date (new Art 1
 11(4)).\n\nRegulation (EU) 2024/1689 laying down harmonised rules on artif
 icial intelligence (Artificial Intelligence Act)\, as amended by Regulatio
 n (EU) 2026/1744 (Digital Omnibus on AI) (European Union)\n\nSource: https
 ://eur-lex.europa.eu/eli/reg/2026/1744/oj\n\nhttps://regulations.fru.dev/r
 egulations/eu-ai-act
URL:https://regulations.fru.dev/regulations/eu-ai-act
CATEGORIES:European Union,ai,biometrics,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6851@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20261202
DTEND;VALUE=DATE:20261203
SUMMARY:EU Platform Work Directive: Transposition deadline
DESCRIPTION:Member States must bring national laws into force to comply wit
 h the Directive (Article 29).\n\nDirective (EU) 2024/2831 on improving wor
 king conditions in platform work (European Union)\n\nSource: https://eur-l
 ex.europa.eu/eli/dir/2024/2831/oj/eng\n\nhttps://regulations.fru.dev/regul
 ations/eu-platform-work
URL:https://regulations.fru.dev/regulations/eu-platform-work
CATEGORIES:European Union,privacy,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-107@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20261209
DTEND;VALUE=DATE:20261210
SUMMARY:Product Liability Directive: Transposition deadline\; old PLD repea
 led
DESCRIPTION:Member States must transpose by 9 Dec 2026 (Art 22). Directive 
 85/374/EEC is repealed from that date but still applies to products placed
  on the market before it (Art 21).\n\nDirective (EU) 2024/2853 on liabilit
 y for defective products (new Product Liability Directive) (European Union
 )\n\nSource: https://eur-lex.europa.eu/eli/dir/2024/2853/oj\n\nhttps://reg
 ulations.fru.dev/regulations/eu-pld
URL:https://regulations.fru.dev/regulations/eu-pld
CATEGORIES:European Union,ai,cybersecurity
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20261210
DTEND;VALUE=DATE:20261211
SUMMARY:Australia Privacy Act: Children's Online Privacy Code must be regis
 tered
DESCRIPTION:OAIC must develop and register the Children's Online Privacy Co
 de within 24 months of Royal Assent.\n\nPrivacy Act 1988 (Cth)\, as amende
 d by the Privacy and Other Legislation Amendment Act 2024 (Australia)\n\nS
 ource: https://www.oaic.gov.au/privacy/privacy-registers/privacy-codes/chi
 ldrens-online-privacy-code\n\nhttps://regulations.fru.dev/regulations/au-p
 rivacy-act
URL:https://regulations.fru.dev/regulations/au-privacy-act
CATEGORIES:Australia,privacy,children,breach-notification,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-7@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20261210
DTEND;VALUE=DATE:20261211
SUMMARY:Australia Privacy Act: Automated decision-making transparency appli
 es
DESCRIPTION:Privacy policies must disclose the kinds of personal informatio
 n used in substantially automated decisions that significantly affect indi
 viduals (24 months after assent).\n\nPrivacy Act 1988 (Cth)\, as amended b
 y the Privacy and Other Legislation Amendment Act 2024 (Australia)\n\nSour
 ce: https://www.legislation.gov.au/C2024A00128/asmade\n\nhttps://regulatio
 ns.fru.dev/regulations/au-privacy-act
URL:https://regulations.fru.dev/regulations/au-privacy-act
CATEGORIES:Australia,privacy,children,breach-notification,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-88@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20261224
DTEND;VALUE=DATE:20261225
SUMMARY:eIDAS 2 / EU Digital Identity Wallet: Member States must provide EU
  Digital Identity Wallets
DESCRIPTION:Each Member State must provide at least one wallet within 24 mo
 nths of the entry into force of the implementing acts under Arts 5a(23) an
 d 5c(6) (Art 5a(1)).\n\nRegulation (EU) 2024/1183 amending Regulation (EU)
  No 910/2014 as regards establishing the European Digital Identity Framewo
 rk (eIDAS 2) (European Union)\n\nSource: https://eur-lex.europa.eu/eli/reg
 _impl/2024/2977/oj\n\nhttps://regulations.fru.dev/regulations/eu-eidas2
URL:https://regulations.fru.dev/regulations/eu-eidas2
CATEGORIES:European Union,privacy,data-access,biometrics
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-7017@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20261228
DTEND;VALUE=DATE:20261229
SUMMARY:Malaysia Online Safety Act: Online Safety Plan due to MCMC
DESCRIPTION:Licensed providers must prepare an Online Safety Plan and submi
 t it to MCMC within 180 days of 1 July 2026. Updates are due each year and
  after material changes.\n\nOnline Safety Act 2025 (Act 866) (Malaysia)\n\
 nSource: https://lom.agc.gov.my/ilims/upload/portal/akta/outputp/3582105/P
 UA%20244_2026.pdf\n\nhttps://regulations.fru.dev/regulations/my-online-saf
 ety-act
URL:https://regulations.fru.dev/regulations/my-online-safety-act
CATEGORIES:Malaysia,online-safety,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6930@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20261231
DTEND;VALUE=DATE:20270101
SUMMARY:Utah App Store Accountability Act: Private right of action begins
DESCRIPTION:Section 13-75-401 takes effect.\n\nUtah App Store Accountabilit
 y Act (SB 142) (Utah)\n\nSource: https://le.utah.gov/Session/2025/bills/en
 rolled/SB0142.pdf\n\nhttps://regulations.fru.dev/regulations/us-ut-app-sto
 re
URL:https://regulations.fru.dev/regulations/us-ut-app-store
CATEGORIES:Utah,children,privacy,online-safety
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6905@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20270101
DTEND;VALUE=DATE:20270102
SUMMARY:California AI Auditor Registry: Act takes effect
DESCRIPTION:Default effective date for 2026 regular-session statutes.\n\nAr
 tificial Intelligence: Auditors: Registration (AB 1405) (California)\n\nSo
 urce: https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id
 =202520260AB1405\n\nhttps://regulations.fru.dev/regulations/us-ca-ab1405
URL:https://regulations.fru.dev/regulations/us-ca-ab1405
CATEGORIES:California,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-191@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20270101
DTEND;VALUE=DATE:20270102
SUMMARY:California AI Transparency Act (SB 942): Large online platform and 
 hosting platform duties
DESCRIPTION:Large online platforms and GenAI hosting platforms must meet th
 e provenance duties added by AB 853.\n\nCalifornia AI Transparency Act (SB
  942\, Stats. 2024\, ch. 291)\, as amended by AB 853 (Stats. 2025\, ch. 67
 4) (California)\n\nSource: https://leginfo.legislature.ca.gov/faces/billNa
 vClient.xhtml?bill_id=202520260AB853\n\nhttps://regulations.fru.dev/regula
 tions/us-ca-sb942
URL:https://regulations.fru.dev/regulations/us-ca-sb942
CATEGORIES:California,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6900@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20270101
DTEND;VALUE=DATE:20270102
SUMMARY:California Digital Age Assurance Act: Age signal duties begin
DESCRIPTION:OS providers must offer the age interface at account setup and 
 developers must request signals.\n\nDigital Age Assurance Act (AB 1043) (C
 alifornia)\n\nSource: https://leginfo.legislature.ca.gov/faces/billNavClie
 nt.xhtml?bill_id=202520260AB1043\n\nhttps://regulations.fru.dev/regulation
 s/us-ca-ab1043
URL:https://regulations.fru.dev/regulations/us-ca-ab1043
CATEGORIES:California,children,privacy,online-safety
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-186@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20270101
DTEND;VALUE=DATE:20270102
SUMMARY:California SB 53 (TFAIA): First OES anonymized incident report and 
 CDT definition review
DESCRIPTION:OES begins publishing annual anonymized incident summaries and 
 the Department of Technology begins annual review of the act's definitions
 \; the CalCompute framework report is due to the Legislature.\n\nCaliforni
 a SB 53\, Transparency in Frontier Artificial Intelligence Act (Stats. 202
 5\, ch. 138) (California)\n\nSource: https://leginfo.legislature.ca.gov/fa
 ces/billNavClient.xhtml?bill_id=202520260SB53\n\nhttps://regulations.fru.d
 ev/regulations/us-ca-sb53
URL:https://regulations.fru.dev/regulations/us-ca-sb53
CATEGORIES:California,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6909@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20270101
DTEND;VALUE=DATE:20270102
SUMMARY:California SB 976 addictive feeds: Age assurance duty and AG rules
DESCRIPTION:Operators must reasonably determine users are not minors\; AG r
 egulations on age assurance and parental consent due.\n\nProtecting Our Ki
 ds from Social Media Addiction Act (SB 976) (California)\n\nSource: https:
 //leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202320240SB
 976\n\nhttps://regulations.fru.dev/regulations/us-ca-sb976
URL:https://regulations.fru.dev/regulations/us-ca-sb976
CATEGORIES:California,children,online-safety
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-169@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20270101
DTEND;VALUE=DATE:20270102
SUMMARY:CCPA / CPRA: ADMT requirements compliance date
DESCRIPTION:Businesses using ADMT for significant decisions must comply wit
 h Article 11 (pre-use notice\, opt-out\, access rights) by this date (11 C
 CR 7200(b)).\n\nCalifornia Consumer Privacy Act of 2018\, as amended by th
 e California Privacy Rights Act of 2020 (Cal. Civ. Code 1798.100 et seq.) 
 and CPPA regulations (Cal. Code Regs. tit. 11\, 7000 et seq.) (California)
 \n\nSource: https://cppa.ca.gov/regulations/pdf/ccpa_updates_cyber_risk_ad
 mt_appr_text.pdf\n\nhttps://regulations.fru.dev/regulations/us-ca-ccpa
URL:https://regulations.fru.dev/regulations/us-ca-ccpa
CATEGORIES:California,privacy,ai,cybersecurity,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-170@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20270101
DTEND;VALUE=DATE:20270102
SUMMARY:CCPA / CPRA: Browsers must support opt-out preference signal (AB 56
 6)
DESCRIPTION:Businesses that develop or maintain a browser must include cons
 umer-configurable functionality to send an opt-out preference signal (Civ.
  Code 1798.136\, operative Jan 1\, 2027).\n\nCalifornia Consumer Privacy A
 ct of 2018\, as amended by the California Privacy Rights Act of 2020 (Cal.
  Civ. Code 1798.100 et seq.) and CPPA regulations (Cal. Code Regs. tit. 11
 \, 7000 et seq.) (California)\n\nSource: https://leginfo.legislature.ca.go
 v/faces/billStatusClient.xhtml?bill_id=202520260AB566\n\nhttps://regulatio
 ns.fru.dev/regulations/us-ca-ccpa
URL:https://regulations.fru.dev/regulations/us-ca-ccpa
CATEGORIES:California,privacy,ai,cybersecurity,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-204@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20270101
DTEND;VALUE=DATE:20270102
SUMMARY:Colorado AI Act: ADMT obligations apply
DESCRIPTION:Developer documentation\, consumer notices\, post-adverse-outco
 me disclosure\, correction and human-review rights take effect.\n\nColorad
 o SB 24-205 (Consumer Protections for Artificial Intelligence)\, as delaye
 d by SB 25B-004 and repealed and reenacted by SB 26-189 (Automated Decisio
 n-Making Technology) (Colorado)\n\nSource: https://leg.colorado.gov/bills/
 sb26-189\n\nhttps://regulations.fru.dev/regulations/us-co-ai-act
URL:https://regulations.fru.dev/regulations/us-co-ai-act
CATEGORIES:Colorado,ai,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-205@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20270101
DTEND;VALUE=DATE:20270102
SUMMARY:Colorado AI Act: AG rules due
DESCRIPTION:Attorney General must adopt rules clarifying the post-adverse-o
 utcome disclosure requirements.\n\nColorado SB 24-205 (Consumer Protection
 s for Artificial Intelligence)\, as delayed by SB 25B-004 and repealed and
  reenacted by SB 26-189 (Automated Decision-Making Technology) (Colorado)\
 n\nSource: https://leg.colorado.gov/bills/sb26-189\n\nhttps://regulations.
 fru.dev/regulations/us-co-ai-act
URL:https://regulations.fru.dev/regulations/us-co-ai-act
CATEGORIES:Colorado,ai,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-221@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20270101
DTEND;VALUE=DATE:20270102
SUMMARY:Connecticut Data Privacy Act (CTDPA): Data broker registration requ
 ired
DESCRIPTION:Data brokers may not sell or license brokered personal data in 
 Connecticut unless registered with the Department of Consumer Protection (
 $2\,500 initial fee).\n\nConnecticut Data Privacy Act (Public Act 22-15)\,
  Conn. Gen. Stat. 42-515 et seq.\, as amended by Public Act 25-113 (SB 129
 5) and Public Act 26-64 (SB 4) (Connecticut)\n\nSource: https://www.cga.ct
 .gov/2026/ACT/PA/PDF/2026PA-00064-R00SB-00004-PA.PDF\n\nhttps://regulation
 s.fru.dev/regulations/us-ct-ctdpa
URL:https://regulations.fru.dev/regulations/us-ct-ctdpa
CATEGORIES:Connecticut,privacy,children,ai,health
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-226@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20270101
DTEND;VALUE=DATE:20270102
SUMMARY:Delaware Personal Data Privacy Act (DPDPA): Amended thresholds and 
 third-party duties take effect
DESCRIPTION:Applicability drops to 10\,000 consumers (or 5\,000 + 20% reven
 ue from sale) and new third-party duties (12D-107A) apply.\n\nDelaware Per
 sonal Data Privacy Act (HB 154)\, 6 Del. C. ch. 12D (Delaware)\n\nSource: 
 https://delcode.delaware.gov/title6/c012d/index.html\n\nhttps://regulation
 s.fru.dev/regulations/us-de-dpdpa
URL:https://regulations.fru.dev/regulations/us-de-dpdpa
CATEGORIES:Delaware,privacy,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-250@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20270101
DTEND;VALUE=DATE:20270102
SUMMARY:Louisiana Data Privacy Act: Louisiana Data Privacy Act takes effect
DESCRIPTION:Consumer rights and controller duties apply (Act 502\, Section 
 2)\; data protection assessment requirements apply to processing from this
  date.\n\nLouisiana Data Privacy Act (SB 386\, 2026 Regular Session\, Act 
 No. 502)\, La. R.S. 51:1780.1-1780.5 (Louisiana)\n\nSource: https://legis.
 la.gov/legis/ViewDocument.aspx?d=1480202\n\nhttps://regulations.fru.dev/re
 gulations/us-la-ldpa
URL:https://regulations.fru.dev/regulations/us-la-ldpa
CATEGORIES:Louisiana,privacy,biometrics
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-263@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20270101
DTEND;VALUE=DATE:20270102
SUMMARY:New Hampshire Privacy Act: Ban on selling personal data of children
  under 13 (HB 1460)
DESCRIPTION:HB 1460 (2026\, ch. 168) prohibits controllers from selling the
  personal data of a child under 13.\n\nNew Hampshire Privacy Act (SB 255\,
  2024)\, RSA chapter 507-H (New Hampshire)\n\nSource: https://gc.nh.gov/bi
 ll_status/billinfo.aspx?id=2443&inflect=2\n\nhttps://regulations.fru.dev/r
 egulations/us-nh-privacy
URL:https://regulations.fru.dev/regulations/us-nh-privacy
CATEGORIES:New Hampshire,privacy,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-280@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20270101
DTEND;VALUE=DATE:20270102
SUMMARY:NY RAISE Act: RAISE Act takes effect
DESCRIPTION:Transparency reports\, frontier AI frameworks\, incident report
 ing and DFS disclosure filings apply.\n\nNew York Responsible AI Safety an
 d Education (RAISE) Act (S6953-B/A6453-B of 2025)\, as amended by chapter 
 amendment S8828 of 2026 (New York)\n\nSource: https://www.nysenate.gov/leg
 islation/bills/2025/S8828\n\nhttps://regulations.fru.dev/regulations/us-ny
 -raise
URL:https://regulations.fru.dev/regulations/us-ny-raise
CATEGORIES:New York,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-282@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20270101
DTEND;VALUE=DATE:20270102
SUMMARY:Oklahoma OKCDPA: Oklahoma Consumer Data Privacy Act takes effect
DESCRIPTION:All OKCDPA obligations and consumer rights apply.\n\nOklahoma C
 onsumer Data Privacy Act (SB 546\, 2026) (Oklahoma)\n\nSource: https://www
 .okhouse.gov/posts/news-20260323_2\n\nhttps://regulations.fru.dev/regulati
 ons/us-ok-okcdpa
URL:https://regulations.fru.dev/regulations/us-ok-okcdpa
CATEGORIES:Oklahoma,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-7038@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20270101
DTEND;VALUE=DATE:20270102
SUMMARY:UAE Child Digital Safety Law: Compliance deadline under the Decree 
 by Law
DESCRIPTION:Article 18: those covered must comply within one year from entr
 y into force. The Cabinet may extend this.\n\nFederal Decree by Law No. 26
  of 2025 Regarding Child Digital Safety (United Arab Emirates)\n\nSource: 
 https://uaelegislation.gov.ae/en/legislations/3912\n\nhttps://regulations.
 fru.dev/regulations/ae-child-digital-safety
URL:https://regulations.fru.dev/regulations/ae-child-digital-safety
CATEGORIES:United Arab Emirates,children,online-safety,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-310@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20270101
DTEND;VALUE=DATE:20270102
SUMMARY:Utah UCPA: UCPA extends to motor vehicle manufacturers
DESCRIPTION:Motor vehicle manufacturers whose vehicles are sold or leased i
 n Utah and that collect personal data through vehicle data systems are cov
 ered regardless of the revenue and consumer thresholds (13-61-102\, as ame
 nded by Laws 2026\, ch. 193).\n\nUtah Consumer Privacy Act (SB 227\, 2022)
  (Utah)\n\nSource: https://le.utah.gov/xcode/Title13/Chapter61/13-61-S102.
 html\n\nhttps://regulations.fru.dev/regulations/us-ut-ucpa
URL:https://regulations.fru.dev/regulations/us-ut-ucpa
CATEGORIES:Utah,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6937@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20270101
DTEND;VALUE=DATE:20270102
SUMMARY:Vermont Kids Code: Takes effect
DESCRIPTION:9 V.S.A. sections 2449a to 2449j effective.\n\nVermont Age-Appr
 opriate Design Code (Act 63 of 2025\, S.69) (Vermont)\n\nSource: https://l
 egislature.vermont.gov/bill/status/2026/S.69\n\nhttps://regulations.fru.de
 v/regulations/us-vt-aadc
URL:https://regulations.fru.dev/regulations/us-vt-aadc
CATEGORIES:Vermont,children,privacy,online-safety
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-60@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20270112
DTEND;VALUE=DATE:20270113
SUMMARY:EU Data Act: Cloud switching charges abolished
DESCRIPTION:Providers of data processing services may no longer impose any 
 switching charges on customers (Art 29(1)).\n\nRegulation (EU) 2023/2854 o
 n harmonised rules on fair access to and use of data (Data Act) (European 
 Union)\n\nSource: https://eur-lex.europa.eu/eli/reg/2023/2854/oj\n\nhttps:
 //regulations.fru.dev/regulations/eu-data-act
URL:https://regulations.fru.dev/regulations/eu-data-act
CATEGORIES:European Union,data-access,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-114@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20270116
DTEND;VALUE=DATE:20270117
SUMMARY:Indonesia PDP Law: Implementing regulation GR 33/2026 takes effect
DESCRIPTION:Detailed PDP implementing rules (DPIA\, cross-border\, children
 's consent) apply\, 6 months after the 16 Jul 2026 enactment.\n\nLaw No. 2
 7 of 2022 on Personal Data Protection (Undang-Undang Pelindungan Data Prib
 adi) (Indonesia)\n\nSource: https://www.kk-advocates.com/news/read/indones
 ia-gr-pdp-personal-data-protection-compliance-regime-new-phase\n\nhttps://
 regulations.fru.dev/regulations/id-pdp
URL:https://regulations.fru.dev/regulations/id-pdp
CATEGORIES:Indonesia,privacy,breach-notification,data-residency,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6917@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20270125
DTEND;VALUE=DATE:20270126
SUMMARY:NY SAFE for Kids Act: Act and rules take effect
DESCRIPTION:180 days after State Register publication.\n\nStop Addictive Fe
 eds Exploitation (SAFE) for Kids Act (New York)\n\nSource: https://ag.ny.g
 ov/press-release/2026/attorney-general-james-and-governor-hochul-release-f
 inal-safe-kids-act-rules\n\nhttps://regulations.fru.dev/regulations/us-ny-
 safe-kids
URL:https://regulations.fru.dev/regulations/us-ny-safe-kids
CATEGORIES:New York,children,online-safety
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-179@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20270131
DTEND;VALUE=DATE:20270201
SUMMARY:California Delete Act / DROP: Annual data broker registration deadl
 ine
DESCRIPTION:Data brokers must renew registration with CalPrivacy by January
  31 following each year they meet the definition.\n\nCalifornia Delete Act
  (SB 362\, 2023)\, Cal. Civ. Code 1798.99.80 et seq.\, and DROP regulation
 s (California)\n\nSource: https://leginfo.legislature.ca.gov/faces/codes_d
 isplaySection.xhtml?lawCode=CIV&sectionNum=1798.99.82\n\nhttps://regulatio
 ns.fru.dev/regulations/us-ca-delete-act
URL:https://regulations.fru.dev/regulations/us-ca-delete-act
CATEGORIES:California,privacy,data-access
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6859@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20270205
DTEND;VALUE=DATE:20270206
SUMMARY:EU Cyber Solidarity Act: First Commission evaluation
DESCRIPTION:Commission evaluates the Regulation and reports to Parliament a
 nd Council\, then every 4 years (Article 25).\n\nRegulation (EU) 2025/38 l
 aying down measures to strengthen solidarity and capacities in the Union t
 o detect\, prepare for and respond to cyber threats and incidents (Cyber S
 olidarity Act) (European Union)\n\nSource: https://eur-lex.europa.eu/eli/r
 eg/2025/38/oj/eng\n\nhttps://regulations.fru.dev/regulations/eu-cyber-soli
 darity-act
URL:https://regulations.fru.dev/regulations/eu-cyber-solidarity-act
CATEGORIES:European Union,cybersecurity
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6972@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20270218
DTEND;VALUE=DATE:20270219
SUMMARY:Digital Services Act: DSA SME impact report
DESCRIPTION:Commission report under Article 91 on effects on SMEs.\n\nRegul
 ation (EU) 2022/2065 on a Single Market for Digital Services (Digital Serv
 ices Act) (European Union)\n\nSource: https://eur-lex.europa.eu/eli/reg/20
 22/2065/oj/eng\n\nhttps://regulations.fru.dev/regulations/eu-dsa
URL:https://regulations.fru.dev/regulations/eu-dsa
CATEGORIES:European Union,online-safety,children,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-322@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20270301
DTEND;VALUE=DATE:20270302
SUMMARY:Vietnam AI Law: Transition ends for existing AI systems (general)
DESCRIPTION:Existing AI systems in most sectors must comply (12-month trans
 ition).\n\nLaw on Artificial Intelligence (Law No. 134/2025/QH15) (Vietnam
 )\n\nSource: https://www.vilaf.com.vn/blog/vietnam-enacts-its-first-law-on
 -artificial-intelligence-key-regulatory-obligations-from-1-march-2026/\n\n
 https://regulations.fru.dev/regulations/vn-ai-law
URL:https://regulations.fru.dev/regulations/vn-ai-law
CATEGORIES:Vietnam,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-81@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20270326
DTEND;VALUE=DATE:20270327
SUMMARY:European Health Data Space (EHDS): EHDS general application date
DESCRIPTION:The regulation applies generally from 26 Mar 2027\, subject to 
 the phased exceptions below (final article).\n\nRegulation (EU) 2025/327 o
 n the European Health Data Space (European Union)\n\nSource: https://eur-l
 ex.europa.eu/eli/reg/2025/327/oj\n\nhttps://regulations.fru.dev/regulation
 s/eu-ehds
URL:https://regulations.fru.dev/regulations/eu-ehds
CATEGORIES:European Union,health,privacy,data-access
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6886@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20270401
DTEND;VALUE=DATE:20270402
SUMMARY:CFPB Open Banking Rule (Section 1033): Tier 2 compliance date (orig
 inal)
DESCRIPTION:Banks with $10B to $250B in assets and smaller nondepositories.
  Original date in 12 CFR 1033.121\; subject to the 90-day stay\, planned e
 xtension and injunction.\n\nTentative: depends on a proposal not yet adopt
 ed.\n\nRequired Rulemaking on Personal Financial Data Rights (12 CFR Part 
 1033) (United States)\n\nSource: https://www.federalregister.gov/documents
 /2024/11/18/2024-25079/required-rulemaking-on-personal-financial-data-righ
 ts\n\nhttps://regulations.fru.dev/regulations/us-cfpb-1033
URL:https://regulations.fru.dev/regulations/us-cfpb-1033
CATEGORIES:United States,data-access,financial,privacy,cybersecurity
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-254@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20270401
DTEND;VALUE=DATE:20270402
SUMMARY:Maryland Online Data Privacy Act (MODPA): Discretionary 60-day cure
  period ends
DESCRIPTION:The Division's discretionary notice-and-cure (at least 60 days)
  applies only to violations occurring on or before April 1\, 2027 (Com. La
 w 14-4614).\n\nMaryland Online Data Privacy Act of 2024 (SB 541 / HB 567)\
 , Md. Code\, Com. Law 14-4601 et seq. (Maryland)\n\nSource: https://mgaleg
 .maryland.gov/2024RS/Chapters_noln/CH_455_sb0541e.pdf\n\nhttps://regulatio
 ns.fru.dev/regulations/us-md-modpa
URL:https://regulations.fru.dev/regulations/us-md-modpa
CATEGORIES:Maryland,privacy,children,health,biometrics
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-97@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20270402
DTEND;VALUE=DATE:20270403
SUMMARY:GDPR: GDPR Procedural Regulation applies
DESCRIPTION:Harmonised rules for cross-border complaint admissibility\, rig
 hts to be heard and access to preliminary findings\, and investigation tim
 elines apply to DPAs from 2 April 2027 (Regulation (EU) 2025/2518\, final 
 article).\n\nRegulation (EU) 2016/679 (General Data Protection Regulation)
  (European Union)\n\nSource: https://eur-lex.europa.eu/eli/reg/2025/2518/o
 j\n\nhttps://regulations.fru.dev/regulations/eu-gdpr
URL:https://regulations.fru.dev/regulations/eu-gdpr
CATEGORIES:European Union,privacy,breach-notification,data-access,children,
 biometrics,health
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-104@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20270417
DTEND;VALUE=DATE:20270418
SUMMARY:NIS2: Next biennial entity notification
DESCRIPTION:Competent authorities notify the Commission and Cooperation Gro
 up of the number of essential and important entities\, repeated every two 
 years after 17 Apr 2025 (Art 3(5)).\n\nDirective (EU) 2022/2555 on measure
 s for a high common level of cybersecurity across the Union (NIS2 Directiv
 e) (European Union)\n\nSource: https://eur-lex.europa.eu/eli/dir/2022/2555
 /oj\n\nhttps://regulations.fru.dev/regulations/eu-nis2
URL:https://regulations.fru.dev/regulations/eu-nis2
CATEGORIES:European Union,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-161@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20270501
DTEND;VALUE=DATE:20270502
SUMMARY:Alabama Personal Data Protection Act (APDPA): APDPA takes effect
DESCRIPTION:Consumer rights and controller/processor obligations apply (HB 
 351 section 12).\n\nAlabama Personal Data Protection Act (HB 351\, 2026 Re
 gular Session) (Alabama)\n\nSource: https://alison.legislature.state.al.us
 /files/pdf/SearchableInstruments/2026RS/HB351-enr.pdf\n\nhttps://regulatio
 ns.fru.dev/regulations/us-al-apdpa
URL:https://regulations.fru.dev/regulations/us-al-apdpa
CATEGORIES:Alabama,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-118@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20270513
DTEND;VALUE=DATE:20270514
SUMMARY:India DPDP Act: Main data fiduciary obligations apply (18 months)
DESCRIPTION:Rules 3\, 5-16\, 22 and 23 (notice\, security safeguards\, brea
 ch notification\, retention\, children's consent\, SDF duties\, cross-bord
 er) come into force 18 months after publication.\n\nDigital Personal Data 
 Protection Act\, 2023 and Digital Personal Data Protection Rules\, 2025 (I
 ndia)\n\nSource: https://egazette.gov.in/WriteReadData/2025/267650.pdf\n\n
 https://regulations.fru.dev/regulations/in-dpdp
URL:https://regulations.fru.dev/regulations/in-dpdp
CATEGORIES:India,privacy,children,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-7039@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20270630
DTEND;VALUE=DATE:20270701
SUMMARY:UAE Child Digital Safety Law: Social media platforms' transition en
 ds
DESCRIPTION:Article 8 of Cabinet Resolution No. 106 of 2026 gives platforms
  12 months from entry into force to comply.\n\nFederal Decree by Law No. 2
 6 of 2025 Regarding Child Digital Safety (United Arab Emirates)\n\nSource:
  https://uaelegislation.gov.ae/en/legislations/4506\n\nhttps://regulations
 .fru.dev/regulations/ae-child-digital-safety
URL:https://regulations.fru.dev/regulations/ae-child-digital-safety
CATEGORIES:United Arab Emirates,children,online-safety,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6901@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20270701
DTEND;VALUE=DATE:20270702
SUMMARY:California Digital Age Assurance Act: Deadline for existing devices
  and apps
DESCRIPTION:OS providers must offer the age interface for accounts set up b
 efore 2027\, and developers must request signals for earlier installs.\n\n
 Digital Age Assurance Act (AB 1043) (California)\n\nSource: https://leginf
 o.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202520260AB1043\n\n
 https://regulations.fru.dev/regulations/us-ca-ab1043
URL:https://regulations.fru.dev/regulations/us-ca-ab1043
CATEGORIES:California,children,privacy,online-safety
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-183@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20270701
DTEND;VALUE=DATE:20270702
SUMMARY:California SB 243 (companion chatbots): First annual report to Offi
 ce of Suicide Prevention
DESCRIPTION:Operators begin annual reporting on crisis referrals and detect
 ion protocols.\n\nCalifornia SB 243\, Companion Chatbots (Stats. 2025\, ch
 . 677) (California)\n\nSource: https://leginfo.legislature.ca.gov/faces/bi
 llNavClient.xhtml?bill_id=202520260SB243\n\nhttps://regulations.fru.dev/re
 gulations/us-ca-sb243
URL:https://regulations.fru.dev/regulations/us-ca-sb243
CATEGORIES:California,ai,children,online-safety
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-127@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20270701
DTEND;VALUE=DATE:20270702
SUMMARY:South Korea PIPA: Mandatory ISMS-P certification
DESCRIPTION:ISMS-P certification becomes mandatory for private entities mee
 ting the statutory criteria.\n\nPersonal Information Protection Act (as am
 ended by Act No. 21445\, 2026) (South Korea)\n\nSource: https://www.law.go
 .kr/법령/개인정보보호법\n\nhttps://regulations.fru.dev/regulation
 s/kr-pipa
URL:https://regulations.fru.dev/regulations/kr-pipa
CATEGORIES:South Korea,privacy,breach-notification,biometrics,data-residenc
 y
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-307@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20270701
DTEND;VALUE=DATE:20270702
SUMMARY:Utah AI Policy Act: Scheduled repeal of Title 13\, Ch. 72
DESCRIPTION:SB 332 extends the AI Policy Act repeal date from May 1\, 2025 
 to July 1\, 2027.\n\nUtah Artificial Intelligence Policy Act (SB 149\, 202
 4)\, as amended by SB 226 and SB 332 (2025) (Utah)\n\nSource: https://le.u
 tah.gov/~2025/bills/static/SB0332.html\n\nhttps://regulations.fru.dev/regu
 lations/us-ut-aipa
URL:https://regulations.fru.dev/regulations/us-ut-aipa
CATEGORIES:Utah,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-7020@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20270701
DTEND;VALUE=DATE:20270702
SUMMARY:Vietnam Cybersecurity Law 2025: Transition ends for existing system
 s and products
DESCRIPTION:Information systems classified under the 2015 law\, and securit
 y products already in use\, must meet the new law's conditions within 12 m
 onths of its effective date.\n\nCybersecurity Law 2025 (Law No. 116/2025/Q
 H15) (Vietnam)\n\nSource: https://vanban.chinhphu.vn/?pageid=27160&docid=2
 16499\n\nhttps://regulations.fru.dev/regulations/vn-cybersecurity-law
URL:https://regulations.fru.dev/regulations/vn-cybersecurity-law
CATEGORIES:Vietnam,cybersecurity,data-residency,online-safety
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-251@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20270731
DTEND;VALUE=DATE:20270801
SUMMARY:Louisiana Data Privacy Act: 30-day cure period expires
DESCRIPTION:AG's obligation to give 30-day notice and allow cure before inv
 estigating applies only from Jan 1 through July 31\, 2027 (R.S. 51:1780.5(
 D)).\n\nLouisiana Data Privacy Act (SB 386\, 2026 Regular Session\, Act No
 . 502)\, La. R.S. 51:1780.1-1780.5 (Louisiana)\n\nSource: https://legis.la
 .gov/legis/ViewDocument.aspx?d=1480202\n\nhttps://regulations.fru.dev/regu
 lations/us-la-ldpa
URL:https://regulations.fru.dev/regulations/us-la-ldpa
CATEGORIES:Louisiana,privacy,biometrics
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-43@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20270802
DTEND;VALUE=DATE:20270803
SUMMARY:EU AI Act: Legacy GPAI models must comply\; national AI sandboxes o
 perational
DESCRIPTION:Providers of GPAI models placed on the market before 2 Aug 2025
  must comply (Art 111(3)). Each Member State must have at least one nation
 al AI regulatory sandbox operational (Art 57(1) as amended by the Omnibus)
 .\n\nRegulation (EU) 2024/1689 laying down harmonised rules on artificial 
 intelligence (Artificial Intelligence Act)\, as amended by Regulation (EU)
  2026/1744 (Digital Omnibus on AI) (European Union)\n\nSource: https://eur
 -lex.europa.eu/eli/reg/2024/1689/oj\n\nhttps://regulations.fru.dev/regulat
 ions/eu-ai-act
URL:https://regulations.fru.dev/regulations/eu-ai-act
CATEGORIES:European Union,ai,biometrics,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-323@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20270901
DTEND;VALUE=DATE:20270902
SUMMARY:Vietnam AI Law: Transition ends for existing AI systems in health\,
  education and finance
DESCRIPTION:Existing AI systems in healthcare\, education and finance must 
 comply (18-month transition).\n\nLaw on Artificial Intelligence (Law No. 1
 34/2025/QH15) (Vietnam)\n\nSource: https://www.vilaf.com.vn/blog/vietnam-e
 nacts-its-first-law-on-artificial-intelligence-key-regulatory-obligations-
 from-1-march-2026/\n\nhttps://regulations.fru.dev/regulations/vn-ai-law
URL:https://regulations.fru.dev/regulations/vn-ai-law
CATEGORIES:Vietnam,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6965@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20270910
DTEND;VALUE=DATE:20270911
SUMMARY:Peru AI Law and Regulation: Private sector: transport\, commerce\, 
 labour
DESCRIPTION:Obligations apply two years after publication.\n\nTentative: de
 pends on a proposal not yet adopted.\n\nLey N° 31814\, Ley que promueve e
 l uso de la inteligencia artificial en favor del desarrollo económico y s
 ocial del país\, and its Regulation (Decreto Supremo N° 115-2025-PCM) (P
 eru)\n\nSource: https://www.gob.pe/institucion/pcm/normas-legales/7133522-
 115-2025-pcm\n\nhttps://regulations.fru.dev/regulations/pe-ai-law
URL:https://regulations.fru.dev/regulations/pe-ai-law
CATEGORIES:Peru,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-61@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20270912
DTEND;VALUE=DATE:20270913
SUMMARY:EU Data Act: Unfair-terms rules extend to older long-term contracts
DESCRIPTION:Chapter IV (unfair contractual terms) applies to contracts conc
 luded on or before 12 Sep 2025 that are of indefinite duration or expire a
 t least 10 years from 11 Jan 2024 (Art 50).\n\nRegulation (EU) 2023/2854 o
 n harmonised rules on fair access to and use of data (Data Act) (European 
 Union)\n\nSource: https://eur-lex.europa.eu/eli/reg/2023/2854/oj\n\nhttps:
 //regulations.fru.dev/regulations/eu-data-act
URL:https://regulations.fru.dev/regulations/eu-data-act
CATEGORIES:European Union,data-access,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-105@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20271017
DTEND;VALUE=DATE:20271018
SUMMARY:NIS2: Commission review of NIS2
DESCRIPTION:Commission must review the functioning of NIS2 and report to Pa
 rliament and Council\, then every 36 months (Art 40).\n\nDirective (EU) 20
 22/2555 on measures for a high common level of cybersecurity across the Un
 ion (NIS2 Directive) (European Union)\n\nSource: https://eur-lex.europa.eu
 /eli/dir/2022/2555/oj\n\nhttps://regulations.fru.dev/regulations/eu-nis2
URL:https://regulations.fru.dev/regulations/eu-nis2
CATEGORIES:European Union,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-197@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20271110
DTEND;VALUE=DATE:20271111
SUMMARY:CMMC 2.0: Phase 3: Level 3 certification
DESCRIPTION:Phase 3 begins one year after Phase 2\; Level 3 (DIBCAC) requir
 ements added to applicable solicitations (32 CFR 170.3(e)(3)).\n\nCybersec
 urity Maturity Model Certification (CMMC) Program (32 CFR Part 170) and DF
 ARS acquisition rule (48 CFR Parts 204\, 212\, 217\, 252) (United States (
 Federal))\n\nSource: https://www.federalregister.gov/documents/2024/10/15/
 2024-22905/cybersecurity-maturity-model-certification-cmmc-program\n\nhttp
 s://regulations.fru.dev/regulations/us-cmmc
URL:https://regulations.fru.dev/regulations/us-cmmc
CATEGORIES:United States (Federal),cybersecurity
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6996@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20271122
DTEND;VALUE=DATE:20271123
SUMMARY:Japan Active Cyber Defense Act: Communications data measures in for
 ce (latest date)
DESCRIPTION:Chapters 3 to 7 on agreements with operators and collection of 
 communications data take effect by Cabinet Order within 2 years and 6 mont
 hs of promulgation. e-Gov lists 22 Nov 2027 as the outer limit\, not a fix
 ed date.\n\nTentative: depends on a proposal not yet adopted.\n\nAct on th
 e Prevention of Damage from Unauthorized Acts against Important Computers 
 (Act No. 42 of 2025) (Japan)\n\nSource: https://laws.e-gov.go.jp/api/2/law
 _revisions/507AC0000000042?response_format=json\n\nhttps://regulations.fru
 .dev/regulations/jp-active-cyber-defense
URL:https://regulations.fru.dev/regulations/jp-active-cyber-defense
CATEGORIES:Japan,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6959@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20271130
DTEND;VALUE=DATE:20271201
SUMMARY:Peru PDPL and 2024 Regulation: DPO required: small companies
DESCRIPTION:Companies with annual sales above 150 UIT up to 1\,700 UIT.\n\n
 Ley N° 29733\, Ley de Protección de Datos Personales\, and its Regulatio
 n (Decreto Supremo N° 016-2024-JUS) (Peru)\n\nSource: https://www.gob.pe/
 institucion/smv/normas-legales/6426760-016-2024-jus\n\nhttps://regulations
 .fru.dev/regulations/pe-pdpl
URL:https://regulations.fru.dev/regulations/pe-pdpl
CATEGORIES:Peru,privacy,breach-notification,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-28@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20271201
DTEND;VALUE=DATE:20271202
SUMMARY:Chile Personal Data Protection Law (Ley 21.719): Proposed postponem
 ent of entry into force
DESCRIPTION:Government bill Boletin 18623-07 (filed 1 Sep 2026\, 'suma' urg
 ency) would replace the 24-month vacatio legis in transitional Art 1 with 
 a fixed date of 1 Dec 2027\; in first committee stage in the Senate\, not 
 law.\n\nTentative: depends on a proposal not yet adopted.\n\nLey Nº 21.71
 9 que regula la protección y el tratamiento de los datos personales y cre
 a la Agencia de Protección de Datos Personales (Chile)\n\nSource: https:/
 /tramitacion.senado.cl/appsenado/templates/tramitacion/index.php?boletin_i
 ni=18623-07\n\nhttps://regulations.fru.dev/regulations/cl-pdpl
URL:https://regulations.fru.dev/regulations/cl-pdpl
CATEGORIES:Chile,privacy,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-44@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20271202
DTEND;VALUE=DATE:20271203
SUMMARY:EU AI Act: High-risk obligations apply to Annex III systems
DESCRIPTION:Chapter III Sections 1-3 (high-risk requirements and provider/d
 eployer obligations) apply to AI systems classified high-risk under Art 6(
 2) and Annex III (employment\, credit scoring\, education\, biometrics\, e
 ssential services and similar). Deferred from 2 Aug 2026 by Regulation (EU
 ) 2026/1744.\n\nRegulation (EU) 2024/1689 laying down harmonised rules on 
 artificial intelligence (Artificial Intelligence Act)\, as amended by Regu
 lation (EU) 2026/1744 (Digital Omnibus on AI) (European Union)\n\nSource: 
 https://eur-lex.europa.eu/eli/reg/2026/1744/oj\n\nhttps://regulations.fru.
 dev/regulations/eu-ai-act
URL:https://regulations.fru.dev/regulations/eu-ai-act
CATEGORIES:European Union,ai,biometrics,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-51@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20271211
DTEND;VALUE=DATE:20271212
SUMMARY:Cyber Resilience Act: CRA fully applies
DESCRIPTION:All remaining obligations\, including essential cybersecurity r
 equirements\, conformity assessment and CE marking\, apply (Art 71(2)). Pr
 oducts placed on the market earlier are covered only if substantially modi
 fied (Art 69(2)).\n\nRegulation (EU) 2024/2847 on horizontal cybersecurity
  requirements for products with digital elements (Cyber Resilience Act) (E
 uropean Union)\n\nSource: https://eur-lex.europa.eu/eli/reg/2024/2847/oj\n
 \nhttps://regulations.fru.dev/regulations/eu-cra
URL:https://regulations.fru.dev/regulations/eu-cra
CATEGORIES:European Union,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-89@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20271224
DTEND;VALUE=DATE:20271225
SUMMARY:eIDAS 2 / EU Digital Identity Wallet: Private relying parties must 
 accept wallets
DESCRIPTION:Private relying parties required by law or contract to use stro
 ng user authentication must accept wallets on user request within 36 month
 s of the implementing acts' entry into force (Art 5f(2)).\n\nRegulation (E
 U) 2024/1183 amending Regulation (EU) No 910/2014 as regards establishing 
 the European Digital Identity Framework (eIDAS 2) (European Union)\n\nSour
 ce: https://eur-lex.europa.eu/eli/reg_impl/2024/2977/oj\n\nhttps://regulat
 ions.fru.dev/regulations/eu-eidas2
URL:https://regulations.fru.dev/regulations/eu-eidas2
CATEGORIES:European Union,privacy,data-access,biometrics
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-171@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20271231
DTEND;VALUE=DATE:20280101
SUMMARY:CCPA / CPRA: Risk assessments for pre-existing processing due
DESCRIPTION:Risk assessments must be completed and documented for high-risk
  processing that began before Jan 1\, 2026 and continues after (11 CCR 715
 5(b)).\n\nCalifornia Consumer Privacy Act of 2018\, as amended by the Cali
 fornia Privacy Rights Act of 2020 (Cal. Civ. Code 1798.100 et seq.) and CP
 PA regulations (Cal. Code Regs. tit. 11\, 7000 et seq.) (California)\n\nSo
 urce: https://cppa.ca.gov/regulations/pdf/ccpa_updates_cyber_risk_admt_app
 r_text.pdf\n\nhttps://regulations.fru.dev/regulations/us-ca-ccpa
URL:https://regulations.fru.dev/regulations/us-ca-ccpa
CATEGORIES:California,privacy,ai,cybersecurity,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-192@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20280101
DTEND;VALUE=DATE:20280102
SUMMARY:California AI Transparency Act (SB 942): Capture device manufacture
 r duties
DESCRIPTION:Capture device manufacturer provenance requirements become oper
 ative.\n\nCalifornia AI Transparency Act (SB 942\, Stats. 2024\, ch. 291)\
 , as amended by AB 853 (Stats. 2025\, ch. 674) (California)\n\nSource: htt
 ps://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=20252026
 0AB853\n\nhttps://regulations.fru.dev/regulations/us-ca-sb942
URL:https://regulations.fru.dev/regulations/us-ca-sb942
CATEGORIES:California,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-180@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20280101
DTEND;VALUE=DATE:20280102
SUMMARY:California Delete Act / DROP: Independent third-party audits begin
DESCRIPTION:Beginning Jan 1\, 2028 and every 3 years thereafter\, data brok
 ers must undergo an independent audit of Delete Act compliance.\n\nCalifor
 nia Delete Act (SB 362\, 2023)\, Cal. Civ. Code 1798.99.80 et seq.\, and D
 ROP regulations (California)\n\nSource: https://www.cppa.ca.gov/data_broke
 rs/\n\nhttps://regulations.fru.dev/regulations/us-ca-delete-act
URL:https://regulations.fru.dev/regulations/us-ca-delete-act
CATEGORIES:California,privacy,data-access
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-315@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20280101
DTEND;VALUE=DATE:20280102
SUMMARY:Vermont VDPOSA: Vermont Data Privacy and Online Surveillance Act ta
 kes effect
DESCRIPTION:All obligations under Act 145 apply (sec. 4).\n\nVermont Data P
 rivacy and Online Surveillance Act (S.71\, Act 145 of 2026) (Vermont)\n\nS
 ource: https://legislature.vermont.gov/Documents/2026/Docs/ACTS/ACT145/ACT
 145%20As%20Enacted.pdf\n\nhttps://regulations.fru.dev/regulations/us-vt-vd
 posa
URL:https://regulations.fru.dev/regulations/us-vt-vdposa
CATEGORIES:Vermont,privacy,health,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6998@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20280114
DTEND;VALUE=DATE:20280115
SUMMARY:Taiwan AI Basic Act: Agencies must align laws with the Act
DESCRIPTION:Government agencies must finish amending or adopting laws and a
 dministrative measures within 2 years of entry into force (art. 18). Date 
 is computed from the statute.\n\nTentative: depends on a proposal not yet 
 adopted.\n\nArtificial Intelligence Basic Act (Taiwan)\n\nSource: https://
 law.moj.gov.tw/LawClass/LawAll.aspx?pcode=H0160093\n\nhttps://regulations.
 fru.dev/regulations/tw-ai-basic-act
URL:https://regulations.fru.dev/regulations/tw-ai-basic-act
CATEGORIES:Taiwan,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6862@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20280201
DTEND;VALUE=DATE:20280202
SUMMARY:EU CSAM Interim Regulation: Commission implementation report
DESCRIPTION:Commission report on implementation\, including proportionality
  and error rates (Article 9).\n\nRegulation (EU) 2026/1881 on a temporary 
 derogation from certain provisions of Directive 2002/58/EC for combating o
 nline child sexual abuse (European Union)\n\nSource: https://eur-lex.europ
 a.eu/eli/reg/2026/1881/oj/eng\n\nhttps://regulations.fru.dev/regulations/e
 u-csam-interim
URL:https://regulations.fru.dev/regulations/eu-csam-interim
CATEGORIES:European Union,privacy,children,online-safety
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-172@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20280401
DTEND;VALUE=DATE:20280402
SUMMARY:CCPA / CPRA: First risk assessment submission to CPPA
DESCRIPTION:Businesses must submit required risk assessment information and
  attestation for assessments conducted in 2026 and 2027 (11 CCR 7157(a)(1)
 )\; annually by April 1 thereafter.\n\nCalifornia Consumer Privacy Act of 
 2018\, as amended by the California Privacy Rights Act of 2020 (Cal. Civ. 
 Code 1798.100 et seq.) and CPPA regulations (Cal. Code Regs. tit. 11\, 700
 0 et seq.) (California)\n\nSource: https://cppa.ca.gov/regulations/pdf/ccp
 a_updates_cyber_risk_admt_appr_text.pdf\n\nhttps://regulations.fru.dev/reg
 ulations/us-ca-ccpa
URL:https://regulations.fru.dev/regulations/us-ca-ccpa
CATEGORIES:California,privacy,ai,cybersecurity,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-173@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20280401
DTEND;VALUE=DATE:20280402
SUMMARY:CCPA / CPRA: Cybersecurity audit due: revenue over $100M
DESCRIPTION:First cybersecurity audit report (covering Jan 1\, 2027 - Jan 1
 \, 2028) and certification due for businesses with 2026 annual gross reven
 ue over $100M (11 CCR 7121(a)(1)).\n\nCalifornia Consumer Privacy Act of 2
 018\, as amended by the California Privacy Rights Act of 2020 (Cal. Civ. C
 ode 1798.100 et seq.) and CPPA regulations (Cal. Code Regs. tit. 11\, 7000
  et seq.) (California)\n\nSource: https://cppa.ca.gov/regulations/pdf/ccpa
 _updates_cyber_risk_admt_appr_text.pdf\n\nhttps://regulations.fru.dev/regu
 lations/us-ca-ccpa
URL:https://regulations.fru.dev/regulations/us-ca-ccpa
CATEGORIES:California,privacy,ai,cybersecurity,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6887@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20280401
DTEND;VALUE=DATE:20280402
SUMMARY:CFPB Open Banking Rule (Section 1033): Tier 3 compliance date (orig
 inal)
DESCRIPTION:Banks with $3B to $10B in assets. Original date\; subject to st
 ay\, extension and injunction.\n\nTentative: depends on a proposal not yet
  adopted.\n\nRequired Rulemaking on Personal Financial Data Rights (12 CFR
  Part 1033) (United States)\n\nSource: https://www.federalregister.gov/doc
 uments/2024/11/18/2024-25079/required-rulemaking-on-personal-financial-dat
 a-rights\n\nhttps://regulations.fru.dev/regulations/us-cfpb-1033
URL:https://regulations.fru.dev/regulations/us-cfpb-1033
CATEGORIES:United States,data-access,financial,privacy,cybersecurity
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6863@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20280403
DTEND;VALUE=DATE:20280404
SUMMARY:EU CSAM Interim Regulation: Interim derogation expires
DESCRIPTION:The Regulation applies until this date.\n\nRegulation (EU) 2026
 /1881 on a temporary derogation from certain provisions of Directive 2002/
 58/EC for combating online child sexual abuse (European Union)\n\nSource: 
 https://eur-lex.europa.eu/eli/reg/2026/1881/oj/eng\n\nhttps://regulations.
 fru.dev/regulations/eu-csam-interim
URL:https://regulations.fru.dev/regulations/eu-csam-interim
CATEGORIES:European Union,privacy,children,online-safety
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-52@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20280611
DTEND;VALUE=DATE:20280612
SUMMARY:Cyber Resilience Act: Legacy type-examination certificates expire
DESCRIPTION:EU type-examination certificates and approval decisions on cybe
 rsecurity requirements under other harmonisation legislation remain valid 
 until this date unless they expire earlier (Art 69(1)).\n\nRegulation (EU)
  2024/2847 on horizontal cybersecurity requirements for products with digi
 tal elements (Cyber Resilience Act) (European Union)\n\nSource: https://eu
 r-lex.europa.eu/eli/reg/2024/2847/oj\n\nhttps://regulations.fru.dev/regula
 tions/eu-cra
URL:https://regulations.fru.dev/regulations/eu-cra
CATEGORIES:European Union,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-45@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20280802
DTEND;VALUE=DATE:20280803
SUMMARY:EU AI Act: High-risk obligations apply to Annex I product-embedded 
 systems
DESCRIPTION:Chapter III Sections 1-3 apply to AI systems classified high-ri
 sk under Art 6(1) and Annex I (safety components of products covered by EU
  harmonisation legislation). Deferred from 2 Aug 2027 by Regulation (EU) 2
 026/1744.\n\nRegulation (EU) 2024/1689 laying down harmonised rules on art
 ificial intelligence (Artificial Intelligence Act)\, as amended by Regulat
 ion (EU) 2026/1744 (Digital Omnibus on AI) (European Union)\n\nSource: htt
 ps://eur-lex.europa.eu/eli/reg/2026/1744/oj\n\nhttps://regulations.fru.dev
 /regulations/eu-ai-act
URL:https://regulations.fru.dev/regulations/eu-ai-act
CATEGORIES:European Union,ai,biometrics,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6966@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20280910
DTEND;VALUE=DATE:20280911
SUMMARY:Peru AI Law and Regulation: Private sector: production\, agricultur
 e\, energy\, mining
DESCRIPTION:Obligations apply three years after publication.\n\nTentative: 
 depends on a proposal not yet adopted.\n\nLey N° 31814\, Ley que promueve
  el uso de la inteligencia artificial en favor del desarrollo económico y
  social del país\, and its Regulation (Decreto Supremo N° 115-2025-PCM) 
 (Peru)\n\nSource: https://www.gob.pe/institucion/pcm/normas-legales/713352
 2-115-2025-pcm\n\nhttps://regulations.fru.dev/regulations/pe-ai-law
URL:https://regulations.fru.dev/regulations/pe-ai-law
CATEGORIES:Peru,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-53@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20280911
DTEND;VALUE=DATE:20280912
SUMMARY:Cyber Resilience Act: Report on single reporting platform
DESCRIPTION:Commission report assessing the single reporting platform's eff
 ectiveness (Art 70(2)).\n\nRegulation (EU) 2024/2847 on horizontal cyberse
 curity requirements for products with digital elements (Cyber Resilience A
 ct) (European Union)\n\nSource: https://eur-lex.europa.eu/eli/reg/2024/284
 7/oj\n\nhttps://regulations.fru.dev/regulations/eu-cra
URL:https://regulations.fru.dev/regulations/eu-cra
CATEGORIES:European Union,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-62@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20280912
DTEND;VALUE=DATE:20280913
SUMMARY:EU Data Act: Commission evaluation
DESCRIPTION:Commission evaluation report due\, including the impact of clou
 d switching rules (Arts 23-31) (Art 49(2)).\n\nRegulation (EU) 2023/2854 o
 n harmonised rules on fair access to and use of data (Data Act) (European 
 Union)\n\nSource: https://eur-lex.europa.eu/eli/reg/2023/2854/oj\n\nhttps:
 //regulations.fru.dev/regulations/eu-data-act
URL:https://regulations.fru.dev/regulations/eu-data-act
CATEGORIES:European Union,data-access,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-222@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20281001
DTEND;VALUE=DATE:20281002
SUMMARY:Connecticut Data Privacy Act (CTDPA): Data brokers must process sta
 te deletion mechanism requests
DESCRIPTION:Registered data brokers must access the DCP accessible deletion
  mechanism at least every 45 days and process deletion requests.\n\nConnec
 ticut Data Privacy Act (Public Act 22-15)\, Conn. Gen. Stat. 42-515 et seq
 .\, as amended by Public Act 25-113 (SB 1295) and Public Act 26-64 (SB 4) 
 (Connecticut)\n\nSource: https://www.cga.ct.gov/2026/ACT/PA/PDF/2026PA-000
 64-R00SB-00004-PA.PDF\n\nhttps://regulations.fru.dev/regulations/us-ct-ctd
 pa
URL:https://regulations.fru.dev/regulations/us-ct-ctdpa
CATEGORIES:Connecticut,privacy,children,ai,health
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-198@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20281110
DTEND;VALUE=DATE:20281111
SUMMARY:CMMC 2.0: Phase 4: full implementation
DESCRIPTION:CMMC requirements included in all applicable DoD solicitations 
 and contracts\, including option periods (32 CFR 170.3(e)(4)).\n\nCybersec
 urity Maturity Model Certification (CMMC) Program (32 CFR Part 170) and DF
 ARS acquisition rule (48 CFR Parts 204\, 212\, 217\, 252) (United States (
 Federal))\n\nSource: https://www.federalregister.gov/documents/2024/10/15/
 2024-22905/cybersecurity-maturity-model-certification-cmmc-program\n\nhttp
 s://regulations.fru.dev/regulations/us-cmmc
URL:https://regulations.fru.dev/regulations/us-cmmc
CATEGORIES:United States (Federal),cybersecurity
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6960@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20281130
DTEND;VALUE=DATE:20281201
SUMMARY:Peru PDPL and 2024 Regulation: DPO required: micro companies
DESCRIPTION:Micro companies with annual sales up to 150 UIT.\n\nLey N° 297
 33\, Ley de Protección de Datos Personales\, and its Regulation (Decreto 
 Supremo N° 016-2024-JUS) (Peru)\n\nSource: https://www.gob.pe/institucion
 /smv/normas-legales/6426760-016-2024-jus\n\nhttps://regulations.fru.dev/re
 gulations/pe-pdpl
URL:https://regulations.fru.dev/regulations/pe-pdpl
CATEGORIES:Peru,privacy,breach-notification,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6906@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20290101
DTEND;VALUE=DATE:20290102
SUMMARY:California AI Auditor Registry: Registry opens and registration req
 uired
DESCRIPTION:Agency must launch the AI Auditor Registry\; unregistered perso
 ns may not offer or conduct covered AI audits.\n\nArtificial Intelligence:
  Auditors: Registration (AB 1405) (California)\n\nSource: https://leginfo.
 legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202520260AB1405\n\nht
 tps://regulations.fru.dev/regulations/us-ca-ab1405
URL:https://regulations.fru.dev/regulations/us-ca-ab1405
CATEGORIES:California,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-82@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20290326
DTEND;VALUE=DATE:20290327
SUMMARY:European Health Data Space (EHDS): Primary use for first data categ
 ories\; secondary use framework applies
DESCRIPTION:Patient rights and EHR rules apply to patient summaries\, ePres
 criptions and eDispensations (Art 14(1)(a)-(c)). Chapter IV secondary-use 
 rules (data permits\, Health Data Access Bodies) apply.\n\nRegulation (EU)
  2025/327 on the European Health Data Space (European Union)\n\nSource: ht
 tps://eur-lex.europa.eu/eli/reg/2025/327/oj\n\nhttps://regulations.fru.dev
 /regulations/eu-ehds
URL:https://regulations.fru.dev/regulations/eu-ehds
CATEGORIES:European Union,health,privacy,data-access
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-174@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20290401
DTEND;VALUE=DATE:20290402
SUMMARY:CCPA / CPRA: Cybersecurity audit due: revenue $50M-$100M
DESCRIPTION:First cybersecurity audit report (covering 2028) due for busine
 sses with 2027 annual gross revenue between $50M and $100M (11 CCR 7121(a)
 (2)).\n\nCalifornia Consumer Privacy Act of 2018\, as amended by the Calif
 ornia Privacy Rights Act of 2020 (Cal. Civ. Code 1798.100 et seq.) and CPP
 A regulations (Cal. Code Regs. tit. 11\, 7000 et seq.) (California)\n\nSou
 rce: https://cppa.ca.gov/regulations/pdf/ccpa_updates_cyber_risk_admt_appr
 _text.pdf\n\nhttps://regulations.fru.dev/regulations/us-ca-ccpa
URL:https://regulations.fru.dev/regulations/us-ca-ccpa
CATEGORIES:California,privacy,ai,cybersecurity,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6888@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20290401
DTEND;VALUE=DATE:20290402
SUMMARY:CFPB Open Banking Rule (Section 1033): Tier 4 compliance date (orig
 inal)
DESCRIPTION:Banks with $1.5B to $3B in assets. Original date\; subject to s
 tay\, extension and injunction.\n\nTentative: depends on a proposal not ye
 t adopted.\n\nRequired Rulemaking on Personal Financial Data Rights (12 CF
 R Part 1033) (United States)\n\nSource: https://www.federalregister.gov/do
 cuments/2024/11/18/2024-25079/required-rulemaking-on-personal-financial-da
 ta-rights\n\nhttps://regulations.fru.dev/regulations/us-cfpb-1033
URL:https://regulations.fru.dev/regulations/us-cfpb-1033
CATEGORIES:United States,data-access,financial,privacy,cybersecurity
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-316@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20290630
DTEND;VALUE=DATE:20290701
SUMMARY:Vermont VDPOSA: Mandatory 60-day cure period expires
DESCRIPTION:The AG's duty to issue a cure notice before enforcement ends Ju
 ne 30\, 2029 (Act 145 sec. 3).\n\nVermont Data Privacy and Online Surveill
 ance Act (S.71\, Act 145 of 2026) (Vermont)\n\nSource: https://legislature
 .vermont.gov/Documents/2026/Docs/ACTS/ACT145/ACT145%20As%20Enacted.pdf\n\n
 https://regulations.fru.dev/regulations/us-vt-vdposa
URL:https://regulations.fru.dev/regulations/us-vt-vdposa
CATEGORIES:Vermont,privacy,health,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-257@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20290731
DTEND;VALUE=DATE:20290801
SUMMARY:Minnesota Consumer Data Privacy Act (MCDPA): Postsecondary institut
 ions must comply
DESCRIPTION:Postsecondary institutions regulated by the Office of Higher Ed
 ucation must comply by July 31\, 2029.\n\nMinnesota Consumer Data Privacy 
 Act (HF 4757\, 2024 Minn. Laws ch. 121\, art. 5)\, Minn. Stat. 325M.10-325
 M.21 (Minnesota)\n\nSource: https://www.revisor.mn.gov/statutes/cite/325M.
 20\n\nhttps://regulations.fru.dev/regulations/us-mn-mcdpa
URL:https://regulations.fru.dev/regulations/us-mn-mcdpa
CATEGORIES:Minnesota,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6967@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20290910
DTEND;VALUE=DATE:20290911
SUMMARY:Peru AI Law and Regulation: Private sector: all other uses
DESCRIPTION:Obligations apply four years after publication.\n\nTentative: d
 epends on a proposal not yet adopted.\n\nLey N° 31814\, Ley que promueve 
 el uso de la inteligencia artificial en favor del desarrollo económico y 
 social del país\, and its Regulation (Decreto Supremo N° 115-2025-PCM) (
 Peru)\n\nSource: https://www.gob.pe/institucion/pcm/normas-legales/7133522
 -115-2025-pcm\n\nhttps://regulations.fru.dev/regulations/pe-ai-law
URL:https://regulations.fru.dev/regulations/pe-ai-law
CATEGORIES:Peru,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-206@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20300101
DTEND;VALUE=DATE:20300102
SUMMARY:Colorado AI Act: Mandatory cure period ends
DESCRIPTION:The AG's obligation to offer a 60-day notice-and-cure period ex
 pires.\n\nColorado SB 24-205 (Consumer Protections for Artificial Intellig
 ence)\, as delayed by SB 25B-004 and repealed and reenacted by SB 26-189 (
 Automated Decision-Making Technology) (Colorado)\n\nSource: https://leg.co
 lorado.gov/bills/sb26-189\n\nhttps://regulations.fru.dev/regulations/us-co
 -ai-act
URL:https://regulations.fru.dev/regulations/us-co-ai-act
CATEGORIES:Colorado,ai,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-175@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20300401
DTEND;VALUE=DATE:20300402
SUMMARY:CCPA / CPRA: Cybersecurity audit due: revenue under $50M
DESCRIPTION:First cybersecurity audit report (covering 2029) due for covere
 d businesses with 2028 annual gross revenue under $50M (11 CCR 7121(a)(3))
 \; annual by April 1 thereafter.\n\nCalifornia Consumer Privacy Act of 201
 8\, as amended by the California Privacy Rights Act of 2020 (Cal. Civ. Cod
 e 1798.100 et seq.) and CPPA regulations (Cal. Code Regs. tit. 11\, 7000 e
 t seq.) (California)\n\nSource: https://cppa.ca.gov/regulations/pdf/ccpa_u
 pdates_cyber_risk_admt_appr_text.pdf\n\nhttps://regulations.fru.dev/regula
 tions/us-ca-ccpa
URL:https://regulations.fru.dev/regulations/us-ca-ccpa
CATEGORIES:California,privacy,ai,cybersecurity,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6889@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20300401
DTEND;VALUE=DATE:20300402
SUMMARY:CFPB Open Banking Rule (Section 1033): Tier 5 compliance date (orig
 inal)
DESCRIPTION:Banks with $850M to $1.5B in assets. Original date\; subject to
  stay\, extension and injunction.\n\nTentative: depends on a proposal not 
 yet adopted.\n\nRequired Rulemaking on Personal Financial Data Rights (12 
 CFR Part 1033) (United States)\n\nSource: https://www.federalregister.gov/
 documents/2024/11/18/2024-25079/required-rulemaking-on-personal-financial-
 data-rights\n\nhttps://regulations.fru.dev/regulations/us-cfpb-1033
URL:https://regulations.fru.dev/regulations/us-cfpb-1033
CATEGORIES:United States,data-access,financial,privacy,cybersecurity
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-46@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20300802
DTEND;VALUE=DATE:20300803
SUMMARY:EU AI Act: Public-authority high-risk systems must comply
DESCRIPTION:Providers and deployers of high-risk AI systems intended for us
 e by public authorities that were placed on the market before the Chapter 
 III application date must comply (Art 111(2)\, as replaced by the Omnibus)
 .\n\nRegulation (EU) 2024/1689 laying down harmonised rules on artificial 
 intelligence (Artificial Intelligence Act)\, as amended by Regulation (EU)
  2026/1744 (Digital Omnibus on AI) (European Union)\n\nSource: https://eur
 -lex.europa.eu/eli/reg/2026/1744/oj\n\nhttps://regulations.fru.dev/regulat
 ions/eu-ai-act
URL:https://regulations.fru.dev/regulations/eu-ai-act
CATEGORIES:European Union,ai,biometrics,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-54@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20301211
DTEND;VALUE=DATE:20301212
SUMMARY:Cyber Resilience Act: First CRA evaluation
DESCRIPTION:Commission evaluation and review report\, then every four years
  (Art 70(1)).\n\nRegulation (EU) 2024/2847 on horizontal cybersecurity req
 uirements for products with digital elements (Cyber Resilience Act) (Europ
 ean Union)\n\nSource: https://eur-lex.europa.eu/eli/reg/2024/2847/oj\n\nht
 tps://regulations.fru.dev/regulations/eu-cra
URL:https://regulations.fru.dev/regulations/eu-cra
CATEGORIES:European Union,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-47@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20301231
DTEND;VALUE=DATE:20310101
SUMMARY:EU AI Act: Large-scale EU IT systems must comply
DESCRIPTION:AI systems that are components of the large-scale IT systems in
  Annex X (e.g. SIS\, VIS\, Eurodac\, EES\, ETIAS) placed on the market bef
 ore 2 Aug 2027 must be brought into compliance (Art 111(1)).\n\nRegulation
  (EU) 2024/1689 laying down harmonised rules on artificial intelligence (A
 rtificial Intelligence Act)\, as amended by Regulation (EU) 2026/1744 (Dig
 ital Omnibus on AI) (European Union)\n\nSource: https://eur-lex.europa.eu/
 eli/reg/2024/1689/oj\n\nhttps://regulations.fru.dev/regulations/eu-ai-act
URL:https://regulations.fru.dev/regulations/eu-ai-act
CATEGORIES:European Union,ai,biometrics,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-83@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20310326
DTEND;VALUE=DATE:20310327
SUMMARY:European Health Data Space (EHDS): Primary use for second data cate
 gories\; EHR systems in service\; extra secondary-use categories
DESCRIPTION:Primary-use rules extend to medical images\, lab results and di
 scharge reports (Art 14(1)(d)-(f)). Chapter III applies to EHR systems put
  into service under Art 26(2). Additional secondary-use categories in Art 
 51(1)(b)\,(f)\,(g)\,(m)\,(p) apply.\n\nRegulation (EU) 2025/327 on the Eur
 opean Health Data Space (European Union)\n\nSource: https://eur-lex.europa
 .eu/eli/reg/2025/327/oj\n\nhttps://regulations.fru.dev/regulations/eu-ehds
URL:https://regulations.fru.dev/regulations/eu-ehds
CATEGORIES:European Union,health,privacy,data-access
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-84@regulations.fru.dev
DTSTAMP:20260926T142658Z
DTSTART;VALUE=DATE:20350326
DTEND;VALUE=DATE:20350327
SUMMARY:European Health Data Space (EHDS): Third-country participation in s
 econdary use
DESCRIPTION:Art 75(5) applies from 26 Mar 2035.\n\nRegulation (EU) 2025/327
  on the European Health Data Space (European Union)\n\nSource: https://eur
 -lex.europa.eu/eli/reg/2025/327/oj\n\nhttps://regulations.fru.dev/regulati
 ons/eu-ehds
URL:https://regulations.fru.dev/regulations/eu-ehds
CATEGORIES:European Union,health,privacy,data-access
TRANSP:TRANSPARENT
END:VEVENT
END:VCALENDAR
