BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//fru.dev//Regulations//EN
CALSCALE:GREGORIAN
METHOD:PUBLISH
X-WR-CALNAME:Regulation deadlines (regulations.fru.dev)
X-WR-CALDESC:Compliance deadlines tracked at regulations.fru.dev
REFRESH-INTERVAL;VALUE=DURATION:P1D
X-PUBLISHED-TTL:P1D
BEGIN:VEVENT
UID:deadline-6908@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20250101
DTEND;VALUE=DATE:20250102
SUMMARY:California SB 976 addictive feeds: Takes effect
DESCRIPTION:Actual-knowledge feed and notification limits apply\, subject t
 o litigation.\n\nProtecting Our Kids from Social Media Addiction Act (SB 9
 76) (California)\n\nSource: https://leginfo.legislature.ca.gov/faces/billN
 avClient.xhtml?bill_id=202320240SB976\n\nhttps://regulations.fru.dev/regul
 ations/us-ca-sb976
URL:https://regulations.fru.dev/regulations/us-ca-sb976
CATEGORIES:California,children,online-safety
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-166@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20250101
DTEND;VALUE=DATE:20250102
SUMMARY:CCPA / CPRA: CPI adjustment of thresholds and fines
DESCRIPTION:Revenue threshold rises to $26\,625\,000 and fines to $2\,663 /
  $7\,988 per violation.\n\nCalifornia Consumer Privacy Act of 2018\, as am
 ended by the California Privacy Rights Act of 2020 (Cal. Civ. Code 1798.10
 0 et seq.) and CPPA regulations (Cal. Code Regs. tit. 11\, 7000 et seq.) (
 California)\n\nSource: https://cppa.ca.gov/regulations/cpi_adjustment.html
 \n\nhttps://regulations.fru.dev/regulations/us-ca-ccpa
URL:https://regulations.fru.dev/regulations/us-ca-ccpa
CATEGORIES:California,privacy,ai,cybersecurity,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-34@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20250101
DTEND;VALUE=DATE:20250102
SUMMARY:China Network Data Security Regulations: Network Data Regulations t
 ake effect
DESCRIPTION:All provisions\, including the 10-million-person threshold duti
 es and annual important-data risk assessments\, apply.\n\nRegulations on N
 etwork Data Security Management (State Council Order No. 790) (China)\n\nS
 ource: https://www.gov.cn/zhengce/content/202409/content_6977766.htm\n\nht
 tps://regulations.fru.dev/regulations/cn-network-data-regs
URL:https://regulations.fru.dev/regulations/cn-network-data-regs
CATEGORIES:China,privacy,cybersecurity,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-209@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20250101
DTEND;VALUE=DATE:20250102
SUMMARY:Colorado Privacy Act (CPA): 60-day cure period expires
DESCRIPTION:Mandatory 60-day notice-and-cure before AG enforcement ends\; e
 nforcement may proceed without cure.\n\nColorado Privacy Act (SB 21-190)\,
  C.R.S. 6-1-1301 et seq.\, as amended by HB 24-1130\, SB 24-041 and SB 25-
 276 (Colorado)\n\nSource: https://leg.colorado.gov/bills/sb21-190\n\nhttps
 ://regulations.fru.dev/regulations/us-co-cpa
URL:https://regulations.fru.dev/regulations/us-co-cpa
CATEGORIES:Colorado,privacy,children,biometrics
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-217@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20250101
DTEND;VALUE=DATE:20250102
SUMMARY:Connecticut Data Privacy Act (CTDPA): Universal opt-out preference 
 signals required
DESCRIPTION:Controllers must honor opt-out preference signals for targeted 
 advertising and sale (effective Jan 1\, 2025).\n\nConnecticut Data Privacy
  Act (Public Act 22-15)\, Conn. Gen. Stat. 42-515 et seq.\, as amended by 
 Public Act 25-113 (SB 1295) and Public Act 26-64 (SB 4) (Connecticut)\n\nS
 ource: https://www.cga.ct.gov/asp/cgabillstatus/cgabillstatus.asp?selBillT
 ype=Bill&which_year=2022&bill_num=6\n\nhttps://regulations.fru.dev/regulat
 ions/us-ct-ctdpa
URL:https://regulations.fru.dev/regulations/us-ct-ctdpa
CATEGORIES:Connecticut,privacy,children,ai,health
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-223@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20250101
DTEND;VALUE=DATE:20250102
SUMMARY:Delaware Personal Data Privacy Act (DPDPA): DPDPA takes effect
DESCRIPTION:Consumer rights and controller duties apply\; 60-day mandatory 
 cure period begins.\n\nDelaware Personal Data Privacy Act (HB 154)\, 6 Del
 . C. ch. 12D (Delaware)\n\nSource: https://delcode.delaware.gov/title6/c01
 2d/index.html\n\nhttps://regulations.fru.dev/regulations/us-de-dpdpa
URL:https://regulations.fru.dev/regulations/us-de-dpdpa
CATEGORIES:Delaware,privacy,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-240@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20250101
DTEND;VALUE=DATE:20250102
SUMMARY:Iowa Consumer Data Protection Act (ICDPA): ICDPA takes effect
DESCRIPTION:Consumer rights and controller/processor obligations apply.\n\n
 Iowa Consumer Data Protection Act (SF 262\, 2023)\, Iowa Code ch. 715D (Io
 wa)\n\nSource: https://www.legis.iowa.gov/docs/code/715D.pdf\n\nhttps://re
 gulations.fru.dev/regulations/us-ia-icdpa
URL:https://regulations.fru.dev/regulations/us-ia-icdpa
CATEGORIES:Iowa,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-129@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20250101
DTEND;VALUE=DATE:20250102
SUMMARY:Malaysia PDPA: PDPA amendments phase 1
DESCRIPTION:Miscellaneous provisions commence (e.g. electronic service of n
 otices).\n\nPersonal Data Protection Act 2010 (Act 709)\, as amended by th
 e Personal Data Protection (Amendment) Act 2024 (Act A1727) (Malaysia)\n\n
 Source: https://www.pdp.gov.my/ppdpv1/en/personal-data-protection-amendmen
 t-act-2024-commencement-date-determination/\n\nhttps://regulations.fru.dev
 /regulations/my-pdpa
URL:https://regulations.fru.dev/regulations/my-pdpa
CATEGORIES:Malaysia,privacy,breach-notification,biometrics,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-260@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20250101
DTEND;VALUE=DATE:20250102
SUMMARY:Nebraska NDPA: Nebraska Data Privacy Act takes effect
DESCRIPTION:Controller and processor obligations and consumer rights under 
 Neb. Rev. Stat. 87-1101 et seq. apply.\n\nNebraska Data Privacy Act (LB 10
 74\, 2024) (Nebraska)\n\nSource: https://nebraskalegislature.gov/bills/vie
 w_bill.php?DocumentID=54904\n\nhttps://regulations.fru.dev/regulations/us-
 ne-ndpa
URL:https://regulations.fru.dev/regulations/us-ne-ndpa
CATEGORIES:Nebraska,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-261@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20250101
DTEND;VALUE=DATE:20250102
SUMMARY:New Hampshire Privacy Act: New Hampshire Privacy Act takes effect
DESCRIPTION:RSA 507-H obligations and consumer rights apply (Laws 2024\, 5:
 1\, eff. Jan. 1\, 2025).\n\nNew Hampshire Privacy Act (SB 255\, 2024)\, RS
 A chapter 507-H (New Hampshire)\n\nSource: https://gc.nh.gov/rsa/html/LII/
 507-H/507-H-2.htm\n\nhttps://regulations.fru.dev/regulations/us-nh-privacy
URL:https://regulations.fru.dev/regulations/us-nh-privacy
CATEGORIES:New Hampshire,privacy,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-302@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20250101
DTEND;VALUE=DATE:20250102
SUMMARY:Texas TDPSA: Universal opt-out mechanism requirement applies
DESCRIPTION:Controllers must honor global privacy control / universal opt-o
 ut signals (Bus. & Com. Code 541.055(e)).\n\nTexas Data Privacy and Securi
 ty Act (HB 4\, 2023) (Texas)\n\nSource: https://capitol.texas.gov/BillLook
 up/History.aspx?LegSess=88R&Bill=HB4\n\nhttps://regulations.fru.dev/regula
 tions/us-tx-tdpsa
URL:https://regulations.fru.dev/regulations/us-tx-tdpsa
CATEGORIES:Texas,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6890@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20250106
DTEND;VALUE=DATE:20250107
SUMMARY:HIPAA Security Rule update (NPRM): NPRM published
DESCRIPTION:Proposed Security Rule changes published in the Federal Registe
 r.\n\nHIPAA Security Rule To Strengthen the Cybersecurity of Electronic Pr
 otected Health Information (proposed rule) (United States)\n\nSource: http
 s://www.federalregister.gov/documents/2025/01/06/2024-30983/hipaa-security
 -rule-to-strengthen-the-cybersecurity-of-electronic-protected-health-infor
 mation\n\nhttps://regulations.fru.dev/regulations/us-hhs-hipaa-security-np
 rm
URL:https://regulations.fru.dev/regulations/us-hhs-hipaa-security-nprm
CATEGORIES:United States,health,cybersecurity,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6857@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20250112
DTEND;VALUE=DATE:20250113
SUMMARY:Interoperable Europe Act: Interoperability assessments mandatory
DESCRIPTION:Article 3(1) to (4) (interoperability assessments) and Article 
 17 apply.\n\nRegulation (EU) 2024/903 laying down measures for a high leve
 l of public sector interoperability across the Union (Interoperable Europe
  Act) (European Union)\n\nSource: https://eur-lex.europa.eu/eli/reg/2024/9
 03/oj/eng\n\nhttps://regulations.fru.dev/regulations/eu-interoperable-euro
 pe
URL:https://regulations.fru.dev/regulations/eu-interoperable-europe
CATEGORIES:European Union,data-access
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-264@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20250115
DTEND;VALUE=DATE:20250116
SUMMARY:New Jersey NJDPA: NJDPA takes effect
DESCRIPTION:The act takes effect on the 365th day after enactment on Jan 16
 \, 2024 (sec. 17).\n\nNew Jersey Data Privacy Act (P.L.2023\, c.266\; S332
 ) (New Jersey)\n\nSource: https://pub.njleg.state.nj.us/Bills/2022/PL23/26
 6_.PDF\n\nhttps://regulations.fru.dev/regulations/us-nj-njdpa
URL:https://regulations.fru.dev/regulations/us-nj-njdpa
CATEGORIES:New Jersey,privacy,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6880@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20250117
DTEND;VALUE=DATE:20250118
SUMMARY:CFPB Open Banking Rule (Section 1033): Final rule effective
DESCRIPTION:Rule published 2024-11-18 takes effect.\n\nRequired Rulemaking 
 on Personal Financial Data Rights (12 CFR Part 1033) (United States)\n\nSo
 urce: https://www.federalregister.gov/documents/2024/11/18/2024-25079/requ
 ired-rulemaking-on-personal-financial-data-rights\n\nhttps://regulations.f
 ru.dev/regulations/us-cfpb-1033
URL:https://regulations.fru.dev/regulations/us-cfpb-1033
CATEGORIES:United States,data-access,financial,privacy,cybersecurity
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-71@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20250117
DTEND;VALUE=DATE:20250118
SUMMARY:DORA: DORA applies
DESCRIPTION:All DORA obligations (ICT risk management\, incident reporting\
 , testing\, third-party risk\, register of information) apply from 17 Jan 
 2025 (Art 64).\n\nRegulation (EU) 2022/2554 on digital operational resilie
 nce for the financial sector (Digital Operational Resilience Act) (Europea
 n Union)\n\nSource: https://eur-lex.europa.eu/eli/reg/2022/2554/oj\n\nhttp
 s://regulations.fru.dev/regulations/eu-dora
URL:https://regulations.fru.dev/regulations/eu-dora
CATEGORIES:European Union,cybersecurity,financial,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-102@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20250117
DTEND;VALUE=DATE:20250118
SUMMARY:NIS2: Digital infrastructure entities submit registration data
DESCRIPTION:DNS providers\, TLD registries\, domain registration services\,
  cloud\, data centre\, CDN\, managed (security) service providers\, market
 places\, search engines and social networks had to submit registration det
 ails to competent authorities (Art 27(2)).\n\nDirective (EU) 2022/2555 on 
 measures for a high common level of cybersecurity across the Union (NIS2 D
 irective) (European Union)\n\nSource: https://eur-lex.europa.eu/eli/dir/20
 22/2555/oj\n\nhttps://regulations.fru.dev/regulations/eu-nis2
URL:https://regulations.fru.dev/regulations/eu-nis2
CATEGORIES:European Union,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6944@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20250129
DTEND;VALUE=DATE:20250130
SUMMARY:Ontario Bill 194: Enhancing Digital Security and Trust Act in force
DESCRIPTION:Schedule 1 (cyber security\, AI and minors' data framework) and
  some FIPPA amendments come into force by OIC 361/2025.\n\nStrengthening C
 yber Security and Building Trust in the Public Sector Act\, 2024 (Ontario\
 , Canada)\n\nSource: https://www.ontario.ca/laws/oic/o250361\n\nhttps://re
 gulations.fru.dev/regulations/ca-on-bill194
URL:https://regulations.fru.dev/regulations/ca-on-bill194
CATEGORIES:Ontario\, Canada,cybersecurity,ai,privacy,children,breach-notifi
 cation
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-7008@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20250129
DTEND;VALUE=DATE:20250130
SUMMARY:Pakistan PECA: PECA amendment takes effect
DESCRIPTION:Act No. II of 2025 got presidential assent and took effect on 2
 9 Jan 2025\, per the Gazette of Pakistan.\n\nPrevention of Electronic Crim
 es Act\, 2016 (as amended by the Prevention of Electronic Crimes (Amendmen
 t) Act\, 2025) (Pakistan)\n\nSource: https://na.gov.pk/uploads/documents/6
 79b243193585_457.pdf\n\nhttps://regulations.fru.dev/regulations/pk-peca
URL:https://regulations.fru.dev/regulations/pk-peca
CATEGORIES:Pakistan,cybersecurity,online-safety
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-38@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20250202
DTEND;VALUE=DATE:20250203
SUMMARY:EU AI Act: Prohibited practices and AI literacy apply
DESCRIPTION:Chapters I and II apply\, including the Article 5 bans on prohi
 bited AI practices and the Article 4 AI literacy duty (Art 113(a)).\n\nReg
 ulation (EU) 2024/1689 laying down harmonised rules on artificial intellig
 ence (Artificial Intelligence Act)\, as amended by Regulation (EU) 2026/17
 44 (Digital Omnibus on AI) (European Union)\n\nSource: https://eur-lex.eur
 opa.eu/eli/reg/2024/1689/oj\n\nhttps://regulations.fru.dev/regulations/eu-
 ai-act
URL:https://regulations.fru.dev/regulations/eu-ai-act
CATEGORIES:European Union,ai,biometrics,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6858@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20250204
DTEND;VALUE=DATE:20250205
SUMMARY:EU Cyber Solidarity Act: Cyber Solidarity Act enters into force
DESCRIPTION:Published in the OJ on 2025-01-15\; enters into force on the 20
 th day.\n\nRegulation (EU) 2025/38 laying down measures to strengthen soli
 darity and capacities in the Union to detect\, prepare for and respond to 
 cyber threats and incidents (Cyber Solidarity Act) (European Union)\n\nSou
 rce: https://eur-lex.europa.eu/eli/reg/2025/38/oj/eng\n\nhttps://regulatio
 ns.fru.dev/regulations/eu-cyber-solidarity-act
URL:https://regulations.fru.dev/regulations/eu-cyber-solidarity-act
CATEGORIES:European Union,cybersecurity
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-238@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20250307
DTEND;VALUE=DATE:20250308
SUMMARY:HIPAA: Security Rule NPRM comment period closed
DESCRIPTION:Comments closed on the proposed HIPAA Security Rule update (90 
 FR 898)\; OCR has not issued a final rule.\n\nHIPAA Privacy\, Security and
  Breach Notification Rules (45 CFR Parts 160 and 164) (United States (Fede
 ral))\n\nSource: https://www.federalregister.gov/documents/2025/01/06/2024
 -30983/hipaa-security-rule-to-strengthen-the-cybersecurity-of-electronic-p
 rotected-health-information\n\nhttps://regulations.fru.dev/regulations/us-
 hipaa
URL:https://regulations.fru.dev/regulations/us-hipaa
CATEGORIES:United States (Federal),privacy,health,cybersecurity,breach-noti
 fication
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6891@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20250307
DTEND;VALUE=DATE:20250308
SUMMARY:HIPAA Security Rule update (NPRM): Comment period closes
DESCRIPTION:Public comments on the NPRM due.\n\nHIPAA Security Rule To Stre
 ngthen the Cybersecurity of Electronic Protected Health Information (propo
 sed rule) (United States)\n\nSource: https://www.federalregister.gov/docum
 ents/2025/01/06/2024-30983/hipaa-security-rule-to-strengthen-the-cybersecu
 rity-of-electronic-protected-health-information\n\nhttps://regulations.fru
 .dev/regulations/us-hhs-hipaa-security-nprm
URL:https://regulations.fru.dev/regulations/us-hhs-hipaa-security-nprm
CATEGORIES:United States,health,cybersecurity,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-157@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20250317
DTEND;VALUE=DATE:20250318
SUMMARY:UK Online Safety Act: Illegal harms duties enforceable
DESCRIPTION:Illegal content safety duties apply\; illegal content risk asse
 ssments had to be completed by 16 March 2025.\n\nOnline Safety Act 2023 (U
 nited Kingdom)\n\nSource: https://www.ofcom.org.uk/online-safety/illegal-a
 nd-harmful-content\n\nhttps://regulations.fru.dev/regulations/uk-osa
URL:https://regulations.fru.dev/regulations/uk-osa
CATEGORIES:United Kingdom,online-safety,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-128@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20250321
DTEND;VALUE=DATE:20250322
SUMMARY:Mexico LFPDPPP 2025: New LFPDPPP in force
DESCRIPTION:Law published 20 March 2025 enters into force the following day
 \, repealing the 2010 law.\n\nLey Federal de Protección de Datos Personal
 es en Posesión de los Particulares (2025) (Mexico)\n\nSource: https://www
 .diputados.gob.mx/LeyesBiblio/pdf/LFPDPPP.pdf\n\nhttps://regulations.fru.d
 ev/regulations/mx-lfpdppp
URL:https://regulations.fru.dev/regulations/mx-lfpdppp
CATEGORIES:Mexico,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-80@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20250325
DTEND;VALUE=DATE:20250326
SUMMARY:European Health Data Space (EHDS): EHDS enters into force
DESCRIPTION:Regulation (EU) 2025/327\, published 5 Mar 2025\, enters into f
 orce on the twentieth day following publication.\n\nRegulation (EU) 2025/3
 27 on the European Health Data Space (European Union)\n\nSource: https://e
 ur-lex.europa.eu/eli/reg/2025/327/oj\n\nhttps://regulations.fru.dev/regula
 tions/eu-ehds
URL:https://regulations.fru.dev/regulations/eu-ehds
CATEGORIES:European Union,health,privacy,data-access
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-7026@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20250327
DTEND;VALUE=DATE:20250328
SUMMARY:Indonesia PP 17/2025 (Child Protection Online): PP 17/2025 in force
DESCRIPTION:The regulation was signed\, promulgated and took effect on the 
 same day.\n\nGovernment Regulation No. 17 of 2025 on Governance of Electro
 nic Systems in Child Protection (Indonesia)\n\nSource: https://peraturan.b
 pk.go.id/Details/316698/pp-no-17-tahun-2025\n\nhttps://regulations.fru.dev
 /regulations/id-child-online-protection
URL:https://regulations.fru.dev/regulations/id-child-online-protection
CATEGORIES:Indonesia,children,online-safety,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6955@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20250330
DTEND;VALUE=DATE:20250331
SUMMARY:Peru PDPL and 2024 Regulation: New regulation in force
DESCRIPTION:Regulation enters into force 120 calendar days after publicatio
 n.\n\nLey N° 29733\, Ley de Protección de Datos Personales\, and its Reg
 ulation (Decreto Supremo N° 016-2024-JUS) (Peru)\n\nSource: https://www.g
 ob.pe/institucion/smv/normas-legales/6426760-016-2024-jus\n\nhttps://regul
 ations.fru.dev/regulations/pe-pdpl
URL:https://regulations.fru.dev/regulations/pe-pdpl
CATEGORIES:Peru,privacy,breach-notification,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-130@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20250401
DTEND;VALUE=DATE:20250402
SUMMARY:Malaysia PDPA: PDPA amendments phase 2
DESCRIPTION:'Data controller' terminology\, biometric data as sensitive dat
 a\, higher penalties\, Security Principle for processors\, and removal of 
 the cross-border whitelist take effect.\n\nPersonal Data Protection Act 20
 10 (Act 709)\, as amended by the Personal Data Protection (Amendment) Act 
 2024 (Act A1727) (Malaysia)\n\nSource: https://www.pdp.gov.my/ppdpv1/en/pe
 rsonal-data-protection-amendment-act-2024-commencement-date-determination/
 \n\nhttps://regulations.fru.dev/regulations/my-pdpa
URL:https://regulations.fru.dev/regulations/my-pdpa
CATEGORIES:Malaysia,privacy,breach-notification,biometrics,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-227@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20250408
DTEND;VALUE=DATE:20250409
SUMMARY:DOJ Bulk Data Rule: Prohibitions and restrictions take effect
DESCRIPTION:Core prohibitions on covered data transactions and security req
 uirements for restricted transactions apply.\n\nPreventing Access to U.S. 
 Sensitive Personal Data and Government-Related Data by Countries of Concer
 n or Covered Persons (28 CFR Part 202) - DOJ Data Security Program (United
  States (Federal))\n\nSource: https://www.federalregister.gov/documents/20
 25/01/08/2024-31486/preventing-access-to-us-sensitive-personal-data-and-go
 vernment-related-data-by-countries-of-concern\n\nhttps://regulations.fru.d
 ev/regulations/us-doj-bulk-data
URL:https://regulations.fru.dev/regulations/us-doj-bulk-data
CATEGORIES:United States (Federal),privacy,data-residency,cybersecurity,bio
 metrics,health,financial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-158@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20250416
DTEND;VALUE=DATE:20250417
SUMMARY:UK Online Safety Act: Children's access assessments due
DESCRIPTION:Services had to complete children's access assessments to deter
 mine whether children are likely to access them.\n\nOnline Safety Act 2023
  (United Kingdom)\n\nSource: https://www.ofcom.org.uk/online-safety/protec
 ting-children/protection-of-children-duties-under-the-online-safety-act\n\
 nhttps://regulations.fru.dev/regulations/uk-osa
URL:https://regulations.fru.dev/regulations/uk-osa
CATEGORIES:United Kingdom,online-safety,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-103@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20250417
DTEND;VALUE=DATE:20250418
SUMMARY:NIS2: Member States establish entity lists
DESCRIPTION:Member States had to establish lists of essential and important
  entities and notify the Commission of entity numbers (Art 3(3) and (5)). 
 Repeated every two years.\n\nDirective (EU) 2022/2555 on measures for a hi
 gh common level of cybersecurity across the Union (NIS2 Directive) (Europe
 an Union)\n\nSource: https://eur-lex.europa.eu/eli/dir/2022/2555/oj\n\nhtt
 ps://regulations.fru.dev/regulations/eu-nis2
URL:https://regulations.fru.dev/regulations/eu-nis2
CATEGORIES:European Union,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6941@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20250421
DTEND;VALUE=DATE:20250422
SUMMARY:Arkansas COPPA 2.0: Approved by Governor
DESCRIPTION:Became Act 952.\n\nArkansas Children and Teens' Online Privacy 
 Protection Act (Act 952 of 2025\, HB 1717) (Arkansas)\n\nSource: https://a
 rkleg.state.ar.us/Bills/Detail?id=HB1717&ddBienniumSession=2025%2F2025R\n\
 nhttps://regulations.fru.dev/regulations/us-ar-cttoppa
URL:https://regulations.fru.dev/regulations/us-ar-cttoppa
CATEGORIES:Arkansas,children,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-72@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20250430
DTEND;VALUE=DATE:20250501
SUMMARY:DORA: First registers of information submitted to the ESAs
DESCRIPTION:Competent authorities had to submit financial entities' registe
 rs of ICT third-party contractual arrangements (reference date 31 Mar 2025
 ) to the ESAs by 30 Apr 2025. National authorities set earlier deadlines f
 or entities.\n\nRegulation (EU) 2022/2554 on digital operational resilienc
 e for the financial sector (Digital Operational Resilience Act) (European 
 Union)\n\nSource: https://www.eba.europa.eu/publications-and-media/press-r
 eleases/esas-announce-timeline-collect-information-designation-critical-ic
 t-third-party-service-providers\n\nhttps://regulations.fru.dev/regulations
 /eu-dora
URL:https://regulations.fru.dev/regulations/eu-dora
CATEGORIES:European Union,cybersecurity,financial,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-35@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20250501
DTEND;VALUE=DATE:20250502
SUMMARY:China PI Compliance Audit Measures: PI compliance audit measures ta
 ke effect
DESCRIPTION:Self-audit and regulator-ordered audit regime applies\; 10M+ pr
 ocessors must audit at least every two years.\n\nAdministrative Measures f
 or Personal Information Protection Compliance Audits (CAC Order No. 18) (C
 hina)\n\nSource: https://www.cac.gov.cn/2025-02/14/c_1741233507681519.htm\
 n\nhttps://regulations.fru.dev/regulations/cn-pi-compliance-audit
URL:https://regulations.fru.dev/regulations/cn-pi-compliance-audit
CATEGORIES:China,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-275@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20250501
DTEND;VALUE=DATE:20250502
SUMMARY:NYDFS Cybersecurity Regulation (Part 500): Vulnerability scans\, ac
 cess privileges\, malware controls\, Class A monitoring
DESCRIPTION:500.5(a)(2) automated scans\, 500.7 access privilege restrictio
 ns\, 500.14(a)(2) malicious code protection\, and 500.14(b) Class A endpoi
 nt detection and centralized logging apply.\n\nNew York DFS Cybersecurity 
 Requirements for Financial Services Companies (23 NYCRR Part 500)\, Second
  Amendment (New York)\n\nSource: https://www.dfs.ny.gov/cybersecurity/23-N
 YCRR-Part-500\n\nhttps://regulations.fru.dev/regulations/us-ny-dfs-500
URL:https://regulations.fru.dev/regulations/us-ny-dfs-500
CATEGORIES:New York,cybersecurity,breach-notification,financial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-306@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20250507
DTEND;VALUE=DATE:20250508
SUMMARY:Utah AI Policy Act: SB 226 amendments effective
DESCRIPTION:Disclosure duties narrowed (on clear request or high-risk inter
 actions)\, safe harbor added\, provisions recodified in Title 13\, Ch. 75.
 \n\nUtah Artificial Intelligence Policy Act (SB 149\, 2024)\, as amended b
 y SB 226 and SB 332 (2025) (Utah)\n\nSource: https://le.utah.gov/~2025/bil
 ls/static/SB0226.html\n\nhttps://regulations.fru.dev/regulations/us-ut-aip
 a
URL:https://regulations.fru.dev/regulations/us-ut-aipa
CATEGORIES:Utah,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6928@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20250507
DTEND;VALUE=DATE:20250508
SUMMARY:Utah App Store Accountability Act: Act takes effect
DESCRIPTION:Definitions and general provisions effective.\n\nUtah App Store
  Accountability Act (SB 142) (Utah)\n\nSource: https://le.utah.gov/Session
 /2025/bills/enrolled/SB0142.pdf\n\nhttps://regulations.fru.dev/regulations
 /us-ut-app-store
URL:https://regulations.fru.dev/regulations/us-ut-app-store
CATEGORIES:Utah,children,privacy,online-safety
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6912@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20250509
DTEND;VALUE=DATE:20250510
SUMMARY:NY Algorithmic Pricing Disclosure Act: Signed as part of FY2026 bud
 get
DESCRIPTION:S3008C Part X signed as Chapter 58 of 2025.\n\nNew York Algorit
 hmic Pricing Disclosure Act (General Business Law section 349-a) (New York
 )\n\nSource: https://www.nysenate.gov/legislation/bills/2025/S3008/amendme
 nt/C\n\nhttps://regulations.fru.dev/regulations/us-ny-algo-pricing
URL:https://regulations.fru.dev/regulations/us-ny-algo-pricing
CATEGORIES:New York,privacy,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-298@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20250519
DTEND;VALUE=DATE:20250520
SUMMARY:TAKE IT DOWN Act: Criminal provisions effective on enactment
DESCRIPTION:Publishing or threatening to publish non-consensual intimate im
 ages\, including digital forgeries\, became a federal crime upon signature
 .\n\nTools to Address Known Exploitation by Immobilizing Technological Dee
 pfakes on Websites and Networks Act (TAKE IT DOWN Act) (United States (Fed
 eral))\n\nSource: https://www.govinfo.gov/content/pkg/PLAW-119publ12/html/
 PLAW-119publ12.htm\n\nhttps://regulations.fru.dev/regulations/us-take-it-d
 own
URL:https://regulations.fru.dev/regulations/us-take-it-down
CATEGORIES:United States (Federal),online-safety,ai,children,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-210@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20250523
DTEND;VALUE=DATE:20250524
SUMMARY:Colorado Privacy Act (CPA): SB 25-276 geolocation and sensitive-dat
 a sale amendment effective
DESCRIPTION:Adds precise geolocation data definitions and prohibits selling
  sensitive data without consent (effective on signature).\n\nColorado Priv
 acy Act (SB 21-190)\, C.R.S. 6-1-1301 et seq.\, as amended by HB 24-1130\,
  SB 24-041 and SB 25-276 (Colorado)\n\nSource: https://leg.colorado.gov/bi
 lls/sb25-276\n\nhttps://regulations.fru.dev/regulations/us-co-cpa
URL:https://regulations.fru.dev/regulations/us-co-cpa
CATEGORIES:Colorado,privacy,children,biometrics
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6993@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20250523
DTEND;VALUE=DATE:20250524
SUMMARY:Japan Active Cyber Defense Act: Act promulgated
DESCRIPTION:Act No. 42 of 2025 promulgated\; preparatory supplementary prov
 isions apply from this day.\n\nAct on the Prevention of Damage from Unauth
 orized Acts against Important Computers (Act No. 42 of 2025) (Japan)\n\nSo
 urce: https://laws.e-gov.go.jp/api/2/law_revisions/507AC0000000042?respons
 e_format=json\n\nhttps://regulations.fru.dev/regulations/jp-active-cyber-d
 efense
URL:https://regulations.fru.dev/regulations/jp-active-cyber-defense
CATEGORIES:Japan,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6924@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20250527
DTEND;VALUE=DATE:20250528
SUMMARY:Texas App Store Accountability Act: Signed by Governor
DESCRIPTION:SB 2420 signed.\n\nTexas App Store Accountability Act (SB 2420)
  (Texas)\n\nSource: https://capitol.texas.gov/BillLookup/History.aspx?LegS
 ess=89R&Bill=SB2420\n\nhttps://regulations.fru.dev/regulations/us-tx-app-s
 tore
URL:https://regulations.fru.dev/regulations/us-tx-app-store
CATEGORIES:Texas,children,privacy,online-safety
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-2@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20250530
DTEND;VALUE=DATE:20250531
SUMMARY:Australia Cyber Security Act (ransomware reporting): Ransomware pay
 ment reporting starts
DESCRIPTION:Reporting business entities must report ransomware/cyber-extort
 ion payments to ASD within 72 hours of payment.\n\nCyber Security Act 2024
  (Cth) and Cyber Security (Ransomware Payment Reporting) Rules 2025 (Austr
 alia)\n\nSource: https://www.homeaffairs.gov.au/cyber-security-subsite/fil
 es/factsheet-ransomware-payment-reporting.pdf\n\nhttps://regulations.fru.d
 ev/regulations/au-cyber-security-act
URL:https://regulations.fru.dev/regulations/au-cyber-security-act
CATEGORIES:Australia,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6938@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20250530
DTEND;VALUE=DATE:20250531
SUMMARY:Nebraska Kids Code: Approved by Governor
DESCRIPTION:LB 504 signed.\n\nNebraska Age-Appropriate Online Design Code A
 ct (LB 504) (Nebraska)\n\nSource: https://nebraskalegislature.gov/FloorDoc
 s/109/PDF/Slip/LB504.pdf\n\nhttps://regulations.fru.dev/regulations/us-ne-
 aadc
URL:https://regulations.fru.dev/regulations/us-ne-aadc
CATEGORIES:Nebraska,children,privacy,online-safety
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6986@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20250601
DTEND;VALUE=DATE:20250602
SUMMARY:China Facial Recognition Measures: Facial recognition measures take
  effect
DESCRIPTION:Consent\, impact assessment\, storage and filing duties apply.\
 n\nMeasures for the Security Management of Facial Recognition Technology A
 pplications (China)\n\nSource: https://www.cac.gov.cn/2025-03/21/c_1744174
 262156096.htm\n\nhttps://regulations.fru.dev/regulations/cn-facial-recogni
 tion
URL:https://regulations.fru.dev/regulations/cn-facial-recognition
CATEGORIES:China,biometrics,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-131@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20250601
DTEND;VALUE=DATE:20250602
SUMMARY:Malaysia PDPA: PDPA amendments phase 3
DESCRIPTION:Mandatory DPO appointment\, data breach notification\, and data
  portability take effect.\n\nPersonal Data Protection Act 2010 (Act 709)\,
  as amended by the Personal Data Protection (Amendment) Act 2024 (Act A172
 7) (Malaysia)\n\nSource: https://www.pdp.gov.my/ppdpv1/en/personal-data-pr
 otection-amendment-act-2024-commencement-date-determination/\n\nhttps://re
 gulations.fru.dev/regulations/my-pdpa
URL:https://regulations.fru.dev/regulations/my-pdpa
CATEGORIES:Malaysia,privacy,breach-notification,biometrics,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-265@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20250602
DTEND;VALUE=DATE:20250603
SUMMARY:New Jersey NJDPA: Division of Consumer Affairs proposes NJDPA rules
  (N.J.A.C. 13:45L)
DESCRIPTION:Proposed rules published at 57 N.J.R. 1101(a)\; comments were d
 ue Aug 1\, 2025.\n\nNew Jersey Data Privacy Act (P.L.2023\, c.266\; S332) 
 (New Jersey)\n\nSource: https://www.njoag.gov/murphy-administration-announ
 ces-proposed-rules-establishing-comprehensive-consumer-data-privacy-protec
 tions/\n\nhttps://regulations.fru.dev/regulations/us-nj-njdpa
URL:https://regulations.fru.dev/regulations/us-nj-njdpa
CATEGORIES:New Jersey,privacy,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-119@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20250604
DTEND;VALUE=DATE:20250605
SUMMARY:Japan AI Promotion Act: AI Promotion Act promulgated and partly in 
 force
DESCRIPTION:Most provisions\, including basic principles and stakeholder du
 ties\, take effect on promulgation.\n\nAct on Promotion of Research and De
 velopment\, and Utilization of Artificial Intelligence-Related Technology 
 (Japan)\n\nSource: https://www8.cao.go.jp/cstp/ai/ai_act/ai_act.html\n\nht
 tps://regulations.fru.dev/regulations/jp-ai-act
URL:https://regulations.fru.dev/regulations/jp-ai-act
CATEGORIES:Japan,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-5@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20250610
DTEND;VALUE=DATE:20250611
SUMMARY:Australia Privacy Act: Statutory tort for serious invasions of priv
 acy commences
DESCRIPTION:Individuals can sue for serious invasions of privacy (Schedule 
 2)\, 6 months after Royal Assent.\n\nPrivacy Act 1988 (Cth)\, as amended b
 y the Privacy and Other Legislation Amendment Act 2024 (Australia)\n\nSour
 ce: https://www.legislation.gov.au/C2024A00128/asmade\n\nhttps://regulatio
 ns.fru.dev/regulations/au-privacy-act
URL:https://regulations.fru.dev/regulations/au-privacy-act
CATEGORIES:Australia,privacy,children,breach-notification,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6946@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20250611
DTEND;VALUE=DATE:20250612
SUMMARY:Alberta POPA: POPA in force
DESCRIPTION:Act comes into force with the Access to Information Act\, procl
 aimed in force June 11\, 2025.\n\nProtection of Privacy Act (Alberta\, Can
 ada)\n\nSource: https://kings-printer.alberta.ca/1266.cfm?page=p28p5.cfm&l
 eg_type=Acts&isbncln=9780779861309&display=html\n\nhttps://regulations.fru
 .dev/regulations/ca-ab-popa
URL:https://regulations.fru.dev/regulations/ca-ab-popa
CATEGORIES:Alberta\, Canada,privacy,breach-notification,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6936@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20250612
DTEND;VALUE=DATE:20250613
SUMMARY:Vermont Kids Code: Signed by Governor
DESCRIPTION:Became Act 63.\n\nVermont Age-Appropriate Design Code (Act 63 o
 f 2025\, S.69) (Vermont)\n\nSource: https://legislature.vermont.gov/bill/s
 tatus/2026/S.69\n\nhttps://regulations.fru.dev/regulations/us-vt-aadc
URL:https://regulations.fru.dev/regulations/us-vt-aadc
CATEGORIES:Vermont,children,privacy,online-safety
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-16@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20250618
DTEND;VALUE=DATE:20250619
SUMMARY:Canada Bill C-8 / CCSPA: Bill C-8 introduced
DESCRIPTION:First reading in the House of Commons.\n\nCritical Cyber System
 s Protection Act (enacted by Bill C-8\, An Act respecting cyber security) 
 (Canada)\n\nSource: https://www.parl.ca/legisinfo/en/bill/45-1/c-8\n\nhttp
 s://regulations.fru.dev/regulations/ca-ccspa
URL:https://regulations.fru.dev/regulations/ca-ccspa
CATEGORIES:Canada,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-148@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20250619
DTEND;VALUE=DATE:20250620
SUMMARY:Data (Use and Access) Act: Royal Assent
DESCRIPTION:The Act receives Royal Assent\; commencement staged by regulati
 ons.\n\nData (Use and Access) Act 2025 (United Kingdom)\n\nSource: https:/
 /www.legislation.gov.uk/ukpga/2025/18/contents\n\nhttps://regulations.fru.
 dev/regulations/uk-duaa
URL:https://regulations.fru.dev/regulations/uk-duaa
CATEGORIES:United Kingdom,privacy,data-access,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6919@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20250620
DTEND;VALUE=DATE:20250621
SUMMARY:NY Child Data Protection Act: Takes effect
DESCRIPTION:Effective one year after becoming law.\n\nNew York Child Data P
 rotection Act (New York)\n\nSource: https://www.nysenate.gov/legislation/b
 ills/2023/S7695/amendment/B\n\nhttps://regulations.fru.dev/regulations/us-
 ny-cdpa
URL:https://regulations.fru.dev/regulations/us-ny-cdpa
CATEGORIES:New York,children,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-303@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20250622
DTEND;VALUE=DATE:20250623
SUMMARY:TRAIGA: HB 149 signed
DESCRIPTION:Governor Abbott signs TRAIGA.\n\nTexas Responsible Artificial I
 ntelligence Governance Act (HB 149\, 89th Legislature) (Texas)\n\nSource: 
 https://capitol.texas.gov/BillLookup/History.aspx?LegSess=89R&Bill=HB149\n
 \nhttps://regulations.fru.dev/regulations/us-tx-traiga
URL:https://regulations.fru.dev/regulations/us-tx-traiga
CATEGORIES:Texas,ai,biometrics
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-213@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20250623
DTEND;VALUE=DATE:20250624
SUMMARY:COPPA Rule: Amended COPPA Rule takes effect
DESCRIPTION:The April 2025 amendments to 16 CFR Part 312 became effective\;
  during the transition operators could comply with either the pre-2025 or 
 the amended Rule.\n\nChildren's Online Privacy Protection Rule (16 CFR Par
 t 312)\, as amended April 2025 (United States (Federal))\n\nSource: https:
 //www.federalregister.gov/documents/2025/04/22/2025-05904/childrens-online
 -privacy-protection-rule\n\nhttps://regulations.fru.dev/regulations/us-cop
 pa
URL:https://regulations.fru.dev/regulations/us-coppa
CATEGORIES:United States (Federal),privacy,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6897@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20250627
DTEND;VALUE=DATE:20250628
SUMMARY:California ADS employment regulations: OAL approves regulations
DESCRIPTION:Office of Administrative Law approves the Civil Rights Council'
 s ADS rules.\n\nCivil Rights Council Regulations on Automated-Decision Sys
 tems in Employment (FEHA) (California)\n\nSource: https://calcivilrights.c
 a.gov/2025/06/30/civil-rights-council-secures-approval-for-regulations-to-
 protect-against-employment-discrimination-related-to-artificial-intelligen
 ce/\n\nhttps://regulations.fru.dev/regulations/us-ca-ads-regs
URL:https://regulations.fru.dev/regulations/us-ca-ads-regs
CATEGORIES:California,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6931@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20250630
DTEND;VALUE=DATE:20250701
SUMMARY:Louisiana app store age verification law: Signed by Governor
DESCRIPTION:Became Act 481 of the 2025 Regular Session.\n\nLouisiana Act 48
 1 of 2025 on Minors' Use of Applications (HB 570) (Louisiana)\n\nSource: h
 ttps://legis.la.gov/legis/BillInfo.aspx?s=25RS&b=HB570&sbi=y\n\nhttps://re
 gulations.fru.dev/regulations/us-la-app-store
URL:https://regulations.fru.dev/regulations/us-la-app-store
CATEGORIES:Louisiana,children,privacy,online-safety
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-211@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20250701
DTEND;VALUE=DATE:20250702
SUMMARY:Colorado Privacy Act (CPA): Biometric identifier amendment (HB 24-1
 130) effective
DESCRIPTION:Any controller processing biometric identifiers must adopt a wr
 itten biometric policy\, give notice\, obtain consent and follow retention
 /deletion rules.\n\nColorado Privacy Act (SB 21-190)\, C.R.S. 6-1-1301 et 
 seq.\, as amended by HB 24-1130\, SB 24-041 and SB 25-276 (Colorado)\n\nSo
 urce: https://leg.colorado.gov/bills/hb24-1130\n\nhttps://regulations.fru.
 dev/regulations/us-co-cpa
URL:https://regulations.fru.dev/regulations/us-co-cpa
CATEGORIES:Colorado,privacy,children,biometrics
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6969@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20250701
DTEND;VALUE=DATE:20250702
SUMMARY:Digital Services Act: DSA transparency report templates mandatory
DESCRIPTION:Implementing Regulation (EU) 2024/2835 requires all intermediar
 y services to use harmonised templates for content moderation data collect
 ed from this date.\n\nRegulation (EU) 2022/2065 on a Single Market for Dig
 ital Services (Digital Services Act) (European Union)\n\nSource: https://e
 ur-lex.europa.eu/eli/reg_impl/2024/2835/oj/eng\n\nhttps://regulations.fru.
 dev/regulations/eu-dsa
URL:https://regulations.fru.dev/regulations/eu-dsa
CATEGORIES:European Union,online-safety,children,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6945@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20250701
DTEND;VALUE=DATE:20250702
SUMMARY:Ontario Bill 194: FIPPA privacy amendments in force
DESCRIPTION:Remaining FIPPA amendments\, including privacy impact assessmen
 ts\, safeguards and breach notification to the IPC\, come into force.\n\nS
 trengthening Cyber Security and Building Trust in the Public Sector Act\, 
 2024 (Ontario\, Canada)\n\nSource: https://www.ontario.ca/laws/oic/o250361
 \n\nhttps://regulations.fru.dev/regulations/ca-on-bill194
URL:https://regulations.fru.dev/regulations/ca-on-bill194
CATEGORIES:Ontario\, Canada,cybersecurity,ai,privacy,children,breach-notifi
 cation
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-284@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20250701
DTEND;VALUE=DATE:20250702
SUMMARY:Oregon OCPA: OCPA applies to nonprofits
DESCRIPTION:Nonprofit organizations meeting the thresholds become subject t
 o OCPA.\n\nOregon Consumer Privacy Act (SB 619\, 2023) (Oregon)\n\nSource:
  https://www.doj.state.or.us/consumer-protection/for-businesses/privacy-la
 w-faqs-for-nonprofits/\n\nhttps://regulations.fru.dev/regulations/us-or-oc
 pa
URL:https://regulations.fru.dev/regulations/us-or-ocpa
CATEGORIES:Oregon,privacy,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-300@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20250701
DTEND;VALUE=DATE:20250702
SUMMARY:Tennessee TIPA: TIPA takes effect
DESCRIPTION:Controller and processor obligations and consumer rights under 
 Tenn. Code Ann. 47-18-3301 et seq. apply.\n\nTennessee Information Protect
 ion Act (HB 1181 / SB 73\, 2023) (Tennessee)\n\nSource: https://wapp.capit
 ol.tn.gov/apps/BillInfo/Default.aspx?BillNumber=HB1181&GA=113\n\nhttps://r
 egulations.fru.dev/regulations/us-tn-tipa
URL:https://regulations.fru.dev/regulations/us-tn-tipa
CATEGORIES:Tennessee,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-7018@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20250701
DTEND;VALUE=DATE:20250702
SUMMARY:Vietnam Law on Data: Law on Data takes effect
DESCRIPTION:The Law on Data enters into force.\n\nLaw on Data (Law No. 60/2
 024/QH15) (Vietnam)\n\nSource: https://vanban.chinhphu.vn/?pageid=27160&do
 cid=212488\n\nhttps://regulations.fru.dev/regulations/vn-data-law
URL:https://regulations.fru.dev/regulations/vn-data-law
CATEGORIES:Vietnam,data-residency,data-access,cybersecurity
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-73@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20250708
DTEND;VALUE=DATE:20250709
SUMMARY:DORA: TLPT regulatory technical standards enter into force
DESCRIPTION:Commission Delegated Regulation (EU) 2025/1190 (published 18 Ju
 ne 2025) sets criteria for which financial entities must run threat-led pe
 netration testing\, plus methodology and tester requirements.\n\nRegulatio
 n (EU) 2022/2554 on digital operational resilience for the financial secto
 r (Digital Operational Resilience Act) (European Union)\n\nSource: https:/
 /eur-lex.europa.eu/eli/reg_del/2025/1190/oj\n\nhttps://regulations.fru.dev
 /regulations/eu-dora
URL:https://regulations.fru.dev/regulations/eu-dora
CATEGORIES:European Union,cybersecurity,financial,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-266@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20250715
DTEND;VALUE=DATE:20250716
SUMMARY:New Jersey NJDPA: Universal opt-out mechanism must be honored
DESCRIPTION:Controllers that sell personal data or process it for targeted 
 advertising must honor user-selected universal opt-out signals within six 
 months of the effective date (N.J.S.A. 56:8-166.11).\n\nNew Jersey Data Pr
 ivacy Act (P.L.2023\, c.266\; S332) (New Jersey)\n\nSource: https://pub.nj
 leg.state.nj.us/Bills/2022/PL23/266_.PDF\n\nhttps://regulations.fru.dev/re
 gulations/us-nj-njdpa
URL:https://regulations.fru.dev/regulations/us-nj-njdpa
CATEGORIES:New Jersey,privacy,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-159@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20250725
DTEND;VALUE=DATE:20250726
SUMMARY:UK Online Safety Act: Protection of children duties apply
DESCRIPTION:Children's safety duties and Protection of Children Codes take 
 effect\, including highly effective age assurance\; children's risk assess
 ments due by 24 July 2025.\n\nOnline Safety Act 2023 (United Kingdom)\n\nS
 ource: https://www.ofcom.org.uk/online-safety/protecting-children/protecti
 on-of-children-duties-under-the-online-safety-act\n\nhttps://regulations.f
 ru.dev/regulations/uk-osa
URL:https://regulations.fru.dev/regulations/uk-osa
CATEGORIES:United Kingdom,online-safety,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6881@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20250729
DTEND;VALUE=DATE:20250730
SUMMARY:CFPB Open Banking Rule (Section 1033): Court stays Forcht Bank liti
 gation
DESCRIPTION:E.D. Ky. stays the industry challenge after the CFPB says it wi
 ll reconsider the rule\; compliance dates stayed by 90 days.\n\nRequired R
 ulemaking on Personal Financial Data Rights (12 CFR Part 1033) (United Sta
 tes)\n\nSource: https://www.federalregister.gov/documents/2025/08/22/2025-
 16139/personal-financial-data-rights-reconsideration\n\nhttps://regulation
 s.fru.dev/regulations/us-cfpb-1033
URL:https://regulations.fru.dev/regulations/us-cfpb-1033
CATEGORIES:United States,data-access,financial,privacy,cybersecurity
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-255@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20250731
DTEND;VALUE=DATE:20250801
SUMMARY:Minnesota Consumer Data Privacy Act (MCDPA): MCDPA takes effect
DESCRIPTION:Consumer rights and controller/processor obligations apply (pos
 tsecondary institutions excepted).\n\nMinnesota Consumer Data Privacy Act 
 (HF 4757\, 2024 Minn. Laws ch. 121\, art. 5)\, Minn. Stat. 325M.10-325M.21
  (Minnesota)\n\nSource: https://www.revisor.mn.gov/statutes/cite/325M.20\n
 \nhttps://regulations.fru.dev/regulations/us-mn-mcdpa
URL:https://regulations.fru.dev/regulations/us-mn-mcdpa
CATEGORIES:Minnesota,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-39@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20250802
DTEND;VALUE=DATE:20250803
SUMMARY:EU AI Act: GPAI\, governance\, notified bodies and penalties apply
DESCRIPTION:Chapter III Section 4 (notifying authorities)\, Chapter V (gene
 ral-purpose AI model obligations)\, Chapter VII (governance)\, Chapter XII
  (penalties\, except Art 101) and Art 78 apply (Art 113(b)).\n\nRegulation
  (EU) 2024/1689 laying down harmonised rules on artificial intelligence (A
 rtificial Intelligence Act)\, as amended by Regulation (EU) 2026/1744 (Dig
 ital Omnibus on AI) (European Union)\n\nSource: https://eur-lex.europa.eu/
 eli/reg/2024/1689/oj\n\nhttps://regulations.fru.dev/regulations/eu-ai-act
URL:https://regulations.fru.dev/regulations/eu-ai-act
CATEGORIES:European Union,ai,biometrics,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-115@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20250814
DTEND;VALUE=DATE:20250815
SUMMARY:Israel Privacy Protection Law Amendment 13: Amendment 13 in force
DESCRIPTION:Amended Privacy Protection Law\, PPA enforcement powers and sta
 tutory damages take effect.\n\nPrivacy Protection Law\, 5741-1981 (Amendme
 nt No. 13) (Israel)\n\nSource: https://www.gov.il/en/departments/the_priva
 cy_protection_authority/govil-landing-page\n\nhttps://regulations.fru.dev/
 regulations/il-ppl-amendment-13
URL:https://regulations.fru.dev/regulations/il-ppl-amendment-13
CATEGORIES:Israel,privacy,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-149@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20250820
DTEND;VALUE=DATE:20250821
SUMMARY:Data (Use and Access) Act: Stage 1 commencement
DESCRIPTION:Technical data protection provisions\, ICO statutory objects\, 
 Smart Data framework (Part 1) and AI/copyright reporting duties commence (
 Commencement No. 1 Regulations 2025).\n\nData (Use and Access) Act 2025 (U
 nited Kingdom)\n\nSource: https://www.legislation.gov.uk/ukpga/2025/18/con
 tents\n\nhttps://regulations.fru.dev/regulations/uk-duaa
URL:https://regulations.fru.dev/regulations/uk-duaa
CATEGORIES:United Kingdom,privacy,data-access,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6882@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20250822
DTEND;VALUE=DATE:20250823
SUMMARY:CFPB Open Banking Rule (Section 1033): Reconsideration ANPR publish
 ed
DESCRIPTION:CFPB seeks comment on representatives\, fees\, data security an
 d privacy\, and on extending compliance dates.\n\nRequired Rulemaking on P
 ersonal Financial Data Rights (12 CFR Part 1033) (United States)\n\nSource
 : https://www.federalregister.gov/documents/2025/08/22/2025-16139/personal
 -financial-data-rights-reconsideration\n\nhttps://regulations.fru.dev/regu
 lations/us-cfpb-1033
URL:https://regulations.fru.dev/regulations/us-cfpb-1033
CATEGORIES:United States,data-access,financial,privacy,cybersecurity
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-14@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20250823
DTEND;VALUE=DATE:20250824
SUMMARY:Brazil LGPD: Deadline to adopt ANPD standard contractual clauses
DESCRIPTION:Agents relying on contractual clauses for international transfe
 rs must incorporate the ANPD-approved SCCs into their contracts within 12 
 months of publication.\n\nLei Geral de Proteção de Dados Pessoais (Law N
 o. 13.709/2018) (Brazil)\n\nSource: https://www.in.gov.br/en/web/dou/-/res
 olucao-cd/anpd-n-19-de-23-de-agosto-de-2024-580095396\n\nhttps://regulatio
 ns.fru.dev/regulations/br-lgpd
URL:https://regulations.fru.dev/regulations/br-lgpd
CATEGORIES:Brazil,privacy,breach-notification,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-200@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20250828
DTEND;VALUE=DATE:20250829
SUMMARY:Colorado AI Act: SB 25B-004 delays the act
DESCRIPTION:Special-session bill pushes the SB 24-205 effective date from F
 ebruary 1\, 2026 to June 30\, 2026.\n\nColorado SB 24-205 (Consumer Protec
 tions for Artificial Intelligence)\, as delayed by SB 25B-004 and repealed
  and reenacted by SB 26-189 (Automated Decision-Making Technology) (Colora
 do)\n\nSource: https://leg.colorado.gov/bills/sb25b-004\n\nhttps://regulat
 ions.fru.dev/regulations/us-co-ai-act
URL:https://regulations.fru.dev/regulations/us-co-ai-act
CATEGORIES:Colorado,ai,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-29@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20250901
DTEND;VALUE=DATE:20250902
SUMMARY:China AI Content Labeling Measures: AI content labeling measures an
 d GB 45438-2025 take effect
DESCRIPTION:Explicit and implicit labeling duties for AI-generated content 
 and platform detection duties apply.\n\nMeasures for Labeling AI-Generated
  Synthetic Content (China)\n\nSource: https://www.cac.gov.cn/2025-03/14/c_
 1743654684782215.htm\n\nhttps://regulations.fru.dev/regulations/cn-ai-labe
 ling
URL:https://regulations.fru.dev/regulations/cn-ai-labeling
CATEGORIES:China,ai,online-safety
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-120@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20250901
DTEND;VALUE=DATE:20250902
SUMMARY:Japan AI Promotion Act: AI Promotion Act fully in force
DESCRIPTION:Provisions establishing the AI Strategy Headquarters and AI Bas
 ic Plan take effect.\n\nAct on Promotion of Research and Development\, and
  Utilization of Artificial Intelligence-Related Technology (Japan)\n\nSour
 ce: https://www8.cao.go.jp/cstp/ai/ai_act/ai_act.html\n\nhttps://regulatio
 ns.fru.dev/regulations/jp-ai-act
URL:https://regulations.fru.dev/regulations/jp-ai-act
CATEGORIES:Japan,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-109@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20250903
DTEND;VALUE=DATE:20250904
SUMMARY:EU-US Data Privacy Framework: General Court upholds DPF (Latombe v 
 Commission)
DESCRIPTION:General Court dismissed Philippe Latombe's action for annulment
  (Case T-553/23) and confirmed the US offered adequate protection when the
  decision was adopted.\n\nCommission Implementing Decision (EU) 2023/1795 
 on the adequate level of protection of personal data under the EU-US Data 
 Privacy Framework (European Union)\n\nSource: https://curia.europa.eu/jcms
 /upload/docs/application/pdf/2025-09/cp250106en.pdf\n\nhttps://regulations
 .fru.dev/regulations/eu-us-dpf
URL:https://regulations.fru.dev/regulations/eu-us-dpf
CATEGORIES:European Union,privacy,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6962@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20250909
DTEND;VALUE=DATE:20250910
SUMMARY:Peru AI Law and Regulation: Regulation published
DESCRIPTION:DS 115-2025-PCM approving the AI regulation published in El Per
 uano.\n\nLey N° 31814\, Ley que promueve el uso de la inteligencia artifi
 cial en favor del desarrollo económico y social del país\, and its Regul
 ation (Decreto Supremo N° 115-2025-PCM) (Peru)\n\nSource: https://www.gob
 .pe/institucion/pcm/normas-legales/7133522-115-2025-pcm\n\nhttps://regulat
 ions.fru.dev/regulations/pe-ai-law
URL:https://regulations.fru.dev/regulations/pe-ai-law
CATEGORIES:Peru,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-57@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20250912
DTEND;VALUE=DATE:20250913
SUMMARY:EU Data Act: Data Act applies
DESCRIPTION:Most obligations apply\, including user data access and sharing
  (Chapters II-III)\, cloud switching (Chapter VI) and interoperability\; C
 hapter IV unfair terms apply to contracts concluded after this date (Art 5
 0).\n\nRegulation (EU) 2023/2854 on harmonised rules on fair access to and
  use of data (Data Act) (European Union)\n\nSource: https://eur-lex.europa
 .eu/eli/reg/2023/2854/oj\n\nhttps://regulations.fru.dev/regulations/eu-dat
 a-act
URL:https://regulations.fru.dev/regulations/eu-data-act
CATEGORIES:European Union,data-access,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-58@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20250912
DTEND;VALUE=DATE:20250913
SUMMARY:EU Data Act: Member States notify penalty rules
DESCRIPTION:Member States had to notify the Commission of their penalty rul
 es (Art 40(2)).\n\nRegulation (EU) 2023/2854 on harmonised rules on fair a
 ccess to and use of data (Data Act) (European Union)\n\nSource: https://eu
 r-lex.europa.eu/eli/reg/2023/2854/oj\n\nhttps://regulations.fru.dev/regula
 tions/eu-data-act
URL:https://regulations.fru.dev/regulations/eu-data-act
CATEGORIES:European Union,data-access,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-133@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20250919
DTEND;VALUE=DATE:20250920
SUMMARY:Nigeria NDPA: GAID 2025 takes effect
DESCRIPTION:General Application and Implementation Directive becomes effect
 ive\, replacing the NDPR 2019 and NDPR Implementation Framework.\n\nNigeri
 a Data Protection Act\, 2023 and NDPA General Application and Implementati
 on Directive (GAID) 2025 (Nigeria)\n\nSource: https://ndpc.gov.ng/resource
 s/\n\nhttps://regulations.fru.dev/regulations/ng-ndpa
URL:https://regulations.fru.dev/regulations/ng-ndpa
CATEGORIES:Nigeria,privacy,breach-notification,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-167@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20250922
DTEND;VALUE=DATE:20250923
SUMMARY:CCPA / CPRA: ADMT\, risk assessment and cybersecurity audit regulat
 ions approved
DESCRIPTION:OAL approves the CCPA Updates\, Cybersecurity Audit\, Risk Asse
 ssment\, ADMT and Insurance regulations and files them with the Secretary 
 of State.\n\nCalifornia Consumer Privacy Act of 2018\, as amended by the C
 alifornia Privacy Rights Act of 2020 (Cal. Civ. Code 1798.100 et seq.) and
  CPPA regulations (Cal. Code Regs. tit. 11\, 7000 et seq.) (California)\n\
 nSource: https://cppa.ca.gov/regulations/ccpa_updates.html\n\nhttps://regu
 lations.fru.dev/regulations/us-ca-ccpa
URL:https://regulations.fru.dev/regulations/us-ca-ccpa
CATEGORIES:California,privacy,ai,cybersecurity,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-65@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20250924
DTEND;VALUE=DATE:20250925
SUMMARY:Data Governance Act: Legacy data intermediaries must comply
DESCRIPTION:Entities that were already providing data intermediation servic
 es on 23 June 2022 had to comply with Chapter III by 24 Sep 2025 (Art 37).
 \n\nRegulation (EU) 2022/868 on European data governance (Data Governance 
 Act) (European Union)\n\nSource: https://eur-lex.europa.eu/eli/reg/2022/86
 8/oj\n\nhttps://regulations.fru.dev/regulations/eu-dga
URL:https://regulations.fru.dev/regulations/eu-dga
CATEGORIES:European Union,data-access,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-135@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20250924
DTEND;VALUE=DATE:20250925
SUMMARY:New Zealand Privacy Act: Privacy Amendment Act 2025 technical chang
 es commence
DESCRIPTION:Technical amendments commence the day after Royal Assent (23 Se
 p 2025).\n\nPrivacy Act 2020 (New Zealand)\, as amended by the Privacy Ame
 ndment Act 2025 (New Zealand)\n\nSource: https://www.justice.govt.nz/justi
 ce-sector-policy/key-initiatives/enhancing-the-privacy-act/\n\nhttps://reg
 ulations.fru.dev/regulations/nz-privacy-act
URL:https://regulations.fru.dev/regulations/nz-privacy-act
CATEGORIES:New Zealand,privacy,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-184@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20250929
DTEND;VALUE=DATE:20250930
SUMMARY:California SB 53 (TFAIA): SB 53 signed
DESCRIPTION:Governor Newsom signs SB 53 (chapter 138).\n\nCalifornia SB 53\
 , Transparency in Frontier Artificial Intelligence Act (Stats. 2025\, ch. 
 138) (California)\n\nSource: https://leginfo.legislature.ca.gov/faces/bill
 NavClient.xhtml?bill_id=202520260SB53\n\nhttps://regulations.fru.dev/regul
 ations/us-ca-sb53
URL:https://regulations.fru.dev/regulations/us-ca-sb53
CATEGORIES:California,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6956@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20250930
DTEND;VALUE=DATE:20251001
SUMMARY:Peru PDPL and 2024 Regulation: Data portability applies
DESCRIPTION:Article 76 on portability takes effect six months after the reg
 ulation enters into force.\n\nTentative: depends on a proposal not yet ado
 pted.\n\nLey N° 29733\, Ley de Protección de Datos Personales\, and its 
 Regulation (Decreto Supremo N° 016-2024-JUS) (Peru)\n\nSource: https://ww
 w.gob.pe/institucion/smv/normas-legales/6426760-016-2024-jus\n\nhttps://re
 gulations.fru.dev/regulations/pe-pdpl
URL:https://regulations.fru.dev/regulations/pe-pdpl
CATEGORIES:Peru,privacy,breach-notification,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6898@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20251001
DTEND;VALUE=DATE:20251002
SUMMARY:California ADS employment regulations: ADS regulations take effect
DESCRIPTION:Rules apply to employment decisions using automated-decision sy
 stems.\n\nCivil Rights Council Regulations on Automated-Decision Systems i
 n Employment (FEHA) (California)\n\nSource: https://calcivilrights.ca.gov/
 2025/06/30/civil-rights-council-secures-approval-for-regulations-to-protec
 t-against-employment-discrimination-related-to-artificial-intelligence/\n\
 nhttps://regulations.fru.dev/regulations/us-ca-ads-regs
URL:https://regulations.fru.dev/regulations/us-ca-ads-regs
CATEGORIES:California,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-212@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20251001
DTEND;VALUE=DATE:20251002
SUMMARY:Colorado Privacy Act (CPA): Minors' data amendment (SB 24-041) effe
 ctive
DESCRIPTION:Controllers offering online services to minors must use reasona
 ble care\, conduct assessments\, and obtain consent for targeted ads\, sal
 e and certain profiling of minors.\n\nColorado Privacy Act (SB 21-190)\, C
 .R.S. 6-1-1301 et seq.\, as amended by HB 24-1130\, SB 24-041 and SB 25-27
 6 (Colorado)\n\nSource: https://leg.colorado.gov/bills/sb24-041\n\nhttps:/
 /regulations.fru.dev/regulations/us-co-cpa
URL:https://regulations.fru.dev/regulations/us-co-cpa
CATEGORIES:Colorado,privacy,children,biometrics
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-252@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20251001
DTEND;VALUE=DATE:20251002
SUMMARY:Maryland Online Data Privacy Act (MODPA): MODPA takes effect
DESCRIPTION:Act takes effect\; data protection assessments apply to process
 ing activities on or after Oct 1\, 2025.\n\nMaryland Online Data Privacy A
 ct of 2024 (SB 541 / HB 567)\, Md. Code\, Com. Law 14-4601 et seq. (Maryla
 nd)\n\nSource: https://mgaleg.maryland.gov/2024RS/Chapters_noln/CH_455_sb0
 541e.pdf\n\nhttps://regulations.fru.dev/regulations/us-md-modpa
URL:https://regulations.fru.dev/regulations/us-md-modpa
CATEGORIES:Maryland,privacy,children,health,biometrics
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-259@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20251001
DTEND;VALUE=DATE:20251002
SUMMARY:Montana Consumer Data Privacy Act (MCDPA): SB 297 amendments take e
 ffect\; cure period eliminated
DESCRIPTION:Lower thresholds (25\,000 / 15\,000 + 25%)\, minors' data prote
 ctions\, AG assessment demands\; the 60-day cure period is removed.\n\nMon
 tana Consumer Data Privacy Act (SB 384\, 2023)\, Mont. Code Ann. 30-14-280
 1 et seq.\, as amended by SB 297 (2025) (Montana)\n\nSource: https://archi
 ve.legmt.gov/bills/mca/title_0300/chapter_0140/part_0280/section_0170/0300
 -0140-0280-0170.html\n\nhttps://regulations.fru.dev/regulations/us-mt-mcdp
 a
URL:https://regulations.fru.dev/regulations/us-mt-mcdpa
CATEGORIES:Montana,privacy,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-228@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20251006
DTEND;VALUE=DATE:20251007
SUMMARY:DOJ Bulk Data Rule: Due diligence\, audit and reporting obligations
  apply
DESCRIPTION:Subpart J (data compliance program\, due diligence and audits f
 or restricted transactions) and reporting requirements in 202.1103 and 202
 .1104 apply.\n\nPreventing Access to U.S. Sensitive Personal Data and Gove
 rnment-Related Data by Countries of Concern or Covered Persons (28 CFR Par
 t 202) - DOJ Data Security Program (United States (Federal))\n\nSource: ht
 tps://www.federalregister.gov/documents/2025/01/08/2024-31486/preventing-a
 ccess-to-us-sensitive-personal-data-and-government-related-data-by-countri
 es-of-concern\n\nhttps://regulations.fru.dev/regulations/us-doj-bulk-data
URL:https://regulations.fru.dev/regulations/us-doj-bulk-data
CATEGORIES:United States (Federal),privacy,data-residency,cybersecurity,bio
 metrics,health,financial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6910@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20251008
DTEND;VALUE=DATE:20251009
SUMMARY:California social media account deletion: Signed by Governor
DESCRIPTION:Chaptered as Chapter 464\, Statutes of 2025.\n\nAccount Cancell
 ation (AB 656) (California)\n\nSource: https://leginfo.legislature.ca.gov/
 faces/billNavClient.xhtml?bill_id=202520260AB656\n\nhttps://regulations.fr
 u.dev/regulations/us-ca-ab656
URL:https://regulations.fru.dev/regulations/us-ca-ab656
CATEGORIES:California,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6848@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20251010
DTEND;VALUE=DATE:20251011
SUMMARY:EU Political Advertising Regulation (TTPA): TTPA applies
DESCRIPTION:Most of the Regulation applies\, including labelling\, transpar
 ency notices and the targeting restrictions.\n\nRegulation (EU) 2024/900 o
 n the transparency and targeting of political advertising (European Union)
 \n\nSource: https://eur-lex.europa.eu/eli/reg/2024/900/oj/eng\n\nhttps://r
 egulations.fru.dev/regulations/eu-ttpa
URL:https://regulations.fru.dev/regulations/eu-ttpa
CATEGORIES:European Union,privacy,online-safety
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6902@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20251013
DTEND;VALUE=DATE:20251014
SUMMARY:California AI autonomous-harm defense ban: Signed by Governor
DESCRIPTION:Chaptered as Chapter 672\, Statutes of 2025.\n\nArtificial Inte
 lligence: Defenses (AB 316) (California)\n\nSource: https://leginfo.legisl
 ature.ca.gov/faces/billNavClient.xhtml?bill_id=202520260AB316\n\nhttps://r
 egulations.fru.dev/regulations/us-ca-ab316
URL:https://regulations.fru.dev/regulations/us-ca-ab316
CATEGORIES:California,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-188@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20251013
DTEND;VALUE=DATE:20251014
SUMMARY:California AI Transparency Act (SB 942): AB 853 signed
DESCRIPTION:AB 853 (ch. 674) delays the operative date and adds platform an
 d device duties.\n\nCalifornia AI Transparency Act (SB 942\, Stats. 2024\,
  ch. 291)\, as amended by AB 853 (Stats. 2025\, ch. 674) (California)\n\nS
 ource: https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_i
 d=202520260AB853\n\nhttps://regulations.fru.dev/regulations/us-ca-sb942
URL:https://regulations.fru.dev/regulations/us-ca-sb942
CATEGORIES:California,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6899@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20251013
DTEND;VALUE=DATE:20251014
SUMMARY:California Digital Age Assurance Act: Signed by Governor
DESCRIPTION:Chaptered as Chapter 675\, Statutes of 2025.\n\nDigital Age Ass
 urance Act (AB 1043) (California)\n\nSource: https://leginfo.legislature.c
 a.gov/faces/billNavClient.xhtml?bill_id=202520260AB1043\n\nhttps://regulat
 ions.fru.dev/regulations/us-ca-ab1043
URL:https://regulations.fru.dev/regulations/us-ca-ab1043
CATEGORIES:California,children,privacy,online-safety
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-181@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20251013
DTEND;VALUE=DATE:20251014
SUMMARY:California SB 243 (companion chatbots): SB 243 signed
DESCRIPTION:SB 243 chaptered (ch. 677).\n\nCalifornia SB 243\, Companion Ch
 atbots (Stats. 2025\, ch. 677) (California)\n\nSource: https://leginfo.leg
 islature.ca.gov/faces/billNavClient.xhtml?bill_id=202520260SB243\n\nhttps:
 //regulations.fru.dev/regulations/us-ca-sb243
URL:https://regulations.fru.dev/regulations/us-ca-sb243
CATEGORIES:California,ai,children,online-safety
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6883@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20251021
DTEND;VALUE=DATE:20251022
SUMMARY:CFPB Open Banking Rule (Section 1033): Reconsideration comment peri
 od closes
DESCRIPTION:Comments on the ANPR due.\n\nRequired Rulemaking on Personal Fi
 nancial Data Rights (12 CFR Part 1033) (United States)\n\nSource: https://
 www.federalregister.gov/documents/2025/08/22/2025-16139/personal-financial
 -data-rights-reconsideration\n\nhttps://regulations.fru.dev/regulations/us
 -cfpb-1033
URL:https://regulations.fru.dev/regulations/us-cfpb-1033
CATEGORIES:United States,data-access,financial,privacy,cybersecurity
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6884@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20251029
DTEND;VALUE=DATE:20251030
SUMMARY:CFPB Open Banking Rule (Section 1033): Court enjoins enforcement
DESCRIPTION:E.D. Ky. enjoins the CFPB from enforcing the rule until it comp
 letes its reconsideration.\n\nRequired Rulemaking on Personal Financial Da
 ta Rights (12 CFR Part 1033) (United States)\n\nSource: https://www.govinf
 o.gov/content/pkg/USCOURTS-kyed-5_24-cv-00304/pdf/USCOURTS-kyed-5_24-cv-00
 304-1.pdf\n\nhttps://regulations.fru.dev/regulations/us-cfpb-1033
URL:https://regulations.fru.dev/regulations/us-cfpb-1033
CATEGORIES:United States,data-access,financial,privacy,cybersecurity
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6968@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20251029
DTEND;VALUE=DATE:20251030
SUMMARY:Digital Services Act: DSA delegated act on researcher data access i
 n force
DESCRIPTION:Delegated Regulation (EU) 2025/2050 sets the procedure for vett
 ed researchers to access VLOP and VLOSE data under Article 40(4). Publishe
 d in the OJ on 2025-10-09\; in force on the 20th day.\n\nRegulation (EU) 2
 022/2065 on a Single Market for Digital Services (Digital Services Act) (E
 uropean Union)\n\nSource: https://eur-lex.europa.eu/eli/reg_del/2025/2050/
 oj/eng\n\nhttps://regulations.fru.dev/regulations/eu-dsa
URL:https://regulations.fru.dev/regulations/eu-dsa
CATEGORIES:European Union,online-safety,children,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-110@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20251031
DTEND;VALUE=DATE:20251101
SUMMARY:EU-US Data Privacy Framework: Latombe appeal lodged at the Court of
  Justice
DESCRIPTION:Latombe appealed the General Court judgment to the Court of Jus
 tice on points of law (reported as Case C-703/25 P)\; the DPF stays valid 
 while it is pending.\n\nCommission Implementing Decision (EU) 2023/1795 on
  the adequate level of protection of personal data under the EU-US Data Pr
 ivacy Framework (European Union)\n\nSource: https://www.wilmerhale.com/en/
 insights/blogs/wilmerhale-privacy-and-cybersecurity-law/20251201-european-
 court-of-justice-to-review-challenge-to-eu-us-data-privacy-framework\n\nht
 tps://regulations.fru.dev/regulations/eu-us-dpf
URL:https://regulations.fru.dev/regulations/eu-us-dpf
CATEGORIES:European Union,privacy,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-7013@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20251031
DTEND;VALUE=DATE:20251101
SUMMARY:Singapore Cybersecurity Act: 2024 amendments commence
DESCRIPTION:Most of the Cybersecurity (Amendment) Act 2024 takes effect\, c
 overing foundational digital infrastructure\, entities of special cybersec
 urity interest and systems of temporary cybersecurity concern.\n\nCybersec
 urity Act 2018 (Singapore)\n\nSource: https://sso.agc.gov.sg/Acts-Supp/19-
 2024/Published/20240704?DocDate=20240704\n\nhttps://regulations.fru.dev/re
 gulations/sg-cybersecurity-act
URL:https://regulations.fru.dev/regulations/sg-cybersecurity-act
CATEGORIES:Singapore,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6982@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20251101
DTEND;VALUE=DATE:20251102
SUMMARY:China Cyber Incident Reporting Measures: Incident reporting measure
 s take effect
DESCRIPTION:1\, 2 and 4 hour reporting windows apply to relatively major an
 d higher incidents.\n\nAdministrative Measures for National Cybersecurity 
 Incident Reporting (China)\n\nSource: https://www.cac.gov.cn/2025-09/15/c_
 1759583017717009.htm\n\nhttps://regulations.fru.dev/regulations/cn-inciden
 t-reporting
URL:https://regulations.fru.dev/regulations/cn-incident-reporting
CATEGORIES:China,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-276@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20251101
DTEND;VALUE=DATE:20251102
SUMMARY:NYDFS Cybersecurity Regulation (Part 500): Universal MFA and asset 
 inventory
DESCRIPTION:500.12 multi-factor authentication for all users and 500.13(a) 
 asset inventory requirements apply.\n\nNew York DFS Cybersecurity Requirem
 ents for Financial Services Companies (23 NYCRR Part 500)\, Second Amendme
 nt (New York)\n\nSource: https://www.dfs.ny.gov/cybersecurity/23-NYCRR-Par
 t-500\n\nhttps://regulations.fru.dev/regulations/us-ny-dfs-500
URL:https://regulations.fru.dev/regulations/us-ny-dfs-500
CATEGORIES:New York,cybersecurity,breach-notification,financial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-7032@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20251102
DTEND;VALUE=DATE:20251103
SUMMARY:Egypt PDPL: Executive Regulations take effect
DESCRIPTION:Decree No. 816 of 2025 was published in Al-Waqa'i al-Misriyya N
 o. 244 (supplement A) on 1 November 2025 and applies from the next day.\n\
 nLaw No. 151 of 2020 on the Protection of Personal Data and its Executive 
 Regulations (Egypt)\n\nSource: https://www.pdpc.gov.eg/assets/pdf-data/Exe
 cutive%20Regulation.pdf\n\nhttps://regulations.fru.dev/regulations/eg-pdpl
URL:https://regulations.fru.dev/regulations/eg-pdpl
CATEGORIES:Egypt,privacy,data-residency,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-7027@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20251103
DTEND;VALUE=DATE:20251104
SUMMARY:New Zealand Biometric Processing Privacy Code: Biometric code in fo
 rce
DESCRIPTION:The Biometric Processing Privacy Code applies to new biometric 
 processing.\n\nBiometric Processing Privacy Code 2025 (New Zealand)\n\nSou
 rce: https://www.privacy.org.nz/privacy-principles/codes-of-practice/biome
 tric-processing-privacy-code/\n\nhttps://regulations.fru.dev/regulations/n
 z-biometric-code
URL:https://regulations.fru.dev/regulations/nz-biometric-code
CATEGORIES:New Zealand,biometrics,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-7042@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20251104
DTEND;VALUE=DATE:20251105
SUMMARY:Kenya Computer Misuse and Cybercrimes Act: 2025 amendments commence
DESCRIPTION:Computer Misuse and Cybercrimes (Amendment) Act No. 17 of 2025:
  assented 15 October 2025\, published 21 October 2025\, commenced 4 Novemb
 er 2025.\n\nComputer Misuse and Cybercrimes Act\, 2018 (Kenya)\n\nSource: 
 https://new.kenyalaw.org/akn/ke/act/2025/17\n\nhttps://regulations.fru.dev
 /regulations/ke-cmca
URL:https://regulations.fru.dev/regulations/ke-cmca
CATEGORIES:Kenya,cybersecurity,online-safety
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-195@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20251110
DTEND;VALUE=DATE:20251111
SUMMARY:CMMC 2.0: DFARS rule effective\; Phase 1 begins
DESCRIPTION:CMMC Level 1 and Level 2 self-assessment requirements begin app
 earing in applicable DoD solicitations and contracts (32 CFR 170.3(e)(1)).
 \n\nCybersecurity Maturity Model Certification (CMMC) Program (32 CFR Part
  170) and DFARS acquisition rule (48 CFR Parts 204\, 212\, 217\, 252) (Uni
 ted States (Federal))\n\nSource: https://www.federalregister.gov/documents
 /2025/09/10/2025-17359/defense-federal-acquisition-regulation-supplement-a
 ssessing-contractor-implementation-of\n\nhttps://regulations.fru.dev/regul
 ations/us-cmmc
URL:https://regulations.fru.dev/regulations/us-cmmc
CATEGORIES:United States (Federal),cybersecurity
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6913@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20251110
DTEND;VALUE=DATE:20251111
SUMMARY:NY Algorithmic Pricing Disclosure Act: Disclosure duty takes effect
DESCRIPTION:Algorithmic pricing disclosures required.\n\nNew York Algorithm
 ic Pricing Disclosure Act (General Business Law section 349-a) (New York)\
 n\nSource: https://ag.ny.gov/press-release/2025/attorney-general-james-war
 ns-new-yorkers-about-algorithmic-pricing-new-law-takes\n\nhttps://regulati
 ons.fru.dev/regulations/us-ny-algo-pricing
URL:https://regulations.fru.dev/regulations/us-ny-algo-pricing
CATEGORIES:New York,privacy,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-7002@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20251111
DTEND;VALUE=DATE:20251112
SUMMARY:Taiwan PDPA: 2025 amendment promulgated
DESCRIPTION:Amendment adds PDPC powers\, breach reporting and security duti
 es. Its start date will be set by the Executive Yuan and is not yet known.
 \n\nTentative: depends on a proposal not yet adopted.\n\nPersonal Data Pro
 tection Act (Taiwan)\n\nSource: https://law.moj.gov.tw/LawClass/LawHistory
 .aspx?pcode=I0050021\n\nhttps://regulations.fru.dev/regulations/tw-pdpa
URL:https://regulations.fru.dev/regulations/tw-pdpa
CATEGORIES:Taiwan,privacy,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-145@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20251112
DTEND;VALUE=DATE:20251113
SUMMARY:UK Cyber Security and Resilience Bill: Introduced (Commons first re
 ading)
DESCRIPTION:Bill introduced in the House of Commons.\n\nCyber Security and 
 Resilience (Network and Information Systems) Bill (United Kingdom)\n\nSour
 ce: https://bills.parliament.uk/bills/4035\n\nhttps://regulations.fru.dev/
 regulations/uk-csr-bill
URL:https://regulations.fru.dev/regulations/uk-csr-bill
CATEGORIES:United Kingdom,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-116@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20251113
DTEND;VALUE=DATE:20251114
SUMMARY:India DPDP Act: DPDP Rules published\; Board and procedural rules i
 n force
DESCRIPTION:Rules 1\, 2 and 17-21 (Data Protection Board constitution and f
 unctioning) take effect on publication in the Official Gazette.\n\nDigital
  Personal Data Protection Act\, 2023 and Digital Personal Data Protection 
 Rules\, 2025 (India)\n\nSource: https://egazette.gov.in/WriteReadData/2025
 /267650.pdf\n\nhttps://regulations.fru.dev/regulations/in-dpdp
URL:https://regulations.fru.dev/regulations/in-dpdp
CATEGORIES:India,privacy,children,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6971@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20251117
DTEND;VALUE=DATE:20251118
SUMMARY:Digital Services Act: DSA review report on VLOP scope and interplay
DESCRIPTION:Commission report under Article 91 on Article 33 scope and inte
 raction with other laws.\n\nRegulation (EU) 2022/2065 on a Single Market f
 or Digital Services (Digital Services Act) (European Union)\n\nSource: htt
 ps://eur-lex.europa.eu/eli/reg/2022/2065/oj/eng\n\nhttps://regulations.fru
 .dev/regulations/eu-dsa
URL:https://regulations.fru.dev/regulations/eu-dsa
CATEGORIES:European Union,online-safety,children,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-74@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20251118
DTEND;VALUE=DATE:20251119
SUMMARY:DORA: First critical ICT third-party providers designated
DESCRIPTION:The ESAs published the first list of 19 critical ICT third-part
 y providers (including AWS\, Google Cloud and Microsoft)\, which now come 
 under direct EU oversight.\n\nRegulation (EU) 2022/2554 on digital operati
 onal resilience for the financial sector (Digital Operational Resilience A
 ct) (European Union)\n\nSource: https://www.eba.europa.eu/publications-and
 -media/press-releases/european-supervisory-authorities-designate-critical-
 ict-third-party-providers-under-digital\n\nhttps://regulations.fru.dev/reg
 ulations/eu-dora
URL:https://regulations.fru.dev/regulations/eu-dora
CATEGORIES:European Union,cybersecurity,financial,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6867@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20251120
DTEND;VALUE=DATE:20251121
SUMMARY:EU Consumer Credit Directive 2 (CCD2): Transposition deadline
DESCRIPTION:Member States must adopt and publish transposing laws (Article 
 48).\n\nDirective (EU) 2023/2225 on credit agreements for consumers (Europ
 ean Union)\n\nSource: https://eur-lex.europa.eu/eli/dir/2023/2225/oj/eng\n
 \nhttps://regulations.fru.dev/regulations/eu-ccd2
URL:https://regulations.fru.dev/regulations/eu-ccd2
CATEGORIES:European Union,financial,privacy,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-7009@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20251125
DTEND;VALUE=DATE:20251126
SUMMARY:Singapore Online Safety (Relief and Accountability) Act: Act assent
 ed to
DESCRIPTION:Passed by Parliament on 5 November 2025 and assented to by the 
 President on 25 November 2025.\n\nOnline Safety (Relief and Accountability
 ) Act 2025 (Singapore)\n\nSource: https://sso.agc.gov.sg/Acts-Supp/23-2025
 /Published/20251208?DocDate=20251208\n\nhttps://regulations.fru.dev/regula
 tions/sg-online-safety-act
URL:https://regulations.fru.dev/regulations/sg-online-safety-act
CATEGORIES:Singapore,online-safety,children,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-95@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20251126
DTEND;VALUE=DATE:20251127
SUMMARY:GDPR: GDPR Procedural Regulation adopted
DESCRIPTION:Regulation (EU) 2025/2518 laying down additional procedural rul
 es for cross-border GDPR enforcement signed by Parliament and Council.\n\n
 Regulation (EU) 2016/679 (General Data Protection Regulation) (European Un
 ion)\n\nSource: https://eur-lex.europa.eu/eli/reg/2025/2518/oj\n\nhttps://
 regulations.fru.dev/regulations/eu-gdpr
URL:https://regulations.fru.dev/regulations/eu-gdpr
CATEGORIES:European Union,privacy,breach-notification,data-access,children,
 biometrics,health
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6957@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20251130
DTEND;VALUE=DATE:20251201
SUMMARY:Peru PDPL and 2024 Regulation: DPO required: large companies
DESCRIPTION:Companies with annual sales above 2\,300 UIT must appoint a dat
 a protection officer where Art. 37.1(2)-(3) applies.\n\nLey N° 29733\, Le
 y de Protección de Datos Personales\, and its Regulation (Decreto Supremo
  N° 016-2024-JUS) (Peru)\n\nSource: https://www.gob.pe/institucion/smv/no
 rmas-legales/6426760-016-2024-jus\n\nhttps://regulations.fru.dev/regulatio
 ns/pe-pdpl
URL:https://regulations.fru.dev/regulations/pe-pdpl
CATEGORIES:Peru,privacy,breach-notification,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-296@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20251203
DTEND;VALUE=DATE:20251204
SUMMARY:SEC Regulation S-P: Larger entities must comply
DESCRIPTION:Larger covered institutions (18 months after Federal Register p
 ublication) must have incident response programs\, 30-day customer notific
 ation\, and service-provider oversight in place.\n\nRegulation S-P: Privac
 y of Consumer Financial Information and Safeguarding Customer Information 
 (2024 amendments) (United States (Federal))\n\nSource: https://www.federal
 register.gov/documents/2024/06/03/2024-11116/regulation-s-p-privacy-of-con
 sumer-financial-information-and-safeguarding-customer-information\n\nhttps
 ://regulations.fru.dev/regulations/us-sec-reg-sp
URL:https://regulations.fru.dev/regulations/us-sec-reg-sp
CATEGORIES:United States (Federal),financial,privacy,cybersecurity,breach-n
 otification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-8@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20251210
DTEND;VALUE=DATE:20251211
SUMMARY:Australia Social Media Minimum Age: Social media minimum age obliga
 tion applies
DESCRIPTION:Age-restricted platforms must take reasonable steps to prevent 
 under-16s from holding accounts.\n\nOnline Safety Amendment (Social Media 
 Minimum Age) Act 2024 (Australia)\n\nSource: https://www.legislation.gov.a
 u/C2024A00127/asmade\n\nhttps://regulations.fru.dev/regulations/au-social-
 media-min-age
URL:https://regulations.fru.dev/regulations/au-social-media-min-age
CATEGORIES:Australia,children,online-safety
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6892@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20251216
DTEND;VALUE=DATE:20251217
SUMMARY:AI state-law preemption EO: EO published in Federal Register
DESCRIPTION:Signed 2025-12-11 and published at 90 FR 58499.\n\nExecutive Or
 der 14365: Ensuring a National Policy Framework for Artificial Intelligenc
 e (United States)\n\nSource: https://www.federalregister.gov/documents/202
 5/12/16/2025-23092/ensuring-a-national-policy-framework-for-artificial-int
 elligence\n\nhttps://regulations.fru.dev/regulations/us-eo-14365-ai-preemp
 tion
URL:https://regulations.fru.dev/regulations/us-eo-14365-ai-preemption
CATEGORIES:United States,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-278@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20251219
DTEND;VALUE=DATE:20251220
SUMMARY:NY RAISE Act: RAISE Act signed
DESCRIPTION:Governor Hochul signs the RAISE Act with an agreed chapter amen
 dment.\n\nNew York Responsible AI Safety and Education (RAISE) Act (S6953-
 B/A6453-B of 2025)\, as amended by chapter amendment S8828 of 2026 (New Yo
 rk)\n\nSource: https://www.governor.ny.gov/news/governor-hochul-signs-nati
 on-leading-legislation-require-ai-frameworks-ai-frontier-models\n\nhttps:/
 /regulations.fru.dev/regulations/us-ny-raise
URL:https://regulations.fru.dev/regulations/us-ny-raise
CATEGORIES:New York,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6925@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20251223
DTEND;VALUE=DATE:20251224
SUMMARY:Texas App Store Accountability Act: Preliminary injunction
DESCRIPTION:W.D. Tex. (CCIA v. Paxton) enjoins the AG from implementing or 
 enforcing SB 2420 on First Amendment grounds.\n\nTexas App Store Accountab
 ility Act (SB 2420) (Texas)\n\nSource: https://www.govinfo.gov/content/pkg
 /USCOURTS-txwd-1_25-cv-01660/pdf/USCOURTS-txwd-1_25-cv-01660-0.pdf\n\nhttp
 s://regulations.fru.dev/regulations/us-tx-app-store
URL:https://regulations.fru.dev/regulations/us-tx-app-store
CATEGORIES:Texas,children,privacy,online-safety
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-224@regulations.fru.dev
DTSTAMP:20260926T195651Z
DTSTART;VALUE=DATE:20251231
DTEND;VALUE=DATE:20260101
SUMMARY:Delaware Personal Data Privacy Act (DPDPA): Mandatory 60-day cure p
 eriod expires
DESCRIPTION:Mandatory notice-and-cure ends Dec 31\, 2025\; from Jan 1\, 202
 6 DOJ decides whether to offer a cure using statutory factors.\n\nDelaware
  Personal Data Privacy Act (HB 154)\, 6 Del. C. ch. 12D (Delaware)\n\nSour
 ce: https://delcode.delaware.gov/title6/c012d/index.html\n\nhttps://regula
 tions.fru.dev/regulations/us-de-dpdpa
URL:https://regulations.fru.dev/regulations/us-de-dpdpa
CATEGORIES:Delaware,privacy,children
TRANSP:TRANSPARENT
END:VEVENT
END:VCALENDAR
