Skip to content

Compliance deadlines: what is due next

326 dated deadlines across 110 regulations, 70 still ahead.

70 deadlines from today onPastAll

DateRegulation
September 20261
in 6dUK DUAA

ICO abolished; Information Commission takes over

October 20262
in 7dCTDPA

PA 26-64 (SB 4) amendments take effect

in 32dUK CSR Bill

Lords report stage scheduledtentative

November 20262
in 47dCMMC 2.0

Phase 2: Level 2 C3PAO certification

in 50dIndia DPDP

Consent Manager registration rule in force (12 months)

December 20266
in 2moChile PDPL

Law in force

in 2moEU AI Act

New bans on sexual deepfakes and CSAM generation; Art 50(2) grace period ends

in 3moEU PLD

Transposition deadline; old PLD repealed

in 3moAU Privacy Act

Children's Online Privacy Code must be registered

in 3moAU Privacy Act

Automated decision-making transparency applies

in 3moeIDAS 2

Member States must provide EU Digital Identity Wallets

January 202716
in 3moCA SB 942

Large online platform and hosting platform duties

in 3moCA SB 53

First OES anonymized incident report and CDT definition review

in 3moCCPA / CPRA

ADMT requirements compliance date

in 3moCCPA / CPRA

Browsers must support opt-out preference signal (AB 566)

in 3moColorado AI Act

ADMT obligations apply

in 3moColorado AI Act

AG rules due

in 3moCTDPA

Data broker registration required

in 3moDelaware DPDPA

Amended thresholds and third-party duties take effect

in 3moLouisiana LDPA

Louisiana Data Privacy Act takes effect

in 3moNH Privacy Act

Ban on selling personal data of children under 13 (HB 1460)

in 3moNY RAISE Act

RAISE Act takes effect

in 3moOKCDPA

Oklahoma Consumer Data Privacy Act takes effect

in 3moUtah UCPA

UCPA extends to motor vehicle manufacturers

in 4moEU Data Act

Cloud switching charges abolished

in 4moIndonesia PDP

Implementing regulation GR 33/2026 takes effect

in 4moCA Delete Act

Annual data broker registration deadline

March 20272
in 5moVietnam AI Law

Transition ends for existing AI systems (general)

in 6moEU EHDS

EHDS general application date

April 20273
in 6moMaryland MODPA

Discretionary 60-day cure period ends

in 6moGDPR

GDPR Procedural Regulation applies

in 7moNIS2

Next biennial entity notification

May 20272
in 7moAlabama APDPA

APDPA takes effect

in 8moIndia DPDP

Main data fiduciary obligations apply (18 months)

July 20274
in 9moCA SB 243

First annual report to Office of Suicide Prevention

in 9moKorea PIPA

Mandatory ISMS-P certification

in 9moUtah AIPA

Scheduled repeal of Title 13, Ch. 72

in 10moLouisiana LDPA

30-day cure period expires

August 20271
in 10moEU AI Act

Legacy GPAI models must comply; national AI sandboxes operational

September 20272
in 11moVietnam AI Law

Transition ends for existing AI systems in health, education and finance

in 12moEU Data Act

Unfair-terms rules extend to older long-term contracts

October 20271
in 13moNIS2

Commission review of NIS2

November 20271
in 14moCMMC 2.0

Phase 3: Level 3 certification

December 20275
in 14moChile PDPL

Proposed postponement of entry into forcetentative

in 14moEU AI Act

High-risk obligations apply to Annex III systems

in 15moEU CRA

CRA fully applies

in 15moeIDAS 2

Private relying parties must accept wallets

in 15moCCPA / CPRA

Risk assessments for pre-existing processing due

January 20283
in 15moCA SB 942

Capture device manufacturer duties

in 15moCA Delete Act

Independent third-party audits begin

in 15moVermont VDPOSA

Vermont Data Privacy and Online Surveillance Act takes effect

April 20282
in 18moCCPA / CPRA

First risk assessment submission to CPPA

in 18moCCPA / CPRA

Cybersecurity audit due: revenue over $100M

June 20281
in 21moEU CRA

Legacy type-examination certificates expire

August 20281
in 22moEU AI Act

High-risk obligations apply to Annex I product-embedded systems

September 20282
in 24moEU CRA

Report on single reporting platform

in 24moEU Data Act

Commission evaluation

October 20281
in 2yCTDPA

Data brokers must process state deletion mechanism requests

November 20281
in 2.1yCMMC 2.0

Phase 4: full implementation

March 20291
in 2.5yEU EHDS

Primary use for first data categories; secondary use framework applies

April 20291
in 2.5yCCPA / CPRA

Cybersecurity audit due: revenue $50M-$100M

June 20291
in 2.8yVermont VDPOSA

Mandatory 60-day cure period expires

July 20291
in 2.9yMinnesota MCDPA

Postsecondary institutions must comply

January 20301
in 3.3yColorado AI Act

Mandatory cure period ends

April 20301
in 3.5yCCPA / CPRA

Cybersecurity audit due: revenue under $50M

August 20301
in 3.9yEU AI Act

Public-authority high-risk systems must comply

December 20302
in 4.2yEU CRA

First CRA evaluation

in 4.3yEU AI Act

Large-scale EU IT systems must comply

March 20311
in 4.5yEU EHDS

Primary use for second data categories; EHR systems in service; extra secondary-use categories

March 20351
in 8.5yEU EHDS

Third-country participation in secondary use

Summaries for reference, not legal advice. Check the official text.

Rule changes by email

The morning after a new data, privacy or AI law, or a deadline change; nothing in quiet weeks.

Double opt-in. Unsubscribe any time.