BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//fru.dev//Regulations//EN
CALSCALE:GREGORIAN
METHOD:PUBLISH
X-WR-CALNAME:Regulation deadlines (regulations.fru.dev)
X-WR-CALDESC:Compliance deadlines tracked at regulations.fru.dev
REFRESH-INTERVAL;VALUE=DURATION:P1D
X-PUBLISHED-TTL:P1D
BEGIN:VEVENT
UID:deadline-192@regulations.fru.dev
DTSTAMP:20260926T195648Z
DTSTART;VALUE=DATE:20280101
DTEND;VALUE=DATE:20280102
SUMMARY:California AI Transparency Act (SB 942): Capture device manufacture
 r duties
DESCRIPTION:Capture device manufacturer provenance requirements become oper
 ative.\n\nCalifornia AI Transparency Act (SB 942\, Stats. 2024\, ch. 291)\
 , as amended by AB 853 (Stats. 2025\, ch. 674) (California)\n\nSource: htt
 ps://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=20252026
 0AB853\n\nhttps://regulations.fru.dev/regulations/us-ca-sb942
URL:https://regulations.fru.dev/regulations/us-ca-sb942
CATEGORIES:California,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-180@regulations.fru.dev
DTSTAMP:20260926T195648Z
DTSTART;VALUE=DATE:20280101
DTEND;VALUE=DATE:20280102
SUMMARY:California Delete Act / DROP: Independent third-party audits begin
DESCRIPTION:Beginning Jan 1\, 2028 and every 3 years thereafter\, data brok
 ers must undergo an independent audit of Delete Act compliance.\n\nCalifor
 nia Delete Act (SB 362\, 2023)\, Cal. Civ. Code 1798.99.80 et seq.\, and D
 ROP regulations (California)\n\nSource: https://www.cppa.ca.gov/data_broke
 rs/\n\nhttps://regulations.fru.dev/regulations/us-ca-delete-act
URL:https://regulations.fru.dev/regulations/us-ca-delete-act
CATEGORIES:California,privacy,data-access
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-315@regulations.fru.dev
DTSTAMP:20260926T195648Z
DTSTART;VALUE=DATE:20280101
DTEND;VALUE=DATE:20280102
SUMMARY:Vermont VDPOSA: Vermont Data Privacy and Online Surveillance Act ta
 kes effect
DESCRIPTION:All obligations under Act 145 apply (sec. 4).\n\nVermont Data P
 rivacy and Online Surveillance Act (S.71\, Act 145 of 2026) (Vermont)\n\nS
 ource: https://legislature.vermont.gov/Documents/2026/Docs/ACTS/ACT145/ACT
 145%20As%20Enacted.pdf\n\nhttps://regulations.fru.dev/regulations/us-vt-vd
 posa
URL:https://regulations.fru.dev/regulations/us-vt-vdposa
CATEGORIES:Vermont,privacy,health,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6998@regulations.fru.dev
DTSTAMP:20260926T195648Z
DTSTART;VALUE=DATE:20280114
DTEND;VALUE=DATE:20280115
SUMMARY:Taiwan AI Basic Act: Agencies must align laws with the Act
DESCRIPTION:Government agencies must finish amending or adopting laws and a
 dministrative measures within 2 years of entry into force (art. 18). Date 
 is computed from the statute.\n\nTentative: depends on a proposal not yet 
 adopted.\n\nArtificial Intelligence Basic Act (Taiwan)\n\nSource: https://
 law.moj.gov.tw/LawClass/LawAll.aspx?pcode=H0160093\n\nhttps://regulations.
 fru.dev/regulations/tw-ai-basic-act
URL:https://regulations.fru.dev/regulations/tw-ai-basic-act
CATEGORIES:Taiwan,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6862@regulations.fru.dev
DTSTAMP:20260926T195648Z
DTSTART;VALUE=DATE:20280201
DTEND;VALUE=DATE:20280202
SUMMARY:EU CSAM Interim Regulation: Commission implementation report
DESCRIPTION:Commission report on implementation\, including proportionality
  and error rates (Article 9).\n\nRegulation (EU) 2026/1881 on a temporary 
 derogation from certain provisions of Directive 2002/58/EC for combating o
 nline child sexual abuse (European Union)\n\nSource: https://eur-lex.europ
 a.eu/eli/reg/2026/1881/oj/eng\n\nhttps://regulations.fru.dev/regulations/e
 u-csam-interim
URL:https://regulations.fru.dev/regulations/eu-csam-interim
CATEGORIES:European Union,privacy,children,online-safety
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-172@regulations.fru.dev
DTSTAMP:20260926T195648Z
DTSTART;VALUE=DATE:20280401
DTEND;VALUE=DATE:20280402
SUMMARY:CCPA / CPRA: First risk assessment submission to CPPA
DESCRIPTION:Businesses must submit required risk assessment information and
  attestation for assessments conducted in 2026 and 2027 (11 CCR 7157(a)(1)
 )\; annually by April 1 thereafter.\n\nCalifornia Consumer Privacy Act of 
 2018\, as amended by the California Privacy Rights Act of 2020 (Cal. Civ. 
 Code 1798.100 et seq.) and CPPA regulations (Cal. Code Regs. tit. 11\, 700
 0 et seq.) (California)\n\nSource: https://cppa.ca.gov/regulations/pdf/ccp
 a_updates_cyber_risk_admt_appr_text.pdf\n\nhttps://regulations.fru.dev/reg
 ulations/us-ca-ccpa
URL:https://regulations.fru.dev/regulations/us-ca-ccpa
CATEGORIES:California,privacy,ai,cybersecurity,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-173@regulations.fru.dev
DTSTAMP:20260926T195648Z
DTSTART;VALUE=DATE:20280401
DTEND;VALUE=DATE:20280402
SUMMARY:CCPA / CPRA: Cybersecurity audit due: revenue over $100M
DESCRIPTION:First cybersecurity audit report (covering Jan 1\, 2027 - Jan 1
 \, 2028) and certification due for businesses with 2026 annual gross reven
 ue over $100M (11 CCR 7121(a)(1)).\n\nCalifornia Consumer Privacy Act of 2
 018\, as amended by the California Privacy Rights Act of 2020 (Cal. Civ. C
 ode 1798.100 et seq.) and CPPA regulations (Cal. Code Regs. tit. 11\, 7000
  et seq.) (California)\n\nSource: https://cppa.ca.gov/regulations/pdf/ccpa
 _updates_cyber_risk_admt_appr_text.pdf\n\nhttps://regulations.fru.dev/regu
 lations/us-ca-ccpa
URL:https://regulations.fru.dev/regulations/us-ca-ccpa
CATEGORIES:California,privacy,ai,cybersecurity,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6887@regulations.fru.dev
DTSTAMP:20260926T195648Z
DTSTART;VALUE=DATE:20280401
DTEND;VALUE=DATE:20280402
SUMMARY:CFPB Open Banking Rule (Section 1033): Tier 3 compliance date (orig
 inal)
DESCRIPTION:Banks with $3B to $10B in assets. Original date\; subject to st
 ay\, extension and injunction.\n\nTentative: depends on a proposal not yet
  adopted.\n\nRequired Rulemaking on Personal Financial Data Rights (12 CFR
  Part 1033) (United States)\n\nSource: https://www.federalregister.gov/doc
 uments/2024/11/18/2024-25079/required-rulemaking-on-personal-financial-dat
 a-rights\n\nhttps://regulations.fru.dev/regulations/us-cfpb-1033
URL:https://regulations.fru.dev/regulations/us-cfpb-1033
CATEGORIES:United States,data-access,financial,privacy,cybersecurity
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6863@regulations.fru.dev
DTSTAMP:20260926T195648Z
DTSTART;VALUE=DATE:20280403
DTEND;VALUE=DATE:20280404
SUMMARY:EU CSAM Interim Regulation: Interim derogation expires
DESCRIPTION:The Regulation applies until this date.\n\nRegulation (EU) 2026
 /1881 on a temporary derogation from certain provisions of Directive 2002/
 58/EC for combating online child sexual abuse (European Union)\n\nSource: 
 https://eur-lex.europa.eu/eli/reg/2026/1881/oj/eng\n\nhttps://regulations.
 fru.dev/regulations/eu-csam-interim
URL:https://regulations.fru.dev/regulations/eu-csam-interim
CATEGORIES:European Union,privacy,children,online-safety
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-52@regulations.fru.dev
DTSTAMP:20260926T195648Z
DTSTART;VALUE=DATE:20280611
DTEND;VALUE=DATE:20280612
SUMMARY:Cyber Resilience Act: Legacy type-examination certificates expire
DESCRIPTION:EU type-examination certificates and approval decisions on cybe
 rsecurity requirements under other harmonisation legislation remain valid 
 until this date unless they expire earlier (Art 69(1)).\n\nRegulation (EU)
  2024/2847 on horizontal cybersecurity requirements for products with digi
 tal elements (Cyber Resilience Act) (European Union)\n\nSource: https://eu
 r-lex.europa.eu/eli/reg/2024/2847/oj\n\nhttps://regulations.fru.dev/regula
 tions/eu-cra
URL:https://regulations.fru.dev/regulations/eu-cra
CATEGORIES:European Union,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-45@regulations.fru.dev
DTSTAMP:20260926T195648Z
DTSTART;VALUE=DATE:20280802
DTEND;VALUE=DATE:20280803
SUMMARY:EU AI Act: High-risk obligations apply to Annex I product-embedded 
 systems
DESCRIPTION:Chapter III Sections 1-3 apply to AI systems classified high-ri
 sk under Art 6(1) and Annex I (safety components of products covered by EU
  harmonisation legislation). Deferred from 2 Aug 2027 by Regulation (EU) 2
 026/1744.\n\nRegulation (EU) 2024/1689 laying down harmonised rules on art
 ificial intelligence (Artificial Intelligence Act)\, as amended by Regulat
 ion (EU) 2026/1744 (Digital Omnibus on AI) (European Union)\n\nSource: htt
 ps://eur-lex.europa.eu/eli/reg/2026/1744/oj\n\nhttps://regulations.fru.dev
 /regulations/eu-ai-act
URL:https://regulations.fru.dev/regulations/eu-ai-act
CATEGORIES:European Union,ai,biometrics,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6966@regulations.fru.dev
DTSTAMP:20260926T195648Z
DTSTART;VALUE=DATE:20280910
DTEND;VALUE=DATE:20280911
SUMMARY:Peru AI Law and Regulation: Private sector: production\, agricultur
 e\, energy\, mining
DESCRIPTION:Obligations apply three years after publication.\n\nTentative: 
 depends on a proposal not yet adopted.\n\nLey N° 31814\, Ley que promueve
  el uso de la inteligencia artificial en favor del desarrollo económico y
  social del país\, and its Regulation (Decreto Supremo N° 115-2025-PCM) 
 (Peru)\n\nSource: https://www.gob.pe/institucion/pcm/normas-legales/713352
 2-115-2025-pcm\n\nhttps://regulations.fru.dev/regulations/pe-ai-law
URL:https://regulations.fru.dev/regulations/pe-ai-law
CATEGORIES:Peru,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-53@regulations.fru.dev
DTSTAMP:20260926T195648Z
DTSTART;VALUE=DATE:20280911
DTEND;VALUE=DATE:20280912
SUMMARY:Cyber Resilience Act: Report on single reporting platform
DESCRIPTION:Commission report assessing the single reporting platform's eff
 ectiveness (Art 70(2)).\n\nRegulation (EU) 2024/2847 on horizontal cyberse
 curity requirements for products with digital elements (Cyber Resilience A
 ct) (European Union)\n\nSource: https://eur-lex.europa.eu/eli/reg/2024/284
 7/oj\n\nhttps://regulations.fru.dev/regulations/eu-cra
URL:https://regulations.fru.dev/regulations/eu-cra
CATEGORIES:European Union,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-62@regulations.fru.dev
DTSTAMP:20260926T195648Z
DTSTART;VALUE=DATE:20280912
DTEND;VALUE=DATE:20280913
SUMMARY:EU Data Act: Commission evaluation
DESCRIPTION:Commission evaluation report due\, including the impact of clou
 d switching rules (Arts 23-31) (Art 49(2)).\n\nRegulation (EU) 2023/2854 o
 n harmonised rules on fair access to and use of data (Data Act) (European 
 Union)\n\nSource: https://eur-lex.europa.eu/eli/reg/2023/2854/oj\n\nhttps:
 //regulations.fru.dev/regulations/eu-data-act
URL:https://regulations.fru.dev/regulations/eu-data-act
CATEGORIES:European Union,data-access,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-222@regulations.fru.dev
DTSTAMP:20260926T195648Z
DTSTART;VALUE=DATE:20281001
DTEND;VALUE=DATE:20281002
SUMMARY:Connecticut Data Privacy Act (CTDPA): Data brokers must process sta
 te deletion mechanism requests
DESCRIPTION:Registered data brokers must access the DCP accessible deletion
  mechanism at least every 45 days and process deletion requests.\n\nConnec
 ticut Data Privacy Act (Public Act 22-15)\, Conn. Gen. Stat. 42-515 et seq
 .\, as amended by Public Act 25-113 (SB 1295) and Public Act 26-64 (SB 4) 
 (Connecticut)\n\nSource: https://www.cga.ct.gov/2026/ACT/PA/PDF/2026PA-000
 64-R00SB-00004-PA.PDF\n\nhttps://regulations.fru.dev/regulations/us-ct-ctd
 pa
URL:https://regulations.fru.dev/regulations/us-ct-ctdpa
CATEGORIES:Connecticut,privacy,children,ai,health
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-198@regulations.fru.dev
DTSTAMP:20260926T195648Z
DTSTART;VALUE=DATE:20281110
DTEND;VALUE=DATE:20281111
SUMMARY:CMMC 2.0: Phase 4: full implementation
DESCRIPTION:CMMC requirements included in all applicable DoD solicitations 
 and contracts\, including option periods (32 CFR 170.3(e)(4)).\n\nCybersec
 urity Maturity Model Certification (CMMC) Program (32 CFR Part 170) and DF
 ARS acquisition rule (48 CFR Parts 204\, 212\, 217\, 252) (United States (
 Federal))\n\nSource: https://www.federalregister.gov/documents/2024/10/15/
 2024-22905/cybersecurity-maturity-model-certification-cmmc-program\n\nhttp
 s://regulations.fru.dev/regulations/us-cmmc
URL:https://regulations.fru.dev/regulations/us-cmmc
CATEGORIES:United States (Federal),cybersecurity
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6960@regulations.fru.dev
DTSTAMP:20260926T195648Z
DTSTART;VALUE=DATE:20281130
DTEND;VALUE=DATE:20281201
SUMMARY:Peru PDPL and 2024 Regulation: DPO required: micro companies
DESCRIPTION:Micro companies with annual sales up to 150 UIT.\n\nLey N° 297
 33\, Ley de Protección de Datos Personales\, and its Regulation (Decreto 
 Supremo N° 016-2024-JUS) (Peru)\n\nSource: https://www.gob.pe/institucion
 /smv/normas-legales/6426760-016-2024-jus\n\nhttps://regulations.fru.dev/re
 gulations/pe-pdpl
URL:https://regulations.fru.dev/regulations/pe-pdpl
CATEGORIES:Peru,privacy,breach-notification,data-residency
TRANSP:TRANSPARENT
END:VEVENT
END:VCALENDAR
