BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//fru.dev//Calendar//EN
CALSCALE:GREGORIAN
METHOD:PUBLISH
X-WR-CALNAME:Compliance deadlines | Calendar by fru.dev
X-WR-TIMEZONE:America/Chicago
REFRESH-INTERVAL;VALUE=DURATION:PT12H
X-PUBLISHED-TTL:PT12H
BEGIN:VEVENT
UID:reg-us-nj-njdpa-2026-06-30-a5328-sensitive-data-sale-ban-@calendar.fru
 .dev
DTSTAMP:20260925T144757Z
DTSTART;VALUE=DATE:20260630
DTEND;VALUE=DATE:20260701
TRANSP:TRANSPARENT
SUMMARY:New Jersey NJDPA: A5328 sensitive data sale ban takes effect
DESCRIPTION:A5328\, signed June 30\, 2026\, prohibits selling sensitive pe
 rsonal data; the ban took effect on signing. Not legal advice.\nWhere: Ne
 w Jersey\nSource: https://www.njleg.state.nj.us/bill-search/2026/A5328\nh
 ttps://calendar.fru.dev/events/reg-us-nj-njdpa-2026-06-30-a5328-sensitive
 -data-sale-ban-
URL:https://calendar.fru.dev/events/reg-us-nj-njdpa-2026-06-30-a5328-sensi
 tive-data-sale-ban-
CATEGORIES:Compliance deadlines
LOCATION:New Jersey
END:VEVENT
BEGIN:VEVENT
UID:reg-us-co-ai-act-2026-06-30-delayed-effective-date-superse@calendar.fr
 u.dev
DTSTAMP:20260925T144757Z
DTSTART;VALUE=DATE:20260630
DTEND;VALUE=DATE:20260701
TRANSP:TRANSPARENT
SUMMARY:Colorado AI Act: Delayed effective date (superseded)
DESCRIPTION:SB 25B-004 date; superseded by SB 26-189 before it arrived\, s
 o no obligations applied. Not legal advice.\nWhere: Colorado\nSource: htt
 ps://leg.colorado.gov/bills/sb25b-004\nhttps://calendar.fru.dev/events/re
 g-us-co-ai-act-2026-06-30-delayed-effective-date-superse
URL:https://calendar.fru.dev/events/reg-us-co-ai-act-2026-06-30-delayed-ef
 fective-date-superse
CATEGORIES:Compliance deadlines
LOCATION:Colorado
END:VEVENT
BEGIN:VEVENT
UID:reg-us-ct-ctdpa-2026-07-01-pa-25-113-sb-1295-amendments-t@calendar.fru
 .dev
DTSTAMP:20260925T144757Z
DTSTART;VALUE=DATE:20260701
DTEND;VALUE=DATE:20260702
TRANSP:TRANSPARENT
SUMMARY:Connecticut Data Privacy Act (CTDPA): PA 25-113 (SB 1295) amendmen
 ts take effect
DESCRIPTION:Thresholds drop to 35\,000 consumers or any sensitive-data pro
 cessing or data sale; expanded sensitive data\, minors' protections\, and
  LLM-training disclosure...\nWhere: Connecticut\nSource: https://www.cga.
 ct.gov/2025/ACT/PA/PDF/2025PA-00113-R00SB-01295-PA.PDF\nhttps://calendar.
 fru.dev/events/reg-us-ct-ctdpa-2026-07-01-pa-25-113-sb-1295-amendments-t
URL:https://calendar.fru.dev/events/reg-us-ct-ctdpa-2026-07-01-pa-25-113-s
 b-1295-amendments-t
CATEGORIES:Compliance deadlines
LOCATION:Connecticut
END:VEVENT
BEGIN:VEVENT
UID:reg-us-nj-njdpa-2026-07-01-mandatory-30-day-cure-period-e@calendar.fru
 .dev
DTSTAMP:20260925T144757Z
DTSTART;VALUE=DATE:20260701
DTEND;VALUE=DATE:20260702
TRANSP:TRANSPARENT
SUMMARY:New Jersey NJDPA: Mandatory 30-day cure period expires
DESCRIPTION:The Division's duty to issue a cure notice before enforcement 
 ends on the first day of the 18th month after the effective date (N.J.S.A
 . 56:8-166.17(b))....\nWhere: New Jersey\nSource: https://pub.njleg.state
 .nj.us/Bills/2022/PL23/266_.PDF\nhttps://calendar.fru.dev/events/reg-us-n
 j-njdpa-2026-07-01-mandatory-30-day-cure-period-e
URL:https://calendar.fru.dev/events/reg-us-nj-njdpa-2026-07-01-mandatory-3
 0-day-cure-period-e
CATEGORIES:Compliance deadlines
LOCATION:New Jersey
END:VEVENT
BEGIN:VEVENT
UID:reg-us-ut-ucpa-2026-07-01-right-to-correct-takes-effect@calendar.fru.d
 ev
DTSTAMP:20260925T144757Z
DTSTART;VALUE=DATE:20260701
DTEND;VALUE=DATE:20260702
TRANSP:TRANSPARENT
SUMMARY:Utah UCPA: Right to correct takes effect
DESCRIPTION:Consumers may ask controllers to correct inaccurate personal d
 ata (13-61-201(4)\, as amended by Laws 2025\, ch. 468). Not legal advice.
 \nWhere: Utah\nSource: https://le.utah.gov/xcode/Title13/Chapter61/13-61-
 S201.html\nhttps://calendar.fru.dev/events/reg-us-ut-ucpa-2026-07-01-righ
 t-to-correct-takes-effect
URL:https://calendar.fru.dev/events/reg-us-ut-ucpa-2026-07-01-right-to-cor
 rect-takes-effect
CATEGORIES:Compliance deadlines
LOCATION:Utah
END:VEVENT
BEGIN:VEVENT
UID:reg-us-va-vcdpa-2026-07-01-ban-on-selling-precise-geoloca@calendar.fru
 .dev
DTSTAMP:20260925T144757Z
DTSTART;VALUE=DATE:20260701
DTEND;VALUE=DATE:20260702
TRANSP:TRANSPARENT
SUMMARY:Virginia VCDPA: Ban on selling precise geolocation data (SB 338)
DESCRIPTION:Controllers may not sell consumers' precise geolocation data (
 1\,750-ft radius)\, replacing the prior consent-based treatment. Not lega
 l advice.\nWhere: Virginia\nSource: https://lis.virginia.gov/bill-details
 /20261/SB338\nhttps://calendar.fru.dev/events/reg-us-va-vcdpa-2026-07-01-
 ban-on-selling-precise-geoloca
URL:https://calendar.fru.dev/events/reg-us-va-vcdpa-2026-07-01-ban-on-sell
 ing-precise-geoloca
CATEGORIES:Compliance deadlines
LOCATION:Virginia
END:VEVENT
BEGIN:VEVENT
UID:reg-jp-appi-2026-07-17-2026-appi-amendment-act-promul@calendar.fru.dev
DTSTAMP:20260925T144757Z
DTSTART;VALUE=DATE:20260717
DTEND;VALUE=DATE:20260718
TRANSP:TRANSPARENT
SUMMARY:Japan APPI: 2026 APPI amendment act promulgated
DESCRIPTION:Amendment enacted by the Diet on 10 July 2026 and promulgated;
  main provisions take effect by cabinet order within two years of promulg
 ation. Not legal advice.\nWhere: Japan\nSource: https://www.ppc.go.jp/fil
 es/pdf/260731_shiryou-1.pdf\nhttps://calendar.fru.dev/events/reg-jp-appi-
 2026-07-17-2026-appi-amendment-act-promul
URL:https://calendar.fru.dev/events/reg-jp-appi-2026-07-17-2026-appi-amend
 ment-act-promul
CATEGORIES:Compliance deadlines
LOCATION:Japan
END:VEVENT
BEGIN:VEVENT
UID:reg-eu-ai-act-2026-07-27-digital-omnibus-on-ai-enters-i@calendar.fru.d
 ev
DTSTAMP:20260925T144757Z
DTSTART;VALUE=DATE:20260727
DTEND;VALUE=DATE:20260728
TRANSP:TRANSPARENT
SUMMARY:EU AI Act: Digital Omnibus on AI enters into force
DESCRIPTION:Regulation (EU) 2026/1744 (adopted 8 July 2026\, OJ 24 July 20
 26) enters into force on the third day after publication. Amended Article
 s 102 to 110 apply...\nWhere: European Union\nSource: https://eur-lex.eur
 opa.eu/eli/reg/2026/1744/oj\nhttps://calendar.fru.dev/events/reg-eu-ai-ac
 t-2026-07-27-digital-omnibus-on-ai-enters-i
URL:https://calendar.fru.dev/events/reg-eu-ai-act-2026-07-27-digital-omnib
 us-on-ai-enters-i
CATEGORIES:Compliance deadlines
LOCATION:European Union
END:VEVENT
BEGIN:VEVENT
UID:reg-us-ca-delete-act-2026-08-01-data-brokers-must-begin-proces@calenda
 r.fru.dev
DTSTAMP:20260925T144757Z
DTSTART;VALUE=DATE:20260801
DTEND;VALUE=DATE:20260802
TRANSP:TRANSPARENT
SUMMARY:California Delete Act / DROP: Data brokers must begin processing D
 ROP deletion requests
DESCRIPTION:Brokers must access DROP at least every 45 days\, process veri
 fied deletion requests within 45 days\, and treat unverified requests as 
 opt-outs of...\nWhere: California\nSource: https://www.cppa.ca.gov/data_b
 rokers/\nhttps://calendar.fru.dev/events/reg-us-ca-delete-act-2026-08-01-
 data-brokers-must-begin-proces
URL:https://calendar.fru.dev/events/reg-us-ca-delete-act-2026-08-01-data-b
 rokers-must-begin-proces
CATEGORIES:Compliance deadlines
LOCATION:California
END:VEVENT
BEGIN:VEVENT
UID:reg-us-ct-ctdpa-2026-08-01-profiling-impact-assessments-a@calendar.fru
 .dev
DTSTAMP:20260925T144757Z
DTSTART;VALUE=DATE:20260801
DTEND;VALUE=DATE:20260802
TRANSP:TRANSPARENT
SUMMARY:Connecticut Data Privacy Act (CTDPA): Profiling impact assessments
  apply
DESCRIPTION:Impact assessment requirements apply to profiling activities c
 reated or generated on or after Aug 1\, 2026 (Conn. Gen. Stat. 42-522 as 
 amended). Not legal...\nWhere: Connecticut\nSource: https://www.cga.ct.go
 v/2025/ACT/PA/PDF/2025PA-00113-R00SB-01295-PA.PDF\nhttps://calendar.fru.d
 ev/events/reg-us-ct-ctdpa-2026-08-01-profiling-impact-assessments-a
URL:https://calendar.fru.dev/events/reg-us-ct-ctdpa-2026-08-01-profiling-i
 mpact-assessments-a
CATEGORIES:Compliance deadlines
LOCATION:Connecticut
END:VEVENT
BEGIN:VEVENT
UID:reg-us-ca-sb942-2026-08-02-covered-provider-duties-apply@calendar.fru.
 dev
DTSTAMP:20260925T144757Z
DTSTART;VALUE=DATE:20260802
DTEND;VALUE=DATE:20260803
TRANSP:TRANSPARENT
SUMMARY:California AI Transparency Act (SB 942): Covered provider duties a
 pply
DESCRIPTION:Detection tool\, manifest and latent disclosures\, and license
 -revocation duties become operative. Not legal advice.\nWhere: California
 \nSource: https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bi
 ll_id=202520260AB853\nhttps://calendar.fru.dev/events/reg-us-ca-sb942-202
 6-08-02-covered-provider-duties-apply
URL:https://calendar.fru.dev/events/reg-us-ca-sb942-2026-08-02-covered-pro
 vider-duties-apply
CATEGORIES:Compliance deadlines
LOCATION:California
END:VEVENT
BEGIN:VEVENT
UID:reg-eu-ai-act-2026-08-02-general-application-transparen@calendar.fru.d
 ev
DTSTAMP:20260925T144757Z
DTSTART;VALUE=DATE:20260802
DTEND;VALUE=DATE:20260803
TRANSP:TRANSPARENT
SUMMARY:EU AI Act: General application: transparency obligations\, GPAI fi
 nes\, most other rules
DESCRIPTION:The AI Act's general date of application. Article 50 transpare
 ncy obligations (chatbot disclosure\, deepfake labelling\, machine-readab
 le marking of synthetic...\nWhere: European Union\nSource: https://eur-le
 x.europa.eu/eli/reg/2024/1689/oj\nhttps://calendar.fru.dev/events/reg-eu-
 ai-act-2026-08-02-general-application-transparen
URL:https://calendar.fru.dev/events/reg-eu-ai-act-2026-08-02-general-appli
 cation-transparen
CATEGORIES:Compliance deadlines
LOCATION:European Union
END:VEVENT
BEGIN:VEVENT
UID:reg-eu-dsa-2026-08-31-chatgpt-designated-as-vlose-re@calendar.fru.dev
DTSTAMP:20260925T144757Z
DTSTART;VALUE=DATE:20260831
DTEND;VALUE=DATE:20260901
TRANSP:TRANSPARENT
SUMMARY:Digital Services Act: ChatGPT designated as VLOSE; Reddit and Robl
 ox as VLOPs
DESCRIPTION:Commission designated ChatGPT as a very large online search en
 gine and Reddit and Roblox as very large online platforms. They have four
  months (by January...\nWhere: European Union\nSource: https://digital-st
 rategy.ec.europa.eu/en/news/commission-designates-chatgpt-reddit-roblox-u
 nder-digital-services-act\nhttps://calendar.fru.dev/events/reg-eu-dsa-202
 6-08-31-chatgpt-designated-as-vlose-re
URL:https://calendar.fru.dev/events/reg-eu-dsa-2026-08-31-chatgpt-designat
 ed-as-vlose-re
CATEGORIES:Compliance deadlines
LOCATION:European Union
END:VEVENT
BEGIN:VEVENT
UID:reg-kr-pipa-2026-09-11-2026-pipa-amendments-take-effe@calendar.fru.dev
DTSTAMP:20260925T144757Z
DTSTART;VALUE=DATE:20260911
DTEND;VALUE=DATE:20260912
TRANSP:TRANSPARENT
SUMMARY:South Korea PIPA: 2026 PIPA amendments take effect
DESCRIPTION:10%-of-revenue fines\, CEO accountability\, and notice duties 
 for possible breaches apply. Not legal advice.\nWhere: South Korea\nSourc
 e: https://www.law.go.kr/법령/개인정보보호법\nhttps://calendar.f
 ru.dev/events/reg-kr-pipa-2026-09-11-2026-pipa-amendments-take-effe
URL:https://calendar.fru.dev/events/reg-kr-pipa-2026-09-11-2026-pipa-amend
 ments-take-effe
CATEGORIES:Compliance deadlines
LOCATION:South Korea
END:VEVENT
BEGIN:VEVENT
UID:reg-eu-cra-2026-09-11-vulnerability-and-incident-rep@calendar.fru.dev
DTSTAMP:20260925T144757Z
DTSTART;VALUE=DATE:20260911
DTEND;VALUE=DATE:20260912
TRANSP:TRANSPARENT
SUMMARY:Cyber Resilience Act: Vulnerability and incident reporting obligat
 ions apply
DESCRIPTION:Art 14: manufacturers must report actively exploited vulnerabi
 lities and severe incidents (24-hour early warning\, 72-hour notification
 ) via the single...\nWhere: European Union\nSource: https://eur-lex.europ
 a.eu/eli/reg/2024/2847/oj\nhttps://calendar.fru.dev/events/reg-eu-cra-202
 6-09-11-vulnerability-and-incident-rep
URL:https://calendar.fru.dev/events/reg-eu-cra-2026-09-11-vulnerability-an
 d-incident-rep
CATEGORIES:Compliance deadlines
LOCATION:European Union
END:VEVENT
BEGIN:VEVENT
UID:reg-eu-data-act-2026-09-12-access-by-design-for-new-conne@calendar.fru
 .dev
DTSTAMP:20260925T144757Z
DTSTART;VALUE=DATE:20260912
DTEND;VALUE=DATE:20260913
TRANSP:TRANSPARENT
SUMMARY:EU Data Act: Access-by-design for new connected products
DESCRIPTION:Art 3(1) design obligation (product data and related service d
 ata accessible to the user by default) applies to connected products and 
 related services...\nWhere: European Union\nSource: https://eur-lex.europ
 a.eu/eli/reg/2023/2854/oj\nhttps://calendar.fru.dev/events/reg-eu-data-ac
 t-2026-09-12-access-by-design-for-new-conne
URL:https://calendar.fru.dev/events/reg-eu-data-act-2026-09-12-access-by-d
 esign-for-new-conne
CATEGORIES:Compliance deadlines
LOCATION:European Union
END:VEVENT
BEGIN:VEVENT
UID:reg-uk-duaa-2026-09-30-ico-abolished-information-comm@calendar.fru.dev
DTSTAMP:20260925T144757Z
DTSTART;VALUE=DATE:20260930
DTEND;VALUE=DATE:20261001
TRANSP:TRANSPARENT
SUMMARY:Data (Use and Access) Act: ICO abolished; Information Commission t
 akes over
DESCRIPTION:Sections 118-119 commence: office of Information Commissioner 
 abolished and functions transferred to the Information Commission (Commen
 cement No. 9...\nWhere: United Kingdom\nSource: https://www.legislation.g
 ov.uk/uksi/2026/1015/regulation/2/made\nhttps://calendar.fru.dev/events/r
 eg-uk-duaa-2026-09-30-ico-abolished-information-comm
URL:https://calendar.fru.dev/events/reg-uk-duaa-2026-09-30-ico-abolished-i
 nformation-comm
CATEGORIES:Compliance deadlines
LOCATION:United Kingdom
END:VEVENT
BEGIN:VEVENT
UID:reg-us-ct-ctdpa-2026-10-01-pa-26-64-sb-4-amendments-take-@calendar.fru
 .dev
DTSTAMP:20260925T144757Z
DTSTART;VALUE=DATE:20261001
DTEND;VALUE=DATE:20261002
TRANSP:TRANSPARENT
SUMMARY:Connecticut Data Privacy Act (CTDPA): PA 26-64 (SB 4) amendments t
 ake effect
DESCRIPTION:Prohibits controllers and third parties from selling precise g
 eolocation data and enacts data broker and other consumer protection prov
 isions. Not legal advice.\nWhere: Connecticut\nSource: https://www.cga.ct
 .gov/2026/ACT/PA/PDF/2026PA-00064-R00SB-00004-PA.PDF\nhttps://calendar.fr
 u.dev/events/reg-us-ct-ctdpa-2026-10-01-pa-26-64-sb-4-amendments-take-
URL:https://calendar.fru.dev/events/reg-us-ct-ctdpa-2026-10-01-pa-26-64-sb
 -4-amendments-take-
CATEGORIES:Compliance deadlines
LOCATION:Connecticut
END:VEVENT
BEGIN:VEVENT
UID:reg-uk-csr-bill-2026-10-26-lords-report-stage-scheduled@calendar.fru.d
 ev
DTSTAMP:20260925T144757Z
DTSTART;VALUE=DATE:20261026
DTEND;VALUE=DATE:20261027
TRANSP:TRANSPARENT
SUMMARY:UK Cyber Security and Resilience Bill: Lords report stage schedule
 d
DESCRIPTION:House of Lords report stage scheduled (committee stage sat 1\,
  3 and 7 Sept 2026). Not legal advice.\nWhere: United Kingdom\nSource: ht
 tps://bills.parliament.uk/bills/4035\nhttps://calendar.fru.dev/events/reg
 -uk-csr-bill-2026-10-26-lords-report-stage-scheduled
URL:https://calendar.fru.dev/events/reg-uk-csr-bill-2026-10-26-lords-repor
 t-stage-scheduled
CATEGORIES:Compliance deadlines
LOCATION:United Kingdom
STATUS:TENTATIVE
END:VEVENT
BEGIN:VEVENT
UID:reg-us-cmmc-2026-11-10-phase-2-level-2-c3pao-certific@calendar.fru.dev
DTSTAMP:20260925T144757Z
DTSTART;VALUE=DATE:20261110
DTEND;VALUE=DATE:20261111
TRANSP:TRANSPARENT
SUMMARY:CMMC 2.0: Phase 2: Level 2 C3PAO certification
DESCRIPTION:Phase 2 begins one calendar year after Phase 1; applicable sol
 icitations require CMMC Level 2 third-party (C3PAO) certification (32 CFR
  170.3(e)(2)). Not...\nWhere: United States (Federal)\nSource: https://ww
 w.federalregister.gov/documents/2024/10/15/2024-22905/cybersecurity-matur
 ity-model-certification-cmmc-program\nhttps://calendar.fru.dev/events/reg
 -us-cmmc-2026-11-10-phase-2-level-2-c3pao-certific
URL:https://calendar.fru.dev/events/reg-us-cmmc-2026-11-10-phase-2-level-2
 -c3pao-certific
CATEGORIES:Compliance deadlines
LOCATION:United States (Federal)
END:VEVENT
BEGIN:VEVENT
UID:reg-in-dpdp-2026-11-13-consent-manager-registration-r@calendar.fru.dev
DTSTAMP:20260925T144757Z
DTSTART;VALUE=DATE:20261113
DTEND;VALUE=DATE:20261114
TRANSP:TRANSPARENT
SUMMARY:India DPDP Act: Consent Manager registration rule in force (12 mon
 ths)
DESCRIPTION:Rule 4 (registration and obligations of Consent Managers) come
 s into force one year after publication. Not legal advice.\nWhere: India\
 nSource: https://egazette.gov.in/WriteReadData/2025/267650.pdf\nhttps://c
 alendar.fru.dev/events/reg-in-dpdp-2026-11-13-consent-manager-registratio
 n-r
URL:https://calendar.fru.dev/events/reg-in-dpdp-2026-11-13-consent-manager
 -registration-r
CATEGORIES:Compliance deadlines
LOCATION:India
END:VEVENT
BEGIN:VEVENT
UID:reg-cl-pdpl-2026-12-01-law-in-force@calendar.fru.dev
DTSTAMP:20260925T144757Z
DTSTART;VALUE=DATE:20261201
DTEND;VALUE=DATE:20261202
TRANSP:TRANSPARENT
SUMMARY:Chile Personal Data Protection Law (Ley 21.719): Law in force
DESCRIPTION:Main obligations apply and the Personal Data Protection Agency
  begins supervision. Not legal advice.\nWhere: Chile\nSource: https://www
 .bcn.cl/leychile/navegar?idNorma=1209272\nhttps://calendar.fru.dev/events
 /reg-cl-pdpl-2026-12-01-law-in-force
URL:https://calendar.fru.dev/events/reg-cl-pdpl-2026-12-01-law-in-force
CATEGORIES:Compliance deadlines
LOCATION:Chile
END:VEVENT
BEGIN:VEVENT
UID:reg-eu-ai-act-2026-12-02-new-bans-on-sexual-deepfakes-a@calendar.fru.d
 ev
DTSTAMP:20260925T144757Z
DTSTART;VALUE=DATE:20261202
DTEND;VALUE=DATE:20261203
TRANSP:TRANSPARENT
SUMMARY:EU AI Act: New bans on sexual deepfakes and CSAM generation; Art 5
 0(2) grace period ends
DESCRIPTION:New Art 5(1)(ba)/(bb) prohibitions on AI systems that generate
  non-consensual intimate imagery of identifiable persons or child sexual 
 abuse material apply....\nWhere: European Union\nSource: https://eur-lex.
 europa.eu/eli/reg/2026/1744/oj\nhttps://calendar.fru.dev/events/reg-eu-ai
 -act-2026-12-02-new-bans-on-sexual-deepfakes-a
URL:https://calendar.fru.dev/events/reg-eu-ai-act-2026-12-02-new-bans-on-s
 exual-deepfakes-a
CATEGORIES:Compliance deadlines
LOCATION:European Union
END:VEVENT
BEGIN:VEVENT
UID:reg-eu-pld-2026-12-09-transposition-deadline-old-pld@calendar.fru.dev
DTSTAMP:20260925T144757Z
DTSTART;VALUE=DATE:20261209
DTEND;VALUE=DATE:20261210
TRANSP:TRANSPARENT
SUMMARY:Product Liability Directive: Transposition deadline; old PLD repea
 led
DESCRIPTION:Member States must transpose by 9 Dec 2026 (Art 22). Directive
  85/374/EEC is repealed from that date but still applies to products plac
 ed on the market...\nWhere: European Union\nSource: https://eur-lex.europ
 a.eu/eli/dir/2024/2853/oj\nhttps://calendar.fru.dev/events/reg-eu-pld-202
 6-12-09-transposition-deadline-old-pld
URL:https://calendar.fru.dev/events/reg-eu-pld-2026-12-09-transposition-de
 adline-old-pld
CATEGORIES:Compliance deadlines
LOCATION:European Union
END:VEVENT
BEGIN:VEVENT
UID:reg-au-privacy-act-2026-12-10-automated-decision-making-tran@calendar.
 fru.dev
DTSTAMP:20260925T144757Z
DTSTART;VALUE=DATE:20261210
DTEND;VALUE=DATE:20261211
TRANSP:TRANSPARENT
SUMMARY:Australia Privacy Act: Automated decision-making transparency appl
 ies
DESCRIPTION:Privacy policies must disclose the kinds of personal informati
 on used in substantially automated decisions that significantly affect in
 dividuals (24 months...\nWhere: Australia\nSource: https://www.legislatio
 n.gov.au/C2024A00128/asmade\nhttps://calendar.fru.dev/events/reg-au-priva
 cy-act-2026-12-10-automated-decision-making-tran
URL:https://calendar.fru.dev/events/reg-au-privacy-act-2026-12-10-automate
 d-decision-making-tran
CATEGORIES:Compliance deadlines
LOCATION:Australia
END:VEVENT
BEGIN:VEVENT
UID:reg-au-privacy-act-2026-12-10-childrens-online-privacy-code-@calendar.
 fru.dev
DTSTAMP:20260925T144757Z
DTSTART;VALUE=DATE:20261210
DTEND;VALUE=DATE:20261211
TRANSP:TRANSPARENT
SUMMARY:Australia Privacy Act: Children's Online Privacy Code must be regi
 stered
DESCRIPTION:OAIC must develop and register the Children's Online Privacy C
 ode within 24 months of Royal Assent. Not legal advice.\nWhere: Australia
 \nSource: https://www.oaic.gov.au/privacy/privacy-registers/privacy-codes
 /childrens-online-privacy-code\nhttps://calendar.fru.dev/events/reg-au-pr
 ivacy-act-2026-12-10-childrens-online-privacy-code-
URL:https://calendar.fru.dev/events/reg-au-privacy-act-2026-12-10-children
 s-online-privacy-code-
CATEGORIES:Compliance deadlines
LOCATION:Australia
END:VEVENT
BEGIN:VEVENT
UID:reg-eu-eidas2-2026-12-24-member-states-must-provide-eu-@calendar.fru.d
 ev
DTSTAMP:20260925T144757Z
DTSTART;VALUE=DATE:20261224
DTEND;VALUE=DATE:20261225
TRANSP:TRANSPARENT
SUMMARY:eIDAS 2 / EU Digital Identity Wallet: Member States must provide E
 U Digital Identity Wallets
DESCRIPTION:Each Member State must provide at least one wallet within 24 m
 onths of the entry into force of the implementing acts under Arts 5a(23) 
 and 5c(6) (Art...\nWhere: European Union\nSource: https://eur-lex.europa.
 eu/eli/reg_impl/2024/2977/oj\nhttps://calendar.fru.dev/events/reg-eu-eida
 s2-2026-12-24-member-states-must-provide-eu-
URL:https://calendar.fru.dev/events/reg-eu-eidas2-2026-12-24-member-states
 -must-provide-eu-
CATEGORIES:Compliance deadlines
LOCATION:European Union
END:VEVENT
BEGIN:VEVENT
UID:reg-us-co-ai-act-2027-01-01-admt-obligations-apply@calendar.fru.dev
DTSTAMP:20260925T144757Z
DTSTART;VALUE=DATE:20270101
DTEND;VALUE=DATE:20270102
TRANSP:TRANSPARENT
SUMMARY:Colorado AI Act: ADMT obligations apply
DESCRIPTION:Developer documentation\, consumer notices\, post-adverse-outc
 ome disclosure\, correction and human-review rights take effect. Not lega
 l advice.\nWhere: Colorado\nSource: https://leg.colorado.gov/bills/sb26-1
 89\nhttps://calendar.fru.dev/events/reg-us-co-ai-act-2027-01-01-admt-obli
 gations-apply
URL:https://calendar.fru.dev/events/reg-us-co-ai-act-2027-01-01-admt-oblig
 ations-apply
CATEGORIES:Compliance deadlines
LOCATION:Colorado
END:VEVENT
BEGIN:VEVENT
UID:reg-us-de-dpdpa-2027-01-01-amended-thresholds-and-third-p@calendar.fru
 .dev
DTSTAMP:20260925T144757Z
DTSTART;VALUE=DATE:20270101
DTEND;VALUE=DATE:20270102
TRANSP:TRANSPARENT
SUMMARY:Delaware Personal Data Privacy Act (DPDPA): Amended thresholds and
  third-party duties take effect
DESCRIPTION:Applicability drops to 10\,000 consumers (or 5\,000 + 20% reve
 nue from sale) and new third-party duties (12D-107A) apply. Not legal adv
 ice.\nWhere: Delaware\nSource: https://delcode.delaware.gov/title6/c012d/
 index.html\nhttps://calendar.fru.dev/events/reg-us-de-dpdpa-2027-01-01-am
 ended-thresholds-and-third-p
URL:https://calendar.fru.dev/events/reg-us-de-dpdpa-2027-01-01-amended-thr
 esholds-and-third-p
CATEGORIES:Compliance deadlines
LOCATION:Delaware
END:VEVENT
BEGIN:VEVENT
UID:reg-us-la-ldpa-2027-01-01-louisiana-data-privacy-act-tak@calendar.fru.
 dev
DTSTAMP:20260925T144757Z
DTSTART;VALUE=DATE:20270101
DTEND;VALUE=DATE:20270102
TRANSP:TRANSPARENT
SUMMARY:Louisiana Data Privacy Act: Louisiana Data Privacy Act takes effec
 t
DESCRIPTION:Consumer rights and controller duties apply (Act 502\, Section
  2); data protection assessment requirements apply to processing from thi
 s date. Not legal advice.\nWhere: Louisiana\nSource: https://legis.la.gov
 /legis/ViewDocument.aspx?d=1480202\nhttps://calendar.fru.dev/events/reg-u
 s-la-ldpa-2027-01-01-louisiana-data-privacy-act-tak
URL:https://calendar.fru.dev/events/reg-us-la-ldpa-2027-01-01-louisiana-da
 ta-privacy-act-tak
CATEGORIES:Compliance deadlines
LOCATION:Louisiana
END:VEVENT
BEGIN:VEVENT
UID:reg-us-nh-privacy-2027-01-01-ban-on-selling-personal-data-o@calendar.f
 ru.dev
DTSTAMP:20260925T144757Z
DTSTART;VALUE=DATE:20270101
DTEND;VALUE=DATE:20270102
TRANSP:TRANSPARENT
SUMMARY:New Hampshire Privacy Act: Ban on selling personal data of childre
 n under 13 (HB 1460)
DESCRIPTION:HB 1460 (2026\, ch. 168) prohibits controllers from selling th
 e personal data of a child under 13. Not legal advice.\nWhere: New Hampsh
 ire\nSource: https://gc.nh.gov/bill_status/billinfo.aspx?id=2443&inflect=
 2\nhttps://calendar.fru.dev/events/reg-us-nh-privacy-2027-01-01-ban-on-se
 lling-personal-data-o
URL:https://calendar.fru.dev/events/reg-us-nh-privacy-2027-01-01-ban-on-se
 lling-personal-data-o
CATEGORIES:Compliance deadlines
LOCATION:New Hampshire
END:VEVENT
BEGIN:VEVENT
UID:reg-us-ny-raise-2027-01-01-raise-act-takes-effect@calendar.fru.dev
DTSTAMP:20260925T144757Z
DTSTART;VALUE=DATE:20270101
DTEND;VALUE=DATE:20270102
TRANSP:TRANSPARENT
SUMMARY:NY RAISE Act: RAISE Act takes effect
DESCRIPTION:Transparency reports\, frontier AI frameworks\, incident repor
 ting and DFS disclosure filings apply. Not legal advice.\nWhere: New York
 \nSource: https://www.nysenate.gov/legislation/bills/2025/S8828\nhttps://
 calendar.fru.dev/events/reg-us-ny-raise-2027-01-01-raise-act-takes-effect
URL:https://calendar.fru.dev/events/reg-us-ny-raise-2027-01-01-raise-act-t
 akes-effect
CATEGORIES:Compliance deadlines
LOCATION:New York
END:VEVENT
BEGIN:VEVENT
UID:reg-us-ok-okcdpa-2027-01-01-oklahoma-consumer-data-privacy@calendar.fr
 u.dev
DTSTAMP:20260925T144757Z
DTSTART;VALUE=DATE:20270101
DTEND;VALUE=DATE:20270102
TRANSP:TRANSPARENT
SUMMARY:Oklahoma OKCDPA: Oklahoma Consumer Data Privacy Act takes effect
DESCRIPTION:All OKCDPA obligations and consumer rights apply. Not legal ad
 vice.\nWhere: Oklahoma\nSource: https://www.okhouse.gov/posts/news-202603
 23_2\nhttps://calendar.fru.dev/events/reg-us-ok-okcdpa-2027-01-01-oklahom
 a-consumer-data-privacy
URL:https://calendar.fru.dev/events/reg-us-ok-okcdpa-2027-01-01-oklahoma-c
 onsumer-data-privacy
CATEGORIES:Compliance deadlines
LOCATION:Oklahoma
END:VEVENT
BEGIN:VEVENT
UID:reg-us-ut-ucpa-2027-01-01-ucpa-extends-to-motor-vehicle-@calendar.fru.
 dev
DTSTAMP:20260925T144757Z
DTSTART;VALUE=DATE:20270101
DTEND;VALUE=DATE:20270102
TRANSP:TRANSPARENT
SUMMARY:Utah UCPA: UCPA extends to motor vehicle manufacturers
DESCRIPTION:Motor vehicle manufacturers whose vehicles are sold or leased 
 in Utah and that collect personal data through vehicle data systems are c
 overed regardless of...\nWhere: Utah\nSource: https://le.utah.gov/xcode/T
 itle13/Chapter61/13-61-S102.html\nhttps://calendar.fru.dev/events/reg-us-
 ut-ucpa-2027-01-01-ucpa-extends-to-motor-vehicle-
URL:https://calendar.fru.dev/events/reg-us-ut-ucpa-2027-01-01-ucpa-extends
 -to-motor-vehicle-
CATEGORIES:Compliance deadlines
LOCATION:Utah
END:VEVENT
BEGIN:VEVENT
UID:reg-us-ca-sb942-2027-01-01-large-online-platform-and-host@calendar.fru
 .dev
DTSTAMP:20260925T144757Z
DTSTART;VALUE=DATE:20270101
DTEND;VALUE=DATE:20270102
TRANSP:TRANSPARENT
SUMMARY:California AI Transparency Act (SB 942): Large online platform and
  hosting platform duties
DESCRIPTION:Large online platforms and GenAI hosting platforms must meet t
 he provenance duties added by AB 853. Not legal advice.\nWhere: Californi
 a\nSource: https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?b
 ill_id=202520260AB853\nhttps://calendar.fru.dev/events/reg-us-ca-sb942-20
 27-01-01-large-online-platform-and-host
URL:https://calendar.fru.dev/events/reg-us-ca-sb942-2027-01-01-large-onlin
 e-platform-and-host
CATEGORIES:Compliance deadlines
LOCATION:California
END:VEVENT
BEGIN:VEVENT
UID:reg-us-ca-sb53-2027-01-01-first-oes-anonymized-incident-@calendar.fru.
 dev
DTSTAMP:20260925T144757Z
DTSTART;VALUE=DATE:20270101
DTEND;VALUE=DATE:20270102
TRANSP:TRANSPARENT
SUMMARY:California SB 53 (TFAIA): First OES anonymized incident report and
  CDT definition review
DESCRIPTION:OES begins publishing annual anonymized incident summaries and
  the Department of Technology begins annual review of the act's definitio
 ns; the CalCompute...\nWhere: California\nSource: https://leginfo.legisla
 ture.ca.gov/faces/billNavClient.xhtml?bill_id=202520260SB53\nhttps://cale
 ndar.fru.dev/events/reg-us-ca-sb53-2027-01-01-first-oes-anonymized-incide
 nt-
URL:https://calendar.fru.dev/events/reg-us-ca-sb53-2027-01-01-first-oes-an
 onymized-incident-
CATEGORIES:Compliance deadlines
LOCATION:California
END:VEVENT
BEGIN:VEVENT
UID:reg-us-ca-ccpa-2027-01-01-admt-requirements-compliance-d@calendar.fru.
 dev
DTSTAMP:20260925T144757Z
DTSTART;VALUE=DATE:20270101
DTEND;VALUE=DATE:20270102
TRANSP:TRANSPARENT
SUMMARY:CCPA / CPRA: ADMT requirements compliance date
DESCRIPTION:Businesses using ADMT for significant decisions must comply wi
 th Article 11 (pre-use notice\, opt-out\, access rights) by this date (11
  CCR 7200(b)). Not...\nWhere: California\nSource: https://cppa.ca.gov/reg
 ulations/pdf/ccpa_updates_cyber_risk_admt_appr_text.pdf\nhttps://calendar
 .fru.dev/events/reg-us-ca-ccpa-2027-01-01-admt-requirements-compliance-d
URL:https://calendar.fru.dev/events/reg-us-ca-ccpa-2027-01-01-admt-require
 ments-compliance-d
CATEGORIES:Compliance deadlines
LOCATION:California
END:VEVENT
BEGIN:VEVENT
UID:reg-us-ca-ccpa-2027-01-01-browsers-must-support-opt-out-@calendar.fru.
 dev
DTSTAMP:20260925T144757Z
DTSTART;VALUE=DATE:20270101
DTEND;VALUE=DATE:20270102
TRANSP:TRANSPARENT
SUMMARY:CCPA / CPRA: Browsers must support opt-out preference signal (AB 5
 66)
DESCRIPTION:Businesses that develop or maintain a browser must include con
 sumer-configurable functionality to send an opt-out preference signal (Ci
 v. Code 1798.136\,...\nWhere: California\nSource: https://leginfo.legisla
 ture.ca.gov/faces/billStatusClient.xhtml?bill_id=202520260AB566\nhttps://
 calendar.fru.dev/events/reg-us-ca-ccpa-2027-01-01-browsers-must-support-o
 pt-out-
URL:https://calendar.fru.dev/events/reg-us-ca-ccpa-2027-01-01-browsers-mus
 t-support-opt-out-
CATEGORIES:Compliance deadlines
LOCATION:California
END:VEVENT
BEGIN:VEVENT
UID:reg-us-co-ai-act-2027-01-01-ag-rules-due@calendar.fru.dev
DTSTAMP:20260925T144757Z
DTSTART;VALUE=DATE:20270101
DTEND;VALUE=DATE:20270102
TRANSP:TRANSPARENT
SUMMARY:Colorado AI Act: AG rules due
DESCRIPTION:Attorney General must adopt rules clarifying the post-adverse-
 outcome disclosure requirements. Not legal advice.\nWhere: Colorado\nSour
 ce: https://leg.colorado.gov/bills/sb26-189\nhttps://calendar.fru.dev/eve
 nts/reg-us-co-ai-act-2027-01-01-ag-rules-due
URL:https://calendar.fru.dev/events/reg-us-co-ai-act-2027-01-01-ag-rules-d
 ue
CATEGORIES:Compliance deadlines
LOCATION:Colorado
END:VEVENT
BEGIN:VEVENT
UID:reg-us-ct-ctdpa-2027-01-01-data-broker-registration-requi@calendar.fru
 .dev
DTSTAMP:20260925T144757Z
DTSTART;VALUE=DATE:20270101
DTEND;VALUE=DATE:20270102
TRANSP:TRANSPARENT
SUMMARY:Connecticut Data Privacy Act (CTDPA): Data broker registration req
 uired
DESCRIPTION:Data brokers may not sell or license brokered personal data in
  Connecticut unless registered with the Department of Consumer Protection
  ($2\,500 initial...\nWhere: Connecticut\nSource: https://www.cga.ct.gov/
 2026/ACT/PA/PDF/2026PA-00064-R00SB-00004-PA.PDF\nhttps://calendar.fru.dev
 /events/reg-us-ct-ctdpa-2027-01-01-data-broker-registration-requi
URL:https://calendar.fru.dev/events/reg-us-ct-ctdpa-2027-01-01-data-broker
 -registration-requi
CATEGORIES:Compliance deadlines
LOCATION:Connecticut
END:VEVENT
BEGIN:VEVENT
UID:reg-eu-data-act-2027-01-12-cloud-switching-charges-abolis@calendar.fru
 .dev
DTSTAMP:20260925T144757Z
DTSTART;VALUE=DATE:20270112
DTEND;VALUE=DATE:20270113
TRANSP:TRANSPARENT
SUMMARY:EU Data Act: Cloud switching charges abolished
DESCRIPTION:Providers of data processing services may no longer impose any
  switching charges on customers (Art 29(1)). Not legal advice.\nWhere: Eu
 ropean Union\nSource: https://eur-lex.europa.eu/eli/reg/2023/2854/oj\nhtt
 ps://calendar.fru.dev/events/reg-eu-data-act-2027-01-12-cloud-switching-c
 harges-abolis
URL:https://calendar.fru.dev/events/reg-eu-data-act-2027-01-12-cloud-switc
 hing-charges-abolis
CATEGORIES:Compliance deadlines
LOCATION:European Union
END:VEVENT
BEGIN:VEVENT
UID:reg-id-pdp-2027-01-16-implementing-regulation-gr-33-@calendar.fru.dev
DTSTAMP:20260925T144757Z
DTSTART;VALUE=DATE:20270116
DTEND;VALUE=DATE:20270117
TRANSP:TRANSPARENT
SUMMARY:Indonesia PDP Law: Implementing regulation GR 33/2026 takes effect
DESCRIPTION:Detailed PDP implementing rules (DPIA\, cross-border\, childre
 n's consent) apply\, 6 months after the 16 Jul 2026 enactment. Not legal 
 advice.\nWhere: Indonesia\nSource: https://www.kk-advocates.com/news/read
 /indonesia-gr-pdp-personal-data-protection-compliance-regime-new-phase\nh
 ttps://calendar.fru.dev/events/reg-id-pdp-2027-01-16-implementing-regulat
 ion-gr-33-
URL:https://calendar.fru.dev/events/reg-id-pdp-2027-01-16-implementing-reg
 ulation-gr-33-
CATEGORIES:Compliance deadlines
LOCATION:Indonesia
END:VEVENT
BEGIN:VEVENT
UID:reg-us-ca-delete-act-2027-01-31-annual-data-broker-registratio@calenda
 r.fru.dev
DTSTAMP:20260925T144757Z
DTSTART;VALUE=DATE:20270131
DTEND;VALUE=DATE:20270201
TRANSP:TRANSPARENT
SUMMARY:California Delete Act / DROP: Annual data broker registration dead
 line
DESCRIPTION:Data brokers must renew registration with CalPrivacy by Januar
 y 31 following each year they meet the definition. Not legal advice.\nWhe
 re: California\nSource: https://leginfo.legislature.ca.gov/faces/codes_di
 splaySection.xhtml?lawCode=CIV&sectionNum=1798.99.82\nhttps://calendar.fr
 u.dev/events/reg-us-ca-delete-act-2027-01-31-annual-data-broker-registrat
 io
URL:https://calendar.fru.dev/events/reg-us-ca-delete-act-2027-01-31-annual
 -data-broker-registratio
CATEGORIES:Compliance deadlines
LOCATION:California
END:VEVENT
BEGIN:VEVENT
UID:reg-vn-ai-law-2027-03-01-transition-ends-for-existing-a@calendar.fru.d
 ev
DTSTAMP:20260925T144757Z
DTSTART;VALUE=DATE:20270301
DTEND;VALUE=DATE:20270302
TRANSP:TRANSPARENT
SUMMARY:Vietnam AI Law: Transition ends for existing AI systems (general)
DESCRIPTION:Existing AI systems in most sectors must comply (12-month tran
 sition). Not legal advice.\nWhere: Vietnam\nSource: https://www.vilaf.com
 .vn/blog/vietnam-enacts-its-first-law-on-artificial-intelligence-key-regu
 latory-obligations-from-1-march-2026/\nhttps://calendar.fru.dev/events/re
 g-vn-ai-law-2027-03-01-transition-ends-for-existing-a
URL:https://calendar.fru.dev/events/reg-vn-ai-law-2027-03-01-transition-en
 ds-for-existing-a
CATEGORIES:Compliance deadlines
LOCATION:Vietnam
END:VEVENT
BEGIN:VEVENT
UID:reg-eu-ehds-2027-03-26-ehds-general-application-date@calendar.fru.dev
DTSTAMP:20260925T144757Z
DTSTART;VALUE=DATE:20270326
DTEND;VALUE=DATE:20270327
TRANSP:TRANSPARENT
SUMMARY:European Health Data Space (EHDS): EHDS general application date
DESCRIPTION:The regulation applies generally from 26 Mar 2027\, subject to
  the phased exceptions below (final article). Not legal advice.\nWhere: E
 uropean Union\nSource: https://eur-lex.europa.eu/eli/reg/2025/327/oj\nhtt
 ps://calendar.fru.dev/events/reg-eu-ehds-2027-03-26-ehds-general-applicat
 ion-date
URL:https://calendar.fru.dev/events/reg-eu-ehds-2027-03-26-ehds-general-ap
 plication-date
CATEGORIES:Compliance deadlines
LOCATION:European Union
END:VEVENT
BEGIN:VEVENT
UID:reg-us-md-modpa-2027-04-01-discretionary-60-day-cure-peri@calendar.fru
 .dev
DTSTAMP:20260925T144757Z
DTSTART;VALUE=DATE:20270401
DTEND;VALUE=DATE:20270402
TRANSP:TRANSPARENT
SUMMARY:Maryland Online Data Privacy Act (MODPA): Discretionary 60-day cur
 e period ends
DESCRIPTION:The Division's discretionary notice-and-cure (at least 60 days
 ) applies only to violations occurring on or before April 1\, 2027 (Com. 
 Law 14-4614). Not...\nWhere: Maryland\nSource: https://mgaleg.maryland.go
 v/2024RS/Chapters_noln/CH_455_sb0541e.pdf\nhttps://calendar.fru.dev/event
 s/reg-us-md-modpa-2027-04-01-discretionary-60-day-cure-peri
URL:https://calendar.fru.dev/events/reg-us-md-modpa-2027-04-01-discretiona
 ry-60-day-cure-peri
CATEGORIES:Compliance deadlines
LOCATION:Maryland
END:VEVENT
BEGIN:VEVENT
UID:reg-eu-gdpr-2027-04-02-gdpr-procedural-regulation-app@calendar.fru.dev
DTSTAMP:20260925T144757Z
DTSTART;VALUE=DATE:20270402
DTEND;VALUE=DATE:20270403
TRANSP:TRANSPARENT
SUMMARY:GDPR: GDPR Procedural Regulation applies
DESCRIPTION:Harmonised rules for cross-border complaint admissibility\, ri
 ghts to be heard and access to preliminary findings\, and investigation t
 imelines apply to DPAs...\nWhere: European Union\nSource: https://eur-lex
 .europa.eu/eli/reg/2025/2518/oj\nhttps://calendar.fru.dev/events/reg-eu-g
 dpr-2027-04-02-gdpr-procedural-regulation-app
URL:https://calendar.fru.dev/events/reg-eu-gdpr-2027-04-02-gdpr-procedural
 -regulation-app
CATEGORIES:Compliance deadlines
LOCATION:European Union
END:VEVENT
BEGIN:VEVENT
UID:reg-eu-nis2-2027-04-17-next-biennial-entity-notificat@calendar.fru.dev
DTSTAMP:20260925T144757Z
DTSTART;VALUE=DATE:20270417
DTEND;VALUE=DATE:20270418
TRANSP:TRANSPARENT
SUMMARY:NIS2: Next biennial entity notification
DESCRIPTION:Competent authorities notify the Commission and Cooperation Gr
 oup of the number of essential and important entities\, repeated every tw
 o years after 17 Apr...\nWhere: European Union\nSource: https://eur-lex.e
 uropa.eu/eli/dir/2022/2555/oj\nhttps://calendar.fru.dev/events/reg-eu-nis
 2-2027-04-17-next-biennial-entity-notificat
URL:https://calendar.fru.dev/events/reg-eu-nis2-2027-04-17-next-biennial-e
 ntity-notificat
CATEGORIES:Compliance deadlines
LOCATION:European Union
END:VEVENT
BEGIN:VEVENT
UID:reg-us-al-apdpa-2027-05-01-apdpa-takes-effect@calendar.fru.dev
DTSTAMP:20260925T144757Z
DTSTART;VALUE=DATE:20270501
DTEND;VALUE=DATE:20270502
TRANSP:TRANSPARENT
SUMMARY:Alabama Personal Data Protection Act (APDPA): APDPA takes effect
DESCRIPTION:Consumer rights and controller/processor obligations apply (HB
  351 section 12). Not legal advice.\nWhere: Alabama\nSource: https://alis
 on.legislature.state.al.us/files/pdf/SearchableInstruments/2026RS/HB351-e
 nr.pdf\nhttps://calendar.fru.dev/events/reg-us-al-apdpa-2027-05-01-apdpa-
 takes-effect
URL:https://calendar.fru.dev/events/reg-us-al-apdpa-2027-05-01-apdpa-takes
 -effect
CATEGORIES:Compliance deadlines
LOCATION:Alabama
END:VEVENT
BEGIN:VEVENT
UID:reg-in-dpdp-2027-05-13-main-data-fiduciary-obligation@calendar.fru.dev
DTSTAMP:20260925T144757Z
DTSTART;VALUE=DATE:20270513
DTEND;VALUE=DATE:20270514
TRANSP:TRANSPARENT
SUMMARY:India DPDP Act: Main data fiduciary obligations apply (18 months)
DESCRIPTION:Rules 3\, 5-16\, 22 and 23 (notice\, security safeguards\, bre
 ach notification\, retention\, children's consent\, SDF duties\, cross-bo
 rder) come into force 18...\nWhere: India\nSource: https://egazette.gov.i
 n/WriteReadData/2025/267650.pdf\nhttps://calendar.fru.dev/events/reg-in-d
 pdp-2027-05-13-main-data-fiduciary-obligation
URL:https://calendar.fru.dev/events/reg-in-dpdp-2027-05-13-main-data-fiduc
 iary-obligation
CATEGORIES:Compliance deadlines
LOCATION:India
END:VEVENT
BEGIN:VEVENT
UID:reg-us-ca-sb243-2027-07-01-first-annual-report-to-office-@calendar.fru
 .dev
DTSTAMP:20260925T144757Z
DTSTART;VALUE=DATE:20270701
DTEND;VALUE=DATE:20270702
TRANSP:TRANSPARENT
SUMMARY:California SB 243 (companion chatbots): First annual report to Off
 ice of Suicide Prevention
DESCRIPTION:Operators begin annual reporting on crisis referrals and detec
 tion protocols. Not legal advice.\nWhere: California\nSource: https://leg
 info.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202520260SB243\
 nhttps://calendar.fru.dev/events/reg-us-ca-sb243-2027-07-01-first-annual-
 report-to-office-
URL:https://calendar.fru.dev/events/reg-us-ca-sb243-2027-07-01-first-annua
 l-report-to-office-
CATEGORIES:Compliance deadlines
LOCATION:California
END:VEVENT
BEGIN:VEVENT
UID:reg-kr-pipa-2027-07-01-mandatory-isms-p-certification@calendar.fru.dev
DTSTAMP:20260925T144757Z
DTSTART;VALUE=DATE:20270701
DTEND;VALUE=DATE:20270702
TRANSP:TRANSPARENT
SUMMARY:South Korea PIPA: Mandatory ISMS-P certification
DESCRIPTION:ISMS-P certification becomes mandatory for private entities me
 eting the statutory criteria. Not legal advice.\nWhere: South Korea\nSour
 ce: https://www.law.go.kr/법령/개인정보보호법\nhttps://calendar.
 fru.dev/events/reg-kr-pipa-2027-07-01-mandatory-isms-p-certification
URL:https://calendar.fru.dev/events/reg-kr-pipa-2027-07-01-mandatory-isms-
 p-certification
CATEGORIES:Compliance deadlines
LOCATION:South Korea
END:VEVENT
BEGIN:VEVENT
UID:reg-us-ut-aipa-2027-07-01-scheduled-repeal-of-title-13-c@calendar.fru.
 dev
DTSTAMP:20260925T144757Z
DTSTART;VALUE=DATE:20270701
DTEND;VALUE=DATE:20270702
TRANSP:TRANSPARENT
SUMMARY:Utah AI Policy Act: Scheduled repeal of Title 13\, Ch. 72
DESCRIPTION:SB 332 extends the AI Policy Act repeal date from May 1\, 2025
  to July 1\, 2027. Not legal advice.\nWhere: Utah\nSource: https://le.uta
 h.gov/~2025/bills/static/SB0332.html\nhttps://calendar.fru.dev/events/reg
 -us-ut-aipa-2027-07-01-scheduled-repeal-of-title-13-c
URL:https://calendar.fru.dev/events/reg-us-ut-aipa-2027-07-01-scheduled-re
 peal-of-title-13-c
CATEGORIES:Compliance deadlines
LOCATION:Utah
END:VEVENT
BEGIN:VEVENT
UID:reg-us-la-ldpa-2027-07-31-30-day-cure-period-expires@calendar.fru.dev
DTSTAMP:20260925T144757Z
DTSTART;VALUE=DATE:20270731
DTEND;VALUE=DATE:20270801
TRANSP:TRANSPARENT
SUMMARY:Louisiana Data Privacy Act: 30-day cure period expires
DESCRIPTION:AG's obligation to give 30-day notice and allow cure before in
 vestigating applies only from Jan 1 through July 31\, 2027 (R.S. 51:1780.
 5(D)). Not legal advice.\nWhere: Louisiana\nSource: https://legis.la.gov/
 legis/ViewDocument.aspx?d=1480202\nhttps://calendar.fru.dev/events/reg-us
 -la-ldpa-2027-07-31-30-day-cure-period-expires
URL:https://calendar.fru.dev/events/reg-us-la-ldpa-2027-07-31-30-day-cure-
 period-expires
CATEGORIES:Compliance deadlines
LOCATION:Louisiana
END:VEVENT
BEGIN:VEVENT
UID:reg-eu-ai-act-2027-08-02-legacy-gpai-models-must-comply@calendar.fru.d
 ev
DTSTAMP:20260925T144757Z
DTSTART;VALUE=DATE:20270802
DTEND;VALUE=DATE:20270803
TRANSP:TRANSPARENT
SUMMARY:EU AI Act: Legacy GPAI models must comply; national AI sandboxes o
 perational
DESCRIPTION:Providers of GPAI models placed on the market before 2 Aug 202
 5 must comply (Art 111(3)). Each Member State must have at least one nati
 onal AI regulatory...\nWhere: European Union\nSource: https://eur-lex.eur
 opa.eu/eli/reg/2024/1689/oj\nhttps://calendar.fru.dev/events/reg-eu-ai-ac
 t-2027-08-02-legacy-gpai-models-must-comply
URL:https://calendar.fru.dev/events/reg-eu-ai-act-2027-08-02-legacy-gpai-m
 odels-must-comply
CATEGORIES:Compliance deadlines
LOCATION:European Union
END:VEVENT
BEGIN:VEVENT
UID:reg-vn-ai-law-2027-09-01-transition-ends-for-existing-a@calendar.fru.d
 ev
DTSTAMP:20260925T144757Z
DTSTART;VALUE=DATE:20270901
DTEND;VALUE=DATE:20270902
TRANSP:TRANSPARENT
SUMMARY:Vietnam AI Law: Transition ends for existing AI systems in health\
 , education and finance
DESCRIPTION:Existing AI systems in healthcare\, education and finance must
  comply (18-month transition). Not legal advice.\nWhere: Vietnam\nSource:
  https://www.vilaf.com.vn/blog/vietnam-enacts-its-first-law-on-artificial
 -intelligence-key-regulatory-obligations-from-1-march-2026/\nhttps://cale
 ndar.fru.dev/events/reg-vn-ai-law-2027-09-01-transition-ends-for-existing
 -a
URL:https://calendar.fru.dev/events/reg-vn-ai-law-2027-09-01-transition-en
 ds-for-existing-a
CATEGORIES:Compliance deadlines
LOCATION:Vietnam
END:VEVENT
BEGIN:VEVENT
UID:reg-eu-data-act-2027-09-12-unfair-terms-rules-extend-to-o@calendar.fru
 .dev
DTSTAMP:20260925T144757Z
DTSTART;VALUE=DATE:20270912
DTEND;VALUE=DATE:20270913
TRANSP:TRANSPARENT
SUMMARY:EU Data Act: Unfair-terms rules extend to older long-term contract
 s
DESCRIPTION:Chapter IV (unfair contractual terms) applies to contracts con
 cluded on or before 12 Sep 2025 that are of indefinite duration or expire
  at least 10 years...\nWhere: European Union\nSource: https://eur-lex.eur
 opa.eu/eli/reg/2023/2854/oj\nhttps://calendar.fru.dev/events/reg-eu-data-
 act-2027-09-12-unfair-terms-rules-extend-to-o
URL:https://calendar.fru.dev/events/reg-eu-data-act-2027-09-12-unfair-term
 s-rules-extend-to-o
CATEGORIES:Compliance deadlines
LOCATION:European Union
END:VEVENT
BEGIN:VEVENT
UID:reg-eu-nis2-2027-10-17-commission-review-of-nis2@calendar.fru.dev
DTSTAMP:20260925T144757Z
DTSTART;VALUE=DATE:20271017
DTEND;VALUE=DATE:20271018
TRANSP:TRANSPARENT
SUMMARY:NIS2: Commission review of NIS2
DESCRIPTION:Commission must review the functioning of NIS2 and report to P
 arliament and Council\, then every 36 months (Art 40). Not legal advice.\
 nWhere: European Union\nSource: https://eur-lex.europa.eu/eli/dir/2022/25
 55/oj\nhttps://calendar.fru.dev/events/reg-eu-nis2-2027-10-17-commission-
 review-of-nis2
URL:https://calendar.fru.dev/events/reg-eu-nis2-2027-10-17-commission-revi
 ew-of-nis2
CATEGORIES:Compliance deadlines
LOCATION:European Union
END:VEVENT
BEGIN:VEVENT
UID:reg-us-cmmc-2027-11-10-phase-3-level-3-certification@calendar.fru.dev
DTSTAMP:20260925T144757Z
DTSTART;VALUE=DATE:20271110
DTEND;VALUE=DATE:20271111
TRANSP:TRANSPARENT
SUMMARY:CMMC 2.0: Phase 3: Level 3 certification
DESCRIPTION:Phase 3 begins one year after Phase 2; Level 3 (DIBCAC) requir
 ements added to applicable solicitations (32 CFR 170.3(e)(3)). Not legal 
 advice.\nWhere: United States (Federal)\nSource: https://www.federalregis
 ter.gov/documents/2024/10/15/2024-22905/cybersecurity-maturity-model-cert
 ification-cmmc-program\nhttps://calendar.fru.dev/events/reg-us-cmmc-2027-
 11-10-phase-3-level-3-certification
URL:https://calendar.fru.dev/events/reg-us-cmmc-2027-11-10-phase-3-level-3
 -certification
CATEGORIES:Compliance deadlines
LOCATION:United States (Federal)
END:VEVENT
BEGIN:VEVENT
UID:reg-cl-pdpl-2027-12-01-proposed-postponement-of-entry@calendar.fru.dev
DTSTAMP:20260925T144757Z
DTSTART;VALUE=DATE:20271201
DTEND;VALUE=DATE:20271202
TRANSP:TRANSPARENT
SUMMARY:Chile Personal Data Protection Law (Ley 21.719): Proposed postpone
 ment of entry into force
DESCRIPTION:Government bill Boletin 18623-07 (filed 1 Sep 2026\, 'suma' ur
 gency) would replace the 24-month vacatio legis in transitional Art 1 wit
 h a fixed date of 1...\nWhere: Chile\nSource: https://tramitacion.senado.
 cl/appsenado/templates/tramitacion/index.php?boletin_ini=18623-07\nhttps:
 //calendar.fru.dev/events/reg-cl-pdpl-2027-12-01-proposed-postponement-of
 -entry
URL:https://calendar.fru.dev/events/reg-cl-pdpl-2027-12-01-proposed-postpo
 nement-of-entry
CATEGORIES:Compliance deadlines
LOCATION:Chile
STATUS:TENTATIVE
END:VEVENT
BEGIN:VEVENT
UID:reg-eu-ai-act-2027-12-02-high-risk-obligations-apply-to@calendar.fru.d
 ev
DTSTAMP:20260925T144757Z
DTSTART;VALUE=DATE:20271202
DTEND;VALUE=DATE:20271203
TRANSP:TRANSPARENT
SUMMARY:EU AI Act: High-risk obligations apply to Annex III systems
DESCRIPTION:Chapter III Sections 1-3 (high-risk requirements and provider/
 deployer obligations) apply to AI systems classified high-risk under Art 
 6(2) and Annex III...\nWhere: European Union\nSource: https://eur-lex.eur
 opa.eu/eli/reg/2026/1744/oj\nhttps://calendar.fru.dev/events/reg-eu-ai-ac
 t-2027-12-02-high-risk-obligations-apply-to
URL:https://calendar.fru.dev/events/reg-eu-ai-act-2027-12-02-high-risk-obl
 igations-apply-to
CATEGORIES:Compliance deadlines
LOCATION:European Union
END:VEVENT
BEGIN:VEVENT
UID:reg-eu-cra-2027-12-11-cra-fully-applies@calendar.fru.dev
DTSTAMP:20260925T144757Z
DTSTART;VALUE=DATE:20271211
DTEND;VALUE=DATE:20271212
TRANSP:TRANSPARENT
SUMMARY:Cyber Resilience Act: CRA fully applies
DESCRIPTION:All remaining obligations\, including essential cybersecurity 
 requirements\, conformity assessment and CE marking\, apply (Art 71(2)). 
 Products placed on the...\nWhere: European Union\nSource: https://eur-lex
 .europa.eu/eli/reg/2024/2847/oj\nhttps://calendar.fru.dev/events/reg-eu-c
 ra-2027-12-11-cra-fully-applies
URL:https://calendar.fru.dev/events/reg-eu-cra-2027-12-11-cra-fully-applie
 s
CATEGORIES:Compliance deadlines
LOCATION:European Union
END:VEVENT
BEGIN:VEVENT
UID:reg-eu-eidas2-2027-12-24-private-relying-parties-must-a@calendar.fru.d
 ev
DTSTAMP:20260925T144757Z
DTSTART;VALUE=DATE:20271224
DTEND;VALUE=DATE:20271225
TRANSP:TRANSPARENT
SUMMARY:eIDAS 2 / EU Digital Identity Wallet: Private relying parties must
  accept wallets
DESCRIPTION:Private relying parties required by law or contract to use str
 ong user authentication must accept wallets on user request within 36 mon
 ths of the...\nWhere: European Union\nSource: https://eur-lex.europa.eu/e
 li/reg_impl/2024/2977/oj\nhttps://calendar.fru.dev/events/reg-eu-eidas2-2
 027-12-24-private-relying-parties-must-a
URL:https://calendar.fru.dev/events/reg-eu-eidas2-2027-12-24-private-relyi
 ng-parties-must-a
CATEGORIES:Compliance deadlines
LOCATION:European Union
END:VEVENT
BEGIN:VEVENT
UID:reg-us-ca-ccpa-2027-12-31-risk-assessments-for-pre-exist@calendar.fru.
 dev
DTSTAMP:20260925T144757Z
DTSTART;VALUE=DATE:20271231
DTEND;VALUE=DATE:20280101
TRANSP:TRANSPARENT
SUMMARY:CCPA / CPRA: Risk assessments for pre-existing processing due
DESCRIPTION:Risk assessments must be completed and documented for high-ris
 k processing that began before Jan 1\, 2026 and continues after (11 CCR 7
 155(b)). Not legal advice.\nWhere: California\nSource: https://cppa.ca.go
 v/regulations/pdf/ccpa_updates_cyber_risk_admt_appr_text.pdf\nhttps://cal
 endar.fru.dev/events/reg-us-ca-ccpa-2027-12-31-risk-assessments-for-pre-e
 xist
URL:https://calendar.fru.dev/events/reg-us-ca-ccpa-2027-12-31-risk-assessm
 ents-for-pre-exist
CATEGORIES:Compliance deadlines
LOCATION:California
END:VEVENT
BEGIN:VEVENT
UID:reg-us-vt-vdposa-2028-01-01-vermont-data-privacy-and-onlin@calendar.fr
 u.dev
DTSTAMP:20260925T144757Z
DTSTART;VALUE=DATE:20280101
DTEND;VALUE=DATE:20280102
TRANSP:TRANSPARENT
SUMMARY:Vermont VDPOSA: Vermont Data Privacy and Online Surveillance Act t
 akes effect
DESCRIPTION:All obligations under Act 145 apply (sec. 4). Not legal advice
 .\nWhere: Vermont\nSource: https://legislature.vermont.gov/Documents/2026
 /Docs/ACTS/ACT145/ACT145%20As%20Enacted.pdf\nhttps://calendar.fru.dev/eve
 nts/reg-us-vt-vdposa-2028-01-01-vermont-data-privacy-and-onlin
URL:https://calendar.fru.dev/events/reg-us-vt-vdposa-2028-01-01-vermont-da
 ta-privacy-and-onlin
CATEGORIES:Compliance deadlines
LOCATION:Vermont
END:VEVENT
BEGIN:VEVENT
UID:reg-us-ca-sb942-2028-01-01-capture-device-manufacturer-du@calendar.fru
 .dev
DTSTAMP:20260925T144757Z
DTSTART;VALUE=DATE:20280101
DTEND;VALUE=DATE:20280102
TRANSP:TRANSPARENT
SUMMARY:California AI Transparency Act (SB 942): Capture device manufactur
 er duties
DESCRIPTION:Capture device manufacturer provenance requirements become ope
 rative. Not legal advice.\nWhere: California\nSource: https://leginfo.leg
 islature.ca.gov/faces/billNavClient.xhtml?bill_id=202520260AB853\nhttps:/
 /calendar.fru.dev/events/reg-us-ca-sb942-2028-01-01-capture-device-manufa
 cturer-du
URL:https://calendar.fru.dev/events/reg-us-ca-sb942-2028-01-01-capture-dev
 ice-manufacturer-du
CATEGORIES:Compliance deadlines
LOCATION:California
END:VEVENT
BEGIN:VEVENT
UID:reg-us-ca-delete-act-2028-01-01-independent-third-party-audits@calenda
 r.fru.dev
DTSTAMP:20260925T144757Z
DTSTART;VALUE=DATE:20280101
DTEND;VALUE=DATE:20280102
TRANSP:TRANSPARENT
SUMMARY:California Delete Act / DROP: Independent third-party audits begin
DESCRIPTION:Beginning Jan 1\, 2028 and every 3 years thereafter\, data bro
 kers must undergo an independent audit of Delete Act compliance. Not lega
 l advice.\nWhere: California\nSource: https://www.cppa.ca.gov/data_broker
 s/\nhttps://calendar.fru.dev/events/reg-us-ca-delete-act-2028-01-01-indep
 endent-third-party-audits
URL:https://calendar.fru.dev/events/reg-us-ca-delete-act-2028-01-01-indepe
 ndent-third-party-audits
CATEGORIES:Compliance deadlines
LOCATION:California
END:VEVENT
BEGIN:VEVENT
UID:reg-us-ca-ccpa-2028-04-01-cybersecurity-audit-due-revenu@calendar.fru.
 dev
DTSTAMP:20260925T144757Z
DTSTART;VALUE=DATE:20280401
DTEND;VALUE=DATE:20280402
TRANSP:TRANSPARENT
SUMMARY:CCPA / CPRA: Cybersecurity audit due: revenue over $100M
DESCRIPTION:First cybersecurity audit report (covering Jan 1\, 2027 - Jan 
 1\, 2028) and certification due for businesses with 2026 annual gross rev
 enue over $100M (11 CCR...\nWhere: California\nSource: https://cppa.ca.go
 v/regulations/pdf/ccpa_updates_cyber_risk_admt_appr_text.pdf\nhttps://cal
 endar.fru.dev/events/reg-us-ca-ccpa-2028-04-01-cybersecurity-audit-due-re
 venu
URL:https://calendar.fru.dev/events/reg-us-ca-ccpa-2028-04-01-cybersecurit
 y-audit-due-revenu
CATEGORIES:Compliance deadlines
LOCATION:California
END:VEVENT
BEGIN:VEVENT
UID:reg-us-ca-ccpa-2028-04-01-first-risk-assessment-submissi@calendar.fru.
 dev
DTSTAMP:20260925T144757Z
DTSTART;VALUE=DATE:20280401
DTEND;VALUE=DATE:20280402
TRANSP:TRANSPARENT
SUMMARY:CCPA / CPRA: First risk assessment submission to CPPA
DESCRIPTION:Businesses must submit required risk assessment information an
 d attestation for assessments conducted in 2026 and 2027 (11 CCR 7157(a)(
 1)); annually by...\nWhere: California\nSource: https://cppa.ca.gov/regul
 ations/pdf/ccpa_updates_cyber_risk_admt_appr_text.pdf\nhttps://calendar.f
 ru.dev/events/reg-us-ca-ccpa-2028-04-01-first-risk-assessment-submissi
URL:https://calendar.fru.dev/events/reg-us-ca-ccpa-2028-04-01-first-risk-a
 ssessment-submissi
CATEGORIES:Compliance deadlines
LOCATION:California
END:VEVENT
BEGIN:VEVENT
UID:reg-eu-cra-2028-06-11-legacy-type-examination-certif@calendar.fru.dev
DTSTAMP:20260925T144757Z
DTSTART;VALUE=DATE:20280611
DTEND;VALUE=DATE:20280612
TRANSP:TRANSPARENT
SUMMARY:Cyber Resilience Act: Legacy type-examination certificates expire
DESCRIPTION:EU type-examination certificates and approval decisions on cyb
 ersecurity requirements under other harmonisation legislation remain vali
 d until this date...\nWhere: European Union\nSource: https://eur-lex.euro
 pa.eu/eli/reg/2024/2847/oj\nhttps://calendar.fru.dev/events/reg-eu-cra-20
 28-06-11-legacy-type-examination-certif
URL:https://calendar.fru.dev/events/reg-eu-cra-2028-06-11-legacy-type-exam
 ination-certif
CATEGORIES:Compliance deadlines
LOCATION:European Union
END:VEVENT
BEGIN:VEVENT
UID:reg-eu-ai-act-2028-08-02-high-risk-obligations-apply-to@calendar.fru.d
 ev
DTSTAMP:20260925T144757Z
DTSTART;VALUE=DATE:20280802
DTEND;VALUE=DATE:20280803
TRANSP:TRANSPARENT
SUMMARY:EU AI Act: High-risk obligations apply to Annex I product-embedded
  systems
DESCRIPTION:Chapter III Sections 1-3 apply to AI systems classified high-r
 isk under Art 6(1) and Annex I (safety components of products covered by 
 EU harmonisation...\nWhere: European Union\nSource: https://eur-lex.europ
 a.eu/eli/reg/2026/1744/oj\nhttps://calendar.fru.dev/events/reg-eu-ai-act-
 2028-08-02-high-risk-obligations-apply-to
URL:https://calendar.fru.dev/events/reg-eu-ai-act-2028-08-02-high-risk-obl
 igations-apply-to
CATEGORIES:Compliance deadlines
LOCATION:European Union
END:VEVENT
BEGIN:VEVENT
UID:reg-eu-cra-2028-09-11-report-on-single-reporting-pla@calendar.fru.dev
DTSTAMP:20260925T144757Z
DTSTART;VALUE=DATE:20280911
DTEND;VALUE=DATE:20280912
TRANSP:TRANSPARENT
SUMMARY:Cyber Resilience Act: Report on single reporting platform
DESCRIPTION:Commission report assessing the single reporting platform's ef
 fectiveness (Art 70(2)). Not legal advice.\nWhere: European Union\nSource
 : https://eur-lex.europa.eu/eli/reg/2024/2847/oj\nhttps://calendar.fru.de
 v/events/reg-eu-cra-2028-09-11-report-on-single-reporting-pla
URL:https://calendar.fru.dev/events/reg-eu-cra-2028-09-11-report-on-single
 -reporting-pla
CATEGORIES:Compliance deadlines
LOCATION:European Union
END:VEVENT
BEGIN:VEVENT
UID:reg-eu-data-act-2028-09-12-commission-evaluation@calendar.fru.dev
DTSTAMP:20260925T144757Z
DTSTART;VALUE=DATE:20280912
DTEND;VALUE=DATE:20280913
TRANSP:TRANSPARENT
SUMMARY:EU Data Act: Commission evaluation
DESCRIPTION:Commission evaluation report due\, including the impact of clo
 ud switching rules (Arts 23-31) (Art 49(2)). Not legal advice.\nWhere: Eu
 ropean Union\nSource: https://eur-lex.europa.eu/eli/reg/2023/2854/oj\nhtt
 ps://calendar.fru.dev/events/reg-eu-data-act-2028-09-12-commission-evalua
 tion
URL:https://calendar.fru.dev/events/reg-eu-data-act-2028-09-12-commission-
 evaluation
CATEGORIES:Compliance deadlines
LOCATION:European Union
END:VEVENT
BEGIN:VEVENT
UID:reg-us-ct-ctdpa-2028-10-01-data-brokers-must-process-stat@calendar.fru
 .dev
DTSTAMP:20260925T144757Z
DTSTART;VALUE=DATE:20281001
DTEND;VALUE=DATE:20281002
TRANSP:TRANSPARENT
SUMMARY:Connecticut Data Privacy Act (CTDPA): Data brokers must process st
 ate deletion mechanism requests
DESCRIPTION:Registered data brokers must access the DCP accessible deletio
 n mechanism at least every 45 days and process deletion requests. Not leg
 al advice.\nWhere: Connecticut\nSource: https://www.cga.ct.gov/2026/ACT/P
 A/PDF/2026PA-00064-R00SB-00004-PA.PDF\nhttps://calendar.fru.dev/events/re
 g-us-ct-ctdpa-2028-10-01-data-brokers-must-process-stat
URL:https://calendar.fru.dev/events/reg-us-ct-ctdpa-2028-10-01-data-broker
 s-must-process-stat
CATEGORIES:Compliance deadlines
LOCATION:Connecticut
END:VEVENT
BEGIN:VEVENT
UID:reg-us-cmmc-2028-11-10-phase-4-full-implementation@calendar.fru.dev
DTSTAMP:20260925T144757Z
DTSTART;VALUE=DATE:20281110
DTEND;VALUE=DATE:20281111
TRANSP:TRANSPARENT
SUMMARY:CMMC 2.0: Phase 4: full implementation
DESCRIPTION:CMMC requirements included in all applicable DoD solicitations
  and contracts\, including option periods (32 CFR 170.3(e)(4)). Not legal
  advice.\nWhere: United States (Federal)\nSource: https://www.federalregi
 ster.gov/documents/2024/10/15/2024-22905/cybersecurity-maturity-model-cer
 tification-cmmc-program\nhttps://calendar.fru.dev/events/reg-us-cmmc-2028
 -11-10-phase-4-full-implementation
URL:https://calendar.fru.dev/events/reg-us-cmmc-2028-11-10-phase-4-full-im
 plementation
CATEGORIES:Compliance deadlines
LOCATION:United States (Federal)
END:VEVENT
BEGIN:VEVENT
UID:reg-eu-ehds-2029-03-26-primary-use-for-first-data-cat@calendar.fru.dev
DTSTAMP:20260925T144757Z
DTSTART;VALUE=DATE:20290326
DTEND;VALUE=DATE:20290327
TRANSP:TRANSPARENT
SUMMARY:European Health Data Space (EHDS): Primary use for first data cate
 gories; secondary use framework applies
DESCRIPTION:Patient rights and EHR rules apply to patient summaries\, ePre
 scriptions and eDispensations (Art 14(1)(a)-(c)). Chapter IV secondary-us
 e rules (data permits\,...\nWhere: European Union\nSource: https://eur-le
 x.europa.eu/eli/reg/2025/327/oj\nhttps://calendar.fru.dev/events/reg-eu-e
 hds-2029-03-26-primary-use-for-first-data-cat
URL:https://calendar.fru.dev/events/reg-eu-ehds-2029-03-26-primary-use-for
 -first-data-cat
CATEGORIES:Compliance deadlines
LOCATION:European Union
END:VEVENT
BEGIN:VEVENT
UID:reg-us-ca-ccpa-2029-04-01-cybersecurity-audit-due-revenu@calendar.fru.
 dev
DTSTAMP:20260925T144757Z
DTSTART;VALUE=DATE:20290401
DTEND;VALUE=DATE:20290402
TRANSP:TRANSPARENT
SUMMARY:CCPA / CPRA: Cybersecurity audit due: revenue $50M-$100M
DESCRIPTION:First cybersecurity audit report (covering 2028) due for busin
 esses with 2027 annual gross revenue between $50M and $100M (11 CCR 7121(
 a)(2)). Not legal advice.\nWhere: California\nSource: https://cppa.ca.gov
 /regulations/pdf/ccpa_updates_cyber_risk_admt_appr_text.pdf\nhttps://cale
 ndar.fru.dev/events/reg-us-ca-ccpa-2029-04-01-cybersecurity-audit-due-rev
 enu
URL:https://calendar.fru.dev/events/reg-us-ca-ccpa-2029-04-01-cybersecurit
 y-audit-due-revenu
CATEGORIES:Compliance deadlines
LOCATION:California
END:VEVENT
BEGIN:VEVENT
UID:reg-us-vt-vdposa-2029-06-30-mandatory-60-day-cure-period-e@calendar.fr
 u.dev
DTSTAMP:20260925T144757Z
DTSTART;VALUE=DATE:20290630
DTEND;VALUE=DATE:20290701
TRANSP:TRANSPARENT
SUMMARY:Vermont VDPOSA: Mandatory 60-day cure period expires
DESCRIPTION:The AG's duty to issue a cure notice before enforcement ends J
 une 30\, 2029 (Act 145 sec. 3). Not legal advice.\nWhere: Vermont\nSource
 : https://legislature.vermont.gov/Documents/2026/Docs/ACTS/ACT145/ACT145%
 20As%20Enacted.pdf\nhttps://calendar.fru.dev/events/reg-us-vt-vdposa-2029
 -06-30-mandatory-60-day-cure-period-e
URL:https://calendar.fru.dev/events/reg-us-vt-vdposa-2029-06-30-mandatory-
 60-day-cure-period-e
CATEGORIES:Compliance deadlines
LOCATION:Vermont
END:VEVENT
BEGIN:VEVENT
UID:reg-us-mn-mcdpa-2029-07-31-postsecondary-institutions-mus@calendar.fru
 .dev
DTSTAMP:20260925T144757Z
DTSTART;VALUE=DATE:20290731
DTEND;VALUE=DATE:20290801
TRANSP:TRANSPARENT
SUMMARY:Minnesota Consumer Data Privacy Act (MCDPA): Postsecondary institu
 tions must comply
DESCRIPTION:Postsecondary institutions regulated by the Office of Higher E
 ducation must comply by July 31\, 2029. Not legal advice.\nWhere: Minneso
 ta\nSource: https://www.revisor.mn.gov/statutes/cite/325M.20\nhttps://cal
 endar.fru.dev/events/reg-us-mn-mcdpa-2029-07-31-postsecondary-institution
 s-mus
URL:https://calendar.fru.dev/events/reg-us-mn-mcdpa-2029-07-31-postseconda
 ry-institutions-mus
CATEGORIES:Compliance deadlines
LOCATION:Minnesota
END:VEVENT
BEGIN:VEVENT
UID:reg-us-co-ai-act-2030-01-01-mandatory-cure-period-ends@calendar.fru.de
 v
DTSTAMP:20260925T144757Z
DTSTART;VALUE=DATE:20300101
DTEND;VALUE=DATE:20300102
TRANSP:TRANSPARENT
SUMMARY:Colorado AI Act: Mandatory cure period ends
DESCRIPTION:The AG's obligation to offer a 60-day notice-and-cure period e
 xpires. Not legal advice.\nWhere: Colorado\nSource: https://leg.colorado.
 gov/bills/sb26-189\nhttps://calendar.fru.dev/events/reg-us-co-ai-act-2030
 -01-01-mandatory-cure-period-ends
URL:https://calendar.fru.dev/events/reg-us-co-ai-act-2030-01-01-mandatory-
 cure-period-ends
CATEGORIES:Compliance deadlines
LOCATION:Colorado
END:VEVENT
BEGIN:VEVENT
UID:reg-us-ca-ccpa-2030-04-01-cybersecurity-audit-due-revenu@calendar.fru.
 dev
DTSTAMP:20260925T144757Z
DTSTART;VALUE=DATE:20300401
DTEND;VALUE=DATE:20300402
TRANSP:TRANSPARENT
SUMMARY:CCPA / CPRA: Cybersecurity audit due: revenue under $50M
DESCRIPTION:First cybersecurity audit report (covering 2029) due for cover
 ed businesses with 2028 annual gross revenue under $50M (11 CCR 7121(a)(3
 )); annual by April 1...\nWhere: California\nSource: https://cppa.ca.gov/
 regulations/pdf/ccpa_updates_cyber_risk_admt_appr_text.pdf\nhttps://calen
 dar.fru.dev/events/reg-us-ca-ccpa-2030-04-01-cybersecurity-audit-due-reve
 nu
URL:https://calendar.fru.dev/events/reg-us-ca-ccpa-2030-04-01-cybersecurit
 y-audit-due-revenu
CATEGORIES:Compliance deadlines
LOCATION:California
END:VEVENT
BEGIN:VEVENT
UID:reg-eu-ai-act-2030-08-02-public-authority-high-risk-sys@calendar.fru.d
 ev
DTSTAMP:20260925T144757Z
DTSTART;VALUE=DATE:20300802
DTEND;VALUE=DATE:20300803
TRANSP:TRANSPARENT
SUMMARY:EU AI Act: Public-authority high-risk systems must comply
DESCRIPTION:Providers and deployers of high-risk AI systems intended for u
 se by public authorities that were placed on the market before the Chapte
 r III application...\nWhere: European Union\nSource: https://eur-lex.euro
 pa.eu/eli/reg/2026/1744/oj\nhttps://calendar.fru.dev/events/reg-eu-ai-act
 -2030-08-02-public-authority-high-risk-sys
URL:https://calendar.fru.dev/events/reg-eu-ai-act-2030-08-02-public-author
 ity-high-risk-sys
CATEGORIES:Compliance deadlines
LOCATION:European Union
END:VEVENT
BEGIN:VEVENT
UID:reg-eu-cra-2030-12-11-first-cra-evaluation@calendar.fru.dev
DTSTAMP:20260925T144757Z
DTSTART;VALUE=DATE:20301211
DTEND;VALUE=DATE:20301212
TRANSP:TRANSPARENT
SUMMARY:Cyber Resilience Act: First CRA evaluation
DESCRIPTION:Commission evaluation and review report\, then every four year
 s (Art 70(1)). Not legal advice.\nWhere: European Union\nSource: https://
 eur-lex.europa.eu/eli/reg/2024/2847/oj\nhttps://calendar.fru.dev/events/r
 eg-eu-cra-2030-12-11-first-cra-evaluation
URL:https://calendar.fru.dev/events/reg-eu-cra-2030-12-11-first-cra-evalua
 tion
CATEGORIES:Compliance deadlines
LOCATION:European Union
END:VEVENT
BEGIN:VEVENT
UID:reg-eu-ai-act-2030-12-31-large-scale-eu-it-systems-must@calendar.fru.d
 ev
DTSTAMP:20260925T144757Z
DTSTART;VALUE=DATE:20301231
DTEND;VALUE=DATE:20310101
TRANSP:TRANSPARENT
SUMMARY:EU AI Act: Large-scale EU IT systems must comply
DESCRIPTION:AI systems that are components of the large-scale IT systems i
 n Annex X (e.g. SIS\, VIS\, Eurodac\, EES\, ETIAS) placed on the market b
 efore 2 Aug 2027 must be...\nWhere: European Union\nSource: https://eur-l
 ex.europa.eu/eli/reg/2024/1689/oj\nhttps://calendar.fru.dev/events/reg-eu
 -ai-act-2030-12-31-large-scale-eu-it-systems-must
URL:https://calendar.fru.dev/events/reg-eu-ai-act-2030-12-31-large-scale-e
 u-it-systems-must
CATEGORIES:Compliance deadlines
LOCATION:European Union
END:VEVENT
END:VCALENDAR
