Compliance deadline calendar
The compliance dates that matter over the next two years, in your own calendar. Subscribe once and corrections and new dates arrive automatically.
Subscribe: Google Calendar · Outlook · Apple Calendar · download .ics
Other apps: add a calendar “from URL” and paste https://compliancecolleague.ai/tools/deadline-calendar/deadlines.ics
Consent Manager registration and obligations under the Digital Personal Data Protection Rules, 2025 come into force. Core obligations follow on 13 May 2027.
Source: DPDP Rules, 2025, Rule 1 and Rule 4; DPDP Act, 2023 ss. 6(9), 27(1)(d). More
Last day to comment on the initial public draft of NIST SP 800-82 Rev. 4, Guide to Operational Technology Security, rebuilt around CSF 2.0.
Source: NIST CSRC, SP 800-82 Rev. 4 initial public draft (21 Sep 2026). More
The intimate-imagery and child sexual abuse material prohibitions (Art. 5(1)(ba), (bb)) apply, and generative AI systems placed on the market before 2 Aug 2026 must meet the Art. 50(2) machine-readable marking duty.
Source: Regulation (EU) 2024/1689 Art. 5, Art. 111(4) and Art. 113, as amended by Regulation (EU) 2026/1744. More
APP entities must say in their privacy policy when computer programs make, or substantially help make, decisions that could significantly affect individuals. Applies to decisions made after this date.
Source: Privacy and Other Legislation Amendment Act 2024, s. 2 (item 7) and Schedule 1 Part 15. More
Businesses that use automated decision-making technology for significant decisions before this date (including tools first deployed during 2026) must comply with the ADMT rules by 1 January 2027. Use that starts later must comply from the start.
Source: CCPA Regulations, 11 CCR § 7200(b). More
The core obligations of the Digital Personal Data Protection Act and Rules apply: notice, consent, security safeguards, breach notification, data principal rights and retention.
Source: DPDP Rules, 2025, Rule 1 (18 months from notification). More
Provider and deployer obligations for high-risk AI systems listed in Annex III (employment, credit, education, essential services and others) apply, deferred from August 2026 by the Digital Omnibus.
Source: Regulation (EU) 2024/1689 Art. 113, as amended by Regulation (EU) 2026/1744. More
All remaining Cyber Resilience Act obligations apply to products with digital elements, including the essential cybersecurity requirements and conformity assessment. Vulnerability and incident reporting already applies.
Source: Regulation (EU) 2024/2847 Art. 71(2). More
Risk assessments must be completed for processing activities that began before 1 January 2026 and are still continuing.
Source: CCPA Regulations, 11 CCR § 7155(b). More
Businesses with 2026 revenue over $100 million submit their first cybersecurity audit certification (audit period 2027). Risk-assessment information and an executive attestation for assessments conducted in 2026-2027 are also due.
Source: CCPA Regulations, 11 CCR §§ 7121 and 7157(a). More
High-risk obligations apply to AI systems that are safety components of products covered by the EU harmonisation legislation in Annex I (machinery, medical devices, toys and others).
Source: Regulation (EU) 2024/1689 Art. 113, as amended by Regulation (EU) 2026/1744. More
Not legal advice. Dates are taken from the official texts and re-checked monthly; confirm against the source before you rely on one.