BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//fru.dev//Regulations//EN
CALSCALE:GREGORIAN
METHOD:PUBLISH
X-WR-CALNAME:Regulation deadlines (regulations.fru.dev)
X-WR-CALDESC:Compliance deadlines tracked at regulations.fru.dev
REFRESH-INTERVAL;VALUE=DURATION:P1D
X-PUBLISHED-TTL:P1D
BEGIN:VEVENT
UID:deadline-1@regulations.fru.dev
DTSTAMP:20260926T195647Z
DTSTART;VALUE=DATE:20220102
DTEND;VALUE=DATE:20220103
SUMMARY:UAE PDPL: PDPL enters into force
DESCRIPTION:Decree-law takes effect\; compliance obligations tied to Execut
 ive Regulations.\n\nFederal Decree-Law No. 45 of 2021 on the Protection of
  Personal Data (United Arab Emirates)\n\nSource: https://uaelegislation.go
 v.ae/en/legislations/1972\n\nhttps://regulations.fru.dev/regulations/ae-pd
 pl
URL:https://regulations.fru.dev/regulations/ae-pdpl
CATEGORIES:United Arab Emirates,privacy,breach-notification,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-233@regulations.fru.dev
DTSTAMP:20260926T195647Z
DTSTART;VALUE=DATE:20220110
DTEND;VALUE=DATE:20220111
SUMMARY:GLBA Safeguards Rule: 2021 Safeguards Rule amendments effective
DESCRIPTION:The amended Safeguards Rule published December 9\, 2021 took ef
 fect\, with the more detailed program elements in 314.5 deferred.\n\nFTC S
 tandards for Safeguarding Customer Information (Safeguards Rule)\, 16 CFR 
 Part 314\, under the Gramm-Leach-Bliley Act (United States (Federal))\n\nS
 ource: https://www.federalregister.gov/documents/2021/12/09/2021-25736/sta
 ndards-for-safeguarding-customer-information\n\nhttps://regulations.fru.de
 v/regulations/us-glba-safeguards
URL:https://regulations.fru.dev/regulations/us-glba-safeguards
CATEGORIES:United States (Federal),financial,cybersecurity,breach-notificat
 ion,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-7023@regulations.fru.dev
DTSTAMP:20260926T195647Z
DTSTART;VALUE=DATE:20220123
DTEND;VALUE=DATE:20220124
SUMMARY:Australia Online Safety Act: Online Safety Act commences
DESCRIPTION:The whole Act commences by Proclamation.\n\nOnline Safety Act 2
 021 (Australia)\n\nSource: https://www.legislation.gov.au/C2021A00076/asma
 de\n\nhttps://regulations.fru.dev/regulations/au-online-safety-act
URL:https://regulations.fru.dev/regulations/au-online-safety-act
CATEGORIES:Australia,online-safety,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6975@regulations.fru.dev
DTSTAMP:20260926T195647Z
DTSTART;VALUE=DATE:20220301
DTEND;VALUE=DATE:20220302
SUMMARY:China Algorithmic Recommendation Provisions: Algorithmic recommenda
 tion provisions take effect
DESCRIPTION:User opt-out\, transparency and algorithm filing duties apply.\
 n\nProvisions on the Administration of Algorithmic Recommendation in Inter
 net Information Services (China)\n\nSource: https://www.cac.gov.cn/2022-01
 /04/c_1642894606364259.htm\n\nhttps://regulations.fru.dev/regulations/cn-a
 lgorithm-recommendation
URL:https://regulations.fru.dev/regulations/cn-algorithm-recommendation
CATEGORIES:China,ai,online-safety,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-121@regulations.fru.dev
DTSTAMP:20260926T195647Z
DTSTART;VALUE=DATE:20220401
DTEND;VALUE=DATE:20220402
SUMMARY:Japan APPI: 2020 amendments in force
DESCRIPTION:Mandatory breach reporting\, pseudonymized information and stri
 cter cross-border rules apply.\n\nAct on the Protection of Personal Inform
 ation (Act No. 57 of 2003)\, as amended including the 2026 amendment act (
 Japan)\n\nSource: https://www.ppc.go.jp/en/legal/\n\nhttps://regulations.f
 ru.dev/regulations/jp-appi
URL:https://regulations.fru.dev/regulations/jp-appi
CATEGORIES:Japan,privacy,children,biometrics,breach-notification,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-7012@regulations.fru.dev
DTSTAMP:20260926T195647Z
DTSTART;VALUE=DATE:20220411
DTEND;VALUE=DATE:20220412
SUMMARY:Singapore Cybersecurity Act: Cybersecurity service provider licensi
 ng commences
DESCRIPTION:Part 5 and the Second Schedule take effect. Penetration testing
  and managed SOC providers need a licence.\n\nCybersecurity Act 2018 (Sing
 apore)\n\nSource: https://sso.agc.gov.sg/Acts-Supp/9-2018/Published/202112
 31?DocDate=20180312\n\nhttps://regulations.fru.dev/regulations/sg-cybersec
 urity-act
URL:https://regulations.fru.dev/regulations/sg-cybersecurity-act
CATEGORIES:Singapore,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-142@regulations.fru.dev
DTSTAMP:20260926T195647Z
DTSTART;VALUE=DATE:20220601
DTEND;VALUE=DATE:20220602
SUMMARY:Thailand PDPA: PDPA main obligations take effect
DESCRIPTION:Core data protection obligations and penalties apply after post
 ponement Royal Decrees.\n\nPersonal Data Protection Act B.E. 2562 (2019) (
 Thailand)\n\nSource: https://www.ratchakitcha.soc.go.th/DATA/PDF/2562/A/06
 9/T_0052.PDF\n\nhttps://regulations.fru.dev/regulations/th-pdpa
URL:https://regulations.fru.dev/regulations/th-pdpa
CATEGORIES:Thailand,privacy,breach-notification,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-63@regulations.fru.dev
DTSTAMP:20260926T195647Z
DTSTART;VALUE=DATE:20220623
DTEND;VALUE=DATE:20220624
SUMMARY:Data Governance Act: DGA enters into force
DESCRIPTION:Entered into force on the twentieth day after publication in OJ
  L 152 of 3 June 2022 (Art 38).\n\nRegulation (EU) 2022/868 on European da
 ta governance (Data Governance Act) (European Union)\n\nSource: https://eu
 r-lex.europa.eu/eli/reg/2022/868/oj\n\nhttps://regulations.fru.dev/regulat
 ions/eu-dga
URL:https://regulations.fru.dev/regulations/eu-dga
CATEGORIES:European Union,data-access,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6991@regulations.fru.dev
DTSTAMP:20260926T195647Z
DTSTART;VALUE=DATE:20220627
DTEND;VALUE=DATE:20220628
SUMMARY:India CERT-In Cyber Security Directions: CERT-In Directions take ef
 fect
DESCRIPTION:The Directions apply 60 days after issue on 28 Apr 2022. The ex
 act day (27 or 28 June 2022) depends on how the 60 days are counted.\n\nTe
 ntative: depends on a proposal not yet adopted.\n\nDirections under sectio
 n 70B(6) of the Information Technology Act\, 2000 relating to information 
 security practices\, procedure\, prevention\, response and reporting of cy
 ber incidents for Safe and Trusted Internet (India)\n\nSource: https://www
 .cert-in.org.in/PDF/CERT-In_Directions_70B_28.04.2022.pdf\n\nhttps://regul
 ations.fru.dev/regulations/in-certin-directions
URL:https://regulations.fru.dev/regulations/in-certin-directions
CATEGORIES:India,cybersecurity,breach-notification,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-7025@regulations.fru.dev
DTSTAMP:20260926T195647Z
DTSTART;VALUE=DATE:20220708
DTEND;VALUE=DATE:20220709
SUMMARY:Australia SOCI Act: Mandatory cyber incident reporting starts for m
 ost assets
DESCRIPTION:The Application Rules registered on 7 April 2022 gave most asse
 t classes a 3-month grace period before Part 2B incident reporting applied
 . The date is worked out from that grace period.\n\nTentative: depends on 
 a proposal not yet adopted.\n\nSecurity of Critical Infrastructure Act 201
 8 (Australia)\n\nSource: https://www.legislation.gov.au/F2022L00562/asmade
 \n\nhttps://regulations.fru.dev/regulations/au-soci-act
URL:https://regulations.fru.dev/regulations/au-soci-act
CATEGORIES:Australia,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6977@regulations.fru.dev
DTSTAMP:20260926T195647Z
DTSTART;VALUE=DATE:20220901
DTEND;VALUE=DATE:20220902
SUMMARY:China Data Export Security Assessment Measures: Security assessment
  measures take effect
DESCRIPTION:Covered data exports require a CAC security assessment.\n\nMeas
 ures for the Security Assessment of Outbound Data Transfers (China)\n\nSou
 rce: https://www.cac.gov.cn/2022-07/07/c_1658811536396503.htm\n\nhttps://r
 egulations.fru.dev/regulations/cn-sa-measures
URL:https://regulations.fru.dev/regulations/cn-sa-measures
CATEGORIES:China,data-residency,privacy,cybersecurity
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-22@regulations.fru.dev
DTSTAMP:20260926T195647Z
DTSTART;VALUE=DATE:20220922
DTEND;VALUE=DATE:20220923
SUMMARY:Quebec Law 25: Phase 1: privacy officer and incident reporting
DESCRIPTION:Person in charge of personal information protection\, confident
 iality incident notification and register apply.\n\nAct to modernize legis
 lative provisions as regards the protection of personal information (Law 2
 5\, formerly Bill 64) (Quebec\, Canada)\n\nSource: https://www.legisquebec
 .gouv.qc.ca/en/document/cs/P-39.1\n\nhttps://regulations.fru.dev/regulatio
 ns/ca-qc-law25
URL:https://regulations.fru.dev/regulations/ca-qc-law25
CATEGORIES:Quebec\, Canada,privacy,breach-notification,biometrics
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6992@regulations.fru.dev
DTSTAMP:20260926T195647Z
DTSTART;VALUE=DATE:20220925
DTEND;VALUE=DATE:20220926
SUMMARY:India CERT-In Cyber Security Directions: Extended date for MSMEs an
 d subscriber validation
DESCRIPTION:The Directions apply to micro\, small and medium enterprises\, 
 and subscriber validation duties apply to data centres\, VPS\, cloud and V
 PN providers\, from this date.\n\nDirections under section 70B(6) of the I
 nformation Technology Act\, 2000 relating to information security practice
 s\, procedure\, prevention\, response and reporting of cyber incidents for
  Safe and Trusted Internet (India)\n\nSource: https://www.cert-in.org.in/P
 DF/CERT-In_directions_extension_MSMEs_and_validation_27.06.2022.pdf\n\nhtt
 ps://regulations.fru.dev/regulations/in-certin-directions
URL:https://regulations.fru.dev/regulations/in-certin-directions
CATEGORIES:India,cybersecurity,breach-notification,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-141@regulations.fru.dev
DTSTAMP:20260926T195647Z
DTSTART;VALUE=DATE:20221001
DTEND;VALUE=DATE:20221002
SUMMARY:Singapore PDPA: Higher financial penalty cap applies
DESCRIPTION:Maximum penalty rises to 10% of Singapore turnover for organiza
 tions with turnover above SGD 10 million.\n\nPersonal Data Protection Act 
 2012 (Singapore) (Singapore)\n\nSource: https://sso.agc.gov.sg/Act/PDPA201
 2\n\nhttps://regulations.fru.dev/regulations/sg-pdpa
URL:https://regulations.fru.dev/regulations/sg-pdpa
CATEGORIES:Singapore,privacy,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6876@regulations.fru.dev
DTSTAMP:20260926T195647Z
DTSTART;VALUE=DATE:20221001
DTEND;VALUE=DATE:20221002
SUMMARY:UK Telecommunications Security Act: Security measures regulations i
 n force
DESCRIPTION:Electronic Communications (Security Measures) Regulations 2022 
 come into force.\n\nTelecommunications (Security) Act 2021 and the Electro
 nic Communications (Security Measures) Regulations 2022 (United Kingdom)\n
 \nSource: https://www.legislation.gov.uk/uksi/2022/933/made\n\nhttps://reg
 ulations.fru.dev/regulations/uk-telecom-security
URL:https://regulations.fru.dev/regulations/uk-telecom-security
CATEGORIES:United Kingdom,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-112@regulations.fru.dev
DTSTAMP:20260926T195647Z
DTSTART;VALUE=DATE:20221017
DTEND;VALUE=DATE:20221018
SUMMARY:Indonesia PDP Law: PDP Law enacted and in force
DESCRIPTION:Law takes effect on enactment\, starting a 2-year transition.\n
 \nLaw No. 27 of 2022 on Personal Data Protection (Undang-Undang Pelindunga
 n Data Pribadi) (Indonesia)\n\nSource: https://peraturan.bpk.go.id/Details
 /229798/uu-no-27-tahun-2022\n\nhttps://regulations.fru.dev/regulations/id-
 pdp
URL:https://regulations.fru.dev/regulations/id-pdp
CATEGORIES:Indonesia,privacy,breach-notification,data-residency,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-66@regulations.fru.dev
DTSTAMP:20260926T195647Z
DTSTART;VALUE=DATE:20221101
DTEND;VALUE=DATE:20221102
SUMMARY:Digital Markets Act: DMA enters into force
DESCRIPTION:Entered into force twenty days after publication\; certain proc
 edural articles apply from this date (Art 54).\n\nRegulation (EU) 2022/192
 5 on contestable and fair markets in the digital sector (Digital Markets A
 ct) (European Union)\n\nSource: https://eur-lex.europa.eu/eli/reg/2022/192
 5/oj\n\nhttps://regulations.fru.dev/regulations/eu-dma
URL:https://regulations.fru.dev/regulations/eu-dma
CATEGORIES:European Union,data-access,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-75@regulations.fru.dev
DTSTAMP:20260926T195647Z
DTSTART;VALUE=DATE:20221116
DTEND;VALUE=DATE:20221117
SUMMARY:Digital Services Act: DSA enters into force
DESCRIPTION:Entered into force twenty days after publication\; VLOP designa
 tion provisions (Art 33(3)-(6)) and Commission enforcement sections apply 
 from this date (Art 93).\n\nRegulation (EU) 2022/2065 on a Single Market f
 or Digital Services (Digital Services Act) (European Union)\n\nSource: htt
 ps://eur-lex.europa.eu/eli/reg/2022/2065/oj\n\nhttps://regulations.fru.dev
 /regulations/eu-dsa
URL:https://regulations.fru.dev/regulations/eu-dsa
CATEGORIES:European Union,online-safety,children,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6873@regulations.fru.dev
DTSTAMP:20260926T195647Z
DTSTART;VALUE=DATE:20221206
DTEND;VALUE=DATE:20221207
SUMMARY:UK PSTI Act (product security): Royal Assent
DESCRIPTION:PSTI Act receives Royal Assent.\n\nProduct Security and Telecom
 munications Infrastructure Act 2022 and the Product Security Regulations 2
 023 (United Kingdom)\n\nSource: https://www.legislation.gov.uk/ukpga/2022/
 46/introduction/enacted\n\nhttps://regulations.fru.dev/regulations/uk-psti
URL:https://regulations.fru.dev/regulations/uk-psti
CATEGORIES:United Kingdom,cybersecurity
TRANSP:TRANSPARENT
END:VEVENT
END:VCALENDAR
