Compliance Colleague · Tools

Compliance deadline calendar

11 dates · updated 2026-10-03

The compliance dates that matter over the next two years, in your own calendar. Subscribe once and corrections and new dates arrive automatically.

Subscribe: Google Calendar · Outlook · Apple Calendar · download .ics

Other apps: add a calendar “from URL” and paste https://compliancecolleague.ai/tools/deadline-calendar/deadlines.ics

13 November 2026 · India
India DPDP: Consent Manager provisions commence

Consent Manager registration and obligations under the Digital Personal Data Protection Rules, 2025 come into force. Core obligations follow on 13 May 2027.

Source: DPDP Rules, 2025, Rule 1 and Rule 4; DPDP Act, 2023 ss. 6(9), 27(1)(d). More

30 November 2026 · United States
NIST SP 800-82 Rev. 4 (OT security) draft: comments close

Last day to comment on the initial public draft of NIST SP 800-82 Rev. 4, Guide to Operational Technology Security, rebuilt around CSF 2.0.

Source: NIST CSRC, SP 800-82 Rev. 4 initial public draft (21 Sep 2026). More

2 December 2026 · European Union
EU AI Act: new Art. 5 prohibitions and Art. 50(2) marking for older generative systems

The intimate-imagery and child sexual abuse material prohibitions (Art. 5(1)(ba), (bb)) apply, and generative AI systems placed on the market before 2 Aug 2026 must meet the Art. 50(2) machine-readable marking duty.

Source: Regulation (EU) 2024/1689 Art. 5, Art. 111(4) and Art. 113, as amended by Regulation (EU) 2026/1744. More

10 December 2026 · Australia
Australia: automated-decision transparency (APP 1.7-1.9) in force

APP entities must say in their privacy policy when computer programs make, or substantially help make, decisions that could significantly affect individuals. Applies to decisions made after this date.

Source: Privacy and Other Legislation Amendment Act 2024, s. 2 (item 7) and Schedule 1 Part 15. More

1 January 2027 · California, United States
California CCPA: ADMT compliance date

Businesses that use automated decision-making technology for significant decisions before this date (including tools first deployed during 2026) must comply with the ADMT rules by 1 January 2027. Use that starts later must comply from the start.

Source: CCPA Regulations, 11 CCR § 7200(b). More

13 May 2027 · India
India DPDP: full compliance deadline

The core obligations of the Digital Personal Data Protection Act and Rules apply: notice, consent, security safeguards, breach notification, data principal rights and retention.

Source: DPDP Rules, 2025, Rule 1 (18 months from notification). More

2 December 2027 · European Union
EU AI Act: high-risk obligations for Annex III systems apply

Provider and deployer obligations for high-risk AI systems listed in Annex III (employment, credit, education, essential services and others) apply, deferred from August 2026 by the Digital Omnibus.

Source: Regulation (EU) 2024/1689 Art. 113, as amended by Regulation (EU) 2026/1744. More

11 December 2027 · European Union
EU Cyber Resilience Act applies in full

All remaining Cyber Resilience Act obligations apply to products with digital elements, including the essential cybersecurity requirements and conformity assessment. Vulnerability and incident reporting already applies.

Source: Regulation (EU) 2024/2847 Art. 71(2). More

31 December 2027 · California, United States
California CCPA: risk assessments due for processing begun before 2026

Risk assessments must be completed for processing activities that began before 1 January 2026 and are still continuing.

Source: CCPA Regulations, 11 CCR § 7155(b). More

1 April 2028 · California, United States
California CCPA: first cybersecurity audit certifications and risk-assessment submissions

Businesses with 2026 revenue over $100 million submit their first cybersecurity audit certification (audit period 2027). Risk-assessment information and an executive attestation for assessments conducted in 2026-2027 are also due.

Source: CCPA Regulations, 11 CCR §§ 7121 and 7157(a). More

2 August 2028 · European Union
EU AI Act: high-risk obligations for Annex I products apply

High-risk obligations apply to AI systems that are safety components of products covered by the EU harmonisation legislation in Annex I (machinery, medical devices, toys and others).

Source: Regulation (EU) 2024/1689 Art. 113, as amended by Regulation (EU) 2026/1744. More

Need to know what a date means for you? Compliance Colleague answers with the article cited, across 30+ standards and laws. Try it free, no card required →

Not legal advice. Dates are taken from the official texts and re-checked monthly; confirm against the source before you rely on one.